Skip to content

Conversation

@jemsab
Copy link

@jemsab jemsab commented Nov 20, 2025

The current version of the Rust Dockerfile removes the imagemagick package from the OCI image because of CVE CVE-2019-10131.

According to Debian's security tracker https://security-tracker.debian.org/tracker/CVE-2019-10131, the vulnerability has been fixed in all Debian versions referenced in the manifest file (bullseye, bookworm and trixie). This workaround is therefore no longer necessary.

Removing the workaround will also remove a layer from the generated OCI image reducing deployment size.

The current version of the Rust Dockerfile removes the imagemagick package from the OCI image because of CVE CVE-2019-10131. 

According to Debian's security tracker https://security-tracker.debian.org/tracker/CVE-2019-10131, the vulnerability has been fixed in all Debian versions referenced in the manifest file (bullseye, bookworm and trixie). This workaround is therefore no longer necessary.

Removing the workaround will also remove a layer from the generated OCI image reducing deployment size.
@jemsab jemsab requested a review from a team as a code owner November 20, 2025 15:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant