FROM fireflyiii/core@sha256:... + apt-get upgrade -- no app-code changes. This exists to
clear OS-package CVEs that Debian already has a fix for but upstream's image build hasn't
picked up yet, without taking on Firefly III's actual PHP/Laravel build process.
The upstream image scanned at 235 HIGH/CRITICAL findings (113 fixed, 110 affected, 12
fix_deferred). The apt-get upgrade layer clears the entire fixed bucket, leaving 122
that Debian's own security tracker has no fix for yet -- documented in
trivyignore-entries.yml, nothing a Dockerfile can do about those. (A few more --
libunbound8 -- turned up in the real CI scan shortly after and are documented there too.)
To pick up a new upstream release: bump the digest in the FROM line, rebuild, re-review
whatever's left in the scan (the apt-get upgrade set will shift as Debian ships patches).
Used by home-k8s-config's personal_finance_core_image.
Content type
Image
Digest
sha256:dcef4c2c1…
Size
318.5 MB
Last updated
about 2 months ago
docker pull gschaetz/fireflyiii-core