diff --git a/Dockerfile b/Dockerfile index 6512386f0..8600ea228 100644 --- a/Dockerfile +++ b/Dockerfile @@ -117,7 +117,10 @@ RUN npm run build # Runtime stage - multi-arch base image # ============================================== # Image pinned to a SHA256 digest for reproducible builds. -FROM alpine:3.21.3@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c +# To refresh: `docker buildx imagetools inspect alpine:3.24.1` and update the +# digest below. This is the multi-arch index digest, not a per-platform one, so +# it stays correct for every TARGETARCH this image is built for. +FROM alpine:3.24.1@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b # Re-declare args for use in this stage ARG TARGETARCH diff --git a/scripts/scan-shipped-image.sh b/scripts/scan-shipped-image.sh index 7f5df9cb4..25063f40b 100755 --- a/scripts/scan-shipped-image.sh +++ b/scripts/scan-shipped-image.sh @@ -39,9 +39,11 @@ # WHAT IT DOES NOT COVER. OS package CVEs in the base image (musl, openssl, # zlib, curl). govulncheck only knows about Go modules and the Go standard # library. A Trivy scan-type: image step would cover those; it is not added -# here because the pinned alpine:3.21.3 runtime base already carries fixable -# CRITICAL/HIGH openssl, musl and zlib advisories, so such a gate would land -# red. Tracked separately. +# here, and is tracked separately. The reason it was originally deferred is +# gone: the runtime base was alpine:3.21.3, which carried fixable CRITICAL/HIGH +# openssl, musl and zlib advisories that would have landed such a gate red on +# day one. The base is now alpine:3.24.1, measured clean of fixable +# CRITICAL/HIGH OS advisories, so adding that gate is unblocked. # # Exit 0 = every Go binary found, and no advisory with a published fix. # Exit 1 = at least one fixable advisory, or the enumeration came back empty.