-
Notifications
You must be signed in to change notification settings - Fork 0
chore(deps): update docker.io/library/eclipse-temurin docker tag to v25 #234
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
✅
|
| Descriptor | Linter | Files | Fixed | Errors | Warnings | Elapsed time |
|---|---|---|---|---|---|---|
| ✅ ACTION | actionlint | 4 | 0 | 0 | 0.02s | |
| ✅ DOCKERFILE | hadolint | 1 | 0 | 0 | 0.16s | |
| ✅ JSON | jsonlint | 6 | 0 | 0 | 0.19s | |
| ✅ JSON | npm-package-json-lint | yes | no | no | 0.81s | |
| ✅ JSON | prettier | 6 | 0 | 0 | 0.95s | |
| ✅ JSON | v8r | 6 | 0 | 0 | 10.8s | |
| ✅ MARKDOWN | markdownlint | 2 | 0 | 0 | 0.62s | |
| ✅ MARKDOWN | markdown-table-formatter | 2 | 0 | 0 | 0.35s | |
| ✅ REPOSITORY | dustilock | yes | no | no | 0.4s | |
| ✅ REPOSITORY | gitleaks | yes | no | no | 0.38s | |
| ✅ REPOSITORY | git_diff | yes | no | no | 0.01s | |
| ✅ REPOSITORY | grype | yes | no | no | 42.44s | |
| kics | yes | no | 1 | 35.28s | ||
| ✅ REPOSITORY | secretlint | yes | no | no | 1.54s | |
| ✅ REPOSITORY | syft | yes | no | no | 4.05s | |
| ✅ REPOSITORY | trivy | yes | no | no | 11.47s | |
| ✅ REPOSITORY | trivy-sbom | yes | no | no | 0.71s | |
| ✅ REPOSITORY | trufflehog | yes | no | no | 5.74s | |
| ✅ YAML | prettier | 10 | 0 | 0 | 0.67s | |
| ✅ YAML | v8r | 10 | 0 | 0 | 10.46s | |
| ✅ YAML | yamllint | 10 | 0 | 0 | 0.73s |
Detailed Issues
⚠️ REPOSITORY / kics - 1 warning
warning: Dockerfile doesn't contain instruction 'HEALTHCHECK'
┌─ Dockerfile:1:1
│
1 │ FROM docker.io/library/eclipse-temurin:25-jre-noble@sha256:df05e5e48556a59aff4fa62105690f94ce7eccc1d9cf1464b774af4a392a534a
│ ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
│
= Healthcheck Instruction Missing
= Ensure that HEALTHCHECK is being used. The HEALTHCHECK instruction tells Docker how to test a container to check that it is still working
warning: 1 warnings emitted
See detailed reports in MegaLinter artifacts
You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:
- oxsecurity/megalinter/flavors/[email protected] (86 linters)
Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)
- Documentation: Custom Flavors
- Command:
npx [email protected] --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,DOCKERFILE_HADOLINT,JSON_JSONLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_DUSTILOCK,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_GRYPE,REPOSITORY_KICS,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R
9d003d2 to
6ec3aae
Compare
6ec3aae to
2cb136f
Compare
2cb136f to
12a35d2
Compare
12a35d2 to
467d77a
Compare
467d77a to
979a6aa
Compare
Trivy image scan report
|
| Package | ID | Severity | Installed Version | Fixed Version |
|---|---|---|---|---|
ch.qos.logback:logback-core |
CVE-2024-12798 | MEDIUM | 1.2.13 | 1.5.13, 1.3.15 |
ch.qos.logback:logback-core |
CVE-2024-12801 | LOW | 1.2.13 | 1.5.13, 1.3.15 |
com.nimbusds:nimbus-jose-jwt |
CVE-2025-53864 | MEDIUM | 9.37.3 | 10.0.2, 9.37.4 |
commons-beanutils:commons-beanutils |
CVE-2025-48734 | HIGH | 1.9.4 | 1.11.0 |
org.apache.commons:commons-lang3 |
CVE-2025-48924 | MEDIUM | 3.14.0 | 3.18.0 |
org.fhir:ucum |
CVE-2024-55887 | HIGH | 1.0.3 | 1.0.9 |
org.hl7.fhir.publisher:org.hl7.fhir.publisher.cli |
CVE-2024-52807 | HIGH | 1.7.1 | 1.7.4 |
org.hl7.fhir.publisher:org.hl7.fhir.publisher.cli |
CVE-2025-24363 | MEDIUM | 1.7.1 | 1.8.9 |
org.hl7.fhir.publisher:org.hl7.fhir.publisher.core |
CVE-2024-52807 | HIGH | 1.7.1 | 1.7.4 |
org.hl7.fhir.publisher:org.hl7.fhir.publisher.core |
CVE-2025-24363 | MEDIUM | 1.7.1 | 1.8.9 |
No Misconfigurations found
Node.js
No Vulnerabilities found
No Misconfigurations found
Ruby
No Vulnerabilities found
No Misconfigurations found
root/.dotnet/tools/.store/firely.terminal/3.4.0/firely.terminal/3.4.0/tools/net8.0/any/Firely.Terminal.deps.json
No Vulnerabilities found
No Misconfigurations found
| @@ -1,4 +1,4 @@ | |||
| FROM docker.io/library/eclipse-temurin:21-jre-noble@sha256:f338d0c73119b9d54a8e92213c6b9ebf7275e5f76ba8e487f49360edc1b00958 | |||
| FROM docker.io/library/eclipse-temurin:25-jre-noble@sha256:df05e5e48556a59aff4fa62105690f94ce7eccc1d9cf1464b774af4a392a534a | |||
Check notice
Code scanning / KICS (MegaLinter REPOSITORY_KICS)
Healthcheck Instruction Missing Note

This PR contains the following updates:
21-jre-noble->25-jre-nobleConfiguration
📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, on day 1 of the month ( * 0-3 1 * * ) (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.