From 4af58ca2dd75d7d9ce6456f24edfe6163b582b95 Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Sat, 10 Oct 2026 02:02:57 +0000 Subject: [PATCH] Pin dependencies --- .../Release-renovate-1791597776657.yaml | 16 ++++++++++++++++ .gitea/workflows/release/build-image.yaml | 2 +- .../workflows/release/update-composer-lock.yaml | 2 +- Dockerfile | 4 ++-- compose.override.yaml | 2 +- compose.yaml | 4 ++-- docker/logstash/Dockerfile | 2 +- docker/nginx/Dockerfile | 2 +- package.json | 2 +- 9 files changed, 26 insertions(+), 10 deletions(-) create mode 100644 .changes/unreleased/Release-renovate-1791597776657.yaml diff --git a/.changes/unreleased/Release-renovate-1791597776657.yaml b/.changes/unreleased/Release-renovate-1791597776657.yaml new file mode 100644 index 0000000..19e7c7d --- /dev/null +++ b/.changes/unreleased/Release-renovate-1791597776657.yaml @@ -0,0 +1,16 @@ +kind: Release +body: | + - axllent/mailpit: -> + - chill/base-image: 8.4-edge -> 8.4-edge + - composer: 2 -> 2 + - docker.elastic.co/logstash/logstash-oss: 8.1.0-amd64 -> 8.1.0-amd64 + - gitea.champs-libres.be/chill-project/chill-skeleton-basic/base-image: latest -> latest + - intl-messageformat: ^10.5.11 -> 10.7.18 + - nginx: -> + - php: 8.4-fpm-alpine -> 8.4-fpm-alpine + - redis: -> + - registry.gitlab.com/champs-libres/public/relatorio-tornado/app: latest -> latest + +time: 2026-10-10T02:02:56+00:00 +custom: + Issue: "" diff --git a/.gitea/workflows/release/build-image.yaml b/.gitea/workflows/release/build-image.yaml index 7f99db4..816c3a3 100644 --- a/.gitea/workflows/release/build-image.yaml +++ b/.gitea/workflows/release/build-image.yaml @@ -19,7 +19,7 @@ jobs: password: ${{ secrets.OVH_REGISTRY_PASSWORD }} - name: Install Dependencies and Build Assets - uses: docker://chill/base-image:8.4-edge + uses: docker://chill/base-image:8.4-edge@sha256:dd1e5379861a98aa3d70e46b3c4546bd020d66c94a70a7edf5f2f33ebb9a673c env: APP_ENV: prod with: diff --git a/.gitea/workflows/release/update-composer-lock.yaml b/.gitea/workflows/release/update-composer-lock.yaml index c5ea7b8..4156739 100644 --- a/.gitea/workflows/release/update-composer-lock.yaml +++ b/.gitea/workflows/release/update-composer-lock.yaml @@ -19,7 +19,7 @@ jobs: with: cmd: 'cat composer.lock | jq --raw-output ''.packages[] | select ( .name | contains ("chill-project/chill-bundles")) | .version''' - name: run composer update to update composer.lock - uses: docker://gitea.champs-libres.be/chill-project/chill-skeleton-basic/base-image:latest + uses: docker://gitea.champs-libres.be/chill-project/chill-skeleton-basic/base-image:latest@sha256:d728a939475e465c488056ec8b9c12f31601ea27251aad830499577857b7be94 with: # this is where we set the command to execute args: composer update --no-install diff --git a/Dockerfile b/Dockerfile index 7b6b20e..2cf6897 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM php:8.4-fpm-alpine AS chill_base_php82 +FROM php:8.4-fpm-alpine@sha256:78cd8de9970a9cd6ff4d98860a94eb5bf37dd2d5776b4785562dbfad01c29d5a AS chill_base_php82 ENV POSTGRES_VERSION=16 @@ -56,7 +56,7 @@ RUN curl -o /usr/local/bin/php-cs-fixer https://cs.symfony.com/download/php-cs-f # to make php-cs-fixer works with php 8.2 ENV PHP_CS_FIXER_IGNORE_ENV=1 -COPY --from=composer:2 /usr/bin/composer /usr/bin/composer +COPY --from=composer:2@sha256:af98f42dfff7c68ba8d53c2164fd9fde1087b7d449514baa38c418b1f6bc4bac /usr/bin/composer /usr/bin/composer ENV COMPOSER_ALLOW_SUPERUSER=1 ENV COMPOSER_MEMORY_LIMIT=-1 diff --git a/compose.override.yaml b/compose.override.yaml index 6532ca5..463b44c 100644 --- a/compose.override.yaml +++ b/compose.override.yaml @@ -3,7 +3,7 @@ version: '3' services: ###> symfony/mailer ### mailer: - image: axllent/mailpit + image: axllent/mailpit@sha256:b68349e3a014b90c5610bfb26b2ae36f3892d7b8cf25ee140c6c71c98d2fcf48 ports: - "1025" - "8025" diff --git a/compose.yaml b/compose.yaml index b312fef..0914805 100644 --- a/compose.yaml +++ b/compose.yaml @@ -17,9 +17,9 @@ services: ###> chill-project/chill-bundles ### redis: - image: redis + image: redis@sha256:2c2dff791878316e3b083188be0d578423b24813cdda5de0e80ea4f7b3e6bfd6 relatorio: - image: registry.gitlab.com/champs-libres/public/relatorio-tornado/app:latest + image: registry.gitlab.com/champs-libres/public/relatorio-tornado/app:latest@sha256:2c4aa2f422c389d940adfd760b0856d237023d66cded0aa026b532b29192212e ###< chill-project/chill-bundles ### volumes: diff --git a/docker/logstash/Dockerfile b/docker/logstash/Dockerfile index 67db6cc..8ae607f 100644 --- a/docker/logstash/Dockerfile +++ b/docker/logstash/Dockerfile @@ -1,4 +1,4 @@ -FROM docker.elastic.co/logstash/logstash-oss:8.1.0-amd64 +FROM docker.elastic.co/logstash/logstash-oss:8.1.0-amd64@sha256:f48c2f7db8b63572fa36db259c98c3894d89fb28d37f9546c26acfc0de525338 RUN \ bin/logstash-plugin install logstash-output-gelf \ diff --git a/docker/nginx/Dockerfile b/docker/nginx/Dockerfile index 7114361..6e35c39 100644 --- a/docker/nginx/Dockerfile +++ b/docker/nginx/Dockerfile @@ -1,4 +1,4 @@ -FROM nginx +FROM nginx@sha256:f9ea18bfa4fad859e1ed38259d711da7ccad2c3516e875cec3351a57c859f571 COPY ./public /var/www/app/public diff --git a/package.json b/package.json index 4ab5330..9f5acf3 100644 --- a/package.json +++ b/package.json @@ -6,7 +6,7 @@ "devDependencies": { "@symfony/ux-translator": "file:vendor/symfony/ux-translator/assets", "bootstrap": "5.2.3", - "intl-messageformat": "^10.5.11" + "intl-messageformat": "10.7.18" }, "scripts": { "specs-build": "yaml-merge vendor/chill-project/chill-bundles/src/Bundle/ChillMainBundle/chill.api.specs.yaml vendor/chill-project/chill-bundles/src/Bundle/ChillPersonBundle/chill.api.specs.yaml vendor/chill-project/chill-bundles/src/Bundle/ChillCalendarBundle/chill.api.specs.yaml vendor/chill-project/chill-bundles/src/Bundle/ChillThirdPartyBundle/chill.api.specs.yaml vendor/chill-project/chill-bundles/src/Bundle/ChillDocStoreBundle/chill.api.specs.yaml> templates/api/specs.yaml", -- 2.54.0