Skip to content

[Snyk] Security upgrade ubuntu from noble-20260113 to 24.04#300

Open
kevin-benton wants to merge 1 commit intomainfrom
snyk-fix-c7cfc356d6cb023496fe408a15e47835
Open

[Snyk] Security upgrade ubuntu from noble-20260113 to 24.04#300
kevin-benton wants to merge 1 commit intomainfrom
snyk-fix-c7cfc356d6cb023496fe408a15e47835

Conversation

@kevin-benton
Copy link
Contributor

snyk-top-banner

Snyk has created this PR to fix 2 vulnerabilities in the dockerfile dependencies of this project.

Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Snyk changed the following file(s):

  • docker/util/Dockerfile

We recommend upgrading to ubuntu:24.04, as this image has only 9 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
medium severity Directory Traversal
SNYK-UBUNTU2404-PAM-11936905
  231  
medium severity Directory Traversal
SNYK-UBUNTU2404-PAM-11936905
  231  
medium severity Directory Traversal
SNYK-UBUNTU2404-PAM-11936905
  231  
medium severity Directory Traversal
SNYK-UBUNTU2404-PAM-11936905
  231  
medium severity Improper Verification of Cryptographic Signature
SNYK-UBUNTU2404-GNUPG2-14849569
  149  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Directory Traversal

@kevin-benton
Copy link
Contributor Author

Merge Risk: High

This represents a downgrade from a future-dated, hypothetical operating system build (noble-20260113) to the Ubuntu 24.04 LTS release from April 2024. This is an unusual and inherently high-risk operation.

Breaking Changes:

  • System Downgrade: You are moving from a 2026-era system to a 2024-era system. This will revert approximately two years of critical updates, including security patches, kernel features, and core system libraries.
  • Kernel Version: Ubuntu 24.04 LTS shipped with the 6.8 kernel. A system from 2026 would have a significantly newer kernel (e.g., 6.17 or later), meaning a loss of newer hardware support and kernel-level features.
  • Toolchain and Libraries: Ubuntu 24.04 uses core components like GCC 13/14, Python 3.12, and glibc 2.39. A 2026 system would have newer versions. Applications compiled on the newer system will likely fail to run on Ubuntu 24.04 due to missing library functions (e.g., in glibc).

Recommendation: Do not proceed with this downgrade. This is not a standard upgrade path and is almost certain to cause system instability and application failures. A fresh installation of the desired OS version is the only recommended approach.

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

Copy link

@github-advanced-security github-advanced-security bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Snyk Container found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants