Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump nginx from b9e1705 to d05f6fe in /docker-nginx #62

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 10, 2025

Bumps nginx from b9e1705 to d05f6fe.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps nginx from `b9e1705` to `d05f6fe`.

---
updated-dependencies:
- dependency-name: nginx
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Feb 10, 2025
@jon-signal jon-signal self-requested a review February 10, 2025 14:02
@katherine-signal
Copy link

katherine-signal commented Feb 10, 2025

Here's a diff of the changes from b9e1705b to d05f6fee. I ended up following what Chris did because poking around the docker-library/repo-info repos was not fruitful (I wasn't sure how to get a git diff of a non-tag/branch in the github UI, and locally it was just too detailed code changes to sift through). As the doc mentioned, it was difficult to pick out a high-level summary of the changes, but here is what I think is relevant:

  • I did the "follow base image digest back" directions, and the base Alpine image did not change from 3.20.5.
    • But the diff shows that the docker-nginx source changed from nginxinc/docker-nginx@2396849 to nginxinc/docker-nginx@cffeb93, and one of the changes included between the two commits was bumping the mainline branch to Alpine 3.21, which I wasn't quite able to reconcile with the point above...
  • Bumped nginx version from 1.26.2 to 1.26.3, which contained some bug/security fixes and also took along some dependency version updates (commit)
    • There are a bunch of usr/lib/nginx/modules/... SHA digest changes, which I think is associated with this?
  • And then there were also some Alpine package manager related updates? e.g.lib/apk/db/scripts.tar, etc/apk/world, and lib/apk/db/installed

Things I wasn't sure about:

  • Whether the base Alpine image actually changed (I don't think so?)
  • What some of the ManifestBlobMismatch events in the diff referred to
  • If there are any other updates with the nginx update that I've missed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Development

Successfully merging this pull request may close these issues.

1 participant