Skip to content

Update python:3.10-slim Docker digest to 6214889 - autoclosed#64

Closed
renovate[bot] wants to merge 1 commit intomainfrom
renovate/python-3.10-slim
Closed

Update python:3.10-slim Docker digest to 6214889 - autoclosed#64
renovate[bot] wants to merge 1 commit intomainfrom
renovate/python-3.10-slim

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Dec 18, 2023

This PR contains the following updates:

Package Type Update Change
python final digest 2bac437 -> 6214889

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to a2c9b8d Update python:3.10-slim Docker digest to 1145b3e Dec 19, 2023
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch 2 times, most recently from 2be5b1f to 207557a Compare December 19, 2023 13:32
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 1145b3e Update python:3.10-slim Docker digest to 0c33c8b Dec 19, 2023
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 0c33c8b Update python:3.10-slim Docker digest to 25f03d1 Dec 19, 2023
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from 207557a to fa7277d Compare December 19, 2023 16:56
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 25f03d1 Update python:3.10-slim Docker digest to 4bd9a0e Feb 15, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from fa7277d to fb3169f Compare February 15, 2024 23:37
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 4bd9a0e Update python:3.10-slim Docker digest to 6ef542d Mar 12, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from fb3169f to d4c0877 Compare March 12, 2024 12:07
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 6ef542d Update python:3.10-slim Docker digest to 1326d0f Mar 12, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from d4c0877 to d7b1f86 Compare March 12, 2024 15:41
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 1326d0f Update python:3.10-slim Docker digest to 684b1aa Mar 20, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from d7b1f86 to 6354a2c Compare March 20, 2024 23:27
@dryrunsecurity
Copy link
Copy Markdown

dryrunsecurity Bot commented Mar 20, 2024

Hi there 👋, @DryRunSecurity here, below is a summary of our analysis and findings.

DryRun Security Status Findings
Configured Codepaths Analyzer 0 findings
Sensitive Files Analyzer 1 finding
IDOR Analyzer 0 findings
SQL Injection Analyzer 0 findings
Server-Side Request Forgery Analyzer 0 findings
Secrets Analyzer 0 findings
Authn/Authz Analyzer 0 findings

Note

🟢 Risk threshold not exceeded.

Change Summary (click to expand)

The following is a summary of changes in this pull request made by me, your security buddy 🤖. Note that this summary is auto-generated and not meant to be a definitive list of security issues but rather a helpful summary from a security perspective.

Summary:

The provided code change is for a Dockerfile, which is used to build Docker images. The key changes include updating the base image to a newer version, installing Node.js and npm, and globally installing the Renovate tool for dependency management. From an application security perspective, these changes are generally positive steps, as they can help improve the security of the application by keeping the base image and dependencies up-to-date. However, it's important to review the changes thoroughly and ensure that there are no unintended security implications, such as the introduction of new vulnerabilities in the base image or the potential for misuse of the installed tools.

Files Changed:

  • Dockerfile: The Dockerfile is being updated to use a newer version of the Python base image (python:3.10-slim@sha256:3b37199fbc5a730a551909b3efa7b29105c859668b7502451c163f2a4a7ae1ed). This change helps keep the base image secure by incorporating the latest security fixes and improvements. The Dockerfile also includes the installation of Node.js, npm, and the global installation of the Renovate tool, which is a positive step towards managing the application's dependencies and keeping them up-to-date. Additionally, the Dockerfile sets up a non-root user (python) to run the application, which is a security best practice to minimize the risk of privilege escalation vulnerabilities.

Powered by DryRun Security

@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 684b1aa Update python:3.10-slim Docker digest to 364ec90 Mar 26, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from 6354a2c to 76995d3 Compare March 26, 2024 00:10
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 364ec90 Update python:3.10-slim Docker digest to f80e619 Mar 26, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from 76995d3 to de24287 Compare March 26, 2024 03:56
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to f80e619 Update python:3.10-slim Docker digest to 40b40b5 Apr 10, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from de24287 to 1408772 Compare April 10, 2024 06:58
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 40b40b5 Update python:3.10-slim Docker digest to 64157e9 Apr 10, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from 1408772 to 9533949 Compare April 10, 2024 10:07
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 64157e9 Update python:3.10-slim Docker digest to 64157e9 - autoclosed Apr 16, 2024
@renovate renovate Bot closed this Apr 16, 2024
@renovate renovate Bot deleted the renovate/python-3.10-slim branch April 16, 2024 01:52
@renovate renovate Bot restored the renovate/python-3.10-slim branch April 16, 2024 04:01
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 64157e9 - autoclosed Update python:3.10-slim Docker digest to 64157e9 Apr 16, 2024
@renovate renovate Bot reopened this Apr 16, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from fc263bf to 5f0fc36 Compare June 27, 2024 04:32
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 4d0756b Update python:3.10-slim Docker digest to 7031721 Jun 27, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from 5f0fc36 to 5a9a90a Compare June 27, 2024 08:02
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 7031721 Update python:3.10-slim Docker digest to 7de57d5 Jun 27, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from 5a9a90a to e63b177 Compare June 27, 2024 14:01
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 7de57d5 Update python:3.10-slim Docker digest to 4eae94b Jul 2, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from e63b177 to 26786fb Compare July 2, 2024 08:44
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 4eae94b Update python:3.10-slim Docker digest to 04bd043 Jul 2, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from 26786fb to 7a7cd9c Compare July 2, 2024 16:56
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 04bd043 Update python:3.10-slim Docker digest to b91344b Jul 2, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from 7a7cd9c to 71d4036 Compare July 2, 2024 23:00
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to b91344b Update python:3.10-slim Docker digest to f93dde2 Jul 3, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from 71d4036 to c254a34 Compare July 3, 2024 04:57
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to f93dde2 Update python:3.10-slim Docker digest to f7af2d7 Jul 3, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from c254a34 to aca3fde Compare July 3, 2024 07:41
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to f7af2d7 Update python:3.10-slim Docker digest to 82d8733 Jul 3, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from aca3fde to 4537b29 Compare July 3, 2024 13:29
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 82d8733 Update python:3.10-slim Docker digest to 3b37199 Jul 3, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from 4537b29 to 90ee0da Compare July 3, 2024 18:26
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 3b37199 Update python:3.10-slim Docker digest to e52d6e4 Jul 10, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from 90ee0da to 6fba43c Compare July 10, 2024 22:16
@dryrunsecurity
Copy link
Copy Markdown

dryrunsecurity Bot commented Jul 10, 2024

DryRun Security Summary

A Dockerfile patch updates the Python 3.10 slim base image with a new SHA256 hash, raising potential security concerns about image integrity and unverified modifications.

Expand for full summary

Summary: A Dockerfile patch updates the Python 3.10 slim base image with a new SHA256 hash, potentially introducing security-related image changes.

Security Findings:
• Potential Image Integrity Risk

  • Location: Dockerfile
  • Risk: Changing base image hash could introduce unknown security modifications
  • Explanation: The new image hash may include unverified updates that could potentially compromise system security

View PR in the DryRun Dashboard.

@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to e52d6e4 Update python:3.10-slim Docker digest to 3be54ac Jul 11, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from 6fba43c to 75aedc5 Compare July 11, 2024 04:43
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to 3be54ac Update python:3.10-slim Docker digest to ab8f686 Jul 23, 2024
@renovate renovate Bot force-pushed the renovate/python-3.10-slim branch from 75aedc5 to 66522f9 Compare July 23, 2024 11:57
@renovate renovate Bot changed the title Update python:3.10-slim Docker digest to ab8f686 Update python:3.10-slim Docker digest to a962d0c Jul 23, 2024
@dryrunsecurity
Copy link
Copy Markdown

dryrunsecurity Bot commented Apr 29, 2025

DryRun Security

No security concerns detected in this pull request.


All finding details can be found in the DryRun Security Dashboard.

@dryrunsecurity
Copy link
Copy Markdown

dryrunsecurity Bot commented Sep 9, 2025

DryRun Security

This pull request updates the Dockerfile to use the python:3.10-slim base image. Python 3.10 reached end-of-life in October 2023 and no longer receives security patches, so this change poses a security risk (scanner flagged it as non-blocking).

Use of Outdated/Unsupported Software Version in Dockerfile
Vulnerability Use of Outdated/Unsupported Software Version
Description The Dockerfile is being updated to use python:3.10-slim as the base image. Python 3.10 reached its end-of-life (EOL) for security support in October 2023. This means the application's runtime will no longer receive security patches for newly discovered vulnerabilities, posing a significant security risk.

scsctl/Dockerfile

Lines 29 to 35 in 462a2ca

RUN pip install -r requirements.txt
# FROM python:3.12.0b3-slim@sha256:8e3ef64883278384c49293caf631d614b4bfdac7bb494d44e17cf2d711ce2652
FROM python:3.10-slim@sha256:122c1a0e792fad67b870205fd0f5e4d6d0f6f3f13b2fce1b9472c1ecbe274671
RUN groupadd -g 999 python && \
useradd -r -u 999 -g python python


All finding details can be found in the DryRun Security Dashboard.

Warning

Your DryRun Security account will expire on August 31, 2025. Contact hi@dryrunsecurity.com to avoid service interruption.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant