aws-samples / aws-workshop-for-kubernetes

AWS Workshop for Kubernetes
Apache License 2.0
2.66k stars 1.07k forks source link

Security upgrade node from boron to 14.21.3 #590

Open cloudgeek7 opened 1 year ago

cloudgeek7 commented 1 year ago

Changes included in this PR

We recommend upgrading to node:14.21.3, as this image has only 388 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Some of the most important vulnerabilities in your base image include:

Severity | Priority Score / 1000 | Issue | Exploit Maturity -- | -- | -- | -- Critical  | 714 | NULL Pointer DereferenceSNYK-DEBIAN9-IMAGEMAGICK-401678 | No Known Exploit Critical  | 714 | Out-of-bounds ReadSNYK-DEBIAN9-LIBXML2-429367 | No Known Exploit Critical  | 714 | Integer Overflow or WraparoundSNYK-DEBIAN9-MERCURIAL-311063 | No Known Exploit Critical  | 714 | OS Command InjectionSNYK-DEBIAN9-MERCURIAL-311070 | No Known Exploit Critical  | 714 | Incorrect Permission Assignment for Critical ResourceSNYK-DEBIAN9-MERCURIAL-311113 | No Known Exploit