Highlights
Denial of Service: 2 prior fixes. Scrutinize any change in this area.
Dockerfile: most-fixed (2 issues). Treat as high-risk during review.
4 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Denial of Service: Two separate Alpine base image upgrades were needed to remediate known vulnerabilities, indicating a recurring pattern of shipping outdated base images.
Dependency Vulnerability: Alpine 3.18.2 contained OpenSSL vulnerabilities; upgrading the base image was required to avoid known CVEs.
Denial of Service: golang.org/x/net had HTTP/2 DoS vulnerabilities, fixed by dependency upgrade. This is a critical network-facing dependency for the webhook.