Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade node from 18.18.2-bullseye-slim to 18.20.2-bullseye-slim #2408

Merged
merged 1 commit into from
Apr 26, 2024

Conversation

swirlds-automation
Copy link
Contributor

This PR was automatically created by Snyk using the credentials of a real user.


Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Changes included in this PR

  • Dockerfile

We recommend upgrading to node:18.20.2-bullseye-slim, as this image has only 69 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Some of the most important vulnerabilities in your base image include:

Severity Priority Score / 1000 Issue Exploit Maturity
medium severity 514 Information Exposure
SNYK-DEBIAN11-GNUTLS28-6062102
No Known Exploit
high severity 614 Out-of-bounds Write
SNYK-DEBIAN11-PERL-6085272
No Known Exploit
medium severity 514 Out-of-bounds Read
SNYK-DEBIAN11-TAR-3253527
No Known Exploit
critical severity 500 Integer Overflow or Wraparound
SNYK-DEBIAN11-ZLIB-6008961
No Known Exploit
high severity 471 Allocation of Resources Without Limits or Throttling
SNYK-UPSTREAM-NODE-6564548
No Known Exploit

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling

Copy link

Acceptance Tests

     19 files  266 suites   25m 58s ⏱️
   583 tests 571 ✔️ 3 💤   9
1 010 runs  989 ✔️ 8 💤 13

Results for commit c64b9aa.

@ebadiere ebadiere force-pushed the snyk-fix-247eb28d0e64b23f73d2a025e1bc1b12 branch from c64b9aa to 392f97f Compare April 26, 2024 02:32
Copy link

sonarcloud bot commented Apr 26, 2024

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarCloud

Copy link

Tests

    2 files  147 suites   13s ⏱️
819 tests 818 ✔️ 1 💤 0
831 runs  830 ✔️ 1 💤 0

Results for commit 392f97f.

@ebadiere ebadiere self-assigned this Apr 26, 2024
@ebadiere ebadiere added the dependencies Pull requests that update a dependency file label Apr 26, 2024
@ebadiere ebadiere added this to the 0.47.0 milestone Apr 26, 2024
@ebadiere ebadiere merged commit 87a3a52 into main Apr 26, 2024
29 of 32 checks passed
@ebadiere ebadiere deleted the snyk-fix-247eb28d0e64b23f73d2a025e1bc1b12 branch April 26, 2024 13:44
ebadiere added a commit that referenced this pull request Apr 26, 2024
Signed-off-by: ebadiere <ebadiere@gmail.com>
ebadiere added a commit that referenced this pull request Apr 26, 2024
Signed-off-by: ebadiere <ebadiere@gmail.com>
ebadiere added a commit that referenced this pull request Apr 26, 2024
Signed-off-by: ebadiere <ebadiere@gmail.com>
ebadiere added a commit that referenced this pull request Apr 26, 2024
Signed-off-by: ebadiere <ebadiere@gmail.com>
AlfredoG87 pushed a commit that referenced this pull request Apr 26, 2024
Signed-off-by: ebadiere <ebadiere@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

None yet

3 participants