Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Apr 29, 2025

This PR contains the following updates:

Package Type Update Change OpenSSF
anchore/scan-action action digest 7c05671 -> 2c901ab OpenSSF Scorecard
astral-sh/setup-uv action digest c7f87aa -> 6b9c606 OpenSSF Scorecard
bridgecrewio/checkov-action action digest 0508198 -> 5e2c7c3
ghcr.io/astral-sh/uv final digest 4a6c944 -> bc574e7

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from yxtay as a code owner April 29, 2025 19:57
@renovate renovate bot enabled auto-merge (squash) April 29, 2025 19:57
@trunk-io
Copy link

trunk-io bot commented Apr 29, 2025

⏱️ 32m total CI duration on this PR
Slowest 15 Jobs Cumulative Duration Recent Runs
megalinter 8m 🟩🟩
Analyze (actions) 2m 🟩🟩
trunk 2m 🟩🟩
docker 2m 🟩🟩
Analyze (python) 2m 🟩🟩
python (windows-latest, 3.12) 2m 🟩🟩
msdo 1m 🟩🟩
kics 1m 🟩🟩
syft 1m 🟩🟩
trivy 1m 🟩🟩
grype 1m 🟩🟩
checkov 1m 🟩🟩
osv-scan-pr / osv-scan 1m 🟩🟩
devskim 1m 🟩🟩
python (ubuntu-latest, 3.12) 47s 🟩🟩

settingsfeedbackdocs ⋅ learn more about trunk.io

@github-actions
Copy link
Contributor

kics-logo

KICS version: v2.1.7

Category Results
CRITICAL CRITICAL 0
HIGH HIGH 0
MEDIUM MEDIUM 6
LOW LOW 0
INFO INFO 0
TRACE TRACE 0
TOTAL TOTAL 6
Metric Values
Files scanned placeholder 7
Files parsed placeholder 7
Files failed to scan placeholder 0
Total executed queries placeholder 73
Queries failed to execute placeholder 0
Execution time placeholder 1

Queries Results

Query Name Query Id Severity Platform Cwe Cloud Provider Category Experimental Description File Name Line Issue Type Search Key Expected Value Actual Value
Container Traffic Not Bound To Host Interface 451d79dc-0588-476a-ad03-3c7f0320abb3 MEDIUM DockerCompose 693 COMMON Networking and Firewall false Incoming container traffic should be bound to a specific host interface compose.yaml 51 IncorrectValue services.app.ports Docker compose file to have 'ports' attribute bound to a specific host interface. Docker compose file doesn't have 'ports' attribute bound to a specific host interface
Container Traffic Not Bound To Host Interface 451d79dc-0588-476a-ad03-3c7f0320abb3 MEDIUM DockerCompose 693 COMMON Networking and Firewall false Incoming container traffic should be bound to a specific host interface compose.yaml 33 IncorrectValue services.app_ci.ports Docker compose file to have 'ports' attribute bound to a specific host interface. Docker compose file doesn't have 'ports' attribute bound to a specific host interface
Container Traffic Not Bound To Host Interface 451d79dc-0588-476a-ad03-3c7f0320abb3 MEDIUM DockerCompose 693 COMMON Networking and Firewall false Incoming container traffic should be bound to a specific host interface compose.yaml 12 IncorrectValue services.app_dev.ports Docker compose file to have 'ports' attribute bound to a specific host interface. Docker compose file doesn't have 'ports' attribute bound to a specific host interface
Healthcheck Not Set 698ed579-b239-4f8f-a388-baa4bcb13ef8 MEDIUM DockerCompose 703 COMMON Availability false Check containers periodically to see if they are running properly. compose.yaml 41 MissingAttribute services.app Healthcheck should be defined. Healthcheck is not defined.
Healthcheck Not Set 698ed579-b239-4f8f-a388-baa4bcb13ef8 MEDIUM DockerCompose 703 COMMON Availability false Check containers periodically to see if they are running properly. compose.yaml 22 MissingAttribute services.app_ci Healthcheck should be defined. Healthcheck is not defined.
Healthcheck Not Set 698ed579-b239-4f8f-a388-baa4bcb13ef8 MEDIUM DockerCompose 703 COMMON Availability false Check containers periodically to see if they are running properly. compose.yaml 2 MissingAttribute services.app_dev Healthcheck should be defined. Healthcheck is not defined.

@github-actions
Copy link
Contributor

github-actions bot commented Apr 29, 2025

🦙 MegaLinter status: ✅ SUCCESS

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 2 0 0 0.19s
✅ COPYPASTE jscpd yes no no 1.21s
✅ DOCKERFILE hadolint 1 0 0 0.32s
✅ EDITORCONFIG editorconfig-checker 3 0 0 0.02s
✅ REPOSITORY checkov yes no no 13.22s
✅ REPOSITORY devskim yes no no 0.98s
✅ REPOSITORY dustilock yes no no 0.01s
✅ REPOSITORY gitleaks yes no no 0.38s
✅ REPOSITORY git_diff yes no no 0.0s
✅ REPOSITORY grype yes no no 21.27s
✅ REPOSITORY kics yes no no 3.05s
✅ REPOSITORY secretlint yes no no 0.86s
✅ REPOSITORY semgrep yes no no 13.87s
✅ REPOSITORY syft yes no no 0.98s
✅ REPOSITORY trivy yes no no 7.49s
✅ REPOSITORY trivy-sbom yes no no 0.07s
✅ REPOSITORY trufflehog yes no no 6.4s
✅ SPELL lychee 2 0 0 0.47s
✅ YAML prettier 2 0 0 0 0.49s
✅ YAML v8r 2 0 0 2.15s
✅ YAML yamllint 2 0 0 0.31s

See detailed report in MegaLinter reports
Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff

MegaLinter is graciously provided by OX Security

@renovate renovate bot force-pushed the renovate/all-digest branch from 6de6655 to baf0c8b Compare April 29, 2025 22:03
@renovate renovate bot changed the title chore(deps): update bridgecrewio/checkov-action digest to 5e2c7c3 chore(deps): update all digest updates Apr 29, 2025
@renovate renovate bot merged commit 15147dd into main Apr 29, 2025
58 of 61 checks passed
@renovate renovate bot deleted the renovate/all-digest branch April 29, 2025 23:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants