Replies: 1 comment 2 replies
-
|
jre-base subpackages were removed from Wolfi on January 14 2025 and have not been updated since. If you pin or use those package names you are not receiving any updates to those. See: To receive Java 21 with CVE SLA and support please consider purchasing https://images.chainguard.dev/directory/image/jdk/versions https://images.chainguard.dev/directory/image/jre/versions which are always up to date, provide version tags for all micro releases, and always contain correct package composition configuration. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Our security scans reveal that
Name: openjdk-21-jre-base, Version: 21.0.5-r1
CVE-2025-21502, Severity: MEDIUM, Source: https://github.com/wolfi-dev/advisories/blob/main/openjdk-21.advisories.yaml
CVSS score: 4.8, CVSS exploitability score: 2.2
🩹 Fixed version: 21.0.6-r0
The advisory says the fix version is 21.0.6-r0 but there is no such package for the base(headless) package: https://pkgs.org/search/?q=openjdk-21-jre-base
Is it possible for you guys to build a new version of the base(headless) package to fix this vulnerability, or is the base package discontinued?
Beta Was this translation helpful? Give feedback.
All reactions