Repository navigation
fix(docker): keep git and openssh-client out of the runtime image - #565
Merged
Merged
Conversation
Only the dev stage needs them (docker-entrypoint writes VERSION from git outside prod; .git is not in the image, and composer installs from dist). git was the only reason libexpat was in the runtime image, which now has two CVEs (CVE-2026-102633 MEDIUM, CVE-2026-77214 HIGH) fixed only in Alpine edge. Dropping it removes both, so the .trivyignore exception for CVE-2026-102633 goes too.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Target branch:
feature/docker-master.Why
The stage image scan failed again (run 37893397774 on
5f5ff1b). Trivy now also flags CVE-2026-77214 (HIGH) inlibexpat 2.8.5-r0, next to CVE-2026-102633 (MEDIUM), which #562 ignored. Both are fixed only inlibexpat 2.9.0-r0in Alpine edge. Alpine 3.24 still ships 2.8.5-r0 (APKINDEX and the 3.24-stable APKBUILD are unchanged, and the 3.24 secdb has no entry), so the dailyapk upgradecan't fix it.gitis the only package that pullslibexpatinto the runtime image, and the runtime image doesn't need git:composer install --prefer-dist: all 177 locked packages have a dist archive, no VCS repositories.docker-entrypointonly runsgit rev-parsewhenAPP_ENV != prod, and.gitis in.dockerignore, so it can't work in a built image anyway.src/,build/,bin/,config/ordocker/calls git or ssh at runtime.Changes
Dockerfile:gitandopenssh-clientmove from the basebewelcome_phpstage tobewelcome_php_dev, which docker-compose and the devcontainer build..trivyignore: the CVE-2026-102633 exception is removed. It's no longer needed, and the file is back to header-only.This replaces a growing list of exceptions with a smaller image.
Tested
sha-c577043: every job green, including Scan image, with no exceptions.libexpat,gitandsshare absent. The PHPxml,domandsimplexmlextensions are present (they use libxml2).php,webandcronare healthy, and there are no git-related errors in the logs./,/faq,/signup,/loginand/feedbackreturn 200, and/about/faqreturns 301 (fix(seo): /about/faq is a permanent redirect, links go to /faq (sysadmins-infra#654) #564 is included).Not tested: a local build of the
bewelcome_php_devtarget. That stage only gains twoapk addpackages.