Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade docker file dependancy libpq-dev to 13.19-0+deb11u1 for secur… #11315

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

saudf
Copy link

@saudf saudf commented Feb 15, 2025

…ity reasons

Resolves #11314

Problem

The current Dockerfile installs libpq-dev 13.18-0+deb11u1 which contains the CVE-2025-1094 vulnerability.

Solution

Upgrade libpq-dev to 13.19-0+deb11u1 which is the patched version.

Checklist

  • I have read the contributing guide and understand what's expected of me.
  • I have run this code in development, and it appears to resolve the stated issue.
  • This PR includes tests, or tests are not required or relevant for this PR.
  • This PR has no interface changes (e.g., macros, CLI, logs, JSON artifacts, config files, adapter interface, etc.) or this PR has already received feedback and approval from Product or DX.
  • This PR includes type annotations for new and modified functions.

@saudf saudf requested a review from a team as a code owner February 15, 2025 14:52
@cla-bot cla-bot bot added the cla:yes label Feb 15, 2025
@github-actions github-actions bot added the community This PR is from a community member label Feb 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cla:yes community This PR is from a community member
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[Bug] libpq-dev in the docker file contains CVE-2025-1094, bump up to the fixed version
1 participant