eikek / eikek/sharry

Update eikek0/sharry:v1.15.0 to fix vulnerabilities

Open
#1,797 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Elm
Stars
1.3k
Forks
72
Avg merge
21h 30m
Merged PRs (30d)
1

Description

Hello,

We are using base image provide by sharry (eikek0/sharry:v1.15.0) to build our own image. Everything works fine as expected, but we noticed some vulnerabilities reported by our Snyk security scan results. All seems to be originated from mentioned base image. Is there a possibility to update recommended versions and release new image for the fixes? For your reference, I am adding some of reported vulnerabilities below:

Vulnerability 1: [CVE-2026-21932](https://www.cve.org/CVERecord?id=CVE-2026-21932)
Introduced through: openjdk17/openjdk17-jre@17.0.14_p7-r0, openjdk17/openjdk17-jmods@17.0.14_p7-r0 and others
Fixed in: openjdk17/openjdk17-jre@17.0.18_p8-r0, @17.0.18_p8-r0

Vulnerability 2: [CVE-2026-25646](https://www.cve.org/CVERecord?id=CVE-2026-25646)
Introduced through: libpng/libpng@1.6.44-r0, freetype/freetype@2.13.3-r0 and others
Fixed in: libpng/libpng@1.6.55-r0, @1.6.55-r0

Vulnerability 3: [CVE-2025-69421](https://www.cve.org/CVERecord?id=CVE-2025-69421)
Introduced through: openssl/libssl3@3.3.3-r0, openssl/libcrypto3@3.3.3-r0 and others
Fixed in: openssl/libssl3@3.3.6-r0, @3.3.6-r0

Contributor guide

Open the contributing guide

Research direction

The issue names only the eikek0/sharry:v1.15.0 base image and three CVEs; no repository file or test is identified. Start by locating the image build or release configuration, compare the listed OpenJDK, libpng, freetype, and OpenSSL fixed versions, and rebuild the image. Done means a newly released recommended image no longer contains the reported vulnerable versions.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker
Domain
devops, infrastructure, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.