diff --git a/.github/workflows/.trivyignore b/.github/workflows/.trivyignore index e69de29..e74d4f0 100644 --- a/.github/workflows/.trivyignore +++ b/.github/workflows/.trivyignore @@ -0,0 +1,4 @@ +# Date: Feb 12, 2024 +# Notes: Issue with libexpat, parsing large tokens can trigger a denial of service +# Needs to be fixed in Docker Image. +CVE-2023-52425 \ No newline at end of file diff --git a/Dockerfile b/Dockerfile index 4b41849..f0e77a9 100644 --- a/Dockerfile +++ b/Dockerfile @@ -16,4 +16,4 @@ RUN true COPY --chown=java:java --from=builder application/application/ ./ USER 1000 -ENTRYPOINT ["java", "$JAVA_OPTS", "org.springframework.boot.loader.launch.JarLauncher"] +ENTRYPOINT ["java", "org.springframework.boot.loader.launch.JarLauncher"]