Skip to content

Comments

fix(deps): update module github.com/goreleaser/goreleaser to v2#106

Open
renovate-sh-app[bot] wants to merge 1 commit intomainfrom
renovate/github.com-goreleaser-goreleaser-2.x
Open

fix(deps): update module github.com/goreleaser/goreleaser to v2#106
renovate-sh-app[bot] wants to merge 1 commit intomainfrom
renovate/github.com-goreleaser-goreleaser-2.x

Conversation

@renovate-sh-app
Copy link

@renovate-sh-app renovate-sh-app bot commented Jan 7, 2026

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
github.com/goreleaser/goreleaser v1.24.0v2.13.3 age confidence

Release Notes

goreleaser/goreleaser (github.com/goreleaser/goreleaser)

v2.13.3

Compare Source

Announcement

Read the official announcement: Announcing GoReleaser v2.13.

Changelog

Bug fixes
Documentation updates
Other work

Full Changelog: goreleaser/goreleaser@v2.13.2...v2.13.3

Helping out

This release is only possible thanks to all the support of some awesome people!

Want to be one of them?
You can sponsor, get a Pro License or contribute with code.

Where to go next?

GoReleaser logo

v2.13.2

Compare Source

Announcement

Read the official announcement: Announcing GoReleaser v2.13.

Changelog

Bug fixes
Documentation updates
Other work

Full Changelog: goreleaser/goreleaser@v2.13.1...v2.13.2

Helping out

This release is only possible thanks to all the support of some awesome people!

Want to be one of them?
You can sponsor, get a Pro License or contribute with code.

Where to go next?

GoReleaser logo

v2.13.1

Compare Source

Announcement

Read the official announcement: Announcing GoReleaser v2.13.

Changelog

Security updates
Bug fixes
Documentation updates
Other work

Full Changelog: goreleaser/goreleaser@v2.13.0...v2.13.1

Helping out

This release is only possible thanks to all the support of some awesome people!

Want to be one of them?
You can sponsor, get a Pro License or contribute with code.

Where to go next?

GoReleaser logo

v2.13.0

Compare Source

Announcement

Read the official announcement: Announcing GoReleaser v2.13.

Changelog

New Features
Bug fixes
Documentation updates
Other work

Full Changelog: goreleaser/goreleaser@v2.12.7...v2.13.0

Helping out

This release is only possible thanks to all the support of some awesome people!

Want to be one of them?
You can sponsor, get a Pro License or contribute with code.

Where to go next?

GoReleaser logo

v2.12.7

Compare Source

Announcement

Read the official announcement: Announcing GoReleaser v2.12.

Changelog

Bug fixes
Documentation updates
Other work

Full Changelog: goreleaser/goreleaser@v2.12.6...v2.12.7

Helping out

This release is only possible thanks to all the support of some awesome people!

Want to be one of them?
You can sponsor, get a Pro License or contribute with code.

Where to go next?

GoReleaser logo

v2.12.6

Compare Source

Announcement

Read the official announcement: Announcing GoReleaser v2.12.

Changelog

Bug fixes
Documentation updates
Other work

Full Changelog: goreleaser/goreleaser@v2.12.5...v2.12.6

Helping out

This release is only possible thanks to all the support of some awesome people!

Want to be one of them?
You can sponsor, get a Pro License or contribute with code.

Where to go next?

GoReleaser logo

v2.12.5

Compare Source

Announcement

Read the official announcement: Announcing GoReleaser v2.12.

Changelog

Full Changelog: goreleaser/goreleaser@v2.12.4...v2.12.5

Helping out

This release is only possible thanks to all the support of some awesome people!

Want to be one of them?
You can sponsor, get a Pro License or contribute with code.

Where to go next?

GoReleaser logo

v2.12.4

Compare Source

Announcement

Read the official announcement: Announcing GoReleaser v2.12.

Changelog

Bug fixes

Full Changelog: goreleaser/goreleaser@v2.12.3...v2.12.4

Helping out

This release is only possible thanks to all the support of some awesome people!

Want to be one of them?
You can sponsor, get a Pro License or contribute with code.

Where to go next?

GoReleaser logo

v2.12.3

Compare Source

Announcement

Read the official announcement: Announcing GoReleaser v2.12.

Changelog

Bug fixes
Documentation updates
Other work

Full Changelog: goreleaser/goreleaser@v2.12.2...v2.12.3

Helping out

This release is only possible thanks to all the support of some awesome people!

Want to be one of them?
You can sponsor, get a Pro License or contribute with code.

Where to go next?

GoReleaser logo

v2.12.2

Compare Source

Announcement

Read the official announcement: Announcing GoReleaser v2.12.

Changelog

Bug fixes
Other work

Full Changelog: goreleaser/goreleaser@v2.12.1...v2.12.2

Helping out

This release is only possible thanks to all the support of some awesome people!

Want to be one of them?
You can sponsor, get a Pro License or contribute with code.

Where to go next?

GoReleaser logo

v2.12.1

Compare Source

Announcement

Read the official announcement: Announcing GoReleaser v2.12.

Changelog

Bug fixes
Documentation updates
Other work

Full Changelog: goreleaser/goreleaser@v2.12.0...v2.12.1

Helping out

This release is only possible thanks to all the support of some awesome people!

Want to be one of them?
You can sponsor, get a Pro License or contribute with code.

Where to go next?

GoReleaser logo

v2.12.0

Compare Source

Announcement

Read the official announcement: Announcing GoReleaser v2.12.

Changelog

New Features

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

Need help?

You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.

@renovate-sh-app
Copy link
Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 10 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.21 -> 1.25.5
github.com/goreleaser/nfpm/v2 v2.35.3 -> v2.44.1
github.com/caarlos0/log v0.4.4 -> v0.5.4
github.com/charmbracelet/lipgloss v0.9.1 -> v0.10.0
github.com/goreleaser/fileglob v1.3.0 -> v1.4.0
github.com/invopop/jsonschema v0.12.0 -> v0.13.0
github.com/lucasb-eyer/go-colorful v1.2.0 -> v1.3.0
github.com/mailru/easyjson v0.7.7 -> v0.9.0
github.com/mattn/go-isatty v0.0.18 -> v0.0.20
github.com/mattn/go-runewidth v0.0.15 -> v0.0.19
github.com/rivo/uniseg v0.4.2 -> v0.4.7

@github-actions

This comment has been minimized.

| datasource | package                          | from    | to      |
| ---------- | -------------------------------- | ------- | ------- |
| go         | github.com/goreleaser/goreleaser | v1.24.0 | v2.13.3 |


Signed-off-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
@renovate-sh-app renovate-sh-app bot force-pushed the renovate/github.com-goreleaser-goreleaser-2.x branch from 7980f66 to 0c30b67 Compare January 13, 2026 05:10
@github-actions
Copy link
Contributor

😢 zizmor failed with exit code 14.

Expand for full output
error[unpinned-uses]: unpinned action reference
  --> ./.github/workflows/base-goreleaser-ci.yaml:21:9
   |
21 |         uses: docker/setup-qemu-action@v3
   |         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ action is not pinned to a hash (required by blanket policy)
   |
   = note: audit confidence → High

error[unpinned-uses]: unpinned action reference
  --> ./.github/workflows/base-goreleaser-ci.yaml:26:9
   |
26 |         uses: docker/setup-buildx-action@v3
   |         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ action is not pinned to a hash (required by blanket policy)
   |
   = note: audit confidence → High

error[unpinned-uses]: unpinned action reference
  --> ./.github/workflows/base-goreleaser-ci.yaml:33:9
   |
33 |       - uses: anchore/sbom-action/download-syft@v0.15.10
   |         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ action is not pinned to a hash (required by blanket policy)
   |
   = note: audit confidence → High

error[unpinned-uses]: unpinned action reference
  --> ./.github/workflows/base-goreleaser-ci.yaml:39:9
   |
39 |         uses: goreleaser/goreleaser-action@v5
   |         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ action is not pinned to a hash (required by blanket policy)
   |
   = note: audit confidence → High

error[cache-poisoning]: runtime artifacts potentially vulnerable to a cache poisoning attack
  --> ./.github/workflows/base-goreleaser-ci.yaml:29:9
   |
29 |         uses: actions/setup-go@v5
   |         ^^^^^^^^^^^^^^^^^^^^^^^^^ cache enabled by default here
...
39 |         uses: goreleaser/goreleaser-action@v5
   |         ------------------------------------- runtime artifacts usually published here
   |
   = note: audit confidence → Low
   = note: this finding has an auto-fix

error[unpinned-uses]: unpinned action reference
  --> ./.github/workflows/base-release.yaml:23:9
   |
23 |         uses: docker/setup-qemu-action@v3
   |         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ action is not pinned to a hash (required by blanket policy)
   |
   = note: audit confidence → High

error[unpinned-uses]: unpinned action reference
  --> ./.github/workflows/base-release.yaml:28:9
   |
28 |         uses: docker/setup-buildx-action@v3
   |         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ action is not pinned to a hash (required by blanket policy)
   |
   = note: audit confidence → High

error[unpinned-uses]: unpinned action reference
  --> ./.github/workflows/base-release.yaml:35:9
   |
35 |       - uses: anchore/sbom-action/download-syft@v0.15.10
   |         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ action is not pinned to a hash (required by blanket policy)
   |
   = note: audit confidence → High

error[unpinned-uses]: unpinned action reference
  --> ./.github/workflows/base-release.yaml:41:9
   |
41 |         uses: docker/login-action@v3
   |         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ action is not pinned to a hash (required by blanket policy)
   |
   = note: audit confidence → High

error[unpinned-uses]: unpinned action reference
  --> ./.github/workflows/base-release.yaml:48:9
   |
48 |         uses: goreleaser/goreleaser-action@v5
   |         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ action is not pinned to a hash (required by blanket policy)
   |
   = note: audit confidence → High

error[cache-poisoning]: runtime artifacts potentially vulnerable to a cache poisoning attack
  --> ./.github/workflows/base-release.yaml:31:9
   |
31 |         uses: actions/setup-go@v5
   |         ^^^^^^^^^^^^^^^^^^^^^^^^^ cache enabled by default here
...
48 |         uses: goreleaser/goreleaser-action@v5
   |         ------------------------------------- runtime artifacts usually published here
   |
   = note: audit confidence → Low
   = note: this finding has an auto-fix

error[dangerous-triggers]: use of fundamentally insecure workflow trigger
 --> ./.github/workflows/ci-delta-to-cumulative.yaml:3:1
  |
3 | / on:
4 | |   workflow_run:
5 | |     workflows: [Continuous Integration]
6 | |     types:
7 | |       - completed
  | |_________________^ workflow_run is almost always used insecurely
  |
  = note: audit confidence → Medium

error[excessive-permissions]: overly broad permissions
  --> ./.github/workflows/release-delta-to-cumulative.yaml:14:5
   |
 8 | /   release:
 9 | |     name: Release delta-to-cumulative
10 | |     uses: ./.github/workflows/base-release.yaml
11 | |     with:
12 | |       distribution: delta-to-cumulative
13 | |     secrets: inherit
14 | |     permissions: write-all
   | |_____^^^^^^^^^^^^^^^^^^^^^^- this job
   |       |
   |       uses write-all permissions
   |
   = note: audit confidence → High

27 findings (7 ignored, 7 suppressed, 2 fixable): 0 informational, 0 low, 0 medium, 13 high

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants