Skip to content

Update python Docker tag to v3.14.6 - #2

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/python-3.x
Jun 14, 2026
Merged

Update python Docker tag to v3.14.6#2
renovate[bot] merged 1 commit into
mainfrom
renovate/python-3.x

Conversation

@renovate

@renovate renovate Bot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
python patch 3.14.53.14.6

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@github-actions

Copy link
Copy Markdown

Trivy Security Scan

ghcr.io/cluebotng/monitoring-toolforge:5e28c023d9d7140e0cb56d99f5c48520fbb90855 (ubuntu 24.04)

Severity Package Installed Fixed CVE Title
🟠 HIGH libssl3t64 3.0.13-0ubuntu3.9 3.0.13-0ubuntu3.11 CVE-2026-45447 openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
🟠 HIGH openssl 3.0.13-0ubuntu3.9 3.0.13-0ubuntu3.11 CVE-2026-45447 openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()

cnb/lifecycle/launcher

Severity Package Installed Fixed CVE Title
🟠 HIGH stdlib v1.26.0 1.25.8, 1.26.1 CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url
🟠 HIGH stdlib v1.26.0 1.26.1 CVE-2026-27137 crypto/x509: Incorrect enforcement of email constraints in crypto/x509
🟠 HIGH stdlib v1.26.0 1.25.9, 1.26.2 CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
🟠 HIGH stdlib v1.26.0 1.25.9, 1.26.2 CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
🟠 HIGH stdlib v1.26.0 1.25.9, 1.26.2 CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
🟠 HIGH stdlib v1.26.0 1.26.2 CVE-2026-33810 crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-33814 When processing HTTP/2 SETTINGS frames, transport will enter an infini ...
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-39820 Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-39823 CVE-2026-27142 fixed a vulnerability in which URLs were not correctly ...
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-39825 ReverseProxy can forward queries containing parameters not visible to ...
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-39836 ELSA-2026-22112: go-toolset:ol8 security update (IMPORTANT)
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-42499 Pathological inputs could cause DoS through consumePhrase when parsing ...
🟠 HIGH stdlib v1.26.0 1.25.11, 1.26.4 CVE-2026-42504 Decoding a maliciously-crafted MIME header containing many invalid enc ...

layers/sbom/launch/buildpacksio_lifecycle/launcher/sbom.cdx.json

Severity Package Installed Fixed CVE Title
🟠 HIGH stdlib 1.26.0 1.25.8, 1.26.1 CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url
🟠 HIGH stdlib 1.26.0 1.26.1 CVE-2026-27137 crypto/x509: Incorrect enforcement of email constraints in crypto/x509
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
🟠 HIGH stdlib 1.26.0 1.26.2 CVE-2026-33810 crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-33814 When processing HTTP/2 SETTINGS frames, transport will enter an infini ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39820 Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39823 CVE-2026-27142 fixed a vulnerability in which URLs were not correctly ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39825 ReverseProxy can forward queries containing parameters not visible to ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39836 ELSA-2026-22112: go-toolset:ol8 security update (IMPORTANT)
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-42499 Pathological inputs could cause DoS through consumePhrase when parsing ...
🟠 HIGH stdlib 1.26.0 1.25.11, 1.26.4 CVE-2026-42504 Decoding a maliciously-crafted MIME header containing many invalid enc ...

layers/sbom/launch/buildpacksio_lifecycle/launcher/sbom.spdx.json

Severity Package Installed Fixed CVE Title
🟠 HIGH stdlib 1.26.0 1.25.8, 1.26.1 CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url
🟠 HIGH stdlib 1.26.0 1.26.1 CVE-2026-27137 crypto/x509: Incorrect enforcement of email constraints in crypto/x509
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
🟠 HIGH stdlib 1.26.0 1.26.2 CVE-2026-33810 crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-33814 When processing HTTP/2 SETTINGS frames, transport will enter an infini ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39820 Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39823 CVE-2026-27142 fixed a vulnerability in which URLs were not correctly ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39825 ReverseProxy can forward queries containing parameters not visible to ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39836 ELSA-2026-22112: go-toolset:ol8 security update (IMPORTANT)
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-42499 Pathological inputs could cause DoS through consumePhrase when parsing ...
🟠 HIGH stdlib 1.26.0 1.25.11, 1.26.4 CVE-2026-42504 Decoding a maliciously-crafted MIME header containing many invalid enc ...

@renovate
renovate Bot merged commit ab78e4f into main Jun 14, 2026
7 checks passed
@renovate
renovate Bot deleted the renovate/python-3.x branch June 14, 2026 15:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant