Skip to content

[Snyk] Security upgrade alpine from 3.9 to 3.19.4#40

Open
ayoinc wants to merge 1 commit into
masterfrom
snyk-fix-aadae49be7a1628306d2c864a0012526
Open

[Snyk] Security upgrade alpine from 3.9 to 3.19.4#40
ayoinc wants to merge 1 commit into
masterfrom
snyk-fix-aadae49be7a1628306d2c864a0012526

Conversation

@ayoinc

@ayoinc ayoinc commented Sep 8, 2024

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 3 vulnerabilities in the dockerfile dependencies of this project.

Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Snyk changed the following file(s):

  • docker/Dockerfile.flux

We recommend upgrading to alpine:3.19.4, as this image has only 0 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Improper Certificate Validation
SNYK-ALPINE39-OPENSSL-1089232
  614  
high severity Improper Certificate Validation
SNYK-ALPINE39-OPENSSL-1089232
  614  
high severity Integer Overflow or Wraparound
SNYK-ALPINE39-OPENSSL-1089235
  614  
high severity Integer Overflow or Wraparound
SNYK-ALPINE39-OPENSSL-1089235
  614  
medium severity Out-of-bounds Write
SNYK-ALPINE39-MUSL-1042761
  514  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@sonarqubecloud

sonarqubecloud Bot commented Sep 8, 2024

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
2 Security Hotspots
D Maintainability Rating on New Code (required ≥ A)

See analysis details on SonarCloud

Catch issues before they fail your Quality Gate with our IDE extension SonarLint

@iacbot

iacbot Bot commented Sep 8, 2024

Copy link
Copy Markdown

🔍 Lacework analyzed your pull request. Here is the summary.

Static Analysis: ⚠️ Found 44 violations in this pull request.
  • Critical : 0
  • High : 6
  • Medium : 14
  • Low : 24
  • Info : 0
Violation Severity File Guidelines
Minimize wildcard use in Roles and ClusterRoles High rbac.yaml VIEW
Minimize wildcard use in Roles and ClusterRoles High kustomization.yaml VIEW
Use read-only filesystem for containers where possible High kustomization.yaml VIEW
Use read-only filesystem for containers where possible High memcached.yaml VIEW
Use read-only filesystem for containers where possible High deployment.yaml VIEW
Use read-only filesystem for containers where possible High kustomization.yaml VIEW
CPU requests should be set Medium kustomization.yaml VIEW
Image Pull Policy should be Always Medium kustomization.yaml VIEW
Image Pull Policy should be Always Medium memcached.yaml VIEW
Image Pull Policy should be Always Medium kustomization.yaml VIEW
Image Pull Policy should be Always Medium deployment.yaml VIEW
Memory limits should be set Medium memcached.yaml VIEW
Memory limits should be set Medium kustomization.yaml VIEW
Memory limits should be set Medium kustomization.yaml VIEW
Memory limits should be set Medium deployment.yaml VIEW
Memory requests should be set Medium kustomization.yaml VIEW
Minimize the admission of containers with capabilities assigned Medium deployment.yaml VIEW
Minimize the admission of containers with capabilities assigned Medium kustomization.yaml VIEW
Minimize the admission of containers with capabilities assigned Medium memcached.yaml VIEW
Minimize the admission of containers with capabilities assigned Medium kustomization.yaml VIEW
Ensure that Service Account Tokens are only mounted where necessary Low kustomization.yaml VIEW
Ensure that Service Account Tokens are only mounted where necessary Low memcached.yaml VIEW
Ensure that Service Account Tokens are only mounted where necessary Low kustomization.yaml VIEW
Ensure that Service Account Tokens are only mounted where necessary Low deployment.yaml VIEW
Ensure that the seccomp profile is set to docker/default or runtime/default Low kustomization.yaml VIEW
Ensure that the seccomp profile is set to docker/default or runtime/default Low deployment.yaml VIEW
Ensure that the seccomp profile is set to docker/default or runtime/default Low kustomization.yaml VIEW
Ensure that the seccomp profile is set to docker/default or runtime/default Low memcached.yaml VIEW
Liveness Probe Should be Configured Low kustomization.yaml VIEW
Liveness Probe Should be Configured Low memcached.yaml VIEW
Readiness Probe Should be Configured Low memcached.yaml VIEW
Readiness Probe Should be Configured Low kustomization.yaml VIEW
The default namespace should not be used Low serviceaccount.yaml VIEW
The default namespace should not be used Low service.yaml VIEW
The default namespace should not be used Low memcached.yaml VIEW
The default namespace should not be used Low deployment.yaml VIEW
The default namespace should not be used Low secret.yaml VIEW
The default namespace should not be used Low kustomization.yaml VIEW
The default namespace should not be used Low kube.yaml VIEW
The default namespace should not be used Low kustomization.yaml VIEW
The default namespace should not be used Low kustomization.yaml VIEW
The default namespace should not be used Low memcached.yaml VIEW
The default namespace should not be used Low kustomization.yaml VIEW
The default namespace should not be used Low kustomization.yaml VIEW

💬 Share your feedback with us.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants