Configure autobuilds on Docker Hub (critical!)
See original GitHub issue_Issue originally created by user bittner on date 2019-05-21 03:45:37. Link to original issue: https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/1420._
Type of Issue
Security issue
Description
The Docker image owasp/modsecurity-crs provided by this repository inherits from owasp/modsecurity:2.9-apache-ubuntu
, however autobuilds seem not configured on Docker Hub.
This results in the CRS image being much older (“Updated 6 months ago”) than the owasp/modsecurity image (“Updated 23 days ago”). Subsequently, the Clair image scanner on Quay.io complains about a security issue of the older image that the younger doesn’t have.
Required Action
Can we please configure autobuilds on Docker Hub that depend on the parent image, so that each time the parent image is updated also a build of the CRS image is triggered? There’s an “Enable for base image” option now that can be enabed in owasp/modsecurity-crs.
Issue Analytics
- State:
- Created 3 years ago
- Comments:16
Top GitHub Comments
User bittner commented on date 2019-05-30 22:43:05:
The publicly accessible URL is https://hub.docker.com/r/owasp/modsecurity-crs/tags
User csanders-git commented on date 2019-05-21 05:39:58:
10-4 thanks, will update tmrw