And high CVEs CVE-2024-6345, CVE-2023-29491, CVE-2023-7104
Issue-ID: INF-493
Change-Id: I073bfca3de06d8b68cc4d31c39e753fbe4a80cf5
Signed-off-by: vpachchi <vineela.pachchipulusu@windriver.com>
libtirpc-dev \
linux-headers \
make \
- ncurses-dev \
openssl-dev \
pax-utils \
- sqlite-dev \
tcl-dev \
tk \
tk-dev \
RUN mkdir -p /.venv && \
python -m venv /.venv \
+ && pip install --no-cache-dir --upgrade pip setuptools==70.0 \
&& pip install --no-cache-dir -r /tmp/requirements.txt -r /tmp/requirements-stx.txt -c /tmp/constraints.txt \
&& pip install --no-cache-dir -e /src
USER root
-# Upgrade expat to latest version to mitigate CVE-2024-45492
+# Upgrade packages to latest versions to mitigate CVEs
RUN echo "https://dl-cdn.alpinelinux.org/alpine/edge/main" >> /etc/apk/repositories && \
- apk update && \
- apk add --upgrade expat && \
- apk info expat
+ apk update \
+ && apk add --upgrade expat busybox krb5 ncurses ncurses-dev sqlite sqlite-dev \
+ && apk info expat busybox krb5 ncurses sqlite
RUN apk add --no-cache bash