Skip to content

chore(deps): update all non-major dependencies - #264

Merged
renovate[bot] merged 1 commit into
masterfrom
renovate/all-minor-patch
Aug 10, 2026
Merged

chore(deps): update all non-major dependencies#264
renovate[bot] merged 1 commit into
masterfrom
renovate/all-minor-patch

Conversation

@renovate

@renovaterenovateBot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
docker.io/library/python (source)finalpatch3.14.6-slim3.14.7-slim
github/codeql-actionactionpatchv4.37.5v4.37.6
step-security/harden-runneractionpatchv2.20.0v2.20.1

Release Notes

github/codeql-action (github/codeql-action)

v4.37.6

Compare Source

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #​4070
step-security/harden-runner (step-security/harden-runner)

v2.20.1

Compare Source

What's Changed
  • AWS CodeBuild-hosted runner support
  • Implicitly allow single-labeled (internal) domains in block-mode

Full Changelog: step-security/harden-runner@v2.20.0...v2.20.1


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actionsBot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

MegaLinter analysis: Success

DescriptorLinterFilesFixedErrorsWarningsElapsed time
✅ ACTIONactionlint4001.23s
✅ ACTIONzizmor4003.97s
✅ COPYPASTEjscpdyesnono0.67s
✅ DOCKERFILEhadolint1001.33s
✅ JSONjsonlint3000.12s
✅ JSONprettier3000.48s
✅ JSONv8r3002.43s
✅ MARKDOWNmarkdownlint1000.64s
✅ MARKDOWNmarkdown-table-formatter1000.23s
✅ PYTHONbandit1003.46s
✅ PYTHONblack1002.25s
✅ PYTHONflake81001.22s
✅ PYTHONisort1000.3s
✅ PYTHONmypy1003.39s
✅ PYTHONpylint1003.28s
✅ PYTHONpyright1001.72s
✅ PYTHONruff1000.33s
✅ REPOSITORYbetterleaksyesnono2.54s
✅ REPOSITORYcheckovyesnono37.9s
✅ REPOSITORYdustilockyesnono0.2s
✅ REPOSITORYgitleaksyesnono1.2s
✅ REPOSITORYgit_diffyesnono0.01s
✅ REPOSITORYgrypeyesnono71.61s
✅ REPOSITORYkingfisheryesnono11.93s
✅ REPOSITORYosv-scanneryesnono0.29s
✅ REPOSITORYsecretlintyesnono1.3s
✅ REPOSITORYsyftyesnono3.07s
✅ REPOSITORYtrivyyesnono12.1s
✅ REPOSITORYtrivy-sbomyesnono0.16s
✅ REPOSITORYtrufflehogyesnono5.72s
✅ YAMLprettier7000.77s
✅ YAMLv8r7007.41s
✅ YAMLyamllint7000.8s

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.6.0 --custom-flavor-setup --custom-flavor-linters PYTHON_PYLINT,PYTHON_BLACK,PYTHON_FLAKE8,PYTHON_ISORT,PYTHON_BANDIT,PYTHON_MYPY,PYTHON_PYRIGHT,PYTHON_RUFF,ACTION_ACTIONLINT,ACTION_ZIZMOR,COPYPASTE_JSCPD,DOCKERFILE_HADOLINT,JSON_JSONLINT,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_DUSTILOCK,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,REPOSITORY_KINGFISHER,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

@renovate
renovateBotforce-pushed the renovate/all-minor-patch branch from c07c128 to 8618b58CompareAugust 10, 2026 04:40
@github-actions

Copy link
Copy Markdown
Contributor

Trivy image scan report

ghcr.io/chgl/github-reusable-workflow-with-fixed-image-tags:v1.2.3-beta.123 (debian 13.6)

No Vulnerabilities found

No Misconfigurations found

Python

3 known vulnerabilities found (CRITICAL: 0 HIGH: 2 MEDIUM: 1 LOW: 0)

Show detailed table of vulnerabilities
PackageIDSeverityInstalled VersionFixed Version
msgpackGHSA-6v7p-g79w-8964HIGH1.1.21.2.1
setuptoolsCVE-2025-47273HIGH70.3.078.1.1
setuptoolsCVE-2026-59890MEDIUM70.3.083.0.0

No Misconfigurations found

@github-actions

Copy link
Copy Markdown
Contributor

Trivy image scan report

ghcr.io/chgl/github-reusable-workflow:pr-264 (debian 13.6)

No Vulnerabilities found

No Misconfigurations found

Python

3 known vulnerabilities found (HIGH: 2 MEDIUM: 1 LOW: 0 CRITICAL: 0)

Show detailed table of vulnerabilities
PackageIDSeverityInstalled VersionFixed Version
msgpackGHSA-6v7p-g79w-8964HIGH1.1.21.2.1
setuptoolsCVE-2025-47273HIGH70.3.078.1.1
setuptoolsCVE-2026-59890MEDIUM70.3.083.0.0

No Misconfigurations found

@github-actions

Copy link
Copy Markdown
Contributor

Trivy image scan report

ghcr.io/chgl/github-reusable-workflow-without-test-image:pr-264 (debian 13.6)

No Vulnerabilities found

No Misconfigurations found

Python

3 known vulnerabilities found (CRITICAL: 0 HIGH: 2 MEDIUM: 1 LOW: 0)

Show detailed table of vulnerabilities
PackageIDSeverityInstalled VersionFixed Version
msgpackGHSA-6v7p-g79w-8964HIGH1.1.21.2.1
setuptoolsCVE-2025-47273HIGH70.3.078.1.1
setuptoolsCVE-2026-59890MEDIUM70.3.083.0.0

No Misconfigurations found

@renovate
renovateBot merged commit 4d3dce6 into masterAug 10, 2026
39 checks passed
@renovate
renovateBot deleted the renovate/all-minor-patch branch August 10, 2026 09:53
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 1.11.48 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants