From e1aa6fb1af86a885f866cb9d085dbeadeffb8bb2 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 17 Jan 2024 13:43:08 +0000 Subject: [PATCH 1/4] fix: app/Dockerfile to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-DEBIAN10-NCURSES-1655739 - https://snyk.io/vuln/SNYK-DEBIAN10-NCURSES-1655739 - https://snyk.io/vuln/SNYK-DEBIAN10-NCURSES-5421196 - https://snyk.io/vuln/SNYK-DEBIAN10-NCURSES-5421196 - https://snyk.io/vuln/SNYK-DEBIAN10-NCURSES-5421196 --- app/Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/Dockerfile b/app/Dockerfile index 04b7ce7..9c8082d 100644 --- a/app/Dockerfile +++ b/app/Dockerfile @@ -1,4 +1,4 @@ -FROM python:3.8-slim-buster +FROM python:3.13.0a2-slim WORKDIR /code ENV FLASK_APP=app.py ENV FLASK_RUN_HOST=0.0.0.0 From c9580e4fa918dfbf91eecd722171bc71e641f321 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 23 Feb 2024 15:42:17 +0000 Subject: [PATCH 2/4] fix: app/Dockerfile to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-DEBIAN12-GLIBC-6210088 - https://snyk.io/vuln/SNYK-DEBIAN12-GLIBC-6210098 - https://snyk.io/vuln/SNYK-DEBIAN12-GLIBC-6210098 - https://snyk.io/vuln/SNYK-DEBIAN12-GNUTLS28-6159410 - https://snyk.io/vuln/SNYK-DEBIAN12-GNUTLS28-6159418 --- app/Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/Dockerfile b/app/Dockerfile index 9c8082d..b35fa25 100644 --- a/app/Dockerfile +++ b/app/Dockerfile @@ -1,4 +1,4 @@ -FROM python:3.13.0a2-slim +FROM python:3.13.0a3-slim WORKDIR /code ENV FLASK_APP=app.py ENV FLASK_RUN_HOST=0.0.0.0 From 38c829709e195d3a985e3f3621dbe7a9f5a3d9d7 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 6 May 2024 19:11:06 +0000 Subject: [PATCH 3/4] fix: app/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-6808933 --- app/requirements.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/app/requirements.txt b/app/requirements.txt index 27069da..b672b08 100644 --- a/app/requirements.txt +++ b/app/requirements.txt @@ -2,3 +2,4 @@ flask flask-bootstrap numpy requests +werkzeug>=3.0.3 # not directly required, pinned by Snyk to avoid a vulnerability From d0a7680388e8d8a152f83dc8cfe7fd68a0b2bf30 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 9 May 2024 23:39:54 +0000 Subject: [PATCH 4/4] fix: app/Dockerfile to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-DEBIAN12-GLIBC-6617103 - https://snyk.io/vuln/SNYK-DEBIAN12-GLIBC-6673964 - https://snyk.io/vuln/SNYK-DEBIAN12-GLIBC-6673969 - https://snyk.io/vuln/SNYK-DEBIAN12-GLIBC-6673972 - https://snyk.io/vuln/SNYK-DEBIAN12-ZLIB-6008963 --- app/Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/Dockerfile b/app/Dockerfile index b35fa25..c74f02e 100644 --- a/app/Dockerfile +++ b/app/Dockerfile @@ -1,4 +1,4 @@ -FROM python:3.13.0a3-slim +FROM python:3.13.0b1-slim WORKDIR /code ENV FLASK_APP=app.py ENV FLASK_RUN_HOST=0.0.0.0