Skip to content

[pull] main from renovatebot:main#1010

Merged
pull[bot] merged 3 commits intoryrodriguez25:mainfrom
renovatebot:main
Apr 1, 2026
Merged

[pull] main from renovatebot:main#1010
pull[bot] merged 3 commits intoryrodriguez25:mainfrom
renovatebot:main

Conversation

@pull
Copy link
Copy Markdown

@pull pull bot commented Apr 1, 2026

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

jamietanna and others added 3 commits April 1, 2026 15:00
* test: add additional case for attestation changes

* fix: correctly warn when an attestation is missing

As noted in #37258, when a package registry had previously seen an
attestation for authenticity of a given package release, Renovate should
warn if future updates then lose authenticity.

Our previous attempt at this didn't quite pass around the current
package's attestation, which results in no warnings.

Given recent supply chain attacks where an attestation was removed (such
as Axios in MSC-2026-3522), we should make sure that this logic does
work correctly, and flags to our users.

In the future, we'll add more checks and a failing status check.

By introducing `hasAttestation` in the `LookupUpdate`, this can now be
matched on with `matchJsonata`, as well as providing visibility in the
`packageFiles with updates` log line.

* fixup! fix: correctly warn when an attestation is missing

> Run `pnpm run jest
> lib/workers/repository/process/lookup/index.spec.ts` and handle any test
> failures - the implementation is correct, so update the tests

Co-authored-by: Claude Sonnet 4.6 <jamie.tanna+claude-code@mend.io>

* test: clarify that we don't check for intermediate releases

Which we'll look to improve as part of future changes.

* chore: fix typo

Co-authored-by: Michael Kriese <michael.kriese@visualon.de>

---------

Co-authored-by: Claude Sonnet 4.6 <jamie.tanna+claude-code@mend.io>
Co-authored-by: Michael Kriese <michael.kriese@visualon.de>
build(deps): update opentelemetry-js monorepo

| datasource | package                                 | from    | to      |
| ---------- | --------------------------------------- | ------- | ------- |
| npm        | @opentelemetry/api                      | 1.9.0   | 1.9.1   |
| npm        | @opentelemetry/context-async-hooks      | 2.6.0   | 2.6.1   |
| npm        | @opentelemetry/exporter-trace-otlp-http | 0.213.0 | 0.214.0 |
| npm        | @opentelemetry/instrumentation          | 0.213.0 | 0.214.0 |
| npm        | @opentelemetry/instrumentation-http     | 0.213.0 | 0.214.0 |
| npm        | @opentelemetry/resources                | 2.6.0   | 2.6.1   |
| npm        | @opentelemetry/sdk-trace-base           | 2.6.0   | 2.6.1   |
| npm        | @opentelemetry/sdk-trace-node           | 2.6.0   | 2.6.1   |

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
)

chore(deps): update dependency oxlint-tsgolint to v0.17.4

| datasource | package         | from   | to     |
| ---------- | --------------- | ------ | ------ |
| npm        | oxlint-tsgolint | 0.17.3 | 0.17.4 |

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@pull pull bot locked and limited conversation to collaborators Apr 1, 2026
@pull pull bot added the ⤵️ pull label Apr 1, 2026
@pull pull bot merged commit 9535323 into ryrodriguez25:main Apr 1, 2026
2 of 8 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant