From 4383c6c9d833122cc4a8b0e63028ddcbb15e29d0 Mon Sep 17 00:00:00 2001 From: AIOSAI Date: Wed, 3 Jun 2026 11:51:32 -0700 Subject: [PATCH] security(docker): pin ubuntu:24.04 base image by digest (DPLAN-0193 step 2) --- CHANGELOG.md | 4 ++++ Dockerfile.test | 2 +- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 424b3927..decfcb13 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -94,6 +94,10 @@ and this project uses [Calendar Versioning](https://calver.org/) in the format GHSA-9hjg-9r4m-mvj7, GHSA-gc5v-m9x4-r6x2) — the oldest surfaced only because the dependency was declared without a version bound. No runtime change (the AIPass venv already ran a fixed release). (DPLAN-0193) +- **Pinned the test container base image by digest** — `Dockerfile.test` now pins + `ubuntu:24.04` to its registry digest (`sha256:786a8b55…`) so the test image is + reproducible and tamper-evident, clearing the Scorecard `containerImage not + pinned by hash` finding. (DPLAN-0193) --- diff --git a/Dockerfile.test b/Dockerfile.test index 445e0847..3cd9753f 100644 --- a/Dockerfile.test +++ b/Dockerfile.test @@ -1,4 +1,4 @@ -FROM ubuntu:24.04 +FROM ubuntu:24.04@sha256:786a8b558f7be160c6c8c4a54f9a57274f3b4fb1491cf65146521ae77ff1dc54 ENV DEBIAN_FRONTEND=noninteractive