From fcf47d49147543665d4906afdf90a34451371816 Mon Sep 17 00:00:00 2001 From: Gian Miguel Del Mundo Date: Thu, 2 Oct 2025 15:51:16 +0800 Subject: [PATCH 1/2] Updated Eclipse Temurin image for CVE-2025-6965 --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 562d78f..6992c2e 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ -# sha from https://hub.docker.com/layers/amd64/eclipse-temurin/21.0.7_6-jre-alpine-3.21/images/sha256-62fa775039897e4420368514ba6c167741f6d45a0de9ff9125bee57e5aca8b75 -FROM eclipse-temurin@sha256:62fa775039897e4420368514ba6c167741f6d45a0de9ff9125bee57e5aca8b75 +# sha from https://hub.docker.com/layers/library/eclipse-temurin/21.0.8_9-jre-alpine-3.22/images/sha256-3408c45e1faee20e4e68808939a75f87efa469b927d20e12309689ead053daba +FROM eclipse-temurin@sha256:4ca7eff3ab0ef9b41f5fefa35efaeda9ed8d26e161e1192473b24b3a6c348aef WORKDIR /app EXPOSE 8088 From 51891d96fa6fb8fb7b05e234c797536b56a93fd5 Mon Sep 17 00:00:00 2001 From: Gian Miguel Del Mundo Date: Thu, 2 Oct 2025 15:51:29 +0800 Subject: [PATCH 2/2] Added CVE-2025-55163 to .trivyignore --- .trivyignore | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.trivyignore b/.trivyignore index 5a128a7..8e88307 100644 --- a/.trivyignore +++ b/.trivyignore @@ -2,8 +2,8 @@ # See https://aquasecurity.github.io/trivy/v0.35/docs/vulnerability/examples/filter/ # for more details -# UID2-5864 -CVE-2025-6965 exp:2025-10-01 - # UID2-6097 CVE-2025-59375 exp:2025-12-15 + +# UID2-6128 +CVE-2025-55163 exp:2025-10-30