deep-dream-maker icon indicating copy to clipboard operation
deep-dream-maker copied to clipboard

[Snyk] Security upgrade nginx from alpine to 1.20-alpine

Open snyk-bot opened this issue 2 years ago • 1 comments

Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Changes included in this PR

  • webapp/Dockerfile.prod

We recommend upgrading to nginx:1.20-alpine, as this image has only 2 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Some of the most important vulnerabilities in your base image include:

Severity Priority Score / 1000 Issue Exploit Maturity
high severity 400 Out-of-bounds Read
SNYK-ALPINE315-FREETYPE-2834869
No Known Exploit
high severity 400 Out-of-bounds Read
SNYK-ALPINE315-FREETYPE-2834870
No Known Exploit
critical severity 571 Out-of-bounds Read
SNYK-ALPINE315-PCRE2-2869383
No Known Exploit
critical severity 571 Out-of-bounds Read
SNYK-ALPINE315-PCRE2-2869384
No Known Exploit

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

snyk-bot avatar Jun 17 '22 10:06 snyk-bot

Codecov Report

Merging #71 (c270d6f) into dev-2.0 (8cf68d8) will not change coverage. The diff coverage is n/a.

@@           Coverage Diff            @@
##           dev-2.0      #71   +/-   ##
========================================
  Coverage    79.71%   79.71%           
========================================
  Files           18       18           
  Lines          276      276           
========================================
  Hits           220      220           
  Misses          56       56           

:mega: Codecov can now indicate which changes are the most critical in Pull Requests. Learn more

codecov[bot] avatar Jun 17 '22 10:06 codecov[bot]