Fork me on GitHub
#docker
<
2022-04-28
>
cap10morgan16:04:28

Heads up everyone, some potential (but sadly unavoidable) breakage incoming: https://github.com/Quantisan/docker-clojure/issues/159

cap10morgan22:04:03

The short version of why we have to migrate is that Oracle is only going to do the first two follow-up releases of any major new version of Java, with the subsequent ones left up to the community. And since they already did 17.0.1 and 17.0.2, they're done. But 17.0.2 is susceptible to following security vulnerabilities: https://www.oracle.com/security-alerts/cpuapr2022.html#AppendixJAVA

cap10morgan22:04:48

So the official Docker image folks are removing the vanilla openjdk:17 image variants (and I believe later versions too) b/c there will be no more official releases w/ these vulns patched. Whereas the other OpenJDK distributions (Eclipse Temurin, Amazon Corretto, etc.) have mostly already released 17.0.3.