Skip to content

chore(deps): update all non-major dependencies - #264

Merged
renovate[bot] merged 1 commit into
masterfrom
renovate/all-minor-patch
Aug 10, 2026
Merged

chore(deps): update all non-major dependencies#264
renovate[bot] merged 1 commit into
masterfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
docker.io/library/python (source) final patch 3.14.6-slim3.14.7-slim
github/codeql-action action patch v4.37.5v4.37.6
step-security/harden-runner action patch v2.20.0v2.20.1

Release Notes

github/codeql-action (github/codeql-action)

v4.37.6

Compare Source

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #​4070
step-security/harden-runner (step-security/harden-runner)

v2.20.1

Compare Source

What's Changed
  • AWS CodeBuild-hosted runner support
  • Implicitly allow single-labeled (internal) domains in block-mode

Full Changelog: step-security/harden-runner@v2.20.0...v2.20.1


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

MegaLinter analysis: Success

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 4 0 0 1.23s
✅ ACTION zizmor 4 0 0 3.97s
✅ COPYPASTE jscpd yes no no 0.67s
✅ DOCKERFILE hadolint 1 0 0 1.33s
✅ JSON jsonlint 3 0 0 0.12s
✅ JSON prettier 3 0 0 0.48s
✅ JSON v8r 3 0 0 2.43s
✅ MARKDOWN markdownlint 1 0 0 0.64s
✅ MARKDOWN markdown-table-formatter 1 0 0 0.23s
✅ PYTHON bandit 1 0 0 3.46s
✅ PYTHON black 1 0 0 2.25s
✅ PYTHON flake8 1 0 0 1.22s
✅ PYTHON isort 1 0 0 0.3s
✅ PYTHON mypy 1 0 0 3.39s
✅ PYTHON pylint 1 0 0 3.28s
✅ PYTHON pyright 1 0 0 1.72s
✅ PYTHON ruff 1 0 0 0.33s
✅ REPOSITORY betterleaks yes no no 2.54s
✅ REPOSITORY checkov yes no no 37.9s
✅ REPOSITORY dustilock yes no no 0.2s
✅ REPOSITORY gitleaks yes no no 1.2s
✅ REPOSITORY git_diff yes no no 0.01s
✅ REPOSITORY grype yes no no 71.61s
✅ REPOSITORY kingfisher yes no no 11.93s
✅ REPOSITORY osv-scanner yes no no 0.29s
✅ REPOSITORY secretlint yes no no 1.3s
✅ REPOSITORY syft yes no no 3.07s
✅ REPOSITORY trivy yes no no 12.1s
✅ REPOSITORY trivy-sbom yes no no 0.16s
✅ REPOSITORY trufflehog yes no no 5.72s
✅ YAML prettier 7 0 0 0.77s
✅ YAML v8r 7 0 0 7.41s
✅ YAML yamllint 7 0 0 0.8s

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.6.0 --custom-flavor-setup --custom-flavor-linters PYTHON_PYLINT,PYTHON_BLACK,PYTHON_FLAKE8,PYTHON_ISORT,PYTHON_BANDIT,PYTHON_MYPY,PYTHON_PYRIGHT,PYTHON_RUFF,ACTION_ACTIONLINT,ACTION_ZIZMOR,COPYPASTE_JSCPD,DOCKERFILE_HADOLINT,JSON_JSONLINT,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_DUSTILOCK,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,REPOSITORY_KINGFISHER,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from c07c128 to 8618b58 Compare August 10, 2026 04:40
@github-actions

Copy link
Copy Markdown
Contributor

Trivy image scan report

ghcr.io/chgl/github-reusable-workflow-with-fixed-image-tags:v1.2.3-beta.123 (debian 13.6)

No Vulnerabilities found

No Misconfigurations found

Python

3 known vulnerabilities found (CRITICAL: 0 HIGH: 2 MEDIUM: 1 LOW: 0)

Show detailed table of vulnerabilities
Package ID Severity Installed Version Fixed Version
msgpack GHSA-6v7p-g79w-8964 HIGH 1.1.2 1.2.1
setuptools CVE-2025-47273 HIGH 70.3.0 78.1.1
setuptools CVE-2026-59890 MEDIUM 70.3.0 83.0.0

No Misconfigurations found

@github-actions

Copy link
Copy Markdown
Contributor

Trivy image scan report

ghcr.io/chgl/github-reusable-workflow:pr-264 (debian 13.6)

No Vulnerabilities found

No Misconfigurations found

Python

3 known vulnerabilities found (HIGH: 2 MEDIUM: 1 LOW: 0 CRITICAL: 0)

Show detailed table of vulnerabilities
Package ID Severity Installed Version Fixed Version
msgpack GHSA-6v7p-g79w-8964 HIGH 1.1.2 1.2.1
setuptools CVE-2025-47273 HIGH 70.3.0 78.1.1
setuptools CVE-2026-59890 MEDIUM 70.3.0 83.0.0

No Misconfigurations found

@github-actions

Copy link
Copy Markdown
Contributor

Trivy image scan report

ghcr.io/chgl/github-reusable-workflow-without-test-image:pr-264 (debian 13.6)

No Vulnerabilities found

No Misconfigurations found

Python

3 known vulnerabilities found (CRITICAL: 0 HIGH: 2 MEDIUM: 1 LOW: 0)

Show detailed table of vulnerabilities
Package ID Severity Installed Version Fixed Version
msgpack GHSA-6v7p-g79w-8964 HIGH 1.1.2 1.2.1
setuptools CVE-2025-47273 HIGH 70.3.0 78.1.1
setuptools CVE-2026-59890 MEDIUM 70.3.0 83.0.0

No Misconfigurations found

@renovate
renovate Bot merged commit 4d3dce6 into master Aug 10, 2026
39 checks passed
@renovate
renovate Bot deleted the renovate/all-minor-patch branch August 10, 2026 09:53
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 1.11.48 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants