This is an automated email from the ASF dual-hosted git repository.
tballison pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tika.git
The following commit(s) were added to refs/heads/main by this push:
new e334af1751 TIKA-4926 (#3248)
e334af1751 is described below
commit e334af1751a0edafe8d96edee9bfe33b8a25770f
Author: Tim Allison <[email protected]>
AuthorDate: Thu Sep 24 14:53:49 2026 -0400
TIKA-4926 (#3248)
---
.devcontainer/Dockerfile | 2 +-
.github/dependabot.yml | 9 +++++++++
.../ROOT/pages/maintainers/release-guides/docker.adoc | 14 +++++++++-----
tika-grpc/docker-build/Dockerfile | 2 +-
tika-server/docker-build/full/Dockerfile | 2 +-
tika-server/docker-build/full/Dockerfile.snapshot | 2 +-
tika-server/docker-build/minimal/Dockerfile | 2 +-
tika-server/docker-build/minimal/Dockerfile.snapshot | 2 +-
8 files changed, 24 insertions(+), 11 deletions(-)
diff --git a/.devcontainer/Dockerfile b/.devcontainer/Dockerfile
index 87fc72d64e..4057a63c39 100644
--- a/.devcontainer/Dockerfile
+++ b/.devcontainer/Dockerfile
@@ -15,7 +15,7 @@
# Vendor-neutral dev environment: Docker-official Temurin JDK matching
# tika-parent's maven.compiler.release. Maven comes from ./mvnw.
-FROM eclipse-temurin:17-jdk
+FROM
eclipse-temurin:17-jdk@sha256:bc033b57e11b773c3043babfd664e7a5ef110805548b921cbfc3e8c67a0725d6
RUN apt-get update \
&& apt-get install -y --no-install-recommends git \
diff --git a/.github/dependabot.yml b/.github/dependabot.yml
index adf7706707..7c1f3786d0 100644
--- a/.github/dependabot.yml
+++ b/.github/dependabot.yml
@@ -32,3 +32,12 @@ updates:
directory: "/"
schedule:
interval: "weekly"
+
+ - package-ecosystem: "docker"
+ directories:
+ - "/.devcontainer"
+ - "/tika-grpc/docker-build"
+ - "/tika-server/docker-build/full"
+ - "/tika-server/docker-build/minimal"
+ schedule:
+ interval: "weekly"
diff --git a/docs/modules/ROOT/pages/maintainers/release-guides/docker.adoc
b/docs/modules/ROOT/pages/maintainers/release-guides/docker.adoc
index 2b16d23a31..3b92c730da 100644
--- a/docs/modules/ROOT/pages/maintainers/release-guides/docker.adoc
+++ b/docs/modules/ROOT/pages/maintainers/release-guides/docker.adoc
@@ -183,8 +183,12 @@ The Tika git tag (e.g. `4.0.0`) stays put. The `-<N>`
suffix in
hand. The workflow auto-creates a `4.0.0-2` git tag at the same SHA it built
from for provenance.
-*Case 1: pure base-image refresh* (no Dockerfile changes — `FROM
ubuntu:resolute`
-just picks up newer upstream layers).
+The base images are pinned by digest (`FROM ubuntu:resolute@sha256:...`), and
+dependabot opens a PR each week when an upstream image is rebuilt. A rebuild
+at the original tag therefore reuses the base image that tag pinned. Only the
+apt packages installed on top of it are refreshed.
+
+*Case 1: apt-package refresh only.* Rebuild at the original tag:
[source,bash]
----
@@ -196,9 +200,9 @@ gh workflow run docker-release.yml \
`source_ref` defaults to the `tag`, so the workflow checks out at the
original `4.0.0` source state.
-*Case 2: Dockerfile changes since the original release.* Land the
-Dockerfile changes on `main` first (or on a branch). Then point the
-workflow at that ref:
+*Case 2: newer base image (a base-image CVE) or Dockerfile changes.* Land the
+change on `main` first: merge dependabot's digest bump, or the Dockerfile
+fix. Then point the workflow at that ref:
[source,bash]
----
diff --git a/tika-grpc/docker-build/Dockerfile
b/tika-grpc/docker-build/Dockerfile
index 629612bc68..6b82e1d7fa 100644
--- a/tika-grpc/docker-build/Dockerfile
+++ b/tika-grpc/docker-build/Dockerfile
@@ -15,7 +15,7 @@
# the subsequent stages -- see TIKA-3912
ARG UID_GID="35002:35002"
-FROM ubuntu:noble
+FROM
ubuntu:resolute@sha256:da6fc2be547864451aa253836dd926da33623312df4a9a243e35dc877c378a78
ARG UID_GID
COPY libs/ /tika/libs/
diff --git a/tika-server/docker-build/full/Dockerfile
b/tika-server/docker-build/full/Dockerfile
index caff173fc4..e34d4e576d 100644
--- a/tika-server/docker-build/full/Dockerfile
+++ b/tika-server/docker-build/full/Dockerfile
@@ -15,7 +15,7 @@
# the subsequent stages -- see TIKA-3912
ARG UID_GID="35002:35002"
-FROM ubuntu:resolute AS base
+FROM
ubuntu:resolute@sha256:da6fc2be547864451aa253836dd926da33623312df4a9a243e35dc877c378a78
AS base
FROM base AS fetch_tika
diff --git a/tika-server/docker-build/full/Dockerfile.snapshot
b/tika-server/docker-build/full/Dockerfile.snapshot
index 4318dee335..4e48286e99 100644
--- a/tika-server/docker-build/full/Dockerfile.snapshot
+++ b/tika-server/docker-build/full/Dockerfile.snapshot
@@ -15,7 +15,7 @@
ARG UID_GID="35002:35002"
-FROM ubuntu:resolute AS runtime
+FROM
ubuntu:resolute@sha256:da6fc2be547864451aa253836dd926da33623312df4a9a243e35dc877c378a78
AS runtime
ARG UID_GID
ARG TIKA_VERSION
ARG JRE='openjdk-25-jre-headless'
diff --git a/tika-server/docker-build/minimal/Dockerfile
b/tika-server/docker-build/minimal/Dockerfile
index 115554e587..c28c324c06 100644
--- a/tika-server/docker-build/minimal/Dockerfile
+++ b/tika-server/docker-build/minimal/Dockerfile
@@ -16,7 +16,7 @@
# the subsequent stages -- see TIKA-3912
ARG UID_GID="35002:35002"
-FROM ubuntu:resolute AS base
+FROM
ubuntu:resolute@sha256:da6fc2be547864451aa253836dd926da33623312df4a9a243e35dc877c378a78
AS base
FROM base AS fetch_tika
diff --git a/tika-server/docker-build/minimal/Dockerfile.snapshot
b/tika-server/docker-build/minimal/Dockerfile.snapshot
index 55eb708de7..31982444f0 100644
--- a/tika-server/docker-build/minimal/Dockerfile.snapshot
+++ b/tika-server/docker-build/minimal/Dockerfile.snapshot
@@ -15,7 +15,7 @@
ARG UID_GID="35002:35002"
-FROM ubuntu:resolute AS runtime
+FROM
ubuntu:resolute@sha256:da6fc2be547864451aa253836dd926da33623312df4a9a243e35dc877c378a78
AS runtime
ARG UID_GID
ARG TIKA_VERSION
ARG JRE='openjdk-25-jre-headless'