From ad03387165a2d742e537a2d64575f33df5098a41 Mon Sep 17 00:00:00 2001 From: Dmytro Pashynskyi <61313167+dspashynskyi@users.noreply.github.com> Date: Fri, 10 Nov 2023 14:44:40 +0200 Subject: [PATCH 1/2] chore: enable dependabot (#6) Co-authored-by: Vladislav Yatsun --- .github/dependabot.yml | 13 +++++++++++++ 1 file changed, 13 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..49d85a8 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,13 @@ +version: 2 +updates: + - package-ecosystem: "gradle" + directory: "/" + schedule: + interval: "weekly" + day: "wednesday" + time: "09:00" + # Disable version updates, keep security updates only + open-pull-requests-limit: 0 + commit-message: + # Prefix all commit messages with "chore: " + prefix: "chore" From b6aa5773ea4d19f3f9d60628a11d5ece80bd069f Mon Sep 17 00:00:00 2001 From: Aliaksandr Stsiapanay Date: Wed, 15 Nov 2023 18:23:17 +0300 Subject: [PATCH 2/2] chore: fix CVE-2023-5363 (#11) Co-authored-by: Aliaksandr Stsiapanay --- Dockerfile | 3 +++ 1 file changed, 3 insertions(+) diff --git a/Dockerfile b/Dockerfile index faa71d1..01706f4 100644 --- a/Dockerfile +++ b/Dockerfile @@ -12,6 +12,9 @@ RUN gradle --no-daemon build --stacktrace -PdisableCompression=true RUN mkdir /build && tar -xf /home/gradle/src/build/distributions/aidial-auth-helper-*.tar --strip-components=1 -C /build FROM eclipse-temurin:17-jdk-alpine +# fix CVE-2023-5363 +# TODO remove the fix once a new version is released +RUN apk update && apk upgrade --no-cache libcrypto3 libssl3 WORKDIR /app