Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Some google-managed base images would be helpful. The last time I checked, some of the major public docker images were still shellshock-vulnerable. Pre-installed GCE tools would be helpful. Perhaps automated environment variables about region, etc.


If you have found an official Docker image that is still shellshock vulnerable, the library maintainers [1] would love to hear from you as they take that stuff quite seriously. As far as I know the entire library is fully patched.

[1] https://github.com/docker-library/official-images


As one of the maintainers in question, I'd absolutely mirror this whole statement: if any of the image upstreams have an important update available that isn't applied, we're very interested in rectifying that.


Which images are still shellshock vulnerable? Wasn't aware that was an issue if we stick to the docker-managed images.


Which?

See https://gist.github.com/voltagex/582473e3b86ee5ae4438 - I ran some tests on the three most popular (?) official base images.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: