From 555e018f4eac8e980e8b6ddb389b4ee5be1a56ea Mon Sep 17 00:00:00 2001 From: David Nguyen Date: Thu, 1 Aug 2024 11:31:48 -0700 Subject: [PATCH] Update base images (#2226) The base-builder and base-server images are ~4months old at this point and the security scanner I'm using picks up a CVE-2023-45288. This CVE is resolved in go >= 1.22.2 so is likely already resolved in base-builder 1.14.11 since that was built recently and 1.22.5 is the latest in golang:1.22-alpine3.20 if someone pulls it today. --- server/Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/server/Dockerfile b/server/Dockerfile index 2de8c9a67..b1ef9078e 100644 --- a/server/Dockerfile +++ b/server/Dockerfile @@ -1,5 +1,5 @@ -ARG BASE_SERVER_IMAGE=temporalio/base-server:1.15.7 -ARG BASE_BUILDER_IMAGE=temporalio/base-builder:1.14.8 +ARG BASE_SERVER_IMAGE=temporalio/base-server:1.15.8 +ARG BASE_BUILDER_IMAGE=temporalio/base-builder:1.14.11 FROM ${BASE_BUILDER_IMAGE} AS server-builder