Skip to content
This repository was archived by the owner on Dec 19, 2025. It is now read-only.

[ADMINAPI-1321] - Docker Security Vulnerability Remediation - .net 8.0.21#374

Merged
dfernandez-gap merged 2 commits intomainfrom
ADMINAPI-1321-3
Nov 4, 2025
Merged

[ADMINAPI-1321] - Docker Security Vulnerability Remediation - .net 8.0.21#374
dfernandez-gap merged 2 commits intomainfrom
ADMINAPI-1321-3

Conversation

@DavidJGapCR
Copy link

No description provided.

@github-actions
Copy link

github-actions bot commented Oct 29, 2025

🔍 Vulnerabilities of development:latest

📦 Image Reference development:latest
digestsha256:3d765acfb1dd740b6504f585de23260cae61412c74ae10cc7099658347ff7412
vulnerabilitiescritical: 0 high: 0 medium: 0 low: 2 unspecified: 1
platformlinux/amd64
size90 MB
packages593
📦 Base Image alpine:3.21
also known as
  • 3.21.5
  • d7d2af10dd52b47735f4b5abdb91ff534bffee8495cd5b3f588a14c7389c6676
digestsha256:41c81533144786e0beb2b148667355a6c7659aa99a14ed837ff15a98ca9d71f3
vulnerabilitiescritical: 0 high: 0 medium: 0 low: 2
critical: 0 high: 0 medium: 0 low: 2 busybox 1.37.0-r13 (apk)

pkg:apk/alpine/busybox@1.37.0-r13?os_name=alpine&os_version=3.21

low : CVE--2025--46394

Affected range<=1.37.0-r13
Fixed versionNot Fixed
Description

low : CVE--2024--58251

Affected range<=1.37.0-r13
Fixed versionNot Fixed
Description
critical: 0 high: 0 medium: 0 low: 0 unspecified: 1lz4 1.10.0-r0 (apk)

pkg:apk/alpine/lz4@1.10.0-r0?os_name=alpine&os_version=3.21

unspecified : CVE--2025--62813

Affected range<=1.10.0-r0
Fixed versionNot Fixed
Description

@DavidJGapCR DavidJGapCR force-pushed the ADMINAPI-1321-3 branch 6 times, most recently from ee5e99d to bda6e65 Compare October 30, 2025 19:43
@DavidJGapCR DavidJGapCR marked this pull request as ready for review October 30, 2025 22:37
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates Docker base images and package versions across all Dockerfiles, upgrading from Alpine 3.20 to Alpine 3.21, .NET SDK from 8.0.403 to 8.0.415, and .NET ASP.NET runtime from 8.0.8/8.0.10 to 8.0.21. It also updates various Alpine package versions including musl, bash, and PostgreSQL client.

Key changes:

  • Upgraded Alpine base image from 3.20 to 3.21 with updated SHA256 hashes
  • Updated .NET SDK and ASP.NET runtime to latest versions (8.0.415 and 8.0.21)
  • Updated Alpine package versions (musl from 1.2.5-r1 to 1.2.5-r9, PostgreSQL client from version 14 to 15)

Reviewed Changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

File Description
Docker/dev.pgsql.Dockerfile Updates Alpine 3.21, .NET 8.0.415/8.0.21, package versions, and PostgreSQL 15 client
Docker/dev.mssql.Dockerfile Updates Alpine 3.21, .NET 8.0.415/8.0.21, and musl package version
Docker/api.pgsql.Dockerfile Updates Alpine 3.21, .NET 8.0.21, package versions, and PostgreSQL 15 client
Docker/api.mssql.Dockerfile Updates Alpine 3.21, .NET 8.0.21, and musl package version
Comments suppressed due to low confidence (1)

Docker/api.pgsql.Dockerfile:1

  • The icu package version (74.2-r1) is pinned in dev.pgsql.Dockerfile line 44 but uses a looser version constraint (icu=~74) here. Consider using a consistent versioning approach across all Dockerfiles for better maintainability and reproducibility.
# SPDX-License-Identifier: Apache-2.0

@dfernandez-gap dfernandez-gap merged commit c21eaf9 into main Nov 4, 2025
22 checks passed
@dfernandez-gap dfernandez-gap deleted the ADMINAPI-1321-3 branch November 4, 2025 19:18
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants