Skip to content

Pin all base images in Dockerfiles to SHA256 digests #1188

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Aug 12, 2025
Merged

Conversation

oCHRISo
Copy link
Collaborator

@oCHRISo oCHRISo commented Jul 29, 2025

Proposed changes

pins all base images in Dockerfiles to their SHA256 digests, addressing supply chain security concerns and remediating the "containerImage not pinned by hash" Scorecard alert. This ensures that builds use immutable, verified images and reduces the risk of upstream image changes or attacks.

Checklist

Before creating a PR, run through this checklist and mark each as complete.

  • I have read the CONTRIBUTING document
  • I have run make install-tools and have attached any dependency changes to this pull request
  • If applicable, I have added tests that prove my fix is effective or that my feature works
  • If applicable, I have checked that any relevant tests pass after adding my changes
  • If applicable, I have updated any relevant documentation (README.md)
  • If applicable, I have tested my cross-platform changes on Ubuntu 22, Redhat 8, SUSE 15 and FreeBSD 13

@oCHRISo oCHRISo requested a review from a team as a code owner July 29, 2025 08:59
@oCHRISo oCHRISo changed the title Pin all base images in Dockerfiles to SHA256 digests for supply chain… Pin all base images in Dockerfiles to SHA256 digests Jul 29, 2025
@oCHRISo oCHRISo merged commit de1e010 into main Aug 12, 2025
25 checks passed
@oCHRISo oCHRISo deleted the pin-dependencies branch August 12, 2025 09:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants