Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Oct 4, 2025

Note: This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change OpenSSF
anchore/syft minor v1.18.1 β†’ v1.40.0 OpenSSF Scorecard
aquaproj/aqua minor v2.42.2 β†’ v2.56.3 OpenSSF Scorecard
aquaproj/aqua-installer action patch v4.0.3 β†’ v4.0.4 OpenSSF Scorecard
aquaproj/aqua-registry minor v4.296.0 β†’ v4.454.0 OpenSSF Scorecard
charmbracelet/glow minor v2.0.0 β†’ v2.1.1 OpenSSF Scorecard
cli/cli minor v2.65.0 β†’ v2.83.2 OpenSSF Scorecard
direnv/direnv minor v2.35.0 β†’ v2.37.1 OpenSSF Scorecard
git-town/git-town minor v17.2.0 β†’ v17.3.0 OpenSSF Scorecard
golang/go minor 1.23.5 β†’ 1.25.5 OpenSSF Scorecard
golangci/golangci-lint minor v1.63.4 β†’ v1.64.8 OpenSSF Scorecard
goreleaser/goreleaser minor v2.5.1 β†’ v2.13.3 OpenSSF Scorecard
mikefarah/yq minor v4.45.1 β†’ v4.50.1 OpenSSF Scorecard
miniscruff/changie minor v1.21.0 β†’ v1.24.0 OpenSSF Scorecard
mvdan/gofumpt minor v0.7.0 β†’ v0.9.2 OpenSSF Scorecard

Release Notes

anchore/syft (anchore/syft)

v1.40.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v1.39.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v1.38.2

Compare Source

Bug Fixes

(Full Changelog)

v1.38.0

Compare Source

Added Features
Bug Fixes
  • Support extras statements in Python PDM cataloger [#​4352 @​wagoodman]
  • Preserve --from argument order [#​4350 @​wagoodman]
  • SBOM generated by Syft 1.28 contains license elements missing id or name (causing CycloneDX parser error) [#​4363]
  • empty PURL output in dependency snapshot format breaks sbom-action [#​4311]
  • Interface includes constraint elements, can only be used in type parameters [#​4346]
  • Upgrade github.com/nwaples/rardecode@​v1.1.3 to 2.2.1 [#​4338]
  • Upgrade to Golang 1.25.4 [#​4341]
Additional Changes

(Full Changelog)

v1.37.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v1.36.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v1.34.2

Compare Source

Bug Fixes

(Full Changelog)

v1.34.1

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v1.33.0

Compare Source

Added Features

(Full Changelog)

v1.32.0

Compare Source

Added Features
Bug Fixes
Additional Changes

(Full Changelog)

v1.31.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v1.30.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v1.29.1

Compare Source

Bug Fixes

(Full Changelog)

v1.29.0

Compare Source

Added Features
Additional Changes

(Full Changelog)

v1.28.0

Compare Source

Added Features
Additional Changes

(Full Changelog)

v1.27.1

Compare Source

Bug Fixes
Additional Changes

(Full Changelog)

v1.27.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

A HUGE thank you to @​rezmoss for his help identifying and solving an issue causing excessive time and memory consumption with large numbers of symlinks! ❀️

v1.26.1

Compare Source

Bug Fixes

(Full Changelog)

v1.26.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v1.25.1

Compare Source

Additional Changes

(Full Changelog)

v1.25.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v1.24.0

Compare Source

Added Features
Bug Fixes
Additional Changes

(Full Changelog)

v1.23.1

Compare Source

Additional Changes

(Full Changelog)

v1.23.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v1.22.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v1.21.0

Compare Source

Added Features
Bug Fixes
Additional Changes

(Full Changelog)

v1.20.0

Compare Source

Added Features
Bug Fixes
Additional Changes

(Full Changelog)

v1.19.0

Compare Source

Added Features
Bug Fixes
Additional Changes

(Full Changelog)

aquaproj/aqua (aquaproj/aqua)

v2.56.3

Compare Source

πŸ› Bug Fixes

#​4475 cp: Fix a bug that command arguments are ignored and always all commands are copied
#​4476 update-aqua: Fix a bug that a command argument is ignored and always the latest version is installed

Others

#​4471 Update sigstore/cosign to v3.0.4

v2.56.2

Compare Source

Refactoring

#​4448 Replace logrus with slog
#​4450 Use urfave/cli/v3 Destination pattern for flag values

v2.56.1

Compare Source

Fixes

#​4436 gr: Exclude eabihf

v2.56.0

Compare Source

Features

#​4422 Get pseudo-versions from Go Proxy if no tagged version exists @​gizmoguy

Fixes

#​4401 Add YAML tags @​Shion1305
#​4404 Update golangci-lint to v2.7.2, with lint fixes @​Shion1305

Dependency Updates

#​4402 Update goreleaser to v2.13.1
#​4405 Update anchore/syft to v1.38.2
#​4406 Update Cosign to v3.0.3
#​4420 Update expr to v1.17.7
[#​4424](https://re


Configuration

πŸ“… Schedule: Branch creation - "after 10pm on monday,before 3am on monday" in timezone America/Chicago, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

β™» Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

πŸ‘» Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from a team as a code owner October 4, 2025 18:32
@renovate renovate bot added the dependencies label Oct 4, 2025
@renovate renovate bot enabled auto-merge (squash) October 4, 2025 18:32
renovate-approve[bot]
renovate-approve bot previously approved these changes Oct 4, 2025
@snyk-io
Copy link

snyk-io bot commented Oct 4, 2025

βœ… Snyk checks have passed. No issues have been found so far.

Status Scanner Critical High Medium Low Total (0)
βœ… Open Source Security 0 0 0 0 0 issues
βœ… Licenses 0 0 0 0 0 issues
βœ… Code Security 0 0 0 0 0 issues

πŸ’» Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

sheldonhull
sheldonhull previously approved these changes Oct 4, 2025
renovate-approve[bot]
renovate-approve bot previously approved these changes Oct 4, 2025
renovate-approve[bot]
renovate-approve bot previously approved these changes Oct 6, 2025
renovate-approve[bot]
renovate-approve bot previously approved these changes Oct 7, 2025
renovate-approve[bot]
renovate-approve bot previously approved these changes Oct 7, 2025
renovate-approve[bot]
renovate-approve bot previously approved these changes Oct 8, 2025
renovate-approve[bot]
renovate-approve bot previously approved these changes Oct 9, 2025
renovate-approve[bot]
renovate-approve bot previously approved these changes Oct 10, 2025
renovate-approve[bot]
renovate-approve bot previously approved these changes Dec 28, 2025
renovate-approve[bot]
renovate-approve bot previously approved these changes Dec 29, 2025
renovate-approve[bot]
renovate-approve bot previously approved these changes Dec 30, 2025
renovate-approve[bot]
renovate-approve bot previously approved these changes Jan 1, 2026
renovate-approve[bot]
renovate-approve bot previously approved these changes Jan 3, 2026
renovate-approve[bot]
renovate-approve bot previously approved these changes Jan 8, 2026
renovate-approve[bot]
renovate-approve bot previously approved these changes Jan 8, 2026
renovate-approve[bot]
renovate-approve bot previously approved these changes Jan 9, 2026
renovate-approve[bot]
renovate-approve bot previously approved these changes Jan 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants