Skip to content

Conversation

@aadams19
Copy link
Contributor

The golang library 1.10.3 is protected against the zip slip vulnerability.
Signed-off-by: Andrea Adams [email protected]

The golang library 1.10.3 is protected against the zip slip
vulnerability.
Signed-off-by: Andrea Adams <[email protected]>
Copy link
Member

@matrixik matrixik left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes in Dockerfile looks fine but you need to bump version in build.yml.
https://github.com/monasca/monasca-docker/blob/master/influxdb-watcher/build.yml#L5

@aadams19 aadams19 added the WIP label Jun 14, 2018
@aadams19
Copy link
Contributor Author

More invistigation is needed because go 1.9.4 is still getting installed

(20/26) Installing git (2.15.2-r0)
(21/26) Installing go (1.9.4-r0)
(22/26) Installing glide (0.13.1-r0)

@matrixik
Copy link
Member

Probably similarly like in #434 glide is installing go as a dependence.

@matrixik
Copy link
Member

@aadams19 Could you install in similar way that was done in #434 ?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants