Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Nov 25, 2025

This PR contains the following updates:

Package Type Update Change
mikefarah/yq action patch v4.49.1 -> v4.49.2

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

mikefarah/yq (mikefarah/yq)

v4.49.2

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@gitnotebooks
Copy link

gitnotebooks bot commented Nov 25, 2025

@coderabbitai
Copy link
Contributor

coderabbitai bot commented Nov 25, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

@deepsource-io
Copy link
Contributor

deepsource-io bot commented Nov 25, 2025

Here's the code health analysis summary for commits 23ae806..188c0e1. View details on DeepSource ↗.

Analysis Summary

AnalyzerStatusSummaryLink
DeepSource Python LogoPython✅ SuccessView Check ↗
DeepSource Docker LogoDocker✅ SuccessView Check ↗
DeepSource Secrets LogoSecrets✅ SuccessView Check ↗

💡 If you’re a repository administrator, you can configure the quality gates from the settings.

@mergify
Copy link
Contributor

mergify bot commented Nov 25, 2025

🧪 CI Insights

Here's what we observed from your CI run for 188c0e1.

🟢 All jobs passed!

But CI Insights is watching 👀

@MH0386
Copy link
Contributor

MH0386 commented Nov 25, 2025

🔍 Vulnerabilities of ghcr.io/alphaspheredotai/vocalizr:802d12d-pr-990

📦 Image Reference ghcr.io/alphaspheredotai/vocalizr:802d12d-pr-990
digestsha256:294cc3642eaad8cc1f1cdcd1db3dbab73d612466e7bcbc84a2381a01aeff94f1
vulnerabilitiescritical: 0 high: 1 medium: 0 low: 0
platformlinux/amd64
size4.3 GB
packages251
critical: 0 high: 1 medium: 0 low: 0 gradio 6.1.0 (pypi)

pkg:pypi/[email protected]

# Dockerfile (28:28)
COPY --from=builder --chown=nonroot:nonroot --chmod=755 /home/nonroot/.local/ /home/nonroot/.local/

high 8.1: CVE--2023--6572 OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities

Affected range<2023-11-06
Fixed versionNot Fixed
CVSS Score8.1
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score1.662%
EPSS Percentile82nd percentile
Description

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository gradio-app/gradio prior to main.

@sonarqubecloud
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants