Skip to content

Conversation

@scottschreckengaust
Copy link
Member

@scottschreckengaust scottschreckengaust commented Dec 24, 2025

Fixes:

Suppress:

Summary

Updates to python3.13 slim-bookworm base images and setup Vulnerability Exploitability eXchange (VEX).

Changes

Please provide a summary of what's being changed

Add .vex/ directory with an entry in OpenVEX format for https://security-tracker.debian.org/tracker/CVE-2023-45853

User experience

Please share what the user experience looks like before and after this change

Checklist

If your change doesn't seem to apply, please leave them unchecked.

  • I have reviewed the contributing guidelines
  • I have performed a self-review of this change
  • Changes have been tested
  • Changes are documented

Is this a breaking change? (Y/N) N

RFC issue number:

Checklist:

  • Migration process documented
  • Implement warnings (if it can live side by side)

Acknowledgment

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of the project license.

Signed-off-by: Scott Schreckengaust <scottschreckengaust@users.noreply.github.com>
Signed-off-by: Scott Schreckengaust <scottschreckengaust@users.noreply.github.com>
@codecov
Copy link

codecov bot commented Dec 24, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.54%. Comparing base (2fee425) to head (b959089).

Additional details and impacted files
@@ Coverage Diff @@ ## main #2000 +/- ## ========================================== - Coverage 90.55% 90.54% -0.02%  ========================================== Files 861 861 Lines 64686 64686 Branches 10407 10407 ========================================== - Hits 58577 58568 -9  - Misses 3777 3784 +7  - Partials 2332 2334 +2 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.
Signed-off-by: Scott Schreckengaust <scottschreckengaust@users.noreply.github.com>
Signed-off-by: Scott Schreckengaust <scottschreckengaust@users.noreply.github.com>
Signed-off-by: Scott Schreckengaust <scottschreckengaust@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant