Conversation
…igest The python:3.11-slim-trixie base was rebuilt with OpenSSL 3.5.7-1~deb13u3, so the exact openssl=...deb13u2 pin became a downgrade and every image build failed with "Packages were downgraded and -y was used without --allow-downgrades". - Bump the openssl / libssl3t64 / openssl-provider-legacy pin to 3.5.7-1~deb13u3 in all 24 Dockerfiles that carry it. - Pin the base image by digest (python_image_digest ARG) so the base, and the OpenSSL it ships, only changes when bumped explicitly together with the openssl pin, instead of whenever the upstream tag is rebuilt. Signed-off-by: Jakub Piasecki <jakub.piasecki@intel.com>
jpiaseck
force-pushed
the
jpiaseck/openssl-bump-base-digest-pin
branch
from
October 2, 2026 13:19
6a83976 to
cfbbc82
Compare
intelpljanot
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
All 24 service images built from
python:3.11-slim-trixiefail to build:The upstream
python:3.11-slim-trixietag was rebuilt with OpenSSL3.5.7-1~deb13u3(now intrixie-security), while the Dockerfiles pinopenssl=3.5.7-1~deb13u2. Because the base is referenced by a floating tag, the exact apt pin turns into a downgrade every time Debian ships an OpenSSL update and the base is rebuilt.Fix
openssl/libssl3t64/openssl-provider-legacyto3.5.7-1~deb13u3in the 24 Dockerfiles that carry the pin.python_image_digestARG:bab1b7ef…is the current multi-arch index digest ofpython:3.11-slim-trixie(Python 3.11.17, Debian 13.7, OpenSSL3.5.7-1~deb13u3).With the digest pinned, the base — and the OpenSSL it ships — only changes when the digest is bumped explicitly, together with the openssl pin. Future upstream rebuilds no longer break the build, and published Dockerfiles stay reproducible.
To bump in the future: update
python_image_digestto the newpython:3.11-slim-trixiedigest and the openssl pin to the version that base ships, in the same change.Testing
Built locally with
deployment/update_images.sh --build(no push):3.5.7-1~deb13u3, Python3.11.17, and the bottom 4 layers of every image match the pinned base digest exactly.textExtractorUsvcandttsFastapiModelServer— their builds were interrupted by a local disk-space issue, not a build error. The change to those two Dockerfiles is identical to the other 22.Note (pre-existing, not changed here)
ingestionandprompt_templateDockerfiles do not contain therm -f /usr/bin/dmesg /usr/bin/base64 /usr/bin/perlhardening step that the other images have, so those binaries remain in those two images. Left out of scope for this PR.