Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update docker #2799

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate-bot
Copy link
Contributor

@renovate-bot renovate-bot commented Nov 18, 2024

This PR contains the following updates:

Package Type Update Change Pending
alpine final minor 3.20.3 -> 3.21.2 3.21.3
golang final patch 1.23.4-alpine -> 1.23.5-alpine 1.24.0-alpine (+1)
mcr.microsoft.com/dotnet/aspnet final digest 372b162 -> adc89f8
mcr.microsoft.com/dotnet/runtime-deps final patch 9.0.1-noble-chiseled -> 9.0.2-noble-chiseled
mcr.microsoft.com/dotnet/sdk stage digest 7d24e90 -> 7f8e8b1
mcr.microsoft.com/dotnet/sdk stage patch 9.0.101-noble -> 9.0.200-noble
node stage patch 20.18.1-alpine -> 20.18.2-alpine 20.18.3
python final minor 3.12.8-slim -> 3.13.2-slim
python final minor 3.12.8-alpine -> 3.13.1-alpine 3.13.2-alpine

Release Notes

dotnet/runtime (mcr.microsoft.com/dotnet/runtime-deps)

v9.0.2: .NET 9.0.2

Compare Source

Release

What's Changed

Full Changelog: dotnet/runtime@v9.0.1...v9.0.2

dotnet/sdk (mcr.microsoft.com/dotnet/sdk)

v9.0.200

Compare Source

v9.0.102

nodejs/node (node)

v20.18.2: 2025-01-21, Version 20.18.2 'Iron' (LTS), @​RafaelGSS

Compare Source

This is a security release.

Notable Changes
  • CVE-2025-23083 - throw on InternalWorker use when permission model is enabled (High)
  • CVE-2025-23085 - src: fix HTTP2 mem leak on premature close and ERR_PROTO (Medium)
  • CVE-2025-23084 - path: fix path traversal in normalize() on Windows (Medium)

Dependency update:

  • CVE-2025-22150 - Use of Insufficiently Random Values in undici fetch() (Medium)
Commits

Configuration

📅 Schedule: Branch creation - "* 0-3 * * 1" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot requested review from yoshi-approver and a team as code owners November 18, 2024 00:55
@forking-renovate forking-renovate bot added the dependencies Pull requests that update a dependency file label Nov 18, 2024
@renovate-bot renovate-bot force-pushed the renovate/docker branch 2 times, most recently from 9cdf015 to 85b2aa2 Compare November 18, 2024 17:40
@renovate-bot renovate-bot changed the title chore(deps): update docker chore(deps): update eclipse-temurin docker tag to v21.0.5_11-jre-alpine Nov 19, 2024
@renovate-bot renovate-bot changed the title chore(deps): update eclipse-temurin docker tag to v21.0.5_11-jre-alpine chore(deps): update docker Nov 19, 2024
@renovate-bot renovate-bot force-pushed the renovate/docker branch 6 times, most recently from 5eedeb0 to 715f56e Compare November 26, 2024 19:06
@renovate-bot renovate-bot force-pushed the renovate/docker branch 10 times, most recently from 7203307 to 07a9eb6 Compare December 4, 2024 01:59
@renovate-bot renovate-bot force-pushed the renovate/docker branch 7 times, most recently from 5765b8c to f782086 Compare December 13, 2024 04:52
@renovate-bot renovate-bot force-pushed the renovate/docker branch 10 times, most recently from e331329 to 6def4d5 Compare January 30, 2025 06:47
@renovate-bot renovate-bot force-pushed the renovate/docker branch 7 times, most recently from 4d36d88 to 9050441 Compare February 7, 2025 06:36
@renovate-bot renovate-bot force-pushed the renovate/docker branch 11 times, most recently from 457bf0f to 2f84145 Compare February 14, 2025 04:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant