Skip to content

[Snyk] Security upgrade alpine from 3.9 to 3.18.12 - #654

Open
VaniHaripriya wants to merge 1 commit into
masterfrom
snyk-fix-ca8ca3aafc7f46c4c492bfd924a4bf0c
Open

[Snyk] Security upgrade alpine from 3.9 to 3.18.12#654
VaniHaripriya wants to merge 1 commit into
masterfrom
snyk-fix-ca8ca3aafc7f46c4c492bfd924a4bf0c

Conversation

@VaniHaripriya

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 3 vulnerabilities in the dockerfile dependencies of this project.

Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Snyk changed the following file(s):

  • backend/Dockerfile.conformance

We recommend upgrading to alpine:3.18.12, as this image has only 0 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
medium severity NULL Pointer Dereference
SNYK-ALPINE39-OPENSSL-1089231
  621  
medium severity NULL Pointer Dereference
SNYK-ALPINE39-OPENSSL-1089231
  621  
high severity Improper Certificate Validation
SNYK-ALPINE39-OPENSSL-1089232
  614  
high severity Improper Certificate Validation
SNYK-ALPINE39-OPENSSL-1089232
  614  
high severity Integer Overflow or Wraparound
SNYK-ALPINE39-OPENSSL-1089235
  614  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 NULL Pointer Dereference

@coderabbitai

coderabbitai Bot commented Nov 28, 2025

Copy link
Copy Markdown

Important

Review skipped

Ignore keyword(s) in the title.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch snyk-fix-ca8ca3aafc7f46c4c492bfd924a4bf0c

Tip

📝 Customizable high-level summaries are now available in beta!

You can now customize how CodeRabbit generates the high-level summary in your pull requests — including its content, structure, tone, and formatting.

  • Provide your own instructions using the high_level_summary_instructions setting.
  • Format the summary however you like (bullet lists, tables, multi-section layouts, contributor stats, etc.).
  • Use high_level_summary_in_walkthrough to move the summary from the description to the walkthrough section.

Example instruction:

"Divide the high-level summary into five sections:

  1. 📝 Description — Summarize the main change in 50–60 words, explaining what was done.
  2. 📓 References — List relevant issues, discussions, documentation, or related PRs.
  3. 📦 Dependencies & Requirements — Mention any new/updated dependencies, environment variable changes, or configuration updates.
  4. 📊 Contributor Summary — Include a Markdown table showing contributions:
    | Contributor | Lines Added | Lines Removed | Files Changed |
  5. ✔️ Additional Notes — Add any extra reviewer context.
    Keep each section concise (under 200 words) and use bullet or numbered lists for clarity."

Note: This feature is currently in beta for Pro-tier users, and pricing will be announced later.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actions Bot commented Nov 28, 2025

Copy link
Copy Markdown

Test Results

 1 files  ±0   1 suites  ±0   9m 26s ⏱️ + 1m 34s
72 tests ±0  33 ✅ +9  39 💤  - 9  0 ❌ ±0 
81 runs  ±0  42 ✅ +9  39 💤  - 9  0 ❌ ±0 

Results for commit 9a47d6e. ± Comparison against base commit f851ceb.

This pull request skips 23 and un-skips 32 tests.
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload component_with_pip_index_urls.yaml pipeline [FullRegression, E2EEssential]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload component_with_pip_install.yaml pipeline [FullRegression, E2EEssential]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload component_with_pip_install_in_venv.yaml pipeline [FullRegression, E2EEssential]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload concat_message.yaml pipeline [FullRegression, E2EEssential]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload container_no_input.yaml pipeline [FullRegression, E2EEssential]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload dict_input.yaml pipeline [FullRegression, E2EEssential]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload embedded_artifact.yaml pipeline [FullRegression, E2EEssential]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload iris_pipeline_compiled.yaml pipeline [FullRegression, E2EEssential]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload lightweight_python_functions_pipeline.yaml pipeline [FullRegression, E2EEssential]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload lightweight_python_functions_with_outputs.yaml pipeline [FullRegression, E2EEssential]
…
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload add_numbers.yaml pipeline [FullRegression, Sample, E2ECritical]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload artifact_cache.yaml pipeline [FullRegression, Sample, E2ECritical]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload artifact_crust.yaml pipeline [FullRegression, Sample, E2ECritical]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload collected_parameters.yaml pipeline [FullRegression, Sample, E2ECritical]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload component_with_optional_inputs.yaml pipeline [FullRegression, Sample, E2ECritical]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload container_component_with_no_inputs.yaml pipeline [FullRegression, Sample, E2ECritical]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload flip_coin.yaml pipeline [FullRegression, Sample, E2ECritical]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload loop_consume_upstream.yaml pipeline [FullRegression, Sample, E2ECritical]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload mixed_parameters.yaml pipeline [FullRegression, Sample, E2ECritical]
E2E Tests Suite ‑ [It] Upload and Verify Pipeline Run > Upload a pipeline file, run it and verify that pipeline run succeeds > Upload modelcar.yaml pipeline [FullRegression, Sample, E2ECritical]
…

♻️ This comment has been updated with latest results.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants