diff --git a/Dockerfile b/Dockerfile index 822c1ce..f16ed40 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ # Base image pinned by its multi-arch index digest, so a re-pushed tag cannot # change what is built. Refresh the digest and the tag together. -FROM python:3.11.16-slim-bookworm@sha256:a36c24f9cbdf4fd0f52d67f0823eeac19c2028c637cecc392d97f980d4fec56b AS builder +FROM python:3.11.17-slim-bookworm@sha256:2333bd330d12de02514770b3585cad313644316047cdee24a7acfdece6de6efb AS builder ENV PIP_DISABLE_PIP_VERSION_CHECK=1 \ PIP_NO_CACHE_DIR=1 @@ -14,7 +14,7 @@ COPY pyproject.toml README.md LICENSE NOTICE ./ COPY src ./src RUN python -m pip wheel --no-deps --no-build-isolation --wheel-dir /wheels . -FROM python:3.11.16-slim-bookworm@sha256:a36c24f9cbdf4fd0f52d67f0823eeac19c2028c637cecc392d97f980d4fec56b AS runtime +FROM python:3.11.17-slim-bookworm@sha256:2333bd330d12de02514770b3585cad313644316047cdee24a7acfdece6de6efb AS runtime ENV PIP_DISABLE_PIP_VERSION_CHECK=1 \ PIP_NO_CACHE_DIR=1 \ diff --git a/tests/unit/test_container_release.py b/tests/unit/test_container_release.py index 257fac8..728ffb7 100644 --- a/tests/unit/test_container_release.py +++ b/tests/unit/test_container_release.py @@ -11,8 +11,11 @@ def test_runtime_image_is_multistage_non_root_and_offline_installed() -> None: dockerfile = Path("Dockerfile").read_text(encoding="utf-8") - # Both stages pin the base image by digest, not by tag alone. - assert dockerfile.count("FROM python:3.11.16-slim-bookworm@sha256:") == 2 + # Both stages pin the base image by patch release and digest, not by tag alone. + base_stages = re.findall( + r"^FROM python:3\.11\.\d+-slim-bookworm@sha256:[0-9a-f]{64} AS ", dockerfile, re.M + ) + assert len(base_stages) == 2 assert "AS builder" in dockerfile assert "pip install --require-hashes -r requirements/build.txt" in dockerfile assert "pip wheel --no-deps --no-build-isolation --wheel-dir /wheels ." in dockerfile