security: upgrade some package versions
This commit is contained in:
@@ -21,6 +21,10 @@ RUN apt-get update && apt-get upgrade -y && apt-get install -y --no-install-reco
|
||||
libpq5 \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# Patch system-level wheel (CVE-2026-24049) + setuptools-vendored jaraco.context
|
||||
# (CVE-2026-23949) that Trivy flags in /usr/local site-packages.
|
||||
RUN pip install --no-cache-dir --upgrade pip setuptools wheel
|
||||
|
||||
RUN groupadd --gid 1000 appgroup && \
|
||||
useradd --uid 1000 --gid appgroup --shell /bin/bash --create-home appuser
|
||||
|
||||
|
||||
Reference in New Issue
Block a user