зеркало из
1
0
Форкнуть 0
Signed-off-by: Anish Ramasekar <anish.ramasekar@gmail.com>
This commit is contained in:
Anish Ramasekar 2022-09-12 17:29:55 +00:00
Родитель 90fdd63229
Коммит 174a043fcb
1 изменённых файлов: 3 добавлений и 1 удалений

Просмотреть файл

@ -3,7 +3,9 @@ ARG BASEIMAGE=k8s.gcr.io/build-image/debian-iptables:bullseye-v1.5.1
FROM --platform=${TARGETPLATFORM:-linux/amd64} ${BASEIMAGE}
# upgrading zlib1g due to CVE-2022-37434
RUN clean-install ca-certificates zlib1g
# upgrading libc-bin and libc6 due to CVE-2021-3999
# upgrading libpcre2-8-0 due to CVE-2022-1586, CVE-2022-1587
RUN clean-install ca-certificates zlib1g libc-bin libc6 libpcre2-8-0
COPY ./init/init-iptables.sh /bin/
RUN chmod +x /bin/init-iptables.sh
# Kubernetes runAsNonRoot requires USER to be numeric