Skip to content

chore: update VS Code to 1.135.0 - #62

Open
sdf-actions-actor[bot] wants to merge 1 commit into
mainfrom
automated/update-vscode-08d4889
Open

chore: update VS Code to 1.135.0#62
sdf-actions-actor[bot] wants to merge 1 commit into
mainfrom
automated/update-vscode-08d4889

Conversation

@sdf-actions-actor

Copy link
Copy Markdown
Contributor

🔄 Automated VS Code Update

This PR updates the VS Code commit hash to the latest stable release.

Previous version: df53daabb18cd157bdb08c7f01c34df936cf12f4
New version: 08d4889f9ec4a1685d257b9b95de036c8e1ce1e5
Release: 1.135.0

Changes

  • Updated VSCODE_COMMIT in Dockerfile

Verification

This PR will trigger the build workflow to ensure the container builds successfully with the new VS Code version.


This PR was created automatically by the Update VS Code Version workflow.

Update VSCODE_COMMIT from df53daa to 08d4889
@github-actions

Copy link
Copy Markdown

🔒 Trivy Security Scan Results

Status: ⚠️ Vulnerabilities found (see details in artifacts)
Vulnerabilities Found: 172 critical/high severity issues

⚠️ Action Required: Critical or high severity vulnerabilities detected.

Top 10 Critical/High Severity Vulnerabilities:

Type Package Vulnerability Severity Fixed Version
node-pkg loader-utils CVE-2022-37601 CRITICAL 2.0.3, 1.4.1
node-pkg minimist CVE-2021-44906 CRITICAL 1.2.6, 0.2.4
node-pkg sha.js CVE-2025-9288 CRITICAL 2.4.12
node-pkg tar CVE-2026-59873 CRITICAL 7.5.19
node-pkg tar CVE-2026-59873 CRITICAL 7.5.19
python-pkg Twisted CVE-2022-24801 CRITICAL 22.4.0
node-pkg adm-zip CVE-2026-39244 HIGH 0.6.0
node-pkg axios GHSA-gcfj-64vw-6mp9 HIGH 0.33.0, 1.18.0
node-pkg brace-expansion CVE-2026-13149 HIGH 5.0.7, 1.1.16, 2.1.2
node-pkg brace-expansion CVE-2026-14257 HIGH 5.0.8, 3.0.3, 2.1.3, 1.1.17

... and 5 more issues.

📊 Scan Details

  • Image: ghcr.io/smartdatafoundry/devcontainer
  • Scan Date: 2026-08-27 03:53:57 UTC
  • Total Vulnerabilities: 172

Action Run: view run
Trivy Report: view report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant