Skip to content

chore: update dependencies - #567

Draft
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/dependencies
Draft

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/dependencies

Conversation

@renovate

@renovate renovate Bot commented Dec 25, 2024 •

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

Update Request | Renovate Bot

This PR contains the following updates:

Package Type Update Change Age Adoption Passing Confidence
awslabs/soci-snapshotter minor v0.15.0 → v0.16.0 age adoption passing confidence
ceph/ceph minor 21.1.0 → 21.3.0 age adoption passing confidence
cloudflare/cloudflared minor 2026.8.3 → 2026.9.3 age adoption passing confidence
container-registry/harbor-workload-identity-federation minor v0.0.1 → v0.1.0 age adoption passing confidence
containers/crun minor 1.29.1 → 1.30 age adoption passing confidence
fosrl/newt minor 1.16.0 → 1.17.0 age adoption passing confidence
git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git patch 6.18.50 → 6.18.53 age adoption passing confidence
github.com/anchore/grype indirect minor v0.111.0 → v0.119.0 age adoption passing confidence
github.com/anchore/syft indirect minor v1.42.4 → v1.52.0 age adoption passing confidence
github.com/dsseng/syft replace patch v1.42.4-0.20260415171054-31b9430f030f → v1.42.4 age adoption passing confidence
google/gvisor minor 20260831.0 → 20260921.0 age adoption passing confidence
https://github.com/spinkube/containerd-shim-spin.git minor v0.25.1 → v0.26.0 age adoption passing confidence
kata-containers/kata-containers major 3.32.0 → 4.2.0 age adoption passing confidence
netbirdio/netbird minor 0.78.1 → 0.79.0 age adoption passing confidence
siderolabs/talos-vmtoolsd patch v1.5.1 → v1.5.2 age adoption passing confidence
slackhq/nebula patch 1.11.1 → 1.11.2 age adoption passing confidence
systemd/systemd major 261.2 → 262 age adoption passing confidence
tailscale/tailscale patch 1.102.3 → 1.102.4 age adoption passing confidence

Release Notes

awslabs/soci-snapshotter (awslabs/soci-snapshotter)

v0.16.0

Compare Source

Changelog

  • Fix daemon crash with concurrent image pulls in parallel pull path (#​2082)
  • Allow custom headers to be passed to content fetch requests (#​2078, #​2086)
  • Fix bug where local content would incorrectly report as not validated (#​2073)

Full Changelog: awslabs/soci-snapshotter@v0.15.0...v0.16.0

These binaries were compiled using glibc 2.34.

ceph/ceph (ceph/ceph)

v21.3.0

Compare Source

v21.1.1

Compare Source

cloudflare/cloudflared (cloudflare/cloudflared)

v2026.9.3

Compare Source

SHA256 Checksums:
cloudflared-amd64.pkg: 48d0d3b28b3b5d142490f57316981b65ae46fbbe33408c22b0a4a11b5242de50
cloudflared-arm64.pkg: 79f17181cda2bbcfe6ad36cd9ee1946faaf079e6a9d6c0bc4a32fbb644a4c29d
cloudflared-darwin-amd64.tgz: ab588b3b4db9cdb4476c30a3db2a72635b1d8327d44741fee6799a0f37b0ec07
cloudflared-darwin-arm64.tgz: 5472c1a01c84bc31b3021056a73b4e5774ddddefc572124ea8fdf6c340639f32
cloudflared-fips-linux-amd64: 32a68f04c5816304ece7f5129ab81581c95eb26352848d2605cde42d63316e88
cloudflared-fips-linux-amd64.deb: 4dd10ab302a672c34739d88305ad83bf847b37840ccbd1f17a2ab94bf3dc690c
cloudflared-fips-linux-x86_64.rpm: eae2945bc1b947d225b25325eda961be1fa924097d9cfdd0ae70e154bd16dc3e
cloudflared-linux-386: d6b2f917e2e78b3e3afba760af726e51751d10c2fcad4a2fb2a69feb4bd47421
cloudflared-linux-386.deb: efd821ce6adeb899b419a26965f09ca4d64c7dca9b386b1be6ecb5b7e947cf34
cloudflared-linux-386.rpm: e3c3d6bf81c14eec403a540328e66ef3304539fc5c00f0dada6d5b70a9205d59
cloudflared-linux-aarch64.rpm: e37b746dd252ab51b8dbe90f07eaf50c0335d137009cc224a97203acf1c331ab
cloudflared-linux-amd64: 77e26d8d900e0b8469f416239d14b5f296525fdf79fee6f511ef55609e3fbac2
cloudflared-linux-amd64.deb: bc073ef293d504cf5ac533bd0aa1c824ef6b4f358765ccaa6628a8a95cacb4b7
cloudflared-linux-arm: 967dc371a3fedbf09e881c13ee7ba317155ebc336cbd4afb756b46fc6785e5af
cloudflared-linux-arm.deb: a9d12267d5991328c40c5071fcc82c3d6d1953800bd30d3530a5120b2dda9b4f
cloudflared-linux-arm.rpm: 20b3b2ae15b744a04eb27b94300450eb9d280ffff4d196ff3e2509daaf0c7024
cloudflared-linux-arm64: aaeb2d7d0da3614634c7e03ab13487a1522c2e79165ed2929cfe23d5e95b326d
cloudflared-linux-arm64.deb: bcce0111878f13d26e66b1d2ea7f270c8bde4bd549e32ce74d32474521583ca3
cloudflared-linux-armhf: a714b1bee87e71ce7260555b30722ce711d12aaa0fee5a8aadc767ee6b816a14
cloudflared-linux-armhf.deb: 4815dd7fc7b4c3ff5d29a7bbe80bba9e253d29b2eb84079e853b158fdfd7e975
cloudflared-linux-armhf.rpm: 4350c58a83ce4cd8717eb6352713e6d2d615c204a6e6161015cf0db4a2142c18
cloudflared-linux-x86_64.rpm: b64f9131b5ea2772c4a8fb9fb67f95437190ad63e909871396adb92c2b6d99eb
cloudflared-windows-386.exe: 9b95ddc2eba67b86ed3dc4cc2a15881960563031b52ce564376af41fb91ad402
cloudflared-windows-386.msi: c26a212d4e04e3d0525aa131c02653801920cd88c706cb67c0eb8a09293f4591
cloudflared-windows-amd64.exe: f096265ec2fcbe9bb6e2d64268db167ced3fcbb83d894bdb9e2fcdb26f2ea7e2
cloudflared-windows-amd64.msi: 597c2f4daa5965f10a3893a56aefe27a5e5946bcbd333d984a32743c6df7a561

v2026.9.2

Compare Source

SHA256 Checksums:
cloudflared-amd64.pkg: 86dd0f8fcb3060b6080f2c3233967887d6ceb0fbed180ccfd8999f4b82baa0fd
cloudflared-arm64.pkg: 966fd7f038fc04286fc2a9883352b6342899927958b694d1d316a99cc4f58c9a
cloudflared-darwin-amd64.tgz: 5353cd803c5ed275a23cf1185860776bf3917d93890588b021a7ff896136efb4
cloudflared-darwin-arm64.tgz: 1e4cf155145f9a459e3cc5b1ca147c312fb7dca6be7faef75d8832ff6d673c7a
cloudflared-fips-linux-amd64: 605ca757adedbb81b45a93584f87d23ebbe35d5b018a5475a6cc6858d664f682
cloudflared-fips-linux-amd64.deb: 5fb596219cc8c37e400e06bca1ca3a0e23a477a56e4446229eb52919f6f42974
cloudflared-fips-linux-x86_64.rpm: dcd12ba94fa9edb8c971d4e3d16f4bea71127207713d4ded905d6cdb38060a76
cloudflared-linux-386: 4d813b9d5b35ef683f5614dc0811c69618bad1fc3350687e95ad4fc549e7342c
cloudflared-linux-386.deb: 25c17dcc4c496abd34682e22d6a3f864f0c4797581a19ce3f3ae5e27963239c0
cloudflared-linux-386.rpm: 1f2ff2662358a578f0735ec462e7d2654dc58e4c23725abf9ba6081c34601156
cloudflared-linux-aarch64.rpm: cb7842ff6f959d3a77d43314be5b6015dc17a3a90d92630887396fab0797c31f
cloudflared-linux-amd64: ea2c9bb2d5017a796b64bf36e605d727accf76a5500014bb12952ce11ae1f932
cloudflared-linux-amd64.deb: aa2604c46d5b8848247c6d32ca8e6d7e62e97d7d7ecc4a62023d58d246f6dea4
cloudflared-linux-arm: 871f8a4f48b841d91834b45157b169c601c29892da3629edc4b1d2088ab4767d
cloudflared-linux-arm.deb: a55cada018840b7cbb07ce764e91f34d4797de1c0a0bc688bcdf86fee2a6aca3
cloudflared-linux-arm.rpm: 53ce7747b64f16ef6e75eb77d4ecaca7df1abc6399054d7b62f5eea86722f93d
cloudflared-linux-arm64: 39f23e7c55ce2c2e502a0b3e070b978bf69135b19246b5b7581dadb94cf2144d
cloudflared-linux-arm64.deb: 8bbbffa69cedbf546dc224a9319e90626069b0c917c4070b43aaf81f87cf2821
cloudflared-linux-armhf: dbab3ca93dc0bb7bff1b15486c3ca2b96c71b3ac0cda24e340517ceae20898cc
cloudflared-linux-armhf.deb: 1f6a3a17a309f0ad2b25c85f7322a298b4938ad5e904b19bced157040ee07e55
cloudflared-linux-armhf.rpm: f3709a03692906b8539c9bd27c1b38f3d183d71d20d6c0d991abb9566fcfe610
cloudflared-linux-x86_64.rpm: e18befe6459389d8667d2b6496664009164c16f45aa660cfd0cfdfd8f748576a
cloudflared-windows-386.exe: d2be3e66033b499634dc9a675051b70dd37fb2bd91d4f864073fd71cc69c1003
cloudflared-windows-386.msi: 5321d7e658043beab5179d9f0b32b199b722d0c95bfad5085c89c6fa70b3f82a
cloudflared-windows-amd64.exe: 214f5d74f66941d147d054f6cc9d821c60ff6a9b2d5355f6c854c6bee217c548
cloudflared-windows-amd64.msi: 73a62ea87074d97a8fa98575f2100de826fb6d38ee52b70f569c113f8a824c99

v2026.9.1

Compare Source

SHA256 Checksums:
cloudflared-amd64.pkg: c4084991b83b2f538853c97a502f424805467e4375d18138ab80bc2414340997
cloudflared-arm64.pkg: b877c291db70cc83891785c4bf3da88ac3a82944d34ebeb953f932a4d5f02cf1
cloudflared-darwin-amd64.tgz: 1ea07ae775b03236bd6be18ca1848d6bdc4af2f4f3bce398823b5a36e5761b75
cloudflared-darwin-arm64.tgz: 9a0b19f67dc7a3011bc6b972c7ce06a5fcea8784ac6bd599ffa382ea4aeb5a6e
cloudflared-fips-linux-amd64: 7fac1c6aae4ae2131e73056d88c3e35a7120feaa9088333e737d25ae9bb5116c
cloudflared-fips-linux-amd64.deb: 673e05158218563b415532e30f2cb1d68ae73b908ffc0b0e526b9d852937480c
cloudflared-fips-linux-x86_64.rpm: 485dc5891fd1944b67b9bac4541a37a066888240007127ee07edd7f37ac96e21
cloudflared-linux-386: 5d66134cf7646cb98f33aeee7bcc8b97d8feacd76db279f5903f9585226e0922
cloudflared-linux-386.deb: 7e57a9d784613fb5df8b8702e34aeabe0f6ceeaddb0a52885fef0aed9195bd11
cloudflared-linux-386.rpm: bde6c912d0e782eeddb6bbd4f0ca82f3a8919d16e00ade13d3cb8a4a0cd3fde1
cloudflared-linux-aarch64.rpm: 01c79e73b1e2b534e43352076cc5494d99049c097b8ffe4357462c79115446f7
cloudflared-linux-amd64: 03f1f25d1cc93b9ad6c60569d44060bc4f17ed97075760ed8cfca4b12dcd68cc
cloudflared-linux-amd64.deb: 3be76adc4185d36a0bfb4c2dd8663292f0ed363797f2180333b513b43c81d419
cloudflared-linux-arm: 093ffa3638ab2b636de63c43a8c68f96a69cf71f9699dd8277a91b160b0f4fc0
cloudflared-linux-arm.deb: a53341634814b4d0f44147b8ba73169e33b160135d2a9224ba9fd2ea4beef5af
cloudflared-linux-arm.rpm: 1f1dd1afecb74d1936e48758fd01089274b2770e1d291154fd9b13592eff937b
cloudflared-linux-arm64: 3d97437c71848bd8df68041e12436b484a661d95073ea1937f01a845ce88faa3
cloudflared-linux-arm64.deb: 2a870d5bf6ea74d16c0923b804eabbf4943f1fd7c63a5c20fd41cc66b629c725
cloudflared-linux-armhf: 95420507a720fb543122a5d69372fbde8f5c919790e95ddd4374a449e0a6f4dd
cloudflared-linux-armhf.deb: 813dc2ff3af161ec77c7fab4b84a15c732e03f5503bb709e3f51bb82ac261ca5
cloudflared-linux-armhf.rpm: b5ef384fc490cc1cc891322012bc001ae2ea9c36370b8cb71369256b9c84b54d
cloudflared-linux-x86_64.rpm: e9e2daff5ecc2b3e8d3a5e1ce17f95b3dc2360e6bb846da29647bbb967cf52b9
cloudflared-windows-386.exe: 11b6e4b2d306950bd87e7caa4deee8e80a32d71ffee555a96237a76651eeae4c
cloudflared-windows-386.msi: 8086e90565aa5e864df664242706e819341547525c220ca09f785d4969edfdae
cloudflared-windows-amd64.exe: 2837888cc0f5d58f15b6dc478376de90b4d3ba5241c7947455d1e0a0df429712
cloudflared-windows-amd64.msi: 6f85717310db514c0db658c3b7bbdff36c1d613c4edeafb4981b3160cc7b836f

v2026.9.0

Compare Source

SHA256 Checksums:
cloudflared-amd64.pkg: 57f6a86a7f77b75722227729f6d6ce41e5ab1bc82415bd4d39a734c7d9e0c4ce
cloudflared-arm64.pkg: 3372ef71d54c93217efeeec486e53c44b8746032ff0a85088556ed51c80e1a6d
cloudflared-darwin-amd64.tgz: 53481a9eed22fbf29cf3be7638d7c437acb423cdbe06e62639d8467b05d2f44f
cloudflared-darwin-arm64.tgz: 2d67b7315f96799123e19442580ce7c7616d6d7f322686fa829dd4e3fddfe715
cloudflared-fips-linux-amd64: 2accaa85e279995f2e1e0179e5258c99dcafbafbbeb559f05eb031daa4c57f08
cloudflared-fips-linux-amd64.deb: 543e1513f60ec7a2c47970b0769cf354da5430dc046138fa6f05938d9533b2bc
cloudflared-fips-linux-x86_64.rpm: b45120bdc6e43b3eadf8043836252763afa3d9fd1c0b2c0d345de1911ff053ff
cloudflared-linux-386: d18731b05ae5c457ae5bdab76f0d517918403789ac7df754e37565d8375c6f24
cloudflared-linux-386.deb: 97e56b9818b2b94556507dd06949033d6d59e5de37d2ced6c56ef230186e7f5d
cloudflared-linux-386.rpm: 89f5d28faa57b710e1d3280198790be2a62167b9d29a89789e7ac13619755762
cloudflared-linux-aarch64.rpm: 842ee766fb9b6d97ab8be35131738db72eb6a13f78de775d29f802a67672e6bd
cloudflared-linux-amd64: 53b7a7a5420d188758d24341294acb0d1bca54296548ac05e38811a694ac6134
cloudflared-linux-amd64.deb: 1ea48af7a774376b71e329c6fdc0b7853298df270356132a294f8d8d5eb0e543
cloudflared-linux-arm: 0077f9b0ce9d9bd95e67c22aff33d132c83513c0e80b0bc686f00fe418bb336b
cloudflared-linux-arm.deb: 68af658a4d6a812c613c804f5a4e93287797f84597e1657f7a491ef3b3837284
cloudflared-linux-arm.rpm: c21f54f6966ab1148d3e15af2a8e15a380ab1c0cb7d0feab84b27e19a7ef230c
cloudflared-linux-arm64: 98aca3173f73248fad6180fc75dade2d186a6e54fa807e088108cb4345de8efe
cloudflared-linux-arm64.deb: 2355fac318375a79d4f62690251e92a52d56f2737e30f053bb3419000fc32593
cloudflared-linux-armhf: 738271eeb53f010c30c559071fa7b312262bbcad2f358232fb4b710075d80d47
cloudflared-linux-armhf.deb: 444a5b5e8db1bb0b5b58d2889b05d9a6c2e04656139fc24e3a39355eb57c94bf
cloudflared-linux-armhf.rpm: 059ff745b6483b25b8fb7ff7d7d66eda822fa5c4b40f2d6c7318693422e819b1
cloudflared-linux-x86_64.rpm: 8f2ba4ee8655edf99adece12c1b93776bbdb29b8ef7a3e8bdb5193699c93eb22
cloudflared-windows-386.exe: e11ee417d5bab1918c3e257c2b1f9541d6febd545091ecf87e249c3cfb7880b0
cloudflared-windows-386.msi: af64b20c2c71419a3641f24c1e2b7f6d039da7dfb24b8986b6d599ab870ab94a
cloudflared-windows-amd64.exe: 547057326266f0e1c7d50d102dbd22ff283d740c055bd61e94f10e2c606f89af
cloudflared-windows-amd64.msi: 7ee5b66c158c40f8f6cb62b01b7e48ee8cf5907e35b1a1fad3534d41b6d29488
container-registry/harbor-workload-identity-federation (container-registry/harbor-workload-identity-federation)

