Skip to content

Commit ef797c6

Browse files
Upgrade: [dependabot] - bump NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml from 5.2.9 to 5.2.11 (#277)
Bumps [NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml](https://github.com/nhsdigital/eps-common-workflows) from 5.2.9 to 5.2.11. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/nhsdigital/eps-common-workflows/releases">NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml's releases</a>.</em></p> <blockquote> <h2>v5.2.11</h2> <h2><a href="https://github.com/NHSDigital/eps-common-workflows/compare/v5.2.10...v5.2.11">5.2.11</a> (2026-01-08)</h2> <h3>Fix</h3> <ul> <li>[AEA-6060] - use trivy for sbom and licence scan (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/41">#41</a>) (<a href="https://github.com/NHSDigital/eps-common-workflows/commit/2fe6bc6cd974efb4d55a2a7b665385f7a2d28950">2fe6bc6</a>)</li> </ul> <h2>Info</h2> <p><a href="https://github.com/NHSDigital/eps-common-workflows/compare/343b01abc9a6...2fe6bc6cd974">See code diff</a> <a href="https://github.com/NHSDigital/eps-common-workflows/actions/runs/20815530676">Release workflow run</a> - Workflow ID: 20815530676</p> <p>It was initialized by <a href="https://github.com/MatthewPopat-NHS">MatthewPopat-NHS</a></p> <h2>v5.2.10</h2> <h2><a href="https://github.com/NHSDigital/eps-common-workflows/compare/v5.2.9...v5.2.10">5.2.10</a> (2026-01-07)</h2> <h3>Chore</h3> <ul> <li>[AEA-0000] - update python and node (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/42">#42</a>) (<a href="https://github.com/NHSDigital/eps-common-workflows/commit/343b01abc9a63bfe9c34d1e72ae358ce421aa805">343b01a</a>)</li> </ul> <h2>Info</h2> <p><a href="https://github.com/NHSDigital/eps-common-workflows/compare/2b3ddfd1e59d...343b01abc9a6">See code diff</a> <a href="https://github.com/NHSDigital/eps-common-workflows/actions/runs/20791091362">Release workflow run</a> - Workflow ID: 20791091362</p> <p>It was initialized by <a href="https://github.com/anthony-nhs">anthony-nhs</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/NHSDigital/eps-common-workflows/commit/2fe6bc6cd974efb4d55a2a7b665385f7a2d28950"><code>2fe6bc6</code></a> Fix: [AEA-6060] - use trivy for sbom and licence scan (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/41">#41</a>)</li> <li><a href="https://github.com/NHSDigital/eps-common-workflows/commit/343b01abc9a63bfe9c34d1e72ae358ce421aa805"><code>343b01a</code></a> Chore: [AEA-0000] - update python and node (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/42">#42</a>)</li> <li>See full diff in <a href="https://github.com/nhsdigital/eps-common-workflows/compare/2b3ddfd1e59daf9905522d0140c6cd08e2547432...2fe6bc6cd974efb4d55a2a7b665385f7a2d28950">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml&package-manager=github_actions&previous-version=5.2.9&new-version=5.2.11)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: anthony-nhs <121869075+anthony-nhs@users.noreply.github.com> Co-authored-by: Anthony Brown <anthony.brown8@nhs.net>
1 parent f082b78 commit ef797c6

File tree

10 files changed

+515
-499
lines changed

10 files changed

+515
-499
lines changed

.github/workflows/ci.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ jobs:
2828
echo "TAG_FORMAT=$TAG_FORMAT" >> "$GITHUB_OUTPUT"
2929
3030
quality_checks:
31-
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2b3ddfd1e59daf9905522d0140c6cd08e2547432
31+
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2fe6bc6cd974efb4d55a2a7b665385f7a2d28950
3232
needs: [get_asdf_version]
3333
with:
3434
asdfVersion: ${{ needs.get_asdf_version.outputs.asdf_version }}

.github/workflows/pull_request.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ jobs:
3333
echo "TAG_FORMAT=$TAG_FORMAT" >> "$GITHUB_OUTPUT"
3434
3535
quality_checks:
36-
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2b3ddfd1e59daf9905522d0140c6cd08e2547432
36+
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2fe6bc6cd974efb4d55a2a7b665385f7a2d28950
3737
needs: [get_asdf_version]
3838
with:
3939
asdfVersion: ${{ needs.get_asdf_version.outputs.asdf_version }}

.github/workflows/release.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727
echo "TAG_FORMAT=$TAG_FORMAT" >> "$GITHUB_OUTPUT"
2828
2929
quality_checks:
30-
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2b3ddfd1e59daf9905522d0140c6cd08e2547432
30+
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2fe6bc6cd974efb4d55a2a7b665385f7a2d28950
3131
needs: [get_asdf_version]
3232
with:
3333
asdfVersion: ${{ needs.get_asdf_version.outputs.asdf_version }}

.gitignore

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,3 +34,4 @@ cdk.out
3434
.requirements_syncKnowledgeBaseFunction
3535
.local_config/
3636
.dependencies/
37+
.poetry/

.trivyignore.yaml

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
vulnerabilities:
2+
- id: CVE-2025-66418
3+
paths:
4+
- "node_modules/@cdklabs/generative-ai-cdk-constructs/lambda/aws-bedrock-batch-stepfn/uv.lock"
5+
- "node_modules/@cdklabs/generative-ai-cdk-constructs/lambda/opensearch-serverless-custom-resources/poetry.lock"
6+
statement: downstream dependency just used in build stage
7+
- id: CVE-2025-66471
8+
paths:
9+
- "node_modules/@cdklabs/generative-ai-cdk-constructs/lambda/aws-bedrock-batch-stepfn/uv.lock"
10+
- "node_modules/@cdklabs/generative-ai-cdk-constructs/lambda/opensearch-serverless-custom-resources/poetry.lock"
11+
statement: downstream dependency just used in build stage
12+
- id: CVE-2026-21441
13+
paths:
14+
- "node_modules/@cdklabs/generative-ai-cdk-constructs/lambda/aws-bedrock-batch-stepfn/uv.lock"
15+
- "node_modules/@cdklabs/generative-ai-cdk-constructs/lambda/opensearch-serverless-custom-resources/poetry.lock"
16+
statement: downstream dependency just used in build stage

Makefile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -65,6 +65,7 @@ clean:
6565

6666
deep-clean: clean
6767
rm -rf .venv
68+
rm -rf .poetry
6869
find . -name 'node_modules' -type d -prune -exec rm -rf '{}' +
6970

7071
check-licenses: check-licenses-node check-licenses-python

poetry.lock

Lines changed: 491 additions & 487 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

pyproject.toml

Lines changed: 0 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -47,10 +47,3 @@ aws-lambda-powertools = "^3.23.0"
4747

4848
[tool.black]
4949
line-length = 120
50-
51-
[build-system]
52-
requires = ["poetry>=0.12"]
53-
build-backend = "poetry.masonry.api"
54-
55-
[tool.poetry.requires-plugins]
56-
poetry-plugin-export = ">=1.8"

scripts/run_sync.sh

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -64,8 +64,8 @@ echo "Generating config for ${EPSAM_CONFIG}"
6464

6565
echo "Installing dependencies locally"
6666
mkdir -p .dependencies
67-
poetry export --without-hashes --format=requirements.txt --with slackBotFunction > .dependencies/requirements_slackBotFunction
68-
poetry export --without-hashes --format=requirements.txt --with syncKnowledgeBaseFunction > .dependencies/requirements_syncKnowledgeBaseFunction
67+
poetry show --only=slackBotFunction | grep -E "^[a-zA-Z]" | awk '{print $1"=="$2}' > .dependencies/requirements_slackBotFunction
68+
poetry show --only=syncKnowledgeBaseFunction | grep -E "^[a-zA-Z]" | awk '{print $1"=="$2}' > .dependencies/requirements_syncKnowledgeBaseFunction
6969
pip3 install -r .dependencies/requirements_slackBotFunction -t .dependencies/slackBotFunction/python
7070
pip3 install -r .dependencies/requirements_syncKnowledgeBaseFunction -t .dependencies/syncKnowledgeBaseFunction/python
7171

trivy.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
ignorefile: ".trivyignore.yaml"

0 commit comments

Comments
 (0)