bell-sw/Liberica

Upgrade Alpine to latest release 3.16.4 to fix vulnerabilities

etiennepeiniau opened this issue · 2 comments

Hi,

Is-it possible to upgrade the base image for alpine versions to 3.16.4 (mostly just a build / publish) ?

This will correct the following critical CVE : https://nvd.nist.gov/vuln/detail/CVE-2023-0286

You can find the alpine changelog here : https://www.alpinelinux.org/posts/Alpine-3.14.9-3.15.7-3.16.4-released.html

Thanks.

Any plans to address this?

Hi,
New Alpine images have been built from 3.16.4 (which is referenced as 3.16 in dockerfiles)

# cat /etc/alpine-release 3.16.4