-
Notifications
You must be signed in to change notification settings - Fork 1.8k
chore(deps): update redis docker tag from 7.2.11 to v8 (docker-compose.yml) #12389
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: dev
Are you sure you want to change the base?
Conversation
This pull request contains a no-op image reference change in the docker-compose.yml file, where an identical Redis image is added and removed without introducing any actual modifications or security implications.
|
Vulnerability | No-op Image Reference |
---|---|
Description | The docker-compose.yml patch shows an identical Redis image reference being added and removed. This means no actual change was made to the image specification, resulting in no new security implications or modifications to the existing configuration. |
django-DefectDojo/docker-compose.yml
Lines 114 to 120 in c1881af
- defectdojo_postgres:/var/lib/postgresql/data | |
redis: | |
# Pinning to this version due to licensing constraints | |
image: redis:8.0.2-alpine@sha256:48501c5ad00d5563bc30c075c7bcef41d7d98de3e9a1e6c752068c66f0a8463b | |
volumes: | |
- defectdojo_redis:/data | |
volumes: |
All finding details can be found in the DryRun Security Dashboard.
0124d07
to
9258a9b
Compare
docker-compose.yml
Outdated
redis: | ||
# Pinning to this version due to licensing constraints | ||
image: redis:7.2.8-alpine@sha256:c88ea2979a49ca497bbf7d39241b237f86c98e58cb2f6b1bc2dd167621f819bb | ||
image: redis:8.0.0-alpine@sha256:0779069b3c24a47a2f681855c1c01d046793e7c5f7d2b079c2aa0652c42eaf0e |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looking at license change.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We may migrate to ValKey instead of updating Redis to a newer version.
Testing ValKey is currently happening.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Leaving a review comment to test something
81d59f4
to
e7f6ac3
Compare
9a969e0
to
e7aed07
Compare
e7aed07
to
c1881af
Compare
Update on this - we're looking at migrating to ValKey - that is currently being run on the public demo without issues. |
e6703bb
to
494fdad
Compare
494fdad
to
e2752dd
Compare
e2752dd
to
399987e
Compare
de9cbbb
to
18c5ad1
Compare
This pull request has conflicts, please resolve those before we can evaluate the pull request. |
18c5ad1
to
0b63e81
Compare
Conflicts have been resolved. A maintainer will review the pull request shortly. |
0b63e81
to
c5f9ba6
Compare
c5f9ba6
to
63a914b
Compare
This PR contains the following updates:
7.2.11-alpine
->8.2.2-alpine
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.