Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade python from 3.8 to 3.8.12-slim-buster #3134

Merged
merged 1 commit into from Mar 4, 2022

Conversation

snyk-bot
Copy link
Contributor

@snyk-bot snyk-bot commented Mar 4, 2022

Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Changes included in this PR

  • ingestion/tests/integration/source/mlflow/Dockerfile

We recommend upgrading to python:3.8.12-slim-buster, as this image has only 80 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Some of the most important vulnerabilities in your base image include:

Severity Priority Score / 1000 Issue Exploit Maturity
critical severity 500 Release of Invalid Pointer or Reference
SNYK-DEBIAN11-AOM-1290331
No Known Exploit
critical severity 500 Use After Free
SNYK-DEBIAN11-AOM-1298721
No Known Exploit
critical severity 500 Buffer Overflow
SNYK-DEBIAN11-AOM-1300249
No Known Exploit
high severity 400 CVE-2022-0530
SNYK-DEBIAN11-UNZIP-2396444
No Known Exploit
high severity 400 Out-of-bounds Write
SNYK-DEBIAN11-UNZIP-2396445
No Known Exploit

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@pmbrull pmbrull self-requested a review March 4, 2022 06:37
@sonarcloud
Copy link

sonarcloud bot commented Mar 4, 2022

[open-metadata-ingestion] Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information

@pmbrull pmbrull merged commit 834bb8e into main Mar 4, 2022
@pmbrull pmbrull deleted the snyk-fix-7d60716af7727077f0b88b86c931685f branch March 4, 2022 07:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants