<#148 [Snyk] Security upgrade ruby from 3.3.3-alpi...
# pact-ruby-standalone
g
#148 [Snyk] Security upgrade ruby from 3.3.3-alpine to 3.3.5-alpine Pull request opened by mefellows snyk-top-banner Snyk has created this PR to fix 1 vulnerabilities in the dockerfile dependencies of this project. Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image. Snyk changed the following file(s): •
Dockerfile-bundle-base
We recommend upgrading to
ruby:3.3.5-alpine
, as this image has only 0 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected. Vulnerabilities that will be fixed with an upgrade: | Issue | Score | | | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----- | | [[low severity](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67 "low severity")](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67) | [CVE-2024-5535](https://github.com/advisories/GHSA-4fc7-mvrr-wv2c "CVE-2024-5535") [SNYK-ALPINE320-OPENSSL-7413532](https://snyk.io/vuln/SNYK-ALPINE320-OPENSSL-7413532) | 364 | | [[low severity](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67 "low severity")](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67) | [CVE-2024-5535](https://github.com/advisories/GHSA-4fc7-mvrr-wv2c "CVE-2024-5535") [SNYK-ALPINE320-OPENSSL-7413532](https://snyk.io/vuln/SNYK-ALPINE320-OPENSSL-7413532) | 364 | --- Important • Check the changes in this PR to ensure they won't cause issues with your project. • Max score is 1000. Note that the real score may have changed since the PR was raised. • This PR was automatically created by Snyk using the credentials of a real user. --- Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs. For more information: https://camo.githubusercontent.com/23a915974522b728c1aa69b8394562ff52ff905d25bc143bbbd16f8b59d8989c/68747470733a2f2f6170692e7365676d656e742e696f2f76312f706978656c2f747261636b3f646174613d65794a33636d6c305a55746c65534936496e4a79576d785a634564485932527954485a7362306c596430645563566734576b4652546e4e434f5545774969776959573576626e6c746233567a535751694f6949304e3259304d6a49324d79316b4e6a566a4c54526a5a444d744f445934597931695a5759344e7a4a695a6d526d4d4759694c434a6c646d567564434936496c425349485a705a58646c5a434973496e42796233426c636e52705a584d694f6e736963484a4a5a434936496a51335a6a51794d6a597a4c5751324e574d744e474e6b4d7930344e6a686a4c574a6c5a6a67334d6d4a6d5a4759775a694a3966513d3d 🧐 View latest project report 📜 Customise PR templates 🛠️ Adjust project settings 📚 Read about Snyk's upgrade logic --- Learn how to fix vulnerabilities with free interactive lessons: 🦉 Learn about vulnerability in an interactive lesson of Snyk Learn. pact-foundation/pact-ruby-standalone ✅ All checks have passed 15/15 successful checks