diff --git a/Dockerfile b/Dockerfile index 09d1a694ba7714ca49031986b078e5409c85bf21..3001866e09d0a9029256c93aa545ca5c2378dddf 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,7 +2,7 @@ ARG BASE_REGISTRY=registry1.dso.mil ARG BASE_IMAGE=ironbank/redhat/ubi/ubi8 ARG BASE_TAG=8.4 -FROM quay.io/coreos/clair:v4.2.1 as base +FROM quay.io/coreos/clair:v4.2.2 as base FROM ${BASE_REGISTRY}/${BASE_IMAGE}:${BASE_TAG} as build diff --git a/hardening_manifest.yaml b/hardening_manifest.yaml index 1c43da086dd8a1133cd26686cde3de2128954839..c82550fcd6224081ce4db4d9af55df31ea3c34d4 100644 --- a/hardening_manifest.yaml +++ b/hardening_manifest.yaml @@ -8,7 +8,7 @@ name: "opensource/quay/clair" # The most specific version should be the first tag and will be shown # on ironbank.dsop.io tags: -- "v4.2.1" +- "v4.2.2" - "latest" # Build args passed to Dockerfile ARGs @@ -27,7 +27,7 @@ labels: org.opencontainers.image.url: "https://github.com/quay/clair" # Name of the distributing entity, organization or individual org.opencontainers.image.vendor: "Red Hat" - org.opencontainers.image.version: "v4.2.1" + org.opencontainers.image.version: "v4.2.2" # Keywords to help with search (ex. "cicd,gitops,golang") mil.dso.ironbank.image.keywords: "security,scanning,container" # This value can be "opensource" or "commercial" @@ -37,8 +37,8 @@ labels: # List of resources to make available to the offline build context resources: -- tag: quay.io/coreos/clair:v4.2.1 - url: docker://quay.io/coreos/clair@sha256:3c74e585b9e3576010b745babfe94728b7bc8f94695f0d88241822bbbc1ad4fd +- tag: quay.io/coreos/clair:v4.2.2 + url: docker://quay.io/coreos/clair@sha256:e3579576665e1cdf1f59ede14d8ad93c530bdf7257a05af66276dfe8dd998e13 - filename: musl.tar.gz url: https://musl.libc.org/releases/musl-1.2.0.tar.gz validation: