This is an automated email from the ASF dual-hosted git repository.

tballison pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tika.git


The following commit(s) were added to refs/heads/main by this push:
     new e334af1751 TIKA-4926 (#3248)
e334af1751 is described below

commit e334af1751a0edafe8d96edee9bfe33b8a25770f
Author: Tim Allison <[email protected]>
AuthorDate: Thu Sep 24 14:53:49 2026 -0400

    TIKA-4926 (#3248)
---
 .devcontainer/Dockerfile                                   |  2 +-
 .github/dependabot.yml                                     |  9 +++++++++
 .../ROOT/pages/maintainers/release-guides/docker.adoc      | 14 +++++++++-----
 tika-grpc/docker-build/Dockerfile                          |  2 +-
 tika-server/docker-build/full/Dockerfile                   |  2 +-
 tika-server/docker-build/full/Dockerfile.snapshot          |  2 +-
 tika-server/docker-build/minimal/Dockerfile                |  2 +-
 tika-server/docker-build/minimal/Dockerfile.snapshot       |  2 +-
 8 files changed, 24 insertions(+), 11 deletions(-)

diff --git a/.devcontainer/Dockerfile b/.devcontainer/Dockerfile
index 87fc72d64e..4057a63c39 100644
--- a/.devcontainer/Dockerfile
+++ b/.devcontainer/Dockerfile
@@ -15,7 +15,7 @@
 
 # Vendor-neutral dev environment: Docker-official Temurin JDK matching
 # tika-parent's maven.compiler.release. Maven comes from ./mvnw.
-FROM eclipse-temurin:17-jdk
+FROM 
eclipse-temurin:17-jdk@sha256:bc033b57e11b773c3043babfd664e7a5ef110805548b921cbfc3e8c67a0725d6
 
 RUN apt-get update \
     && apt-get install -y --no-install-recommends git \
diff --git a/.github/dependabot.yml b/.github/dependabot.yml
index adf7706707..7c1f3786d0 100644
--- a/.github/dependabot.yml
+++ b/.github/dependabot.yml
@@ -32,3 +32,12 @@ updates:
       directory: "/"
       schedule:
           interval: "weekly"
+
+    - package-ecosystem: "docker"
+      directories:
+          - "/.devcontainer"
+          - "/tika-grpc/docker-build"
+          - "/tika-server/docker-build/full"
+          - "/tika-server/docker-build/minimal"
+      schedule:
+          interval: "weekly"
diff --git a/docs/modules/ROOT/pages/maintainers/release-guides/docker.adoc 
b/docs/modules/ROOT/pages/maintainers/release-guides/docker.adoc
index 2b16d23a31..3b92c730da 100644
--- a/docs/modules/ROOT/pages/maintainers/release-guides/docker.adoc
+++ b/docs/modules/ROOT/pages/maintainers/release-guides/docker.adoc
@@ -183,8 +183,12 @@ The Tika git tag (e.g. `4.0.0`) stays put. The `-<N>` 
suffix in
 hand. The workflow auto-creates a `4.0.0-2` git tag at the same SHA it built
 from for provenance.
 
-*Case 1: pure base-image refresh* (no Dockerfile changes — `FROM 
ubuntu:resolute`
-just picks up newer upstream layers).
+The base images are pinned by digest (`FROM ubuntu:resolute@sha256:...`), and
+dependabot opens a PR each week when an upstream image is rebuilt. A rebuild
+at the original tag therefore reuses the base image that tag pinned. Only the
+apt packages installed on top of it are refreshed.
+
+*Case 1: apt-package refresh only.* Rebuild at the original tag:
 
 [source,bash]
 ----
@@ -196,9 +200,9 @@ gh workflow run docker-release.yml \
 `source_ref` defaults to the `tag`, so the workflow checks out at the
 original `4.0.0` source state.
 
-*Case 2: Dockerfile changes since the original release.* Land the
-Dockerfile changes on `main` first (or on a branch). Then point the
-workflow at that ref:
+*Case 2: newer base image (a base-image CVE) or Dockerfile changes.* Land the
+change on `main` first: merge dependabot's digest bump, or the Dockerfile
+fix. Then point the workflow at that ref:
 
 [source,bash]
 ----
diff --git a/tika-grpc/docker-build/Dockerfile 
b/tika-grpc/docker-build/Dockerfile
index 629612bc68..6b82e1d7fa 100644
--- a/tika-grpc/docker-build/Dockerfile
+++ b/tika-grpc/docker-build/Dockerfile
@@ -15,7 +15,7 @@
 # the subsequent stages -- see TIKA-3912
 ARG UID_GID="35002:35002"
 
-FROM ubuntu:noble
+FROM 
ubuntu:resolute@sha256:da6fc2be547864451aa253836dd926da33623312df4a9a243e35dc877c378a78
 
 ARG UID_GID
 COPY libs/ /tika/libs/
diff --git a/tika-server/docker-build/full/Dockerfile 
b/tika-server/docker-build/full/Dockerfile
index caff173fc4..e34d4e576d 100644
--- a/tika-server/docker-build/full/Dockerfile
+++ b/tika-server/docker-build/full/Dockerfile
@@ -15,7 +15,7 @@
 # the subsequent stages -- see TIKA-3912
 ARG UID_GID="35002:35002"
 
-FROM ubuntu:resolute AS base
+FROM 
ubuntu:resolute@sha256:da6fc2be547864451aa253836dd926da33623312df4a9a243e35dc877c378a78
 AS base
 
 FROM base AS fetch_tika
 
diff --git a/tika-server/docker-build/full/Dockerfile.snapshot 
b/tika-server/docker-build/full/Dockerfile.snapshot
index 4318dee335..4e48286e99 100644
--- a/tika-server/docker-build/full/Dockerfile.snapshot
+++ b/tika-server/docker-build/full/Dockerfile.snapshot
@@ -15,7 +15,7 @@
 
 ARG UID_GID="35002:35002"
 
-FROM ubuntu:resolute AS runtime
+FROM 
ubuntu:resolute@sha256:da6fc2be547864451aa253836dd926da33623312df4a9a243e35dc877c378a78
 AS runtime
 ARG UID_GID
 ARG TIKA_VERSION
 ARG JRE='openjdk-25-jre-headless'
diff --git a/tika-server/docker-build/minimal/Dockerfile 
b/tika-server/docker-build/minimal/Dockerfile
index 115554e587..c28c324c06 100644
--- a/tika-server/docker-build/minimal/Dockerfile
+++ b/tika-server/docker-build/minimal/Dockerfile
@@ -16,7 +16,7 @@
 # the subsequent stages -- see TIKA-3912
 ARG UID_GID="35002:35002"
 
-FROM ubuntu:resolute AS base
+FROM 
ubuntu:resolute@sha256:da6fc2be547864451aa253836dd926da33623312df4a9a243e35dc877c378a78
 AS base
 
 FROM base AS fetch_tika
 
diff --git a/tika-server/docker-build/minimal/Dockerfile.snapshot 
b/tika-server/docker-build/minimal/Dockerfile.snapshot
index 55eb708de7..31982444f0 100644
--- a/tika-server/docker-build/minimal/Dockerfile.snapshot
+++ b/tika-server/docker-build/minimal/Dockerfile.snapshot
@@ -15,7 +15,7 @@
 
 ARG UID_GID="35002:35002"
 
-FROM ubuntu:resolute AS runtime
+FROM 
ubuntu:resolute@sha256:da6fc2be547864451aa253836dd926da33623312df4a9a243e35dc877c378a78
 AS runtime
 ARG UID_GID
 ARG TIKA_VERSION
 ARG JRE='openjdk-25-jre-headless'

Reply via email to