mirror of
https://github.com/suitenumerique/meet.git
synced 2026-10-02 07:28:36 +00:00
🔒️(agents) upgrade libpcre2-8-0 to fix CVE-2026-103111
The python:3.14.7-slim base image ships libpcre2-8-0 10.46-1~deb13u2, which is affected by CVE-2026-103111 (HIGH): an out-of-bounds write triggered by a crafted regular expression. Explicitly install libpcre2-8-0 in the base stage so apt pulls the patched 10.46-1~deb13u3 from trixie-security. All stages (builder, development, production) inherit the fix. This line can be dropped once an upstream python slim image ships the patched package.
This commit is contained in:
@@ -18,6 +18,7 @@ and this project adheres to
|
||||
- 🐛(frontend) enforce recording-mode permissions on the checkboxes
|
||||
- 🔒️(agents) fix util-linux CVEs reported by Cyberwatch
|
||||
- 🔒️(backend) fix HIGH CVEs in Django and urllib3
|
||||
- 🔒️(agents) upgrade libpcre2-8-0 to fix CVE-2026-103111
|
||||
|
||||
## [1.33.0] - 2026-09-30
|
||||
|
||||
|
||||
@@ -5,6 +5,7 @@ RUN sed -i "s|^URIs: http://|URIs: https://|" /etc/apt/sources.list.d/debian.sou
|
||||
&& apt-get update && apt-get install -y --no-install-recommends \
|
||||
libglib2.0-0 \
|
||||
libgobject-2.0-0 \
|
||||
libpcre2-8-0 \
|
||||
libssl3t64 \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
|
||||
Reference in New Issue
Block a user