FreeFeed/freefeed-server

trivial risk reduction with docker base image bump up to node:18.16.1-bookworm

Closed this issue · 4 comments

Snyk scanner for Docker files suggests to bump up version of base image to reduce various risks

image

pull request can be applied to try impact on current codebase

@silpol this is a major upgrade. NodeJS 18.x is still a supported branch. are you sure those issues are not fixable?

Can you add more details about problems which snyk reports?

oh, here's the link: https://snyk.io/test/docker/node%3A18.16.1-buster

it looks like the problems are not really node related, but distro related.

can we change distro instead?

@indeyets ok, it makes sense, I have updated pull request