Skip to content

Update docker and docker-compose versions#100

Merged
sarahchen6 merged 3 commits intomasterfrom
sarahchen6/fix-security-vulnerabilities
Jun 10, 2025
Merged

Update docker and docker-compose versions#100
sarahchen6 merged 3 commits intomasterfrom
sarahchen6/fix-security-vulnerabilities

Conversation

@sarahchen6
Copy link
Copy Markdown
Contributor

@sarahchen6 sarahchen6 commented Jun 5, 2025

Fix security vulnerabilities (https://github.com/DataDog/dd-trace-java-docker-build/security/code-scanning) by updating docker and docker compose versions.

Also update dependabot frequency from monthly to weekly.

Check that the security vulnerabilities are fixed in this PR here. This vulnerability (high) is still not resolved; however, there is no "fixed version" available yet.

Comment thread .github/workflows/ci.yml Outdated
@sarahchen6 sarahchen6 force-pushed the sarahchen6/fix-security-vulnerabilities branch from 4a7b6c3 to 53e3baf Compare June 6, 2025 17:17
@sarahchen6 sarahchen6 changed the title Update Trivy pull Update docker and docker-compose versions Jun 6, 2025
@sarahchen6 sarahchen6 marked this pull request as ready for review June 6, 2025 18:23
Copy link
Copy Markdown
Contributor

@PerfectSlayer PerfectSlayer left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Rather than bumping version to fix the issues for now, what about trying to get the build use latest version every time?

Comment thread Dockerfile Outdated
Comment thread Dockerfile Outdated
@sarahchen6 sarahchen6 requested a review from PerfectSlayer June 10, 2025 14:29
@sarahchen6 sarahchen6 merged commit d947089 into master Jun 10, 2025
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants