<#149 [Snyk] Security upgrade ruby from 3.3.3-alpi...
# pact-ruby-standalone
g
#149 [Snyk] Security upgrade ruby from 3.3.3-alpine to 3.3.5-alpine Pull request opened by mefellows snyk-top-banner Snyk has created this PR to fix 2 vulnerabilities in the dockerfile dependencies of this project. Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image. Snyk changed the following file(s): •
Dockerfile-release-base
We recommend upgrading to
ruby:3.3.5-alpine
, as this image has only 0 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected. Vulnerabilities that will be fixed with an upgrade: | Issue | Score | | | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----- | | [[low severity](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67 "low severity")](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67) | [CVE-2024-6119](https://github.com/advisories/GHSA-7m4m-pwhv-49c5 "CVE-2024-6119") [SNYK-ALPINE320-OPENSSL-7895537](https://snyk.io/vuln/SNYK-ALPINE320-OPENSSL-7895537) | 436 | | [[low severity](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67 "low severity")](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67) | [CVE-2024-6119](https://github.com/advisories/GHSA-7m4m-pwhv-49c5 "CVE-2024-6119") [SNYK-ALPINE320-OPENSSL-7895537](https://snyk.io/vuln/SNYK-ALPINE320-OPENSSL-7895537) | 436 | | [[low severity](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67 "low severity")](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67) | [CVE-2024-5535](https://github.com/advisories/GHSA-4fc7-mvrr-wv2c "CVE-2024-5535") [SNYK-ALPINE320-OPENSSL-7413532](https://snyk.io/vuln/SNYK-ALPINE320-OPENSSL-7413532) | 364 | | [[low severity](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67 "low severity")](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67) | [CVE-2024-5535](https://github.com/advisories/GHSA-4fc7-mvrr-wv2c "CVE-2024-5535") [SNYK-ALPINE320-OPENSSL-7413532](https://snyk.io/vuln/SNYK-ALPINE320-OPENSSL-7413532) | 364 | --- Important • Check the changes in this PR to ensure they won't cause issues with your project. • Max score is 1000. Note that the real score may have changed since the PR was raised. • This PR was automatically created by Snyk using the credentials of a real user. --- Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs. For more information: https://camo.githubusercontent.com/1b7b8d1580a45a711a0233bcd9cdfac4a29125c8a0d68bd15d9c39abd78cbc30/68747470733a2f2f6170692e7365676d656e742e696f2f76312f706978656c2f747261636b3f646174613d65794a33636d6c305a55746c65534936496e4a79576d785a634564485932527954485a7362306c596430645563566734576b4652546e4e434f5545774969776959573576626e6c746233567a535751694f694a684e44646d4d5451334e53316d4d4463304c545269596d55744f44457a5a5330784d6a417a597a4d314f546b794e444d694c434a6c646d567564434936496c425349485a705a58646c5a434973496e42796233426c636e52705a584d694f6e736963484a4a5a434936496d45304e3259784e4463314c5759774e7a51744e474a695a5330344d544e6c4c5445794d444e6a4d7a55354f5449304d794a3966513d3d 🧐 View latest project report 📜 Customise PR templates 🛠️ <https://app.snyk.io/org/pact-foundation-808/project/3a967741-0e97-4401-b242-621cf1bff716?utm_source=github&utm_medium=referra… pact-foundation/pact-ruby-standalone ✅ All checks have passed 15/15 successful checks