Skip to content

fix: move the image to a Debian 13 base - #60

Merged
sindredg merged 1 commit into
mainfrom
fix/debian-13-base
Sep 22, 2026
Merged

sindredg merged 1 commit into
mainfrom
fix/debian-13-base

Conversation

@sindredg

Copy link
Copy Markdown
Owner

Moves the base from python:3.14.7-slim-bookworm to python:3.14.7-slim-trixie, same Python, pinned by digest.

Why: k8-lab Phase 15b. The running image carries 22 OS vulnerability findings across eight packages. Seven of the eight have no fixed version in Debian 12, so rebuilding on bookworm changes nothing, and Dependabot never crosses a Debian release. Package names are left out on purpose: the image is public and still running.

Checked locally:

Check bookworm trixie
ruff check, ruff format --check pass pass
pytest app/tests 143 passed 143 passed
/health, /, /api/moon, /sky 200, 200, 400, 404 200, 200, 400, 404
Runs as uid 10001, read-only root, /etc/debian_version 13.7
zoneinfo from the tzdata package loads Europe/Oslo
linux/amd64 build builds

Not verified: whether Security Command Center closes the findings. That is read after k8-lab bumps its pin and the image is deployed.

🤖 Generated with Claude Code

Security Command Center reports 22 OS vulnerabilities in the running image,
across eight Debian 12 packages. Seven of the eight have no fixed version in
Debian 12, so a rebuild on bookworm cannot close them, and Dependabot only
moves the digest within bookworm. The trixie base carries newer versions of
all eight.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@sindredg
sindredg merged commit 92688d7 into main Sep 22, 2026
2 checks passed
@sindredg
sindredg deleted the fix/debian-13-base branch September 22, 2026 04:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant