Skip to content

Conversation

@mprins
Copy link
Member

@mprins mprins commented Jan 26, 2026

@mprins mprins self-assigned this Jan 26, 2026
@mprins mprins added dependencies Pull requests that update a dependency file security labels Jan 26, 2026
zie: https://github.com/jwilder/dockerize/releases/tag/v0.9.9

Upgrades to Go 1.25.5 to address CVE-2025-61729, addresses HIGH severity vulnerability in Go stdlib.
17 is the default version for Debian Trixie
@mprins mprins marked this pull request as ready for review January 26, 2026 09:48
Copilot AI review requested due to automatic review settings January 26, 2026 09:48
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the Docker image dependencies and base OS to maintain security and compatibility. The changes upgrade OFELIA to 0.3.20, dockerize to 0.9.9 (which addresses a high-severity vulnerability in Go stdlib), and migrates from Debian Bookworm to Debian Trixie ahead of Bookworm's EOL in mid-2026.

Changes:

  • Update base image from Debian Bookworm to Debian Trixie
  • Update OFELIA scheduler from version 0.3.19 to 0.3.20
  • Update dockerize from version 0.9.6 to 0.9.9 (addresses security vulnerability)
  • Update PostgreSQL client from version 15 to 17 (default for Debian Trixie)

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Copy link
Contributor

@oscarporsius oscarporsius left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mprins mprins merged commit fc78c4e into main Jan 26, 2026
7 checks passed
@mprins mprins deleted the mprins-patch-1 branch January 26, 2026 10:27
@mprins mprins changed the title Update OFELIA_VERSION to 0.3.20 Update dependencies Jan 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants