Skip to content

chore(deps): bump checkov from 3.2.531 to 3.3.23 in the pip group across 1 directory - #858

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/pip-4ccf0515dd
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/pip-4ccf0515dd

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the pip group with 1 update in the / directory: checkov.

Updates checkov from 3.2.531 to 3.3.23

Release notes

Sourced from checkov's releases.

3.3.23

Bug Fix

  • sca: apply --skip-path regex and hidden-dir filtering to sca_package - #7712

3.3.21

Bug Fix

  • terraform_json: handle HCL JSON array and single-dict block formats in parser - #7707

3.3.20

Bug Fix

  • terraform_plan: skip resources being removed from state ('forget' action) - #7676

3.3.19

Feature

  • terraform: add CKV_AWS_394 for unconstrained aws_availability_zones data source - #7658

3.3.17

Bug Fix

  • general: honour scope.provider for platform-downloaded custom po… - #7677

3.3.16

Bug Fix

  • terraform: Added current Azure Terraform resources and taggable resources as of hashicorp/azurerm provider version 4.81 - #7652

3.3.15

Bug Fix

  • sca: match CVE suppressions case-insensitively - #7659
  • sca: match CvesAccounts suppressions on unprefixed account ids - #7660

3.3.13

Bug Fix

  • kubernetes: Fix K8S suppressions annotations - #7651

3.3.12

Bug Fix

  • sca: correct Windows path handling in image referencer - #7650

3.3.9

Bug Fix

  • terraform: handle null container_properties in aws_batch_job_def… - #7636

... (truncated)

Changelog

Sourced from checkov's changelog.

3.3.23 - 2026-10-05

Bug Fix

  • sca: apply --skip-path regex and hidden-dir filtering to sca_package - #7712

3.3.21 - 2026-09-30

Bug Fix

  • terraform_json: handle HCL JSON array and single-dict block formats in parser - #7707

3.3.20 - 2026-09-27

Bug Fix

  • terraform_plan: skip resources being removed from state ('forget' action) - #7676

3.3.19 - 2026-09-17

Feature

  • terraform: add CKV_AWS_394 for unconstrained aws_availability_zones data source - #7658

3.3.17 - 2026-09-10

Bug Fix

  • general: honour scope.provider for platform-downloaded custom po… - #7677

3.3.16 - 2026-08-30

Bug Fix

  • terraform: Added current Azure Terraform resources and taggable resources as of hashicorp/azurerm provider version 4.81 - #7652

3.3.15 - 2026-08-27

Bug Fix

  • sca: match CVE suppressions case-insensitively - #7659
  • sca: match CvesAccounts suppressions on unprefixed account ids - #7660

3.3.13 - 2026-08-20

Bug Fix

  • kubernetes: Fix K8S suppressions annotations - #7651

3.3.12 - 2026-08-19

... (truncated)

Commits
  • 06b86ed fix(sca): apply --skip-path regex and hidden-dir filtering to sca_package (#7...
  • e7d3dd9 fix(sca): apply --skip-path regex and hidden-dir filtering to sca_package (#7...
  • 4ef6eb5 chore(secrets): bump bc-detect-secrets from 1.5.50 to 1.5.52 (#7708)
  • d93c9b6 chore(secrets): bump bc-detect-secrets from 1.5.50 to 1.5.52 (#7708)
  • 25dfc3a chore: update release notes
  • bbe2e10 chore: update release notes
  • e8c8dec fix(terraform_json): handle HCL JSON array and single-dict block formats in p...
  • 29ba174 chore: update release notes
  • d89e8dd fix(terraform_plan): skip resources being removed from state ('forget' action)
  • 06ac571 fix(terraform_plan): skip resources being removed from state ('forget' action...
  • Additional commits viewable in compare view

@dependabot
dependabot Bot requested a review from a team October 6, 2026 11:22
@dependabot dependabot Bot added dependencies Dependency updates security Security-related changes or concerns labels Oct 6, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: pip. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ❌ 1 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses.
See the Details below.

Vulnerabilities

requirements.txt

NameVersionVulnerabilitySeverity
ecdsa0.19.2Minerva timing attack on P-256 in python-ecdsahigh
Only included vulnerabilities with severity high or higher.

OpenSSF Scorecard

PackageVersionScoreDetails
pip/ecdsa 0.19.2 🟢 5
Details
CheckScoreReason
Code-Review🟢 3Found 5/15 approved changesets -- score normalized to 3
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained⚠️ 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Security-Policy🟢 10security policy file detected
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing🟢 10project is fuzzed
License🟢 9license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
SAST🟢 8SAST tool detected but not run on all commits
pip/bc-detect-secrets 1.5.52 UnknownUnknown
pip/checkov 3.3.23 🟢 7
Details
CheckScoreReason
Maintained🟢 1030 commit(s) out of 30 and 7 issue activity out of 30 found in the last 90 days -- score normalized to 10
Code-Review🟢 311 out of last 30 changesets reviewed before merge -- score normalized to 3
Vulnerabilities🟢 10no vulnerabilities detected
CII-Best-Practices⚠️ 2badge detected: in_progress
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 6branch protection is not maximal on development and all release branches
Token-Permissions⚠️ 0non read-only tokens detected in GitHub workflows
Security-Policy🟢 10security policy file detected
License🟢 10license file detected
Dependency-Update-Tool🟢 10update tool detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Fuzzing⚠️ 0project is not fuzzed
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 10no binaries found in the repo
Packaging🟢 10publishing workflow detected
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0

Scanned Files

  • requirements.txt

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should not merge this in, pull a vulnerable package

@dependabot dependabot Bot changed the title chore(deps): bump checkov from 3.2.531 to 3.3.22 in the pip group across 1 directory chore(deps): bump checkov from 3.2.531 to 3.3.23 in the pip group across 1 directory Oct 8, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/pip-4ccf0515dd branch from aa6ae84 to 26111e4 Compare October 8, 2026 12:21
Bumps the pip group with 1 update in the / directory: [checkov](https://github.com/bridgecrewio/checkov).


Updates `checkov` from 3.2.531 to 3.3.23
- [Release notes](https://github.com/bridgecrewio/checkov/releases)
- [Changelog](https://github.com/bridgecrewio/checkov/blob/main/CHANGELOG.md)
- [Commits](bridgecrewio/checkov@3.2.531...3.3.23)

---
updated-dependencies:
- dependency-name: checkov
  dependency-version: 3.3.22
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/pip-4ccf0515dd branch from 26111e4 to 0cf9f03 Compare October 8, 2026 13:36

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates security Security-related changes or concerns

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant