Skip to content

Commit 664b9ec

Browse files
Merge pull request #1316 from eclipse-tractusx/chore/xxx-anylsis-libcurl-cve
chore(update): xxx - analysis of cve
2 parents ea5d90d + 9d90915 commit 664b9ec

File tree

4 files changed

+8
-3
lines changed

4 files changed

+8
-3
lines changed

CHANGELOG.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
88
_**For better traceability add the corresponding GitHub issue number in each changelog entry, please.**_
99
## [UNRELEASED - DD.MM.YYYY]
1010
### Changed
11+
- #XXX Updated node:alpine 18 to 20 to fix cves
1112
- #1070 Convert png to svg according to TRG 1.04 - Diagrams as code / Editable static files
1213
- #XXX updated Swagger-ui documentation
1314
- #XXX update IRS chart version from 7.3.1 to 7.4.0

Dockerfile

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -45,6 +45,8 @@ WORKDIR /app
4545

4646
COPY --chmod=755 --from=maven /build/tx-backend/target/traceability-app-*-exec.jar app.jar
4747

48+
RUN apk info -vv
49+
4850
USER 10000:1000
4951

5052
ENTRYPOINT ["java", "-jar", "app.jar"]

frontend/DOCKER_NOTICE.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,9 +15,9 @@ __Traceability-foss__
1515

1616
**Used base image**
1717

18-
- [node:18-alpine](https://github.com/nodejs/docker-node)
18+
- [node:22-alpine](https://github.com/nodejs/docker-node)
1919
- Official Node DockerHub page: https://hub.docker.com/_/node/
20-
- Dockerfile: https://github.com/nodejs/docker-node/blob/main/18/alpine3.18/Dockerfile
20+
- Dockerfile: https://github.com/nodejs/docker-node/blob/main/20/alpine3.20/Dockerfile
2121

2222

2323
- [nginxinc/nginx-unprivileged:alpine](https://github.com/nginxinc/docker-nginx)

frontend/Dockerfile

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@
1717

1818
# Nonroot user is not needed beause we are using the "nginx-unprivileged" image
1919
# STAGE 1: Build
20-
FROM node:18-alpine AS builder
20+
FROM node:20-alpine AS builder
2121

2222
# Copy dependencies info
2323
COPY ./frontend/package.json ./frontend/yarn.lock ./
@@ -75,4 +75,6 @@ USER root
7575
RUN chown nginx:nginx /etc/nginx/nginx.conf
7676
RUN chown nginx:nginx /etc/nginx/security-headers.conf
7777

78+
RUN apk info -vv
79+
7880
USER 101

0 commit comments

Comments
 (0)