Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade ubuntu from 22.04 to 22.10 #218

Closed
wants to merge 275 commits into from

Conversation

rdnt
Copy link
Owner

@rdnt rdnt commented Jul 4, 2023

✨ Snyk has automatically assigned this pull request, set who gets assigned.

As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.

Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Changes included in this PR

  • Dockerfile

We recommend upgrading to ubuntu:22.10, as this image has only 10 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Some of the most important vulnerabilities in your base image include:

Severity Issue Exploit Maturity
low severity Out-of-bounds Write
SNYK-UBUNTU2204-BASH-3098342
No Known Exploit
low severity Improper Input Validation
SNYK-UBUNTU2204-COREUTILS-2801226
No Known Exploit
low severity Allocation of Resources Without Limits or Throttling
SNYK-UBUNTU2204-GLIBC-2801292
No Known Exploit
low severity Memory Leak
SNYK-UBUNTU2204-LIBCAP2-5538282
No Known Exploit
medium severity CVE-2023-2603
SNYK-UBUNTU2204-LIBCAP2-5538296
No Known Exploit

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Memory Leak
🦉 Allocation of Resources Without Limits or Throttling

rdnt and others added 30 commits March 31, 2020 08:28
Trigger gh-pages build on push to master
Bumps [github.com/gookit/color](https://github.com/gookit/color) from 1.2.3 to 1.2.4.
- [Release notes](https://github.com/gookit/color/releases)
- [Commits](gookit/color@v1.2.3...v1.2.4)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [github.com/go-errors/errors](https://github.com/go-errors/errors) from 1.0.1 to 1.0.2.
- [Release notes](https://github.com/go-errors/errors/releases)
- [Commits](go-errors/errors@v1.0.1...v1.0.2)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
rdnt and others added 26 commits June 1, 2023 14:13
* Remove debug log, disable favicon for edit entry modal
* Fix messages in bg not visible
* Improve form handling for keystore creation
* Fix show errors form handling
* Form handling on register modal
* Fix issue with invitations page breaking UI right after registration, remove logging
* Refine keystore routing, refine authstate store
* Allow deletion of accepted (but not finalized) invitation
* Disable revocation for now
* Cleanup
* Keystore deletion
* fix keystore name trim on creation
* Allow test suites to run in parallel
Pkgs error handling, cleanup unused pkgs
* Refine error handling on server domain and application
* Fix various access control issues
* Safeguard around functional opts being nil
* Refine error handling on storage adapters
* Refine server's rest API
* Fix test suites
* Add golangci-lint on CI
* Fix golangci-lint suggestions
* Add .gitkeep & keep it when building
* Update generated files
Bumps [github.com/gin-gonic/gin](https://github.com/gin-gonic/gin) from 1.9.0 to 1.9.1.
- [Release notes](https://github.com/gin-gonic/gin/releases)
- [Changelog](https://github.com/gin-gonic/gin/blob/master/CHANGELOG.md)
- [Commits](gin-gonic/gin@v1.9.0...v1.9.1)

---
updated-dependencies:
- dependency-name: github.com/gin-gonic/gin
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 4.1.4 to 4.1.5.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/v4.1.5/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v4.1.5/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [go.mongodb.org/mongo-driver](https://github.com/mongodb/mongo-go-driver) from 1.11.6 to 1.11.7.
- [Release notes](https://github.com/mongodb/mongo-go-driver/releases)
- [Commits](mongodb/mongo-go-driver@v1.11.6...v1.11.7)

---
updated-dependencies:
- dependency-name: go.mongodb.org/mongo-driver
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/go-co-op/gocron](https://github.com/go-co-op/gocron) from 1.27.0 to 1.28.3.
- [Release notes](https://github.com/go-co-op/gocron/releases)
- [Commits](go-co-op/gocron@v1.27.0...v1.28.3)

---
updated-dependencies:
- dependency-name: github.com/go-co-op/gocron
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/deepmap/oapi-codegen](https://github.com/deepmap/oapi-codegen) from 1.12.4 to 1.13.0.
- [Release notes](https://github.com/deepmap/oapi-codegen/releases)
- [Commits](oapi-codegen/oapi-codegen@v1.12.4...v1.13.0)

---
updated-dependencies:
- dependency-name: github.com/deepmap/oapi-codegen
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.9.0 to 0.10.0.
- [Commits](golang/crypto@v0.9.0...v0.10.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Refine client domain
* Refine user domain entity
* Depend on lint to bail CI early
* Refine app
* Cleanup app ifaces
* Refine error handling on application
* Cleanup enclaverepo
* Refine error handling on enclaverepo
* Fix dependency between enclaverepo and remote
* Move remote-related encryption to remote module
* Refine error handling on remote adapter
* Partially refine rest http server port
* Fix sync bug
* Fix test suites
* Improve golangci-lint
* Refine rest api returned errors
* Organize client rest api file structure & cleanup middleware
* Parallelize all tests
* Add some error handling on keystores/invitations
* Remove metrics endpoint
* Fix lint
* Refine applications startup
* Remove config pkg
* Fix shutdown error
* Refine shared secrets calculations
* Move keypair generation to enclave
* Fix invitations count on sidebar
* Refine invitations page statuses
* Cleanup routers
* Some more error handling
* Silent authentication cronjob
Bumps [github.com/otiai10/copy](https://github.com/otiai10/copy) from 1.11.0 to 1.12.0.
- [Release notes](https://github.com/otiai10/copy/releases)
- [Commits](otiai10/copy@v1.11.0...v1.12.0)

---
updated-dependencies:
- dependency-name: github.com/otiai10/copy
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@rdnt rdnt self-assigned this Jul 4, 2023
@rdnt rdnt closed this Aug 30, 2023
@rdnt rdnt deleted the snyk-fix-eac6de080c132e96d3d9be7df500cd6b branch August 30, 2023 17:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants