Skip to content

chore(deps): bump the docker-base-images group across 1 directory with 2 updates - #1457

Open
dependabot[bot] wants to merge 3 commits into
developfrom
dependabot/docker/docker-base-images-0029c8dd33
Open

chore(deps): bump the docker-base-images group across 1 directory with 2 updates#1457
dependabot[bot] wants to merge 3 commits into
developfrom
dependabot/docker/docker-base-images-0029c8dd33

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Bumps the docker-base-images group with 2 updates in the / directory: python and ollama/ollama.

Updates python from a7fb1e6 to ce40764

Updates ollama/ollama from b88c73a to 57d60e6

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Open in Devin Review

…h 2 updates

Bumps the docker-base-images group with 2 updates in the / directory: python and ollama/ollama.


Updates `python` from `a7fb1e6` to `ce40764`

Updates `ollama/ollama` from `b88c73a` to `57d60e6`

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.14-slim
  dependency-type: direct:production
  dependency-group: docker-base-images
- dependency-name: ollama/ollama
  dependency-version: 57d60e686821ea81a7748a3ec8141308c8b8f95b27105713954abf7a6529e700
  dependency-type: direct:production
  dependency-group: docker-base-images
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file docker Pull requests that update docker code labels Aug 24, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner August 24, 2026 02:54
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file docker Pull requests that update docker code labels Aug 24, 2026
devin-ai-integration[bot]

This comment was marked as resolved.

@github-actions

github-actions Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 245c8f1d2177e451e9812525ef6bbd7db9be3e6e:

  • Branch is BEHIND the base branch; update the branch and re-run checks.
  • Required check strix is FAILURE on the current head.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 2 new potential issues.

Open in Devin Review

Comment thread Dockerfile.ollama
Comment thread Dockerfile
@seonghobae

Copy link
Copy Markdown
Contributor

Exact-head hosted Strix failure was traced to provider infrastructure: NVIDIA NIM returned repeated HTTP 429 rate limits, the configured fallback also emitted provider failure, and the gate correctly failed closed without authoritative vulnerability evidence. Source checks for 245c8f1d2177e451e9812525ef6bbd7db9be3e6e are otherwise green; failed jobs were retried through the normal Actions API. No bypass or source suppression is warranted.

@seonghobae

Copy link
Copy Markdown
Contributor

Current-head review disposition

  • Exact head: 245c8f1d
  • The remaining Dockerfile observation is informational: the Python digest is synchronized across the root image, OCI metadata arguments, and connector image, and the current repository hygiene tests assert that contract.
  • No source change is required. The pending strix check must complete normally.

The informational thread is being resolved after this disposition; no approval or check is being fabricated.

@seonghobae

Copy link
Copy Markdown
Contributor

Exact-head Strix disposition

For exact head 245c8f1d2177e451e9812525ef6bbd7db9be3e6e, Strix failed closed after repeated NVIDIA NIM 429 Too Many Requests; the configured openai-direct/gpt-5.6-luna fallback returned 404 page not found, and no authoritative vulnerability report was produced. The dependency, SAST, build, coverage, and image checks are otherwise green; this is provider infrastructure evidence, not a source finding.

Decision: WAIT_AND_REMEDIATE until a current authoritative Strix result and independent approval exist. No bypass or check suppression is used.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update docker code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant