# Jenkins plugins update

**URL:** <https://community.jenkins.io/t/jenkins-plugins-update/15469>\
**Category:** Ask a question\
**Tags:** question\
**Created:** [May 26, 2024, 7:38pm UTC](https://community.jenkins.io/t/jenkins-plugins-update/15469 "2024-05-26T19:38:22Z")\
**Posts on this page:** 13\
**Page:** 2

<div class="post-metadata">

**Author:** ![arafata](https://avatars.discourse-cdn.com/v4/letter/a/7ba0ec/32.png) [@arafata](https://community.jenkins.io/u/arafata)\
**Post date:** [June 3, 2024, 8:01pm UTC](https://community.jenkins.io/t/jenkins-plugins-update/15469/22 "2024-06-03T20:01:42Z")

</div>

but on github [GitHub - jenkinsci/blueocean-plugin: Blue Ocean is a reboot of the Jenkins CI/CD User Experience](https://github.com/jenkinsci/blueocean-plugin) it is maintained since two months ago

---

<div class="post-metadata">

**Author:** ![MarkEWaite](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/markewaite/32/20_2.png) [@MarkEWaite](https://community.jenkins.io/u/MarkEWaite)\
**Post date:** [June 3, 2024, 8:13pm UTC](https://community.jenkins.io/t/jenkins-plugins-update/15469/23 "2024-06-03T20:13:47Z")

</div>

The [Blue Ocean plugin](https://plugins.jenkins.io/blueocean/) is different than the [obsolete jenkinsci/blueocean container image](https://hub.docker.com/r/jenkinsci/blueocean). The obsolete container image provides enough files to run a Jenkins controller as a container. A plugin is a single file that must be loaded into a Jenkins controller in order to run.

Switch to a container image that is not obsolete.

---

<div class="post-metadata">

**Author:** ![arafata](https://avatars.discourse-cdn.com/v4/letter/a/7ba0ec/32.png) [@arafata](https://community.jenkins.io/u/arafata)\
**Post date:** [June 4, 2024, 11:23am UTC](https://community.jenkins.io/t/jenkins-plugins-update/15469/24 "2024-06-04T11:23:23Z")

</div>

thank you sir , is there any recent release of jenkinsci on docker hub

---

<div class="post-metadata">

**Author:** ![MarkEWaite](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/markewaite/32/20_2.png) [@MarkEWaite](https://community.jenkins.io/u/MarkEWaite)\
**Post date:** [June 4, 2024, 12:04pm UTC](https://community.jenkins.io/t/jenkins-plugins-update/15469/25 "2024-06-04T12:04:22Z")

</div>

You asked:

> [@arafata](#):
>
> is there any recent release of jenkinsci on docker hub

I had previously said:

> [@MarkEWaite](#):
>
> The [`jenkins/jenkins` container image](https://hub.docker.com/r/jenkins/jenkins/tags) is actively maintained

“Actively maintained” means that new container image tags are pushed to Dockerhub each time there is a release of Jenkins core. The [Dockerhub tags](https://hub.docker.com/r/jenkins/jenkins/tags?page=&page_size=&ordering=&name=2.452.1-) for the [jenkins/jenkins container image](https://hub.docker.com/r/jenkins/jenkins) include tags published less than a month ago for Jenkins 2.452.1 (LTS) and tags published last week for Jenkins 2.460 (weekly).

A new LTS will be released Wednesday 12 Jun 2024. A new weekly will be released Tuesday 2 Jun 2024 and Tuesday 11 Jun 2024. New Dockerhub tags to match those releases will created shortly after the release becomes available.

---

<div class="post-metadata">

**Author:** ![arafata](https://avatars.discourse-cdn.com/v4/letter/a/7ba0ec/32.png) [@arafata](https://community.jenkins.io/u/arafata)\
**Post date:** [June 4, 2024, 12:59pm UTC](https://community.jenkins.io/t/jenkins-plugins-update/15469/26 "2024-06-04T12:59:45Z")

</div>

but jenkins/jenkins need a lot of additions to work well on CD/CI , ex : you need to mount docker binary when launching container -v /var/run/docker.sock:/var/run/docker.sock and the more you use container to build image as the container become very slow , and there is no caching when rebuilding an image, …etc

---

<div class="post-metadata">

**Author:** ![MarkEWaite](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/markewaite/32/20_2.png) [@MarkEWaite](https://community.jenkins.io/u/MarkEWaite)\
**Post date:** [June 4, 2024, 2:56pm UTC](https://community.jenkins.io/t/jenkins-plugins-update/15469/27 "2024-06-04T14:56:35Z")

</div>

> [@arafata](#):
>
> you need to mount docker binary when launching container -v /var/run/docker.sock:/var/run/docker.sock

Mounting the Docker socket into the controller image is a mistake for two reasons.

1. Running Jenkins jobs on the controller is a mistake. Use agents to run Jenkins jobs. The [controller isolation section](https://www.jenkins.io/doc/book/security/controller-isolation/) in the [“Securing Jenkins” chapter](https://www.jenkins.io/doc/book/security/) of the documentation describes the security risks of running jobs on the controller
2. Mounting the Docker socket in the container image is a mistake. A [stackoverflow article](https://stackoverflow.com/questions/40844197/what-is-the-docker-security-risk-of-var-run-docker-sock) describes the security risks of mounting the Docker socket in a container

> [@arafata](#):
>
> there is no caching when rebuilding an image

When I build images, the layers that do not change are cached. I don’t know what configuration you use to build container images, but if the layers are not cached in your configuration, then you need to fix that configuration. Layer caching is a standard part of the `docker build` process.

