Comments (2)
Yeah we don't do a great job of adding build information to the image. Perhaps we should add some labels into the image so you can just trace it back to the source?
tldr: the answer appears to be: 2.36-9+deb12u4
You can inspect the image to find the libc version, if you have a tool to do that, the distroless specific info file has the debian control info:
/var/lib/dpkg/status.d/libc6
Also, there are sboms published with images. For instance your image you can find the libc6 version (in my test, we got some repetition here, I'm not sure if we need to modify our sbom generation a bit, but the data is there:
$ cosign download attestation gcr.io/distroless/base-nossl-debian12:nonroot@sha256:51ab103bb161fdf8fee4c6311a2d41f484effc409d4f4c58342ab68b2da7ccc2 | jq -rcs '.[0].payload' | base64 -d | jq -r '.predicate' | jq -r '.packages.[] | select(.name == "libc6") | .versionInfo'
from distroless.
Thanks @loosebazooka. I am able to extract the version using above command.
from distroless.
Related Issues (20)
- Extend Java 11 EOL date HOT 5
- Upgrade busybox to 1.36.1 to fix CVE-2022-30065 and CVE-2022-28391 HOT 1
- Snapshot updates fails more frequently than before
- Feature Request: Python Version Tags
- Verify by key fails but verify by hashivault is success
- CVE-2023-5678 HOT 4
- Upgrade OpenSSL to 3.0.122 to fix CVE-2023-5678 HOT 1
- Using distroless with jib? HOT 1
- zlib1g - CVE-2023-45853 HOT 1
- Misleading claim in README.md? HOT 2
- nodejs build doesn't run since March HOT 2
- Update jetty version to jetty-distribution-9.4.53.v20231009 HOT 2
- Periodic Vulnerability Reports in java
- Golang mime.TypeByExtension(".tif") Returns Empty in Debian 12 Distroless Images HOT 1
- libc6 CVE patches - CVE-2023-6246 and CVE-2023-6779 HOT 4
- openjdk-17 CVE patches - CVE-2024-20918, CVE-2024-20932 and CVE-2024-20952 HOT 3
- How to add msttcorefonts to the image HOT 4
- CVE-2023-52425 HOT 2
- MODULE_NOT_FOUND when starting any node application based on latest distroless images HOT 6
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from distroless.