[Snyk] Security upgrade golang from 1.12.4-alpine to 1.25.3-alpine#45
[Snyk] Security upgrade golang from 1.12.4-alpine to 1.25.3-alpine#45
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-ALPINE39-OPENSSL-588029 - https://snyk.io/vuln/SNYK-ALPINE39-OPENSSL-588029 - https://snyk.io/vuln/SNYK-ALPINE39-MUSL-458529 - https://snyk.io/vuln/SNYK-ALPINE39-MUSL-458529 - https://snyk.io/vuln/SNYK-ALPINE39-OPENSSL-1089231
Upgrade the
|
|
Please mark whether you used AI to assist coding in this PR
|
There was a problem hiding this comment.
✨ PR Review
This security upgrade attempts to update the Golang base image, but the target version appears to be invalid and would likely cause build failures.
1 issues detected:
🐞 Bug - The Docker image tag golang:1.25.3-alpine does not exist and will cause build failures.
Details: The specified Golang version 1.25.3-alpine does not exist as a valid Docker image tag. Go versions currently range up to approximately 1.21-1.22, making 1.25.3 a non-existent future version that will cause Docker build failures.
File:hydra/Dockerfile-e2e (1-1)
Generated by LinearB AI and added by gitStream.
AI-generated content may contain inaccuracies. Please verify before using. We'd love your feedback! 🚀
| @@ -1,4 +1,4 @@ | |||
| FROM golang:1.12.4-alpine | |||
| FROM golang:1.25.3-alpine | |||
There was a problem hiding this comment.
🐞 Bug - Invalid Docker Image: Verify the correct latest stable Golang version and update to a valid tag such as golang:1.21-alpine or golang:1.22-alpine instead of the non-existent 1.25.3-alpine.
| FROM golang:1.25.3-alpine | |
| FROM golang:1.21-alpine |
Snyk has created this PR to fix 3 vulnerabilities in the dockerfile dependencies of this project.
Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.
Snyk changed the following file(s):
hydra/Dockerfile-e2eWe recommend upgrading to
golang:1.25.3-alpine, as this image has only 0 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.Vulnerabilities that will be fixed with an upgrade:
SNYK-ALPINE39-OPENSSL-588029
SNYK-ALPINE39-OPENSSL-588029
SNYK-ALPINE39-MUSL-458529
SNYK-ALPINE39-MUSL-458529
SNYK-ALPINE39-OPENSSL-1089231
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 NULL Pointer Dereference