Skip to content

[Snyk] Security upgrade python from 3.9-slim to 3.14.3-slim#553

Closed
spolti wants to merge 1 commit intorelease-v0.11.1from
snyk-fix-476e9e51c39090e51ecfcad2e968e210
Closed

[Snyk] Security upgrade python from 3.9-slim to 3.14.3-slim#553
spolti wants to merge 1 commit intorelease-v0.11.1from
snyk-fix-476e9e51c39090e51ecfcad2e968e210

Conversation

@spolti
Copy link
Copy Markdown
Owner

@spolti spolti commented Feb 10, 2026

snyk-top-banner

Snyk has created this PR to fix 3 vulnerabilities in the dockerfile dependencies of this project.

Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Snyk changed the following file(s):

  • docs/samples/kafka/transformer.Dockerfile

We recommend upgrading to python:3.14.3-slim, as this image has only 26 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity CVE-2025-69421
SNYK-DEBIAN13-OPENSSL-15123186
  686  
high severity CVE-2025-69421
SNYK-DEBIAN13-OPENSSL-15123186
  686  
high severity CVE-2025-69421
SNYK-DEBIAN13-OPENSSL-15123186
  686  
low severity CVE-2025-11187
SNYK-DEBIAN13-OPENSSL-15123211
  436  
low severity CVE-2025-69418
SNYK-DEBIAN13-OPENSSL-15123213
  436  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@github-actions
Copy link
Copy Markdown

This pull request has been automatically detected as stale because it has not had any activity for 30 days. It will receive two more warnings before being automatically closed. If this pull request is still relevant, please comment or remove the stale label. Add the ignore-stale label to keep this pull request open indefinitely. Warning 1 of 3.

@github-actions
Copy link
Copy Markdown

This pull request is still stale. It will receive one more warning before being automatically closed. Please comment or remove the stale labels if this pull request is still relevant. Add the ignore-stale label to keep this pull request open indefinitely. Warning 2 of 3.

@github-actions
Copy link
Copy Markdown

This is the final warning. This pull request will be automatically closed if there is no activity within the next day. Please comment or remove the stale labels if this pull request is still relevant. Add the ignore-stale label to keep this pull request open indefinitely. Warning 3 of 3.

@github-actions
Copy link
Copy Markdown

This pull request has been automatically closed after 3 warnings with no activity. If you believe this pull request is still relevant, feel free to reopen it.

@github-actions github-actions Bot closed this Apr 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants