Uploaded image for project: 'OpenJDK'
  1. OpenJDK
  2. OPENJDK-123

investigate why we do not run "yum update" in container builds

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • Containers.1.10.GA
    • None
    • container
    • None

      We do not run "yum update" (or "dnf update") in our container builds.
      As a result we do not pick up fixed base packages via this route. We get
      fixed packages for CVEs of severity important or higher via Freshmaker
      rebuilds. But lower severity fixes may not get picked up, e.g.
      https://errata.devel.redhat.com/advisory/45473

            jdowland@redhat.com Jonathan Dowland
            jdowland@redhat.com Jonathan Dowland
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: