chore(deps): update tools (main) - #388
Merged
Merged
Conversation
octo-sts
Bot
force-pushed
the
renovate/main-tools
branch
from
September 2, 2025 12:29
5d418ab to
7498245
Compare
Signed-off-by: Renovate Bot <renovate-bot@users.noreply.github.com>
octo-sts
Bot
force-pushed
the
renovate/main-tools
branch
from
September 2, 2025 17:50
7498245 to
d9e7075
Compare
Member
|
/approve |
Contributor
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: inteon The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.65.0->v0.66.0v1.30.0->v1.32.0v2.76.2->v2.78.0v2.3.0->v2.4.0v0.35.0->v0.36.0v1.36.7->v1.36.8v1.20.2->v1.20.3Release Notes
aquasecurity/trivy (aquasecurity/trivy)
v0.66.0Compare Source
Changelog
7bcb181release: v0.66.0 [main] (#9289)2125895chore(deps): bump the aws group with 7 updates (#9419)29e9ff7refactor(secret): clarify secret scanner messages (#9409)46ab76afix(cyclonedx): handle multiple license types (#9378)1ac9b1ffix(repo): sanitize git repo URL before inserting into report metadata (#9391)6fa3849test: add HTTP basic authentication to git test server (#9407)aa7cf43fix(sbom): add support forfilecomponent type ofCycloneDX(#9372)81d9425fix(misconf): ensure module source is known (#9404)1d646d6ci: migrate GitHub Actions from version tags to SHA pinning (#9405)ce22f54fix: create temp file under composite fs dir (#9387)db19b34chore(deps): bump github.com/ulikunitz/xz from 0.5.12 to 0.5.14 (#9403)d1de58arefactor: switch to stable azcontainerregistry SDK package (#9319)102cbeechore(deps): bump the common group with 7 updates (#9382)7278718refactor(misconf): migrate from custom Azure JSON parser (#9222)4f2a44efix(repo): preserve RepoMetadata on FS cache hit (#9389)9594d63refactor(misconf): use atomic.Int32 (#9385)8abde2cchore(deps): bump the aws group with 6 updates (#9383)2bbad03docs: Fix broken link to "Built-in Checks" (#9375)5f067acfix(plugin): don't remove plugins when updating index.yaml file (#9358)6e99dd3fix: persistent flag option typo (#9374)d1adbe3chore(deps): bump the common group across 1 directory with 26 updates (#9347)84fbf86fix(image): use standardized HTTP client for ECR authentication (#9322)04abb78refactor: exportsystemFileFilteringPost Handler (#9359)e2d30fedocs: update links to Semaphore pages (#9352)03d039ffix(conda): memory leak by adding closure method forpackage.jsonfile (#9349)235c24efeat: add timeout handling for cache database operations (#9307)04ad0c4fix(misconf): use correct field log_bucket instead of target_bucket in gcp bucket (#9296)d3cd101fix(misconf): ensure ignore rules respect subdirectory chart paths (#9324)ea6663achore(deps): bump alpine from 3.21.4 to 3.22.1 (#9301)298a994feat(terraform): use .terraform cache for remote modules in plan scanning (#9277)c9cb3d1chore: fix some function names in comment (#9314)b7b4910chore(deps): bump the aws group with 7 updates (#9311)c3efe5ddocs: add explanation for how to use non-system certificates (#9081)406c209chore(deps): bump the github-actions group across 1 directory with 2 updates (#8962)1319d8dfix(misconf): preserve original paths of remote submodules from .terraform (#9294)c0bd700refactor(terraform): make Scan method of Terraform plan scanner private (#9272)2458d5efix: suppress debug log for context cancellation errors (#9298)5a5e097feat(secret): implement streaming secret scanner with byte offset tracking (#9264)1473e88fix(python): impove package name normalization (#9290)4d4a244feat(misconf): added audit config attribute (#9249)649eb2frefactor(misconf): decouple input fs and track extracted files with fs references (#9281)b77d6e2test(misconf): remove BenchmarkCalculate using outdated check metadata (#9291)b9fb7e5refactor: simplify Detect function signature (#9280)44aac2cci(helm): bump Trivy version to 0.65.0 for Trivy Helm Chart 0.17.0 (#9288)b51c789fix(fs): avoid shadowing errors in file.glob (#9286)c4003b2test(misconf): move terraform scan tests to integration tests (#9271)a590743test(misconf): drop gcp iam test covered by another case (#9285)04d018bchore(deps): bump to alpine from3.21.3to3.21.4(#9283)anchore/syft (github.com/anchore/syft)
v1.32.0Compare Source
Added Features
Bug Fixes
Additional Changes
(Full Changelog)
v1.31.0Compare Source
Added Features
PackageSupplierin root of SPDX document generated by CLI [#3098 #4131 @spiffcs]Bug Fixes
Bundle-Licensefield of manifest [#3186](Full Changelog)
cli/cli (github.com/cli/cli/v2)
v2.78.0: GitHub CLI 2.78.0Compare Source
ℹ️ Note
This release was cut primarily to resolve a Linux package distribution issue. We recommend reviewing the v2.77.0 release notes for the complete set of latest features and fixes.
What's Changed
✨ Features
--forceflag togh run cancelby @ankddev in #11513🐛 Fixes
Full Changelog: cli/cli@v2.77.0...v2.78.0
v2.77.0: GitHub CLI 2.77.0Compare Source
The v2.77.0 release experienced a failure publishing to our official Linux repos. This is resolved in v2.78.0, so we recommend using that release instead.
What's Changed
✨ Features
gh issue viewby @andyfeller in #11496gh pr viewoutput by @andyfeller in #11497🐛 Fixes
gh repo delete --yessafety issue when no repository argument provided by @Copilot in #11536📚 Docs & Chores
help wantedlabel regexp in CI automation by @babakks in #11423gh searchdocs to explain the usage of--to exclude certain results by @Sukhpreet-s in #11162New Contributors
Full Changelog: cli/cli@v2.76.2...v2.77.0
golangci/golangci-lint (github.com/golangci/golangci-lint/v2)
v2.4.0Compare Source
exhaustruct: from v3.3.1 to 4.0.0 (new options:allow-empty,allow-empty-rx,allow-empty-returns,allow-empty-declarations)godox: trim filepath from report messagesstaticcheck: allow empty optionstagalign: from 1.4.2 to 1.4.3v2.3.1Compare Source
gci: from 0.13.6 to 0.13.7gosec: from 2.22.6 to 2.22.7noctx: from 0.3.5 to 0.4.0wsl: from 5.1.0 to 5.1.1protocolbuffers/protobuf-go (google.golang.org/protobuf)
v1.36.8Compare Source
Maintenance:
CL/696316: all: set Go language version to Go 1.23
CL/696315: types: regenerate using latest protobuf v32 release
hashicorp/vault (hashicorp/vault)
v1.20.3Compare Source
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Renovate Bot.