[ 
https://issues.apache.org/jira/browse/SOLR-16523?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17641906#comment-17641906
 ] 

Ritchie Gu commented on SOLR-16523:
-----------------------------------

Hi [~janhoy] , thanks, I will work on the PR for jattach version today.

As for gosu, I think unless it's absolutely needed for solr, i propose to 
remove it as the version of golang it's using is pretty old. For users who need 
to use solr and have to deal with government agencies etc. it's very hard to 
pass their security scan.

what do you think?

> gosu binary version
> -------------------
>
>                 Key: SOLR-16523
>                 URL: https://issues.apache.org/jira/browse/SOLR-16523
>             Project: Solr
>          Issue Type: Improvement
>      Security Level: Public(Default Security Level. Issues are Public) 
>          Components: Docker
>    Affects Versions: 8.11.2
>            Reporter: Ritchie Gu
>            Assignee: Jan Høydahl
>            Priority: Major
>
> I noticed that as part of the process, it's installing gosu and few other 
> packages 
> [https://github.com/apache/solr-docker/blob/main/8.11-slim/Dockerfile#L20,]
> The version of gosu gets installed is a bit of old, and do you have any plan 
> to install newer version gosu in?



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to