Skip to content

chore(oci/reactive-resume): pin dependencies - #4835

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/pin-dig-ghcr.io-jjgadgets-reactive-resume-.x
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/pin-dig-ghcr.io-jjgadgets-reactive-resume-.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented Mar 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
ghcr.io/jjgadgets/reactive-resume pinDigest → 8786b3c
ghcr.io/jjgadgets/reactive-resume pinDigest → f1a0e85

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Mar 1, 2026 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: 581b997
Status:🚫  Build failed.

View logs

@tinfoild
tinfoild Bot force-pushed the renovate/pin-dig-ghcr.io-jjgadgets-reactive-resume-.x branch 26 times, most recently from 1964536 to f4b2837 Compare March 2, 2026 16:22
@tinfoild
tinfoild Bot force-pushed the renovate/pin-dig-ghcr.io-jjgadgets-reactive-resume-.x branch 28 times, most recently from 0ac41a1 to e1a6b80 Compare March 5, 2026 19:32
@ciel-shieru

ciel-shieru commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 10:33 SGT
🤖 Scanner: Ciel Security Scanner
🔗 PR: #4835 — chore(oci/reactive-resume): pin dependencies
📦 Packages checked: 2
🔍 Sources: NVD, OSV.dev, GHSA, GHSL, CISA KEV, FortiGuard, CVE.org, Changelog
⚠️ Vulnerabilities found: 0


Severity Summary

Severity Count
CRITICAL 0
HIGH 0
MEDIUM / MODERATE 0
LOW 0
UNKNOWN / NEEDS VERIFICATION 0
Total 0

Results

Package: ghcr.io/jjgadgets/reactive-resume (server)

  • Ecosystem: OCI / Docker
  • Old version: server-3.7.5
  • New version: server-3.7.5@sha256:f1a0e857...

Vulnerabilities in server-3.7.5

No known vulnerabilities found.

Vulnerabilities in new version (digest-pinned)

No known vulnerabilities found.

Package: ghcr.io/jjgadgets/reactive-resume (frontend/client)

  • Ecosystem: OCI / Docker
  • Old version: client-3.7.5
  • New version: client-3.7.5@sha256:8786b3c3...

Vulnerabilities in client-3.7.5

No known vulnerabilities found.

Vulnerabilities in new version (digest-pinned)

No known vulnerabilities found.

Source scan summary

Source Status Notes
OSV.dev ✅ Scanned No results for reactive-resume across all ecosystems
NVD ✅ Scanned No CVEs found for reactive-resume
GHSA ✅ Scanned No advisories for reactive-resume
GHSL ✅ Scanned No publications found
CISA KEV ✅ Scanned No entries for reactive-resume
FortiGuard ✅ Scanned No advisories found
CVE.org ✅ Scanned No CVEs found for reactive-resume
Changelog ✅ Scanned v3.7.5 adds health module only — no security patches

Recommendations

  • MERGE PRIORITY: LOW — No security vulnerabilities found in either version. This PR is a supply-chain hardening improvement (pinning image digests for immutable references), not a version change. Merge at own discretion.

⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants