-
Notifications
You must be signed in to change notification settings - Fork 0
gomodules: bump github.com/pulumi/pulumi/sdk/v3 from 3.142.0 to 3.149.0 #19
base: trunk
Are you sure you want to change the base?
gomodules: bump github.com/pulumi/pulumi/sdk/v3 from 3.142.0 to 3.149.0 #19
Conversation
Bumps [github.com/pulumi/pulumi/sdk/v3](https://github.com/pulumi/pulumi) from 3.142.0 to 3.149.0. - [Release notes](https://github.com/pulumi/pulumi/releases) - [Changelog](https://github.com/pulumi/pulumi/blob/master/CHANGELOG.md) - [Commits](pulumi/pulumi@v3.142.0...v3.149.0) --- updated-dependencies: - dependency-name: github.com/pulumi/pulumi/sdk/v3 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
The following labels could not be found: |
| @@ -0,0 +1,9 @@ | |||
| FROM golang:1.17 | |||
Check failure
Code scanning / Trivy
Image user should not be 'root' High library
Type: dockerfile
Vulnerability DS002
Severity: HIGH
Message: Specify at least 1 USER command in Dockerfile with non-root user as argument
Link: DS002
| @@ -0,0 +1,9 @@ | |||
| FROM golang:1.17 | |||
Check notice
Code scanning / Trivy
No HEALTHCHECK defined Low library
Type: dockerfile
Vulnerability DS026
Severity: LOW
Message: Add HEALTHCHECK instruction in your Dockerfile
Link: DS026
| FROM golang:1.17 | ||
|
|
||
| RUN curl -sL https://deb.nodesource.com/setup_17.x | bash | ||
| RUN apt-get install --yes nodejs |
Check failure
Code scanning / Trivy
'apt-get' missing '--no-install-recommends' High library
Type: dockerfile
Vulnerability DS029
Severity: HIGH
Message: '--no-install-recommends' flag is missed: 'apt-get install --yes nodejs'
Link: DS029
| @@ -0,0 +1,6 @@ | |||
| FROM golang:1.17 | |||
Check failure
Code scanning / Trivy
Image user should not be 'root' High library
Type: dockerfile
Vulnerability DS002
Severity: HIGH
Message: Specify at least 1 USER command in Dockerfile with non-root user as argument
Link: DS002
| @@ -0,0 +1,6 @@ | |||
| FROM golang:1.17 | |||
Check notice
Code scanning / Trivy
No HEALTHCHECK defined Low library
Type: dockerfile
Vulnerability DS026
Severity: LOW
Message: Add HEALTHCHECK instruction in your Dockerfile
Link: DS026
| @@ -0,0 +1,23 @@ | |||
| FROM golang:1.20@sha256:2edf6aab2d57644f3fe7407132a0d1770846867465a39c2083770cf62734b05d | |||
Check failure
Code scanning / Trivy
Image user should not be 'root' High library
Type: dockerfile
Vulnerability DS002
Severity: HIGH
Message: Specify at least 1 USER command in Dockerfile with non-root user as argument
Link: DS002
| @@ -0,0 +1,23 @@ | |||
| FROM golang:1.20@sha256:2edf6aab2d57644f3fe7407132a0d1770846867465a39c2083770cf62734b05d | |||
Check notice
Code scanning / Trivy
No HEALTHCHECK defined Low library
Type: dockerfile
Vulnerability DS026
Severity: LOW
Message: Add HEALTHCHECK instruction in your Dockerfile
Link: DS026
| @@ -0,0 +1,23 @@ | |||
| FROM golang:1.20@sha256:2edf6aab2d57644f3fe7407132a0d1770846867465a39c2083770cf62734b05d | |||
Check failure
Code scanning / Trivy
Image user should not be 'root' High library
Type: dockerfile
Vulnerability DS002
Severity: HIGH
Message: Specify at least 1 USER command in Dockerfile with non-root user as argument
Link: DS002
| @@ -0,0 +1,23 @@ | |||
| FROM golang:1.20@sha256:2edf6aab2d57644f3fe7407132a0d1770846867465a39c2083770cf62734b05d | |||
Check notice
Code scanning / Trivy
No HEALTHCHECK defined Low library
Type: dockerfile
Vulnerability DS026
Severity: LOW
Message: Add HEALTHCHECK instruction in your Dockerfile
Link: DS026
Bumps github.com/pulumi/pulumi/sdk/v3 from 3.142.0 to 3.149.0.
Release notes
Sourced from github.com/pulumi/pulumi/sdk/v3's releases.
... (truncated)
Changelog
Sourced from github.com/pulumi/pulumi/sdk/v3's changelog.
... (truncated)
Commits
ab282f7Bump Java to 1.2.0 (#18493)3148990Don’t set the files option codecov/test-results-action (#18491)ffaea10Detect when we are in the merge queue and override the branch name (#18488)9a2010bDon't always rebuild targets with%.ensuredependencies (#18474)24113d1[Experimental/Components] Ensure component and type module is relative to the...18f064fUpload test results to codecov (#18479)698d5abImprove the warning when using plugins from PATH (#18476)87de226Rejig import files to record base plugin names and versions in the paramteris...0c37221Go: fix packages/Go SDK generation when name contains "-" (#18457)66ab796Bump bundled .Net and YAML versions (#18471)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)