microservices-demo icon indicating copy to clipboard operation
microservices-demo copied to clipboard

chore(deps): update docker

Open renovate-bot opened this issue 1 year ago • 0 comments

Mend Renovate

This PR contains the following updates:

Package Type Update Change
eclipse-temurin stage digest b87713d -> 9fcac9d
mcr.microsoft.com/dotnet/aspnet final digest 1d6ca86 -> 789045e
mcr.microsoft.com/dotnet/runtime-deps final patch 8.0.1-alpine3.18-amd64 -> 8.0.2-alpine3.18-amd64
mcr.microsoft.com/dotnet/sdk stage digest 8e77ad6 -> 4b684e6
mcr.microsoft.com/dotnet/sdk stage patch 8.0.101 -> 8.0.201
node final patch 20.11.0-alpine -> 20.11.1-alpine
python final digest eb53cb9 -> 5c73034

Release Notes

dotnet/runtime (mcr.microsoft.com/dotnet/runtime-deps)

v8.0.2: .NET 8.0.2

Compare Source

Release

dotnet/sdk (mcr.microsoft.com/dotnet/sdk)

v8.0.200: .NET 8.0.2

Compare Source

Release

nodejs/node (node)

v20.11.1: 2024-02-14, Version 20.11.1 'Iron' (LTS), @​RafaelGSS prepared by @​marco-ippolito

Compare Source

Notable changes

This is a security release.

Notable changes
  • CVE-2024-21892 - Code injection and privilege escalation through Linux capabilities- (High)
  • CVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High)
  • CVE-2024-21896 - Path traversal by monkey-patching Buffer internals- (High)
  • CVE-2024-22017 - setuid() does not drop all privileges due to io_uring - (High)
  • CVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium)
  • CVE-2024-21891 - Multiple permission model bypasses due to improper path traversal sequence sanitization - (Medium)
  • CVE-2024-21890 - Improper handling of wildcards in --allow-fs-read and --allow-fs-write (Medium)
  • CVE-2024-22025 - Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium)
  • undici version 5.28.3
  • libuv version 1.48.0
  • OpenSSL version 3.0.13+quic1
Commits

Configuration

📅 Schedule: Branch creation - "before 4am on Monday" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • [ ] If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

renovate-bot avatar Feb 19 '24 01:02 renovate-bot