Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[🚀 Feature]: Update ubuntu:focal-20230301 to the latest version to resolve security vunerabilities #1955

Closed
imtheish97 opened this issue Sep 28, 2023 · 6 comments

Comments

@imtheish97
Copy link
Contributor

Feature and motivation

“ubuntu:focal-20230301” is nearly 7 months old (1st March) there is a more recent replacement “focal-20230801” (from 1st Aug). There have also been a number of images released since focal-20230301, prior to focal-20230801:
• focal-20230308 (6 months old)
• focal-20230412 (5 months old)
• focal-20230605 (3 months old)
• focal-20230624 (3 months old)

Usage example

Selenium’s base Dockerfile should be updated to use the newer ubuntu “focal” releases, or even moving to a newer version of Ubuntu (Focal = 20.04, Jammy = 22.04, Lunar = 23.04).
Moving to focal-20230801 (1st Aug) will resolve:
• ncurses-bin (high)
• libncursed6 (high)
• libncursesw6 (high)
• libtinfo6 (high)
• ncurses-base (high)

@github-actions
Copy link

@imtheish97, thank you for creating this issue. We will troubleshoot it as soon as we can.


Info for maintainers

Triage this issue by using labels.

If information is missing, add a helpful comment and then I-issue-template label.

If the issue is a question, add the I-question label.

If the issue is valid but there is no time to troubleshoot it, consider adding the help wanted label.

If the issue requires changes or fixes from an external project (e.g., ChromeDriver, GeckoDriver, MSEdgeDriver, W3C), add the applicable G-* label, and it will provide the correct link and auto-close the issue.

After troubleshooting the issue, please add the R-awaiting answer label.

Thank you!

@diemol
Copy link
Member

diemol commented Sep 28, 2023

There is a PR to move to Jammy but it is blocked because Firefox is a snap package in Jammy. You are welcome to help us.

For the focal bump, could you please send a PR?

@imtheish97
Copy link
Contributor Author

There is a PR to move to Jammy but it is blocked because Firefox is a snap package in Jammy. You are welcome to help us.

For the focal bump, could you please send a PR?

no problem will make a PR thanks!

@amardeep2006
Copy link
Contributor

I added a PR few days back that patches all os packages during build. It should be already addressed. #1950

@imtheish97
Copy link
Contributor Author

created a PR here: #1962

Copy link

github-actions bot commented Dec 9, 2023

This issue has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@github-actions github-actions bot locked and limited conversation to collaborators Dec 9, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

3 participants