Skip to content

Conversation

@org-internal-bot
Copy link
Contributor

This PR contains the following updates:

Package Type Update Change
arigaio/atlas stage major 0.38.0-community-alpine β†’ 1.0.0-community-alpine

Configuration

πŸ“… Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

β™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

πŸ”• Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@org-internal-bot org-internal-bot bot added the dependencies Pull requests that update a dependency file label Dec 25, 2025
@org-internal-bot org-internal-bot bot requested a review from davidB December 25, 2025 04:53
@github-actions
Copy link

βœ…βš οΈMegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Warnings Elapsed time
βœ… DOCKERFILE hadolint 1 0 0 0.24s
βœ… EDITORCONFIG editorconfig-checker 1 0 0 0.19s
⚠️ REPOSITORY trivy yes 1 no 4.85s
βœ… REPOSITORY trivy-sbom yes no no 0.33s

Detailed Issues

⚠️ REPOSITORY / trivy - 1 error
2025-12-25T04:54:39Z	INFO	[vulndb] Need to update DB
2025-12-25T04:54:39Z	INFO	[vulndb] Downloading vulnerability DB...
2025-12-25T04:54:39Z	INFO	[vulndb] Downloading artifact...	repo="mirror.gcr.io/aquasec/trivy-db:2"
22.89 MiB / 78.89 MiB [----------------->___________________________________________] 29.02% ? p/s ?65.66 MiB / 78.89 MiB [-------------------------------------------------->__________] 83.22% ? p/s ?78.89 MiB / 78.89 MiB [----------------------------------------------------------->] 100.00% ? p/s ?78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 93.22 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 93.22 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 93.22 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 87.21 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 87.21 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 87.21 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 81.58 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 81.58 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 81.58 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [-------------------------------------------------] 100.00% 34.30 MiB p/s 2.5s2025-12-25T04:54:42Z	INFO	[vulndb] Artifact successfully downloaded	repo="mirror.gcr.io/aquasec/trivy-db:2"
2025-12-25T04:54:42Z	INFO	[vuln] Vulnerability scanning is enabled
2025-12-25T04:54:42Z	INFO	[misconfig] Misconfiguration scanning is enabled
2025-12-25T04:54:42Z	INFO	[misconfig] Need to update the checks bundle
2025-12-25T04:54:42Z	INFO	[misconfig] Downloading the checks bundle...
165.46 KiB / 165.46 KiB [------------------------------------------------------] 100.00% ? p/s 100ms2025-12-25T04:54:44Z	ERROR	[helm scanner] Failed to render Chart files	file_path="charts/cdviz-collector" err="found in Chart.yaml, but missing in charts/ directory: kubewatch"
2025-12-25T04:54:44Z	INFO	Number of language-specific files	num=0
2025-12-25T04:54:44Z	INFO	Detected config files	num=2

Report Summary

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                     Target                     β”‚    Type    β”‚ Vulnerabilities β”‚ Misconfigurations β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ cdviz-db/Dockerfile                            β”‚ dockerfile β”‚        -        β”‚         0         β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ charts/cdviz-db/templates/job-dbmigration.yaml β”‚    helm    β”‚        -        β”‚         1         β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


charts/cdviz-db/templates/job-dbmigration.yaml (helm)
=====================================================
Tests: 93 (SUCCESSES: 92, FAILURES: 1)
Failures: 1 (UNKNOWN: 0, LOW: 1, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

AVD-KSV-0021 (LOW): Container 'cdviz-db-migration' of CronJob 'cdviz-db-migration' should set 'securityContext.runAsGroup' > 10000
════════════════════════════════════════
Force the container to run with group ID > 10000 to avoid conflicts with the host’s user table.

See https://avd.aquasec.com/misconfig/ksv021
────────────────────────────────────────
 charts/cdviz-db/templates/job-dbmigration.yaml:35-65
────────────────────────────────────────
  35 β”Œ           - name: 'cdviz-db-migration'
  36 β”‚             image: "ghcr.io/cdviz-dev/cdviz-db-migration:0.20250607150000.0"
  37 β”‚             # args for https://atlasgo.io/declarative/apply
  38 β”‚             args:
  39 β”‚               - migrate # or schema
  40 β”‚               - apply
  41 β”‚               - -u
  42 β”‚               - "$(DATABASE_URL)"
  43 β””               - --dir
  ..   
────────────────────────────────────────



πŸ“£ Notices:
  - Version 0.68.2 of Trivy is now available, current version is 0.67.2

To suppress version checks, run Trivy scans with the --skip-version-check flag

See detailed reports in MegaLinter artifacts
Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff

MegaLinter is graciously provided by OX Security

@davidB davidB merged commit c684df7 into main Jan 12, 2026
6 checks passed
@davidB davidB deleted the renovate/arigaio-atlas-1.x branch January 12, 2026 10:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants