Skip to content

feat!: next-gen list module - #642

Open
chgl wants to merge 184 commits into
masterfrom
updated-list-module
Open

feat!: next-gen list module#642
chgl wants to merge 184 commits into
masterfrom
updated-list-module

Conversation

@chgl

@chgl chgl commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

No description provided.

Comment thread src/query-sql-on-fhir/src/main/resources/application.yml Fixed
@github-actions

github-actions Bot commented Aug 11, 2026

Copy link
Copy Markdown

⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 13 0 0 0.54s
✅ ACTION zizmor 13 0 0 7.63s
✅ BASH bash-exec 7 0 0 0.03s
✅ BASH shellcheck 3 0 0 0.27s
⚠️ BASH shfmt 7 3 0 0.01s
⚠️ CSHARP csharpier 83 1 0 50.73s
⚠️ CSHARP roslynator 4 2 0 98.81s
✅ CSS stylelint 5 0 0 3.2s
✅ DOCKERFILE hadolint 5 0 0 0.7s
✅ EDITORCONFIG editorconfig-checker 617 0 0 3.74s
✅ ENV dotenv-linter 1 0 0 0.01s
⚠️ GROOVY npm-groovy-lint 11 0 11 33.82s
✅ HTML djlint 2 0 0 3.12s
✅ HTML htmlhint 2 0 0 0.35s
⚠️ JAVA checkstyle 100 0 151 13.09s
✅ JSON jsonlint 87 0 0 0.68s
⚠️ JSON prettier 56 1 0 5.56s
✅ JSON v8r 87 0 0 58.36s
⚠️ MARKDOWN markdownlint 28 370 0 2.63s
✅ REPOSITORY betterleaks yes no no 1.69s
✅ REPOSITORY checkov yes no no 66.05s
✅ REPOSITORY gitleaks yes no no 6.82s
✅ REPOSITORY git_diff yes no no 0.37s
✅ REPOSITORY secretlint yes no no 6.21s
✅ REPOSITORY syft yes no no 18.77s
⚠️ REPOSITORY trivy yes 1 no 16.74s
✅ REPOSITORY trivy-sbom yes no no 5.69s
✅ REPOSITORY trufflehog yes no no 7.81s
✅ XML xmllint 5 0 0 1.32s
✅ YAML prettier 129 0 0 2.91s

Detailed Issues

⚠️ JAVA / checkstyle - 151 warnings

No output available

⚠️ CSHARP / csharpier - 1 error
Warning ./src/hack/config/trino/etc/jvm.config - Appeared to be invalid xml so was not formatted.
Error ./src/list-next/RecruIT.List/Services/Notify/EmailNotificationChannel.cs - Was not formatted.
  ----------------------------- Expected: Around Line 30 -----------------------------
              {
                  await client.AuthenticateAsync(
                      options.SmtpUsername,
  ----------------------------- Actual: Around Line 30 -----------------------------
              {
                  await client.AuthenticateAsync(options.SmtpUsername, options.SmtpPassword ?? "", ct);
              }
  
Checked 81 files in 50412ms.
⚠️ MARKDOWN / markdownlint - 370 errors
needed [Unused link or image reference definition: "list-belongs-to-study"] [Context: "[list-belongs-to-study]: Searc..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:7:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "observation-derived-from-library"] [Context: "[observation-derived-from-libr..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:8:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "eligibilityassessment"] [Context: "[EligibilityAssessment]: Struc..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:9:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "eligibilityassessmentcategory"] [Context: "[EligibilityAssessmentCategory..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:10:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "eligibilityassessmentresult"] [Context: "[EligibilityAssessmentResult]:..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:11:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "codesystemscreeninglist"] [Context: "[CodeSystemScreeningList]: Cod..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:12:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "recruitresearchstudy"] [Context: "[RecruitResearchStudy]: Struct..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:13:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "recruitresearchstudyexample"] [Context: "[RecruitResearchStudyExample]:..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:14:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "recruit-search-parameters-transaction"] [Context: "[recruit-search-parameters-tra..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:15:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "researchstudy-enrollment"] [Context: "[researchstudy-enrollment]: Se..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:16:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "research-subject-id"] [Context: "[research-subject-id]: NamingS..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:17:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "screeninglistbelongstostudy"] [Context: "[ScreeningListBelongsToStudy]:..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:18:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "screeninglist"] [Context: "[ScreeningList]: StructureDefi..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:19:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "screening-list-id"] [Context: "[screening-list-id]: NamingSys..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:20:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "superset-synced-eligibility-library-id"] [Context: "[superset-synced-eligibility-l..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:21:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "screeninglistexample"] [Context: "[ScreeningListExample]: List-S..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:22:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "ui-created-eligibility-library-id"] [Context: "[ui-created-eligibility-librar..."]
fhir/ig/fsh-generated/includes/fsh-link-references.md:23:78 error MD047/single-trailing-newline Files should end with a single newline character
fhir/ig/fsh-generated/includes/fsh-link-references.md:23:1 error MD053/link-image-reference-definitions Link and image reference definitions should be needed [Unused link or image reference definition: "ui-created-research-study-id"] [Context: "[ui-created-research-study-id]..."]

(Truncated to last 5000 characters out of 42170)
⚠️ GROOVY / npm-groovy-lint - 11 warnings

No output available

⚠️ JSON / prettier - 1 error
Checking formatting...
[warn] .config/dotnet-tools.json
[warn] Code style issues found in the above file. Run Prettier with --write to fix.
⚠️ CSHARP / roslynator - 2 errors
d no accessible extension method 'AddBlazorBlueprintComponents' accepting a first argument of type 'IServiceCollection' could be found (are you missing a using directive or an assembly reference?)
      Program.cs(127,6): error CS1061: 'IHealthChecksBuilder' does not contain a definition for 'AddNpgSql' and no accessible extension method 'AddNpgSql' accepting a first argument of type 'IHealthChecksBuilder' could be found (are you missing a using directive or an assembly reference?)
      Program.cs(130,15): error CS1061: 'IServiceCollection' does not contain a definition for 'AddOpenTelemetry' and no accessible extension method 'AddOpenTelemetry' accepting a first argument of type 'IServiceCollection' could be found (are you missing a using directive or an assembly reference?)
      Program.cs(165,18): error CS1061: 'IServiceCollection' does not contain a definition for 'AddDbContextFactory' and no accessible extension method 'AddDbContextFactory' accepting a first argument of type 'IServiceCollection' could be found (are you missing a using directive or an assembly reference?)
      Program.cs(181,18): error CS1061: 'IServiceCollection' does not contain a definition for 'AddDbContext' and no accessible extension method 'AddDbContext' accepting a first argument of type 'IServiceCollection' could be found (are you missing a using directive or an assembly reference?)
      Program.cs(184,38): error CS1061: 'IDataProtectionBuilder' does not contain a definition for 'PersistKeysToDbContext' and no accessible extension method 'PersistKeysToDbContext' accepting a first argument of type 'IDataProtectionBuilder' could be found (are you missing a using directive or an assembly reference?)
      Program.cs(191,18): error CS1061: 'IServiceCollection' does not contain a definition for 'AddHangfire' and no accessible extension method 'AddHangfire' accepting a first argument of type 'IServiceCollection' could be found (are you missing a using directive or an assembly reference?)
      Program.cs(200,18): error CS1061: 'IServiceCollection' does not contain a definition for 'AddHangfireServer' and no accessible extension method 'AddHangfireServer' accepting a first argument of type 'IServiceCollection' could be found (are you missing a using directive or an assembly reference?)
      Program.cs(312,36): error CS1061: 'DataProtectionKeyContext' does not contain a definition for 'Database' and no accessible extension method 'Database' accepting a first argument of type 'DataProtectionKeyContext' could be found (are you missing a using directive or an assembly reference?)
      Program.cs(374,5): error CS1061: 'WebApplication' does not contain a definition for 'UseHangfireDashboard' and no accessible extension method 'UseHangfireDashboard' accepting a first argument of type 'WebApplication' could be found (are you missing a using directive or an assembly reference?)
      Program.cs(388,5): error CS1061: 'WebApplication' does not contain a definition for 'MapPrometheusScrapingEndpoint' and no accessible extension method 'MapPrometheusScrapingEndpoint' accepting a first argument of type 'WebApplication' could be found (are you missing a using directive or an assembly reference?)
      Services/Notify/ScreeningListDiff.cs(27,36): error CS1061: 'Hl7.Fhir.Model.List?' does not contain a definition for 'Entry' and no accessible extension method 'Entry' accepting a first argument of type 'Hl7.Fhir.Model.List?' could be found (are you missing a using directive or an assembly reference?)
      Services/Fhir/ScreeningListService.cs(60,61): error CS1503: Argument 1: cannot convert from 'string' to '?'
      Services/Fhir/ScreeningListService.cs(127,68): error CS1503: Argument 1: cannot convert from 'string' to '?'
      Services/Fhir/ScreeningListService.cs(138,56): error CS1503: Argument 1: cannot convert from 'string' to '?'
      Services/Fhir/ScreeningListService.cs(259,50): error CS1503: Argument 1: cannot convert from 'string' to '?'
      Services/Fhir/ScreeningListService.cs(273,64): error CS1503: Argument 1: cannot convert from 'string' to '?'
      Services/Fhir/ScreeningListService.cs(280,67): error CS1503: Argument 1: cannot convert from 'string' to '?'
      Data/AppDbContext.cs(6,85): error CS1729: 'DbContext' does not contain a constructor that takes 1 arguments
      Data/DataProtectionKeyContext.cs(7,16): error CS1729: 'DbContext' does not contain a constructor that takes 1 arguments
      Program.cs(470,1): info ASP0027: Using public partial class Program { } to make the generated Program class public is no longer required in ASP.NET Core apps. See https://aka.ms/aspnetcore-warnings/ASP0027 for more details.
    Analyzed project 'src/list-next/RecruIT.List/RecruIT.List.csproj' (in 7.4 s)
    
      1 ASP0027 Unnecessary public Program class declaration
     39 CS0103  
     16 CS0234  
    193 CS0246  
      1 CS0311  
      1 CS0411  
     15 CS1061  
      6 CS1503  
      2 CS1729  
    
    274 diagnostics found



(Truncated to last 5000 characters out of 62396)
⚠️ BASH / shfmt - 3 errors
he/
 echo Checking internet connection...
-curl -sSf tx.fhir.org > /dev/null
+curl -sSf tx.fhir.org >/dev/null
 
 if [ $? -eq 0 ]; then
-	echo "Online"
-	txoption=""
-else
-	echo "Offline"
-	txoption="-tx n/a"
+  echo "Online"
+  txoption=""
+else
+  echo "Offline"
+  txoption="-tx n/a"
 fi
 
 echo "$txoption"
@@ -18,13 +18,13 @@
 
 publisher=$input_cache_path/$publisher_jar
 if test -f "$publisher"; then
-	java -jar $publisher -ig . $txoption $*
-
-else
-	publisher=../$publisher_jar
-	if test -f "$publisher"; then
-		java -jar $publisher -ig . $txoption $*
-	else
-		echo IG Publisher NOT FOUND in input-cache or parent folder.  Please run _updatePublisher.  Aborting...
-	fi
+  java -jar $publisher -ig . $txoption $*
+
+else
+  publisher=../$publisher_jar
+  if test -f "$publisher"; then
+    java -jar $publisher -ig . $txoption $*
+  else
+    echo IG Publisher NOT FOUND in input-cache or parent folder. Please run _updatePublisher. Aborting...
+  fi
 fi
diff fhir/ig/_updatePublisher.sh.orig fhir/ig/_updatePublisher.sh
--- fhir/ig/_updatePublisher.sh.orig
+++ fhir/ig/_updatePublisher.sh
@@ -18,63 +18,69 @@
 skipPrompts=false
 FORCE=false
 
-if ! type "curl" > /dev/null; then
-	echo "ERROR: Script needs curl to download latest IG Publisher. Please install curl."
-	exit 1
+if ! type "curl" >/dev/null; then
+  echo "ERROR: Script needs curl to download latest IG Publisher. Please install curl."
+  exit 1
 fi
 
 while [ "$#" -gt 0 ]; do
-    case $1 in
-    -f|--force)  FORCE=true ;;
-    -y|--yes)  skipPrompts=true ; FORCE=true ;;
-    *)  echo "Unknown parameter passed: $1.  Exiting"; exit 1 ;;
-    esac
-    shift
+  case $1 in
+  -f | --force) FORCE=true ;;
+  -y | --yes)
+    skipPrompts=true
+    FORCE=true
+    ;;
+  *)
+    echo "Unknown parameter passed: $1.  Exiting"
+    exit 1
+    ;;
+  esac
+  shift
 done
 
 echo "Checking internet connection"
-curl -sSf tx.fhir.org > /dev/null
-
-if [ $? -ne 0 ] ; then
+curl -sSf tx.fhir.org >/dev/null
+
+if [ $? -ne 0 ]; then
   echo "Offline (or the terminology server is down), unable to update.  Exiting"
   exit 1
 fi
 
-if [ ! -d "$input_cache_path" ] ; then
+if [ ! -d "$input_cache_path" ]; then
   if [ $FORCE != true ]; then
     echo "$input_cache_path does not exist"
     message="create it?"
     read -r -p "$message" response
-    else
+  else
     response=y
   fi
 fi
 
-if [[ $response =~ ^[yY].*$ ]] ; then
+if [[ $response =~ ^[yY].*$ ]]; then
   mkdir ./input-cache
 fi
 
 publisher="$input_cache_path$publisher_jar"
 
-if test -f "$publisher" ; then
-	echo "IG Publisher FOUND in input-cache"
-	jarlocation="$publisher"
-	jarlocationname="Input Cache"
-	upgrade=true
-else
-	publisher="../$publisher_jar"
-	upgrade=true
-	if test -f "$publisher"; then
-		echo "IG Publisher FOUND in parent folder"
-		jarlocation="$publisher"
-		jarlocationname="Parent Folder"
-		upgrade=true
-	else
-		echo "IG Publisher NOT FOUND in input-cache or parent folder"
-		jarlocation=$input_cache_path$publisher_jar
-		jarlocationname="Input Cache"
-		upgrade=false
-	fi
+if test -f "$publisher"; then
+  echo "IG Publisher FOUND in input-cache"
+  jarlocation="$publisher"
+  jarlocationname="Input Cache"
+  upgrade=true
+else
+  publisher="../$publisher_jar"
+  upgrade=true
+  if test -f "$publisher"; then
+    echo "IG Publisher FOUND in parent folder"
+    jarlocation="$publisher"
+    jarlocationname="Parent Folder"
+    upgrade=true
+  else
+    echo "IG Publisher NOT FOUND in input-cache or parent folder"
+    jarlocation=$input_cache_path$publisher_jar
+    jarlocationname="Input Cache"
+    upgrade=false
+  fi
 fi
 
 if [[ $skipPrompts == false ]]; then
@@ -91,16 +97,16 @@
 fi
 if [[ $skipPrompts == true ]] || [[ $response =~ ^[yY].*$ ]]; then
 
-	echo "Downloading most recent publisher to $jarlocationname - it's ~100 MB, so this may take a bit"
-	curl -L $dlurl -o "$jarlocation" --create-dirs
-else
-	echo cancelled publisher update
+  echo "Downloading most recent publisher to $jarlocationname - it's ~100 MB, so this may take a bit"
+  curl -L $dlurl -o "$jarlocation" --create-dirs
+else
+  echo cancelled publisher update
 fi
 
 if [[ $skipPrompts != true ]]; then
-    message="Update scripts? (enter 'y' or 'Y' to continue, any other key to cancel)?"
-    read -r -p "$message" response
-  fi
+  message="Update scripts? (enter 'y' or 'Y' to continue, any other key to cancel)?"
+  read -r -p "$message" response
+fi
 
 if [[ $skipPrompts == true ]] || [[ $response =~ ^[yY].*$ ]]; then
   echo "Downloading most recent scripts "
@@ -109,7 +115,6 @@
   cp /tmp/_build.new _build.bat
   rm /tmp/_build.new
 
-
   curl -L $build_sh_url -o /tmp/_build.new
   cp /tmp/_build.new _build.sh
   chmod +x _build.sh
@@ -135,7 +140,7 @@
   curl -L $gen_sh_url -o /tmp/_genonce.new
   cp /tmp/_genonce.new _genonce.sh
   chmod +x _genonce.sh
-  rm  /tmp/_genonce.new
+  rm /tmp/_genonce.new
 
   curl -L $update_sh_url -o /tmp/_updatePublisher.new
   cp /tmp/_updatePublisher.new _updatePublisher.sh

(Truncated to last 5000 characters out of 8195)
⚠️ REPOSITORY / trivy - 1 error

No output available

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.6.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,ACTION_ZIZMOR,BASH_EXEC,BASH_SHELLCHECK,BASH_SHFMT,CSHARP_CSHARPIER,CSHARP_ROSLYNATOR,CSS_STYLELINT,DOCKERFILE_HADOLINT,EDITORCONFIG_EDITORCONFIG_CHECKER,ENV_DOTENV_LINTER,GROOVY_NPM_GROOVY_LINT,HTML_DJLINT,HTML_HTMLHINT,JAVA_CHECKSTYLE,JSON_JSONLINT,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_BETTERLEAKS,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,XML_XMLLINT,YAML_PRETTIER

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

username: ""
# -- the password used to connect to the database. Injected as the `PGPASSWORD` env var.
# Ignored if `existingSecret.name` is set.
password: ""
@github-actions

Copy link
Copy Markdown

Trivy image scan report

ghcr.io/miracum/recruit/list:pr-642 (debian 13.6)

10 known vulnerabilities found (CRITICAL: 0 HIGH: 1 MEDIUM: 3 LOW: 6)

Show detailed table of vulnerabilities
Package ID Severity Installed Version Fixed Version
libssl3t64 CVE-2026-14456 HIGH 3.5.6-1~deb13u2 3.5.7-1~deb13u2
libssl3t64 CVE-2026-18798 MEDIUM 3.5.6-1~deb13u2 3.5.7-1~deb13u2
libssl3t64 CVE-2026-63072 MEDIUM 3.5.6-1~deb13u2 3.5.7-1~deb13u2
libssl3t64 CVE-2026-63076 MEDIUM 3.5.6-1~deb13u2 3.5.7-1~deb13u2
libssl3t64 CVE-2026-14457 LOW 3.5.6-1~deb13u2 3.5.7-1~deb13u2
libssl3t64 CVE-2026-54874 LOW 3.5.6-1~deb13u2 3.5.7-1~deb13u2
libssl3t64 CVE-2026-63073 LOW 3.5.6-1~deb13u2 3.5.7-1~deb13u2
libssl3t64 CVE-2026-63074 LOW 3.5.6-1~deb13u2 3.5.7-1~deb13u2
libssl3t64 CVE-2026-63075 LOW 3.5.6-1~deb13u2 3.5.7-1~deb13u2
libssl3t64 CVE-2026-75803 LOW 3.5.6-1~deb13u2 3.5.7-1~deb13u2

No Misconfigurations found

Node.js

No Vulnerabilities found

No Misconfigurations found

@github-actions

Copy link
Copy Markdown

Trivy image scan report

ghcr.io/miracum/recruit/list-next:pr-642 (ubuntu 26.04)

18 known vulnerabilities found (CRITICAL: 0 HIGH: 0 MEDIUM: 8 LOW: 10)

Show detailed table of vulnerabilities
Package ID Severity Installed Version Fixed Version
libssl3t64 CVE-2026-14456 MEDIUM 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
libssl3t64 CVE-2026-18798 MEDIUM 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
libssl3t64 CVE-2026-63072 MEDIUM 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
libssl3t64 CVE-2026-63076 MEDIUM 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
libssl3t64 CVE-2026-14457 LOW 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
libssl3t64 CVE-2026-54874 LOW 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
libssl3t64 CVE-2026-63073 LOW 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
libssl3t64 CVE-2026-63074 LOW 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
libssl3t64 CVE-2026-63075 LOW 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
openssl CVE-2026-14456 MEDIUM 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
openssl CVE-2026-18798 MEDIUM 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
openssl CVE-2026-63072 MEDIUM 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
openssl CVE-2026-63076 MEDIUM 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
openssl CVE-2026-14457 LOW 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
openssl CVE-2026-54874 LOW 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
openssl CVE-2026-63073 LOW 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
openssl CVE-2026-63074 LOW 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4
openssl CVE-2026-63075 LOW 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.4

No Misconfigurations found

app/RecruIT.List.deps.json

No Vulnerabilities found

No Misconfigurations found

usr/share/dotnet/shared/Microsoft.AspNetCore.App/10.0.11/Microsoft.AspNetCore.App.deps.json

No Vulnerabilities found

No Misconfigurations found

usr/share/dotnet/shared/Microsoft.NETCore.App/10.0.11/Microsoft.NETCore.App.deps.json

No Vulnerabilities found

No Misconfigurations found

@github-actions

Copy link
Copy Markdown

Trivy image scan report

ghcr.io/miracum/recruit/notify:pr-642 (debian 13.6)

8 known vulnerabilities found (CRITICAL: 0 HIGH: 4 MEDIUM: 3 LOW: 1)

Show detailed table of vulnerabilities
Package ID Severity Installed Version Fixed Version
libexpat1 CVE-2026-72522 MEDIUM 2.8.2-1~deb13u1 2.8.3-1~deb13u1
libuuid1 CVE-2026-53612 HIGH 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2026-53613 HIGH 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2026-53614 HIGH 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2026-53615 HIGH 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2026-13595 MEDIUM 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2026-27456 MEDIUM 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2025-14104 LOW 2.41-5 2.41.3-1

No Misconfigurations found

Java

11 known vulnerabilities found (CRITICAL: 1 HIGH: 4 MEDIUM: 6 LOW: 0)

Show detailed table of vulnerabilities
Package ID Severity Installed Version Fixed Version
ca.uhn.hapi.fhir:org.hl7.fhir.r4 CVE-2026-45367 HIGH 6.9.4.1 6.9.7
ca.uhn.hapi.fhir:org.hl7.fhir.r4 CVE-2026-49485 HIGH 6.9.4.1 6.9.9, 6.9.4.2
ca.uhn.hapi.fhir:org.hl7.fhir.utilities CVE-2026-55471 CRITICAL 6.9.4.1 6.9.10
com.fasterxml.jackson.core:jackson-databind CVE-2026-54515 MEDIUM 2.21.4 3.1.4, 2.18.9, 2.21.5, 2.22.1
com.fasterxml.jackson.core:jackson-databind CVE-2026-59889 MEDIUM 2.21.4 2.21.5, 2.18.9, 2.22.1
com.fasterxml.jackson.core:jackson-databind GHSA-mhm7-754m-9p8w MEDIUM 2.21.4 2.18.9, 2.21.5
org.apache.httpcomponents.client5:httpclient5 CVE-2026-64607 MEDIUM 5.6.1 5.6.3
org.apache.httpcomponents.core5:httpcore5 CVE-2026-54399 HIGH 5.4.2 5.4.3, 5.5-beta2
org.apache.httpcomponents.core5:httpcore5-h2 CVE-2026-54428 HIGH 5.4.2 5.4.3, 5.5-beta2
org.apache.logging.log4j:log4j-api CVE-2026-49844 MEDIUM 2.25.4 2.25.5, 2.26.1
tools.jackson.core:jackson-databind CVE-2026-59889 MEDIUM 3.1.4 3.1.5, 3.2.1

No Misconfigurations found

@github-actions

Copy link
Copy Markdown

Trivy image scan report

ghcr.io/miracum/recruit/superset-library-sync:pr-642 (debian 13.6)

8 known vulnerabilities found (CRITICAL: 0 HIGH: 4 MEDIUM: 3 LOW: 1)

Show detailed table of vulnerabilities
Package ID Severity Installed Version Fixed Version
libexpat1 CVE-2026-72522 MEDIUM 2.8.2-1~deb13u1 2.8.3-1~deb13u1
libuuid1 CVE-2026-53612 HIGH 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2026-53613 HIGH 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2026-53614 HIGH 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2026-53615 HIGH 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2026-13595 MEDIUM 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2026-27456 MEDIUM 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2025-14104 LOW 2.41-5 2.41.3-1

No Misconfigurations found

Java

12 known vulnerabilities found (LOW: 0 CRITICAL: 1 HIGH: 4 MEDIUM: 7)

Show detailed table of vulnerabilities
Package ID Severity Installed Version Fixed Version
at.yawk.lz4:lz4-java CVE-2026-59949 MEDIUM 1.10.1 1.11.1
ca.uhn.hapi.fhir:org.hl7.fhir.r4 CVE-2026-45367 HIGH 6.9.4.1 6.9.7
ca.uhn.hapi.fhir:org.hl7.fhir.r4 CVE-2026-49485 HIGH 6.9.4.1 6.9.9, 6.9.4.2
ca.uhn.hapi.fhir:org.hl7.fhir.utilities CVE-2026-55471 CRITICAL 6.9.4.1 6.9.10
com.fasterxml.jackson.core:jackson-databind CVE-2026-54515 MEDIUM 2.21.4 3.1.4, 2.18.9, 2.21.5, 2.22.1
com.fasterxml.jackson.core:jackson-databind CVE-2026-59889 MEDIUM 2.21.4 2.21.5, 2.18.9, 2.22.1
com.fasterxml.jackson.core:jackson-databind GHSA-mhm7-754m-9p8w MEDIUM 2.21.4 2.18.9, 2.21.5
org.apache.httpcomponents.client5:httpclient5 CVE-2026-64607 MEDIUM 5.6.1 5.6.3
org.apache.httpcomponents.core5:httpcore5 CVE-2026-54399 HIGH 5.4.2 5.4.3, 5.5-beta2
org.apache.httpcomponents.core5:httpcore5-h2 CVE-2026-54428 HIGH 5.4.2 5.4.3, 5.5-beta2
org.apache.logging.log4j:log4j-api CVE-2026-49844 MEDIUM 2.25.4 2.25.5, 2.26.1
tools.jackson.core:jackson-databind CVE-2026-59889 MEDIUM 3.1.4 3.1.5, 3.2.1

No Misconfigurations found

@github-actions

Copy link
Copy Markdown

Trivy image scan report

ghcr.io/miracum/recruit/query:pr-642 (debian 13.6)

8 known vulnerabilities found (CRITICAL: 0 HIGH: 4 MEDIUM: 3 LOW: 1)

Show detailed table of vulnerabilities
Package ID Severity Installed Version Fixed Version
libexpat1 CVE-2026-72522 MEDIUM 2.8.2-1~deb13u1 2.8.3-1~deb13u1
libuuid1 CVE-2026-53612 HIGH 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2026-53613 HIGH 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2026-53614 HIGH 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2026-53615 HIGH 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2026-13595 MEDIUM 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2026-27456 MEDIUM 2.41-5 2.41.5-0+deb13u1
libuuid1 CVE-2025-14104 LOW 2.41-5 2.41.3-1

No Misconfigurations found

Java

33 known vulnerabilities found (MEDIUM: 13 LOW: 0 CRITICAL: 1 HIGH: 19)

Show detailed table of vulnerabilities
Package ID Severity Installed Version Fixed Version
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 CVE-2026-45367 HIGH 6.9.4.1 6.9.7
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 CVE-2026-49485 HIGH 6.9.4.1 6.9.9, 6.9.4.2
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 CVE-2026-55470 HIGH 6.9.4.1 6.9.10
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may CVE-2026-45367 HIGH 6.9.4.1 6.9.7
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may CVE-2026-49485 HIGH 6.9.4.1 6.9.9, 6.9.4.2
ca.uhn.hapi.fhir:org.hl7.fhir.dstu3 CVE-2026-45367 HIGH 6.9.4.1 6.9.7
ca.uhn.hapi.fhir:org.hl7.fhir.dstu3 CVE-2026-49485 HIGH 6.9.4.1 6.9.9, 6.9.4.2
ca.uhn.hapi.fhir:org.hl7.fhir.r4 CVE-2026-45367 HIGH 6.9.4.1 6.9.7
ca.uhn.hapi.fhir:org.hl7.fhir.r4 CVE-2026-49485 HIGH 6.9.4.1 6.9.9, 6.9.4.2
ca.uhn.hapi.fhir:org.hl7.fhir.r5 CVE-2026-45367 HIGH 6.9.4.1 6.9.7
ca.uhn.hapi.fhir:org.hl7.fhir.r5 CVE-2026-49485 HIGH 6.9.4.1 6.9.9, 6.9.4.2
ca.uhn.hapi.fhir:org.hl7.fhir.utilities CVE-2026-55471 CRITICAL 6.9.4.1 6.9.10
com.fasterxml.jackson.core:jackson-databind CVE-2026-54515 MEDIUM 2.21.4 3.1.4, 2.18.9, 2.21.5, 2.22.1
com.fasterxml.jackson.core:jackson-databind CVE-2026-59889 MEDIUM 2.21.4 2.21.5, 2.18.9, 2.22.1
com.fasterxml.jackson.core:jackson-databind GHSA-mhm7-754m-9p8w MEDIUM 2.21.4 2.18.9, 2.21.5
io.netty:netty-codec-compression CVE-2026-59901 HIGH 4.2.15.Final 4.2.16.Final
io.netty:netty-codec-dns CVE-2026-73508 MEDIUM 4.2.15.Final 4.2.16.Final, 4.1.136.Final
io.netty:netty-codec-http CVE-2026-55831 HIGH 4.2.15.Final 4.2.16.Final, 4.1.136.Final
io.netty:netty-codec-http CVE-2026-55833 HIGH 4.2.15.Final 4.2.16.Final, 4.1.136.Final
io.netty:netty-codec-http CVE-2026-56745 HIGH 4.2.15.Final 4.2.16.Final, 4.1.136.Final
io.netty:netty-codec-http CVE-2026-56746 MEDIUM 4.2.15.Final 4.2.16.Final, 4.1.136.Final
io.netty:netty-codec-http CVE-2026-59898 MEDIUM 4.2.15.Final 4.2.16.Final, 4.1.136.Final
io.netty:netty-codec-http CVE-2026-59899 MEDIUM 4.2.15.Final 4.2.16.Final, 4.1.136.Final
io.netty:netty-codec-http CVE-2026-59903 MEDIUM 4.2.15.Final 4.2.17.Final, 4.1.137.Final
io.netty:netty-codec-http CVE-2026-59921 MEDIUM 4.2.15.Final 4.2.16.Final, 4.1.136.Final
io.netty:netty-codec-http2 CVE-2026-56819 HIGH 4.2.15.Final 4.2.16.Final, 4.1.136.Final
io.netty:netty-codec-http2 CVE-2026-59900 MEDIUM 4.2.15.Final 4.2.16.Final, 4.1.136.Final
io.netty:netty-codec-http3 CVE-2026-56816 HIGH 4.2.15.Final 4.2.16.Final
org.apache.httpcomponents.client5:httpclient5 CVE-2026-64607 MEDIUM 5.6.1 5.6.3
org.apache.httpcomponents.core5:httpcore5 CVE-2026-54399 HIGH 5.4.2 5.4.3, 5.5-beta2
org.apache.httpcomponents.core5:httpcore5-h2 CVE-2026-54428 HIGH 5.4.2 5.4.3, 5.5-beta2
org.apache.logging.log4j:log4j-api CVE-2026-49844 MEDIUM 2.25.4 2.25.5, 2.26.1
tools.jackson.core:jackson-databind CVE-2026-59889 MEDIUM 3.1.4 3.1.5, 3.2.1

No Misconfigurations found

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants