Skip to content

Conversation

@arunavo4
Copy link
Collaborator

@arunavo4 arunavo4 commented Nov 8, 2025

No description provided.

@arunavo4 arunavo4 self-assigned this Nov 8, 2025
@cloudflare-workers-and-pages
Copy link

Deploying gitea-mirror-website with  Cloudflare Pages  Cloudflare Pages

Latest commit: 4900596
Status: ✅  Deploy successful!
Preview URL: https://bf2b5f70.gitea-mirror-website.pages.dev
Branch Preview URL: https://bun-v1-3-1.gitea-mirror-website.pages.dev

View logs

@github-actions
Copy link

github-actions bot commented Nov 8, 2025

🐳 Docker Image Built Successfully

Your PR image is available for testing:

Image Tag: pr-149
Full Image Path: ghcr.io/raylabshq/gitea-mirror:pr-149

Pull and Test

docker pull ghcr.io/raylabshq/gitea-mirror:pr-149
docker run -d   -p 4321:4321   -e BETTER_AUTH_SECRET=your-secret-here   -e BETTER_AUTH_URL=http://localhost:4321   --name gitea-mirror-test ghcr.io/raylabshq/gitea-mirror:pr-149

Docker Compose Testing

services:
  gitea-mirror:
    image: ghcr.io/raylabshq/gitea-mirror:pr-149
    ports:
      - "4321:4321"
    environment:
      - BETTER_AUTH_SECRET=your-secret-here
      - BETTER_AUTH_URL=http://localhost:4321
      - BETTER_AUTH_TRUSTED_ORIGINS=http://localhost:4321

💡 Note: PR images are tagged as pr-<number> and built for both linux/amd64 and linux/arm64.
Production images (latest, version tags) use the same multi-platform set.


📦 View in GitHub Packages

@github-actions
Copy link

github-actions bot commented Nov 8, 2025

🔍 Vulnerabilities of gitea-mirror:scan

📦 Image Reference gitea-mirror:scan
digestsha256:eeca510b52b21088945763656bb85e61c6adf4efe7a56dddf31a298526997b36
vulnerabilitiescritical: 0 high: 5 medium: 0 low: 0
platformlinux/amd64
size304 MB
packages894
📦 Base Image alpine:3.20
also known as
  • 3.20.8
  • 7723689796d2bbfe038446faac416211f2eb48871669de9e7d0196db78c44ce1
digestsha256:008827ed2172a676b08121e21cf9db0ce08a90ee6c8a12fc374af8a56c0e496d
vulnerabilitiescritical: 0 high: 0 medium: 0 low: 2
critical: 0 high: 4 medium: 0 low: 0 stdlib 1.23.12 (golang)

pkg:golang/[email protected]

high : CVE--2025--61725

Affected range<1.24.8
Fixed version1.24.8
EPSS Score0.075%
EPSS Percentile23rd percentile
Description

The ParseAddress function constructeds domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.

high : CVE--2025--61723

Affected range<1.24.8
Fixed version1.24.8
EPSS Score0.075%
EPSS Percentile23rd percentile
Description

The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input.

This affects programs which parse untrusted PEM inputs.

high : CVE--2025--58188

Affected range<1.24.8
Fixed version1.24.8
EPSS Score0.033%
EPSS Percentile9th percentile
Description

Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method.

This affects programs which validate arbitrary certificate chains.

high : CVE--2025--58187

Affected range<1.24.9
Fixed version1.24.9
EPSS Score0.017%
EPSS Percentile3rd percentile
Description

Due to the design of the name constraint checking algorithm, the processing time of some inputs scals non-linearly with respect to the size of the certificate.

This affects programs which validate arbitrary certificate chains.

critical: 0 high: 1 medium: 0 low: 0 sqlite 3.45.3-r2 (apk)

pkg:apk/alpine/[email protected]?os_name=alpine&os_version=3.20

high : CVE--2025--6965

Affected range<=3.45.3-r2
Fixed versionNot Fixed
EPSS Score0.037%
EPSS Percentile11th percentile
Description

@github-actions
Copy link

github-actions bot commented Nov 8, 2025

Recommended fixes for local gitea-mirror:scan

Base image is alpine:3.20

Name3.20.8
Digestsha256:008827ed2172a676b08121e21cf9db0ce08a90ee6c8a12fc374af8a56c0e496d
Vulnerabilitiescritical: 0 high: 0 medium: 0 low: 2
Pushed1 month ago
Size3.6 MB
Packages17
OS3.20.8
The base image is also available under the supported tag(s): 3.20.8

Refresh base image

Rebuild the image using a newer base image version. Updating this may result in breaking changes.

✅ This image version is up to date.

Change base image

TagDetailsPushedVulnerabilities
3.21
Tag is preferred tag
Also known as:
  • 3.21.5
Benefits:
  • Minor OS version update
  • Tag is preferred tag
  • Image has similar size
  • Image has same number of vulnerabilities
Image details:
  • Size: 3.6 MB
  • OS: 3.21.5
1 month ago



3.22
Tag is latest
Also known as:
  • 3.22.2
  • 3
  • latest
Benefits:
  • Minor OS version update
  • Image has similar size
  • Tag is latest
  • Image has same number of vulnerabilities
Image details:
  • Size: 3.8 MB
  • OS: 3.22.2
1 month ago



@github-actions
Copy link

github-actions bot commented Nov 8, 2025

Overview

Image reference ghcr.io/raylabshq/gitea-mirror:latest gitea-mirror:scan
- digest 317c4f9d4f80 eeca510b52b2
- tag latest scan
- provenance 4900596 oven-sh/bun@89fa0f3
- vulnerabilities critical: 0 high: 5 medium: 12 low: 4 critical: 0 high: 5 medium: 12 low: 4
- platform linux/amd64 linux/amd64
- size 262 MB 304 MB (+42 MB)
- packages 894 894
Base Image alpine:3.20
also known as:
3.20.8
alpine:3.20
also known as:
3.20.8
- vulnerabilities critical: 0 high: 0 medium: 0 low: 2 critical: 0 high: 0 medium: 0 low: 2
Labels (8 changes)
  • ± 8 changed
-org.opencontainers.image.created=2025-11-08T02:28:54.774Z
+org.opencontainers.image.created=2025-10-22T07:56:38.047Z
-org.opencontainers.image.description=Gitea Mirror auto-syncs GitHub repos to your self-hosted Gitea/Forgejo, with a sleek Web UI and easy Docker deployment.
+org.opencontainers.image.description=Incredibly fast JavaScript runtime, bundler, test runner, and package manager – all in one
-org.opencontainers.image.licenses=AGPL-3.0
+org.opencontainers.image.licenses=NOASSERTION
-org.opencontainers.image.revision=490059666f368c8add12f893ae3b9b0e45a4959b
+org.opencontainers.image.revision=89fa0f343945e61d5e4a0077cc7e93a802ed56e7
-org.opencontainers.image.source=https://github.com/RayLabsHQ/gitea-mirror
+org.opencontainers.image.source=https://github.com/oven-sh/bun
-org.opencontainers.image.title=gitea-mirror
+org.opencontainers.image.title=bun
-org.opencontainers.image.url=https://github.com/RayLabsHQ/gitea-mirror
+org.opencontainers.image.url=https://github.com/oven-sh/bun
-org.opencontainers.image.version=pr-149
+org.opencontainers.image.version=1.3.1-alpine

@arunavo4 arunavo4 merged commit d0cade6 into main Nov 8, 2025
8 checks passed
@arunavo4 arunavo4 deleted the bun-v1.3.1 branch November 8, 2025 02:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants