Skip to content

Bump Alpine to 3.15.1, add support for dependabot#23

Open
gaby wants to merge 1 commit intoappwrite:masterfrom
gaby:bump-dependencies
Open

Bump Alpine to 3.15.1, add support for dependabot#23
gaby wants to merge 1 commit intoappwrite:masterfrom
gaby:bump-dependencies

Conversation

@gaby
Copy link
Copy Markdown

@gaby gaby commented Mar 23, 2022

  • Bump Alpine to v3.15.1 which introduces fixes for several CVE's including BusyBox, OpenSSL, etc
  • Add support for dependabot, to auto create PR's when the base image gets updated.
  • Add apk -U upgrade to catch any base alpine package that needs to be updated.

@gaby
Copy link
Copy Markdown
Author

gaby commented Mar 23, 2022

@eldadfux Another one.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant