Skip to content

Conversation

@org-internal-bot
Copy link
Contributor

This PR contains the following updates:

Package Type Update Change
testcontainers dev-dependencies minor 0.25 -> 0.26

Release Notes

testcontainers/testcontainers-rs (testcontainers)

v0.26.0

Compare Source

Details
Bug Fixes
  • Make port_bindings consistent with docker cli when publish_all_ports = true (#​885)
Features
  • Support build options - no_cache, skip_if_exists and buildargs (#​856)
  • Support docker-compose (#​864)
  • Add target options with custom mode (#​878)
  • Support copying from containers (#​871)
Miscellaneous Tasks
  • Use bollard 0.19.4 (#​870)
  • Update etcetera requirement from 0.10.0 to 0.11.0 (#​869)
Performance
  • Replace ulid with ferroid's ULID for better performance (#​829)
  • Update ferroid for better performance during encode/decode (#​879)

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@org-internal-bot org-internal-bot bot requested a review from davidB December 2, 2025 04:54
@org-internal-bot
Copy link
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: Cargo.lock
Command failed: cargo update --config net.git-fetch-with-cli=true --manifest-path Cargo.toml --package [email protected] --precise 0.26.0
    Updating crates.io index
error: failed to select a version for the requirement `testcontainers = "^0.25"`
candidate versions found which didn't match: 0.26.0
location searched: crates.io index
required by package `testcontainers-redpanda-rs v0.12.0`
    ... which satisfies dependency `testcontainers-redpanda-rs = "^0.12"` of package `cdviz-collector v0.19.4 (/tmp/renovate/repos/github/cdviz-dev/cdviz-collector)`
    ... which satisfies path dependency `cdviz-collector` (locked to 0.19.4) of package `cdviz-collector-testkit v0.0.0 (/tmp/renovate/repos/github/cdviz-dev/cdviz-collector/testkit)`

@github-actions
Copy link
Contributor

github-actions bot commented Dec 2, 2025

⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ REPOSITORY gitleaks yes no no 8.15s
⚠️ REPOSITORY trivy yes 1 no 9.12s
✅ REPOSITORY trivy-sbom yes no no 10.53s

Detailed Issues

⚠️ REPOSITORY / trivy - 1 error
2025-12-02T04:55:06Z	INFO	[vulndb] Need to update DB
2025-12-02T04:55:06Z	INFO	[vulndb] Downloading vulnerability DB...
2025-12-02T04:55:06Z	INFO	[vulndb] Downloading artifact...	repo="mirror.gcr.io/aquasec/trivy-db:2"
1.05 MiB / 76.43 MiB [>______________________________________________________________] 1.37% ? p/s ?27.36 MiB / 76.43 MiB [--------------------->_______________________________________] 35.80% ? p/s ?57.96 MiB / 76.43 MiB [---------------------------------------------->______________] 75.83% ? p/s ?76.43 MiB / 76.43 MiB [--------------------------------------------->] 100.00% 125.38 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [--------------------------------------------->] 100.00% 125.38 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [--------------------------------------------->] 100.00% 125.38 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [--------------------------------------------->] 100.00% 117.29 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [--------------------------------------------->] 100.00% 117.29 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [--------------------------------------------->] 100.00% 117.29 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [--------------------------------------------->] 100.00% 109.72 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [--------------------------------------------->] 100.00% 109.72 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [--------------------------------------------->] 100.00% 109.72 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [--------------------------------------------->] 100.00% 102.64 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [--------------------------------------------->] 100.00% 102.64 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [--------------------------------------------->] 100.00% 102.64 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [---------------------------------------------->] 100.00% 96.02 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [---------------------------------------------->] 100.00% 96.02 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [---------------------------------------------->] 100.00% 96.02 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [---------------------------------------------->] 100.00% 89.83 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [---------------------------------------------->] 100.00% 89.83 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [---------------------------------------------->] 100.00% 89.83 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [---------------------------------------------->] 100.00% 84.03 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [---------------------------------------------->] 100.00% 84.03 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [---------------------------------------------->] 100.00% 84.03 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [---------------------------------------------->] 100.00% 78.61 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [---------------------------------------------->] 100.00% 78.61 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [---------------------------------------------->] 100.00% 78.61 MiB p/s ETA 0s76.43 MiB / 76.43 MiB [-------------------------------------------------] 100.00% 14.22 MiB p/s 5.6s2025-12-02T04:55:12Z	INFO	[vulndb] Artifact successfully downloaded	repo="mirror.gcr.io/aquasec/trivy-db:2"
2025-12-02T04:55:12Z	INFO	[vuln] Vulnerability scanning is enabled
2025-12-02T04:55:12Z	INFO	[misconfig] Misconfiguration scanning is enabled
2025-12-02T04:55:12Z	INFO	[misconfig] Need to update the checks bundle
2025-12-02T04:55:12Z	INFO	[misconfig] Downloading the checks bundle...
165.46 KiB / 165.46 KiB [------------------------------------------------------] 100.00% ? p/s 100ms2025-12-02T04:55:15Z	INFO	Number of language-specific files	num=1
2025-12-02T04:55:15Z	INFO	[cargo] Detecting vulnerabilities...
2025-12-02T04:55:15Z	INFO	Detected config files	num=1

Report Summary

┌────────────┬────────────┬─────────────────┬───────────────────┐
│   Target   │    Type    │ Vulnerabilities │ Misconfigurations │
├────────────┼────────────┼─────────────────┼───────────────────┤
│ Cargo.lock │   cargo    │        0        │         -         │
├────────────┼────────────┼─────────────────┼───────────────────┤
│ Dockerfile │ dockerfile │        -        │         1         │
└────────────┴────────────┴─────────────────┴───────────────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


Dockerfile (dockerfile)
=======================
Tests: 27 (SUCCESSES: 26, FAILURES: 1)
Failures: 1 (UNKNOWN: 0, LOW: 0, MEDIUM: 1, HIGH: 0, CRITICAL: 0)

AVD-DS-0001 (MEDIUM): Specify a tag in the 'FROM' statement for image 'cgr.dev/chainguard/glibc-dynamic'
════════════════════════════════════════
When using a 'FROM' statement you should use a specific tag to avoid uncontrolled behavior when the image is updated.

See https://avd.aquasec.com/misconfig/ds001
────────────────────────────────────────
 Dockerfile:148
────────────────────────────────────────
 148 [ FROM --platform=$BUILDPLATFORM cgr.dev/chainguard/glibc-dynamic:latest AS cdviz-collector
────────────────────────────────────────

See detailed reports in MegaLinter artifacts
Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff

MegaLinter is graciously provided by OX Security

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant