Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(autoupgrade): auto upgrade os packages in rclone Uploader image #2101

Merged
merged 1 commit into from Jan 21, 2024

Conversation

amardeep2006
Copy link
Contributor

Thanks for contributing to the Docker-Selenium project!
A PR well described will help maintainers to quickly review and merge it

Before submitting your PR, please check our contributing guidelines, applied for this repository.
Avoid large PRs, help reviewers by making them as simple and short as possible.

Description

I scanned the rclone based docker image and found os related vulnerable packages. here is the list of vulnerable packages.

image

We scan every image before using in enterprise so auto patching will be helpful.

Motivation and Context

These packages are already patched in upstream Alpine distribution. If we add apk upgrade command to Dockerfile then it will auto apply the OS packages patches on new Docker builds .

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)

Checklist

  • I have read the contributing document.
  • My change requires a change to the documentation.
  • I have updated the documentation accordingly.
  • I have added tests to cover my changes.
  • All new and existing tests passed.

@amardeep2006 amardeep2006 changed the title feat(autoupgrade): auto upgrade os packages feat(autoupgrade): auto upgrade os packages in rclone Uploader image Jan 21, 2024
@VietND96
Copy link
Member

That's great! Thank you for looking into the vulnerability. I will merge this and bump a new nightly build.

@VietND96 VietND96 merged commit e65da83 into SeleniumHQ:trunk Jan 21, 2024
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants