fix: upgrade pip in container image (CVE-2026-1703)
Path traversal in malicious wheel extraction, fixed in pip 26.0.
This commit is contained in:
@@ -1,6 +1,7 @@
|
|||||||
FROM python:3.13-alpine
|
FROM python:3.13-alpine
|
||||||
|
|
||||||
RUN pip install --no-cache-dir pyyaml>=6.0
|
RUN pip install --no-cache-dir --upgrade pip && \
|
||||||
|
pip install --no-cache-dir pyyaml>=6.0
|
||||||
|
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user