Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade nginx from mainline-alpine to 1.25.3-alpine3.18 #7289

Closed
wants to merge 2 commits into from

Conversation

nmanovic
Copy link
Contributor

This PR was automatically created by Snyk using the credentials of a real user.


Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Changes included in this PR

  • Dockerfile.ui

We recommend upgrading to nginx:1.25.3-alpine3.18, as this image has only 0 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Some of the most important vulnerabilities in your base image include:

Severity Issue Exploit Maturity
medium severity Missing Encryption of Sensitive Data
SNYK-ALPINE318-CURL-6104720
No Known Exploit
medium severity Missing Encryption of Sensitive Data
SNYK-ALPINE318-CURL-6104720
No Known Exploit
medium severity CVE-2023-46218
SNYK-ALPINE318-CURL-6104721
No Known Exploit
medium severity CVE-2023-46218
SNYK-ALPINE318-CURL-6104721
No Known Exploit

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

Copy link

codecov bot commented Dec 22, 2023

Codecov Report

Merging #7289 (c8424d6) into develop (f513aa1) will decrease coverage by 0.01%.
The diff coverage is n/a.

Additional details and impacted files
@@             Coverage Diff             @@
##           develop    #7289      +/-   ##
===========================================
- Coverage    83.47%   83.46%   -0.01%     
===========================================
  Files          373      373              
  Lines        39739    39739              
  Branches      3741     3741              
===========================================
- Hits         33171    33168       -3     
- Misses        6568     6571       +3     
Components Coverage Δ
cvat-ui 79.27% <ø> (-0.02%) ⬇️
cvat-server 87.32% <ø> (-0.01%) ⬇️

@bsekachev
Copy link
Member

mainline-alpine has less vulnerabilities according to dockerhub.

image
image

@bsekachev bsekachev closed this Apr 17, 2024
@bsekachev bsekachev deleted the snyk-fix-eeeaef7319c23e97ad6742712856b4c5 branch April 22, 2024 08:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants