Skip to content

Conversation

@org-internal-bot
Copy link
Contributor

This PR contains the following updates:

Package Type Update Change
arigaio/atlas stage major 0.38.0-community-alpine β†’ 1.0.0-community-alpine

Configuration

πŸ“… Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

β™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

πŸ”• Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@org-internal-bot org-internal-bot bot added the dependencies Pull requests that update a dependency file label Dec 25, 2025
@org-internal-bot org-internal-bot bot requested a review from davidB December 25, 2025 04:53
@github-actions
Copy link

βœ…βš οΈMegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Warnings Elapsed time
βœ… DOCKERFILE hadolint 1 0 0 0.24s
βœ… EDITORCONFIG editorconfig-checker 1 0 0 0.19s
⚠️ REPOSITORY trivy yes 1 no 4.85s
βœ… REPOSITORY trivy-sbom yes no no 0.33s

Detailed Issues

⚠️ REPOSITORY / trivy - 1 error
2025-12-25T04:54:39Z	INFO	[vulndb] Need to update DB
2025-12-25T04:54:39Z	INFO	[vulndb] Downloading vulnerability DB...
2025-12-25T04:54:39Z	INFO	[vulndb] Downloading artifact...	repo="mirror.gcr.io/aquasec/trivy-db:2"
22.89 MiB / 78.89 MiB [----------------->___________________________________________] 29.02% ? p/s ?65.66 MiB / 78.89 MiB [-------------------------------------------------->__________] 83.22% ? p/s ?78.89 MiB / 78.89 MiB [----------------------------------------------------------->] 100.00% ? p/s ?78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 93.22 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 93.22 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 93.22 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 87.21 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 87.21 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 87.21 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 81.58 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 81.58 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [---------------------------------------------->] 100.00% 81.58 MiB p/s ETA 0s78.89 MiB / 78.89 MiB [-------------------------------------------------] 100.00% 34.30 MiB p/s 2.5s2025-12-25T04:54:42Z	INFO	[vulndb] Artifact successfully downloaded	repo="mirror.gcr.io/aquasec/trivy-db:2"
2025-12-25T04:54:42Z	INFO	[vuln] Vulnerability scanning is enabled
2025-12-25T04:54:42Z	INFO	[misconfig] Misconfiguration scanning is enabled
2025-12-25T04:54:42Z	INFO	[misconfig] Need to update the checks bundle
2025-12-25T04:54:42Z	INFO	[misconfig] Downloading the checks bundle...
165.46 KiB / 165.46 KiB [------------------------------------------------------] 100.00% ? p/s 100ms2025-12-25T04:54:44Z	ERROR	[helm scanner] Failed to render Chart files	file_path="charts/cdviz-collector" err="found in Chart.yaml, but missing in charts/ directory: kubewatch"
2025-12-25T04:54:44Z	INFO	Number of language-specific files	num=0
2025-12-25T04:54:44Z	INFO	Detected config files	num=2

Report Summary

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                     Target                     β”‚    Type    β”‚ Vulnerabilities β”‚ Misconfigurations β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ cdviz-db/Dockerfile                            β”‚ dockerfile β”‚        -        β”‚         0         β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ charts/cdviz-db/templates/job-dbmigration.yaml β”‚    helm    β”‚        -        β”‚         1         β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


charts/cdviz-db/templates/job-dbmigration.yaml (helm)
=====================================================
Tests: 93 (SUCCESSES: 92, FAILURES: 1)
Failures: 1 (UNKNOWN: 0, LOW: 1, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

AVD-KSV-0021 (LOW): Container 'cdviz-db-migration' of CronJob 'cdviz-db-migration' should set 'securityContext.runAsGroup' > 10000
════════════════════════════════════════
Force the container to run with group ID > 10000 to avoid conflicts with the host’s user table.

See https://avd.aquasec.com/misconfig/ksv021
────────────────────────────────────────
 charts/cdviz-db/templates/job-dbmigration.yaml:35-65
────────────────────────────────────────
  35 β”Œ           - name: 'cdviz-db-migration'
  36 β”‚             image: "ghcr.io/cdviz-dev/cdviz-db-migration:0.20250607150000.0"
  37 β”‚             # args for https://atlasgo.io/declarative/apply
  38 β”‚             args:
  39 β”‚               - migrate # or schema
  40 β”‚               - apply
  41 β”‚               - -u
  42 β”‚               - "$(DATABASE_URL)"
  43 β””               - --dir
  ..   
────────────────────────────────────────



πŸ“£ Notices:
  - Version 0.68.2 of Trivy is now available, current version is 0.67.2

To suppress version checks, run Trivy scans with the --skip-version-check flag

See detailed reports in MegaLinter artifacts
Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff

MegaLinter is graciously provided by OX Security

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant