chore(deps): update chromedp/headless-shell docker tag to v155 - #705
Conversation
✅MegaLinter analysis: Success
Notices
See detailed reports in MegaLinter artifacts Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining
|
✅
|
| Descriptor | Linter | Files | Fixed | Errors | Max errors | Warnings | Elapsed time |
|---|---|---|---|---|---|---|---|
| ✅ BASH | shellcheck | 11 | 0 | 0 | 0.1s | ||
| ✅ BASH | shfmt | 11 | 0 | 0 | 0 | 0.01s | |
| jscpd | yes | 1 | no | 0.51s | |||
| ✅ JSON | prettier | 2 | 0 | 0 | 0 | 0.32s | |
| ✅ JSON | v8r | 2 | 0 | 0 | 1.19s | ||
| ✅ REPOSITORY | betterleaks | yes | no | no | 0.75s | ||
| ✅ REPOSITORY | git_diff | yes | no | no | 0.01s | ||
| osv-scanner | yes | no | 1 | 0.39s | |||
| ✅ REPOSITORY | secretlint | yes | no | no | 0.68s | ||
| ✅ REPOSITORY | syft | yes | no | no | 1.4s | ||
| ✅ REPOSITORY | trivy | yes | no | no | 10.0s | ||
| ✅ REPOSITORY | trivy-sbom | yes | no | no | 0.07s | ||
| ✅ REPOSITORY | trufflehog | yes | no | no | 2.18s | ||
| ✅ YAML | prettier | 50 | 0 | 0 | 0 | 0.23s | |
| ✅ YAML | v8r | 50 | 0 | 0 | 7.75s | ||
| ✅ YAML | yamllint | 50 | 0 | 0 | 1.61s |
Detailed Issues
⚠️ COPYPASTE / jscpd - 1 error
error: Duplicated code block (51 tokens), duplicated at [bin/oci-rm-stack-update.sh:12](0)
┌─ bin/oci-rm-stack-create.sh:32:1
│
32 │ ╭ OCI_RM_DIR=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/oci-rm
33 │ │ WORK_DIR=$(mktemp -d "${TMPDIR:-/tmp}/oci-rm.XXXXXX")
34 │ │ STACK_ZIP="${WORK_DIR}/stack.zip"
35 │ │
· │
39 │ │
40 │ │ echo "Creating stack ${STACK_NAME} in ${REGION}..."
│ ╰────^
│
┌─ bin/oci-rm-stack-update.sh:12:1
│
12 │ ╭ OCI_RM_DIR=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/oci-rm
13 │ │ WORK_DIR=$(mktemp -d "${TMPDIR:-/tmp}/oci-rm.XXXXXX")
14 │ │ STACK_ZIP="${WORK_DIR}/stack.zip"
15 │ │
· │
19 │ │
20 │ │ echo "Updating stack ${STACK_ID}..."
│ ╰────' Duplicated at bin/oci-rm-stack-update.sh:12
error: 1 errors emitted
⚠️ REPOSITORY / osv-scanner - 1 warning
Scanning dir .
Starting filesystem walk for root: /
End status: 47 dirs visited, 157 inodes visited, 0 Extract calls, 5.657335ms elapsed, 5.657505ms wall time
No package sources found, --help for usage information.
[REPOSITORY_OSV_SCANNER_ERROR_NO_PACKAGE_SOURCES] osv-scanner found no lockfiles, manifests, or SBOMs to scan in the repository.
This is a configuration/scope issue, not a vulnerability finding.
Resolutions:
- Verify the repository actually contains a supported lockfile (package-lock.json, go.sum, Gemfile.lock, Pipfile.lock, etc.) at the scanned path.
- If this is expected for some sub-projects, disable osv-scanner for the affected paths or mark it non-blocking via `DISABLE_ERRORS_LINTERS`.
Notices
REPOSITORY_KICS, TERRAFORM_TERRASCAN. See Removed linters to find their replacements.
See detailed reports in MegaLinter artifacts
Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)
- Documentation: Custom Flavors
- Command:
npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters BASH_SHELLCHECK,BASH_SHFMT,COPYPASTE_JSCPD,JSON_V8R,JSON_PRETTIER,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

Show us your support by starring ⭐ the repository
✅
|
| Descriptor | Linter | Files | Fixed | Errors | Max errors | Warnings | Elapsed time |
|---|---|---|---|---|---|---|---|
| ✅ BASH | bash-exec | 11 | 0 | 0 | 0.03s | ||
| ✅ BASH | shellcheck | 11 | 0 | 0 | 0.17s | ||
| ✅ REPOSITORY | betterleaks | yes | no | no | 0.68s | ||
| ✅ REPOSITORY | dustilock | yes | no | no | 0.02s | ||
| osv-scanner | yes | no | 1 | 0.69s | |||
| ✅ REPOSITORY | secretlint | yes | no | no | 0.99s | ||
| ✅ REPOSITORY | syft | yes | no | no | 1.59s | ||
| ✅ REPOSITORY | trivy | yes | no | no | 10.12s | ||
| ✅ REPOSITORY | trivy-sbom | yes | no | no | 0.56s | ||
| ✅ REPOSITORY | trufflehog | yes | no | no | 3.04s | ||
| ✅ TERRAFORM | tflint | yes | no | no | 6.14s |
Detailed Issues
⚠️ REPOSITORY / osv-scanner - 1 warning
Scanning dir .
Starting filesystem walk for root: /
End status: 47 dirs visited, 157 inodes visited, 0 Extract calls, 5.189907ms elapsed, 5.190097ms wall time
No package sources found, --help for usage information.
[REPOSITORY_OSV_SCANNER_ERROR_NO_PACKAGE_SOURCES] osv-scanner found no lockfiles, manifests, or SBOMs to scan in the repository.
This is a configuration/scope issue, not a vulnerability finding.
Resolutions:
- Verify the repository actually contains a supported lockfile (package-lock.json, go.sum, Gemfile.lock, Pipfile.lock, etc.) at the scanned path.
- If this is expected for some sub-projects, disable osv-scanner for the affected paths or mark it non-blocking via `DISABLE_ERRORS_LINTERS`.
Notices
REPOSITORY_KICS, TERRAFORM_TERRASCAN. See Removed linters to find their replacements.
See detailed reports in MegaLinter artifacts
Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)
- Documentation: Custom Flavors
- Command:
npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters BASH_EXEC,BASH_SHELLCHECK,REPOSITORY_DUSTILOCK,REPOSITORY_BETTERLEAKS,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,TERRAFORM_TFLINT

Show us your support by starring ⭐ the repository
✅
|
| Descriptor | Linter | Files | Fixed | Errors | Max errors | Warnings | Elapsed time |
|---|---|---|---|---|---|---|---|
| ✅ ACTION | actionlint | 4 | 0 | 0 | 0.01s | ||
| zizmor | 4 | 0 | 0 | 1 | 0.38s | ||
| ✅ BASH | bash-exec | 11 | 0 | 0 | 0.02s | ||
| ✅ BASH | shellcheck | 11 | 0 | 0 | 0.09s | ||
| ✅ BASH | shfmt | 11 | 0 | 0 | 0 | 0.01s | |
| jscpd | yes | 1 | no | 0.4s | |||
| ✅ EDITORCONFIG | editorconfig-checker | 110 | 0 | 0 | 0.04s | ||
| ✅ JSON | prettier | 2 | 0 | 0 | 0 | 0.41s | |
| ✅ JSON | v8r | 2 | 0 | 0 | 0.99s | ||
| ✅ MARKDOWN | markdownlint | 5 | 0 | 0 | 0 | 0.47s | |
| ✅ MARKDOWN | markdown-table-formatter | 5 | 0 | 0 | 0 | 0.11s | |
| ✅ REPOSITORY | betterleaks | yes | no | no | 1.08s | ||
| ✅ REPOSITORY | git_diff | yes | no | no | 0.02s | ||
| osv-scanner | yes | no | 1 | 0.37s | |||
| ✅ REPOSITORY | secretlint | yes | no | no | 0.64s | ||
| ✅ REPOSITORY | syft | yes | no | no | 1.15s | ||
| ✅ REPOSITORY | trivy | yes | no | no | 5.9s | ||
| ✅ REPOSITORY | trivy-sbom | yes | no | no | 0.1s | ||
| ✅ REPOSITORY | trufflehog | yes | no | no | 1.91s | ||
| lychee | 58 | 37 | 0 | 1.64s | |||
| ✅ YAML | prettier | 50 | 0 | 0 | 0 | 0.17s | |
| ✅ YAML | v8r | 50 | 0 | 0 | 6.85s | ||
| ✅ YAML | yamllint | 50 | 0 | 0 | 0.73s |
Detailed Issues
⚠️ COPYPASTE / jscpd - 1 error
error: Duplicated code block (51 tokens), duplicated at [bin/oci-rm-stack-update.sh:12](0)
┌─ bin/oci-rm-stack-create.sh:32:1
│
32 │ ╭ OCI_RM_DIR=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/oci-rm
33 │ │ WORK_DIR=$(mktemp -d "${TMPDIR:-/tmp}/oci-rm.XXXXXX")
34 │ │ STACK_ZIP="${WORK_DIR}/stack.zip"
35 │ │
· │
39 │ │
40 │ │ echo "Creating stack ${STACK_NAME} in ${REGION}..."
│ ╰────^
│
┌─ bin/oci-rm-stack-update.sh:12:1
│
12 │ ╭ OCI_RM_DIR=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/oci-rm
13 │ │ WORK_DIR=$(mktemp -d "${TMPDIR:-/tmp}/oci-rm.XXXXXX")
14 │ │ STACK_ZIP="${WORK_DIR}/stack.zip"
15 │ │
· │
19 │ │
20 │ │ echo "Updating stack ${STACK_ID}..."
│ ╰────' Duplicated at bin/oci-rm-stack-update.sh:12
error: 1 errors emitted
⚠️ SPELL / lychee - 37 errors
📝 Summary
---------------------
🔍 Total...........66
🔗 Unique..........57
✅ Successful......22
⏳ Timeouts.........0
🔀 Redirected.......0
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors..........37
⛔ Unsupported.....37
Errors in agent/bifrost/config.json
[404] https://api.commandcode.ai/provider (at 23:22) | Rejected status code: 404 Not Found
Errors in agent/compose.yaml
[ERROR] http://localhost:2375/_ping (at 91:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8080/healthz (at 240:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:9119/api/status (at 49:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:9377/health (at 151:33) | Connection refused - server may be down or port blocked
[ERROR] https://hermes/ (at 9:67) | Connection failed. Check network connectivity and firewall settings
[ERROR] https://searxng/ (at 227:45) | Connection failed. Check network connectivity and firewall settings
Errors in arcane/compose.yaml
[ERROR] http://localhost:3552/ (at 6:27) | Connection refused - server may be down or port blocked
Errors in homeassistant/compose.yaml
[ERROR] http://localhost:10000/health (at 148:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:6052/version (at 107:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8095/ (at 66:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8123/ (at 27:33) | Connection refused - server may be down or port blocked
Errors in immich/compose.yaml
[ERROR] http://localhost:8080/api/status (at 164:32) | Connection refused - server may be down or port blocked
Errors in infra/compose.yaml
[ERROR] http://localhost:2375/_ping (at 62:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:9002/healthz (at 99:36) | Connection refused - server may be down or port blocked
Errors in monitoring/compose.yaml
[ERROR] http://localhost:8090/ (at 73:44) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8090/ (at 94:27) | Connection refused - server may be down or port blocked
Errors in pangolin/compose.yaml
[ERROR] http://gerbil:3004/ (at 63:23) | Connection failed. Check network connectivity and firewall settings
[ERROR] http://localhost/ping (at 126:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:3001/api/v1/ (at 51:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:3004/healthz (at 87:32) | Connection refused - server may be down or port blocked
[ERROR] http://pangolin:3001/api/v1/ (at 65:24) | Connection failed. Check network connectivity and firewall settings
Errors in pangolin/traefik/dynamic/config.yml
[ERROR] http://pangolin:3000/ (at 80:18) | Connection failed. Check network connectivity and firewall settings
[ERROR] http://pangolin:3002/ (at 85:18) | Connection failed. Check network connectivity and firewall settings
Errors in pangolin/traefik/traefik.template.yml
[ERROR] http://pangolin:3001/api/v1/traefik-config (at 7:15) | Connection failed. Check network connectivity and firewall settings
Errors in proxy/compose.yaml
[ERROR] http://localhost/healthz (at 36:32) | Connection refused - server may be down or port blocked
[ERROR] https://tinyauth/ (at 50:24) | Connection failed. Check network connectivity and firewall settings
Errors in security/compose.yaml
[ERROR] http://localhost:8080/ (at 52:16) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8080/health (at 34:32) | Connection refused - server may be down or port blocked
Errors in torrent/compose.yaml
[ERROR] http://localhost:6868/ (at 219:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:7878/ping (at 139:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8191/health (at 15:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8989/ping (at 181:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:9696/ping (at 44:33) | Connection refused - server may be down or port blocked
[ERROR] https://profilarr/ (at 204:15) | Connection failed. Check network connectivity and firewall settings
Errors in usenet/compose.yaml
[ERROR] http://localhost:7000/health (at 21:32) | Connection refused - server may be down or port blocked
[ERROR] https://aiostreams/ (at 57:18) | Connection failed. Check network connectivity and firewall settings
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ REPOSITORY / osv-scanner - 1 warning
Scanning dir .
Starting filesystem walk for root: /
End status: 47 dirs visited, 157 inodes visited, 0 Extract calls, 3.125012ms elapsed, 3.125187ms wall time
No package sources found, --help for usage information.
[REPOSITORY_OSV_SCANNER_ERROR_NO_PACKAGE_SOURCES] osv-scanner found no lockfiles, manifests, or SBOMs to scan in the repository.
This is a configuration/scope issue, not a vulnerability finding.
Resolutions:
- Verify the repository actually contains a supported lockfile (package-lock.json, go.sum, Gemfile.lock, Pipfile.lock, etc.) at the scanned path.
- If this is expected for some sub-projects, disable osv-scanner for the affected paths or mark it non-blocking via `DISABLE_ERRORS_LINTERS`.
⚠️ ACTION / zizmor - 1 warning
INFO zizmor: 🌈 zizmor v1.25.0
INFO audit: zizmor: 🌈 completed .github/workflows/automerge.yml
INFO audit: zizmor: 🌈 completed .github/workflows/megalinter.yml
INFO audit: zizmor: 🌈 completed .github/workflows/ossf.yml
INFO audit: zizmor: 🌈 completed .github/workflows/pr.yml
{
"$schema": "https://docs.oasis-open.org/sarif/sarif/v2.1.0/os/schemas/sarif-schema-2.1.0.json",
"runs": [
{
"invocations": [
{
"executionSuccessful": true
}
],
"results": [],
"tool": {
"driver": {
"downloadUri": "https://github.com/zizmorcore/zizmor",
"informationUri": "https://docs.zizmor.sh",
"name": "zizmor",
"rules": [],
"semanticVersion": "1.25.0",
"version": "1.25.0"
}
}
}
],
"version": "2.1.0"
No fixes available to apply.
}
Notices
REPOSITORY_KICS, TERRAFORM_TERRASCAN. See Removed linters to find their replacements.
See detailed reports in MegaLinter artifacts
Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)
- Documentation: Custom Flavors
- Command:
npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,ACTION_ZIZMOR,BASH_EXEC,BASH_SHELLCHECK,BASH_SHFMT,COPYPASTE_JSCPD,EDITORCONFIG_EDITORCONFIG_CHECKER,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

Show us your support by starring ⭐ the repository
3cac46b to
b0550e1
Compare
Risk note:
|
| URL | result |
|---|---|
| example.com | 200 · 976 md · 800×600 |
| news.ycombinator.com | 200 · 10939 md · 800×600 |
| wikipedia/Chromium | 200 · ~662k md · 800×600 |
| httpbin.org/html | 200 · 3597 md · 800×600 |
| burst ×6 | 6/6 ok, 1.1–5.7s |
| container restarts | 0 |
Markdown byte-length is identical to 156 and 157 on every URL; every screenshot decoded to
a valid 800×600 PNG. Latency indistinguishable. No crashes, no context leaks, no
Inspector.detached.
One operational note
The digest here (sha256:47e3a0c0cbef29e321d16c893cd804996243f710ca7855770dd4f9c4cd2b8627)
is what agent-chrome-1 is still running on this stack right now, even though
main's compose file has since moved on twice (see #707). So this bump's behaviour is
already proven in production, not just in my A/B. If the PR sequence is later
squashed/rewritten, this is the digest to fall back to.
Recommendation: keep this as the baseline. See #707 for the full comparison and the one
real caveat in the series (that #707 lands a dev-channel browser, two milestones ahead
of stable, with no point releases available to patch it).
This PR contains the following updates:
152.0.7939.3→155.0.8059.26Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.