UNCLASSIFIED - NO CUI

Skip to content

Update Ubuntu base from AWS ECR

Tomáš Virtus requested to merge virtustom-for-development into development

Use the latest published Ubuntu image from AWS ECR (serial 20220404) as base image. The latest image has packages patched for CVE-2018-25032 and CVE-2022-0778. Canonical has direct control over images published to AWS ECR as opposed to Docker Hub official images which has to go through PR to https://github.com/docker-library/official-images/.

Note that there's one False Positive VAT finding that I've just submitted for justification. Other findings are still in Reviewed state.

This MR still applies to the initial Onboarding issue #1 (closed) .

Edited by Tomáš Virtus

Merge request reports