miracum / ahd2fhir

A REST service for mapping text analysis results from Averbis Health Discovery to FHIR resources.
Apache License 2.0
8 stars 0 forks source link

chore(deps): update github-actions #180

Closed renovate[bot] closed 5 months ago

renovate[bot] commented 5 months ago

Mend Renovate

This PR contains the following updates:

Package Type Update Change
actions/checkout action patch v4.1.6 -> v4.1.7
amannn/action-semantic-pull-request action digest e9fabac -> 0723387
github/codeql-action action patch v3.25.7 -> v3.25.11
miracum/.github action minor v1.9.1 -> v1.10.2

Release Notes

actions/checkout (actions/checkout) ### [`v4.1.7`](https://togithub.com/actions/checkout/blob/HEAD/CHANGELOG.md#v417) [Compare Source](https://togithub.com/actions/checkout/compare/v4.1.6...v4.1.7) - Bump the minor-npm-dependencies group across 1 directory with 4 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/actions/checkout/pull/1739](https://togithub.com/actions/checkout/pull/1739) - Bump actions/checkout from 3 to 4 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/actions/checkout/pull/1697](https://togithub.com/actions/checkout/pull/1697) - Check out other refs/\* by commit by [@​orhantoy](https://togithub.com/orhantoy) in [https://github.com/actions/checkout/pull/1774](https://togithub.com/actions/checkout/pull/1774) - Pin actions/checkout's own workflows to a known, good, stable version. by [@​jww3](https://togithub.com/jww3) in [https://github.com/actions/checkout/pull/1776](https://togithub.com/actions/checkout/pull/1776)
github/codeql-action (github/codeql-action) ### [`v3.25.11`](https://togithub.com/github/codeql-action/compare/v3.25.10...v3.25.11) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.25.10...v3.25.11) ### [`v3.25.10`](https://togithub.com/github/codeql-action/compare/v3.25.9...v3.25.10) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.25.9...v3.25.10) ### [`v3.25.9`](https://togithub.com/github/codeql-action/compare/v3.25.8...v3.25.9) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.25.8...v3.25.9) ### [`v3.25.8`](https://togithub.com/github/codeql-action/compare/v3.25.7...v3.25.8) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.25.7...v3.25.8)
miracum/.github (miracum/.github) ### [`v1.10.2`](https://togithub.com/miracum/.github/releases/tag/v1.10.2) [Compare Source](https://togithub.com/miracum/.github/compare/v1.10.1...v1.10.2) ##### Bug Fixes - set trivy ignore-unfixed to `true` by default ([#​65](https://togithub.com/miracum/.github/issues/65)) ([db8574b](https://togithub.com/miracum/.github/commit/db8574b42e0c528f9cddc1ce84a40a837283cee0)) ### [`v1.10.1`](https://togithub.com/miracum/.github/releases/tag/v1.10.1) [Compare Source](https://togithub.com/miracum/.github/compare/v1.10.0...v1.10.1) ##### CI/CD - create scorecard.yaml ([#​62](https://togithub.com/miracum/.github/issues/62)) ([f5c80e0](https://togithub.com/miracum/.github/commit/f5c80e07c8fc2075aef9d34f4c3bc0aa168de313)) ##### Miscellaneous Chores - **deps:** update docker/build-push-action action to v6 ([#​64](https://togithub.com/miracum/.github/issues/64)) ([e658df8](https://togithub.com/miracum/.github/commit/e658df8deaac2d762eb91585c81d9e7cae0230f7)) - **deps:** update github-actions ([#​63](https://togithub.com/miracum/.github/issues/63)) ([9df18a3](https://togithub.com/miracum/.github/commit/9df18a3ffadf0c24b306e24226bb7f0449c2b286)) ### [`v1.10.0`](https://togithub.com/miracum/.github/releases/tag/v1.10.0) [Compare Source](https://togithub.com/miracum/.github/compare/v1.9.2...v1.10.0) ##### Features - harden runner for build and release jobs ([#​61](https://togithub.com/miracum/.github/issues/61)) ([d53f448](https://togithub.com/miracum/.github/commit/d53f448b46aa81c7c877e45a0ae641bb93d5fd7c)) ### [`v1.9.2`](https://togithub.com/miracum/.github/releases/tag/v1.9.2) [Compare Source](https://togithub.com/miracum/.github/compare/v1.9.1...v1.9.2) ##### Miscellaneous Chores - **deps:** update all non-major dependencies ([#​57](https://togithub.com/miracum/.github/issues/57)) ([54ebc8d](https://togithub.com/miracum/.github/commit/54ebc8d668bc1882e69e92b58ae29eb542cd3fad)) - **deps:** update gcr.io/distroless/python3-debian12:nonroot docker digest to [`14c62b8`](https://togithub.com/miracum/.github/commit/14c62b8) ([#​56](https://togithub.com/miracum/.github/issues/56)) ([5eab4c7](https://togithub.com/miracum/.github/commit/5eab4c7bf6a5b1475f0c8b4d1e38e379a48f7a0a)) - **deps:** update github-actions ([#​60](https://togithub.com/miracum/.github/issues/60)) ([dee5806](https://togithub.com/miracum/.github/commit/dee5806b344d4370c1edc52ac4fd196c3160aec7))

Configuration

📅 Schedule: Branch creation - "every 3 months on the first day of the month" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.



This PR has been generated by Mend Renovate. View repository job log here.

github-actions[bot] commented 5 months ago

🦙 MegaLinter status: ✅ SUCCESS

Descriptor Linter Files Fixed Errors Elapsed time
✅ ACTION actionlint 5 0 0.08s
✅ BASH bash-exec 2 0 0.05s
✅ BASH shellcheck 2 0 0.03s
✅ BASH shfmt 2 0 0.03s
✅ DOCKERFILE hadolint 2 0 0.25s
✅ JSON jsonlint 17 0 0.45s
✅ JSON npm-package-json-lint yes no 0.6s
✅ JSON prettier 17 0 1.66s
✅ MARKDOWN markdownlint 3 0 0.59s
✅ PYTHON bandit 31 0 2.33s
✅ PYTHON black 31 0 2.56s
✅ PYTHON flake8 31 0 1.38s
✅ PYTHON isort 31 0 0.48s
✅ PYTHON mypy 31 0 11.02s
✅ PYTHON pyright 31 0 10.94s
✅ PYTHON ruff 31 0 0.02s
✅ REPOSITORY checkov yes no 15.32s
✅ REPOSITORY gitleaks yes no 0.14s
✅ REPOSITORY git_diff yes no 0.01s
✅ REPOSITORY grype yes no 15.27s
✅ REPOSITORY kics yes no 31.64s
✅ REPOSITORY secretlint yes no 0.94s
✅ REPOSITORY syft yes no 0.67s
✅ REPOSITORY trivy yes no 9.74s
✅ REPOSITORY trivy-sbom yes no 5.56s
✅ REPOSITORY trufflehog yes no 6.75s
✅ YAML prettier 15 0 0.95s
✅ YAML yamllint 15 0 0.63s

See detailed report in MegaLinter reports

You could have same capabilities but better runtime performances if you request a new MegaLinter flavor.

_MegaLinter is graciously provided by OX Security_

github-actions[bot] commented 5 months ago

Trivy image scan report

ghcr.io/miracum/ahd2fhir:pr-180 (debian 12.5)

25 known vulnerabilities found (CRITICAL: 0 HIGH: 12 MEDIUM: 13 LOW: 0)

Show detailed table of vulnerabilities
Package ID Severity Installed Version Fixed Version
libc6 CVE-2024-2961 HIGH 2.36-9+deb12u4 2.36-9+deb12u6
libc6 CVE-2024-33599 HIGH 2.36-9+deb12u4 2.36-9+deb12u7
libc6 CVE-2024-33600 MEDIUM 2.36-9+deb12u4 2.36-9+deb12u7
libc6 CVE-2024-33601 MEDIUM 2.36-9+deb12u4 2.36-9+deb12u7
libc6 CVE-2024-33602 MEDIUM 2.36-9+deb12u4 2.36-9+deb12u7
libpython3.11-minimal CVE-2023-24329 HIGH 3.11.2-6 3.11.2-6+deb12u2
libpython3.11-minimal CVE-2023-41105 HIGH 3.11.2-6 3.11.2-6+deb12u2
libpython3.11-minimal CVE-2023-6597 HIGH 3.11.2-6 3.11.2-6+deb12u2
libpython3.11-minimal CVE-2023-40217 MEDIUM 3.11.2-6 3.11.2-6+deb12u2
libpython3.11-minimal CVE-2024-0450 MEDIUM 3.11.2-6 3.11.2-6+deb12u2
libpython3.11-stdlib CVE-2023-24329 HIGH 3.11.2-6 3.11.2-6+deb12u2
libpython3.11-stdlib CVE-2023-41105 HIGH 3.11.2-6 3.11.2-6+deb12u2
libpython3.11-stdlib CVE-2023-6597 HIGH 3.11.2-6 3.11.2-6+deb12u2
libpython3.11-stdlib CVE-2023-40217 MEDIUM 3.11.2-6 3.11.2-6+deb12u2
libpython3.11-stdlib CVE-2024-0450 MEDIUM 3.11.2-6 3.11.2-6+deb12u2
libssl3 CVE-2023-5678 MEDIUM 3.0.11-1~deb12u2 3.0.13-1~deb12u1
libssl3 CVE-2023-6129 MEDIUM 3.0.11-1~deb12u2 3.0.13-1~deb12u1
libssl3 CVE-2023-6237 MEDIUM 3.0.11-1~deb12u2 3.0.13-1~deb12u1
libssl3 CVE-2024-0727 MEDIUM 3.0.11-1~deb12u2 3.0.13-1~deb12u1
libuuid1 CVE-2024-28085 HIGH 2.38.1-5+b1 2.38.1-5+deb12u1
python3.11-minimal CVE-2023-24329 HIGH 3.11.2-6 3.11.2-6+deb12u2
python3.11-minimal CVE-2023-41105 HIGH 3.11.2-6 3.11.2-6+deb12u2
python3.11-minimal CVE-2023-6597 HIGH 3.11.2-6 3.11.2-6+deb12u2
python3.11-minimal CVE-2023-40217 MEDIUM 3.11.2-6 3.11.2-6+deb12u2
python3.11-minimal CVE-2024-0450 MEDIUM 3.11.2-6 3.11.2-6+deb12u2

No Misconfigurations found

Python

No Vulnerabilities found

No Misconfigurations found

miracum-bot commented 5 months ago

:tada: This issue has been resolved in version 3.1.9 :tada:

The release is available on GitHub release

Your semantic-release bot :package::rocket: