Skip to content

Conversation

@parseplatformorg
Copy link
Contributor

snyk-top-banner

Snyk has created this PR to fix 4 vulnerabilities in the dockerfile dependencies of this project.

Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Snyk changed the following file(s):

  • Dockerfile

We recommend upgrading to node:20.19.0-alpine3.20, as this image has only 0 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
low severity CVE-2025-26519
SNYK-ALPINE320-MUSL-8720638
  364  
low severity CVE-2024-9143
SNYK-ALPINE320-OPENSSL-8235201
  364  
low severity CVE-2024-9143
SNYK-ALPINE320-OPENSSL-8235201
  364  
low severity CVE-2024-13176
SNYK-ALPINE320-OPENSSL-8690013
  364  
low severity CVE-2024-12797
SNYK-ALPINE320-OPENSSL-8710359
  364  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@parse-github-assistant
Copy link

I will reformat the title to use the proper commit message syntax.

@parse-github-assistant parse-github-assistant bot changed the title [Snyk] Security upgrade node from 20.18.2-alpine3.20 to 20.19.0-alpine3.20 refactor: Security upgrade node from 20.18.2-alpine3.20 to 20.19.0-alpine3.20 Mar 16, 2025
@parse-github-assistant
Copy link

parse-github-assistant bot commented Mar 16, 2025

🚀 Thanks for opening this pull request!

@codecov
Copy link

codecov bot commented Mar 16, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 93.55%. Comparing base (b0388d5) to head (bec6dc6).
Report is 4 commits behind head on alpha.

Additional details and impacted files
@@           Coverage Diff           @@
##            alpha    #9652   +/-   ##
=======================================
  Coverage   93.55%   93.55%           
=======================================
  Files         186      186           
  Lines       14840    14840           
=======================================
  Hits        13883    13883           
  Misses        957      957           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mtrezza mtrezza changed the title refactor: Security upgrade node from 20.18.2-alpine3.20 to 20.19.0-alpine3.20 fix: Security upgrade node from 20.18.2-alpine3.20 to 20.19.0-alpine3.20 Mar 16, 2025
@mtrezza mtrezza merged commit 2be1a19 into alpha Mar 16, 2025
24 checks passed
@mtrezza mtrezza deleted the snyk-fix-4691708043f1168706933e76e09212d6 branch March 16, 2025 18:11
parseplatformorg pushed a commit that referenced this pull request Mar 16, 2025
## [8.0.1-alpha.2](8.0.1-alpha.1...8.0.1-alpha.2) (2025-03-16)

### Bug Fixes

* Security upgrade node from 20.18.2-alpine3.20 to 20.19.0-alpine3.20 ([#9652](#9652)) ([2be1a19](2be1a19))
@parseplatformorg
Copy link
Contributor Author

🎉 This change has been released in version 8.0.1-alpha.2

@parseplatformorg parseplatformorg added the state:released-alpha Released as alpha version label Mar 16, 2025
parseplatformorg pushed a commit that referenced this pull request Mar 17, 2025
## [8.0.1](8.0.0...8.0.1) (2025-03-17)

### Bug Fixes

* Security upgrade node from 20.18.2-alpine3.20 to 20.19.0-alpine3.20 ([#9652](#9652)) ([2be1a19](2be1a19))
* Using Parse Server option `extendSessionOnUse` does not correctly clear memory and functions as a debounce instead of a throttle ([#8683](#8683)) ([6258a6a](6258a6a))
@parseplatformorg
Copy link
Contributor Author

🎉 This change has been released in version 8.0.1

@parseplatformorg parseplatformorg added the state:released Released as stable version label Mar 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state:released Released as stable version state:released-alpha Released as alpha version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants