Skip to content

Commit 36047a8

Browse files
committed
[ubuntu] only upgrade specific packages when CVE_UPDATES is specified
Signed-off-by: Tariq Ibrahim <tibrahim@nvidia.com>
1 parent ddec3c5 commit 36047a8

File tree

6 files changed

+6
-6
lines changed

6 files changed

+6
-6
lines changed

ubuntu22.04/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -104,7 +104,7 @@ RUN apt-get update && \
104104
# Install / upgrade packages here that are required to resolve CVEs
105105
ARG CVE_UPDATES
106106
RUN if [ -n "${CVE_UPDATES}" ]; then \
107-
apt-get update && apt-get upgrade -y ${CVE_UPDATES} && \
107+
apt-get update && apt-get --only-upgrade -y install ${CVE_UPDATES} && \
108108
rm -rf /var/lib/apt/lists/*; \
109109
fi
110110

ubuntu22.04/precompiled/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,7 @@ RUN curl -fsSL -o /usr/local/bin/donkey https://github.com/3XX0/donkey/releases/
4747
# Install / upgrade packages here that are required to resolve CVEs
4848
ARG CVE_UPDATES
4949
RUN if [ -n "${CVE_UPDATES}" ]; then \
50-
apt-get update && apt-get upgrade -y ${CVE_UPDATES} && \
50+
apt-get update && apt-get --only-upgrade -y install ${CVE_UPDATES} && \
5151
rm -rf /var/lib/apt/lists/*; \
5252
fi
5353

ubuntu24.04/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -92,7 +92,7 @@ WORKDIR /drivers
9292
# Install / upgrade packages here that are required to resolve CVEs
9393
ARG CVE_UPDATES
9494
RUN if [ -n "${CVE_UPDATES}" ]; then \
95-
apt-get update && apt-get upgrade -y ${CVE_UPDATES} && \
95+
apt-get update && apt-get --only-upgrade -y install ${CVE_UPDATES} && \
9696
rm -rf /var/lib/apt/lists/*; \
9797
fi
9898

ubuntu24.04/precompiled/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,7 @@ RUN usermod -o -u 0 -g 0 _apt
4242
# Install / upgrade packages here that are required to resolve CVEs
4343
ARG CVE_UPDATES
4444
RUN if [ -n "${CVE_UPDATES}" ]; then \
45-
apt-get update && apt-get upgrade -y ${CVE_UPDATES} && \
45+
apt-get update && apt-get --only-upgrade -y install ${CVE_UPDATES} && \
4646
rm -rf /var/lib/apt/lists/*; \
4747
fi
4848

vgpu-manager/ubuntu22.04/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ COPY nvidia-driver /usr/local/bin
4040
# Install / upgrade packages here that are required to resolve CVEs
4141
ARG CVE_UPDATES
4242
RUN if [ -n "${CVE_UPDATES}" ]; then \
43-
apt-get update && apt-get upgrade -y ${CVE_UPDATES} && \
43+
apt-get update && apt-get --only-upgrade -y install ${CVE_UPDATES} && \
4444
rm -rf /var/lib/apt/lists/*; \
4545
fi
4646

vgpu-manager/ubuntu24.04/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ RUN chmod +x /usr/local/bin/nvidia-driver
3434
# Install / upgrade packages here that are required to resolve CVEs
3535
ARG CVE_UPDATES
3636
RUN if [ -n "${CVE_UPDATES}" ]; then \
37-
apt-get update && apt-get upgrade -y ${CVE_UPDATES} && \
37+
apt-get update && apt-get --only-upgrade -y install ${CVE_UPDATES} && \
3838
rm -rf /var/lib/apt/lists/*; \
3939
fi
4040

0 commit comments

Comments
 (0)