Skip to content

Conversation

@parseplatformorg
Copy link
Contributor

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

Snyk has created this PR to fix 2 vulnerabilities in the dockerfile dependencies of this project.

Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Snyk changed the following file(s):

  • Dockerfile

We recommend upgrading to node:20.14.0-alpine3.20, as this image has only 0 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
medium severity Use After Free
SNYK-ALPINE320-BUSYBOX-7233533
  586  
medium severity Use After Free
SNYK-ALPINE320-BUSYBOX-7233533
  586  
medium severity Use After Free
SNYK-ALPINE320-BUSYBOX-7233533
  586  
medium severity Use After Free
SNYK-ALPINE320-BUSYBOX-7233586
  586  
medium severity Use After Free
SNYK-ALPINE320-BUSYBOX-7233586
  586  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Use After Free

@parse-github-assistant
Copy link

I will reformat the title to use the proper commit message syntax.

@parse-github-assistant parse-github-assistant bot changed the title [Snyk] Security upgrade node from lts-alpine to 20.14.0-alpine3.20 refactor: Security upgrade node from lts-alpine to 20.14.0-alpine3.20 Jun 21, 2024
@parse-github-assistant
Copy link

Thanks for opening this pull request!

  • ❌ Please link an issue that describes the reason for this pull request, otherwise your pull request will be closed. Make sure to write it as Closes: #123 in the PR description, so I can recognize it.

@codecov
Copy link

codecov bot commented Jun 22, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 94.15%. Comparing base (42ff468) to head (d93162d).

Additional details and impacted files
@@            Coverage Diff             @@
##            alpha    #9160      +/-   ##
==========================================
+ Coverage   93.79%   94.15%   +0.35%     
==========================================
  Files         186      186              
  Lines       14726    14726              
==========================================
+ Hits        13812    13865      +53     
+ Misses        914      861      -53     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@mtrezza mtrezza merged commit e6be511 into alpha Jun 23, 2024
@mtrezza mtrezza deleted the snyk-fix-d14c13519b9053cfe7f9ddfd0f7ee70e branch June 23, 2024 17:01
@parseplatformorg
Copy link
Contributor Author

🎉 This change has been released in version 7.1.0-alpha.11

@parseplatformorg parseplatformorg added the state:released-alpha Released as alpha version label Jun 29, 2024
@parseplatformorg
Copy link
Contributor Author

🎉 This change has been released in version 7.1.0-beta.1

@parseplatformorg parseplatformorg added the state:released-beta Released as beta version label Jun 30, 2024
@parseplatformorg
Copy link
Contributor Author

🎉 This change has been released in version 7.1.0

@parseplatformorg parseplatformorg added the state:released Released as stable version label Jun 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state:released Released as stable version state:released-alpha Released as alpha version state:released-beta Released as beta version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants