Closed dependabot[bot] closed 5 months ago
ghcr.io/miracum/fhir-gateway:pr-149 (debian 12.5)
Package | ID | Severity | Installed Version | Fixed Version |
---|---|---|---|---|
libc6 |
CVE-2024-33599 | HIGH | 2.36-9+deb12u6 | 2.36-9+deb12u7 |
libc6 |
CVE-2024-33600 | MEDIUM | 2.36-9+deb12u6 | 2.36-9+deb12u7 |
libc6 |
CVE-2024-33601 | MEDIUM | 2.36-9+deb12u6 | 2.36-9+deb12u7 |
libc6 |
CVE-2024-33602 | MEDIUM | 2.36-9+deb12u6 | 2.36-9+deb12u7 |
libc6 |
CVE-2010-4756 | LOW | 2.36-9+deb12u6 | |
libc6 |
CVE-2018-20796 | LOW | 2.36-9+deb12u6 | |
libc6 |
CVE-2019-1010022 | LOW | 2.36-9+deb12u6 | |
libc6 |
CVE-2019-1010023 | LOW | 2.36-9+deb12u6 | |
libc6 |
CVE-2019-1010024 | LOW | 2.36-9+deb12u6 | |
libc6 |
CVE-2019-1010025 | LOW | 2.36-9+deb12u6 | |
libc6 |
CVE-2019-9192 | LOW | 2.36-9+deb12u6 | |
libexpat1 |
CVE-2023-52425 | HIGH | 2.5.0-1 | |
libexpat1 |
CVE-2023-52426 | LOW | 2.5.0-1 | |
libexpat1 |
CVE-2024-28757 | LOW | 2.5.0-1 | |
libgcc-s1 |
CVE-2023-4039 | MEDIUM | 12.2.0-14 | |
libgcc-s1 |
CVE-2022-27943 | LOW | 12.2.0-14 | |
libpng16-16 |
CVE-2021-4214 | LOW | 1.6.39-2 | |
libstdc++6 |
CVE-2023-4039 | MEDIUM | 12.2.0-14 | |
libstdc++6 |
CVE-2022-27943 | LOW | 12.2.0-14 | |
libuuid1 |
CVE-2022-0563 | LOW | 2.38.1-5+deb12u1 | |
zlib1g |
CVE-2023-45853 | CRITICAL | 1:1.2.13.dfsg-1 |
Descriptor | Linter | Files | Fixed | Errors | Elapsed time |
---|---|---|---|---|---|
β ACTION | actionlint | 4 | 0 | 0.03s | |
β DOCKERFILE | hadolint | 2 | 0 | 0.11s | |
β EDITORCONFIG | editorconfig-checker | 66 | 0 | 0.3s | |
β GROOVY | npm-groovy-lint | 2 | 0 | 8.71s | |
β JAVA | checkstyle | 18 | 0 | 4.45s | |
β JSON | jsonlint | 5 | 0 | 0.21s | |
β JSON | prettier | 5 | 0 | 2.15s | |
β JSON | v8r | 5 | 0 | 3.91s | |
β MARKDOWN | markdownlint | 2 | 0 | 0.66s | |
β PYTHON | bandit | 1 | 0 | 0.93s | |
β PYTHON | black | 1 | 0 | 0.63s | |
β PYTHON | flake8 | 1 | 0 | 0.47s | |
β PYTHON | isort | 1 | 0 | 0.52s | |
β PYTHON | mypy | 1 | 0 | 7.35s | |
β PYTHON | ruff | 1 | 0 | 0.02s | |
β REPOSITORY | checkov | yes | no | 16.77s | |
β REPOSITORY | gitleaks | yes | no | 1.04s | |
β REPOSITORY | git_diff | yes | no | 0.03s | |
β REPOSITORY | grype | yes | no | 14.39s | |
β REPOSITORY | kics | yes | no | 4.72s | |
β REPOSITORY | secretlint | yes | no | 1.24s | |
β REPOSITORY | syft | yes | no | 2.6s | |
β REPOSITORY | trivy | yes | no | 10.06s | |
β REPOSITORY | trivy-sbom | yes | no | 7.98s | |
β REPOSITORY | trufflehog | yes | no | 4.09s | |
β SQL | sql-lint | 1 | 0 | 0.48s | |
β XML | xmllint | 1 | 0 | 0.02s | |
β YAML | prettier | 17 | 0 | 1.4s | |
β YAML | yamllint | 17 | 0 | 0.49s |
See detailed report in MegaLinter reports
You could have same capabilities but better runtime performances if you request a new MegaLinter flavor.
Overall Project | 28.96% | :x: |
---|
There is no coverage information present for the Files changed
:tada: This PR is included in version 3.13.1 :tada:
The release is available on GitHub release
Your semantic-release bot :package::rocket:
Bumps requests from 2.31.0 to 2.32.0.
Release notes
Sourced from requests's releases.
... (truncated)
Changelog
Sourced from requests's changelog.
Commits
d6ebc4a
v2.32.09a40d12
Avoid reloading root certificates to improve concurrent performance (#6667)0c030f7
Merge pull request #6702 from nateprewitt/no_char_detection555b870
Allow character detection dependencies to be optional in post-packaging stepsd6dded3
Merge pull request #6700 from franekmagiera/update-redirect-to-invalid-uri-testbf24b7d
Use an invalid URI that will not cause httpbin to throw 5002d5f547
Pin 3.8 and 3.9 runners back to macos-13 (#6688)f1bb07d
Merge pull request #6687 from psf/dependabot/github_actions/github/codeql-act...60047ad
Bump github/codeql-action from 3.24.0 to 3.25.031ebb81
Merge pull request #6682 from frenzymadness/pytest8Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show