Skip to content

build: security upgrade python from 3.14.3-slim to 3.14.5-slim#1005

Merged
TomerFi merged 1 commit into
devfrom
snyk-fix-90cb9f4f5238bd2861bf886c2a0be458
Jun 3, 2026
Merged

build: security upgrade python from 3.14.3-slim to 3.14.5-slim#1005
TomerFi merged 1 commit into
devfrom
snyk-fix-90cb9f4f5238bd2861bf886c2a0be458

Conversation

@snyk-io
Copy link
Copy Markdown
Contributor

@snyk-io snyk-io Bot commented Jun 3, 2026

snyk-top-banner

Snyk has created this PR to fix 3 vulnerabilities in the dockerfile dependencies of this project.

Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Snyk changed the following file(s):

  • Dockerfile

We recommend upgrading to python:3.14.5-slim, as this image has only 43 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
critical severity CVE-2026-31789
SNYK-DEBIAN13-OPENSSL-15969301
  714  
critical severity CVE-2026-31789
SNYK-DEBIAN13-OPENSSL-15969301
  714  
critical severity CVE-2026-31789
SNYK-DEBIAN13-OPENSSL-15969301
  714  
high severity CVE-2026-28389
SNYK-DEBIAN13-OPENSSL-15969306
  614  
high severity CVE-2026-28387
SNYK-DEBIAN13-OPENSSL-15969307
  614  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@snyk-io snyk-io Bot requested review from TomerFi, YogevBokobza and dmatik as code owners June 3, 2026 22:27
@auto-me-bot auto-me-bot Bot added the status: needs review Pull request needs a review label Jun 3, 2026
@snyk-io
Copy link
Copy Markdown
Contributor Author

snyk-io Bot commented Jun 3, 2026

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@auto-me-bot auto-me-bot Bot added status: approved Pull request is approved and removed status: needs review Pull request needs a review labels Jun 3, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Jun 3, 2026

Test Results

69 tests   69 ✅  1s ⏱️
 1 suites   0 💤
 1 files     0 ❌

Results for commit f95a6e1.

@TomerFi TomerFi changed the title [Snyk] Security upgrade python from 3.14.3-slim to 3.14.5-slim build: security upgrade python from 3.14.3-slim to 3.14.5-slim Jun 3, 2026
@TomerFi TomerFi enabled auto-merge (squash) June 3, 2026 22:28
@codecov
Copy link
Copy Markdown

codecov Bot commented Jun 3, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 96.07%. Comparing base (c0ea4e9) to head (f95a6e1).

Additional details and impacted files
@@           Coverage Diff           @@
##              dev    #1005   +/-   ##
=======================================
  Coverage   96.07%   96.07%           
=======================================
  Files           1        1           
  Lines         331      331           
=======================================
  Hits          318      318           
  Misses         13       13           
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@TomerFi TomerFi merged commit 35e2522 into dev Jun 3, 2026
11 checks passed
@TomerFi TomerFi deleted the snyk-fix-90cb9f4f5238bd2861bf886c2a0be458 branch June 3, 2026 22:36
@auto-me-bot auto-me-bot Bot added status: merged Pull request merged and removed status: approved Pull request is approved labels Jun 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status: merged Pull request merged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant