-
Notifications
You must be signed in to change notification settings - Fork 712
Commit 68eed17
authored
[Snyk] Security upgrade nginx from 1.21-alpine to 1.25.3-alpine (#10007)
<p>This PR was automatically created by Snyk using the credentials of a
real user.</p><br />Keeping your Docker base image up-to-date means
you’ll benefit from security fixes in the latest version of your chosen
image.
#### Changes included in this PR
- tools/debug-ui/Dockerfile
We recommend upgrading to `nginx:1.25.3-alpine`, as this image has only
0 known vulnerabilities. To do this, merge this pull request, then
verify your application still works as expected.
Some of the most important vulnerabilities in your base image include:
| Severity | Priority Score / 1000 | Issue | Exploit Maturity |
| :------: | :-------------------- | :---- | :--------------- |
|  | **714** | Cleartext Transmission of Sensitive
Information
<br/>[SNYK-ALPINE315-CURL-3320718](https://snyk.io/vuln/SNYK-ALPINE315-CURL-3320718)
| No Known Exploit |
|  | **817** | Heap-based Buffer Overflow
<br/>[SNYK-ALPINE315-CURL-5958915](https://snyk.io/vuln/SNYK-ALPINE315-CURL-5958915)
| Proof of Concept |
|  | **817** | Heap-based Buffer Overflow
<br/>[SNYK-ALPINE315-CURL-5958915](https://snyk.io/vuln/SNYK-ALPINE315-CURL-5958915)
| Proof of Concept |
|  | **829** | Out-of-bounds Write
<br/>[SNYK-ALPINE315-LIBWEBP-5902238](https://snyk.io/vuln/SNYK-ALPINE315-LIBWEBP-5902238)
| Mature |
|  | **900** | Resource Exhaustion
<br/>[SNYK-ALPINE315-NGHTTP2-5964211](https://snyk.io/vuln/SNYK-ALPINE315-NGHTTP2-5964211)
| Mature |
---
**Note:** _You are seeing this because you or someone else with access
to this repository has authorized Snyk to open fix PRs._
For more information: <img
src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiJkODIyMjE2Yi0zNzg0LTRlMzAtYTM2Ny1iMzgxYzU0NTJiY2YiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6ImQ4MjIyMTZiLTM3ODQtNGUzMC1hMzY3LWIzODFjNTQ1MmJjZiJ9fQ=="
width="0" height="0"/>
🧐 [View latest project
report](https://app.snyk.io/org/ekleog-near/project/c9e60cf1-828f-4594-931a-b7d2f62f8d62?utm_source=github&utm_medium=referral&page=fix-pr)
🛠 [Adjust project
settings](https://app.snyk.io/org/ekleog-near/project/c9e60cf1-828f-4594-931a-b7d2f62f8d62?utm_source=github&utm_medium=referral&page=fix-pr/settings)
[//]: #
'snyk:metadata:{"prId":"d822216b-3784-4e30-a367-b381c5452bcf","prPublicId":"d822216b-3784-4e30-a367-b381c5452bcf","dependencies":[{"name":"nginx","from":"1.21-alpine","to":"1.25.3-alpine"}],"packageManager":"dockerfile","projectPublicId":"c9e60cf1-828f-4594-931a-b7d2f62f8d62","projectUrl":"https://app.snyk.io/org/ekleog-near/project/c9e60cf1-828f-4594-931a-b7d2f62f8d62?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-ALPINE315-NGHTTP2-5964211","SNYK-ALPINE315-LIBWEBP-5902238","SNYK-ALPINE315-CURL-5958915","SNYK-ALPINE315-CURL-3320718"],"upgrade":["SNYK-ALPINE315-CURL-3320718","SNYK-ALPINE315-CURL-5958915","SNYK-ALPINE315-CURL-5958915","SNYK-ALPINE315-LIBWEBP-5902238","SNYK-ALPINE315-NGHTTP2-5964211"],"isBreakingChange":false,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[900,829,817,714],"remediationStrategy":"vuln"}'
---
**Learn how to fix vulnerabilities with free interactive lessons:**
🦉 [Resource
Exhaustion](https://learn.snyk.io/lesson/redos/?loc=fix-pr)File tree
Expand file treeCollapse file tree
0 file changed
+0
-0
lines changedFilter options
Expand file treeCollapse file tree
0 file changed
+0
-0
lines changed
0 commit comments