dockerfile-security icon indicating copy to clipboard operation
dockerfile-security copied to clipboard

apt-get upgrade can be ok in Dockerfile

Open ioggstream opened this issue 2 years ago • 0 comments

Discussion

I found this very interesting PoV https://pythonspeed.com/articles/security-updates-in-docker/ that made it into Hadolint rules.

I suggest to replace the no update rule with a no dist-upgrade rule. See https://github.com/hadolint/hadolint/issues/562

ioggstream avatar Jun 26 '23 16:06 ioggstream