Skip to content

chore(deps): bump distroless/static from e3f9456 to 963fa6c in the dockerfiles-all group#113

Merged
mrz1836 merged 1 commit into
masterfrom
dependabot/docker/master/dockerfiles-all-3ed2d0c5c8
May 20, 2026
Merged

chore(deps): bump distroless/static from e3f9456 to 963fa6c in the dockerfiles-all group#113
mrz1836 merged 1 commit into
masterfrom
dependabot/docker/master/dockerfiles-all-3ed2d0c5c8

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 20, 2026

Bumps the dockerfiles-all group with 1 update: distroless/static.

Updates distroless/static from e3f9456 to 963fa6c

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dockerfiles-all group with 1 update: distroless/static.


Updates `distroless/static` from `e3f9456` to `963fa6c`

---
updated-dependencies:
- dependency-name: distroless/static
  dependency-version: nonroot
  dependency-type: direct:production
  dependency-group: dockerfiles-all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot requested a review from mrz1836 as a code owner May 20, 2026 01:07
@dependabot dependabot Bot added chore Simple dependency updates or version bumps dependencies Dependency updates, version bumps, etc. docker Used for referencing Docker related issues labels May 20, 2026
@github-actions
Copy link
Copy Markdown

🚨 @mrz1836SECURITY - Major version update detected

Dependency: distroless/static
Version: e3f9456nonroot
Type: direct:production
Ecosystem: docker

🔒 This is a security update with potential breaking changes

This requires manual review for potential breaking changes.

Review checklist:

  • Check changelog/release notes for breaking changes
  • Review migration guide if available
  • Test functionality affected by this dependency
  • Update code if necessary to handle breaking changes

@github-actions github-actions Bot added requires-manual-review PR or issue requires manual review by a maintainer or security team size/XS Very small change (≤10 lines) major-update prod-dependency security Security-related issue, vulnerability, or fix labels May 20, 2026
@sonarqubecloud
Copy link
Copy Markdown

@mrz1836 mrz1836 merged commit f1ec573 into master May 20, 2026
39 checks passed
@dependabot dependabot Bot deleted the dependabot/docker/master/dockerfiles-all-3ed2d0c5c8 branch May 20, 2026 11:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore Simple dependency updates or version bumps dependencies Dependency updates, version bumps, etc. docker Used for referencing Docker related issues major-update prod-dependency requires-manual-review PR or issue requires manual review by a maintainer or security team security Security-related issue, vulnerability, or fix size/XS Very small change (≤10 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant