From d600df785afe8648bc23cbcf4495d9d30075dcba Mon Sep 17 00:00:00 2001 From: Bo-Yi Wu Date: Fri, 14 Aug 2026 22:27:40 +0800 Subject: [PATCH] fix(docker): bump drone-telegram base image to 1.4.2 The 1.4.0 image binary was built with Go 1.22.6, affected by stdlib CVE-2025-68121 (crypto/tls certificate validation bypass, CVSS 10.0). 1.4.2 is built with Go 1.25.13 and patched golang.org/x/crypto v0.55.0. Co-Authored-By: Claude Fable 5 --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 977e6dc..f28a9a2 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM ghcr.io/appleboy/drone-telegram:1.4.0 +FROM ghcr.io/appleboy/drone-telegram:1.4.2 COPY entrypoint.sh /entrypoint.sh RUN chmod +x /entrypoint.sh