diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..49d85a8 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,13 @@ +version: 2 +updates: + - package-ecosystem: "gradle" + directory: "/" + schedule: + interval: "weekly" + day: "wednesday" + time: "09:00" + # Disable version updates, keep security updates only + open-pull-requests-limit: 0 + commit-message: + # Prefix all commit messages with "chore: " + prefix: "chore" diff --git a/Dockerfile b/Dockerfile index faa71d1..01706f4 100644 --- a/Dockerfile +++ b/Dockerfile @@ -12,6 +12,9 @@ RUN gradle --no-daemon build --stacktrace -PdisableCompression=true RUN mkdir /build && tar -xf /home/gradle/src/build/distributions/aidial-auth-helper-*.tar --strip-components=1 -C /build FROM eclipse-temurin:17-jdk-alpine +# fix CVE-2023-5363 +# TODO remove the fix once a new version is released +RUN apk update && apk upgrade --no-cache libcrypto3 libssl3 WORKDIR /app