From 71af11d65980808dcb5e0b693426036108e92eb6 Mon Sep 17 00:00:00 2001 From: DeepSource Bot Date: Thu, 17 Feb 2022 07:15:48 +0000 Subject: [PATCH 1/2] Add .deepsource.toml --- .deepsource.toml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 .deepsource.toml diff --git a/.deepsource.toml b/.deepsource.toml new file mode 100644 index 00000000..539d831b --- /dev/null +++ b/.deepsource.toml @@ -0,0 +1,20 @@ +version = 1 + +[[analyzers]] +name = "python" +enabled = true + + [analyzers.meta] + runtime_version = "3.x.x" + +[[analyzers]] +name = "ruby" +enabled = true + +[[analyzers]] +name = "javascript" +enabled = true + +[[analyzers]] +name = "shell" +enabled = true From 0dbcb75648d4d68b4227274de78f243002151b6d Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 26 Apr 2022 01:41:28 +0000 Subject: [PATCH 2/2] fix: Dockerfile to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-UBUNTU1804-BASH-542613 - https://snyk.io/vuln/SNYK-UBUNTU1804-E2FSPROGS-2770723 - https://snyk.io/vuln/SNYK-UBUNTU1804-E2FSPROGS-2770723 - https://snyk.io/vuln/SNYK-UBUNTU1804-E2FSPROGS-2770723 - https://snyk.io/vuln/SNYK-UBUNTU1804-E2FSPROGS-2770723 --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index a25bbf46..1e838949 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ # Copyright 2017-2020 Fitbit, Inc # SPDX-License-Identifier: Apache-2.0 -FROM ubuntu:bionic +FROM ubuntu:latest # Upgrade any ubuntu packages RUN apt-get update && apt-get upgrade -y