wolfi-dev / wolfi-dev/os

[Wolfi Package Update]: ca-certificates - add java-cacerts-keystore package

Open
#78,603 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

needs-triage
Dominant language
Shell
Stars
1.3k
Forks
443
PR merge metrics
No merged PRs in 30d

Description

Package name

ca-certificates

Current version in Wolfi

20251003-r2

Requested version

20251003-r3

Upstream project URL

https://gitlab.alpinelinux.org/alpine/ca-certificates

Problem

Most container workloads don't need the update-ca-certificates infrastructure at runtime - they use immutable, pre-built certificate stores. However, the java-cacerts subpackage depends on ca-certificates, which transitively pulls in libcrypto3 via c_rehash.

For pure Java workloads that don't otherwise need OpenSSL, this unnecessarily introduces OpenSSL vulnerabilities into the image's attack surface.

Steps to reproduce

Create an apko image with openjdk-*-default-jvm and note the inclusion of the libcrypto3 package.

Root cause (if known)

openjdk-* => java-cacerts => ca-certificates => so:libcrypto.so.3 => libcrypto3

Proposed solution

Add a new java-cacerts-keystore subpackage that:

  • Provides only the static /etc/ssl/certs/java/cacerts keystore, generated from
  • Has no runtime dependencies

This allows container images to choose between:

  • java-cacerts - full functionality with update hooks (existing behavior; updated to depend on java-cacerts-keystore)
  • java-cacerts-keystore - static keystore only, no OpenSSL dependency

Ideally, the openjdk-* package dependencies would be updated from java-cacerts to java-cacerts-keystore, so dropping the default libcrypto3 dependency across the Java ecosystem.

Testing performed

No response

Acceptance criteria
  • The requested version is the latest stable upstream release (no pre-releases or RCs)
  • The upstream project uses an OSI-approved license
  • The change aligns with Wolfi’s packaging and security model
  • The package can be reasonably maintained over time
  • There are no known unresolved security or supply-chain concerns

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the ca-certificates package in the Wolfi repository and the upstream Alpine project linked in the issue, then reproduce the dependency chain with an apko image containing openjdk-*-default-jvm. Trace how the existing java-cacerts package is generated and consumed. Done means the requested static keystore package and dependency changes are defined, tested, and no longer pull libcrypto3 into a pure Java image.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
build-system, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.