kata-deploy: Ensure the system is up-to-date

In order to avoid providing an image with security issues, let's ensure
we run `yum update` as part of our image build process.  This is needed
as even with the latest CentOS images there may be fix provided by some
CVE that's already part of the updates but not yet part of the image.

In our case, it's even more needed as the `centos/systemd` image has not
been updated for 3 years or so and those are the vulnerabilities found
in the current images:
https://quay.io/repository/kata-containers/kata-deploy?tab=tags

Fixes: #2303

Signed-off-by: Fabiano Fidêncio <fidencio@redhat.com>
This commit is contained in:
Fabiano Fidêncio 2021-08-05 19:58:24 +02:00
parent b4b843178c
commit d01aebebae

View File

@ -10,6 +10,7 @@ ARG DESTINATION=/opt/kata-artifacts
COPY ${KATA_ARTIFACTS} .
RUN \
yum -y update && \
yum install -y epel-release && \
yum install -y bzip2 jq && \
mkdir -p ${DESTINATION} && \