atomist-skills / docker-build-skill

Atomist Skill to build and push Docker images
Apache License 2.0
1 stars 0 forks source link

Re-pin Docker base image in Dockerfile #370

Closed atomist[bot] closed 2 years ago

atomist[bot] commented 2 years ago

This pull request re-pins the Docker base image atomist/skill:node14 in Dockerfile to the current digest.

https://github.com/atomist-skills/docker-build-skill/blob/3e2edf462a2b78f1b17b84788ff3ea9ca580ed62/Dockerfile#L15-L15

Changelog for atomist/skill:node14

### Comparison Comparing Docker image `atomist/skill:node14` at digests _Current_ `sha256:db10ee511fd4230a006b620ab4cf471e4e58884c5ff4cf1fc47909b1c576a1f5` (645mb) and _Proposed_ `sha256:a3916207013fc09f93a2a0207dde84a9e82f3ede620245e4fd1718acbc502cbe` (645mb): #### Packages The following package differences were detected: | Name | Current | Proposed | Type | | ---- | ------- | -------- | ---- | | `distro-info-data` | `0.46ubuntu4` | `0.46ubuntu4.2` | Apt | | `tzdata` | `2021a-1ubuntu1` | `2021a-2ubuntu0.21.04` | Apt | #### Files The following file modifications were detected: | Name | Current | Proposed | Diff | | ---- | ------- | -------- | ---- | | `/root/.config/configstore/update-notifier-npm.json` | `55b` | `55b` | `0b` | | `/usr/lib/node_modules/@atomist/skill` (1116 files changed) | `14mb` | `15mb` | `890kb` | | `/usr/lib/python3.9/__pycache__/_markupbase.cpython-39.pyc` | `7.6kb` | `7.6kb` | `0b` | | `/usr/lib/python3.9/__pycache__/ftplib.cpython-39.pyc` | `28kb` | `28kb` | `0b` | | `/usr/lib/python3.9/__pycache__/gettext.cpython-39.pyc` | `18kb` | `18kb` | `0b` | | `/usr/lib/python3.9/__pycache__/hashlib.cpython-39.pyc` | `6.5kb` | `6.5kb` | `0b` | | `/usr/lib/python3.9/__pycache__/mailbox.cpython-39.pyc` | `59kb` | `59kb` | `0b` | | `/usr/lib/python3.9/__pycache__/netrc.cpython-39.pyc` | `3.7kb` | `3.7kb` | `0b` | | `/usr/lib/python3.9/__pycache__/nntplib.cpython-39.pyc` | `31kb` | `31kb` | `0b` | | `/usr/lib/python3.9/__pycache__/pathlib.cpython-39.pyc` | `44kb` | `44kb` | `0b` | | `/usr/lib/python3.9/__pycache__/pydoc.cpython-39.pyc` | `83kb` | `83kb` | `0b` | | `/usr/lib/python3.9/__pycache__/rlcompleter.cpython-39.pyc` | `5.6kb` | `5.6kb` | `0b` | | `/usr/lib/python3.9/__pycache__/socket.cpython-39.pyc` | `28kb` | `28kb` | `0b` | | `/usr/lib/python3.9/__pycache__/tarfile.cpython-39.pyc` | `62kb` | `62kb` | `0b` | | `/usr/lib/python3.9/__pycache__/typing.cpython-39.pyc` | `70kb` | `70kb` | `0b` | | `/usr/lib/python3.9/__pycache__/zipfile.cpython-39.pyc` | `58kb` | `58kb` | `0b` | | `/usr/lib/python3.9/asyncio/__pycache__` (2 files changed) | `54kb` | `54kb` | `0b` | | `/usr/lib/python3.9/email/__pycache__/message.cpython-39.pyc` | `37kb` | `37kb` | `0b` | | `/usr/lib/python3.9/http/__pycache__/client.cpython-39.pyc` | `34kb` | `34kb` | `0b` | | `/usr/lib/python3.9/unittest/__pycache__/mock.cpython-39.pyc` | `76kb` | `76kb` | `0b` | | `/usr/lib/python3.9/wsgiref/__pycache__` (2 files changed) | `21kb` | `21kb` | `0b` | | `/usr/share/distro-info/ubuntu.csv` | `2.3kb` | `2.3kb` | `0b` | | `/usr/share/doc/tzdata/changelog.Debian.gz` | `1.4kb` | `1.4kb` | `52b` | | `/usr/share/zoneinfo-icu/44/be` (4 files changed) | `235kb` | `236kb` | `1.5kb` | | `/usr/share/zoneinfo-icu/44/le` (4 files changed) | `235kb` | `236kb` | `1.5kb` | | `/usr/share/zoneinfo/Asia/Amman` | `1.8kb` | `1.8kb` | `0b` | | `/usr/share/zoneinfo/Pacific/Apia` | `1.1kb` | `612b` | `-485b` | | `/usr/share/zoneinfo/leap-seconds.list` | `10kb` | `10kb` | `-7b` | | `/usr/share/zoneinfo/leapseconds` | `3.3kb` | `3.3kb` | `-4b` | | `/usr/share/zoneinfo/posix/Asia/Amman` | `1.8kb` | `1.8kb` | `0b` | | `/usr/share/zoneinfo/posix/Pacific/Apia` | `1.1kb` | `612b` | `-485b` | | `/usr/share/zoneinfo/right/Africa` (20 