chore(deps): bump nginx image from 1.27.0 to 1.27.2 #10161
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
nginx:1.27.2-alpine
.RUN apk upgrade --no-cache
was added to make sure all the patched packages used byalpine
are pulled in.Motivation and Context
This change upgrades the base nginx image since it uses the newer version of
alpine
with security vulnerability fixes.This was reported in issue #10151.
How Has This Been Tested?
I updated the workflow action:
Security Scan for docker image
to build the image in the CI pipeline and runtrivy
on this locally-built image. The failing build (seeold
screenshot below) was fixed with no vulnerabilities.I undid the workflow changes. But here is the workflow I used to verify that this upgrades fixes the security vulnerability.
The
new
screenshot below shows the fixed version of the security scan using this new image. (Upgrade toalpine 3.20
)Screenshots (if appropriate):
Old:
New:
Checklist
My PR contains...
src/
is unmodified: changes to documentation, CI, metadata, etc.)package.json
)My changes...
Documentation
Automated tests