[PR #1702] [MERGED] [Snyk] Security upgrade node from 12.10.0-alpine to 12-alpine #3451

Closed
opened 2026-03-17 01:03:59 +03:00 by kerem · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/hoppscotch/hoppscotch/pull/1702
Author: @snyk-bot
Created: 6/4/2021
Status: Merged
Merged: 6/4/2021
Merged by: @liyasthomas

Base: mainHead: snyk-fix-d3f490e367da882b73794c72abf7a059


📝 Commits (1)

  • 9772614 fix: Dockerfile to reduce vulnerabilities

📊 Changes

1 file changed (+1 additions, -1 deletions)

View changed files

📝 Dockerfile (+1 -1)

📄 Description

Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Changes included in this PR

  • Dockerfile

We recommend upgrading to node:12-alpine, as this image has only 0 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Some of the most important vulnerabilities in your base image include:

Severity Priority Score / 1000 Issue Exploit Maturity
high severity 821 HTTP Request Smuggling
SNYK-UPSTREAM-NODE-1055465
Proof of Concept
high severity 821 Arbitrary File Overwrite
SNYK-UPSTREAM-NODE-538285
Proof of Concept
high severity 821 Arbitrary File Write
SNYK-UPSTREAM-NODE-538286
Proof of Concept
high severity 821 Improper Certificate Validation
SNYK-UPSTREAM-NODE-546815
Proof of Concept
high severity 725 Memory Corruption
SNYK-UPSTREAM-NODE-570870
No Known Exploit

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/hoppscotch/hoppscotch/pull/1702 **Author:** [@snyk-bot](https://github.com/snyk-bot) **Created:** 6/4/2021 **Status:** ✅ Merged **Merged:** 6/4/2021 **Merged by:** [@liyasthomas](https://github.com/liyasthomas) **Base:** `main` ← **Head:** `snyk-fix-d3f490e367da882b73794c72abf7a059` --- ### 📝 Commits (1) - [`9772614`](https://github.com/hoppscotch/hoppscotch/commit/97726141cf914e3812e63fd87788d6cfe2779b92) fix: Dockerfile to reduce vulnerabilities ### 📊 Changes **1 file changed** (+1 additions, -1 deletions) <details> <summary>View changed files</summary> 📝 `Dockerfile` (+1 -1) </details> ### 📄 Description Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image. #### Changes included in this PR - Dockerfile We recommend upgrading to `node:12-alpine`, as this image has only 0 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected. Some of the most important vulnerabilities in your base image include: | Severity | Priority Score / 1000 | Issue | Exploit Maturity | | :------: | :-------------------- | :---- | :--------------- | | ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **821** | HTTP Request Smuggling <br/>[SNYK-UPSTREAM-NODE-1055465](https://snyk.io/vuln/SNYK-UPSTREAM-NODE-1055465) | Proof of Concept | | ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **821** | Arbitrary File Overwrite <br/>[SNYK-UPSTREAM-NODE-538285](https://snyk.io/vuln/SNYK-UPSTREAM-NODE-538285) | Proof of Concept | | ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **821** | Arbitrary File Write <br/>[SNYK-UPSTREAM-NODE-538286](https://snyk.io/vuln/SNYK-UPSTREAM-NODE-538286) | Proof of Concept | | ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **821** | Improper Certificate Validation <br/>[SNYK-UPSTREAM-NODE-546815](https://snyk.io/vuln/SNYK-UPSTREAM-NODE-546815) | Proof of Concept | | ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **725** | Memory Corruption <br/>[SNYK-UPSTREAM-NODE-570870](https://snyk.io/vuln/SNYK-UPSTREAM-NODE-570870) | No Known Exploit | --- **Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs._ For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiJhNmE1NTczOC05MjFmLTQyYjEtOWYyNy0wOTAyYzA2ZWM5MDYiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6ImE2YTU1NzM4LTkyMWYtNDJiMS05ZjI3LTA5MDJjMDZlYzkwNiJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/hoppscotch/project/1bf83de7-12ed-4296-bb8a-a1df83fde800) 🛠 [Adjust project settings](https://app.snyk.io/org/hoppscotch/project/1bf83de7-12ed-4296-bb8a-a1df83fde800/settings) [//]: # 'snyk:metadata:{"prId":"a6a55738-921f-42b1-9f27-0902c06ec906","prPublicId":"a6a55738-921f-42b1-9f27-0902c06ec906","dependencies":[{"name":"node","from":"12.10.0-alpine","to":"12-alpine"}],"packageManager":"dockerfile","projectPublicId":"1bf83de7-12ed-4296-bb8a-a1df83fde800","projectUrl":"https://app.snyk.io/org/hoppscotch/project/1bf83de7-12ed-4296-bb8a-a1df83fde800?utm_source=github&utm_medium=fix-pr","type":"user-initiated","patch":[],"vulns":["SNYK-UPSTREAM-NODE-546815","SNYK-UPSTREAM-NODE-538286","SNYK-UPSTREAM-NODE-538285","SNYK-UPSTREAM-NODE-1055465","SNYK-UPSTREAM-NODE-570870"],"upgrade":["SNYK-UPSTREAM-NODE-1055465","SNYK-UPSTREAM-NODE-538285","SNYK-UPSTREAM-NODE-538286","SNYK-UPSTREAM-NODE-546815","SNYK-UPSTREAM-NODE-570870"],"isBreakingChange":false,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[821,821,821,821,725]}' --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
kerem 2026-03-17 01:03:59 +03:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/hoppscotch#3451
No description provided.