Repository navigation
Conversation
Author
|
The main reason for this change is to reduce the vulnerabilities detected. Many are from binutils. Which is only needed very shortly. |
Member
|
Thanks for the PR! We've intentionally avoided installing and purging apt packages from inside the Re: vulnerabilities, if you're maintaining a derived image, what's in it is yours to manage, and it's reasonable to keep |
Author
|
@tianon Makes total sense. Thanks for your time, I'll close this one |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
On Alpine,
docker-php-ext-enablealready installsbinutilstemporarily when the phpize deps are gone (#420), soreadelfis available for thezend_extension_entrycheck. Debian has no equivalent: if a derived image removesbinutils(e.g. to drop the build toolchain from a production image),readelfis "not found", theifsilently falls through, and every module is written asextension=. For Xdebug that produces a broken config that only surfaces at runtime:This mirrors the Alpine behaviour on Debian: when
readelfis missing, installbinutilsfor the duration of the script and purge it afterwards. Images that still shipbinutils(including all of the images built here) take no new code path.Tested on
php:8.5-fpm(trixie):binutilspresent: no apt calls, output unchanged.binutilspurged:docker-php-ext-enable xdebug vips uvinstallsbinutils, writeszend_extension=xdebug/extension=vips/extension=uv, all three load, and afterwardsbinutilsis gone again and/var/lib/apt/listsis empty.binutilspurged, run as a non-root user: fails loudly (apt-getexit 100) instead of silently writing the wrong ini.