Skip to content

Update docker/build-push-action digest to 10e90e3#474

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/docker-build-push-action-digest
Open

Update docker/build-push-action digest to 10e90e3#474
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/docker-build-push-action-digest

Conversation

@renovate

@renovate renovate Bot commented May 26, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
docker/build-push-action (changelog) action digest 263435310e90e3

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@semanticdiff-com

semanticdiff-com Bot commented May 26, 2026

Copy link
Copy Markdown

Review changes with  SemanticDiff

Changed Files
File Status
  .github/workflows/.docker.yaml  0% smaller

@renovate renovate Bot temporarily deployed to code_quality May 26, 2026 22:02 Inactive
@sonarqubecloud

Copy link
Copy Markdown

@renovate renovate Bot deployed to code_quality May 26, 2026 22:03 Active
@socket-security

Copy link
Copy Markdown

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: pypi transformers has a Deserialization of Untrusted Data vulnerability

CVE: GHSA-3863-2447-669p transformers has a Deserialization of Untrusted Data vulnerability (CRITICAL)

Affected versions: < 4.36.0

Patched version: 4.36.0

From: pyproject.tomlpypi/transformers@4.19.4

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/transformers@4.19.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@MH0386

MH0386 commented May 26, 2026

Copy link
Copy Markdown
Contributor

Recommended fixes for image ghcr.io/github/gh-aw-firewall/agent:latest

Base image is ubuntu:22.04

Namejammy-20260509
Digestsha256:ce941a2a18bbb922e434d6d6d2b31e571a5c3826eaf6ada0a41dcc905bd2d906
Vulnerabilitiescritical: 0 high: 0 medium: 18 low: 9
Pushed2 weeks ago
Size30 MB
Packages143
Flavorubuntu
OS22.04
The base image is also available under the supported tag(s): jammy, jammy-20260509

Refresh base image

Rebuild the image using a newer base image version. Updating this may result in breaking changes.

✅ This image version is up to date.

Change base image

TagDetailsPushedVulnerabilities
25.10
Major OS version update
Also known as:
  • rolling
  • questing
  • questing-20251217
Benefits:
  • Image contains 19 fewer packages
  • Image has similar size
  • Image introduces no new vulnerability but removes 27
  • Major OS version update
Image details:
  • Size: 34 MB
  • OS: 25.10
5 months ago



24.04
Major OS version update
Also known as:
  • noble
  • noble-20260410
Benefits:
  • Image is smaller by 3.6 KB
  • Image contains 12 fewer packages
  • Major OS version update
Image details:
  • Size: 30 MB
  • OS: 24.04
1 month ago



@MH0386

MH0386 commented May 26, 2026

Copy link
Copy Markdown
Contributor
Your image ghcr.io/dependabot/dependabot-updater-core:latest critical: 14 high: 83 medium: 1325 low: 39 unspecified: 2
Current base image ubuntu:24.04 critical: 0 high: 0 medium: 22 low: 2
Updated base image ubuntu:25.10 critical: 0 high: 0 medium: 0 low: 0

@renovate renovate Bot temporarily deployed to docker_image May 26, 2026 22:07 Inactive
@renovate renovate Bot temporarily deployed to docker_image May 26, 2026 22:09 Inactive
@renovate renovate Bot temporarily deployed to docker_image May 26, 2026 22:09 Inactive
@renovate renovate Bot temporarily deployed to docker_image May 26, 2026 22:09 Inactive
@renovate renovate Bot deployed to docker_image May 26, 2026 22:12 Active
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant