-
Notifications
You must be signed in to change notification settings - Fork 1.1k
CVE-2025-29087 sqlite #1036
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. Weβll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Looking at the latest version of the (tag-specific links to Docker Hub aren't always the most reliable thing π) |
the vulnerability we care most about is the one in the aqua database. We run scans using other tools in our pipelines for vulnerabilities and it flagged the sqlite package as having this vulnerability, you can see in the first link in my comment, if the package is between version 3.44.0 (including) and 3.49.1 (excluding) then it is exposed to that vulnerability. I was wondering if you could look into changing the version on the sql package? it would help us greatly as we cant make any releases with high or critical vulnerabilities in our used images. |
as for the url thing, yeah it seems to be a bit weird, the url you provided showed no vulnerabilities, and a different version of the sql package, still within that span i mentioned, but not the same either. |
Background:
Official Images FAQ:
To ensure that we don't push contentless image changes, we rely on periodic base image updates.
The fixed version of SQLite for Alpine 3.21 is I don't see how this vulnerability is a major security concern that warrants an immediate, labor-intensive rebuild as it is only when using the π¨ If users need updated packages sooner, then they should |
https://avd.aquasec.com/nvd/2025/cve-2025-29087/
https://hub.docker.com/layers/library/python/alpine3.21/images/sha256-97ddd224af57478df8d36e0636b2a117174f7237dbf230bb181a33e7a36ad654
python:alpine3.21 has a vulnerable sqlite package installed, and was wondering if someone could update it and maybe look into other vulnerabilities that is listed in docker hub?
The text was updated successfully, but these errors were encountered: