VilnaCRM-Org / user-service

Creative Commons Zero v1.0 Universal
5 stars 1 forks source link

[Snyk] Security upgrade caddy from 2.6-alpine to alpine #8

Closed Kravalg closed 5 months ago

Kravalg commented 6 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image. #### Changes included in this PR - Dockerfile We recommend upgrading to `caddy:alpine`, as this image has only 0 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected. Some of the most important vulnerabilities in your base image include: | Severity | Priority Score / 1000 | Issue | Exploit Maturity | | :------: | :-------------------- | :---- | :--------------- | | ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **514** | Inefficient Regular Expression Complexity
[SNYK-ALPINE316-OPENSSL-5788362](https://snyk.io/vuln/SNYK-ALPINE316-OPENSSL-5788362) | No Known Exploit | | ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **514** | Inefficient Regular Expression Complexity
[SNYK-ALPINE316-OPENSSL-5788362](https://snyk.io/vuln/SNYK-ALPINE316-OPENSSL-5788362) | No Known Exploit | | ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **514** | Excessive Iteration
[SNYK-ALPINE316-OPENSSL-5821140](https://snyk.io/vuln/SNYK-ALPINE316-OPENSSL-5821140) | No Known Exploit | | ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **514** | Excessive Iteration
[SNYK-ALPINE316-OPENSSL-5821140](https://snyk.io/vuln/SNYK-ALPINE316-OPENSSL-5821140) | No Known Exploit | | ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **514** | Improper Check for Unusual or Exceptional Conditions
[SNYK-ALPINE316-OPENSSL-6069876](https://snyk.io/vuln/SNYK-ALPINE316-OPENSSL-6069876) | No Known Exploit | --- **Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs._ For more information: 🧐 [View latest project report](https://app.snyk.io/org/kravalg/project/d08997f6-e9b9-4d0b-9d43-487363da8fcd?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/kravalg/project/d08997f6-e9b9-4d0b-9d43-487363da8fcd?utm_source=github&utm_medium=referral&page=fix-pr/settings) [//]: # 'snyk:metadata:{"prId":"bb80ceca-a77b-4935-af7d-4425942dd566","prPublicId":"bb80ceca-a77b-4935-af7d-4425942dd566","dependencies":[{"name":"caddy","from":"2.6-alpine","to":"alpine"}],"packageManager":"dockerfile","projectPublicId":"d08997f6-e9b9-4d0b-9d43-487363da8fcd","projectUrl":"https://app.snyk.io/org/kravalg/project/d08997f6-e9b9-4d0b-9d43-487363da8fcd?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-ALPINE316-OPENSSL-5788362","SNYK-ALPINE316-OPENSSL-5821140","SNYK-ALPINE316-OPENSSL-6069876"],"upgrade":["SNYK-ALPINE316-OPENSSL-5788362","SNYK-ALPINE316-OPENSSL-5788362","SNYK-ALPINE316-OPENSSL-5821140","SNYK-ALPINE316-OPENSSL-5821140","SNYK-ALPINE316-OPENSSL-6069876"],"isBreakingChange":false,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[514,514,514],"remediationStrategy":"vuln"}' --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Inefficient Regular Expression Complexity](https://learn.snyk.io/lesson/redos/?loc=fix-pr)
codecov[bot] commented 6 months ago

Codecov Report

All modified and coverable lines are covered by tests :white_check_mark:

:exclamation: No coverage uploaded for pull request base (main@c10468d). Click here to learn what that means.

Additional details and impacted files ```diff @@ Coverage Diff @@ ## main #8 +/- ## ======================================== Coverage ? 100.00% Complexity ? 1 ======================================== Files ? 1 Lines ? 2 Branches ? 0 ======================================== Hits ? 2 Misses ? 0 Partials ? 0 ``` | [Flag](https://app.codecov.io/gh/VilnaCRM-Org/user-service/pull/8/flags?src=pr&el=flags&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=VilnaCRM-Org) | Coverage Δ | | |---|---|---| | [unittests](https://app.codecov.io/gh/VilnaCRM-Org/user-service/pull/8/flags?src=pr&el=flag&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=VilnaCRM-Org) | `100.00% <ø> (?)` | | Flags with carried forward coverage won't be shown. [Click here](https://docs.codecov.io/docs/carryforward-flags?utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=VilnaCRM-Org#carryforward-flags-in-the-pull-request-comment) to find out more.

:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.

kukuruzvelt commented 5 months ago

Was already fixed in PR#7