-
Notifications
You must be signed in to change notification settings - Fork 9
Description
This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
Note
These dependencies have not received updates for an extended period and may be unmaintained:
View abandoned dependencies (2)
| Datasource | Name | Last Updated |
|---|---|---|
| pip_requirements | logfmt-logger |
2021-04-19 |
| pip_requirements | python-decouple |
2023-03-01 |
Packages are marked as abandoned when they exceed the abandonmentThreshold since their last release.
Unlike deprecated packages with official notices, abandonment is detected by release inactivity.
Pending Status Checks
The following updates await pending status checks. To force their creation now, click on a checkbox below.
- chore(deps): update dependency python-decouple to v3.8
- chore(deps): update python docker tag to v3.11
- chore(deps): update actions/checkout action to v6
- chore(deps): update dependency pygithub to v2
- chore(deps): update docker/build-push-action action to v6
- chore(deps): update docker/login-action action to v3
- chore(deps): update docker/setup-buildx-action action to v3
Open
The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.
- chore(deps): update dependency requests to v2.32.4 [security]
- chore(deps): pin dependencies (
actions/checkout,docker/build-push-action,docker/login-action,docker/setup-buildx-action,ghcr.io/grafana/github-traffic,grafana/grafana-oss,prom/prometheus,python) - chore(deps): update dependency apscheduler to v3.11.2
- chore(deps): update dependency prometheus-client to v0.23.1
- chore(deps): update dependency pygithub to v1.59.1
- Click on this checkbox to rebase all open PRs at once
Vulnerabilities
4/4 CVEs have Renovate fixes.
pip_requirements
requirements.txt
requests
- PYSEC-2023-74 (fixed in >= 2.31.0)
- GHSA-j8r2-6x86-q33q (fixed in >= 2.31.0)
- GHSA-9wx4-h78v-vm56 (fixed in >= 2.32.0)
- GHSA-9hjg-9r4m-mvj7 (fixed in >= 2.32.4)
Detected Dependencies
docker-compose (1)
docker-compose.yaml (3)
grafana/grafana-oss unknown version→ [Updates:undefined]prom/prometheus unknown version→ [Updates:undefined]ghcr.io/grafana/github-traffic unknown version→ [Updates:undefined]
dockerfile (1)
Dockerfile (1)
python 3.8-slim-buster→ [Updates:3.11-slim-buster,3.8-slim-buster]
github-actions (1)
.github/workflows/push.yaml (4)
actions/checkout v2→ [Updates:v6,v2]docker/setup-buildx-action v1→ [Updates:v3,v1]docker/login-action v1→ [Updates:v3,v1]docker/build-push-action v2→ [Updates:v6,v2]
pip_requirements (1)
requirements.txt (6)
apscheduler ==3.7.0→ [Updates:==3.11.2]requests ==2.25.0→ [Updates:==2.32.4]python-decouple ==3.3→ [Updates:==3.8]prometheus-client ==0.9.0→ [Updates:==0.23.1]pygithub ==1.51→ [Updates:==1.59.1,==2.8.1]logfmt-logger ==0.1.2
Need help?
You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.