From 4362d71e30fb08ff1dcdce9a69a6452df175b4dd Mon Sep 17 00:00:00 2001 From: Bitnami Bot Date: Fri, 7 Aug 2026 17:38:40 +0200 Subject: [PATCH] [bitnami/redis] Release 8.10.0-debian-12-r1 (#96151) Signed-off-by: Bitnami Bot --- bitnami/redis/8.10/debian-12/Dockerfile | 4 +-- .../rootfs/opt/bitnami/scripts/libredis.sh | 32 ++++++++++++++----- 2 files changed, 26 insertions(+), 10 deletions(-) diff --git a/bitnami/redis/8.10/debian-12/Dockerfile b/bitnami/redis/8.10/debian-12/Dockerfile index dd97f93324ed..3463b397f370 100644 --- a/bitnami/redis/8.10/debian-12/Dockerfile +++ b/bitnami/redis/8.10/debian-12/Dockerfile @@ -7,7 +7,7 @@ ARG DOWNLOADS_URL="https://downloads.bitnami.com/files/stacksmith" ARG TARGETARCH LABEL org.opencontainers.image.base.name="docker.io/bitnami/minideb:bookworm" \ - org.opencontainers.image.created="2026-08-05T15:24:43Z" \ + org.opencontainers.image.created="2026-08-07T15:12:55Z" \ org.opencontainers.image.description="Application packaged by Broadcom, Inc." \ org.opencontainers.image.documentation="https://github.com/bitnami/containers/tree/main/bitnami/redis/README.md" \ org.opencontainers.image.source="https://github.com/bitnami/containers/tree/main/bitnami/redis" \ @@ -52,7 +52,7 @@ COPY rootfs / RUN /opt/bitnami/scripts/redis/postunpack.sh ENV APP_VERSION="8.10.0" \ BITNAMI_APP_NAME="redis" \ - IMAGE_REVISION="0" \ + IMAGE_REVISION="1" \ PATH="/opt/bitnami/common/bin:/opt/bitnami/redis/bin:$PATH" EXPOSE 6379 diff --git a/bitnami/redis/8.10/debian-12/rootfs/opt/bitnami/scripts/libredis.sh b/bitnami/redis/8.10/debian-12/rootfs/opt/bitnami/scripts/libredis.sh index 25f87f776b29..ef3e5ab0dd14 100644 --- a/bitnami/redis/8.10/debian-12/rootfs/opt/bitnami/scripts/libredis.sh +++ b/bitnami/redis/8.10/debian-12/rootfs/opt/bitnami/scripts/libredis.sh @@ -50,15 +50,31 @@ redis_conf_set() { local value="${2:-}" # Sanitize inputs - # 1. Escape special characters (\, &, ?) - value="${value//\\/\\\\}" - value="${value//&/\\&}" - value="${value//\?/\\?}" - # 2. \001-\037 strips all ASCII control characters (1-31), \000 is the NUL character (0) that Bash cannot store - # 3. \177 strips DEL (delete) character (127) + # 1. \001-\037 strips all ASCII control characters (1-31), \000 is the NUL character (0) that Bash cannot store + # 2. \177 strips DEL (delete) character (127) value="${value//[$'\001'-$'\037'$'\177']}" - # 4. If the value is empty, set it to an empty string - [[ "$value" = "" ]] && value="\"$value\"" + + case "$key" in + masterauth | requirepass | tls-key-file-pass) + # These keys hold a single opaque string value (e.g. passwords) that may contain + # spaces, '#', quotes or backslashes. Format as a double-quoted Redis config string + # so the parser handles them safely. Other keys (e.g. bind, save, replicaof) pack + # multiple space-separated tokens into $value and must NOT be quoted as a whole. + value="${value//\\/\\\\}" + value="${value//\"/\\\"}" + value="\"${value}\"" + # Escape for sed replacement string in replace_in_file (\ -> \\, & -> \&) + value="${value//\\/\\\\}" + value="${value//&/\\&}" + ;; + *) + # Escape special characters for sed replacement (\, &, ?) + value="${value//\\/\\\\}" + value="${value//&/\\&}" + value="${value//\?/\\?}" + [[ "$value" = "" ]] && value="\"\"" + ;; + esac # Determine whether to enable the configuration for RDB persistence, if yes, do not enable the replacement operation if [ "${key}" == "save" ]; then