Skip to content

chore(deps): update redis docker tag from 7.2.11 to v7.4.6 (docker-compose.yml) - abandoned - autoclosed#10651

Closed
renovate[bot] wants to merge 1 commit into
devfrom
renovate/redis-7.x
Closed

chore(deps): update redis docker tag from 7.2.11 to v7.4.6 (docker-compose.yml) - abandoned - autoclosed#10651
renovate[bot] wants to merge 1 commit into
devfrom
renovate/redis-7.x

Conversation

@renovate

@renovate renovate Bot commented Jul 30, 2024

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
redis minor 7.2.11-alpine -> 7.4.6-alpine

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Jul 30, 2024
@dryrunsecurity

dryrunsecurity Bot commented Jul 30, 2024

Copy link
Copy Markdown

DryRun Security Summary

The Redis service image is being updated from 7.2.5 to 7.4.2, while security concerns were identified regarding hardcoded sensitive environment variables including database credentials and secret keys in docker-compose.yml.

Expand for full summary

The PR updates the Redis service image version from 7.2.5 to 7.4.2 in docker-compose.yml, with potential version-specific security patches. Security findings include:

  1. Hardcoded sensitive environment variables in docker-compose.yml:
    • Database credentials (DD_DATABASE_USER, DD_DATABASE_PASSWORD)
    • Secret keys (DD_SECRET_KEY, DD_CREDENTIAL_AES_256_KEY)
      These default credentials pose a significant security risk if not changed in production environments.

Code Analysis

We ran 9 analyzers against 1 file and 0 analyzers had findings. 9 analyzers had no findings.

View PR in the DryRun Dashboard.

@renovate renovate Bot force-pushed the renovate/redis-7.x branch from 6566fce to 2b696b5 Compare July 30, 2024 06:17
@sonarqubecloud

Copy link
Copy Markdown

mtesauro
mtesauro previously approved these changes Jul 30, 2024
@mtesauro mtesauro self-requested a review July 30, 2024 16:56

@cneill cneill left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're going to hold off on this one while we determine any implications of the change to Redis' licensing

@mtesauro mtesauro dismissed their stale review July 30, 2024 16:59

Reviewing license change

@renovate renovate Bot changed the title Update redis Docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) chore(deps): update redis docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Aug 2, 2024
@renovate renovate Bot force-pushed the renovate/redis-7.x branch from 2b696b5 to d607bfa Compare August 3, 2024 01:44
@renovate renovate Bot changed the title chore(deps): update redis docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Update redis Docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Aug 13, 2024
@renovate renovate Bot changed the title Update redis Docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) chore(deps): update redis docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Aug 14, 2024
@renovate renovate Bot changed the title chore(deps): update redis docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Update redis Docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Aug 14, 2024
@renovate renovate Bot changed the title Update redis Docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) chore(deps): update redis docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Aug 19, 2024
@renovate renovate Bot changed the title chore(deps): update redis docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Update redis Docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Aug 29, 2024
@renovate renovate Bot changed the title Update redis Docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) chore(deps): update redis docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Aug 30, 2024
@renovate renovate Bot changed the title chore(deps): update redis docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Update redis Docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Aug 30, 2024
@renovate renovate Bot changed the title Update redis Docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) chore(deps): update redis docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Sep 1, 2024
@renovate renovate Bot force-pushed the renovate/redis-7.x branch 6 times, most recently from effef4a to 6e06773 Compare September 9, 2024 14:23
@renovate renovate Bot changed the title chore(deps): update redis docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Update redis Docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Sep 16, 2024
@renovate renovate Bot changed the title Update redis Docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) chore(deps): update redis docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Sep 17, 2024
@renovate renovate Bot changed the title chore(deps): update redis docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Update redis Docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Sep 17, 2024
@renovate renovate Bot changed the title Update redis Docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) chore(deps): update redis docker tag from 7.2.5 to v7.4.0 (docker-compose.yml) Sep 19, 2024
@renovate renovate Bot force-pushed the renovate/redis-7.x branch from 1ed4142 to 52392fd Compare January 10, 2025 18:57
@renovate renovate Bot changed the title Update redis Docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) chore(deps): update redis docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Jan 21, 2025
@renovate renovate Bot changed the title chore(deps): update redis docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Update redis Docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Jan 28, 2025
@renovate renovate Bot changed the title Update redis Docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) chore(deps): update redis docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Jan 28, 2025
@renovate renovate Bot changed the title chore(deps): update redis docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Update redis Docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Feb 4, 2025
@renovate renovate Bot changed the title Update redis Docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) chore(deps): update redis docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Feb 5, 2025
@renovate renovate Bot changed the title chore(deps): update redis docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Update redis Docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Feb 6, 2025
@renovate renovate Bot changed the title Update redis Docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) chore(deps): update redis docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Feb 6, 2025
@renovate renovate Bot changed the title chore(deps): update redis docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Update redis Docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Feb 6, 2025
@renovate renovate Bot changed the title Update redis Docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) chore(deps): update redis docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Feb 7, 2025
@renovate renovate Bot changed the title chore(deps): update redis docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Update redis Docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Feb 7, 2025
@renovate renovate Bot changed the title Update redis Docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) chore(deps): update redis docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Feb 12, 2025
@renovate renovate Bot changed the title chore(deps): update redis docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Update redis Docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Feb 12, 2025
@renovate renovate Bot changed the title Update redis Docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) chore(deps): update redis docker tag from 7.2.5 to v7.4.2 (docker-compose.yml) Feb 13, 2025
@renovate

renovate Bot commented Feb 24, 2025

Copy link
Copy Markdown
Contributor Author

Autoclosing Skipped

This PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error.

@github-actions

Copy link
Copy Markdown
Contributor

This pull request has conflicts, please resolve those before we can evaluate the pull request.

@github-actions

Copy link
Copy Markdown
Contributor

Conflicts have been resolved. A maintainer will review the pull request shortly.

@dryrunsecurity

dryrunsecurity Bot commented Apr 23, 2025

Copy link
Copy Markdown

DryRun Security

This pull request identifies a potential security risk in the Redis image configuration, where pinning to a specific digest may delay critical security updates and requires a manual review process to ensure timely patching.

⚠️ Dependency Update Risk in docker-compose.yml
Vulnerability Dependency Update Risk
Description The Redis image is pinned to a specific digest (7.4.4-alpine), which can potentially delay security updates. While this provides image immutability, it requires manual intervention to incorporate security patches. The team should establish a process for regularly reviewing and updating image digests to mitigate potential security risks.

- defectdojo_postgres:/var/lib/postgresql/data
redis:
# Pinning to this version due to licensing constraints
image: redis:7.4.4-alpine@sha256:ee9e8748ace004102a267f7b8265dab2c618317df22507b89d16a8add7154273
volumes:
- defectdojo_redis:/data
volumes:


All finding details can be found in the DryRun Security Dashboard.

@mtesauro mtesauro left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The new license for 7.4.x causes issues with our open source stance and being part of OWASP - being an OWASP project we should be using only OSI approved licenses.

@Maffooch Maffooch left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

blocking

@valentijnscholten

Copy link
Copy Markdown
Member

@mtesauro I suggest we close/ignore this one and focus in v8? #12389

@mtesauro

Copy link
Copy Markdown
Contributor

Update on this - we're looking at migrating to ValKey - that is currently being run on the public demo without issues.

@dryrunsecurity

dryrunsecurity Bot commented Oct 9, 2025

Copy link
Copy Markdown

DryRun Security

This pull request pins Redis to version 7.4.6 in docker-compose.yml, which is within the range affected by CVE-2025-49844 (allows an authenticated user to exploit a specially crafted Lua script). Consider upgrading Redis to a non-vulnerable version (e.g., >8.2.1) or verifying the digest points to a patched image.

Vulnerable Dependency Version in docker-compose.yml
Vulnerability Vulnerable Dependency Version
Description The docker-compose.yml specifies redis:7.4.6-alpine pinned to a SHA256 digest. Assuming this digest corresponds to the 7.4.6-alpine tag, Redis version 7.4.6 is vulnerable to CVE-2025-49844. This CVE affects Redis versions 8.2.1 and below, allowing an authenticated user to exploit a weakness via a specially crafted Lua script.

image: redis:7.4.6-alpine@sha256:3b73847e72874be07e6657b129a94761662b79bc0f679273757d4218573b2a98
volumes:
- defectdojo_redis:/data
volumes:


All finding details can be found in the DryRun Security Dashboard.

@github-actions

Copy link
Copy Markdown
Contributor

This pull request has conflicts, please resolve those before we can evaluate the pull request.

@github-actions

Copy link
Copy Markdown
Contributor

Conflicts have been resolved. A maintainer will review the pull request shortly.

@github-actions

Copy link
Copy Markdown
Contributor

This pull request has conflicts, please resolve those before we can evaluate the pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

conflicts-detected dependencies Pull requests that update a dependency file docker

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants