cvat icon indicating copy to clipboard operation
cvat copied to clipboard

[Snyk] Security upgrade nginx from mainline-alpine to 1.25.3-alpine3.18

Open nmanovic opened this issue 1 year ago • 1 comments

This PR was automatically created by Snyk using the credentials of a real user.


Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Changes included in this PR

  • Dockerfile.ui

We recommend upgrading to nginx:1.25.3-alpine3.18, as this image has only 0 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Some of the most important vulnerabilities in your base image include:

Severity Issue Exploit Maturity
medium severity Missing Encryption of Sensitive Data
SNYK-ALPINE318-CURL-6104720
No Known Exploit
medium severity Missing Encryption of Sensitive Data
SNYK-ALPINE318-CURL-6104720
No Known Exploit
medium severity CVE-2023-46218
SNYK-ALPINE318-CURL-6104721
No Known Exploit
medium severity CVE-2023-46218
SNYK-ALPINE318-CURL-6104721
No Known Exploit

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

nmanovic avatar Dec 22 '23 15:12 nmanovic

Codecov Report

Merging #7289 (c8424d6) into develop (f513aa1) will decrease coverage by 0.01%. The diff coverage is n/a.

Additional details and impacted files
@@             Coverage Diff             @@
##           develop    #7289      +/-   ##
===========================================
- Coverage    83.47%   83.46%   -0.01%     
===========================================
  Files          373      373              
  Lines        39739    39739              
  Branches      3741     3741              
===========================================
- Hits         33171    33168       -3     
- Misses        6568     6571       +3     
Components Coverage Δ
cvat-ui 79.27% <ø> (-0.02%) :arrow_down:
cvat-server 87.32% <ø> (-0.01%) :arrow_down:

codecov[bot] avatar Dec 22 '23 16:12 codecov[bot]

mainline-alpine has less vulnerabilities according to dockerhub.

image image

bsekachev avatar Apr 17 '24 06:04 bsekachev