security(docker): pin ubuntu:24.04 base image by digest (DPLAN-0193 step 2)

This commit is contained in:
AIOSAI
2026-06-03 11:51:32 -07:00
parent ee78c39e80
commit 4383c6c9d8
2 changed files with 5 additions and 1 deletions
+4
View File
@@ -94,6 +94,10 @@ and this project uses [Calendar Versioning](https://calver.org/) in the format
GHSA-9hjg-9r4m-mvj7, GHSA-gc5v-m9x4-r6x2) — the oldest surfaced only because the
dependency was declared without a version bound. No runtime change (the AIPass
venv already ran a fixed release). (DPLAN-0193)
- **Pinned the test container base image by digest** — `Dockerfile.test` now pins
`ubuntu:24.04` to its registry digest (`sha256:786a8b55…`) so the test image is
reproducible and tamper-evident, clearing the Scorecard `containerImage not
pinned by hash` finding. (DPLAN-0193)
---
+1 -1
View File
@@ -1,4 +1,4 @@
FROM ubuntu:24.04
FROM ubuntu:24.04@sha256:786a8b558f7be160c6c8c4a54f9a57274f3b4fb1491cf65146521ae77ff1dc54
ENV DEBIAN_FRONTEND=noninteractive