Internal
Public Access
Upgrade pip during Docker build to fix CVE-2025-8869
Added pip upgrade step in Dockerfile builder stage to ensure latest pip version is used. This fixes CVE-2025-8869 vulnerability found in pip 25.0.1 (fixed in 25.3). pip-audit output before fix: Found 1 known vulnerability in 1 package Name Version ID Fix Versions pip 25.0.1 CVE-2025-8869 25.3 After rebuilding, pip will be upgraded to 25.3+ which resolves the security vulnerability. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.5
parent
de57befe3a
commit
4a6b9a991f
@@ -11,6 +11,9 @@ RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||
zlib1g-dev \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# Upgrade pip to latest version (security)
|
||||
RUN pip install --upgrade pip
|
||||
|
||||
# Install Python dependencies
|
||||
COPY requirements.txt /tmp/
|
||||
RUN pip install --user --no-cache-dir -r /tmp/requirements.txt \
|
||||
|
||||
Reference in New Issue
Block a user