Skip to content

chore(deps): update chromedp/headless-shell docker tag to v155 - #705

Merged
yxtay merged 1 commit into
mainfrom
renovate/chromedp-headless-shell-155.x
Oct 4, 2026
Merged

yxtay merged 1 commit into
mainfrom
renovate/chromedp-headless-shell-155.x

Conversation

@renovate

@renovate renovate Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
chromedp/headless-shell major 152.0.7939.3 → 155.0.8059.26

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from yxtay as a code owner October 4, 2026 00:31
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

✅MegaLinter analysis: Success

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ BASH shfmt 11 0 0 0 0.01s
✅ JSON prettier 2 0 0 0 0.28s
✅ MARKDOWN markdownlint 5 0 0 0 0.37s
✅ MARKDOWN markdown-table-formatter 5 0 0 0 0.11s
✅ TERRAFORM terraform-fmt 7 0 0 0 0.21s
✅ YAML prettier 50 0 0 0 0.23s

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: REPOSITORY_KICS, TERRAFORM_TERRASCAN. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters BASH_SHFMT,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,TERRAFORM_TERRAFORM_FMT,YAML_PRETTIER

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

✅⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ BASH shellcheck 11 0 0 0.1s
✅ BASH shfmt 11 0 0 0 0.01s
⚠️ COPYPASTE jscpd yes 1 no 0.51s
✅ JSON prettier 2 0 0 0 0.32s
✅ JSON v8r 2 0 0 1.19s
✅ REPOSITORY betterleaks yes no no 0.75s
✅ REPOSITORY git_diff yes no no 0.01s
⚠️ REPOSITORY osv-scanner yes no 1 0.39s
✅ REPOSITORY secretlint yes no no 0.68s
✅ REPOSITORY syft yes no no 1.4s
✅ REPOSITORY trivy yes no no 10.0s
✅ REPOSITORY trivy-sbom yes no no 0.07s
✅ REPOSITORY trufflehog yes no no 2.18s
✅ YAML prettier 50 0 0 0 0.23s
✅ YAML v8r 50 0 0 7.75s
✅ YAML yamllint 50 0 0 1.61s

Detailed Issues

⚠️ COPYPASTE / jscpd - 1 error
error: Duplicated code block (51 tokens), duplicated at [bin/oci-rm-stack-update.sh:12](0)
   ┌─ bin/oci-rm-stack-create.sh:32:1
   │  
32 │ ╭ OCI_RM_DIR=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/oci-rm
33 │ │ WORK_DIR=$(mktemp -d "${TMPDIR:-/tmp}/oci-rm.XXXXXX")
34 │ │ STACK_ZIP="${WORK_DIR}/stack.zip"
35 │ │ 
   · │
39 │ │ 
40 │ │ echo "Creating stack ${STACK_NAME} in ${REGION}..."
   │ ╰────^
   │  
   ┌─ bin/oci-rm-stack-update.sh:12:1
   │  
12 │ ╭ OCI_RM_DIR=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/oci-rm
13 │ │ WORK_DIR=$(mktemp -d "${TMPDIR:-/tmp}/oci-rm.XXXXXX")
14 │ │ STACK_ZIP="${WORK_DIR}/stack.zip"
15 │ │ 
   · │
19 │ │ 
20 │ │ echo "Updating stack ${STACK_ID}..."
   │ ╰────' Duplicated at bin/oci-rm-stack-update.sh:12

error: 1 errors emitted
⚠️ REPOSITORY / osv-scanner - 1 warning
Scanning dir .
Starting filesystem walk for root: /
End status: 47 dirs visited, 157 inodes visited, 0 Extract calls, 5.657335ms elapsed, 5.657505ms wall time
No package sources found, --help for usage information.


[REPOSITORY_OSV_SCANNER_ERROR_NO_PACKAGE_SOURCES] osv-scanner found no lockfiles, manifests, or SBOMs to scan in the repository.
This is a configuration/scope issue, not a vulnerability finding.
Resolutions:
  - Verify the repository actually contains a supported lockfile (package-lock.json, go.sum, Gemfile.lock, Pipfile.lock, etc.) at the scanned path.
  - If this is expected for some sub-projects, disable osv-scanner for the affected paths or mark it non-blocking via `DISABLE_ERRORS_LINTERS`.

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: REPOSITORY_KICS, TERRAFORM_TERRASCAN. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters BASH_SHELLCHECK,BASH_SHFMT,COPYPASTE_JSCPD,JSON_V8R,JSON_PRETTIER,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

✅⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ BASH bash-exec 11 0 0 0.03s
✅ BASH shellcheck 11 0 0 0.17s
✅ REPOSITORY betterleaks yes no no 0.68s
✅ REPOSITORY dustilock yes no no 0.02s
⚠️ REPOSITORY osv-scanner yes no 1 0.69s
✅ REPOSITORY secretlint yes no no 0.99s
✅ REPOSITORY syft yes no no 1.59s
✅ REPOSITORY trivy yes no no 10.12s
✅ REPOSITORY trivy-sbom yes no no 0.56s
✅ REPOSITORY trufflehog yes no no 3.04s
✅ TERRAFORM tflint yes no no 6.14s

Detailed Issues

⚠️ REPOSITORY / osv-scanner - 1 warning
Scanning dir .
Starting filesystem walk for root: /
End status: 47 dirs visited, 157 inodes visited, 0 Extract calls, 5.189907ms elapsed, 5.190097ms wall time
No package sources found, --help for usage information.


[REPOSITORY_OSV_SCANNER_ERROR_NO_PACKAGE_SOURCES] osv-scanner found no lockfiles, manifests, or SBOMs to scan in the repository.
This is a configuration/scope issue, not a vulnerability finding.
Resolutions:
  - Verify the repository actually contains a supported lockfile (package-lock.json, go.sum, Gemfile.lock, Pipfile.lock, etc.) at the scanned path.
  - If this is expected for some sub-projects, disable osv-scanner for the affected paths or mark it non-blocking via `DISABLE_ERRORS_LINTERS`.

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: REPOSITORY_KICS, TERRAFORM_TERRASCAN. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters BASH_EXEC,BASH_SHELLCHECK,REPOSITORY_DUSTILOCK,REPOSITORY_BETTERLEAKS,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,TERRAFORM_TFLINT

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

✅⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ ACTION actionlint 4 0 0 0.01s
⚠️ ACTION zizmor 4 0 0 1 0.38s
✅ BASH bash-exec 11 0 0 0.02s
✅ BASH shellcheck 11 0 0 0.09s
✅ BASH shfmt 11 0 0 0 0.01s
⚠️ COPYPASTE jscpd yes 1 no 0.4s
✅ EDITORCONFIG editorconfig-checker 110 0 0 0.04s
✅ JSON prettier 2 0 0 0 0.41s
✅ JSON v8r 2 0 0 0.99s
✅ MARKDOWN markdownlint 5 0 0 0 0.47s
✅ MARKDOWN markdown-table-formatter 5 0 0 0 0.11s
✅ REPOSITORY betterleaks yes no no 1.08s
✅ REPOSITORY git_diff yes no no 0.02s
⚠️ REPOSITORY osv-scanner yes no 1 0.37s
✅ REPOSITORY secretlint yes no no 0.64s
✅ REPOSITORY syft yes no no 1.15s
✅ REPOSITORY trivy yes no no 5.9s
✅ REPOSITORY trivy-sbom yes no no 0.1s
✅ REPOSITORY trufflehog yes no no 1.91s
⚠️ SPELL lychee 58 37 0 1.64s
✅ YAML prettier 50 0 0 0 0.17s
✅ YAML v8r 50 0 0 6.85s
✅ YAML yamllint 50 0 0 0.73s

Detailed Issues

⚠️ COPYPASTE / jscpd - 1 error
error: Duplicated code block (51 tokens), duplicated at [bin/oci-rm-stack-update.sh:12](0)
   ┌─ bin/oci-rm-stack-create.sh:32:1
   │  
32 │ ╭ OCI_RM_DIR=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/oci-rm
33 │ │ WORK_DIR=$(mktemp -d "${TMPDIR:-/tmp}/oci-rm.XXXXXX")
34 │ │ STACK_ZIP="${WORK_DIR}/stack.zip"
35 │ │ 
   · │
39 │ │ 
40 │ │ echo "Creating stack ${STACK_NAME} in ${REGION}..."
   │ ╰────^
   │  
   ┌─ bin/oci-rm-stack-update.sh:12:1
   │  
12 │ ╭ OCI_RM_DIR=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/oci-rm
13 │ │ WORK_DIR=$(mktemp -d "${TMPDIR:-/tmp}/oci-rm.XXXXXX")
14 │ │ STACK_ZIP="${WORK_DIR}/stack.zip"
15 │ │ 
   · │
19 │ │ 
20 │ │ echo "Updating stack ${STACK_ID}..."
   │ ╰────' Duplicated at bin/oci-rm-stack-update.sh:12

error: 1 errors emitted
⚠️ SPELL / lychee - 37 errors
📝 Summary
---------------------
🔍 Total...........66
🔗 Unique..........57
✅ Successful......22
⏳ Timeouts.........0
🔀 Redirected.......0
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors..........37
⛔ Unsupported.....37

Errors in agent/bifrost/config.json
[404] https://api.commandcode.ai/provider (at 23:22) | Rejected status code: 404 Not Found

Errors in agent/compose.yaml
[ERROR] http://localhost:2375/_ping (at 91:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8080/healthz (at 240:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:9119/api/status (at 49:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:9377/health (at 151:33) | Connection refused - server may be down or port blocked
[ERROR] https://hermes/ (at 9:67) | Connection failed. Check network connectivity and firewall settings
[ERROR] https://searxng/ (at 227:45) | Connection failed. Check network connectivity and firewall settings

Errors in arcane/compose.yaml
[ERROR] http://localhost:3552/ (at 6:27) | Connection refused - server may be down or port blocked

Errors in homeassistant/compose.yaml
[ERROR] http://localhost:10000/health (at 148:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:6052/version (at 107:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8095/ (at 66:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8123/ (at 27:33) | Connection refused - server may be down or port blocked

Errors in immich/compose.yaml
[ERROR] http://localhost:8080/api/status (at 164:32) | Connection refused - server may be down or port blocked

Errors in infra/compose.yaml
[ERROR] http://localhost:2375/_ping (at 62:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:9002/healthz (at 99:36) | Connection refused - server may be down or port blocked

Errors in monitoring/compose.yaml
[ERROR] http://localhost:8090/ (at 73:44) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8090/ (at 94:27) | Connection refused - server may be down or port blocked

Errors in pangolin/compose.yaml
[ERROR] http://gerbil:3004/ (at 63:23) | Connection failed. Check network connectivity and firewall settings
[ERROR] http://localhost/ping (at 126:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:3001/api/v1/ (at 51:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:3004/healthz (at 87:32) | Connection refused - server may be down or port blocked
[ERROR] http://pangolin:3001/api/v1/ (at 65:24) | Connection failed. Check network connectivity and firewall settings

Errors in pangolin/traefik/dynamic/config.yml
[ERROR] http://pangolin:3000/ (at 80:18) | Connection failed. Check network connectivity and firewall settings
[ERROR] http://pangolin:3002/ (at 85:18) | Connection failed. Check network connectivity and firewall settings

Errors in pangolin/traefik/traefik.template.yml
[ERROR] http://pangolin:3001/api/v1/traefik-config (at 7:15) | Connection failed. Check network connectivity and firewall settings

Errors in proxy/compose.yaml
[ERROR] http://localhost/healthz (at 36:32) | Connection refused - server may be down or port blocked
[ERROR] https://tinyauth/ (at 50:24) | Connection failed. Check network connectivity and firewall settings

Errors in security/compose.yaml
[ERROR] http://localhost:8080/ (at 52:16) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8080/health (at 34:32) | Connection refused - server may be down or port blocked

Errors in torrent/compose.yaml
[ERROR] http://localhost:6868/ (at 219:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:7878/ping (at 139:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8191/health (at 15:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8989/ping (at 181:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:9696/ping (at 44:33) | Connection refused - server may be down or port blocked
[ERROR] https://profilarr/ (at 204:15) | Connection failed. Check network connectivity and firewall settings

Errors in usenet/compose.yaml
[ERROR] http://localhost:7000/health (at 21:32) | Connection refused - server may be down or port blocked
[ERROR] https://aiostreams/ (at 57:18) | Connection failed. Check network connectivity and firewall settings

Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ REPOSITORY / osv-scanner - 1 warning
Scanning dir .
Starting filesystem walk for root: /
End status: 47 dirs visited, 157 inodes visited, 0 Extract calls, 3.125012ms elapsed, 3.125187ms wall time
No package sources found, --help for usage information.


[REPOSITORY_OSV_SCANNER_ERROR_NO_PACKAGE_SOURCES] osv-scanner found no lockfiles, manifests, or SBOMs to scan in the repository.
This is a configuration/scope issue, not a vulnerability finding.
Resolutions:
  - Verify the repository actually contains a supported lockfile (package-lock.json, go.sum, Gemfile.lock, Pipfile.lock, etc.) at the scanned path.
  - If this is expected for some sub-projects, disable osv-scanner for the affected paths or mark it non-blocking via `DISABLE_ERRORS_LINTERS`.
⚠️ ACTION / zizmor - 1 warning
INFO zizmor: 🌈 zizmor v1.25.0
 INFO audit: zizmor: 🌈 completed .github/workflows/automerge.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/megalinter.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/ossf.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/pr.yml
{
  "$schema": "https://docs.oasis-open.org/sarif/sarif/v2.1.0/os/schemas/sarif-schema-2.1.0.json",
  "runs": [
    {
      "invocations": [
        {
          "executionSuccessful": true
        }
      ],
      "results": [],
      "tool": {
        "driver": {
          "downloadUri": "https://github.com/zizmorcore/zizmor",
          "informationUri": "https://docs.zizmor.sh",
          "name": "zizmor",
          "rules": [],
          "semanticVersion": "1.25.0",
          "version": "1.25.0"
        }
      }
    }
  ],
  "version": "2.1.0"
No fixes available to apply.
}

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: REPOSITORY_KICS, TERRAFORM_TERRASCAN. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,ACTION_ZIZMOR,BASH_EXEC,BASH_SHELLCHECK,BASH_SHFMT,COPYPASTE_JSCPD,EDITORCONFIG_EDITORCONFIG_CHECKER,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@yxtay
yxtay enabled auto-merge (squash) October 4, 2026 02:40
@renovate
renovate Bot force-pushed the renovate/chromedp-headless-shell-155.x branch from 3cac46b to b0550e1 Compare October 4, 2026 05:28
@yxtay
yxtay merged commit 6f5f6e7 into main Oct 4, 2026
15 of 16 checks passed
@yxtay
yxtay deleted the renovate/chromedp-headless-shell-155.x branch October 4, 2026 05:29
@yxtay

yxtay commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Risk note: 155.0.8059.26 — this one is a safe, and actually the preferred, target

Investigated because this stack consumes chromedp/headless-shell only through
[[fastcrw]]'s chrome render rung (renderer:"chrome" → ws://chrome:9222/).

Verdict: no risk. This is the safest bump in the series — 155.0.8059.26 is the
:stable tag, so it is the channel Renovate should be following for this image.

Channel position (2026-10-04)

155.0.8059.26  ==  :stable  ==  :latest   (sha256:47e3a0c0…)
156.0.8078.4   ==  :beta
157.0.8081.0   ==  :dev

Chrome for Testing last-known-good: Stable 154.0.8037.92, Beta 156.0.8078.4,
Dev 157.0.8081.0. So this PR moves the stack 152 → 155 stable, closing the gap to
stable rather than overshooting it. This is the target I'd pick if the question is
"which of the three is lowest risk".

CDP surface

Diffed third_party/blink/public/devtools_protocol/domains/*.pdl between
152.0.7939.3 and 155.0.8059.26 on chromium.googlesource.com (source of truth, not
release notes). Across 155 vs 157 there is exactly one command removal and zero
domain removals, and nothing in the 152→155 window touches anything fastcrw calls.
fastcrw's renderer references only: Page, Runtime, Target, Network, DOM,
Emulation, Fetch, Browser, Inspector, Accessibility.

Live functional A/B

Second fastcrw instance (crw:0.37.2, identical config.docker.toml, chrome tier
repointed at a candidate container — prod agent-chrome-1 untouched), 4 URLs × 3 reps

  • 6-way concurrent burst, markdown length + PNG dimensions as the fidelity check:
URL result
example.com 200 · 976 md · 800×600
news.ycombinator.com 200 · 10939 md · 800×600
wikipedia/Chromium 200 · ~662k md · 800×600
httpbin.org/html 200 · 3597 md · 800×600
burst ×6 6/6 ok, 1.1–5.7s
container restarts 0

Markdown byte-length is identical to 156 and 157 on every URL; every screenshot decoded to
a valid 800×600 PNG. Latency indistinguishable. No crashes, no context leaks, no
Inspector.detached.

One operational note

The digest here (sha256:47e3a0c0cbef29e321d16c893cd804996243f710ca7855770dd4f9c4cd2b8627)
is what agent-chrome-1 is still running on this stack right now, even though
main's compose file has since moved on twice (see #707). So this bump's behaviour is
already proven in production, not just in my A/B. If the PR sequence is later
squashed/rewritten, this is the digest to fall back to.

Recommendation: keep this as the baseline. See #707 for the full comparison and the one
real caveat in the series (that #707 lands a dev-channel browser, two milestones ahead
of stable, with no point releases available to patch it).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant