Skip to content

chore: security fixes#24

Open
andrii-codefresh wants to merge 1 commit intomainfrom
CR-36776-security-main
Open

chore: security fixes#24
andrii-codefresh wants to merge 1 commit intomainfrom
CR-36776-security-main

Conversation

@andrii-codefresh
Copy link
Copy Markdown

@andrii-codefresh andrii-codefresh commented Apr 7, 2026

CVE-2025-61730
CVE-2025-61728

What

Why

Notes

Labels

Assign the following labels to the PR:

security - to trigger image scanning in CI build

PR Comments

Add the following comments to the PR:

/e2e - to trigger E2E build

Security Report

Important

Current summary is in beta mode.
Please analyze the full scan report for comprehensive details.

Fixed CVEs: 6

🟣 Critical: 1

  • CVE-2025-68121 in crypto/tls@1.24.11 at /usr/local/bin/docker-compose

🔴 High: 1

🟠 Medium: 1

  • CVE-2025-61730 in crypto/tls@1.24.11 at /usr/local/bin/docker-compose

⚫ Unassigned: 3

@andrii-codefresh
Copy link
Copy Markdown
Author

/e2e



# DHI source: https://hub.docker.com/repository/docker/octopusdeploy/dhi-debian-base
FROM octopusdeploy/dhi-debian-base:trixie-debian13@sha256:9ef766670af4743904b0f992a26b525c6c914648b56ea597ec23452adcf1a95d AS compose-plugin
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@andrii-codefresh Could we also bump base image? There might be new security fixes since last update

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants