fix: remove exact version pin for libpq-dev in Dockerfile (#12808)#13011
Open
OliverCostello1 wants to merge 1 commit into
Open
fix: remove exact version pin for libpq-dev in Dockerfile (#12808)#13011OliverCostello1 wants to merge 1 commit into
OliverCostello1 wants to merge 1 commit into
Conversation
|
Thanks for your pull request, and welcome to our community! We require contributors to sign our Contributor License Agreement and we don't seem to have your signature on file. Check out this article for more information on why we have a CLA. In order for us to review and merge your code, please submit the Individual Contributor License Agreement form attached above above. If you have questions about the CLA, or if you believe you've received this message in error, please reach out through a comment on this PR. CLA has not been signed by users: @OliverCostello1 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #12808
Removes the exact version pin on
libpq-devindocker/Dockerfile. This pin has required 5+ manual bumps in ~18 months because Debian removes old package versions from apt repos whenever it publishes a security update, breaking Docker builds until a maintainer notices and bumps the pin.What changed
docker/Dockerfile:libpq-dev=13.23-0+deb11u3→libpq-dev(unpinned), with an explanatory comment.Why this is safe
The
apt-mark hold libpq-devline that immediately follows already preventsapt-get dist-upgradefrom changing the installed version during the build. The exact-version pin was providing no additional protection — it was only causing breakage when Debian published patch updates.Checklist