-
Notifications
You must be signed in to change notification settings - Fork 1.7k
Update redis Docker tag from 7.2.10 to v7.4.5 (docker-compose.yml) #10651
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: dev
Are you sure you want to change the base?
Conversation
DryRun Security SummaryThe Redis service image is being updated from 7.2.5 to 7.4.2, while security concerns were identified regarding hardcoded sensitive environment variables including database credentials and secret keys in docker-compose.yml. Expand for full summaryThe PR updates the Redis service image version from 7.2.5 to 7.4.2 in docker-compose.yml, with potential version-specific security patches. Security findings include:
Code AnalysisWe ran |
6566fce
to
2b696b5
Compare
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We're going to hold off on this one while we determine any implications of the change to Redis' licensing
2b696b5
to
d607bfa
Compare
effef4a
to
6e06773
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
blocking
73794a9
to
bcc2c8d
Compare
No security concerns detected in this pull request. All finding details can be found in the DryRun Security Dashboard. |
bcc2c8d
to
beb326d
Compare
6904e0a
to
1760d4c
Compare
1760d4c
to
a3ea2ac
Compare
This PR contains the following updates:
7.2.10-alpine
->7.4.5-alpine
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.