Jelajahi Sumber

CVE fixes Q2.22 (#2357)

* upgrading alpine to fix CVE-2022-28391 vulnerabilities

* bumping spring-boot-version which includes vulnerabilities fixes

* Bumping one more version to clean high vulnerabilities up u

Co-authored-by: Roman Zabaluev <rzabaluev@provectus.com>
MichaelGonzalezMurillo 2 tahun lalu
induk
melakukan
27252393a2
2 mengubah file dengan 2 tambahan dan 2 penghapusan
  1. 1 1
      kafka-ui-api/Dockerfile
  2. 1 1
      pom.xml

+ 1 - 1
kafka-ui-api/Dockerfile

@@ -1,4 +1,4 @@
-FROM alpine:3.15.0
+FROM alpine:3.16.1
 
 RUN apk add --no-cache openjdk13-jre libc6-compat gcompat \
 && addgroup -S kafkaui && adduser -S kafkaui -G kafkaui

+ 1 - 1
pom.xml

@@ -14,7 +14,7 @@
         <maven.compiler.target>13</maven.compiler.target>
         <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
 
-        <spring-boot.version>2.6.7</spring-boot.version>
+        <spring-boot.version>2.6.8</spring-boot.version>
         <jackson-databind-nullable.version>0.2.2</jackson-databind-nullable.version>
         <org.mapstruct.version>1.4.2.Final</org.mapstruct.version>
         <org.projectlombok.version>1.18.20</org.projectlombok.version>