---

<div class="post-metadata">

**Author:** ![arafata](https://avatars.discourse-cdn.com/v4/letter/a/7ba0ec/32.png) [@arafata](https://community.jenkins.io/u/arafata)\
**Post date:** [June 12, 2024, 12:48pm UTC](https://community.jenkins.io/t/jenkins-plugins-update/15469/28 "2024-06-12T12:48:05Z")

</div>

Hi sir , I use the following to launch jenkins/jenkins :

```auto

 jenkins:
    container_name: jenkins
    environment:
      - JAVA_OPTS=-Dhudson.model.DirectoryBrowserSupport.CSP="sandbox allow-scripts; script-src 'unsafe-inline'; style-src 'unsafe-inline';" 
      - PLUGINS_FORCE_UPGRADE=true 
    image: jenkins/jenkins   
    ports:
      - "8080:8080"
    restart: unless-stopped    
    volumes:
      - /var/jenkins_home:/var/jenkins_home:rw # Workspace home
      - /var/run/docker.sock:/var/run/docker.sock:ro # Allows Jenkins to stop/start containers
      - /usr/bin/docker:/usr/bin/docker

```

---

<div class="post-metadata">

**Author:** ![poddingue](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/poddingue/32/985_2.png) [@poddingue](https://community.jenkins.io/u/poddingue)\
**Post date:** [June 13, 2024, 6:48am UTC](https://community.jenkins.io/t/jenkins-plugins-update/15469/30 "2024-06-13T06:48:28Z")

</div>

What are you trying to achieve exactly?

---

<div class="post-metadata">

**Author:** ![arafata](https://avatars.discourse-cdn.com/v4/letter/a/7ba0ec/32.png) [@arafata](https://community.jenkins.io/u/arafata)\
**Post date:** [June 27, 2024, 3:02pm UTC](https://community.jenkins.io/t/jenkins-plugins-update/15469/31 "2024-06-27T15:02:59Z")

</div>

I want to use jenkins container for CI/CD

---

<div class="post-metadata">

**Author:** ![arafata](https://avatars.discourse-cdn.com/v4/letter/a/7ba0ec/32.png) [@arafata](https://community.jenkins.io/u/arafata)\
**Post date:** [June 30, 2024, 11:38am UTC](https://community.jenkins.io/t/jenkins-plugins-update/15469/32 "2024-06-30T11:38:02Z")

</div>

when I use /usr/bin/docker:/usr/bin/docker to accessing docker binary , jenkins become very heavy.  
and there is another problem that is no caching when rebuild image

---

<div class="post-metadata">

**Author:** ![arafata](https://avatars.discourse-cdn.com/v4/letter/a/7ba0ec/32.png) [@arafata](https://community.jenkins.io/u/arafata)\
**Post date:** [June 30, 2024, 11:40am UTC](https://community.jenkins.io/t/jenkins-plugins-update/15469/33 "2024-06-30T11:40:49Z")

</div>

as long as we shoud not use /var/run/docker.sock:/var/run/docker.sock ,  
how do we access docker binary

---

<div class="post-metadata">

**Author:** ![MarkEWaite](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/markewaite/32/20_2.png) [@MarkEWaite](https://community.jenkins.io/u/MarkEWaite)\
**Post date:** [July 1, 2024, 12:01pm UTC](https://community.jenkins.io/t/jenkins-plugins-update/15469/34 "2024-07-01T12:01:48Z")

</div>

Mounting the docker socket inside the controller image is a mistake. See my earlier answer

> [@Jenkins plugins update](https://community.jenkins.io/t/jenkins-plugins-update/15469/27):
>
> Mounting the Docker socket into the controller image is a mistake for two reasons. Running Jenkins jobs on the controller is a mistake. Use agents to run Jenkins jobs. The [controller isolation section](https://www.jenkins.io/doc/book/security/controller-isolation/) in the [“Securing Jenkins” chapter](https://www.jenkins.io/doc/book/security/) of the documentation describes the security risks of running jobs on the controller Mounting the Docker socket in the container image is a mistake. A [stackoverflow article](https://stackoverflow.com/questions/40844197/what-is-the-docker-security-risk-of-var-run-docker-sock) describes the security risks of mounting the Docker socket in a container When I build…

If you really must run Docker from the Jenkins controller, even with the knowledge that it is a mistake, then refer to the [Docker installation instructions for Jenkins](https://www.jenkins.io/doc/book/installing/docker/). Those instructions (for the moment) describe how to configure Docker in Docker for a Jenkins controller.

We plan to replace those instructions soon, because they are a poor choice for Jenkins users. They are complicated, prone to failure, and bring all the security risks of running Docker in Docker.

The most secure approach is to configure agents that are allowed to run Docker, label those agents (something like `docker`) and define the jobs that need Docker to require the label `docker`)

---

<div class="post-metadata">

**Author:** ![arafata](https://avatars.discourse-cdn.com/v4/letter/a/7ba0ec/32.png) [@arafata](https://community.jenkins.io/u/arafata)\
**Post date:** [July 4, 2024, 11:17am UTC](https://community.jenkins.io/t/jenkins-plugins-update/15469/35 "2024-07-04T11:17:07Z")

</div>

thank you so much sir

[Previous page](https://community.jenkins.io/t/jenkins-plugins-update/15469.md?page=1)
