From e507c781581df6ff7844de0e0c327eb39bdfff94 Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 04:08:12 +0000 Subject: [PATCH] fix(security): pin ghcr.io/astral-sh/uv version in Dockerfile Pin ghcr.io/astral-sh/uv image copy in Dockerfile to explicit version 0.10.8 to mitigate supply chain and tag-spoofing risks from using unpinned :latest tags. --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 9e516b6..89ee091 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,8 +1,8 @@ # Stage 1: Build stage FROM python:3.14-alpine AS build -# Install uv -COPY --from=ghcr.io/astral-sh/uv:latest /uv /uvx /bin/ +# Install uv (pin explicit version to mitigate supply chain and tag-spoofing risks) +COPY --from=ghcr.io/astral-sh/uv:0.10.8 /uv /uvx /bin/ # Enable bytecode compilation for faster startup ENV UV_COMPILE_BYTECODE=1