Skip to content

Conversation

org-internal-bot[bot]
Copy link
Contributor

This PR contains the following updates:

Package Update Change
ubi:mozilla/grcov minor 0.8 -> 0.10.5

Release Notes

mozilla/grcov (ubi:mozilla/grcov)

v0.10.5

Compare Source

Release v0.10.5

v0.10.4

Compare Source

Release v0.10.4

v0.10.3

Compare Source

Release v0.10.3

v0.10.2

Compare Source

Release v0.10.2

v0.10.1

Compare Source

Release v0.10.1

v0.10.0

Compare Source

Release v0.10.0

v0.9.1

Compare Source

Release v0.9.1

v0.9.0

Compare Source

Release v0.9.0


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

Copy link
Contributor

⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ REPOSITORY gitleaks yes no no 4.45s
⚠️ REPOSITORY trivy yes 1 no 8.3s
✅ REPOSITORY trivy-sbom yes no no 7.7s

Detailed Issues

⚠️ REPOSITORY / trivy - 1 error
2025-10-12T04:44:59Z	INFO	[vulndb] Need to update DB
2025-10-12T04:44:59Z	INFO	[vulndb] Downloading vulnerability DB...
2025-10-12T04:44:59Z	INFO	[vulndb] Downloading artifact...	repo="mirror.gcr.io/aquasec/trivy-db:2"
20.98 MiB / 72.58 MiB [----------------->___________________________________________] 28.91% ? p/s ?58.48 MiB / 72.58 MiB [------------------------------------------------->___________] 80.58% ? p/s ?72.58 MiB / 72.58 MiB [----------------------------------------------------------->] 100.00% ? p/s ?72.58 MiB / 72.58 MiB [---------------------------------------------->] 100.00% 86.11 MiB p/s ETA 0s72.58 MiB / 72.58 MiB [---------------------------------------------->] 100.00% 86.11 MiB p/s ETA 0s72.58 MiB / 72.58 MiB [---------------------------------------------->] 100.00% 86.11 MiB p/s ETA 0s72.58 MiB / 72.58 MiB [---------------------------------------------->] 100.00% 80.56 MiB p/s ETA 0s72.58 MiB / 72.58 MiB [---------------------------------------------->] 100.00% 80.56 MiB p/s ETA 0s72.58 MiB / 72.58 MiB [---------------------------------------------->] 100.00% 80.56 MiB p/s ETA 0s72.58 MiB / 72.58 MiB [---------------------------------------------->] 100.00% 75.36 MiB p/s ETA 0s72.58 MiB / 72.58 MiB [---------------------------------------------->] 100.00% 75.36 MiB p/s ETA 0s72.58 MiB / 72.58 MiB [---------------------------------------------->] 100.00% 75.36 MiB p/s ETA 0s72.58 MiB / 72.58 MiB [---------------------------------------------->] 100.00% 70.50 MiB p/s ETA 0s72.58 MiB / 72.58 MiB [---------------------------------------------->] 100.00% 70.50 MiB p/s ETA 0s72.58 MiB / 72.58 MiB [---------------------------------------------->] 100.00% 70.50 MiB p/s ETA 0s72.58 MiB / 72.58 MiB [---------------------------------------------->] 100.00% 65.95 MiB p/s ETA 0s72.58 MiB / 72.58 MiB [---------------------------------------------->] 100.00% 65.95 MiB p/s ETA 0s72.58 MiB / 72.58 MiB [---------------------------------------------->] 100.00% 65.95 MiB p/s ETA 0s72.58 MiB / 72.58 MiB [-------------------------------------------------] 100.00% 21.23 MiB p/s 3.6s2025-10-12T04:45:04Z	INFO	[vulndb] Artifact successfully downloaded	repo="mirror.gcr.io/aquasec/trivy-db:2"
2025-10-12T04:45:04Z	INFO	[vuln] Vulnerability scanning is enabled
2025-10-12T04:45:04Z	INFO	[misconfig] Misconfiguration scanning is enabled
2025-10-12T04:45:04Z	INFO	[misconfig] Need to update the checks bundle
2025-10-12T04:45:04Z	INFO	[misconfig] Downloading the checks bundle...
165.46 KiB / 165.46 KiB [------------------------------------------------------] 100.00% ? p/s 100ms2025-10-12T04:45:07Z	INFO	Number of language-specific files	num=1
2025-10-12T04:45:07Z	INFO	[cargo] Detecting vulnerabilities...
2025-10-12T04:45:07Z	INFO	Detected config files	num=1

Report Summary

┌────────────┬────────────┬─────────────────┬───────────────────┐
│   Target   │    Type    │ Vulnerabilities │ Misconfigurations │
├────────────┼────────────┼─────────────────┼───────────────────┤
│ Cargo.lock │   cargo    │        0        │         -         │
├────────────┼────────────┼─────────────────┼───────────────────┤
│ Dockerfile │ dockerfile │        -        │         1         │
└────────────┴────────────┴─────────────────┴───────────────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


Dockerfile (dockerfile)
=======================
Tests: 27 (SUCCESSES: 26, FAILURES: 1)
Failures: 1 (UNKNOWN: 0, LOW: 0, MEDIUM: 1, HIGH: 0, CRITICAL: 0)

AVD-DS-0001 (MEDIUM): Specify a tag in the 'FROM' statement for image 'cgr.dev/chainguard/glibc-dynamic'
════════════════════════════════════════
When using a 'FROM' statement you should use a specific tag to avoid uncontrolled behavior when the image is updated.

See https://avd.aquasec.com/misconfig/ds001
────────────────────────────────────────
 Dockerfile:148
────────────────────────────────────────
 148 [ FROM --platform=$BUILDPLATFORM cgr.dev/chainguard/glibc-dynamic:latest AS cdviz-collector
────────────────────────────────────────



📣 Notices:
  - Version 0.67.2 of Trivy is now available, current version is 0.67.0

To suppress version checks, run Trivy scans with the --skip-version-check flag

See detailed reports in MegaLinter artifacts
Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff

MegaLinter is graciously provided by OX Security

@davidB davidB merged commit 3174fe4 into main Oct 12, 2025
10 checks passed
@davidB davidB deleted the renovate/ubi-mozilla-grcov-0.x branch October 12, 2025 17:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant