From 118dd684d8b09b772a7a88a376b8cf82a56da17d Mon Sep 17 00:00:00 2001 From: spwoodcock Date: Fri, 5 Jul 2024 00:07:50 +0100 Subject: [PATCH] build: upgrade rclone --> v1 pin to avoid CVE-2024-24790 --- odkcentral/ui/Dockerfile | 2 +- src/frontend/prod.dockerfile | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/odkcentral/ui/Dockerfile b/odkcentral/ui/Dockerfile index fc9d80af5b..c164735b35 100644 --- a/odkcentral/ui/Dockerfile +++ b/odkcentral/ui/Dockerfile @@ -35,7 +35,7 @@ RUN VUE_APP_OIDC_ENABLED="false" npm run build -FROM docker.io/rclone/rclone:1.64 as prod +FROM docker.io/rclone/rclone:1 as prod VOLUME /frontend COPY container-entrypoint.sh / RUN chmod +x /container-entrypoint.sh diff --git a/src/frontend/prod.dockerfile b/src/frontend/prod.dockerfile index c0cc092adb..4eacb66678 100644 --- a/src/frontend/prod.dockerfile +++ b/src/frontend/prod.dockerfile @@ -17,7 +17,7 @@ RUN pnpm run build --mode ${NODE_ENV} -FROM docker.io/rclone/rclone:1.64 as prod +FROM docker.io/rclone/rclone:1 as prod ARG APP_VERSION ARG COMMIT_REF ARG VITE_API_URL