Skip to content

Fix/image CVE refresh - #744

Merged
wdower merged 7 commits into
masterfrom
fix/image-cve-refresh
Jul 31, 2026
Merged

Fix/image CVE refresh#744
wdower merged 7 commits into
masterfrom
fix/image-cve-refresh

ci: build Ruby from source for lint/backend (ruby-builder lacks 3.4.10)

d219bbb
Select commit
Loading
Failed to load commit list.
SonarQubeCloud / SonarCloud Code Analysis failed Jul 30, 2026 in 1m 24s

Quality Gate failed

Failed conditions
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Annotations

Check warning on line 207 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Prefix files and paths with "./" or "--" when using glob.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-zcaXOpapJ23NeU9Xi&open=AZ-zcaXOpapJ23NeU9Xi&pullRequest=744

Check warning on line 141 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_M&open=AZ-nD54j7Nsapz3kwv_M&pullRequest=744

Check warning on line 145 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Surround this variable with double quotes; otherwise, it can lead to unexpected behavior.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_P&open=AZ-nD54j7Nsapz3kwv_P&pullRequest=744

Check warning on line 161 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_R&open=AZ-nD54j7Nsapz3kwv_R&pullRequest=744

Check warning on line 134 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Surround this variable with double quotes; otherwise, it can lead to unexpected behavior.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_K&open=AZ-nD54j7Nsapz3kwv_K&pullRequest=744

Check warning on line 141 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Surround this variable with double quotes; otherwise, it can lead to unexpected behavior.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_N&open=AZ-nD54j7Nsapz3kwv_N&pullRequest=744

Check warning on line 120 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Replace this invocation of "curl" with the ADD instruction.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_E&open=AZ-nD54j7Nsapz3kwv_E&pullRequest=744

Check warning on line 239 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Dependency versions are not predictable. Use a lock-file enforcing command instead.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_U&open=AZ-nD54j7Nsapz3kwv_U&pullRequest=744

Check warning on line 142 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Replace this invocation of "curl" with the ADD instruction.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_L&open=AZ-nD54j7Nsapz3kwv_L&pullRequest=744

Check warning on line 52 in .github/actions/setup-ruby-source/action.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-zcalHpapJ23NeU9Xj&open=AZ-zcalHpapJ23NeU9Xj&pullRequest=744

Check warning on line 184 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Dependency versions are not predictable. Use a lock-file enforcing command instead.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_S&open=AZ-nD54j7Nsapz3kwv_S&pullRequest=744

Check warning on line 123 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Surround this variable with double quotes; otherwise, it can lead to unexpected behavior.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_I&open=AZ-nD54j7Nsapz3kwv_I&pullRequest=744

Check warning on line 47 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Lifecycle scripts are enabled by default in Yarn v2+.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-zcaXOpapJ23NeU9Xf&open=AZ-zcaXOpapJ23NeU9Xf&pullRequest=744

Check warning on line 120 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Surround this variable with double quotes; otherwise, it can lead to unexpected behavior.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_G&open=AZ-nD54j7Nsapz3kwv_G&pullRequest=744

Check warning on line 155 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Lifecycle scripts are enabled by default in Yarn v2+.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-zcaXOpapJ23NeU9Xh&open=AZ-zcaXOpapJ23NeU9Xh&pullRequest=744

Check warning on line 71 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Lifecycle scripts are enabled by default in Yarn v2+.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-zcaXOpapJ23NeU9Xg&open=AZ-zcaXOpapJ23NeU9Xg&pullRequest=744

Check warning on line 240 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Lifecycle scripts are enabled by default in Yarn v2+.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_V&open=AZ-nD54j7Nsapz3kwv_V&pullRequest=744

Check warning on line 120 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Surround this variable with double quotes; otherwise, it can lead to unexpected behavior.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_H&open=AZ-nD54j7Nsapz3kwv_H&pullRequest=744

Check warning on line 189 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Lifecycle scripts are enabled by default in Yarn v2+.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_T&open=AZ-nD54j7Nsapz3kwv_T&pullRequest=744

Check warning on line 30 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Use either the version tag or the digest for the image instead of both.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_D&open=AZ-nD54j7Nsapz3kwv_D&pullRequest=744

Check warning on line 120 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_F&open=AZ-nD54j7Nsapz3kwv_F&pullRequest=744

Check warning on line 130 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Surround this variable with double quotes; otherwise, it can lead to unexpected behavior.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_J&open=AZ-nD54j7Nsapz3kwv_J&pullRequest=744

Check warning on line 160 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_Q&open=AZ-nD54j7Nsapz3kwv_Q&pullRequest=744

Check warning on line 141 in Dockerfile

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Surround this variable with double quotes; otherwise, it can lead to unexpected behavior.

See more on https://sonarcloud.io/project/issues?id=mitre_vulcan&issues=AZ-nD54j7Nsapz3kwv_O&open=AZ-nD54j7Nsapz3kwv_O&pullRequest=744