Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Odoo 16/15: Plans on upgrading to bookworm to fix Docker image vulnerabilities? #515

Open
Pexers opened this issue Aug 9, 2024 · 3 comments

Comments

@Pexers
Copy link

Pexers commented Aug 9, 2024

Plans on upgrading to bookworm to fix Docker image vulnerabilities?

There are multiple vulnerabilities identified within DockerHub that would be fixed by an upgrade from bullseye-slim to bookworm-slim for versions 15 & 16. One of these is PyYAML, where vulnerabilities can be found in versions below 5.4.

Is this something planned to be worked on in the near future? Thank you.

@sconetto
Copy link

sconetto commented Aug 9, 2024

up 👍🏻

@otahmasebi
Copy link

up 👍

@hertell
Copy link

hertell commented Sep 8, 2024

For odoo 15 it won't work. The required version of wkhtmltopdf for odoo15 seems to be version 0.12.5-1 (https://github.com/odoo/odoo/wiki/Wkhtmltopdf), and that version has no package for bookworm.

For odoo16 it's just to replace the all words of bullseye -> bookworm, and update the sha1-sums for the corresponding package files.. If the Odoo-devs can confirm that odoo15 works a newer version of Wkhtmltopdf, then it is an easy task to update the Dockerfile to bookworm.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants