Although Renovate is unaffected (https://github.com/renovatebot/renovate/pull/42067) we can see that Containerbase [is using](https://github.com/containerbase/base/blob/ad17fda293a1adaa15671313b346a32f3fd74ef9/.github/workflows/trivy.yml#L21), with very low permissions on the repo. We do not believe there is currently any impact. Investigating further