Propose remediation for dockerfile_lint transitive vulnerabilities#151
Open
assitantforjess wants to merge 1 commit intoprojectatomic:masterfrom
Open
Propose remediation for dockerfile_lint transitive vulnerabilities#151assitantforjess wants to merge 1 commit intoprojectatomic:masterfrom
assitantforjess wants to merge 1 commit intoprojectatomic:masterfrom
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Title: Remediate dockerfile_lint transitive vulnerabilities (lodash / js-yaml)
Summary:
dockerfile_lint depends on transitive packages that currently expose critical or moderate advisories (lodash prototype pollution, js-yaml issues). Upstream does not provide a direct automated fix in the current release.
Options for maintainers:
A) Bump transitive dependencies (if compatible): update junit-report-builder and lodash to patched versions.
B) Replace dockerfile_lint with an actively maintained alternative for CI linting of Dockerfiles.
C) Accept a short-term patch/fork approach where we prepare a PR that updates dependency ranges and test.
Suggested minimal diff for package.json (if bumpable):
(Adjust versions after testing — this example is illustrative.)
Our offer:
Recommendation: