Skip to content

fix: Dockerfile to reduce vulnerabilities

01c1e8f
Select commit
Loading
Failed to load commit list.
Open

[Snyk] Security upgrade python from 3.12.0rc2-alpine to 3.14.0a1-alpine #35

fix: Dockerfile to reduce vulnerabilities
01c1e8f
Select commit
Loading
Failed to load commit list.
Debricked / Vulnerability analysis completed Dec 26, 2024 in 13s

An automation triggered a pipeline warning

Found 9 vulnerabilities. An additional 0 vulnerabilities have been marked as unaffected.

Output from Automations

4 rules were checked:


If a new dependency is added where the license risk is at least medium

then notify all users in the group admins by email

✔️ The rule did not trigger. Manage rule



If a dependency contains a vulnerability which has not been marked as unaffected and which has not triggered this rule for this dependency before

then notify all users in the group admins by email

✔️ The rule did not trigger. Manage rule



If there is a dependency where the license risk is at least high

then send a pipeline warning

✔️ The rule did not trigger. Manage rule



If a dependency contains a vulnerability which has not been marked as unaffected

then send a pipeline warning

⚠️ The rule triggered for the following vulnerabilities, causing a pipeline warning. Manage rule

Vulnerability CVSS2 CVSS3 Dependency Dependency Licenses
CVE-2023-49083 N/A 7.5 cryptography (pip) BSD-3-Clause
CVE-2023-50782 N/A 7.5 cryptography (pip) BSD-3-Clause
CVE-2024-26130 N/A 7.5 cryptography (pip) BSD-3-Clause
CVE-2024-52804 N/A 7.5 tornado (pip) Apache-2.0
CVE-2023-48795 N/A 5.9 paramiko (pip) LGPL-2.0-or-later, LGPL-2.1-or-later
CVE-2024-0727 N/A 5.5 cryptography (pip) BSD-3-Clause
debricked-258644 N/A N/A tornado (pip) Apache-2.0
debricked-258645 N/A N/A tornado (pip) Apache-2.0
debricked-267656 N/A N/A cryptography (pip) BSD-3-Clause