Area for Improvement
Make the operating-system version used by deploy/images/ucpd/Dockerfile explicit and reproducible.
Observed behavior
The Dockerfile uses gcr.io/distroless/static:nonroot. Distroless documents that this unqualified alias currently selects Debian 13 but will move to a newer Debian release in the future. A rebuild can therefore change the operating-system major version without a repository change.
Desired behavior
The ucpd image uses a supported, explicitly versioned Distroless base and builds from an immutable digest on all supported architectures.
Proposed Fix
Replace the base with gcr.io/distroless/static-debian13:nonroot and pin its current multi-platform OCI index digest. Retain the readable Debian 13 tag next to the digest and configure dependency automation to propose digest updates. Verify AMD64, ARM64, and ARMv7 builds.
rad Version
N/A
Operating system
Linux AMD64, ARM64, and ARMv7 container targets.
Additional context
Distroless supported images and versioning guidance: https://github.com/GoogleContainerTools/distroless#what-images-are-available
Area for Improvement
Make the operating-system version used by
deploy/images/ucpd/Dockerfileexplicit and reproducible.Observed behavior
The Dockerfile uses
gcr.io/distroless/static:nonroot. Distroless documents that this unqualified alias currently selects Debian 13 but will move to a newer Debian release in the future. A rebuild can therefore change the operating-system major version without a repository change.Desired behavior
The ucpd image uses a supported, explicitly versioned Distroless base and builds from an immutable digest on all supported architectures.
Proposed Fix
Replace the base with
gcr.io/distroless/static-debian13:nonrootand pin its current multi-platform OCI index digest. Retain the readable Debian 13 tag next to the digest and configure dependency automation to propose digest updates. Verify AMD64, ARM64, and ARMv7 builds.rad Version
N/A
Operating system
Linux AMD64, ARM64, and ARMv7 container targets.
Additional context
Distroless supported images and versioning guidance: https://github.com/GoogleContainerTools/distroless#what-images-are-available