files changed) | `23kb` | `23kb` | `70b` | | `/usr/share/zoneinfo/right/America` (130 files changed) | `226kb` | `227kb` | `910b` | | `/usr/share/zoneinfo/right/Antarctica` (10 files changed) | `11kb` | `11kb` | `28b` | | `/usr/share/zoneinfo/right/Asia` (77 files changed) | `105kb` | `105kb` | `126b` | | `/usr/share/zoneinfo/right/Atlantic` (9 files changed) | `18kb` | `18kb` | `70b` | | `/usr/share/zoneinfo/right/Australia` (11 files changed) | `18kb` | `18kb` | `84b` | | `/usr/share/zoneinfo/right/CET` | `2.1kb` | `2.1kb` | `14b` | | `/usr/share/zoneinfo/right/CST6CDT` | `2.3kb` | `2.4kb` | `14b` | | `/usr/share/zoneinfo/right/EET` | `1.9kb` | `2.0kb` | `14b` | | `/usr/share/zoneinfo/right/EST` | `664b` | `664b` | `0b` | | `/usr/share/zoneinfo/right/EST5EDT` | `2.3kb` | `2.4kb` | `14b` | | `/usr/share/zoneinfo/right/Etc` (28 files changed) | `18kb` | `18kb` | `0b` | | `/usr/share/zoneinfo/right/Europe` (46 files changed) | `107kb` | `107kb` | `490b` | | `/usr/share/zoneinfo/right/Factory` | `664b` | `664b` | `0b` | | `/usr/share/zoneinfo/right/HST` | `664b` | `664b` | `0b` | | `/usr/share/zoneinfo/right/Indian` (8 files changed) | `5.6kb` | `5.6kb` | `0b` | | `/usr/share/zoneinfo/right/MET` | `2.1kb` | `2.1kb` | `14b` | | `/usr/share/zoneinfo/right/MST` | `664b` | `664b` | `0b` | | `/usr/share/zoneinfo/right/MST7MDT` | `2.3kb` | `2.4kb` | `14b` | | `/usr/share/zoneinfo/right/PST8PDT` | `2.3kb` | `2.4kb` | `14b` | | `/usr/share/zoneinfo/right/Pacific` (36 files changed) | `33kb` | `33kb` | `56b` | | `/usr/share/zoneinfo/right/WET` | `1.9kb` | `2.0kb` | `14b` | | `/usr/share/zoneinfo/tzdata.zi` | `111kb` | `111kb` | `36b` | | `/var/cache/ldconfig/aux-cache` | `9.9kb` | `9.9kb` | `0b` | | `/var/lib/dpkg/info/distro-info-data.md5sums` | `366b` | `366b` | `0b` | | `/var/lib/dpkg/info/tzdata.md5sums` | `84kb` | `84kb` | `0b` | | `/var/lib/dpkg/info/tzdata.postrm` | `312b` | `312b` | `0b` | | `/var/lib/dpkg/status` | `235kb` | `235kb` | `8b` | | `/var/lib/dpkg/status-old` | `235kb` | `235kb` | `8b` | | `/var/log/alternatives.log` | `9.1kb` | `9.1kb` | `0b` | | `/var/log/apt/eipp.log.xz` | `11kb` | `11kb` | `12b` | | `/var/log/apt/history.log` | `24kb` | `24kb` | `8b` | | `/var/log/apt/term.log` | `41kb` | `41kb` | `24b` | | `/var/log/dpkg.log` | `226kb` | `226kb` | `56b` | #### History No differences in [`docker history`](https://docs.docker.com/engine/reference/commandline/history/) detected #### Ports No different exposed ports detected #### Environment Variables No different environment variables detected


Pinning FROM lines to digests makes your builds repeatable. Atomist will raise new pull requests whenever the tag moves, so that you know when the base image has been updated. You can follow a new tag at any time. Just replace the digest with the new tag you want to follow. Atomist, will switch to following this new tag.


File changed:

atomist[bot] commented 2 years ago
Vulnerabilities
Comparison

👏 No new critical or high vulnerabilities compared with target branch main 👏 No new critical or high vulnerabilities compared with unstable 🎉 Fixes 4 high severity vulnerabilities compared with stable


More details are available in the vulnerability report

atomist[bot] commented 2 years ago

Pull request auto merged: