Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update github-actions #266

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Nov 18, 2024

This PR contains the following updates:

Package Type Update Change
actions/create-github-app-token action digest 5d869da -> 67e27a7
actions/setup-node action digest 39370e3 -> 1d0ff46
actions/upload-artifact action digest b4b15b8 -> 65c4c4a
docker/build-push-action action digest 4f58ea7 -> ca877d9
docker/metadata-action action digest 8e5442c -> 369eb59
docker/scout-action action digest 6ac950e -> b23590d
docker/setup-buildx-action action digest c47758b -> f7ce87c
github/codeql-action action digest 4f3212b -> 9e8d078
mikefarah/yq action digest bbdd974 -> 8bf425b
peter-evans/create-pull-request action digest 5e91468 -> 67ccf78

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: Branch creation - "* 0-3 * * 1" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from gmeligio as a code owner November 18, 2024 01:00
Copy link
Contributor

github-actions bot commented Nov 18, 2024

Overview

Image reference gmeligio/flutter-android:3.27.3 quay.io/gmeligio/flutter-android:3.27.3
- digest b092aabfc1b1 df06b98d9063
- tag 3.27.3 3.27.3
- environment prod
- provenance d6da41d d82e5e3
- vulnerabilities critical: 0 high: 32 medium: 54 low: 70 unspecified: 4 critical: 0 high: 32 medium: 54 low: 68 unspecified: 4
- platform linux/amd64 linux/amd64
- size 1.6 GB 1.7 GB (+138 MB)
- packages 1131 1132 (+1)
Base Image debian:12-slim
also known as:
12.9-slim
bookworm-slim
debian:12-slim
also known as:
12.9-slim
bookworm-slim
- vulnerabilities critical: 0 high: 0 medium: 0 low: 23 unspecified: 1 critical: 0 high: 0 medium: 0 low: 23 unspecified: 1
Labels (2 changes)
  • ± 2 changed
  • 6 unchanged
-org.opencontainers.image.created=2025-01-22T19:29:35.051Z
+org.opencontainers.image.created=2025-02-07T13:29:36.010Z
 org.opencontainers.image.description=Docker images for Flutter Continuous Integration (CI)
 org.opencontainers.image.licenses=NOASSERTION
-org.opencontainers.image.revision=d6da41d3156d752a0ab7ca55b24181500e42b205
+org.opencontainers.image.revision=d82e5e30b0c4b25b315175b9011eea4fec60f618
 org.opencontainers.image.source=https://github.com/gmeligio/flutter-docker-image
 org.opencontainers.image.title=flutter-docker-image
 org.opencontainers.image.url=https://github.com/gmeligio/flutter-docker-image
 org.opencontainers.image.version=3.27.3
Policies (0 improved, 0 worsened, 2 missing data)
Policy Name gmeligio/flutter-android:3.27.3 quay.io/gmeligio/flutter-android:3.27.3 Change Standing
Default non-root user No Change
No AGPL v3 licenses No Change
No fixable critical or high vulnerabilities ⚠️ 31 ⚠️ 31 No Change
No high-profile vulnerabilities No Change
No outdated base images ❓ No data ❓ No data
No unapproved base images ❓ No data ❓ No data
Supply chain attestations ⚠️ 2 ⚠️ 2 No Change
Packages and Vulnerabilities (6 package changes and 2 vulnerability changes)
  • ➕ 1 packages added
  • ♾️ 5 packages changed
  • 1062 packages unchanged
  • ✔️ 2 vulnerabilities removed
Changes for packages of type deb (2 changes)
Package Version
gmeligio/flutter-android:3.27.3
Version
quay.io/gmeligio/flutter-android:3.27.3
♾️ git 1:2.39.5-0+deb12u1 1:2.39.5-0+deb12u2
critical: 0 high: 0 medium: 0 low: 2
Removed vulnerabilities (2):
  • low : CVE--2024--52006
  • low : CVE--2024--50349
♾️ git-man 1:2.39.5-0+deb12u1 1:2.39.5-0+deb12u2
Changes for packages of type gem (3 changes)
Package Version
gmeligio/flutter-android:3.27.3
Version
quay.io/gmeligio/flutter-android:3.27.3
♾️ aws-partitions 1.1041.0 1.1043.0
♾️ aws-sdk-core 3.216.0 3.217.0
♾️ digest-crc 0.6.5 0.7.0
Changes for packages of type maven (1 changes)
Package Version
gmeligio/flutter-android:3.27.3
Version
quay.io/gmeligio/flutter-android:3.27.3
com.sun.xml.bind/jaxb-core 3.0.0

Copy link
Contributor

github-actions bot commented Nov 18, 2024

Recommended fixes for local gmeligio/flutter-android:3.27.3

Base image is debian:12-slim

Namebookworm-20250113-slim
Digestsha256:88615a98ed57334c7adcf5de988ee406b686c263bb7d324cd7b75db01f980503
Vulnerabilitiescritical: 0 high: 0 medium: 0 low: 23 unspecified: 1
Pushed3 weeks ago
Size28 MB
Packages125
Flavordebian
OS12
Slim
The base image is also available under the supported tag(s): 12.9-slim, bookworm-slim

Refresh base image

Rebuild the image using a newer base image version. Updating this may result in breaking changes.
TagDetailsPushedVulnerabilities
12-slim
Newer image for same tag
Also known as:
  • 12.9-slim
  • bookworm-slim
  • bookworm-20250203-slim
Benefits:
  • Same OS detected
  • Newer image for same tag
  • Image is smaller by 114 B
  • Tag was pushed more recently
  • Image has same number of vulnerabilities
  • Image contains equal number of packages
  • Tag is using slim variant
Image details:
  • Size: 28 MB
  • Flavor: debian
  • OS: 12
  • Slim: ✅
4 days ago



Change base image

TagDetailsPushedVulnerabilities
stable-slim
Tag is preferred tag
Also known as:
  • stable-20250203-slim
Benefits:
  • Same OS detected
  • Image is smaller by 113 B
  • Tag is preferred tag
  • Tag was pushed more recently
  • Image has same number of vulnerabilities
  • Image contains equal number of packages
  • Tag is using slim variant
  • stable-slim was pulled 46K times last month
Image details:
  • Size: 28 MB
  • Flavor: debian
  • OS: 12
  • Slim: ✅
4 days ago



12
Tag is latest
Also known as:
  • 12.9
  • bookworm
  • bookworm-20250203
  • latest
Benefits:
  • Same OS detected
  • Tag was pushed more recently
  • Tag is latest
  • Image has same number of vulnerabilities
  • Image contains equal number of packages
Image details:
  • Size: 48 MB
  • Flavor: debian
  • OS: 12
4 days ago



@renovate renovate bot force-pushed the renovate/github-actions branch 4 times, most recently from aa9fc32 to ee9b5d0 Compare November 26, 2024 12:38
@renovate renovate bot force-pushed the renovate/github-actions branch 2 times, most recently from c82eb35 to 36993b8 Compare December 7, 2024 08:11
@renovate renovate bot force-pushed the renovate/github-actions branch 6 times, most recently from 3489f82 to 67c86d9 Compare December 16, 2024 12:36
@renovate renovate bot force-pushed the renovate/github-actions branch 2 times, most recently from 5b413be to 433723b Compare December 20, 2024 19:19
@renovate renovate bot force-pushed the renovate/github-actions branch from 433723b to 2e0ebe0 Compare December 27, 2024 12:13
@renovate renovate bot force-pushed the renovate/github-actions branch 5 times, most recently from 9eee648 to 099e4f5 Compare January 15, 2025 13:54
@renovate renovate bot force-pushed the renovate/github-actions branch 7 times, most recently from a547163 to cb4f4b6 Compare January 27, 2025 20:51
@renovate renovate bot force-pushed the renovate/github-actions branch 4 times, most recently from b779ba7 to a850a30 Compare January 31, 2025 01:42
@renovate renovate bot force-pushed the renovate/github-actions branch 2 times, most recently from b67a8c3 to 611c59b Compare February 6, 2025 16:41
@renovate renovate bot force-pushed the renovate/github-actions branch from 611c59b to 52b9cb6 Compare February 7, 2025 13:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants