From 1763311e06d4591659966c2794ade874107ab2b1 Mon Sep 17 00:00:00 2001 From: Roi Glinik Date: Wed, 23 Sep 2026 14:26:36 +0300 Subject: [PATCH] ROB-1399: upgrade base packages in runtime image to fix CVEs Run apt-get upgrade in the runner stage so Debian security fixes published after the pinned bookworm snapshot are included. Fixes CVE-2026-42010, CVE-2026-33845 (gnutls), CVE-2026-34182 (openssl) and CVE-2026-6100 (python3.11). Co-Authored-By: Claude Opus 5.5 (1M context) --- Dockerfile | 3 +++ 1 file changed, 3 insertions(+) diff --git a/Dockerfile b/Dockerfile index 32d94d9ec..d53bc5bef 100644 --- a/Dockerfile +++ b/Dockerfile @@ -79,7 +79,10 @@ ENV SLOT_NAME_SUFFIX="${SLOT_NAME_SUFFIX}" \ ECTO_IPV6="true" \ ERL_AFLAGS="-proto_dist inet6_tcp" +# Robusta: upgrade base packages so security fixes published after the +# pinned debian snapshot are included (e.g. gnutls, openssl, python3.11). RUN apt-get update -y && \ + apt-get upgrade -y --no-install-recommends && \ apt-get install -y --no-install-recommends \ libstdc++6 openssl libncurses5 locales iptables sudo tini curl awscli jq xz-utils && \ apt-get clean && rm -rf /var/lib/apt/lists/*