Skip to content

Commit 66933f0

Browse files
Upgrade: [dependabot] - bump NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml from 5.2.9 to 5.2.11 (#391)
Bumps [NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml](https://github.com/nhsdigital/eps-common-workflows) from 5.2.9 to 5.2.11. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/nhsdigital/eps-common-workflows/releases">NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml's releases</a>.</em></p> <blockquote> <h2>v5.2.11</h2> <h2><a href="https://github.com/NHSDigital/eps-common-workflows/compare/v5.2.10...v5.2.11">5.2.11</a> (2026-01-08)</h2> <h3>Fix</h3> <ul> <li>[AEA-6060] - use trivy for sbom and licence scan (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/41">#41</a>) (<a href="https://github.com/NHSDigital/eps-common-workflows/commit/2fe6bc6cd974efb4d55a2a7b665385f7a2d28950">2fe6bc6</a>)</li> </ul> <h2>Info</h2> <p><a href="https://github.com/NHSDigital/eps-common-workflows/compare/343b01abc9a6...2fe6bc6cd974">See code diff</a> <a href="https://github.com/NHSDigital/eps-common-workflows/actions/runs/20815530676">Release workflow run</a> - Workflow ID: 20815530676</p> <p>It was initialized by <a href="https://github.com/MatthewPopat-NHS">MatthewPopat-NHS</a></p> <h2>v5.2.10</h2> <h2><a href="https://github.com/NHSDigital/eps-common-workflows/compare/v5.2.9...v5.2.10">5.2.10</a> (2026-01-07)</h2> <h3>Chore</h3> <ul> <li>[AEA-0000] - update python and node (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/42">#42</a>) (<a href="https://github.com/NHSDigital/eps-common-workflows/commit/343b01abc9a63bfe9c34d1e72ae358ce421aa805">343b01a</a>)</li> </ul> <h2>Info</h2> <p><a href="https://github.com/NHSDigital/eps-common-workflows/compare/2b3ddfd1e59d...343b01abc9a6">See code diff</a> <a href="https://github.com/NHSDigital/eps-common-workflows/actions/runs/20791091362">Release workflow run</a> - Workflow ID: 20791091362</p> <p>It was initialized by <a href="https://github.com/anthony-nhs">anthony-nhs</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/NHSDigital/eps-common-workflows/commit/2fe6bc6cd974efb4d55a2a7b665385f7a2d28950"><code>2fe6bc6</code></a> Fix: [AEA-6060] - use trivy for sbom and licence scan (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/41">#41</a>)</li> <li><a href="https://github.com/NHSDigital/eps-common-workflows/commit/343b01abc9a63bfe9c34d1e72ae358ce421aa805"><code>343b01a</code></a> Chore: [AEA-0000] - update python and node (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/42">#42</a>)</li> <li>See full diff in <a href="https://github.com/nhsdigital/eps-common-workflows/compare/2b3ddfd1e59daf9905522d0140c6cd08e2547432...2fe6bc6cd974efb4d55a2a7b665385f7a2d28950">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml&package-manager=github_actions&previous-version=5.2.9&new-version=5.2.11)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Anthony Brown <anthony.brown8@nhs.net>
1 parent eadadcb commit 66933f0

File tree

11 files changed

+29
-242
lines changed

11 files changed

+29
-242
lines changed

.github/workflows/ci.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ jobs:
2626
TAG_FORMAT=$(yq '.TAG_FORMAT' .github/config/settings.yml)
2727
echo "TAG_FORMAT=$TAG_FORMAT" >> "$GITHUB_OUTPUT"
2828
quality_checks:
29-
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2b3ddfd1e59daf9905522d0140c6cd08e2547432
29+
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2fe6bc6cd974efb4d55a2a7b665385f7a2d28950
3030
needs: [get_asdf_version]
3131
secrets:
3232
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}

.github/workflows/pull_request.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ jobs:
3232
TAG_FORMAT=$(yq '.TAG_FORMAT' .github/config/settings.yml)
3333
echo "TAG_FORMAT=$TAG_FORMAT" >> "$GITHUB_OUTPUT"
3434
quality_checks:
35-
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2b3ddfd1e59daf9905522d0140c6cd08e2547432
35+
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2fe6bc6cd974efb4d55a2a7b665385f7a2d28950
3636
needs: [get_asdf_version]
3737
with:
3838
asdfVersion: ${{ needs.get_asdf_version.outputs.asdf_version }}

.github/workflows/release.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ jobs:
2525
TAG_FORMAT=$(yq '.TAG_FORMAT' .github/config/settings.yml)
2626
echo "TAG_FORMAT=$TAG_FORMAT" >> "$GITHUB_OUTPUT"
2727
quality_checks:
28-
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2b3ddfd1e59daf9905522d0140c6cd08e2547432
28+
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2fe6bc6cd974efb4d55a2a7b665385f7a2d28950
2929
needs: [get_asdf_version]
3030
secrets:
3131
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}

.trivyignore

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
# various vulnerabilities due to running an old version of hapi-fhir
2+
CVE-2023-24057
3+
CVE-2023-28465
4+
CVE-2024-51132
5+
CVE-2024-55887
6+
CVE-2022-42889
7+
CVE-2024-45294
8+
CVE-2024-52007
9+
CVE-2024-45294
10+
CVE-2024-52007
11+
CVE-2024-45294
12+
CVE-2024-52007
13+
CVE-2024-45294
14+
CVE-2024-52007
15+
CVE-2024-45294
16+
CVE-2024-52007
17+
CVE-2021-35515
18+
CVE-2021-35516
19+
CVE-2021-35517
20+
CVE-2021-36090

Makefile

Lines changed: 3 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -33,13 +33,9 @@ lint-githubaction-scripts:
3333
test: download-dependencies
3434
mvn test
3535

36-
check-licenses: check-licenses-python check-licenses-java
37-
38-
check-licenses-python:
39-
scripts/check_python_licenses.sh
40-
41-
check-licenses-java:
42-
mvn validate
36+
check-licenses:
37+
echo "not implemented from console"
38+
exit 1
4339

4440
show-unused-dependencies:
4541
mvn dependency:analyze

licenses/allowedMissingLicense.xml

Lines changed: 0 additions & 8 deletions
This file was deleted.

licenses/licenses.xml

Lines changed: 0 additions & 153 deletions
This file was deleted.

poetry.lock

Lines changed: 1 addition & 49 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

pom.xml

Lines changed: 0 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -175,27 +175,6 @@
175175
</resource>
176176
</resources>
177177
<plugins>
178-
<plugin>
179-
<groupId>se.ayoy.maven-plugins</groupId>
180-
<artifactId>ayoy-license-verifier-maven-plugin</artifactId>
181-
<version>1.2.0</version>
182-
<executions>
183-
<execution>
184-
<phase>validate</phase>
185-
<goals>
186-
<goal>verify</goal>
187-
</goals>
188-
</execution>
189-
</executions>
190-
<configuration>
191-
<licenseFile>${project.basedir}/licenses/licenses.xml</licenseFile>
192-
<excludedMissingLicensesFile>
193-
${project.basedir}/licenses/allowedMissingLicense.xml</excludedMissingLicensesFile>
194-
<failOnForbidden>true</failOnForbidden>
195-
<failOnMissing>true</failOnMissing>
196-
<failOnUnknown>true</failOnUnknown>
197-
</configuration>
198-
</plugin>
199178
<plugin>
200179
<artifactId>maven-dependency-plugin</artifactId>
201180
<version>3.9.0</version>

pyproject.toml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,6 @@ flake8 = "^7.3.0"
2020
requests = "^2.32.5"
2121

2222
[tool.poetry.group.dev.dependencies]
23-
pip-licenses = "^5.0.0"
2423
pre-commit = "^4.5.1"
2524
cfn-lint = "^1.43.2"
2625

0 commit comments

Comments
 (0)