Details
Description
The Black Duck scans need to know what released version of Server that the couchbase-operator-backup builds are based on. It used to extract this from the FROM line of the Dockerfile, but that was changed to a SHA some time ago. I'd prefer it if that were changed back, but failing that, we need a statement in the source code that is 100% guaranteed to be the Server version that is in use. (ie, just sticking it in a .txt somewhere is not, I think, sufficient, since that could be easily overlooked when updating the Dockerfile.)
Attachments
Issue Links
- mentioned in
-
Page Loading...