Skip to content

chore(deps): update python:3.14-alpine3.23 docker digest to e7cff36 - #18

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major-docker-dependencies
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major-docker-dependencies

Conversation

@renovate

@renovate renovate Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change
python (source) final digest 02da11a → e7cff36
python (source) stage digest 02da11a → e7cff36

Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • "before 4am every weekday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Aug 5, 2026
@github-actions

github-actions Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

Vulnerability Scan: Failed — blocking vulnerabilities detected

Image: netbox-mcp-server:scan

Source Library CVE Severity Installed Fixed Title
Python PyJWT CVE-2026-102268 🔴 CRITICAL 2.13.0 2.14.0 PyJWT is a Python implementation of JSON Web Token standards. Prior to ...
Python PyJWT CVE-2026-102266 🟠 HIGH 2.13.0 2.14.0 pyjwt: pyjwt: Authentication bypass via empty HMAC key acceptance
Python PyJWT CVE-2026-102267 🟠 HIGH 2.13.0 2.14.0 pyjwt: pyjwt: Verification key substitution via unvalidated JWKS redirects
Python PyJWT CVE-2026-102271 🟠 HIGH 2.13.0 2.14.0 pyjwt: PyJWT: Authentication bypass via acceptance of DER public keys as HMAC se
Python PyJWT CVE-2026-102272 🟠 HIGH 2.13.0 2.14.0 pyjwt: pyjwt: Token forgery via improper Unicode byte-order mark handling
Python PyJWT CVE-2026-102273 🟠 HIGH 2.13.0 2.14.0 pyjwt: pyjwt: Token forgery via acceptance of public JWK containers as HMAC secr
Python PyJWT CVE-2026-101917 🟡 MEDIUM 2.13.0 2.14.0 pyjwt: PyJWT: Denial of Service via outbound request amplification on unknown ke
Python PyJWT CVE-2026-101918 🟡 MEDIUM 2.13.0 2.15.0 pyjwt: PyJWT: Denial of Service via deeply nested JSON token payload
Python PyJWT CVE-2026-102265 🟡 MEDIUM 2.13.0 2.14.0 pyjwt: pyjwt: Denial of Service via deeply nested token headers
Python PyJWT CVE-2026-102269 🟡 MEDIUM 2.13.0 2.14.0 pyjwt: PyJWT: Token revocation bypass via non-canonical signature decoding
Python PyJWT CVE-2026-102270 🟡 MEDIUM 2.13.0 2.14.0 pyjwt: pyjwt: Denial of Service via regular expression backtracking in is_pem_fo
Python PyJWT CVE-2026-102274 🟡 MEDIUM 2.13.0 2.14.0 pyjwt: pyjwt: Denial of Service via malformed RSA key in JWK set
Python anyio CVE-2026-63374 🔴 CRITICAL 4.12.1 4.14.2 anyio: AnyIO: TLS certificate spoofing via improper internationalized domain nam
Python anyio CVE-2026-64847 🟡 MEDIUM 4.12.1 4.14.2 anyio: AnyIO: Denial of Service due to undrained stderr in process-pool workers
Python cryptography CVE-2026-69247 🟠 HIGH 49.0.0 50.0.0 python-cryptography: python-cryptography: PKCS#7 EnvelopedData decryption expose
Python msgpack GHSA-6v7p-g79w-8964 🟠 HIGH 1.1.2 1.2.1 MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a cau
Python setuptools CVE-2025-47273 🟠 HIGH 70.3.0 78.1.1 setuptools: Path Traversal Vulnerability in setuptools PackageIndex
Python setuptools CVE-2026-59890 🟡 MEDIUM 70.3.0 83.0.0 setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normal
Python urllib3 CVE-2026-97687 🟠 HIGH 2.7.0 2.8.0 urllib3: urllib3: Traffic interception via HTTPS proxy TLS configuration overrid
Python urllib3 CVE-2026-97689 🟠 HIGH 2.7.0 2.8.0 urllib3: urllib3: Denial of Service via unbounded memory allocation in chunk par
Python urllib3 CVE-2026-97688 🟡 MEDIUM 2.7.0 2.8.0 urllib3: urllib3: Denial of Service via infinite loop during chunked Deflate dec

Commit: 8e053be

@renovate renovate Bot changed the title chore(deps): update python:3.14-alpine3.23 docker digest to b165067 chore(deps): update python:3.14-alpine3.23 docker digest to f06b985 Aug 7, 2026
@renovate
renovate Bot force-pushed the renovate/non-major-docker-dependencies branch from 52abbbb to 881a6d7 Compare August 7, 2026 19:53
@renovate renovate Bot changed the title chore(deps): update python:3.14-alpine3.23 docker digest to f06b985 chore(deps): update python:3.14-alpine3.23 docker digest to 6b8f06d Aug 15, 2026
@renovate
renovate Bot force-pushed the renovate/non-major-docker-dependencies branch from 881a6d7 to fac2f14 Compare August 15, 2026 11:42
@renovate renovate Bot changed the title chore(deps): update python:3.14-alpine3.23 docker digest to 6b8f06d chore(deps): update python:3.14-alpine3.23 docker digest to 8caa2ad Sep 5, 2026
@renovate
renovate Bot force-pushed the renovate/non-major-docker-dependencies branch from fac2f14 to d5b24d0 Compare September 5, 2026 03:44
@renovate renovate Bot changed the title chore(deps): update python:3.14-alpine3.23 docker digest to 8caa2ad chore(deps): update python:3.14-alpine3.23 docker digest to 200baf0 Sep 20, 2026
@renovate
renovate Bot force-pushed the renovate/non-major-docker-dependencies branch from d5b24d0 to 08b63d8 Compare September 20, 2026 02:55
@renovate renovate Bot changed the title chore(deps): update python:3.14-alpine3.23 docker digest to 200baf0 chore(deps): update python:3.14-alpine3.23 docker digest to f484505 Oct 2, 2026
@renovate
renovate Bot force-pushed the renovate/non-major-docker-dependencies branch from 08b63d8 to a2b08d3 Compare October 2, 2026 04:10
@renovate renovate Bot changed the title chore(deps): update python:3.14-alpine3.23 docker digest to f484505 chore(deps): update python:3.14-alpine3.23 docker digest to e7cff36 Oct 4, 2026
@renovate
renovate Bot force-pushed the renovate/non-major-docker-dependencies branch from a2b08d3 to a8a22f7 Compare October 4, 2026 11:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants