docker-library / docker-library/python

CVE-2025-29087 sqlite

Open
#1,036 4 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Dockerfile
Stars
2.8k
Forks
1.1k
Avg merge
3d 1h
Merged PRs (30d)
1

Description

https://avd.aquasec.com/nvd/2025/cve-2025-29087/

https://hub.docker.com/layers/library/python/alpine3.21/images/sha256-97ddd224af57478df8d36e0636b2a117174f7237dbf230bb181a33e7a36ad654

python:alpine3.21 has a vulnerable sqlite package installed, and was wondering if someone could update it and maybe look into other vulnerabilities that is listed in docker hub?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the CVE-2025-29087 advisory and the linked python:alpine3.21 Docker Hub image, then identify how the installed sqlite package is supplied. Review the other vulnerabilities listed for that image as requested. Done means the relevant image is updated and the reported sqlite vulnerability is no longer present.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, python, sqlite
Domain
devops, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.