3 ms·
This is not the official Alpine image, it is Glider Labs one.
by asdfe 7y ago
This is not the official Alpine image, it is Glider Labs one.
- silverwind 7y agoYeah, official alpine one looks fine $ docker run -it alpine head -1 /etc/shadow root:!::0:::::
- LukeShu 7y agoGoing through alpine:3.1 to alpine:3.9, then alpine:edge, I see that the following versions have the problem: 3.3, 3.4, 3.5, and 3.8.
- deathanatos 7y ago3.8 looks fine? » docker run --rm -ti alpine:3.8 sh -c 'cat /etc/shadow | grep root' root:!::0::::: The others you mention though, I agree, they look less than fine. Also, has anyone reported this to the official Alpine repository? (since the Talos disclosure seems to be confused; it says official but has URLs to the Glider Labs version?) Edit: Ah, so here's the relevant GitHub issue for official Alpine Linux docker: https://github.com/docker-library/official-images/pull/5516 https://github.com/docker-library/official-images/pull/5516 <=3.5 is no longer supported. Everything newer is patched.
- kamane 7y agoWhat should be done to prevent NULL password then? Like just setting a custom strong password for root user in alpine container Dockerfile ? If yes, could you share the recipe how to correctly do it?
- captn3m0 7y agoUpdate your base images
- LukeShu 7y agoYou're right, they've patched 3.8; I was hitting an older cached image that I had laying around.
- deathanatos 7y agohttps://github.com/docker-library/official-images/pull/5516 https://github.com/docker-library/official-images/pull/5516 The official image was also affected, too, it appears.