wiktorn / Overpass-API

Overpass API docker image
MIT License
135 stars 48 forks source link

Updating base image #125

Closed krogebry closed 2 weeks ago

krogebry commented 3 weeks ago

We found lots of security problems in the built docker image. Bumping to latest nginx container seems to have fixed a lot of these. Still working on testing this fully, but it's looking better.

Wiz scanner found:

Vulnerable packages: CRITICAL: 12, HIGH: 40, MEDIUM: 28, LOW: 7, INFORMATIONAL: 0
    Total: 87
Vulnerabilities: CRITICAL: 25, HIGH: 104, MEDIUM: 298, LOW: 128, INFORMATIONAL: 10
    Total: 565, out of which 251 are fixable

Most old library things.