-
Notifications
You must be signed in to change notification settings - Fork 0
gomodules: bump github.com/go-playground/validator/v10 from 10.23.0 to 10.24.0 #15
base: trunk
Are you sure you want to change the base?
Conversation
Bumps [github.com/go-playground/validator/v10](https://github.com/go-playground/validator) from 10.23.0 to 10.24.0. - [Release notes](https://github.com/go-playground/validator/releases) - [Commits](go-playground/validator@v10.23.0...v10.24.0) --- updated-dependencies: - dependency-name: github.com/go-playground/validator/v10 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
The following labels could not be found: |
| @@ -0,0 +1,9 @@ | |||
| FROM golang:1.17 | |||
Check failure
Code scanning / Trivy
Image user should not be 'root' High library
Type: dockerfile
Vulnerability DS002
Severity: HIGH
Message: Specify at least 1 USER command in Dockerfile with non-root user as argument
Link: DS002
| @@ -0,0 +1,9 @@ | |||
| FROM golang:1.17 | |||
Check notice
Code scanning / Trivy
No HEALTHCHECK defined Low library
Type: dockerfile
Vulnerability DS026
Severity: LOW
Message: Add HEALTHCHECK instruction in your Dockerfile
Link: DS026
| FROM golang:1.17 | ||
|
|
||
| RUN curl -sL https://deb.nodesource.com/setup_17.x | bash | ||
| RUN apt-get install --yes nodejs |
Check failure
Code scanning / Trivy
'apt-get' missing '--no-install-recommends' High library
Type: dockerfile
Vulnerability DS029
Severity: HIGH
Message: '--no-install-recommends' flag is missed: 'apt-get install --yes nodejs'
Link: DS029
| @@ -0,0 +1,6 @@ | |||
| FROM golang:1.17 | |||
Check failure
Code scanning / Trivy
Image user should not be 'root' High library
Type: dockerfile
Vulnerability DS002
Severity: HIGH
Message: Specify at least 1 USER command in Dockerfile with non-root user as argument
Link: DS002
| @@ -0,0 +1,6 @@ | |||
| FROM golang:1.17 | |||
Check notice
Code scanning / Trivy
No HEALTHCHECK defined Low library
Type: dockerfile
Vulnerability DS026
Severity: LOW
Message: Add HEALTHCHECK instruction in your Dockerfile
Link: DS026
| @@ -0,0 +1,23 @@ | |||
| FROM golang:1.20@sha256:2edf6aab2d57644f3fe7407132a0d1770846867465a39c2083770cf62734b05d | |||
Check failure
Code scanning / Trivy
Image user should not be 'root' High library
Type: dockerfile
Vulnerability DS002
Severity: HIGH
Message: Specify at least 1 USER command in Dockerfile with non-root user as argument
Link: DS002
| @@ -0,0 +1,23 @@ | |||
| FROM golang:1.20@sha256:2edf6aab2d57644f3fe7407132a0d1770846867465a39c2083770cf62734b05d | |||
Check notice
Code scanning / Trivy
No HEALTHCHECK defined Low library
Type: dockerfile
Vulnerability DS026
Severity: LOW
Message: Add HEALTHCHECK instruction in your Dockerfile
Link: DS026
| @@ -0,0 +1,23 @@ | |||
| FROM golang:1.20@sha256:2edf6aab2d57644f3fe7407132a0d1770846867465a39c2083770cf62734b05d | |||
Check failure
Code scanning / Trivy
Image user should not be 'root' High library
Type: dockerfile
Vulnerability DS002
Severity: HIGH
Message: Specify at least 1 USER command in Dockerfile with non-root user as argument
Link: DS002
| @@ -0,0 +1,23 @@ | |||
| FROM golang:1.20@sha256:2edf6aab2d57644f3fe7407132a0d1770846867465a39c2083770cf62734b05d | |||
Check notice
Code scanning / Trivy
No HEALTHCHECK defined Low library
Type: dockerfile
Vulnerability DS026
Severity: LOW
Message: Add HEALTHCHECK instruction in your Dockerfile
Link: DS026
Bumps github.com/go-playground/validator/v10 from 10.23.0 to 10.24.0.
Release notes
Sourced from github.com/go-playground/validator/v10's releases.
Commits
2cce309MSGV additions (#1361)6c3307eUpdate README.mdDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)