GitHub
02/17/2025, 7:05 AMDockerfile-bundle-base
We recommend upgrading to ruby:3.4.2-alpine, as this image has only 0 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.
Vulnerabilities that will be fixed with an upgrade:
| Issue | Score | |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----- |
| [[low severity](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67 "low severity")](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67) | [CVE-2024-13176](https://github.com/advisories/GHSA-r9fv-h47r-823f "CVE-2024-13176") [SNYK-ALPINE320-OPENSSL-8690013](https://snyk.io/vuln/SNYK-ALPINE320-OPENSSL-8690013) | 436 |
| [[low severity](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67 "low severity")](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67) | [CVE-2024-13176](https://github.com/advisories/GHSA-r9fv-h47r-823f "CVE-2024-13176") [SNYK-ALPINE320-OPENSSL-8690013](https://snyk.io/vuln/SNYK-ALPINE320-OPENSSL-8690013) | 436 |
| [[low severity](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67 "low severity")](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67) | [CVE-2024-9143](https://github.com/advisories/GHSA-q764-r57m-9wp9 "CVE-2024-9143") [SNYK-ALPINE320-OPENSSL-8235201](https://snyk.io/vuln/SNYK-ALPINE320-OPENSSL-8235201) | 364 |
| [[low severity](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67 "low severity")](https://camo.githubusercontent.com/6b3fab2d4fee347050a15f32c90cf4a87d4569393bb24a45d1aa184b9c4c8a36/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f736e796b2f696d6167652f75706c6f61642f775f32302c685f32302f76313536313937373831392f69636f6e2f6c2e706e67) | [CVE-2024-9143](https://github.com/advisories/GHSA-q764-r57m-9wp9 "CVE-2024-9143") [SNYK-ALPINE320-OPENSSL-8235201](https://snyk.io/vuln/SNYK-ALPINE320-OPENSSL-8235201) | 364 |
---
Important
• Check the changes in this PR to ensure they won't cause issues with your project.
• Max score is 1000. Note that the real score may have changed since the PR was raised.
• This PR was automatically created by Snyk using the credentials of a real user.
---
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: https://camo.githubusercontent.com/faf3db7a4690d96bba4c7539b61d854517dbba712667c6ec31f365b75ef1ef44/68747470733a2f2f6170692e7365676d656e742e696f2f76312f706978656c2f747261636b3f646174613d65794a33636d6c305a55746c65534936496e4a79576d785a634564485932527954485a7362306c596430645563566734576b4652546e4e434f5545774969776959573576626e6c746233567a535751694f694a684d7a41314e7a4d304d533034596d597a4c5451344f5467744f4755795a53316d4e6d466d4d7a5269596a466c4e4755694c434a6c646d567564434936496c425349485a705a58646c5a434973496e42796233426c636e52705a584d694f6e736963484a4a5a434936496d457a4d4455334d7a51784c5468695a6a4d744e4467354f4330345a544a6c4c5759325957597a4e474a694d5755305a534a3966513d3d
🧐 View latest project report
📜 Customise PR templates
🛠️ Adjust project settings
📚 Read about Snyk's upgrade logic
---
Learn how to fix vulnerabilities with free interactive lessons:
🦉 <https://learn.snyk.io/?loc=fix-pr|Learn about vulner…
pact-foundation/pact-ruby-standalone