Description
Possibly as a result of #389, the latest Alpine image tags light up significantly worse than earlier tags when scanned for vulnerabilities. Part of the reason our organization prefers Alpine based images is for its minimal attack surface; the apparent regression is increasing friction for us to adopt the newer builds.
Are additional components really needed in the redis Alpine image? If not, can they be removed again to clean up the scan results?
See for example: https://hub.docker.com/_/redis/tags?page=1&name=7.2.3-alpine3
Metadata
Metadata
Assignees
Labels
No labels