Skip to content

Commit 3062eef

Browse files
fix(deps): update all non-major dependencies
1 parent 65d83da commit 3062eef

File tree

9 files changed

+106
-138
lines changed

9 files changed

+106
-138
lines changed

.github/workflows/deps-renovate.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,8 +14,8 @@ jobs:
1414
name: Check renovate config
1515
runs-on: ubuntu-latest
1616
steps:
17-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
17+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
1818
- name: Validate renovate config
19-
uses: docker://renovate/renovate:latest@sha256:213766a5c66a27813e589459ec282a16848f43bc3bd10b07b61a12eeacbe233f
19+
uses: docker://renovate/renovate:latest@sha256:afab3f24ed9fb01de2a28e15e9683d765ba20448f00ecee8dcc246c2ea9132ed
2020
with:
2121
args: renovate-config-validator

.github/workflows/deps-review.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -17,11 +17,11 @@ jobs:
1717
runs-on: ubuntu-latest
1818
steps:
1919
- name: Harden Runner
20-
uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1
20+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
2121
with:
2222
egress-policy: audit
2323

2424
- name: 'Checkout Repository'
25-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
25+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
2626
- name: 'Dependency Review'
27-
uses: actions/dependency-review-action@3b139cfc5fae8b618d3eae3675e383bb1769c019 # v4.5.0
27+
uses: actions/dependency-review-action@3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261 # v4.8.2

.github/workflows/go-ci.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,13 +13,13 @@ jobs:
1313
name: Lint And Test Code
1414
runs-on: ubuntu-latest
1515
steps:
16-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
17-
- uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4
16+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
17+
- uses: actions/setup-go@7b8cf10d4e4a01d4992d18a89f4d7dc5a3e6d6f4 # v4
1818
with:
1919
go-version-file: go.mod
2020
cache: false
2121
- name: Run GolangCI linter
22-
uses: golangci/golangci-lint-action@971e284b6050e8a5849b72094c50ab08da042db8 # v6.1.1
22+
uses: golangci/golangci-lint-action@55c2c1448f86e01eaae002a5a3a9624417608d84 # v6.5.2
2323
with:
2424
args: '--timeout=5m'
2525
skip-cache: true
@@ -64,7 +64,7 @@ jobs:
6464
id: windows
6565
steps:
6666
- name: Get Cached Artifacts
67-
uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # v4.2.4
67+
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
6868
with:
6969
path: dist
7070
key: dist-${{ github.run_id }}

.github/workflows/sec-codeql.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -22,13 +22,13 @@ jobs:
2222
contents: read
2323
runs-on: ubuntu-latest
2424
steps:
25-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
26-
- uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4
25+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
26+
- uses: actions/setup-go@7b8cf10d4e4a01d4992d18a89f4d7dc5a3e6d6f4 # v4
2727
with:
2828
go-version-file: go.mod
2929
cache: false
3030
- name: Setup Golang Caches
31-
uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # v4.2.4
31+
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
3232
with:
3333
path: |
3434
~/.cache/go-build
@@ -38,11 +38,11 @@ jobs:
3838
${{ runner.os }}-go-
3939
# Initializes the CodeQL tools for scanning.
4040
- name: Initialize CodeQL
41-
uses: github/codeql-action/init@5b62e7a9f186342c830e01bc69a4626fd1573b6e # v2
41+
uses: github/codeql-action/init@b8d3b6e8af63cde30bdc382c0bc28114f4346c88 # v2
4242
with:
4343
languages: go
4444
# Autobuild attempts to build any compiled languages.
4545
- name: Autobuild
46-
uses: github/codeql-action/autobuild@5b62e7a9f186342c830e01bc69a4626fd1573b6e # v2
46+
uses: github/codeql-action/autobuild@b8d3b6e8af63cde30bdc382c0bc28114f4346c88 # v2
4747
- name: Perform CodeQL Analysis
48-
uses: github/codeql-action/analyze@5b62e7a9f186342c830e01bc69a4626fd1573b6e # v2
48+
uses: github/codeql-action/analyze@b8d3b6e8af63cde30bdc382c0bc28114f4346c88 # v2

.github/workflows/sec-scorecard.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -25,12 +25,12 @@ jobs:
2525

2626
steps:
2727
- name: "Checkout code"
28-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
28+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
2929
with:
3030
persist-credentials: false
3131

3232
- name: "Run analysis"
33-
uses: ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
33+
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
3434
with:
3535
results_file: results.sarif
3636
results_format: sarif
@@ -61,6 +61,6 @@ jobs:
6161

6262
# Upload the results to GitHub's code scanning dashboard.
6363
- name: "Upload to code-scanning"
64-
uses: github/codeql-action/upload-sarif@5b62e7a9f186342c830e01bc69a4626fd1573b6e # v2.27.4
64+
uses: github/codeql-action/upload-sarif@b8d3b6e8af63cde30bdc382c0bc28114f4346c88 # v2.28.1
6565
with:
6666
sarif_file: results.sarif

.github/workflows/tpl-packaging.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -38,13 +38,13 @@ jobs:
3838
pull-requests: write
3939
runs-on: ubuntu-latest
4040
steps:
41-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
42-
- uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4
41+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
42+
- uses: actions/setup-go@7b8cf10d4e4a01d4992d18a89f4d7dc5a3e6d6f4 # v4
4343
with:
4444
go-version-file: go.mod
4545
cache: false
4646
- name: Setup Golang Caches
47-
uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # v4.2.4
47+
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
4848
with:
4949
path: |
5050
~/.cache/go-build
@@ -55,13 +55,13 @@ jobs:
5555
- name: Setup Cosign
5656
uses: sigstore/cosign-installer@main
5757
- name: Login to GitHub Container Registry
58-
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3
58+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3
5959
with:
6060
registry: ghcr.io
6161
username: ${{ github.actor }}
6262
password: ${{ secrets.GITHUB_TOKEN }}
6363
- name: Setup QEMU
64-
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3
64+
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3
6565
- name: Run GoReleaser
6666
uses: goreleaser/goreleaser-action@5742e2a039330cbb23ebf35f046f814d4c6ff811 # v5
6767
with:
@@ -88,7 +88,7 @@ jobs:
8888
docker push ${docker_image_dst}
8989
done
9090
- name: Cache Artifacts
91-
uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # v4.2.4
91+
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
9292
if: ${{ inputs.artifacts-cache }}
9393
with:
9494
path: "${{ inputs.artifacts-cache-path }}"

Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM ubuntu:latest@sha256:278628f08d4979fb9af9ead44277dbc9c92c2465922310916ad0c46ec9999295 as base
1+
FROM ubuntu:latest@sha256:c35e29c9450151419d9448b0fd75374fec4fff364a27f176fb458d472dfc9e54 as base
22
RUN useradd -u 1001 merger
33

44
FROM scratch

go.mod

Lines changed: 25 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -1,56 +1,55 @@
11
module github.com/DevOpsHiveHQ/kustomize-plugin-merger
22

3-
go 1.22.7
3+
go 1.25.0
44

5-
toolchain go1.23.3
5+
toolchain go1.25.5
66

77
require (
8-
dario.cat/mergo v1.0.1
8+
dario.cat/mergo v1.0.2
99
github.com/knadh/koanf/parsers/yaml v0.1.0
1010
github.com/knadh/koanf/providers/file v0.1.0
11-
github.com/knadh/koanf/v2 v2.1.2
12-
github.com/stretchr/testify v1.9.0
13-
k8s.io/apimachinery v0.31.2
14-
k8s.io/kube-openapi v0.0.0-20241105132330-32ad38e42d3f
15-
sigs.k8s.io/kustomize/kyaml v0.18.1
11+
github.com/knadh/koanf/v2 v2.3.0
12+
github.com/stretchr/testify v1.11.1
13+
k8s.io/apimachinery v0.35.0
14+
k8s.io/kube-openapi v0.0.0-20251125145642-4e65d59e963e
15+
sigs.k8s.io/kustomize/kyaml v0.21.0
1616
)
1717

1818
require (
19-
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
2019
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
2120
github.com/fsnotify/fsnotify v1.6.0 // indirect
22-
github.com/fxamacker/cbor/v2 v2.7.0 // indirect
21+
github.com/fxamacker/cbor/v2 v2.9.0 // indirect
2322
github.com/go-errors/errors v1.4.2 // indirect
24-
github.com/go-logr/logr v1.4.2 // indirect
23+
github.com/go-logr/logr v1.4.3 // indirect
2524
github.com/go-openapi/jsonpointer v0.21.0 // indirect
2625
github.com/go-openapi/jsonreference v0.20.2 // indirect
2726
github.com/go-openapi/swag v0.23.0 // indirect
28-
github.com/go-viper/mapstructure/v2 v2.2.1 // indirect
29-
github.com/gogo/protobuf v1.3.2 // indirect
30-
github.com/golang/protobuf v1.5.4 // indirect
31-
github.com/google/gnostic-models v0.6.8 // indirect
32-
github.com/google/gofuzz v1.2.0 // indirect
27+
github.com/go-viper/mapstructure/v2 v2.4.0 // indirect
28+
github.com/google/gnostic-models v0.7.0 // indirect
3329
github.com/josharian/intern v1.0.0 // indirect
3430
github.com/json-iterator/go v1.1.12 // indirect
35-
github.com/knadh/koanf/maps v0.1.1 // indirect
31+
github.com/knadh/koanf/maps v0.1.2 // indirect
3632
github.com/mailru/easyjson v0.7.7 // indirect
3733
github.com/mitchellh/copystructure v1.2.0 // indirect
3834
github.com/mitchellh/reflectwalk v1.0.2 // indirect
3935
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
40-
github.com/modern-go/reflect2 v1.0.2 // indirect
36+
github.com/modern-go/reflect2 v1.0.3-0.20250322232337-35a7c28c31ee // indirect
4137
github.com/monochromegane/go-gitignore v0.0.0-20200626010858-205db1a8cc00 // indirect
4238
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
4339
github.com/x448/float16 v0.8.4 // indirect
4440
github.com/xlab/treeprint v1.2.0 // indirect
45-
golang.org/x/net v0.28.0 // indirect
46-
golang.org/x/sys v0.23.0 // indirect
47-
golang.org/x/text v0.17.0 // indirect
48-
google.golang.org/protobuf v1.34.2 // indirect
41+
go.yaml.in/yaml/v2 v2.4.3 // indirect
42+
go.yaml.in/yaml/v3 v3.0.4 // indirect
43+
golang.org/x/net v0.47.0 // indirect
44+
golang.org/x/sys v0.38.0 // indirect
45+
golang.org/x/text v0.31.0 // indirect
46+
google.golang.org/protobuf v1.36.8 // indirect
4947
gopkg.in/inf.v0 v0.9.1 // indirect
5048
gopkg.in/yaml.v3 v3.0.1 // indirect
5149
k8s.io/klog/v2 v2.130.1 // indirect
52-
k8s.io/utils v0.0.0-20240711033017-18e509b52bc8 // indirect
53-
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
54-
sigs.k8s.io/structured-merge-diff/v4 v4.4.2 // indirect
55-
sigs.k8s.io/yaml v1.4.0 // indirect
50+
k8s.io/utils v0.0.0-20251002143259-bc988d571ff4 // indirect
51+
sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect
52+
sigs.k8s.io/randfill v1.0.0 // indirect
53+
sigs.k8s.io/structured-merge-diff/v6 v6.3.0 // indirect
54+
sigs.k8s.io/yaml v1.6.0 // indirect
5655
)

0 commit comments

Comments
 (0)