question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

Configure autobuilds on Docker Hub (critical!)

See original GitHub issue

_Issue originally created by user bittner on date 2019-05-21 03:45:37. Link to original issue: https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/1420._

Type of Issue

Security issue

Description

The Docker image owasp/modsecurity-crs provided by this repository inherits from owasp/modsecurity:2.9-apache-ubuntu, however autobuilds seem not configured on Docker Hub.

This results in the CRS image being much older (“Updated 6 months ago”) than the owasp/modsecurity image (“Updated 23 days ago”). Subsequently, the Clair image scanner on Quay.io complains about a security issue of the older image that the younger doesn’t have.

Required Action

Can we please configure autobuilds on Docker Hub that depend on the parent image, so that each time the parent image is updated also a build of the CRS image is triggered? There’s an “Enable for base image” option now that can be enabed in owasp/modsecurity-crs.

Issue Analytics

  • State:closed
  • Created 3 years ago
  • Comments:16

github_iconTop GitHub Comments

1reaction
CRS-migration-botcommented, May 13, 2020

User bittner commented on date 2019-05-30 22:43:05:

The publicly accessible URL is https://hub.docker.com/r/owasp/modsecurity-crs/tags

1reaction
CRS-migration-botcommented, May 13, 2020

User csanders-git commented on date 2019-05-21 05:39:58:

10-4 thanks, will update tmrw

Read more comments on GitHub >

github_iconTop Results From Across the Web

Set up Automated Builds
When you set up automated builds (also called autobuilds), you create a list of branches and tags that you want to build into...
Read more >
No more automatic rebuilds on upstream images pushes?
With recent Docker Hub update it seems that there is no way anymore to automatically rebuild images when another image is pushed.
Read more >
Docker Hub Hack Affects 190K Accounts, with Concerning ...
Github and Bitbucket tokens for Docker autobuilds are also impacted. UPDATE. Docker Hub has confirmed that it was hacked last week; ...
Read more >
How to Choose a Container Registry: The Top 9 Picks
You can read more about the changes to the rate limits in this article, and the shift to Docker Hub auto builds here....
Read more >
Running ACS-Engine in Docker container
ACS for Kubernetes makes it simple to create, configure, ... Pull Docker image ams0/acs-engine-light-autobuild from Docker Hub; Create a ...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found