Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 28, 2025

Bumps docker/scout-action from 1.18.1 to 1.18.2.

Release notes

Sourced from docker/scout-action's releases.

v1.18.2

What's Changed

  • Minor fixes for DHI by @​cdupuis
  • Add --skip-tlog for docker scout attest get to skip signature verification against the transparency log by @​cdupuis
  • Do not filter CVEs that are marked with a VEX under_investigation statement by @​cdupuis
  • Add predicate type human names for DHI FIPS and STIG attestations by @​cdupuis
Commits
  • f8c7768 Merge bcd3bc7c94089eaf72f3f76cfd3168b6953ab52c into aceeb83b88f2ae54376891227...
  • bcd3bc7 [BOT] Publish v1.18.2 release
  • See full diff in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [docker/scout-action](https://github.com/docker/scout-action) from 1.18.1 to 1.18.2.
- [Release notes](https://github.com/docker/scout-action/releases)
- [Commits](docker/scout-action@v1.18.1...v1.18.2)

---
updated-dependencies:
- dependency-name: docker/scout-action
  dependency-version: 1.18.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 28, 2025
@github-actions
Copy link

🔍 Vulnerabilities of renzof93/generate-api-key:latest

📦 Image Reference renzof93/generate-api-key:latest
digestsha256:5e51158c1a2d09d4c9e18f355a00a33406b49e42cbfb2a2f43c201795b908472
vulnerabilitiescritical: 0 high: 0 medium: 0 low: 0
platformlinux/amd64
size25 MB
packages36
📦 Base Image python:3-alpine3.20
also known as
  • 3.13-alpine3.20
  • 3.13.3-alpine3.20
  • alpine3.20
digestsha256:68834522e73344a5337150a62e87a75be9046c0e39b9bab925be078d953e54e1
vulnerabilitiescritical: 0 high: 0 medium: 0 low: 0

@github-actions
Copy link

Recommended fixes for image renzof93/generate-api-key:latest

Base image is python:3-alpine3.20

Name3.13.3-alpine3.20
Digestsha256:68834522e73344a5337150a62e87a75be9046c0e39b9bab925be078d953e54e1
Vulnerabilitiescritical: 0 high: 0 medium: 0 low: 0
Pushed2 months ago
Size16 MB
Packages41
Flavoralpine
OS3.20
Runtime3.13.3

Refresh base image

Rebuild the image using a newer base image version. Updating this may result in breaking changes.

✅ This image version is up to date.

Change base image

TagDetailsPushedVulnerabilities
3-alpine
Tag is preferred tag
Also known as:
  • alpine
  • alpine3.22
  • 3.13.5-alpine
  • 3.13.5-alpine3.22
  • 3.13-alpine
  • 3.13-alpine3.22
  • 3-alpine3.22
Benefits:
  • Same OS detected
  • Minor runtime version update
  • Minor OS version update
  • Image contains 2 fewer packages
  • Tag is preferred tag
  • Tag was pushed more recently
  • Image has similar size
  • Image has same number of vulnerabilities
  • 3-alpine was pulled 51K times last month
Image details:
  • Size: 17 MB
  • Flavor: alpine
  • OS: 3.22
  • Runtime: 3.13.5
1 month ago



3-alpine3.21
Minor runtime version update
Also known as:
  • alpine3.21
  • 3.13.5-alpine3.21
  • 3.13-alpine3.21
Benefits:
  • Same OS detected
  • Minor runtime version update
  • Minor OS version update
  • Image contains 3 fewer packages
  • Tag was pushed more recently
  • Image has similar size
  • Image has same number of vulnerabilities
Image details:
  • Size: 17 MB
  • Flavor: alpine
  • OS: 3.21
  • Runtime: 3.13.5
1 month ago



@github-actions
Copy link

Overview

Image reference renzof93/generate-api-key:latest renzof93/generate-api-key:latest
- digest 3cdd31665c39 5e51158c1a2d
- tag latest latest
- stream latest
- vulnerabilities critical: 0 high: 0 medium: 0 low: 0 critical: 0 high: 0 medium: 0 low: 0
- platform linux/amd64 linux/amd64
- size 22 MB 25 MB (+2.6 MB)
- packages 36 36
Base Image python:3-alpine3.20 python:3-alpine3.20
- vulnerabilities critical: 0 high: 0 medium: 0 low: 0 critical: 0 high: 0 medium: 0 low: 0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants