Skip to content

Commit 4412018

Browse files
committed
fix: address additional CVEs and CI failures
CVE-2026-4800 (lodash, HIGH) CVE-2026-26996 (minimatch, HIGH) CVE-2026-27903 (minimatch, HIGH) CVE-2026-27904 (minimatch, HIGH) CVE-2026-34785 (rack, HIGH) CVE-2026-34829 (rack, HIGH) CVE-2025-15467 (alpine, CRITICAL) OS-EOL-001 (alpine 3.20.3 end of life)
1 parent d2e0793 commit 4412018

7 files changed

Lines changed: 26 additions & 54 deletions

File tree

bootstrapper/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
ARG GO_VERSION=1.24
22
ARG UBUNTU_VERSION=3.17.7
3-
ARG ALPINE_VERSION=3.20.3
3+
ARG ALPINE_VERSION=3.22
44
ARG BUILDER_IMAGE="golang:${GO_VERSION}"
55
ARG RUNNER_IMAGE="alpine:${ALPINE_VERSION}"
66

docs/package-lock.json

Lines changed: 7 additions & 6 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

docs/package.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -55,6 +55,9 @@
5555
"node-forge": "1.4.0",
5656
"path-to-regexp": "0.1.13",
5757
"picomatch": "2.3.2",
58+
"minimatch": "3.1.4",
59+
"lodash": "4.18.1",
60+
"lodash-es": "4.18.1",
5861
"serve-handler": {
5962
"minimatch": "3.1.4"
6063
},
@@ -72,6 +75,9 @@
7275
"node-forge": "1.4.0",
7376
"path-to-regexp": "0.1.13",
7477
"picomatch": "2.3.2",
78+
"minimatch": "3.1.4",
79+
"lodash": "4.18.1",
80+
"lodash-es": "4.18.1",
7581
"@redocly/openapi-core/minimatch": "5.1.8",
7682
"sucrase/glob/minimatch": "9.0.7",
7783
"serve-handler/minimatch": "3.1.4",

docs/yarn.lock

Lines changed: 9 additions & 44 deletions
Original file line numberDiff line numberDiff line change
@@ -3802,13 +3802,6 @@ brace-expansion@^2.0.1:
38023802
dependencies:
38033803
balanced-match "^1.0.0"
38043804

3805-
brace-expansion@^2.0.2:
3806-
version "2.0.3"
3807-
resolved "https://registry.yarnpkg.com/brace-expansion/-/brace-expansion-2.0.3.tgz#0493338bdd58e319b1039c67cf7ee439892c01d9"
3808-
integrity sha512-MCV/fYJEbqx68aE58kv2cA/kiky1G8vux3OR6/jbS+jIMe/6fJWa0DTzJU7dqijOWYwHi1t29FlfYI9uytqlpA==
3809-
dependencies:
3810-
balanced-match "^1.0.0"
3811-
38123805
brace-expansion@^5.0.2:
38133806
version "5.0.4"
38143807
resolved "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.4.tgz"
@@ -7065,10 +7058,10 @@ locate-path@^7.1.0:
70657058
dependencies:
70667059
p-locate "^6.0.0"
70677060

7068-
lodash-es@4.17.21, lodash-es@^4.17.21:
7069-
version "4.17.21"
7070-
resolved "https://registry.npmjs.org/lodash-es/-/lodash-es-4.17.21.tgz"
7071-
integrity sha512-mKnC+QJ9pWVzv+C4/U3rRsHapFfHvQFoFB92e52xeyGMcX6/OlIl78je1u8vePzYZSkkogMPJ2yjxxsb89cxyw==
7061+
lodash-es@4.17.21, lodash-es@4.18.1, lodash-es@^4.17.21:
7062+
version "4.18.1"
7063+
resolved "https://registry.npmjs.org/lodash-es/-/lodash-es-4.18.1.tgz"
7064+
integrity sha512-J8xewKD/Gk22OZbhpOVSwcs60zhd95ESDwezOFuA3/099925PdHJ7OFHNTGtajL3AlZkykD32HykiMo+BIBI8A==
70727065

70737066
lodash.debounce@^4.0.8:
70747067
version "4.0.8"
@@ -7090,10 +7083,10 @@ lodash.uniq@^4.5.0:
70907083
resolved "https://registry.npmjs.org/lodash.uniq/-/lodash.uniq-4.5.0.tgz"
70917084
integrity sha512-xfBaXQd9ryd9dlSDvnvI0lvxfLJlYAZzXomUYzLKtUeOQvOP5piqAWuGtrhWeqaXK9hhoM/iyJc5AV+XfsX3HQ==
70927085

7093-
lodash@4.17.21, lodash@^4.17.15, lodash@^4.17.20, lodash@^4.17.21, lodash@^4.17.4:
7094-
version "4.17.21"
7095-
resolved "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz"
7096-
integrity sha512-v2kDEe57lecTulaDIuNTPy3Ry4gLGJ6Z1O3vE1krgXZNrsQ+LFTGHVxVjcXPs17LhbZVGedAJv8XZ1tvj5FvSg==
7086+
lodash@4.17.21, lodash@4.18.1, lodash@^4.17.15, lodash@^4.17.20, lodash@^4.17.21, lodash@^4.17.4:
7087+
version "4.18.1"
7088+
resolved "https://registry.npmjs.org/lodash/-/lodash-4.18.1.tgz"
7089+
integrity sha512-dMInicTPVE8d1e5otfwmmjlxkZoUpiVLwyeTdUsi/Caj/gfzzblBcCE5sRHV/AsjuCmxWrte2TNGSYuCeCq+0Q==
70977090

70987091
longest-streak@^3.0.0:
70997092
version "3.1.0"
@@ -8393,14 +8386,7 @@ minimalistic-assert@^1.0.0:
83938386
resolved "https://registry.npmjs.org/minimalistic-assert/-/minimalistic-assert-1.0.1.tgz"
83948387
integrity sha512-UtJcAD4yEaGtjPezWuO9wC4nwUnVH/8/Im3yEHQP4b67cXlD/Qr9hdITCU1xDbSEXg2XKNaP8jsReV7vQd00/A==
83958388

8396-
minimatch@3.1.2:
8397-
version "3.1.2"
8398-
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-3.1.2.tgz#19cd194bfd3e428f049a70817c038d89ab4be35b"
8399-
integrity sha512-J7p63hRiAjw1NDEww1W7i37+ByIrOWO5XQQAzZ3VOcL0PNybwpfmV/N05zFAzwQ9USyEcX6t3UO+K5aqBQOIHw==
8400-
dependencies:
8401-
brace-expansion "^1.1.7"
8402-
8403-
minimatch@3.1.4:
8389+
minimatch@3.1.2, minimatch@3.1.4, minimatch@^3.1.1, minimatch@^5.0.1, minimatch@^9.0.4:
84048390
version "3.1.4"
84058391
resolved "https://registry.npmjs.org/minimatch/-/minimatch-3.1.4.tgz"
84068392
integrity sha512-twmL+S8+7yIsE9wsqgzU3E8/LumN3M3QELrBZ20OdmQ9jB2JvW5oZtBEmft84k/Gs5CG9mqtWc6Y9vW+JEzGxw==
@@ -8421,27 +8407,6 @@ minimatch@9.0.7:
84218407
dependencies:
84228408
brace-expansion "^5.0.2"
84238409

8424-
minimatch@^3.1.1:
8425-
version "3.1.5"
8426-
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-3.1.5.tgz#580c88f8d5445f2bd6aa8f3cadefa0de79fbd69e"
8427-
integrity sha512-VgjWUsnnT6n+NUk6eZq77zeFdpW2LWDzP6zFGrCbHXiYNul5Dzqk2HHQ5uFH2DNW5Xbp8+jVzaeNt94ssEEl4w==
8428-
dependencies:
8429-
brace-expansion "^1.1.7"
8430-
8431-
minimatch@^5.0.1:
8432-
version "5.1.9"
8433-
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-5.1.9.tgz#1293ef15db0098b394540e8f9f744f9fda8dee4b"
8434-
integrity sha512-7o1wEA2RyMP7Iu7GNba9vc0RWWGACJOCZBJX2GJWip0ikV+wcOsgVuY9uE8CPiyQhkGFSlhuSkZPavN7u1c2Fw==
8435-
dependencies:
8436-
brace-expansion "^2.0.1"
8437-
8438-
minimatch@^9.0.4:
8439-
version "9.0.9"
8440-
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-9.0.9.tgz#9b0cb9fcb78087f6fd7eababe2511c4d3d60574e"
8441-
integrity sha512-OBwBN9AL4dqmETlpS2zasx+vTeWclWzkblfZk7KTA5j3jeOONz/tRCnZomUyvNg83wL5Zv9Ss6HMJXAgL8R2Yg==
8442-
dependencies:
8443-
brace-expansion "^2.0.2"
8444-
84458410
minimist@^1.2.0, minimist@^1.2.3:
84468411
version "1.2.8"
84478412
resolved "https://registry.npmjs.org/minimist/-/minimist-1.2.8.tgz"

github_hooks/Gemfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ gem "bundler", ">= 1.8.4"
55

66
gem "pg", "~> 1.1"
77
gem "rails", ">= 8.0.4.1", "< 8.1"
8-
gem "rack", "~> 2.2.20"
8+
gem "rack", "~> 2.2.23"
99
gem "sprockets-rails"
1010

1111
gem "excon", "~> 0.81.0"

github_hooks/Gemfile.lock

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -283,7 +283,7 @@ GEM
283283
nio4r (~> 2.0)
284284
raabro (1.4.0)
285285
racc (1.8.1)
286-
rack (2.2.22)
286+
rack (2.2.23)
287287
rack-session (1.0.2)
288288
rack (< 3)
289289
rack-test (2.2.0)

public-api-gateway/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
ARG GO_VERSION=1.24
2-
ARG ALPINE_VERSION=3.20.3
2+
ARG ALPINE_VERSION=3.22
33
ARG BUILDER_IMAGE="golang:${GO_VERSION}"
44
ARG RUNNER_IMAGE="alpine:${ALPINE_VERSION}"
55

0 commit comments

Comments
 (0)