Skip to content

chore: bump hoverkraft-tech/docker-base-images/super-linter from 0.4.0 to 0.6.0 in the docker-dependencies group across 1 directory#585

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/docker-dependencies-2fa57057bf
Open

chore: bump hoverkraft-tech/docker-base-images/super-linter from 0.4.0 to 0.6.0 in the docker-dependencies group across 1 directory#585
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/docker-dependencies-2fa57057bf

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the docker-dependencies group with 1 update in the / directory: hoverkraft-tech/docker-base-images/super-linter.

Updates hoverkraft-tech/docker-base-images/super-linter from 0.4.0 to 0.6.0

Release notes

Sourced from hoverkraft-tech/docker-base-images/super-linter's releases.

0.6.0

Release Summary

Added support for build platform configuration. Added Super-linter opinionated image.

Internal documentation, branding assets, workflow documentation, and GitHub Actions dependencies were updated.

Breaking change(s)

There is no breaking change.

What's Changed

Full Changelog: hoverkraft-tech/docker-base-images@0.5.2...0.6.0

Version argocd-cmp-hk-deployment - 0.6.0

What's Changed

Version codespace-like - 0.6.0

What's Changed

Version codespace-like - 0.5.3

What's Changed

0.5.2

Release Summary

This release contains documentation updates for actions and workflows.

It also includes internal dependency maintenance for GitHub Actions dependencies.

Breaking change(s)

There is no breaking change.

... (truncated)

Commits
  • 75c563e build(deps): bump the github-actions-dependencies group across 3 directories ...
  • d8f78cf feat(super-linter): add opinionated super-linter image
  • fd55207 docs: update actions and workflows documentation
  • 2ec582d docs: add branding assets
  • ac4733a docs: update actions and workflows documentation
  • d57fd51 feat: support support build platform configuration
  • 30a8796 docs: update actions and workflows documentation
  • e9b7590 build(deps): bump the github-actions-dependencies group across 1 directory wi...
  • 22a1f45 docs: update actions and workflows documentation
  • 45f538e docs: update actions and workflows documentation
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file docker Pull requests that update Docker code labels Jul 10, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Hi, thank you for creating your PR, we will check it out very soon

@github-actions

Copy link
Copy Markdown
Contributor

Super-linter summary

Language Validation result
BIOME_FORMAT Pass ✅
BIOME_LINT Pass ✅
CHECKOV Pass ✅
DOCKERFILE_HADOLINT Pass ✅
GITLEAKS Pass ✅
GIT_MERGE_CONFLICT_MARKERS Pass ✅
JSCPD Pass ✅
PRE_COMMIT Pass ✅
SPELL_CODESPELL Pass ✅
TRIVY Pass ✅

All files and directories linted successfully

For more information, see the GitHub Actions workflow run

Powered by Super-linter

Bumps the docker-dependencies group with 1 update in the / directory: [hoverkraft-tech/docker-base-images/super-linter](https://github.com/hoverkraft-tech/docker-base-images).


Updates `hoverkraft-tech/docker-base-images/super-linter` from 0.4.0 to 0.6.0
- [Release notes](https://github.com/hoverkraft-tech/docker-base-images/releases)
- [Commits](hoverkraft-tech/docker-base-images@0.4.0...0.6.0)

---
updated-dependencies:
- dependency-name: hoverkraft-tech/docker-base-images/super-linter
  dependency-version: 0.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: docker-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore: bump hoverkraft-tech/docker-base-images/super-linter from 0.4.0 to 0.6.0 in the docker-dependencies group chore: bump hoverkraft-tech/docker-base-images/super-linter from 0.4.0 to 0.6.0 in the docker-dependencies group across 1 directory Jul 24, 2026
@dependabot
dependabot Bot force-pushed the dependabot/docker/docker-dependencies-2fa57057bf branch from aaeb149 to 8a3a021 Compare July 24, 2026 04:04
@github-actions

Copy link
Copy Markdown
Contributor

Super-linter summary

Language Validation result
BIOME_FORMAT Pass ✅
BIOME_LINT Pass ✅
CHECKOV Pass ✅
DOCKERFILE_HADOLINT Pass ✅
GITLEAKS Pass ✅
GIT_MERGE_CONFLICT_MARKERS Pass ✅
JSCPD Pass ✅
PRE_COMMIT Pass ✅
SPELL_CODESPELL Pass ✅
TRIVY Fail ❌

Super-linter detected linting errors

For more information, see the GitHub Actions workflow run

Powered by Super-linter

TRIVY

Report Summary

┌────────────────────────────────────────────┬────────────┬─────────────────┬───────────────────┬─────────┐
│                   Target                   │    Type    │ Vulnerabilities │ Misconfigurations │ Secrets │
├────────────────────────────────────────────┼────────────┼─────────────────┼───────────────────┼─────────┤
│ actions/parse-ci-reports/package-lock.json │    npm     │        1        │         -         │    -    │
├────────────────────────────────────────────┼────────────┼─────────────────┼───────────────────┼─────────┤
│ Dockerfile                                 │ dockerfile │        -        │         0         │    -    │
└────────────────────────────────────────────┴────────────┴─────────────────┴───────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement.
VEX allows you to communicate the actual status of vulnerabilities in your project, improving security transparency and reducing false positives for your users.
Learn more and start using VEX: https://trivy.dev/docs/v0.69/guide/supply-chain/vex/repo#publishing-vex-documents

To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable.


actions/parse-ci-reports/package-lock.json (npm)
================================================
Total: 1 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 1, CRITICAL: 0)

┌─────────────────┬─────────────────────┬──────────┬────────┬───────────────────┬───────────────┬─────────────────────────────────────────────────────────────┐
│     Library     │    Vulnerability    │ Severity │ Status │ Installed Version │ Fixed Version │                            Title                            │
├─────────────────┼─────────────────────┼──────────┼────────┼───────────────────┼───────────────┼─────────────────────────────────────────────────────────────┤
│ fast-xml-parser │ GHSA-8r6m-32jq-jx6q │ HIGH     │ fixed  │ 5.10.0            │ 5.10.1        │ fast-xml-parser: Repeated DOCTYPE declarations reset entity │
│                 │                     │          │        │                   │               │ expansion limits                                            │
│                 │                     │          │        │                   │               │ https://github.com/advisories/GHSA-8r6m-32jq-jx6q           │
└─────────────────┴─────────────────────┴──────────┴────────┴───────────────────┴───────────────┴─────────────────────────────────────────────────────────────┘

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update Docker code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants