andrewmkrug / dashy

MIT License
0 stars 0 forks source link

[Snyk] Security upgrade nginx from alpine to 1.25.4-alpine3.18 #137

Closed andrewmkrug closed 6 months ago

andrewmkrug commented 7 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image. #### Changes included in this PR - docker/Dockerfile-lite We recommend upgrading to `nginx:1.25.4-alpine3.18`, as this image has only 0 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected. Some of the most important vulnerabilities in your base image include: | Severity | Priority Score / 1000 | Issue | Exploit Maturity | | :------: | :-------------------- | :---- | :--------------- | | ![low severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/l.png "low severity") | **436** | CVE-2024-28757
[SNYK-ALPINE318-EXPAT-6446356](https://snyk.io/vuln/SNYK-ALPINE318-EXPAT-6446356) | No Known Exploit | --- **Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs._ For more information: 🧐 [View latest project report](https://app.snyk.io/org/andrewmkrug/project/765b00b5-30b4-4c89-af53-13d0895aa81b?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/andrewmkrug/project/765b00b5-30b4-4c89-af53-13d0895aa81b?utm_source=github&utm_medium=referral&page=fix-pr/settings) [//]: # 'snyk:metadata:{"prId":"1579385b-ccec-460d-b7b3-5598958a34b0","prPublicId":"1579385b-ccec-460d-b7b3-5598958a34b0","dependencies":[{"name":"nginx","from":"alpine","to":"1.25.4-alpine3.18"}],"packageManager":"dockerfile","projectPublicId":"765b00b5-30b4-4c89-af53-13d0895aa81b","projectUrl":"https://app.snyk.io/org/andrewmkrug/project/765b00b5-30b4-4c89-af53-13d0895aa81b?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-ALPINE318-EXPAT-6446356"],"upgrade":["SNYK-ALPINE318-EXPAT-6446356"],"isBreakingChange":false,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[436],"remediationStrategy":"vuln"}' --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Learn about vulnerability in an interactive lesson of Snyk Learn.](https://learn.snyk.io/?loc=fix-pr)
netlify[bot] commented 7 months ago

Deploy Preview for peppy-choux-edbc1e ready!

Name Link
Latest commit bc1355f2f0f40065d9e5632d31b76e0e5af38f56
Latest deploy log https://app.netlify.com/sites/peppy-choux-edbc1e/deploys/65f707faf2e0a500082e97fa
Deploy Preview https://deploy-preview-137--peppy-choux-edbc1e.netlify.app
Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

github-actions[bot] commented 6 months ago

This PR is stale because it has been open 6 weeks with no activity. Either remove the stale label or comment below with a short update, otherwise this PR will be closed in 5 days.

github-actions[bot] commented 6 months ago

This pull request was automatically closed because it has been stalled for over 6 weeks with no activity.