[Snyk] Security upgrade debian from bookworm-slim to 12.15-slim - #7038
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #7038 +/- ##
==========================================
- Coverage 29.68% 29.67% -0.01%
==========================================
Files 601 601
Lines 64396 64396
==========================================
- Hits 19116 19112 -4
- Misses 43789 43792 +3
- Partials 1491 1492 +1
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
@caniszczyk Our project enforces the Developer Certificate of Origin (DCO). Please sign off your commits to ensure the DCO check passes: |
|
This PR is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 7 days. |
|
@caniszczyk you need to sign off the commits to ensure DCO passes |
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-DEBIAN12-XZUTILS-15895807 - https://snyk.io/vuln/SNYK-DEBIAN12-ZLIB-6008963 - https://snyk.io/vuln/SNYK-DEBIAN12-UTILLINUX-17690420 - https://snyk.io/vuln/SNYK-DEBIAN12-UTILLINUX-17690420 - https://snyk.io/vuln/SNYK-DEBIAN12-UTILLINUX-17690420 Signed-off-by: Shinnosuke Sawada-Dazai <3600530+Warashi@users.noreply.github.com>
0379f9a to
c0a224a
Compare
✅ Deploy Preview for pipecd-site ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Warashi
left a comment
There was a problem hiding this comment.
Snyk automation opens PRs without commit sign-off. I rebased this PR to add sign-off without modifying its content.
It seems good based on the CI results.
|
Thank you for contributing to PipeCD, @caniszczyk! The changes in this pull request will be part of the upcoming release! |
Snyk has created this PR to fix 3 vulnerabilities in the dockerfile dependencies of this project.
Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.
Snyk changed the following file(s):
tool/codegen/DockerfileWe recommend upgrading to
debian:12.15-slim, as this image has only 70 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.Vulnerabilities that will be fixed with an upgrade:
SNYK-DEBIAN12-XZUTILS-15895807
SNYK-DEBIAN12-ZLIB-6008963
SNYK-DEBIAN12-UTILLINUX-17690420
SNYK-DEBIAN12-UTILLINUX-17690420
SNYK-DEBIAN12-UTILLINUX-17690420
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Heap-based Buffer Overflow
🦉 Integer Overflow or Wraparound
🦉 Use After Free