FROM ghcr.io/home-assistant/home-assistant@sha256:... + apk upgrade -- no app-code
changes. Alpine-based (apk, not apt), same idea as patched-images/litellm.
Upstream scanned at 119 HIGH/CRITICAL findings (118 fixed, 1 affected). apk upgrade
clears the ~10 Alpine OS-level packages with fixes, leaving 76 (52 unique CVE IDs) in
Python, go2rtc, tempio, uv/uvx -- all vendored language deps baked into Home
Assistant's own build, not something an OS-package upgrade touches. One of those (the
ecdsa Minerva timing-attack, CVE-2024-23342) has no fix published anywhere -- same
finding already accepted for alpine-images/iac-tooling.
Home Assistant ships frequently; re-resolve the FROM digest periodically and re-review
what's left in trivyignore-entries.yml.
Used by home-k8s-config's home_assistant_image.
Content type
Image
Digest
sha256:fa944aadc…
Size
600.2 MB
Last updated
about 2 months ago
docker pull gschaetz/home-assistant