Skip to content

Commit b24a858

Browse files
committed
Merge remote-tracking branch 'origin/main' into dependabot/npm_and_yarn/devcontainers/cli-0.86.0
2 parents b0bb2d8 + 2252b30 commit b24a858

7 files changed

Lines changed: 63 additions & 16 deletions

File tree

.github/workflows/ci.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,15 +6,15 @@ permissions: {}
66

77
jobs:
88
get_config_values:
9-
uses: NHSDigital/eps-common-workflows/.github/workflows/get-repo-config.yml@8b259f4f2d2b8ff1345fb0d2f9b9f0fbb9d19845
9+
uses: NHSDigital/eps-common-workflows/.github/workflows/get-repo-config.yml@c4efd04c5ff1c7e92e7fe5932b29d0de1a301cdf
1010
with:
1111
verify_published_from_main_image: true
1212
permissions:
1313
attestations: read
1414
contents: read
1515
packages: read
1616
quality_checks:
17-
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks-devcontainer.yml@8b259f4f2d2b8ff1345fb0d2f9b9f0fbb9d19845
17+
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks-devcontainer.yml@c4efd04c5ff1c7e92e7fe5932b29d0de1a301cdf
1818
needs:
1919
- get_config_values
2020
permissions:
@@ -27,7 +27,7 @@ jobs:
2727
SONAR_TOKEN: '${{ secrets.SONAR_TOKEN }}'
2828
tag_release:
2929
needs: [quality_checks, get_config_values]
30-
uses: NHSDigital/eps-common-workflows/.github/workflows/tag-release-devcontainer.yml@8b259f4f2d2b8ff1345fb0d2f9b9f0fbb9d19845
30+
uses: NHSDigital/eps-common-workflows/.github/workflows/tag-release-devcontainer.yml@c4efd04c5ff1c7e92e7fe5932b29d0de1a301cdf
3131
permissions:
3232
id-token: write
3333
contents: write

.github/workflows/pull_request.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,15 +6,15 @@ name: pull_request
66
permissions: {}
77
jobs:
88
get_config_values:
9-
uses: NHSDigital/eps-common-workflows/.github/workflows/get-repo-config.yml@8b259f4f2d2b8ff1345fb0d2f9b9f0fbb9d19845
9+
uses: NHSDigital/eps-common-workflows/.github/workflows/get-repo-config.yml@c4efd04c5ff1c7e92e7fe5932b29d0de1a301cdf
1010
with:
1111
verify_published_from_main_image: false
1212
permissions:
1313
attestations: read
1414
contents: read
1515
packages: read
1616
quality_checks:
17-
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks-devcontainer.yml@8b259f4f2d2b8ff1345fb0d2f9b9f0fbb9d19845
17+
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks-devcontainer.yml@c4efd04c5ff1c7e92e7fe5932b29d0de1a301cdf
1818
needs:
1919
- get_config_values
2020
with:
@@ -26,7 +26,7 @@ jobs:
2626
secrets:
2727
SONAR_TOKEN: '${{ secrets.SONAR_TOKEN }}'
2828
pr_title_format_check:
29-
uses: NHSDigital/eps-common-workflows/.github/workflows/pr_title_check.yml@8b259f4f2d2b8ff1345fb0d2f9b9f0fbb9d19845
29+
uses: NHSDigital/eps-common-workflows/.github/workflows/pr_title_check.yml@c4efd04c5ff1c7e92e7fe5932b29d0de1a301cdf
3030
permissions:
3131
pull-requests: write
3232
get_issue_number:

.github/workflows/release.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7,15 +7,15 @@ permissions: {}
77

88
jobs:
99
get_config_values:
10-
uses: NHSDigital/eps-common-workflows/.github/workflows/get-repo-config.yml@8b259f4f2d2b8ff1345fb0d2f9b9f0fbb9d19845
10+
uses: NHSDigital/eps-common-workflows/.github/workflows/get-repo-config.yml@c4efd04c5ff1c7e92e7fe5932b29d0de1a301cdf
1111
with:
1212
verify_published_from_main_image: false
1313
permissions:
1414
attestations: read
1515
contents: read
1616
packages: read
1717
quality_checks:
18-
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks-devcontainer.yml@8b259f4f2d2b8ff1345fb0d2f9b9f0fbb9d19845
18+
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks-devcontainer.yml@c4efd04c5ff1c7e92e7fe5932b29d0de1a301cdf
1919
needs:
2020
- get_config_values
2121
permissions:
@@ -28,7 +28,7 @@ jobs:
2828
SONAR_TOKEN: '${{ secrets.SONAR_TOKEN }}'
2929
tag_release:
3030
needs: [quality_checks, get_config_values]
31-
uses: NHSDigital/eps-common-workflows/.github/workflows/tag-release-devcontainer.yml@8b259f4f2d2b8ff1345fb0d2f9b9f0fbb9d19845
31+
uses: NHSDigital/eps-common-workflows/.github/workflows/tag-release-devcontainer.yml@c4efd04c5ff1c7e92e7fe5932b29d0de1a301cdf
3232
permissions:
3333
id-token: write
3434
contents: write

.github/workflows/sync_copilot.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ jobs:
1414

1515
steps:
1616
- name: Sync shared instructions
17-
uses: NHSDigital/eps-copilot-instructions@8b4d7f546fe9825a149cb8cc8cfdb31df58c3730
17+
uses: NHSDigital/eps-copilot-instructions@f8e24afb5384bdd51b0daff4b1ebe57916995345
1818
with:
1919
copilot_instructions_ref: main
2020
calling_repo_base_branch: main

.grype.yaml

Lines changed: 48 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,15 @@ ignore:
3838
- vulnerability: CVE-2026-6100
3939
- vulnerability: CVE-2026-4786
4040
- vulnerability: GHSA-pc3f-x583-g7j2
41+
- vulnerability: CVE-2026-3298
42+
- vulnerability: GHSA-q339-8rmv-2mhv
43+
package:
44+
name: erb
45+
version: 4.0.3
46+
- vulnerability: GHSA-mh2q-q3fh-2475
47+
package:
48+
name: go.opentelemetry.io/otel
49+
version: v1.40.0
4150
# node_24 vulnerabilities
4251
- vulnerability: GHSA-c2c7-rcm5-vvqj
4352
- vulnerability: GHSA-7r86-cg39-jmmj
@@ -53,8 +62,24 @@ ignore:
5362
- vulnerability: GHSA-2599-h6xx-hpxp
5463
# eps-storage-terraform vulnerabilities
5564
- vulnerability: CVE-2025-68119
65+
- vulnerability: GHSA-mh2q-q3fh-2475
66+
package:
67+
name: go.opentelemetry.io/otel
68+
version: v1.38.0
69+
- vulnerability: GHSA-mh2q-q3fh-2475
70+
package:
71+
name: go.opentelemetry.io/otel
72+
version: v1.39.0
5673
# eps-data-extract vulnerabilities
5774
- vulnerability: GHSA-6fmv-xxpf-w3cw
75+
- vulnerability: CVE-2026-34282
76+
package:
77+
name: openjdk
78+
version: 17.0.18+8
79+
- vulnerability: CVE-2026-22016
80+
package:
81+
name: openjdk
82+
version: 17.0.18+8
5883
# fhir-facade vulnerabilities
5984
- vulnerability: CVE-2022-26485
6085
- vulnerability: CVE-2022-26486
@@ -70,6 +95,21 @@ ignore:
7095
- vulnerability: CVE-2025-53066
7196
- vulnerability: CVE-2026-21945
7297
- vulnerability: CVE-2026-21932
98+
package:
99+
name: openjdk
100+
version: 20.0.2+9-78
101+
- vulnerability: CVE-2026-22016
102+
package:
103+
name: openjdk
104+
version: 20.0.2+9-78
105+
- vulnerability: CVE-2026-34282
106+
package:
107+
name: jdk
108+
version: 20.0.2+9-78
109+
- vulnerability: CVE-2026-22016
110+
package:
111+
name: jdk
112+
version: 20.0.2+9-78
73113
# node-24_python_3_14_java_24 vulnerabilities
74114
- vulnerability: GHSA-6fmv-xxpf-w3cw
75115
- vulnerability: CVE-2025-53066
@@ -78,4 +118,11 @@ ignore:
78118
- vulnerability: CVE-2026-27143
79119
- vulnerability: CVE-2026-27144
80120
- vulnerability: CVE-2026-3298
81-
121+
- vulnerability: CVE-2026-34282
122+
package:
123+
name: openjdk
124+
version: 24.0.2+12
125+
- vulnerability: CVE-2026-22016
126+
package:
127+
name: openjdk
128+
version: 24.0.2+12

poetry.lock

Lines changed: 4 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

pyproject.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,4 +21,4 @@ python = "^3.12"
2121
[tool.poetry.scripts]
2222

2323
[tool.poetry.group.dev.dependencies]
24-
pre-commit = "^4.5.1"
24+
pre-commit = "^4.6.0"

0 commit comments

Comments
 (0)