fix: upgrade pip in container image (CVE-2026-1703)
Path traversal in malicious wheel extraction, fixed in pip 26.0.
This commit is contained in:
@@ -1,6 +1,7 @@
|
||||
FROM python:3.13-alpine
|
||||
|
||||
RUN pip install --no-cache-dir pyyaml>=6.0
|
||||
RUN pip install --no-cache-dir --upgrade pip && \
|
||||
pip install --no-cache-dir pyyaml>=6.0
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
|
||||
Reference in New Issue
Block a user