So you might have cut and paste some code from somewhere, maybe an ‘from launcher.gcr.io/debian9’ kind of thing. That’s a good upstream, right? They are maintaining it with a strong CI? When suddenly you read
Hmm. Double whammy. You have been relying since 2018-07-18 on something which is not being updated (and daily rebuilding your tool, running SAST, etc… and never noticed. Shame on you!). But also, the recommended replacement requires GCP credentials which you don’t have in your OSS build environment?
Well at least now you know, and you can probably replace this with debian/stretch and be happy (the Dockerhub one is maintained by the Debian team).
I, of course, would never have made this mistake, and for sure if I had I would have noticed the upstream was never changing in that time 🙂