Conversation
This image uses Wolfi instead of Debian to provide more up-to-date package versions, resulting in many fewer vulnerabilties Before: 674 vulns according to grype, 11 critical, 70 high After: 4 vulns, one high (in npm package minimatch) -- the rest not yet fixed upstream Every tool in the image got a version bump: - git 2.39 -> 2.53 - curl 7.88 -> 8.18 - gcc 12 -> 15 - python 3.11 -> 3.13 - gh 2.23 -> 2.87 Notably, gh had a critical, exploitable CVE in it which was fixed in 2.62 in Nov 2024. Aside from this, most of these updates are not highly severe or exploitable, or are not fixed upstream. This change is mainly about getting a better bill of health from scanners. Signed-off-by: Jason Hall <imjasonh@gmail.com>
imjasonh
marked this pull request as ready for review
February 22, 2026 18:48
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This image uses Wolfi instead of Debian to provide more up-to-date package versions, resulting in many fewer vulnerabilties
Before: 674 vulns according to grype, 11 critical, 70 high
After: 4 vulns, one high (in npm package minimatch) -- the rest not yet fixed upstream
Every tool in the image got a version bump:
Notably, gh had a critical, exploitable CVE in it which was fixed in 2.62 in Nov 2024.
Aside from this, most of these updates are not highly severe or exploitable, or are not fixed upstream. This change is mainly about getting a better bill of health from scanners.