Skip to content

CVE Fixes#41

Merged
amattu2 merged 1 commit into3.2.0from
CVE-fix
Dec 12, 2025
Merged

CVE Fixes#41
amattu2 merged 1 commit into3.2.0from
CVE-fix

Conversation

@amattu2
Copy link

@amattu2 amattu2 commented Dec 12, 2025

Overview

N/A

Change Details (Specifics)

N/A

Related Ticket(s)

N/A

@amattu2 amattu2 marked this pull request as ready for review December 12, 2025 20:50
Copilot AI review requested due to automatic review settings December 12, 2025 20:50
@amattu2 amattu2 temporarily deployed to ccdi-manager-nonprod December 12, 2025 20:53 — with GitHub Actions Inactive
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request aims to address CVE-2025-64756 by updating the Docker base image and npm version. However, there are several concerns with the implementation that need to be addressed before merging.

Key Changes:

  • Updated Alpine Linux base image from version 3.20 to 3.23
  • Added global npm update to latest version during image build

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@amattu2 amattu2 requested a review from kiran1942 December 12, 2025 20:59
@amattu2 amattu2 changed the title fix: CVE-2025-64756 CVE Fixes Dec 12, 2025
@amattu2 amattu2 added this to the 3.2.0 milestone Dec 12, 2025
@amattu2 amattu2 merged commit 275cef1 into 3.2.0 Dec 12, 2025
14 of 15 checks passed
@amattu2 amattu2 deleted the CVE-fix branch December 12, 2025 21:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants