fix(rds): apt-get upgrade base packages to clear stale CVE patches#824
Merged
vieiralucas merged 1 commit intomainfrom Apr 28, 2026
Merged
fix(rds): apt-get upgrade base packages to clear stale CVE patches#824vieiralucas merged 1 commit intomainfrom
vieiralucas merged 1 commit intomainfrom
Conversation
The first post-fix supply-chain validation showed only postgres:13 flagged 35 (HIGH+CRITICAL) Trivy findings — openssl 3.5.1, glibc 2.41-12, dirmngr — all of which already have patched versions on the same Debian 13 release. The upstream `postgres:<major>` tags sometimes lag by a security DB cycle, so we run `apt-get upgrade` during image build to pull the patched packages directly. Apply the same to mysql + mariadb so future stale upstream releases do not block the next supply-chain validation.
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
postgres:<major>tag refresh cadence can lag the security DB by a cycle, so an in-buildapt-get upgradepulls the patched packages directly instead of waiting on Docker Inc to re-publish.Test plan
workflow_dispatchonRDS support images, confirm all 8 scans exit 0Summary by cubic
Run
apt-get upgradein RDS base Dockerfiles to pull patched Debian packages and clear stale CVE findings. Fixes Trivy HIGH/CRITICAL issues onpostgres:13and prevents future drift formysqlandmariadb.apt-get upgrade -y --no-install-recommendsbefore installs inpostgres,mysql, andmariadbDockerfiles.postgres:13(openssl 3.5.1,glibc 2.41-12,dirmngr 2.4.7-21+b3) by pulling Debian 13 patched packages at build time.Written for commit 2c78144. Summary will update on new commits. Review in cubic