Skip to content

[Snyk] Security upgrade debian from bookworm-slim to 12.15-slim - #7038

Merged
Warashi merged 2 commits into
masterfrom
snyk-fix-cdc1813a842868eceb3c5cf844647f2a
Aug 23, 2026
Merged

[Snyk] Security upgrade debian from bookworm-slim to 12.15-slim#7038
Warashi merged 2 commits into
masterfrom
snyk-fix-cdc1813a842868eceb3c5cf844647f2a

Conversation

@caniszczyk

Copy link
Copy Markdown
Contributor

snyk-top-banner

Snyk has created this PR to fix 3 vulnerabilities in the dockerfile dependencies of this project.

Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Snyk changed the following file(s):

  • tool/codegen/Dockerfile

We recommend upgrading to debian:12.15-slim, as this image has only 70 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
medium severity Heap-based Buffer Overflow
SNYK-DEBIAN12-XZUTILS-15895807
  514  
critical severity Integer Overflow or Wraparound
SNYK-DEBIAN12-ZLIB-6008963
  500  
medium severity Use After Free
SNYK-DEBIAN12-UTILLINUX-17690420
  371  
medium severity Use After Free
SNYK-DEBIAN12-UTILLINUX-17690420
  371  
medium severity Use After Free
SNYK-DEBIAN12-UTILLINUX-17690420
  371  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Heap-based Buffer Overflow
🦉 Integer Overflow or Wraparound
🦉 Use After Free

@caniszczyk
caniszczyk requested a review from a team as a code owner July 15, 2026 00:37
@codecov

codecov Bot commented Jul 15, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 29.67%. Comparing base (bb60fdc) to head (38ca3d1).

Additional details and impacted files
@@            Coverage Diff             @@
##           master    #7038      +/-   ##
==========================================
- Coverage   29.68%   29.67%   -0.01%     
==========================================
  Files         601      601              
  Lines       64396    64396              
==========================================
- Hits        19116    19112       -4     
- Misses      43789    43792       +3     
- Partials     1491     1492       +1     
Flag Coverage Δ
. 23.59% <ø> (ø)
.-pkg-app-pipedv1-plugin-analysis 32.16% <ø> (ø)
.-pkg-app-pipedv1-plugin-ecs 31.74% <ø> (ø)
.-pkg-app-pipedv1-plugin-kubernetes 58.39% <ø> (ø)
.-pkg-app-pipedv1-plugin-kubernetes_multicluster 59.62% <ø> (ø)
.-pkg-app-pipedv1-plugin-scriptrun 54.83% <ø> (ø)
.-pkg-app-pipedv1-plugin-terraform 38.46% <ø> (ø)
.-pkg-app-pipedv1-plugin-wait 33.04% <ø> (ø)
.-pkg-app-pipedv1-plugin-waitapproval 52.71% <ø> (ø)
.-pkg-plugin-sdk 49.65% <ø> (-0.20%) ⬇️
.-tool-actions-gh-release 19.23% <ø> (ø)
.-tool-actions-plan-preview 25.51% <ø> (ø)
.-tool-codegen-protoc-gen-auth 0.00% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@yashisrani

Copy link
Copy Markdown

@caniszczyk Our project enforces the Developer Certificate of Origin (DCO). Please sign off your commits to ensure the DCO check passes:

git commit -s -m "Your commit message"

@github-actions

Copy link
Copy Markdown
Contributor

This PR is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 7 days.

@github-actions github-actions Bot added the Stale label Aug 16, 2026
@mohammedfirdouss

Copy link
Copy Markdown
Contributor

@caniszczyk you need to sign off the commits to ensure DCO passes

@github-actions github-actions Bot removed the Stale label Aug 19, 2026
@Warashi
Warashi force-pushed the snyk-fix-cdc1813a842868eceb3c5cf844647f2a branch from 0379f9a to c0a224a Compare August 23, 2026 06:06
@netlify

netlify Bot commented Aug 23, 2026

Copy link
Copy Markdown

Deploy Preview for pipecd-site ready!

Name Link
🔨 Latest commit 38ca3d1
🔍 Latest deploy log https://app.netlify.com/projects/pipecd-site/deploys/6a8a8e36fb4cbc0008e8c6fe
😎 Deploy Preview https://deploy-preview-7038--pipecd-site.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@Warashi Warashi left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Snyk automation opens PRs without commit sign-off. I rebased this PR to add sign-off without modifying its content.
It seems good based on the CI results.

@Warashi
Warashi merged commit 8e6c813 into master Aug 23, 2026
78 of 79 checks passed
@Warashi
Warashi deleted the snyk-fix-cdc1813a842868eceb3c5cf844647f2a branch August 23, 2026 06:13
@github-actions

Copy link
Copy Markdown
Contributor

Thank you for contributing to PipeCD, @caniszczyk! The changes in this pull request will be part of the upcoming release!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants