Skip to content

fix(deps): update all dependencies#4

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/all
Open

fix(deps): update all dependencies#4
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/all

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Apr 6, 2025

This PR contains the following updates:

Package Type Update Change Age Adoption Passing Confidence
actions/dependency-review-action action minor v4.8.2v4.9.0 age adoption passing confidence
actions/setup-go action minor v6.2.0v6.3.0 age adoption passing confidence
github.com/aperturerobotics/cli require minor v1.0.2-0.20260131035933-6db6a670406dv1.1.0 age adoption passing confidence
github/codeql-action action patch v4.32.0v4.32.6 age adoption passing confidence
golang.org/x/text require minor v0.33.0v0.35.0 age adoption passing confidence

Release Notes

actions/dependency-review-action (actions/dependency-review-action)

v4.9.0: Dependency Review Action 4.9.0

Compare Source

This feature release contains a couple of notable changes:

  • There is a new configuration option show_patched_versions which will add a column to the output, showing the fix version of each vulnerable dependency. Thanks @​felickz!
  • Runs which do not display OpenSSF scorecards no longer fetch scorecard information; previously it was fetched regardless of whether or not it was displayed, causing unneccessary slowness. Great catch @​jantiebot!
  • There are a couple of fixes to purl parsing which should improve match accuracy for allow-package-dependency lists, including case (in)sensitivity and url-encoded namespaces Thanks @​juxtin!

What's Changed

New Contributors

Full Changelog: actions/dependency-review-action@v4.8.3...v4.9.0

v4.8.3: 4.8.3

Compare Source

Dependency Review Action v4.8.3

This is a bugfix release that updates a number of upstream dependencies and includes a fix for the earlier feature that detected oversized summaries and upload them as artifacts, which could occasionally crash the action.

We have also updated the release process to use a long-lived v4 branch for the action, instead of a force-pushed tag, which aligns better with git branching strategies; the change should be transparent to end users.

What's Changed

Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.8.2..v4.8.3

actions/setup-go (actions/setup-go)

v6.3.0

Compare Source

What's Changed

Full Changelog: actions/setup-go@v6...v6.3.0

aperturerobotics/cli (github.com/aperturerobotics/cli)

v1.1.0

Compare Source

github/codeql-action (github/codeql-action)

v4.32.6

Compare Source

v4.32.5

Compare Source

  • Repositories owned by an organization can now set up the github-codeql-disable-overlay custom repository property to disable improved incremental analysis for CodeQL. First, create a custom repository property with the name github-codeql-disable-overlay and the type "True/false" in the organization's settings. Then in the repository's settings, set this property to true to disable improved incremental analysis. For more information, see Managing custom properties for repositories in your organization. This feature is not yet available on GitHub Enterprise Server. #​3507
  • Added an experimental change so that when improved incremental analysis fails on a runner — potentially due to insufficient disk space — the failure is recorded in the Actions cache so that subsequent runs will automatically skip improved incremental analysis until something changes (e.g. a larger runner is provisioned or a new CodeQL version is released). We expect to roll this change out to everyone in March. #​3487
  • The minimum memory check for improved incremental analysis is now skipped for CodeQL 2.24.3 and later, which has reduced peak RAM usage. #​3515
  • Reduced log levels for best-effort private package registry connection check failures to reduce noise from workflow annotations. #​3516
  • Added an experimental change which lowers the minimum disk space requirement for improved incremental analysis, enabling it to run on standard GitHub Actions runners. We expect to roll this change out to everyone in March. #​3498
  • Added an experimental change which allows the start-proxy action to resolve the CodeQL CLI version from feature flags instead of using the linked CLI bundle version. We expect to roll this change out to everyone in March. #​3512
  • The previously experimental changes from versions 4.32.3, 4.32.4, 3.32.3 and 3.32.4 are now enabled by default. #​3503, #​3504

v4.32.4

Compare Source

  • Update default CodeQL bundle version to 2.24.2. #​3493
  • Added an experimental change which improves how certificates are generated for the authentication proxy that is used by the CodeQL Action in Default Setup when private package registries are configured. This is expected to generate more widely compatible certificates and should have no impact on analyses which are working correctly already. We expect to roll this change out to everyone in February. #​3473
  • When the CodeQL Action is run with debugging enabled in Default Setup and private package registries are configured, the "Setup proxy for registries" step will output additional diagnostic information that can be used for troubleshooting. #​3486
  • Added a setting which allows the CodeQL Action to enable network debugging for Java programs. This will help GitHub staff support customers with troubleshooting issues in GitHub-managed CodeQL workflows, such as Default Setup. This setting can only be enabled by GitHub staff. #​3485
  • Added a setting which enables GitHub-managed workflows, such as Default Setup, to use a nightly CodeQL CLI release instead of the latest, stable release that is used by default. This will help GitHub staff support customers whose analyses for a given repository or organization require early access to a change in an upcoming CodeQL CLI release. This setting can only be enabled by GitHub staff. #​3484

v4.32.3

Compare Source

  • Added experimental support for testing connections to private package registries. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for Default Setup. #​3466

v4.32.2

Compare Source

v4.32.1

Compare Source

  • A warning is now shown in Default Setup workflow logs if a private package registry is configured using a GitHub Personal Access Token (PAT), but no username is configured. #​3422
  • Fixed a bug which caused the CodeQL Action to fail when repository properties cannot successfully be retrieved. #​3421

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot changed the title fix(deps): update module golang.org/x/text to v0.24.0 fix(deps): update all dependencies Apr 7, 2025
@renovate renovate bot force-pushed the renovate/all branch 2 times, most recently from fec1490 to e672fc0 Compare April 7, 2025 22:02
@renovate renovate bot force-pushed the renovate/all branch 4 times, most recently from d44dce7 to ae64ff9 Compare April 29, 2025 03:05
@renovate renovate bot force-pushed the renovate/all branch 4 times, most recently from 16593f6 to f9187e8 Compare May 8, 2025 19:38
@renovate renovate bot force-pushed the renovate/all branch 3 times, most recently from c0a033e to 36972fe Compare May 16, 2025 11:05
@renovate renovate bot force-pushed the renovate/all branch 2 times, most recently from 95f3bd5 to 98b5e6b Compare June 6, 2025 19:23
@renovate renovate bot force-pushed the renovate/all branch 2 times, most recently from f36587d to ca51a9c Compare June 30, 2025 16:27
@renovate renovate bot force-pushed the renovate/all branch 4 times, most recently from 73526b6 to 2d3b0db Compare July 9, 2025 22:29
@renovate renovate bot force-pushed the renovate/all branch 3 times, most recently from f7dc30b to 166ff23 Compare July 23, 2025 19:51
@renovate renovate bot force-pushed the renovate/all branch 2 times, most recently from 773d082 to c24ac00 Compare August 5, 2025 10:39
@renovate
Copy link
Contributor Author

renovate bot commented Sep 8, 2025

ℹ Artifact update notice

File name: cmd/urfave-cli-genflags/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.24 -> 1.24.0

@renovate renovate bot force-pushed the renovate/all branch 2 times, most recently from 956b90b to cd68cfb Compare September 10, 2025 21:36
@renovate renovate bot force-pushed the renovate/all branch 2 times, most recently from e27dc36 to 921f5b6 Compare September 26, 2025 18:29
@renovate renovate bot force-pushed the renovate/all branch 3 times, most recently from 582711d to 380f6ac Compare October 8, 2025 16:28
@renovate renovate bot force-pushed the renovate/all branch 2 times, most recently from 86e004d to 43f7ede Compare October 10, 2025 21:59
@renovate renovate bot force-pushed the renovate/all branch 3 times, most recently from 58d6108 to b60c5cc Compare October 30, 2025 18:31
@renovate renovate bot changed the title fix(deps): update all dependencies fix(deps): update all dependencies - autoclosed Nov 4, 2025
@renovate renovate bot closed this Nov 4, 2025
@renovate renovate bot deleted the renovate/all branch November 4, 2025 05:03
@renovate renovate bot changed the title fix(deps): update all dependencies - autoclosed fix(deps): update module github.com/aperturerobotics/cli to v1.0.1 Nov 4, 2025
@renovate renovate bot reopened this Nov 4, 2025
@renovate renovate bot force-pushed the renovate/all branch 3 times, most recently from 0fbca77 to 97f46f9 Compare November 11, 2025 00:35
@renovate renovate bot changed the title fix(deps): update module github.com/aperturerobotics/cli to v1.0.1 fix(deps): update all dependencies Nov 11, 2025
@renovate renovate bot force-pushed the renovate/all branch 3 times, most recently from a241743 to fff2ddd Compare November 13, 2025 12:56
@renovate
Copy link
Contributor Author

renovate bot commented Mar 11, 2026

ℹ️ Artifact update notice

File name: cmd/urfave-cli-genflags/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.25 -> 1.25.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

0 participants