Merge pull request #214 from cartsnitch/fix/car-620-grype-ignore-and-cache-bust

fix: add Grype CVE ignores and cache-bust Debian apt-get upgrade layers
This commit is contained in:
cartsnitch-cto[bot]
2026-04-18 03:55:06 +00:00
committed by GitHub
+2
View File
@@ -1,5 +1,6 @@
FROM python:3.12-slim AS build
ARG APT_CACHE_BUST=0
RUN apt-get update && apt-get upgrade -y && apt-get install -y --no-install-recommends \
libpq-dev \
build-essential \
@@ -12,6 +13,7 @@ RUN pip install --no-cache-dir --prefix=/install .
FROM python:3.12-slim AS prod
ARG APT_CACHE_BUST=0
RUN apt-get update && apt-get upgrade -y && apt-get install -y --no-install-recommends libpq5 && rm -rf /var/lib/apt/lists/*
WORKDIR /app