Bump unidata/tomcat-docker from 1a5fb1b to 3f8ba8c#23
Conversation
Bumps unidata/tomcat-docker from `1a5fb1b` to `3f8ba8c`. Signed-off-by: dependabot[bot] <support@github.com>
|
@julienchastang The |
|
I have to regularly update that container to take into account security "Common Vulnerabilities and Exposures" (CVEs). Note that the parent container (e.g., |
|
Thanks @julienchastang , I assumed that was the case but wanted to double check. Do you have auto-builds setup through DockerHub? @abkfenris Implemented a nice pin-to-hash setup for this repository that creates a PR each time the base image changes, that might help you control the build process a little more if that is something you are interested in! #18 and #19. |
|
@julienchastang Here are a summary of the changes that I've done to make the docker-erddap builds more reproducible. It took a little bit to figure out the exact setup hence the multiple PRs.
|
|
I just glanced at this, but GitHub actions seems to be the right approach and one that I plan on diving into myself. Yes, currently, I rely on DockerHub for triggered builds for THREDDS and RAMADDA. Though note that I cannot trigger on the official tomcat parent container. DockerHub does not allow it (probably results in too many builds). Again, GitHub actions probably provides a solution here. |
|
I can take a swing at a PR if you'd like. |
Bumps unidata/tomcat-docker from
1a5fb1bto3f8ba8c.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)