[Snyk] Security upgrade golang from 1.12.4-alpine to 1.25.2-alpine#43
[Snyk] Security upgrade golang from 1.12.4-alpine to 1.25.2-alpine#43
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-ALPINE39-OPENSSL-588029 - https://snyk.io/vuln/SNYK-ALPINE39-OPENSSL-588029 - https://snyk.io/vuln/SNYK-ALPINE39-MUSL-458529 - https://snyk.io/vuln/SNYK-ALPINE39-MUSL-458529 - https://snyk.io/vuln/SNYK-ALPINE39-OPENSSL-1089231
Upgrade Hydra e2e Docker build base image to
|
|
Please mark whether you used AI to assist coding in this PR
|
There was a problem hiding this comment.
✨ PR Review
This PR upgrades the Go base image to address security vulnerabilities, but the target version appears to be invalid which would cause build failures.
1 issues detected:
🐞 Bug - Referencing a non-existent Docker image tag will cause build failures.
Details: The specified Go version 1.25.2-alpine does not exist in the official Go Docker registry. Go versioning has not reached 1.25.x and this would cause Docker build failures when trying to pull a non-existent image.
File:hydra/Dockerfile-e2e (1-1)
Generated by LinearB AI and added by gitStream.
AI-generated content may contain inaccuracies. Please verify before using. We'd love your feedback! 🚀
| @@ -1,4 +1,4 @@ | |||
| FROM golang:1.12.4-alpine | |||
| FROM golang:1.25.2-alpine | |||
There was a problem hiding this comment.
🐞 Bug - Invalid Go Version: Update to a valid and recent Go version such as golang:1.21-alpine or golang:1.20-alpine. Verify the version exists in the Docker Hub golang repository before finalizing the change.
| FROM golang:1.25.2-alpine | |
| FROM golang:1.21-alpine |
Snyk has created this PR to fix 3 vulnerabilities in the dockerfile dependencies of this project.
Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.
Snyk changed the following file(s):
hydra/Dockerfile-e2eWe recommend upgrading to
golang:1.25.2-alpine, as this image has only 3 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.Vulnerabilities that will be fixed with an upgrade:
SNYK-ALPINE39-OPENSSL-588029
SNYK-ALPINE39-OPENSSL-588029
SNYK-ALPINE39-MUSL-458529
SNYK-ALPINE39-MUSL-458529
SNYK-ALPINE39-OPENSSL-1089231
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 NULL Pointer Dereference