-
Notifications
You must be signed in to change notification settings - Fork 297
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
renovate/38.48.0 package update #26897
Conversation
octo-sts
bot
commented
Aug 22, 2024
Signed-off-by: wolfi-bot <121097084+wolfi-bot@users.noreply.github.com>
Package renovate: Click to expand/collapsePackage renovate:
(
"""
# Generated by melange
pkgname = renovate
- pkgver = 38.46.1-r0
+ pkgver = 38.48.0-r0
arch = x86_64
- size = 243483661
+ size = 241084546
origin = renovate
pkgdesc = Automated dependency updates. Multi-platform and multi-language.
url =
- commit = 554aa6aef5094827f7f0027250b000359c5aa28b
- builddate = 1724255145
+ commit = 71789b4b0376f72afff51132af50758691874448
license = AGPL-3.0-only
depend = git
... // 4 identical lines
depend = so:libstdc++.so.6
# vendored = so:better_sqlite3.node=0
- datahash = fe5349f52e08027fa00d546b31fa06b474134c9b2329fbdffc3c1789cdc883bf
+ datahash = af04f4b25467be1593b85a6ad7feea1f5c3f632911cffb2176f595e5ff8eb168
"""
)
Added: /usr/local/lib/node_modules/renovate/dist/modules/manager/bazel-module/parser/index.d.ts bincapz found differences: Click to expand/collapsetime=2024-08-22T13:54:28.409Z level=ERROR source=github.com/chainguard-dev/bincapz/pkg/action/scan.go:222 msg="unable to process /tmp/wolfictl-apk-4266124191/renovate/usr/local/lib/node_modules/renovate/node_modules/tar-fs/test/fixtures/invalid.tar: extract to temp: failed to extract /tmp/wolfictl-apk-4266124191/renovate/usr/local/lib/node_modules/renovate/node_modules/tar-fs/test/fixtures/invalid.tar: failed to create directory for file: mkdir /tmp/invalid.tar4225689087/foo: not a directory" Deleted: renovate/usr/local/lib/node_modules/renovate/node_modules/protobufjs/dist/minimal/protobuf.min.js [
|
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | kernel/platform | get system identification | process.versions |
-MEDIUM | techniques/code_eval | evaluate code dynamically using eval() | eval("require")(t) |
-LOW | encoding/base64 | Supports base64 encoded strings | base64 |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/dcodeio/protobuf.js |
Deleted: renovate/usr/local/lib/node_modules/renovate/node_modules/protobufjs/dist/minimal/protobuf.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | kernel/platform | get system identification | process.versions |
-MEDIUM | ref/path/relative | references and possibly executes relative path | ./compiled |
-MEDIUM | techniques/code_eval | evaluate code dynamically using eval() | eval("quire" |
-LOW | encoding/base64 | Supports base64 encoded strings | base64 |
-LOW | encoding/json/encode | encodes JSON | JSON.stringify |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://developers.google.com/protocol-buffers/docs/proto3?hl=en protobufjs/protobuf.js#665 https://github.com/dcodeio/protobuf.js |
Deleted: renovate/usr/local/lib/node_modules/renovate/dist/modules/manager/bazel-module/parser.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/path/relative | references and possibly executes relative path | ./fragments |
Deleted: renovate/usr/local/lib/node_modules/renovate/node_modules/protobufjs/dist/light/protobuf.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | kernel/platform | get system identification | process.versions |
-MEDIUM | ref/path/relative | references and possibly executes relative path | ./compiled |
-MEDIUM | techniques/code_eval | evaluate code dynamically using eval() | eval("quire" |
-LOW | encoding/base64 | Supports base64 encoded strings | base64 |
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
-LOW | encoding/json/encode | encodes JSON | JSON.stringify |
-LOW | fs/file/read | reads files | fs.readFile |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest/Sending_a https://developers.google.com/protocol-buffers/docs/proto3?hl=en protobufjs/protobuf.js#665 https://github.com/dcodeio/protobuf.js |
Deleted: renovate/usr/local/lib/node_modules/renovate/node_modules/protobufjs/dist/protobuf.min.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | kernel/platform | get system identification | process.versions |
-MEDIUM | techniques/code_eval | evaluate code dynamically using eval() | eval("require")(t) |
-LOW | encoding/base64 | Supports base64 encoded strings | base64 |
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
-LOW | encoding/json/encode | encodes JSON | JSON.stringify |
-LOW | fs/file/read | reads files | fs.readFile |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/dcodeio/protobuf.js |
Deleted: renovate/var/lib/db/sbom/renovate-38.46.1-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/d1809dd933dbe174fa6534844230 |
Deleted: renovate/usr/local/lib/node_modules/renovate/node_modules/protobufjs/dist/light/protobuf.min.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | kernel/platform | get system identification | process.versions |
-MEDIUM | techniques/code_eval | evaluate code dynamically using eval() | eval("require")(t) |
-LOW | encoding/base64 | Supports base64 encoded strings | base64 |
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
-LOW | encoding/json/encode | encodes JSON | JSON.stringify |
-LOW | fs/file/read | reads files | fs.readFile |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/dcodeio/protobuf.js |
Deleted: renovate/usr/local/lib/node_modules/renovate/node_modules/protobufjs/dist/protobuf.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | kernel/platform | get system identification | process.versions |
-MEDIUM | ref/path/relative | references and possibly executes relative path | ./compiled |
-MEDIUM | techniques/code_eval | evaluate code dynamically using eval() | eval("quire" |
-LOW | encoding/base64 | Supports base64 encoded strings | base64 |
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
-LOW | encoding/json/encode | encodes JSON | JSON.stringify |
-LOW | fs/file/read | reads files | fs.readFile |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest/Sending_a https://developers.google.com/protocol-buffers/docs/proto3?hl=en protobufjs/protobuf.js#665 https://github.com/dcodeio/protobuf.js |
Added: renovate/var/lib/db/sbom/renovate-38.48.0-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | downloadLocation |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/b51ccadbcd131ab8f9d57f4e58e8 |
Added: renovate/usr/local/lib/node_modules/renovate/node_modules/@types/node/sqlite.d.ts [⚠️ MEDIUM]
Changed: /tmp/wolfictl-apk-677591590/renovate/usr/local/lib/node_modules/renovate/node_modules/@smithy/core/dist-cjs/submodules/cbor/index.js
Changed: /tmp/wolfictl-apk-677591590/renovate/usr/local/lib/node_modules/renovate/node_modules/@smithy/core/dist-es/submodules/cbor/cbor-encode.js
Open AI suggestions to solve the build error:
|