miracum / ahd2fhir

A REST service for mapping text analysis results from Averbis Health Discovery to FHIR resources.
Apache License 2.0
8 stars 0 forks source link

chore(deps): update dependency certifi to v2024.7.4 [security] #183

Closed renovate[bot] closed 5 months ago

renovate[bot] commented 5 months ago

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
certifi ==2024.6.2 -> ==2024.7.4 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-39689

Certifi 2024.07.04 removes root certificates from "GLOBALTRUST" from the root store. These are in the process of being removed from Mozilla's trust store.

GLOBALTRUST's root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues". Conclusions of Mozilla's investigation can be found here.


Release Notes

certifi/python-certifi (certifi) ### [`v2024.7.4`](https://togithub.com/certifi/python-certifi/compare/2024.06.02...2024.07.04) [Compare Source](https://togithub.com/certifi/python-certifi/compare/2024.06.02...2024.07.04)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

â™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Mend Renovate. View repository job log here.

github-actions[bot] commented 5 months ago

Trivy image scan report

ghcr.io/miracum/ahd2fhir:pr-183 (debian 12.6)

No Vulnerabilities found

No Misconfigurations found

Python

No Vulnerabilities found

No Misconfigurations found

github-actions[bot] commented 5 months ago

🦙 MegaLinter status: ✅ SUCCESS

Descriptor Linter Files Fixed Errors Elapsed time
✅ ACTION actionlint 5 0 0.04s
✅ BASH bash-exec 2 0 0.03s
✅ BASH shellcheck 2 0 0.04s
✅ BASH shfmt 2 0 0.05s
✅ DOCKERFILE hadolint 2 0 0.12s
✅ JSON jsonlint 17 0 0.37s
✅ JSON npm-package-json-lint yes no 0.55s
✅ JSON prettier 17 0 1.71s
✅ MARKDOWN markdownlint 3 0 0.57s
✅ PYTHON bandit 31 0 1.53s
✅ PYTHON black 31 0 3.12s
✅ PYTHON flake8 31 0 2.46s
✅ PYTHON isort 31 0 0.54s
✅ PYTHON mypy 31 0 9.43s
✅ PYTHON pyright 31 0 9.47s
✅ PYTHON ruff 31 0 0.03s
✅ REPOSITORY checkov yes no 14.54s
✅ REPOSITORY gitleaks yes no 0.11s
✅ REPOSITORY git_diff yes no 0.02s
✅ REPOSITORY grype yes no 18.05s
✅ REPOSITORY kics yes no 31.14s
✅ REPOSITORY secretlint yes no 0.93s
✅ REPOSITORY syft yes no 0.58s
✅ REPOSITORY trivy yes no 10.71s
✅ REPOSITORY trivy-sbom yes no 3.05s
✅ REPOSITORY trufflehog yes no 4.5s
✅ YAML prettier 15 0 0.98s
✅ YAML yamllint 15 0 0.55s

See detailed report in MegaLinter reports

You could have same capabilities but better runtime performances if you request a new MegaLinter flavor.

_MegaLinter is graciously provided by OX Security_

miracum-bot commented 5 months ago

:tada: This issue has been resolved in version 3.1.9 :tada:

The release is available on GitHub release

Your semantic-release bot :package::rocket: