odoo / odoo/docker

Odoo 16/15: Plans on upgrading to bookworm to fix Docker image vulnerabilities?

Open
#515 3 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Dockerfile
Stars
1.2k
Forks
1.7k
PR merge metrics
No merged PRs in 30d

Description

Plans on upgrading to bookworm to fix Docker image vulnerabilities?

There are multiple vulnerabilities identified within DockerHub that would be fixed by an upgrade from bullseye-slim to bookworm-slim for versions 15 & 16. One of these is PyYAML, where vulnerabilities can be found in versions below 5.4.

Is this something planned to be worked on in the near future? Thank you.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No specific files or tests are named. Locate the Docker image definitions for Odoo versions 15 and 16, check where bullseye-slim is selected, and review the image build and vulnerability-scan workflow. Done means the relevant images use bookworm-slim and the reported vulnerabilities are addressed.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, dockerfile
Domain
devops, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.