diff --git a/.dockleignore b/.dockleignore new file mode 100644 index 0000000..4cbb1bc --- /dev/null +++ b/.dockleignore @@ -0,0 +1,2 @@ +# This is being done, yet it is still being detected +DKL-DI-0005 diff --git a/.grype.yaml b/.grype.yaml new file mode 100644 index 0000000..1131684 --- /dev/null +++ b/.grype.yaml @@ -0,0 +1,2 @@ +ignore: + - vulnerability: CVE-2025-27558 # Not able to fix it at the moment diff --git a/simplerisk-minimal/Dockerfile b/simplerisk-minimal/Dockerfile index cd99412..0648451 100644 --- a/simplerisk-minimal/Dockerfile +++ b/simplerisk-minimal/Dockerfile @@ -23,7 +23,8 @@ RUN mkdir -p /etc/apt/keyrings && \ apt-get update && \ apt-get install -y --no-install-recommends gnupg2 wget lsb-release && \ wget -qO - https://repo.mysql.com/RPM-GPG-KEY-mysql-2023 | gpg --dearmor -o /etc/apt/keyrings/mysql.gpg && \ - echo "deb [signed-by=/etc/apt/keyrings/mysql.gpg] http://repo.mysql.com/apt/debian/ $(lsb_release -cs) mysql-8.0" | tee /etc/apt/sources.list.d/mysql.list && \ + # FIXME: use $(lsb_release -cs) when trixie becomes available on MySQL repos + echo "deb [signed-by=/etc/apt/keyrings/mysql.gpg] http://repo.mysql.com/apt/debian/ bookworm mysql-8.0" | tee /etc/apt/sources.list.d/mysql.list && \ apt-get update && \ apt-get -y install --no-install-recommends libldap2-dev \ libicu-dev \ diff --git a/simplerisk-minimal/generate_dockerfile.sh b/simplerisk-minimal/generate_dockerfile.sh index 089b935..448e8f0 100755 --- a/simplerisk-minimal/generate_dockerfile.sh +++ b/simplerisk-minimal/generate_dockerfile.sh @@ -46,7 +46,8 @@ RUN mkdir -p /etc/apt/keyrings && \\ apt-get update && \\ apt-get install -y --no-install-recommends gnupg2 wget lsb-release && \\ wget -qO - $MYSQL_KEY_URL | gpg --dearmor -o /etc/apt/keyrings/mysql.gpg && \\ - echo "deb [signed-by=/etc/apt/keyrings/mysql.gpg] http://repo.mysql.com/apt/debian/ \$(lsb_release -cs) mysql-8.0" | tee /etc/apt/sources.list.d/mysql.list && \\ + # FIXME: use \$(lsb_release -cs) when trixie becomes available on MySQL repos + echo "deb [signed-by=/etc/apt/keyrings/mysql.gpg] http://repo.mysql.com/apt/debian/ bookworm mysql-8.0" | tee /etc/apt/sources.list.d/mysql.list && \\ apt-get update && \\ apt-get -y install --no-install-recommends libldap2-dev \\ libicu-dev \\