diff --git a/Dockerfile b/Dockerfile index 0865fa982507dea245cd31a505e18d0525175f0f..09d1a694ba7714ca49031986b078e5409c85bf21 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,7 +2,7 @@ ARG BASE_REGISTRY=registry1.dso.mil ARG BASE_IMAGE=ironbank/redhat/ubi/ubi8 ARG BASE_TAG=8.4 -FROM quay.io/coreos/clair:v4.2.0 as base +FROM quay.io/coreos/clair:v4.2.1 as base FROM ${BASE_REGISTRY}/${BASE_IMAGE}:${BASE_TAG} as build diff --git a/hardening_manifest.yaml b/hardening_manifest.yaml index dfe0accbab0e471132e22b70f3aa87896e4bdd4c..1c43da086dd8a1133cd26686cde3de2128954839 100644 --- a/hardening_manifest.yaml +++ b/hardening_manifest.yaml @@ -8,7 +8,7 @@ name: "opensource/quay/clair" # The most specific version should be the first tag and will be shown # on ironbank.dsop.io tags: -- "v4.2.0" +- "v4.2.1" - "latest" # Build args passed to Dockerfile ARGs @@ -27,7 +27,7 @@ labels: org.opencontainers.image.url: "https://github.com/quay/clair" # Name of the distributing entity, organization or individual org.opencontainers.image.vendor: "Red Hat" - org.opencontainers.image.version: "v4.2.0" + org.opencontainers.image.version: "v4.2.1" # Keywords to help with search (ex. "cicd,gitops,golang") mil.dso.ironbank.image.keywords: "security,scanning,container" # This value can be "opensource" or "commercial" @@ -37,8 +37,8 @@ labels: # List of resources to make available to the offline build context resources: -- tag: quay.io/coreos/clair:v4.2.0 - url: docker://quay.io/coreos/clair@sha256:9c1b84b56dd48a3b174342d9ce3929dd4992a6eb62029500fc444c28afef352a +- tag: quay.io/coreos/clair:v4.2.1 + url: docker://quay.io/coreos/clair@sha256:3c74e585b9e3576010b745babfe94728b7bc8f94695f0d88241822bbbc1ad4fd - filename: musl.tar.gz url: https://musl.libc.org/releases/musl-1.2.0.tar.gz validation: