Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Nov 21, 2025

Bumps the chainguard group with 4 updates: chainguard.dev/apko, chainguard.dev/melange, github.com/chainguard-dev/yam and github.com/chainguard-dev/advisory-schema.

Updates chainguard.dev/apko from 0.30.20 to 0.30.25

Release notes

Sourced from chainguard.dev/apko's releases.

Release v0.30.25

Changelog

  • 9ed23fcd41af473ad01bf7267a0cba3d47f99375 build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#1942)

Release v0.30.24

Changelog

  • 80833b1c7a5aca9a4f5984b1d16395616722e7ae Return structured error if path mutations result in an "already exists" error (#1937)

Release v0.30.23

Changelog

  • 996cb6e00230b757941880eed256887bb2878e87 github: build samples offline too (#1941)

Release v0.30.22

Changelog

  • 1767a213ad33b3965235118732d3bafc06a8de27 build(deps): bump github/codeql-action from 4.31.2 to 4.31.3 (#1936)

Release v0.30.21

Changelog

  • 022d3189f8b26bed14dab64e91c26363048e913d Upgrade golangci-lint to 2.6.1 and enable modernize linter (#1916)
Commits
  • 9ed23fc build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#1942)
  • 9370bdb build(deps): bump google.golang.org/api from 0.255.0 to 0.256.0 (#1933)
  • 2045011 build(deps): bump k8s.io/apimachinery from 0.34.1 to 0.34.2 (#1934)
  • 3e40d92 build(deps): bump golang.org/x/crypto from 0.43.0 to 0.45.0 in the go_modules...
  • e88ef4f build(deps): bump github/codeql-action from 4.31.3 to 4.31.4 (#1945)
  • 80833b1 Return structured error if path mutations result in an "already exists" erro...
  • 996cb6e github: build samples offline too (#1941)
  • 7918e99 apk: fix offline cached builds with alpine key discovery (#1938)
  • 521139e build(deps): bump chainguard-dev/actions from 1.5.8 to 1.5.9 (#1939)
  • 1767a21 build(deps): bump github/codeql-action from 4.31.2 to 4.31.3 (#1936)
  • Additional commits viewable in compare view

Updates chainguard.dev/melange from 0.32.0 to 0.34.0

Release notes

Sourced from chainguard.dev/melange's releases.

Release v0.34.0

What's Changed

Full Changelog: chainguard-dev/melange@v0.33.2...v0.34.0

Release v0.33.2

What's Changed

Full Changelog: chainguard-dev/melange@v0.33.1...v0.33.2

Release v0.33.1

What's Changed

Full Changelog: chainguard-dev/melange@v0.33.0...v0.33.1

Release v0.33.0

What's Changed

Full Changelog: chainguard-dev/melange@v0.32.0...v0.33.0

Commits
  • 6ba2d39 build(deps): bump golang.org/x/crypto from 0.44.0 to 0.45.0 (#2238)
  • dd9ad68 build(deps): bump the gomod group with 3 updates (#2235)
  • 6027416 feat(sca): add isInDir tests ; fix edge case with recursive paths (#2236)
  • 50eab93 feat: allow recursive directories in SCA (#2233)
  • 06698a9 build: always perform build (#2223)
  • 67036a2 fetch: add support for no checksum validation (#2222)
  • 7e10416 qemu runner: make virtfs 9p bindings read-only v2 (#2155)
  • db078ee build(deps): bump github.com/docker/cli (#2232)
  • 62de14e build(deps): bump golang.org/x/crypto from 0.43.0 to 0.44.0 (#2229)
  • 06fbf93 build(deps): bump golangci/golangci-lint-action from 8.0.0 to 9.0.0 (#2228)
  • Additional commits viewable in compare view

Updates github.com/chainguard-dev/yam from 0.2.38 to 0.2.40

Commits
  • 97b602f build(deps): bump golangci/golangci-lint-action from 8.0.0 to 9.0.0 (#161)
  • db01d72 build(deps): bump chainguard-dev/actions from 1.5.7 to 1.5.8 (#160)
  • fa2efb8 build(deps): bump step-security/harden-runner from 2.13.1 to 2.13.2 (#159)
  • 1ed6efb build(deps): bump chainguard-dev/actions from 1.5.6 to 1.5.7 (#158)
  • a1356e5 build(deps): bump octo-sts/action from 1.0.2 to 1.0.3 (#157)
  • See full diff in compare view

Updates github.com/chainguard-dev/advisory-schema from 0.37.26 to 0.37.28

Commits
  • 5ff5478 build(deps): bump chainguard-dev/actions from 1.5.8 to 1.5.9 (#95)
  • a4961b8 build(deps): bump golangci/golangci-lint-action from 8.0.0 to 9.0.0 (#92)
  • 232ab63 build(deps): bump github.com/chainguard-dev/yam in the all group (#91)
  • 3f74d61 build(deps): bump step-security/harden-runner from 2.13.1 to 2.13.2 (#94)
  • f9c83d2 build(deps): bump chainguard-dev/actions from 1.5.7 to 1.5.8 (#93)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Nov 21, 2025
@cpanato
Copy link
Member

cpanato commented Nov 26, 2025

@dependabot rebase

Bumps the chainguard group with 4 updates: [chainguard.dev/apko](https://github.com/chainguard-dev/apko), [chainguard.dev/melange](https://github.com/chainguard-dev/melange), [github.com/chainguard-dev/yam](https://github.com/chainguard-dev/yam) and [github.com/chainguard-dev/advisory-schema](https://github.com/chainguard-dev/advisory-schema).


Updates `chainguard.dev/apko` from 0.30.20 to 0.30.25
- [Release notes](https://github.com/chainguard-dev/apko/releases)
- [Changelog](https://github.com/chainguard-dev/apko/blob/main/NEWS.md)
- [Commits](chainguard-dev/apko@v0.30.20...v0.30.25)

Updates `chainguard.dev/melange` from 0.32.0 to 0.34.0
- [Release notes](https://github.com/chainguard-dev/melange/releases)
- [Changelog](https://github.com/chainguard-dev/melange/blob/main/NEWS.md)
- [Commits](chainguard-dev/melange@v0.32.0...v0.34.0)

Updates `github.com/chainguard-dev/yam` from 0.2.38 to 0.2.40
- [Commits](chainguard-dev/yam@v0.2.38...v0.2.40)

Updates `github.com/chainguard-dev/advisory-schema` from 0.37.26 to 0.37.28
- [Commits](chainguard-dev/advisory-schema@v0.37.26...v0.37.28)

---
updated-dependencies:
- dependency-name: chainguard.dev/apko
  dependency-version: 0.30.25
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: chainguard
- dependency-name: chainguard.dev/melange
  dependency-version: 0.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: chainguard
- dependency-name: github.com/chainguard-dev/yam
  dependency-version: 0.2.40
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: chainguard
- dependency-name: github.com/chainguard-dev/advisory-schema
  dependency-version: 0.37.28
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: chainguard
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/go_modules/chainguard-d9c27f3182 branch from d7e7e25 to f1af2fa Compare November 26, 2025 08:59
@cpanato cpanato merged commit 8f734f3 into main Nov 26, 2025
7 checks passed
@cpanato cpanato deleted the dependabot/go_modules/chainguard-d9c27f3182 branch November 26, 2025 09:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants