Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update postgres docker tag from 17.3 to v17.4 (docker-compose.yml) #11876

Merged
merged 1 commit into from
Feb 24, 2025

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Feb 22, 2025

This PR contains the following updates:

Package Update Change
postgres minor 17.3-alpine -> 17.4-alpine

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Feb 22, 2025
Copy link

dryrunsecurity bot commented Feb 22, 2025

DryRun Security Summary

The PR upgrades PostgreSQL from 17.3-alpine to 17.4-alpine in docker-compose.yml while identifying security concerns around default and hardcoded credentials in environment variables.

Expand for full summary

The PR updates the PostgreSQL service configuration in docker-compose.yml, upgrading the image from 17.3-alpine to 17.4-alpine. Security findings include: potential security risks from default credentials for POSTGRES_DB, POSTGRES_USER, and POSTGRES_PASSWORD; hardcoded sensitive environment variables like DD_SECRET_KEY, DD_CREDENTIAL_AES_256_KEY, and database credentials that could expose sensitive information if not properly managed.

Code Analysis

We ran 9 analyzers against 1 file and 0 analyzers had findings. 9 analyzers had no findings.

View PR in the DryRun Dashboard.

@renovate renovate bot force-pushed the renovate/postgres-17.x branch from 02f4e13 to 84e547c Compare February 22, 2025 07:10
Copy link
Contributor

@mtesauro mtesauro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@mtesauro mtesauro merged commit a375694 into dev Feb 24, 2025
74 checks passed
@renovate renovate bot deleted the renovate/postgres-17.x branch March 3, 2025 16:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file docker
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants