Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Insecure 8.0.31 #1080

Open
nroose opened this issue Aug 19, 2024 · 1 comment
Open

Insecure 8.0.31 #1080

nroose opened this issue Aug 19, 2024 · 1 comment

Comments

@nroose
Copy link

nroose commented Aug 19, 2024

Hey, any chance you will update the 8.0.31 image? I know it's not recent. but the default Google Cloud SQL mysql version is 8.0.31, so we like to use that docker image in our CI. And it has 2 critical vulnerabilities (CVE-2022-23806 and CVE-2023-37920). Just cheaper and easier if you do it than if I do it! Thanks for all you do anyway, even if you won't!

@tianon
Copy link
Member

tianon commented Aug 20, 2024

Sorry, but unfortunately 8.0.39 is the only image we currently support / will update, and even then only until 8.0.40+ is released. 🙈

That being said, the final Dockerfile for that version is still available in our commit history: https://github.com/docker-library/mysql/blob/e0d43b2a29867c5b7d5c01a8fea30a086861df2b/8.0/Dockerfile.oracle

So you could build your own updated image from that via something like docker buildx build 'https://github.com/docker-library/mysql.git#e0d43b2a29867c5b7d5c01a8fea30a086861df2b:8.0' -f Dockerfile.oracle (which may or may not work depending on the continued availability of the artifacts it references).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants