Dependency Dashboard

Open
#23 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
25/100
Issue type
Refactor
Clarity
Needs clarification
Activity status
Stale
Tech stack
docker, github-actions, node.js, python

Research direction

Read the linked Dependency Dashboard documentation first, then inspect renovate.json and the listed dependency files: docker-audit-cli/Dockerfile, .github/workflows/*.yml, package.json, pyproject.toml, .pre-commit-config.yaml, and .python-version. Done would require resolving the repository warnings and handling the pending updates shown by the dashboard.

Written by the indexing model from the issue text.

Description

This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.

Repository Problems

Renovate tried to run on this repository, but found these problems.

  • ⚠️ WARN: Fallback to renovate.json file as a preset is deprecated, please use a default.json file instead.
  • ⚠️ WARN: Cannot access vulnerability alerts. Please ensure permissions have been granted.

Awaiting Schedule

The following updates are awaiting their schedule. To get an update now, click on a checkbox below.

  • chore(deps): pin dependencies
  • fix(deps): update renovate: pre-commit (astral-sh/ruff-pre-commit, astral-sh/uv-pre-commit)
  • feat(deps): update actions/setup-node action to v6.4.0
  • chore(deps): lock file maintenance
  • 🔐 Create all awaiting schedule PRs at once 🔐

Pending Status Checks

The following updates await pending status checks. To force their creation now, click on a checkbox below.

  • feat(deps): update actions/checkout action to v7
  • feat(deps): update pre-commit hook ministryofjustice/devsecops-hooks to v2

Detected Dependencies

dockerfile (1)
docker-audit-cli/Dockerfile (1)
  • python 3.14-slim@sha256:a01e48f10f90ac3ee65ef6937b9d7c831a3570c81b98d39a547ff09fb359de7f → [Updates: 3.14-slim]
github-actions (5)
.github/workflows/dependency-review.yml (2)
  • actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10 → [Updates: v7.0.0]
  • actions/dependency-review-action v5.0.0@a1d282b36b6f3519aa1f3fc636f609c47dddb294
.github/workflows/lint.yml (4)
  • actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10 → [Updates: v7.0.0]
  • actions/setup-node v6.4.0@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39
  • node ${{ vars.NODE_VERSION }}
.github/workflows/pytest.yml (2)
  • actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10 → [Updates: v7.0.0]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39
.github/workflows/release-please.yml (1)
  • googleapis/release-please-action v5.0.0@45996ed1f6d02564a971a2fa1b5860e934307cf7
.github/workflows/sca.yaml (4)
  • actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10 → [Updates: v7.0.0]
  • actions/setup-node v6.1.0@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e → [Updates: v6.4.0, v6.1.0]
  • ministryofjustice/devsecops-actions v1.6.0@7dc13c20e2bf541b8a77fa1320a04983b18846f6
  • node ${{ vars.NODE_VERSION }}
npm (1)
package.json (3)
  • cspell ^10.0.1
  • markdownlint-cli2 ^0.22.1
  • node >=18.0.0
pep621 (1)
pyproject.toml (11)
  • python >=3.14
  • cryptography >=46.0.6
  • dash >=2.0.0
  • openpyxl >=3.0.0
  • pandas >=1.3.0
  • pydantic >=2.0
  • pyjwt >=2.12.1
  • pyyaml >=6.0
  • requests >=2.28.0
  • pytest >=9.0.2
  • ruff >=0.15.8
pre-commit (1)
.pre-commit-config.yaml (3)
  • ministryofjustice/devsecops-hooks v1.6.0 → [Updates: v2.0.1]
  • astral-sh/ruff-pre-commit v0.15.12 → [Updates: v0.15.18]
  • astral-sh/uv-pre-commit 0.11.8 → [Updates: 0.11.21]
pyenv (1)
.python-version (1)
  • python 3.14 → [Updates: 3.14]
renovate-config-presets (1)
renovate.json
Dominant language
Python
Stars
2
Forks
2
Avg merge
10d 5h
Merged PRs (30d)
2

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from ministryofjustice/developer-experience-github-audit

All issues in ministryofjustice/developer-experience-github-audit

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.