miracum / fhir-gateway

A thin layer between FHIR REST clients and resource processing pipelines.
Apache License 2.0
13 stars 7 forks source link

chore(deps): update github-actions #136

Closed renovate[bot] closed 7 months ago

renovate[bot] commented 8 months ago

Mend Renovate

This PR contains the following updates:

Package Type Update Change
github/codeql-action action patch v3.24.6 -> v3.24.9
miracum/.github action minor v1.5.8 -> v1.6.2

Release Notes

github/codeql-action (github/codeql-action) ### [`v3.24.9`](https://togithub.com/github/codeql-action/compare/v3.24.8...v3.24.9) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.24.8...v3.24.9) ### [`v3.24.8`](https://togithub.com/github/codeql-action/compare/v3.24.7...v3.24.8) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.24.7...v3.24.8) ### [`v3.24.7`](https://togithub.com/github/codeql-action/compare/v3.24.6...v3.24.7) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.24.6...v3.24.7)
miracum/.github (miracum/.github) ### [`v1.6.2`](https://togithub.com/miracum/.github/releases/tag/v1.6.2) [Compare Source](https://togithub.com/miracum/.github/compare/v1.6.1...v1.6.2) ##### Miscellaneous Chores - **deps:** update docker.io/library/python:3.12.2-slim docker digest to [`36d57d7`](https://togithub.com/miracum/.github/commit/36d57d7) ([#​41](https://togithub.com/miracum/.github/issues/41)) ([cc6fa0f](https://togithub.com/miracum/.github/commit/cc6fa0f9913128e1b27770bcd43df2c19e547a25)) - **deps:** update github-actions ([#​46](https://togithub.com/miracum/.github/issues/46)) ([ebc01f6](https://togithub.com/miracum/.github/commit/ebc01f6bcb49c40fbf61b5888244bd7996d2e229)) ### [`v1.6.1`](https://togithub.com/miracum/.github/releases/tag/v1.6.1) [Compare Source](https://togithub.com/miracum/.github/compare/v1.6.0...v1.6.1) ##### Miscellaneous Chores - **deps:** update github-actions ([#​45](https://togithub.com/miracum/.github/issues/45)) ([f9d64a7](https://togithub.com/miracum/.github/commit/f9d64a7dbe928557fde9f96defa3e372bc0eaf21)) ### [`v1.6.0`](https://togithub.com/miracum/.github/releases/tag/v1.6.0) [Compare Source](https://togithub.com/miracum/.github/compare/v1.5.9...v1.6.0) ##### Features - add trivy report as a PR comment ([#​44](https://togithub.com/miracum/.github/issues/44)) ([f0e7b63](https://togithub.com/miracum/.github/commit/f0e7b6366b88a4c6b73e9c9f6200b26327d73b75)) ##### Miscellaneous Chores - **deps:** updated pr comment template location ([829c942](https://togithub.com/miracum/.github/commit/829c942d4310a22df627505bb807af03b1e7edd7)) ### [`v1.5.9`](https://togithub.com/miracum/.github/releases/tag/v1.5.9) [Compare Source](https://togithub.com/miracum/.github/compare/v1.5.8...v1.5.9) ##### Bug Fixes - create temp dir ([#​43](https://togithub.com/miracum/.github/issues/43)) ([78c448c](https://togithub.com/miracum/.github/commit/78c448ce94b095535278b2d7ff5d13def3bed87f)) - set TMPDIR to avoid trivy out of disk errors ([265b57e](https://togithub.com/miracum/.github/commit/265b57e3b1623738fc95d6e5d97b4bead183141d)) ##### Miscellaneous Chores - default back to monthly renovations ([24a47ab](https://togithub.com/miracum/.github/commit/24a47abe24071f23a5fc793ad42b34f01115331d)) - **deps:** update github-actions ([#​42](https://togithub.com/miracum/.github/issues/42)) ([0acca4e](https://togithub.com/miracum/.github/commit/0acca4e2cf641d828c9514dce0ff70511b448cc2))

Configuration

📅 Schedule: Branch creation - "every 3 months on the first day of the month" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

â™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.



This PR has been generated by Mend Renovate. View repository job log here.

github-actions[bot] commented 8 months ago

🦙 MegaLinter status: ✅ SUCCESS

Descriptor Linter Files Fixed Errors Elapsed time
✅ ACTION actionlint 4 0 0.02s
✅ DOCKERFILE hadolint 2 0 0.1s
✅ EDITORCONFIG editorconfig-checker 66 0 0.36s
✅ GROOVY npm-groovy-lint 2 0 14.51s
✅ JAVA checkstyle 18 0 9.1s
✅ JSON eslint-plugin-jsonc 5 0 2.84s
✅ JSON jsonlint 5 0 0.34s
✅ JSON prettier 5 0 2.49s
✅ JSON v8r 5 0 4.11s
✅ MARKDOWN markdownlint 2 0 0.58s
✅ PYTHON bandit 1 0 0.92s
✅ PYTHON black 1 0 0.69s
✅ PYTHON flake8 1 0 0.41s
✅ PYTHON isort 1 0 0.44s
✅ PYTHON mypy 1 0 8.15s
✅ PYTHON ruff 1 0 0.06s
✅ REPOSITORY checkov yes no 17.42s
✅ REPOSITORY gitleaks yes no 0.78s
✅ REPOSITORY git_diff yes no 0.04s
✅ REPOSITORY grype yes no 12.13s
✅ REPOSITORY kics yes no 6.28s
✅ REPOSITORY secretlint yes no 1.26s
✅ REPOSITORY syft yes no 3.1s
✅ REPOSITORY trivy yes no 6.73s
✅ REPOSITORY trivy-sbom yes no 3.7s
✅ REPOSITORY trufflehog yes no 9.06s
✅ SQL sql-lint 1 0 0.46s
✅ XML xmllint 1 0 0.03s
✅ YAML prettier 17 0 1.46s
✅ YAML yamllint 17 0 0.8s

See detailed report in MegaLinter reports

You could have same capabilities but better runtime performances if you request a new MegaLinter flavor.

_MegaLinter is graciously provided by OX Security_

github-actions[bot] commented 7 months ago

Target ghcr.io/miracum/fhir-gateway:pr-136 (debian 12.5)

Vulnerabilities (17)

Package ID Severity Installed Version Fixed Version
libc6 CVE-2010-4756 LOW 2.36-9+deb12u4
libc6 CVE-2018-20796 LOW 2.36-9+deb12u4
libc6 CVE-2019-1010022 LOW 2.36-9+deb12u4
libc6 CVE-2019-1010023 LOW 2.36-9+deb12u4
libc6 CVE-2019-1010024 LOW 2.36-9+deb12u4
libc6 CVE-2019-1010025 LOW 2.36-9+deb12u4
libc6 CVE-2019-9192 LOW 2.36-9+deb12u4
libexpat1 CVE-2023-52425 HIGH 2.5.0-1
libexpat1 CVE-2024-28757 HIGH 2.5.0-1
libexpat1 CVE-2023-52426 MEDIUM 2.5.0-1
libgcc-s1 CVE-2023-4039 MEDIUM 12.2.0-14
libgcc-s1 CVE-2022-27943 LOW 12.2.0-14
libpng16-16 CVE-2021-4214 LOW 1.6.39-2
libstdc++6 CVE-2023-4039 MEDIUM 12.2.0-14
libstdc++6 CVE-2022-27943 LOW 12.2.0-14
libuuid1 CVE-2022-0563 LOW 2.38.1-5+b1
zlib1g CVE-2023-45853 CRITICAL 1:1.2.13.dfsg-1

No Misconfigurations found

Target Java

Vulnerabilities (1)

Package ID Severity Installed Version Fixed Version
org.springframework:spring-web CVE-2024-22259 HIGH 6.1.4 6.1.5, 6.0.18, 5.3.33

No Misconfigurations found

miracum-bot commented 7 months ago

:tada: This PR is included in version 3.12.12 :tada:

The release is available on GitHub release

Your semantic-release bot :package::rocket: