Update eikek0/sharry:v1.15.0 to fix vulnerabilities
- Dominant language
- Elm
- Stars
- 1.3k
- Forks
- 72
- Avg merge
- 21h 30m
- Merged PRs (30d)
- 1
Description
Hello,
We are using base image provide by sharry (eikek0/sharry:v1.15.0) to build our own image. Everything works fine as expected, but we noticed some vulnerabilities reported by our Snyk security scan results. All seems to be originated from mentioned base image. Is there a possibility to update recommended versions and release new image for the fixes? For your reference, I am adding some of reported vulnerabilities below:
Vulnerability 1: [CVE-2026-21932](https://www.cve.org/CVERecord?id=CVE-2026-21932)
Introduced through: openjdk17/openjdk17-jre@17.0.14_p7-r0, openjdk17/openjdk17-jmods@17.0.14_p7-r0 and others
Fixed in: openjdk17/openjdk17-jre@17.0.18_p8-r0, @17.0.18_p8-r0
Vulnerability 2: [CVE-2026-25646](https://www.cve.org/CVERecord?id=CVE-2026-25646)
Introduced through: libpng/libpng@1.6.44-r0, freetype/freetype@2.13.3-r0 and others
Fixed in: libpng/libpng@1.6.55-r0, @1.6.55-r0
Vulnerability 3: [CVE-2025-69421](https://www.cve.org/CVERecord?id=CVE-2025-69421)
Introduced through: openssl/libssl3@3.3.3-r0, openssl/libcrypto3@3.3.3-r0 and others
Fixed in: openssl/libssl3@3.3.6-r0, @3.3.6-r0
Contributor guide
Research direction
The issue names only the eikek0/sharry:v1.15.0 base image and three CVEs; no repository file or test is identified. Start by locating the image build or release configuration, compare the listed OpenJDK, libpng, freetype, and OpenSSL fixed versions, and rebuild the image. Done means a newly released recommended image no longer contains the reported vulnerable versions.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker
- Domain
- devops, infrastructure, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100