From 7dbd100f26e81c4475e5b872585ebd064217af78 Mon Sep 17 00:00:00 2001 From: Madhava Jay Date: Wed, 19 Jul 2023 11:28:59 +1000 Subject: [PATCH 1/2] Removing insecure ldap package --- packages/grid/backend/backend.dockerfile | 3 ++- packages/grid/vpn/headscale.dockerfile | 5 +++-- packages/grid/worker/worker.dockerfile | 5 +++-- 3 files changed, 8 insertions(+), 5 deletions(-) diff --git a/packages/grid/backend/backend.dockerfile b/packages/grid/backend/backend.dockerfile index ef702334a43..8d2240d768b 100644 --- a/packages/grid/backend/backend.dockerfile +++ b/packages/grid/backend/backend.dockerfile @@ -56,8 +56,9 @@ RUN --mount=type=cache,target=/root/.cache \ pip uninstall ansible ansible-core -y && \ rm -rf ~/.local/lib/python3.11/site-packages/ansible_collections -# clean up +# security patches RUN apt purge --auto-remove linux-libc-dev -y +RUN apt purge --auto-remove libldap-2.5-0 -y # copy any changed source COPY syft/src /app/syft/src diff --git a/packages/grid/vpn/headscale.dockerfile b/packages/grid/vpn/headscale.dockerfile index 336e532d919..3b6e007a752 100644 --- a/packages/grid/vpn/headscale.dockerfile +++ b/packages/grid/vpn/headscale.dockerfile @@ -44,7 +44,8 @@ RUN mkdir -p /headscale/data ENV NETWORK_NAME="omnet" -# clean up -RUN apt purge --auto-remove linux-libc-dev -y +# security patches +RUN apt purge --auto-remove linux-libc-dev -y || true +RUN apt purge --auto-remove libldap-2.5-0 -y || true CMD ["sh", "-c", "/headscale/headscale.sh ${NETWORK_NAME}"] diff --git a/packages/grid/worker/worker.dockerfile b/packages/grid/worker/worker.dockerfile index bd3730cedc2..afbf5a6ff4d 100644 --- a/packages/grid/worker/worker.dockerfile +++ b/packages/grid/worker/worker.dockerfile @@ -58,8 +58,9 @@ RUN --mount=type=cache,target=/root/.cache \ pip uninstall ansible ansible-core -y && \ rm -rf ~/.local/lib/python3.11/site-packages/ansible_collections -# clean up -RUN apt purge --auto-remove linux-libc-dev -y +# security patches +RUN apt purge --auto-remove linux-libc-dev -y || true +RUN apt purge --auto-remove libldap-2.5-0 -y || true # copy any changed source COPY syft/src /app/syft/src From c2e72b745cf1becc1be301e9fe0793dcdcd4db49 Mon Sep 17 00:00:00 2001 From: Madhava Jay Date: Wed, 19 Jul 2023 11:33:34 +1000 Subject: [PATCH 2/2] Forgot change for backend --- packages/grid/backend/backend.dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/packages/grid/backend/backend.dockerfile b/packages/grid/backend/backend.dockerfile index 8d2240d768b..778c21cba35 100644 --- a/packages/grid/backend/backend.dockerfile +++ b/packages/grid/backend/backend.dockerfile @@ -57,8 +57,8 @@ RUN --mount=type=cache,target=/root/.cache \ rm -rf ~/.local/lib/python3.11/site-packages/ansible_collections # security patches -RUN apt purge --auto-remove linux-libc-dev -y -RUN apt purge --auto-remove libldap-2.5-0 -y +RUN apt purge --auto-remove linux-libc-dev -y || true +RUN apt purge --auto-remove libldap-2.5-0 -y || true # copy any changed source COPY syft/src /app/syft/src