fleet/changes
StepSecurity Bot fb152b9114
Pin image SHA in Dockerfiles (#10205)
## Summary

This pull request is created by [Secure
Repo](https://app.stepsecurity.io/securerepo) at the request of @zwass.
Please merge the Pull Request to incorporate the requested changes.
Please tag @zwass on your message if you have any questions related to
the PR. You can also engage with the
[StepSecurity](https://github.com/step-security) team by tagging
@step-security-bot.

## Security Fixes

### Secure Dockerfiles

Pin image tags to digests in Dockerfiles. With the Docker v2 API
release, it became possible to use digests in place of tags when pulling
images or to use them in FROM lines in Dockerfiles.

- [The Open Source Security Foundation (OpenSSF) Security
Guide](https://github.com/ossf/scorecard/blob/main/docs/checks.md#pinned-dependencies)


## Feedback
For bug reports, feature requests, and general feedback; please create
an issue in
[step-security/secure-repo](https://github.com/step-security/secure-repo).
To create such PRs, please visit https://app.stepsecurity.io/securerepo.


Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>

---------

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: Zach Wasserman <zach@fleetdm.com>
2023-03-01 11:37:00 -08:00
..
.keep Issue 1009 calculate diff software (#1305) 2021-07-08 13:57:43 -03:00
9921-cis-win-10-2.3.10.x CIS - WIN10 - 2.3.10.X policies (#10178) 2023-03-01 10:28:45 -05:00
10104-policy-tab-click-bug Fleet UI: Use app context currentTeam as source of truth for teamId (#10118) 2023-02-27 11:06:18 -06:00
10137-show-query-policy-results Fleet UI: Show query button added to policy results page (#10164) 2023-02-28 12:55:56 -05:00
issue-9124-orbit-enroll-match-by-serial Support matching a host in orbit enrollment using the serial number (#9612) 2023-02-28 12:55:04 -05:00
issue-9400-add-disk-encryption-fleetctl-apply Add disk_encryption option to config and team YAML (#10185) 2023-02-28 15:34:46 -05:00
issue-10126-mdm-info Update API responses for hosts and labels endpoints to include host mdm info (#10141) 2023-02-27 18:40:34 -03:00
pin-dockerfiles Pin image SHA in Dockerfiles (#10205) 2023-03-01 11:37:00 -08:00