From a081c478069c0f7a9110b2bef9ce5d2e9aa279c0 Mon Sep 17 00:00:00 2001 From: Soumen Mukherjee Date: Fri, 24 Feb 2023 00:44:48 +0530 Subject: [PATCH 1/4] updated flag to false --- pkg/proxy/proxy.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkg/proxy/proxy.go b/pkg/proxy/proxy.go index a032e4a..24e4781 100644 --- a/pkg/proxy/proxy.go +++ b/pkg/proxy/proxy.go @@ -21,7 +21,7 @@ import ( var ( transport = &http.Transport{ Proxy: http.ProxyFromEnvironment, - TLSClientConfig: &tls.Config{InsecureSkipVerify: true}, + TLSClientConfig: &tls.Config{InsecureSkipVerify: false}, } httpClient = &http.Client{ Timeout: time.Second * 30, From 25af0b3c09a56a85484f64ed50e43fbb1646505f Mon Sep 17 00:00:00 2001 From: Soumen Mukherjee Date: Fri, 24 Feb 2023 12:19:58 +0530 Subject: [PATCH 2/4] Update proxy.go --- pkg/proxy/proxy.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkg/proxy/proxy.go b/pkg/proxy/proxy.go index 24e4781..a032e4a 100644 --- a/pkg/proxy/proxy.go +++ b/pkg/proxy/proxy.go @@ -21,7 +21,7 @@ import ( var ( transport = &http.Transport{ Proxy: http.ProxyFromEnvironment, - TLSClientConfig: &tls.Config{InsecureSkipVerify: false}, + TLSClientConfig: &tls.Config{InsecureSkipVerify: true}, } httpClient = &http.Client{ Timeout: time.Second * 30, From d97ab6fff0f75e978fc0a5abffaebccb18eae8ef Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 24 Feb 2023 07:14:35 +0000 Subject: [PATCH 3/4] fix: build/package/Dockerfile.build to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-ALPINE310-APKTOOLS-1246341 - https://snyk.io/vuln/SNYK-ALPINE310-APKTOOLS-1534688 - https://snyk.io/vuln/SNYK-ALPINE310-BUSYBOX-1090151 - https://snyk.io/vuln/SNYK-ALPINE310-BUSYBOX-1090151 - https://snyk.io/vuln/SNYK-ALPINE310-OPENSSL-1075741 --- build/package/Dockerfile.build | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/build/package/Dockerfile.build b/build/package/Dockerfile.build index 0383c68..9b04b07 100644 --- a/build/package/Dockerfile.build +++ b/build/package/Dockerfile.build @@ -1,4 +1,4 @@ -FROM golang:1.13.1-alpine +FROM golang:1.19.5-alpine MAINTAINER "Stakater Team" RUN apk update From d2d3e8088b00ce43b8da65e733849ab14c519088 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 24 Feb 2023 07:17:33 +0000 Subject: [PATCH 4/4] fix: build/package/Dockerfile.run to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-ALPINE39-MUSL-1042761 - https://snyk.io/vuln/SNYK-ALPINE39-OPENSSL-1089232 - https://snyk.io/vuln/SNYK-ALPINE39-OPENSSL-1089232 - https://snyk.io/vuln/SNYK-ALPINE39-OPENSSL-1089235 - https://snyk.io/vuln/SNYK-ALPINE39-OPENSSL-1089235 --- build/package/Dockerfile.run | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/build/package/Dockerfile.run b/build/package/Dockerfile.run index 9d2ef4f..3195984 100644 --- a/build/package/Dockerfile.run +++ b/build/package/Dockerfile.run @@ -1,4 +1,4 @@ -FROM alpine:3.9 +FROM alpine:3.15 MAINTAINER "Stakater Team" RUN apk add --update ca-certificates