Skip to content

Patching for base images #1833

Open
Open
@sozercan

Description

@sozercan

What would you like to be added:

Are there any plans to automatically patch actionable CVEs in base images, such as debian-base, and push new versions? Is this a manual process today?

Why is this needed:

It would be ideal if base image versions are automated when an actionable CVE is found so individual projects don't have to maintain OS level patching.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/release-engIssues or PRs related to the Release Engineering subprojecthelp wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.kind/featureCategorizes issue or PR as related to a new feature.priority/important-longtermImportant over the long term, but may not be staffed and/or may need multiple releases to complete.sig/releaseCategorizes an issue or PR as relevant to SIG Release.sig/securityCategorizes an issue or PR as relevant to SIG Security.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions