Skip to content

Commit 4e10b97

Browse files
committed
chore: bumping deps and base images to resolve cves within images
Signed-off-by: Paul Yu <paul.d.yu@gmail.com>
1 parent 80c4b60 commit 4e10b97

22 files changed

Lines changed: 5814 additions & 5280 deletions

File tree

src/ai-service/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
# Use the official Python image as the base image
2-
FROM python:3.11.1-slim-buster
2+
FROM python:3.12.4-alpine
33

44
# Set the working directory to /app
55
WORKDIR /app

src/ai-service/requirements.txt

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
1-
fastapi==0.109.1
2-
uvicorn==0.22.0
3-
pydantic==2.5.0
4-
pytest==7.3.1
1+
fastapi==0.111.1
2+
uvicorn==0.30.3
3+
pydantic==2.8.2
4+
pytest==8.3.2
55
httpx
66
pyyaml
77
semantic-kernel==0.4.2.dev0
8-
azure.identity==1.16.1
9-
requests==2.32.0
8+
azure.identity==1.17.1
9+
requests==2.32.3
1010

11-
openai==1.23.2
12-
pillow==10.3.0
11+
openai==1.37.1
12+
pillow==10.4.0

src/makeline-service/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
# Use an official Golang runtime as a parent image
2-
FROM golang:1.20.5-alpine as builder
2+
FROM golang:1.22.5-alpine AS builder
33

44
# Set the working directory to /app
55
WORKDIR /app
@@ -14,7 +14,7 @@ COPY . /app
1414
RUN go build -ldflags "-X main.version=$APP_VERSION" -o main .
1515

1616
# Run the app on alpine
17-
FROM alpine:latest as runner
17+
FROM alpine:latest AS runner
1818

1919
ARG APP_VERSION=0.1.0
2020

src/makeline-service/go.mod

Lines changed: 29 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -1,59 +1,62 @@
11
module aks-store-demo/makeline-service
22

3-
go 1.20
3+
go 1.22
44

55
require (
6-
github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.6.0
7-
github.com/Azure/azure-sdk-for-go/sdk/data/azcosmos v0.3.6
8-
github.com/Azure/azure-sdk-for-go/sdk/messaging/azservicebus v1.7.0
6+
github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.7.0
7+
github.com/Azure/azure-sdk-for-go/sdk/data/azcosmos v1.0.3
8+
github.com/Azure/azure-sdk-for-go/sdk/messaging/azservicebus v1.7.1
99
github.com/Azure/go-amqp v1.0.5
10-
github.com/gin-contrib/cors v1.6.0
11-
github.com/gin-gonic/gin v1.9.1
10+
github.com/gin-contrib/cors v1.7.2
11+
github.com/gin-gonic/gin v1.10.0
1212
github.com/gofrs/uuid v4.4.0+incompatible
13-
go.mongodb.org/mongo-driver v1.11.7
13+
go.mongodb.org/mongo-driver v1.16.0
1414
)
1515

1616
require (
1717
github.com/Azure/azure-sdk-for-go v68.0.0+incompatible // indirect
18-
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.11.1 // indirect
19-
github.com/Azure/azure-sdk-for-go/sdk/internal v1.8.0 // indirect
18+
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.13.0 // indirect
19+
github.com/Azure/azure-sdk-for-go/sdk/internal v1.10.0 // indirect
2020
github.com/AzureAD/microsoft-authentication-library-for-go v1.2.2 // indirect
21-
github.com/bytedance/sonic v1.11.2 // indirect
21+
github.com/bytedance/sonic v1.11.9 // indirect
22+
github.com/bytedance/sonic/loader v0.1.1 // indirect
2223
github.com/chenzhuoyu/base64x v0.0.0-20230717121745-296ad89f973d // indirect
2324
github.com/chenzhuoyu/iasm v0.9.1 // indirect
24-
github.com/gabriel-vasile/mimetype v1.4.3 // indirect
25+
github.com/cloudwego/base64x v0.1.4 // indirect
26+
github.com/cloudwego/iasm v0.2.0 // indirect
27+
github.com/gabriel-vasile/mimetype v1.4.5 // indirect
2528
github.com/gin-contrib/sse v0.1.0 // indirect
2629
github.com/go-playground/locales v0.14.1 // indirect
2730
github.com/go-playground/universal-translator v0.18.1 // indirect
28-
github.com/go-playground/validator/v10 v10.19.0 // indirect
29-
github.com/goccy/go-json v0.10.2 // indirect
31+
github.com/go-playground/validator/v10 v10.22.0 // indirect
32+
github.com/goccy/go-json v0.10.3 // indirect
3033
github.com/golang-jwt/jwt/v5 v5.2.1 // indirect
31-
github.com/golang/snappy v0.0.1 // indirect
34+
github.com/golang/snappy v0.0.4 // indirect
3235
github.com/google/uuid v1.6.0 // indirect
3336
github.com/json-iterator/go v1.1.12 // indirect
34-
github.com/klauspost/compress v1.13.6 // indirect
35-
github.com/klauspost/cpuid/v2 v2.2.7 // indirect
37+
github.com/klauspost/compress v1.17.9 // indirect
38+
github.com/klauspost/cpuid/v2 v2.2.8 // indirect
3639
github.com/kylelemons/godebug v1.1.0 // indirect
3740
github.com/leodido/go-urn v1.4.0 // indirect
3841
github.com/mattn/go-isatty v0.0.20 // indirect
3942
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
4043
github.com/modern-go/reflect2 v1.0.2 // indirect
41-
github.com/montanaflynn/stats v0.7.0 // indirect
42-
github.com/pelletier/go-toml/v2 v2.1.1 // indirect
44+
github.com/montanaflynn/stats v0.7.1 // indirect
45+
github.com/pelletier/go-toml/v2 v2.2.2 // indirect
4346
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
4447
github.com/pkg/errors v0.9.1 // indirect
4548
github.com/twitchyliquid64/golang-asm v0.15.1 // indirect
4649
github.com/ugorji/go/codec v1.2.12 // indirect
4750
github.com/xdg-go/pbkdf2 v1.0.0 // indirect
48-
github.com/xdg-go/scram v1.1.1 // indirect
49-
github.com/xdg-go/stringprep v1.0.3 // indirect
50-
github.com/youmark/pkcs8 v0.0.0-20181117223130-1be2e3e5546d // indirect
51-
golang.org/x/arch v0.7.0 // indirect
52-
golang.org/x/crypto v0.24.0 // indirect
53-
golang.org/x/net v0.26.0 // indirect
51+
github.com/xdg-go/scram v1.1.2 // indirect
52+
github.com/xdg-go/stringprep v1.0.4 // indirect
53+
github.com/youmark/pkcs8 v0.0.0-20240726163527-a2c0da244d78 // indirect
54+
golang.org/x/arch v0.8.0 // indirect
55+
golang.org/x/crypto v0.25.0 // indirect
56+
golang.org/x/net v0.27.0 // indirect
5457
golang.org/x/sync v0.7.0 // indirect
55-
golang.org/x/sys v0.21.0 // indirect
58+
golang.org/x/sys v0.22.0 // indirect
5659
golang.org/x/text v0.16.0 // indirect
57-
google.golang.org/protobuf v1.33.0 // indirect
60+
google.golang.org/protobuf v1.34.2 // indirect
5861
gopkg.in/yaml.v3 v3.0.1 // indirect
5962
)

0 commit comments

Comments
 (0)