[Snyk] Security upgrade python from 3.7-slim to 3.14.3-slim#140
[Snyk] Security upgrade python from 3.7-slim to 3.14.3-slim#140
Conversation
… reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-DEBIAN12-GLIBC-5927132 - https://snyk.io/vuln/SNYK-DEBIAN12-GLIBC-5927132 - https://snyk.io/vuln/SNYK-DEBIAN12-GLIBC-6210098 - https://snyk.io/vuln/SNYK-DEBIAN12-GLIBC-6210098 - https://snyk.io/vuln/SNYK-DEBIAN12-SYSTEMD-6277507
Dependency Review✅ No vulnerabilities or license issues found.Scanned Manifest Files |
There was a problem hiding this comment.
Pull request overview
Updates the Terraform-managed Docker build context to use a newer Python slim base image to reduce known OS/package vulnerabilities in the resulting container pushed to ECR.
Changes:
- Update Docker base image from
python:3.7-slimtopython:3.14.3-slim.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| @@ -1 +1 @@ | |||
| FROM python:3.7-slim | |||
| FROM python:3.14.3-slim | |||
There was a problem hiding this comment.
This bumps the base image from Python 3.7 to 3.14.3 in one step, which is a major runtime jump and can break dependency compatibility and/or downstream consumers of this ECR image. If the project doesn’t explicitly support 3.14 yet, consider upgrading to a known-supported Python version first (or doing incremental upgrades), and ensure CI builds/tests (or at least a docker build) run against the new base image before merging.
Snyk has created this PR to fix 3 vulnerabilities in the dockerfile dependencies of this project.
Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.
Snyk changed the following file(s):
Infrastructure-Source-Code/terraform/aws/resources/DockerfileWe recommend upgrading to
python:3.14.3-slim, as this image has only 26 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.Vulnerabilities that will be fixed with an upgrade:
SNYK-DEBIAN12-GLIBC-5927132
SNYK-DEBIAN12-GLIBC-5927132
SNYK-DEBIAN12-GLIBC-6210098
SNYK-DEBIAN12-GLIBC-6210098
SNYK-DEBIAN12-SYSTEMD-6277507
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Out-of-bounds Write
🦉 Allocation of Resources Without Limits or Throttling