Skip to content

ci: central workflow - #211

Merged
chgl merged 2 commits into
masterfrom
chart-testing
Sep 11, 2026
Merged

chgl merged 2 commits into
masterfrom
chart-testing

Conversation

@chgl

@chgl chgl commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@github-actions

github-actions Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

✅⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ ACTION actionlint 8 0 0 0.32s
✅ COPYPASTE jscpd yes no no 0.8s
✅ DOCKERFILE hadolint 1 0 0 0.15s
✅ JSON jsonlint 3 0 0 0.14s
✅ JSON prettier 3 0 0 0.51s
✅ JSON v8r 3 0 0 3.41s
✅ MARKDOWN markdownlint 1 0 0 0.52s
✅ MARKDOWN markdown-table-formatter 1 0 0 0.24s
✅ PYTHON bandit 1 0 0 1.95s
✅ PYTHON black 1 0 0 1.97s
✅ PYTHON flake8 1 0 0 1.06s
✅ PYTHON isort 1 0 0 0.24s
✅ PYTHON mypy 1 0 0 4.04s
✅ PYTHON pylint 1 0 0 3.04s
✅ PYTHON pyright 1 0 0 2.03s
✅ PYTHON ruff 1 0 0 0.03s
✅ REPOSITORY betterleaks yes no no 1.07s
⚠️ REPOSITORY checkov yes no 2 25.96s
✅ REPOSITORY devskim yes no no 1.49s
✅ REPOSITORY dustilock yes no no 0.02s
✅ REPOSITORY git_diff yes no no 0.01s
✅ REPOSITORY grype yes no no 73.0s
✅ REPOSITORY kingfisher yes no no 6.41s
✅ REPOSITORY secretlint yes no no 0.72s
✅ REPOSITORY syft yes no no 2.87s
✅ REPOSITORY trivy yes no no 13.65s
✅ REPOSITORY trivy-sbom yes no no 0.17s
✅ REPOSITORY trufflehog yes no no 5.34s
✅ TERRAFORM terragrunt 1 0 0 0.11s
⚠️ YAML prettier 22 48 0 0.74s
✅ YAML v8r 22 0 0 12.75s
✅ YAML yamllint 22 0 0 0.94s

Detailed Issues

⚠️ REPOSITORY / checkov - 2 warnings
warning: Liveness Probe Should be Configured
 = Liveness Probe Should be Configured
 = Liveness Probe Should be Configured

warning: Readiness Probe Should be Configured
 = Readiness Probe Should be Configured
 = Readiness Probe Should be Configured

warning: 2 warnings emitted
⚠️ YAML / prettier - 48 errors
Checking formatting...
[error] charts/test-chart/templates/deployment.yaml: SyntaxError: Block collections are not allowed within flow collections (6:7)
[error]   4 |   name: {{ include "test-chart.fullname" . }}
[error]   5 |   labels:
[error] > 6 |     {{- include "test-chart.labels" . | nindent 4 }}
[error]     |       ^^
[error]   7 | spec:
[error]   8 |   {{- if not .Values.autoscaling.enabled }}
[error]   9 |   replicas: {{ .Values.replicaCount }}
[error] charts/test-chart/templates/hpa.yaml: SyntaxError: Block collections are not allowed within flow collections (1:3)
[error] > 1 | {{- if .Values.autoscaling.enabled }}
[error]     |   ^^
[error]   2 | apiVersion: autoscaling/v2
[error]   3 | kind: HorizontalPodAutoscaler
[error]   4 | metadata:
[error] charts/test-chart/templates/httproute.yaml: SyntaxError: Block collections are not allowed within flow collections (1:3)
[error] > 1 | {{- if .Values.httpRoute.enabled -}}
[error]     |   ^^
[error]   2 | {{- $fullName := include "test-chart.fullname" . -}}
[error]   3 | {{- $svcPort := .Values.service.port -}}
[error]   4 | apiVersion: gateway.networking.k8s.io/v1
[error] charts/test-chart/templates/ingress.yaml: SyntaxError: Block collections are not allowed within flow collections (1:3)
[error] > 1 | {{- if .Values.ingress.enabled -}}
[error]     |   ^^
[error]   2 | apiVersion: networking.k8s.io/v1
[error]   3 | kind: Ingress
[error]   4 | metadata:
[error] charts/test-chart/templates/service.yaml: SyntaxError: Block collections are not allowed within flow collections (6:7)
[error]   4 |   name: {{ include "test-chart.fullname" . }}
[error]   5 |   labels:
[error] > 6 |     {{- include "test-chart.labels" . | nindent 4 }}
[error]     |       ^^
[error]   7 | spec:
[error]   8 |   type: {{ .Values.service.type }}
[error]   9 |   ports:
[error] charts/test-chart/templates/serviceaccount.yaml: SyntaxError: Block collections are not allowed within flow collections (1:3)
[error] > 1 | {{- if .Values.serviceAccount.create -}}
[error]     |   ^^
[error]   2 | apiVersion: v1
[error]   3 | kind: ServiceAccount
[error]   4 | metadata:
[error] charts/test-chart/templates/tests/test-connection.yaml: SyntaxError: Unexpected scalar at node end (4:22)
[error]   2 | kind: Pod
[error]   3 | metadata:
[error] > 4 |   name: "{{ include "test-chart.fullname" . }}-test-connection"
[error]     |                      ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[error]   5 |   labels:
[error]   6 |     {{- include "test-chart.labels" . | nindent 4 }}
[error]   7 |   annotations:
Error occurred when checking code style in 7 files.

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: REPOSITORY_KICS. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters PYTHON_PYLINT,PYTHON_BLACK,PYTHON_FLAKE8,PYTHON_ISORT,PYTHON_BANDIT,PYTHON_MYPY,PYTHON_PYRIGHT,PYTHON_RUFF,ACTION_ACTIONLINT,COPYPASTE_JSCPD,DOCKERFILE_HADOLINT,JSON_JSONLINT,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_DEVSKIM,REPOSITORY_DUSTILOCK,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,REPOSITORY_KINGFISHER,TERRAFORM_TERRAGRUNT,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

readOnlyRootFilesystem on the wget container broke the helm test hook:
wget defaults to saving the response body to ./index.html, which fails
on a read-only root. --spider checks reachability without writing
anything, which is all this hook needs anyway.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

Trivy image scan report

ghcr.io/miracum/github-reusable-workflow:pr-211 (debian 12.13)

92 known vulnerabilities found (CRITICAL: 0 HIGH: 19 MEDIUM: 55 LOW: 18)

Show detailed table of vulnerabilities
Package ID Severity Installed Version Fixed Version
libc6 CVE-2026-0915 MEDIUM 2.36-9+deb12u13 2.36-9+deb12u14
libc6 CVE-2026-4046 MEDIUM 2.36-9+deb12u13 2.36-9+deb12u14
libc6 CVE-2026-4437 MEDIUM 2.36-9+deb12u13 2.36-9+deb12u14
libc6 CVE-2025-15281 LOW 2.36-9+deb12u13 2.36-9+deb12u14
libc6 CVE-2026-0861 LOW 2.36-9+deb12u13 2.36-9+deb12u14
libc6 CVE-2026-4438 LOW 2.36-9+deb12u13 2.36-9+deb12u14
libexpat1 CVE-2026-76957 HIGH 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-50219 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56131 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56403 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56404 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56405 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56406 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56407 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56408 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56409 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56410 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56411 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56412 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-72522 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libgssapi-krb5-2 CVE-2026-40355 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libgssapi-krb5-2 CVE-2026-40356 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libk5crypto3 CVE-2026-40355 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libk5crypto3 CVE-2026-40356 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libkrb5-3 CVE-2026-40355 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libkrb5-3 CVE-2026-40356 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libkrb5support0 CVE-2026-40355 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libkrb5support0 CVE-2026-40356 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
liblzma5 CVE-2026-34743 MEDIUM 5.4.1-1 5.4.1-1+deb12u1
libpython3.11-minimal CVE-2025-13836 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2026-4224 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-minimal CVE-2026-6100 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-minimal CVE-2025-11468 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-12084 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-13837 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-15282 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-4516 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-6069 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-6075 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-8194 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-8291 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2026-0672 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2026-0865 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2026-1299 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-13462 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-minimal CVE-2026-2297 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-minimal CVE-2026-4519 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-stdlib CVE-2025-13836 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2026-4224 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-stdlib CVE-2026-6100 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-stdlib CVE-2025-11468 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-12084 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-13837 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-15282 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-4516 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-6069 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-6075 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-8194 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-8291 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2026-0672 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2026-0865 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2026-1299 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-13462 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-stdlib CVE-2026-2297 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-stdlib CVE-2026-4519 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libssl3 CVE-2026-45447 HIGH 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-34182 MEDIUM 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-45445 MEDIUM 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-34180 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-42766 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-42770 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-45446 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-7383 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-9076 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
python3.11-minimal CVE-2025-13836 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2026-4224 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
python3.11-minimal CVE-2026-6100 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
python3.11-minimal CVE-2025-11468 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-12084 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-13837 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-15282 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-4516 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-6069 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-6075 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-8194 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-8291 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2026-0672 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2026-0865 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2026-1299 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-13462 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
python3.11-minimal CVE-2026-2297 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
python3.11-minimal CVE-2026-4519 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8

No Misconfigurations found

@github-actions

Copy link
Copy Markdown

Trivy image scan report

ghcr.io/miracum/github-reusable-workflow-without-test-image:pr-211 (debian 12.13)

92 known vulnerabilities found (CRITICAL: 0 HIGH: 19 MEDIUM: 55 LOW: 18)

Show detailed table of vulnerabilities
Package ID Severity Installed Version Fixed Version
libc6 CVE-2026-0915 MEDIUM 2.36-9+deb12u13 2.36-9+deb12u14
libc6 CVE-2026-4046 MEDIUM 2.36-9+deb12u13 2.36-9+deb12u14
libc6 CVE-2026-4437 MEDIUM 2.36-9+deb12u13 2.36-9+deb12u14
libc6 CVE-2025-15281 LOW 2.36-9+deb12u13 2.36-9+deb12u14
libc6 CVE-2026-0861 LOW 2.36-9+deb12u13 2.36-9+deb12u14
libc6 CVE-2026-4438 LOW 2.36-9+deb12u13 2.36-9+deb12u14
libexpat1 CVE-2026-76957 HIGH 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-50219 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56131 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56403 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56404 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56405 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56406 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56407 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56408 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56409 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56410 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56411 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56412 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-72522 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libgssapi-krb5-2 CVE-2026-40355 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libgssapi-krb5-2 CVE-2026-40356 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libk5crypto3 CVE-2026-40355 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libk5crypto3 CVE-2026-40356 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libkrb5-3 CVE-2026-40355 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libkrb5-3 CVE-2026-40356 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libkrb5support0 CVE-2026-40355 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libkrb5support0 CVE-2026-40356 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
liblzma5 CVE-2026-34743 MEDIUM 5.4.1-1 5.4.1-1+deb12u1
libpython3.11-minimal CVE-2025-13836 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2026-4224 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-minimal CVE-2026-6100 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-minimal CVE-2025-11468 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-12084 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-13837 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-15282 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-4516 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-6069 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-6075 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-8194 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-8291 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2026-0672 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2026-0865 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2026-1299 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-13462 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-minimal CVE-2026-2297 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-minimal CVE-2026-4519 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-stdlib CVE-2025-13836 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2026-4224 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-stdlib CVE-2026-6100 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-stdlib CVE-2025-11468 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-12084 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-13837 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-15282 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-4516 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-6069 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-6075 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-8194 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-8291 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2026-0672 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2026-0865 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2026-1299 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-13462 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-stdlib CVE-2026-2297 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-stdlib CVE-2026-4519 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libssl3 CVE-2026-45447 HIGH 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-34182 MEDIUM 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-45445 MEDIUM 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-34180 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-42766 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-42770 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-45446 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-7383 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-9076 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
python3.11-minimal CVE-2025-13836 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2026-4224 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
python3.11-minimal CVE-2026-6100 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
python3.11-minimal CVE-2025-11468 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-12084 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-13837 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-15282 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-4516 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-6069 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-6075 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-8194 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-8291 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2026-0672 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2026-0865 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2026-1299 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-13462 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
python3.11-minimal CVE-2026-2297 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
python3.11-minimal CVE-2026-4519 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8

No Misconfigurations found

@github-actions

Copy link
Copy Markdown

Trivy image scan report

ghcr.io/miracum/github-reusable-workflow-with-fixed-image-tags:v1.2.3-beta.123 (debian 12.13)

92 known vulnerabilities found (MEDIUM: 55 LOW: 18 CRITICAL: 0 HIGH: 19)

Show detailed table of vulnerabilities
Package ID Severity Installed Version Fixed Version
libc6 CVE-2026-0915 MEDIUM 2.36-9+deb12u13 2.36-9+deb12u14
libc6 CVE-2026-4046 MEDIUM 2.36-9+deb12u13 2.36-9+deb12u14
libc6 CVE-2026-4437 MEDIUM 2.36-9+deb12u13 2.36-9+deb12u14
libc6 CVE-2025-15281 LOW 2.36-9+deb12u13 2.36-9+deb12u14
libc6 CVE-2026-0861 LOW 2.36-9+deb12u13 2.36-9+deb12u14
libc6 CVE-2026-4438 LOW 2.36-9+deb12u13 2.36-9+deb12u14
libexpat1 CVE-2026-76957 HIGH 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-50219 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56131 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56403 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56404 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56405 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56406 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56407 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56408 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56409 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56410 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56411 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-56412 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libexpat1 CVE-2026-72522 MEDIUM 2.5.0-1+deb12u2 2.5.0-1+deb12u3
libgssapi-krb5-2 CVE-2026-40355 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libgssapi-krb5-2 CVE-2026-40356 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libk5crypto3 CVE-2026-40355 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libk5crypto3 CVE-2026-40356 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libkrb5-3 CVE-2026-40355 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libkrb5-3 CVE-2026-40356 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libkrb5support0 CVE-2026-40355 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
libkrb5support0 CVE-2026-40356 HIGH 1.20.1-2+deb12u4 1.20.1-2+deb12u5
liblzma5 CVE-2026-34743 MEDIUM 5.4.1-1 5.4.1-1+deb12u1
libpython3.11-minimal CVE-2025-13836 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2026-4224 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-minimal CVE-2026-6100 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-minimal CVE-2025-11468 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-12084 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-13837 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-15282 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-4516 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-6069 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-6075 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-8194 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-8291 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2026-0672 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2026-0865 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2026-1299 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-minimal CVE-2025-13462 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-minimal CVE-2026-2297 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-minimal CVE-2026-4519 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-stdlib CVE-2025-13836 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2026-4224 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-stdlib CVE-2026-6100 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-stdlib CVE-2025-11468 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-12084 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-13837 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-15282 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-4516 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-6069 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-6075 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-8194 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-8291 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2026-0672 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2026-0865 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2026-1299 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
libpython3.11-stdlib CVE-2025-13462 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-stdlib CVE-2026-2297 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libpython3.11-stdlib CVE-2026-4519 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
libssl3 CVE-2026-45447 HIGH 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-34182 MEDIUM 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-45445 MEDIUM 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-34180 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-42766 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-42770 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-45446 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-7383 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
libssl3 CVE-2026-9076 LOW 3.0.19-1~deb12u2 3.0.20-1~deb12u2
python3.11-minimal CVE-2025-13836 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2026-4224 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
python3.11-minimal CVE-2026-6100 HIGH 3.11.2-6+deb12u6 3.11.2-6+deb12u8
python3.11-minimal CVE-2025-11468 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-12084 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-13837 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-15282 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-4516 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-6069 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-6075 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-8194 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-8291 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2026-0672 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2026-0865 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2026-1299 MEDIUM 3.11.2-6+deb12u6 3.11.2-6+deb12u7
python3.11-minimal CVE-2025-13462 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
python3.11-minimal CVE-2026-2297 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8
python3.11-minimal CVE-2026-4519 LOW 3.11.2-6+deb12u6 3.11.2-6+deb12u8

No Misconfigurations found

@chgl
chgl merged commit 1094e9c into master Sep 11, 2026
37 checks passed
@chgl
chgl deleted the chart-testing branch September 11, 2026 00:09
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 1.27.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

chgl added a commit that referenced this pull request Sep 11, 2026
…un_id (#216)

The concurrency group added in #212 to serialize sign-image,
image-provenance, and attest-trivy-vulnerability-report was scoped to
github.run_id, which only prevents races between jobs within a single
workflow run. It does nothing to stop separate runs from racing each
other when they build the same image digest (e.g. several renovate
PRs merging back to back without touching the Dockerfile) - which is
exactly what happened on master after #210/#211/#212 merged in quick
succession, cancelling every ci run for hours and blocking releases.

Scoping the group by image+digest instead serializes referrer writes
across runs whenever they target the same underlying ghcr.io digest,
while leaving genuinely unrelated builds (different images, or the
same image at a different digest) free to run in parallel.

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant