From 7676350d8a098925f13735bf40975979e5c106e7 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 31 Jan 2024 16:41:55 +0000 Subject: [PATCH] Bump logstash from 8.11.3 to 8.12.0 in /projects/person-search-index-from-delius/container (#3056) * Bump logstash in /projects/person-search-index-from-delius/container Bumps logstash from 8.11.3 to 8.12.0. --- updated-dependencies: - dependency-name: logstash dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] * Extend suppression for logstash Derby vulnerability --------- Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Marcus Aspin --- projects/person-search-index-from-delius/.trivyignore | 2 +- projects/person-search-index-from-delius/container/Dockerfile | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/projects/person-search-index-from-delius/.trivyignore b/projects/person-search-index-from-delius/.trivyignore index 680435198b..3467a96150 100644 --- a/projects/person-search-index-from-delius/.trivyignore +++ b/projects/person-search-index-from-delius/.trivyignore @@ -2,7 +2,7 @@ # Reason: LDAP authentication not used + no untrusted username input # Package: org.apache.derby:derby:10.14.1.0 # Reference: https://github.com/logstash-plugins/logstash-integration-jdbc/issues/147 -CVE-2022-46337 exp:2024-01-12 +CVE-2022-46337 # Reason: we don't use Maven # Package: org.apache.maven:maven-compat:3.3.9 diff --git a/projects/person-search-index-from-delius/container/Dockerfile b/projects/person-search-index-from-delius/container/Dockerfile index 3c6baf5855..9ca121a483 100644 --- a/projects/person-search-index-from-delius/container/Dockerfile +++ b/projects/person-search-index-from-delius/container/Dockerfile @@ -4,7 +4,7 @@ COPY --chown=yq /pipelines /pipelines RUN find /pipelines -type f -name '*.yml' -exec sh -c 'f="$1"; yq -o=json "$f" > "${f%.yml}.json"' shell {} +; -FROM logstash:8.11.3 +FROM logstash:8.12.0 USER root SHELL ["/bin/bash", "-o", "pipefail", "-c"]