Skip to content

Update base image in Dockerfile to nonroot version#385

Merged
mathieu-benoit merged 2 commits intomainfrom
nonroot-dockerfile
Dec 5, 2025
Merged

Update base image in Dockerfile to nonroot version#385
mathieu-benoit merged 2 commits intomainfrom
nonroot-dockerfile

Conversation

@mathieu-benoit
Copy link
Copy Markdown
Contributor

@mathieu-benoit mathieu-benoit commented Dec 4, 2025

Update base image in Dockerfile to nonroot version

We are also fixing the pinned version, stuck from Jan 2025 because was not done properly since then: #231, that's why we see these changes too:

♾️ | base-files | 12.4+deb12u8 | 12.4+deb12u12
➕ | media-types |   | 10.0.0
♾️ | tzdata | 2024b-0+deb12u1 | 2025b-0+deb12u2

Signed-off-by: Mathieu Benoit <mathieu-benoit@hotmail.fr>
@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Dec 4, 2025

Overview

Image reference score-compose:latest score-compose:latest
- digest ce6fe9df8293 f9907f52de23
- tag latest latest
- provenance 6f8022a 1b284c2
- vulnerabilities critical: 0 high: 0 medium: 0 low: 0 critical: 0 high: 0 medium: 0 low: 0
- platform linux/amd64 linux/amd64
- size 6.3 MB 6.3 MB (+35 kB)
- packages 53 54 (+1)
Policies (1 improved, 0 worsened)
Policy Name score-compose:latest score-compose:latest Change Standing
Default non-root user ⚠️ -1 Improved
No AGPL v3 licenses No Change
No fixable critical or high vulnerabilities No Change
No high-profile vulnerabilities No Change
No outdated base images No Change
No unapproved base images No Change
Supply chain attestations No Change
Packages and Vulnerabilities (3 package changes and 0 vulnerability changes)
  • ➕ 1 packages added
  • ♾️ 2 packages changed
  • 50 packages unchanged
Changes for packages of type deb (3 changes)
Package Version
score-compose:latest
Version
score-compose:latest
♾️ base-files 12.4+deb12u8 12.4+deb12u12
media-types 10.0.0
♾️ tzdata 2024b-0+deb12u1 2025b-0+deb12u2

Added Docker Scout comparison step and improved test directory setup.

Signed-off-by: Mathieu Benoit <mathieu-benoit@hotmail.fr>
@mathieu-benoit mathieu-benoit merged commit 8c4256e into main Dec 5, 2025
3 of 6 checks passed
@mathieu-benoit mathieu-benoit deleted the nonroot-dockerfile branch December 5, 2025 16:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant