SeleniumHQ / SeleniumHQ/docker-selenium

[🐛 Bug]: Outdated Dependencies

Open
#3,220 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

needs-triaging
Dominant language
Go
Stars
8.7k
Forks
2.5k
Avg merge
10h 16m
Merged PRs (30d)
20

Description

What happened?

Our security scans are showing a couple of outdated version in the overlay folder.

  • /java-21-openjdk-amd64
  • /openssl
  • /ffmpeg
  • /libcurl-gnutls*

Can you updaten them in one of your upcoming releases?

Command used to start Selenium Grid with Docker (or Kubernetes)
Not relevant
Relevant log output
Not relevant
Operating System

RHEL 8

Docker Selenium version (image tag)

4.47.0

Selenium Grid chart version (chart version)

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the overlay folder and the image build definitions for the Docker Selenium 4.47.0 images, then identify where java-21-openjdk-amd64, openssl, ffmpeg, and libcurl-gnutls are installed. Update those dependency versions and rebuild or scan the affected image to confirm the reported outdated packages are resolved.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, java
Domain
devops, infrastructure, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.