-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
This security issue CVE-2021-3177
was fixed and the fix is not pushed to dockerhub image.
#577
Comments
Debian Buster is still unfixed so there's nothing actionable we could do https://security-tracker.debian.org/tracker/CVE-2021-3177 See also https://github.com/docker-library/faq#why-does-my-security-scanner-show-that-an-image-has-cves A CVE doesn't imply having an actual vulnerability, and often is even a false positive (given how most distributions handle versioning/security updates in stable releases). If there are actionable items we can resolve, we're happy to do so (and do so actively). We update all Debian based images to include any updates in apt packages at least monthly (we regenerate the base images and then rebuild all dependent images). |
As for python/3.8/buster/slim/Dockerfile Lines 54 to 78 in ada46dd
There hasn't been a python 3.8 release since Dec. 21, 2020, https://www.python.org/downloads/. Once they release a new version, we will publish it. |
@yosifkit just to nudge, seeing that the latest version 3.8.8 is now live here, thank you all for your diligence 🙏 |
docker-library/official-images#9658 😉 (Official builds are in progress.) |
According to NVD, python v3.8.7 has a critical security issue. I'm using
python:3.8-slim
NVD link: https://nvd.nist.gov/vuln/detail/CVE-2021-3177
fix: python/cpython#24248
The text was updated successfully, but these errors were encountered: