# Liquibase image 4.17.2 flagged by Aqua Security

**URL:** <https://forum.liquibase.org/t/liquibase-image-4-17-2-flagged-by-aqua-security/7549>\
**Category:** Uncategorized\
**Created:** [November 21, 2022, 1:41pm UTC](https://forum.liquibase.org/t/liquibase-image-4-17-2-flagged-by-aqua-security/7549 "2022-11-21T13:41:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![alemac](https://avatars.discourse-cdn.com/v4/letter/a/f04885/32.png) [@alemac](https://forum.liquibase.org/u/alemac)\
**Post date:** [November 21, 2022, 1:41pm UTC](https://forum.liquibase.org/t/liquibase-image-4-17-2-flagged-by-aqua-security/7549/1 "2022-11-21T13:41:40Z")

</div>

Hi Community,

I have a puzzling problem with Liquibase 4.17.2 build. During a pipeline run, it is getting flagged by Aqua Security. Several vulnerabilities are flagged: bash, binutils, coreutils, libtasn1-6, libxml2, wget. The type of vulnerabilities is given as ‘PACKAGE’.

Are these known vulnerabilities? I was not able to find anything on this online. Would greatly appreciate any help.

---

<div class="post-metadata">

**Author:** ![tabbyfoo](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.liquibase.org/tabbyfoo/32/748_2.png) [@tabbyfoo](https://forum.liquibase.org/u/tabbyfoo)\
**Post date:** [December 5, 2022, 9:17pm UTC](https://forum.liquibase.org/t/liquibase-image-4-17-2-flagged-by-aqua-security/7549/2 "2022-12-05T21:17:26Z")

</div>

Welcome to the Liquibase Forum, @alemac !

I will ask for someone on the dev team to take a look at this post. Could you take a screenshot or copy the exact text of the warning message and include it in a reply to this message? Thanks!

---

<div class="post-metadata">

**Author:** ![tabbyfoo](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.liquibase.org/tabbyfoo/32/748_2.png) [@tabbyfoo](https://forum.liquibase.org/u/tabbyfoo)\
**Post date:** [December 9, 2022, 5:48pm UTC](https://forum.liquibase.org/t/liquibase-image-4-17-2-flagged-by-aqua-security/7549/3 "2022-12-09T17:48:45Z")

</div>

Hi @alemac - I have an update for you!

This issue was due to the underlying OS of the upstream docker image we use. There was a PR open that updated this issue, and was released in this week’s 4.18 release:

> <https://github.com/liquibase/docker/pull/180>
>
> Updating the base image to ubuntu jammy should resolve #178 and #176

> **[Release Notes](https://docsstage.liquibase.com/release-notes/home.html)**
>
> Reference information for Liquibase release notes.