v0.1.0

Compare Source

Features
  • installer: Wire kubelet on AKS, RKE2, and MicroK8s (#​18) (7295be7)
Bug Fixes
  • chart: Harden the DaemonSet and validate values at install time (#​14) (e5945d1)
  • installer: Check the error from closing the copy source (#​21) (bf65595)
  • Restart the right rke2 unit, and stop asking for --api-audiences (#​27) (784be99)
Documentation
  • Add a page per Kubernetes distribution (#​15) (bb72443)
  • Add Talos Linux WIF example (a622c35)
  • Add Talos WIF example (4564615)
  • Call the Harbor side Trusted Issuers (#​16) (14cd8c8)
  • Fix provider name in Talos workload example comment (3522323)
  • Rename Workload Identity Federation to Federated Robot Accounts (#​10) (8c8c995)
  • update contributors (309fb69)
  • Update the README to convey what the code does (#​25) (c6fbc41)
  • Use GitHub alerts in Talos example (1eaba83)
  • Use official Talos harbor-credential-provider extension (7e386ca)
containers/crun (containers/crun)

v1.30

Compare Source

  • CVE-2026-84042: prevent that rootful krun with passt can execute
    payload from container without proper confinement.
  • CVE-2026-88264: do not follow symlinks when creating /dev/console.
    A rootfs providing /dev/console as a symlink made crun create a root
    owned file on the host at a path chosen by the container image, since
    the devices are created before the pivot_root.
  • CVE-2026-88265: validate /dev/null before reopening the std streams.
    A rootfs providing /dev/null as a symlink to a host file bind mounted
    into the container made crun replace the pipe- or socketpair-based
    std streams with a writable descriptor for that file, and chown it to
    the container user. Refuse to continue unless /dev/null is the
    character device 1:3, and only consider std streams that are
    character devices themselves.
  • linux: skip OPEN_TREE_NAMESPACE when a bind source holds a pinned
    namespace. A recursive clone of such a source picks one up, so the
    bind mount cannot be attached from inside the namespace created by
    OPEN_TREE_NAMESPACE, and by then there is no way to mount it at all.
  • krun: use absolute path for passt binary.
  • krun: support TAP-backed networking.
  • krun: start render server if required.
  • linux: convert sysctl keys to /proc/sys paths as described in
    sysctl.d(5), fixing sysctls for interface names containing dots
    (e.g. VLAN interfaces such as "eth0.100").
  • criu: fix --network-lock, which did not take the method argument.
  • criu: block signals as soon as the container is restored, so that
    a signal arriving before crun starts forwarding them is delivered to
    the container init instead of killing crun.
  • criu: block signals across the vfork used for a detached restore, so
    that a signal handler of a program embedding libcrun no longer runs
    in the child and corrupts the state of the suspended caller.
  • build: add --enable-werror and --enable-sanitizers configure options.
  • release: add crun.keyring with the release signing keys
  • linux: apply recursive propagation flags recursively. A 1.29
    regression dropped MS_REC when mount_setattr() is available, so an
    "rslave" mount only had its top level mount converted and a mount
    created by the container under it propagated back to the host,
    clobbering the devpts of the host for a container bind mounting /dev.
  • linux: clear the flags which are not requested on a read-only
    remount, so that a "bind,ro" mount of a nosuid,nodev,noexec source
    only gets the requested flag, as it was before 1.27.
  • linux: honor options which only clear flags (e.g. "dev", "suid",
    "exec", "rw") for bind mounts instead of silently keeping the flags
    of the source.
  • linux: clear nosymfollow on remount unless it is requested.
  • linux: set the atime flags the way mount(2) does, so that e.g. a
    "bind,relatime" mount of a noatime source is no longer left with
    noatime.
  • linux: fix idmapped bind mounts with a relative source.
  • linux: do not crash on a mount without a type. This is reproducible
    with podman by running a container with a CDI device in a pod that
    has a user namespace, as the mounts in a CDI specification usually
    have no type.
  • linux: do not crash on a mount without a source, or on a null entry
    in maskedPaths or readonlyPaths; reject them with EINVAL.
  • libcrun: cope with a JSON null where the configuration expects a
    string, instead of dereferencing it.
  • cgroup: refuse to run in a frozen cgroup, like runc does, instead of
    hanging forever with no indication of what is going on.
  • cgroup: destroy the cgroup if its setup fails, so that an invalid
    resource limit no longer leaves an empty cgroup behind.
  • cgroup: treat an empty cgroup path in the status file as no cgroup,
    fixing "crun update" on a container started with
    --cgroup-manager=disabled.
  • cgroup: handle a device entry with no "access" in the cgroup v1
    writer, which wrote "c 1:3 (null)" to devices.allow.
  • exec: use the systemd AttachProcessesToUnit method as a fallback when
    writing to cgroup.procs is denied, fixing "crun exec" for a rootless
    user in a login session when the container uses the systemd cgroup
    manager.
  • exec: use exit code 255 for "crun exec" failures, like runc does, so
    that they can be told apart from the executed process exiting with 1.
  • exec: use the same error as runc for a paused container.
  • seccomp: apply all the argument conditions, removing the arbitrary
    limit of 6 conditions.
  • seccomp: validate the argument indices once per syscall entry, so an
    out of range index is no longer accepted when every name of the entry
    is unknown to libseccomp.
  • seccomp: checksum every field that affects the generated filter, so a
    cached filter is not reused for a different configuration.
  • restore: forward signals to the container init on a foreground
    restore, so that a ^C no longer kills crun and leaves the container
    running.
  • restore: use a throw-away process to drive a detached restore, so
    that a program embedding libcrun is no longer moved in and out of the
    container cgroup and left with the container init as a child.
  • restore: put CRIU into the container cgroup, so that the restored
    tasks are created there.
  • restore: fix --manage-cgroups-mode, which was always overridden with
    the default "soft" mode.
  • restore: fix bind mounts with a relative source, and create the
    missing mountpoints inside the bind mount sources.
  • checkpoint: fix masked directories with a non-default --root.
  • criu: only relocate the unified hierarchy on restore with cgroup v2,
    so that named v1 hierarchies are no longer duplicated on every
    checkpoint and restore.
  • criu: fix stripping the rootfs prefix from the mount destination when
    the rootfs is "/" or not set.
  • container: report the bundle path consistently, and pass it to the
    createRuntime and poststart hooks instead of the working directory of
    crun.
  • container: tell the hook type and its number when a hook fails.
  • scheduler: reject a SCHED_DEADLINE value equal to 2^63.
  • scheduler: fix the CPU affinity reset on systems with more than 1024
    CPUs, and fix the CPU_ALLOC argument, which allocated a set about 8
    times smaller than needed.
  • ring_buffer: fix an off-by-one in the wrapped regions, which could
    truncate or garble the pty output once the ring buffer wrapped and
    was drained partially.
  • intelrdt: fix a signed overflow in the schemata comparator, which
    could misorder the qsort() and send the bsearch() down the wrong
    branch.
  • status: fix a NULL dereference on the optional "owner" and
    "external_descriptors" fields, which crashed "crun list --format=json"
    and the checkpoint path on a status file without them.
  • utils: fall back to the uid_map heuristic to detect the initial user
    namespace on OpenVZ, and on kernels without /proc/self/ns/user.
  • utils: say that the AppArmor profile is not loaded instead of
    reporting a confusing ENOENT on the procfs file.
  • wamr: resolve the wasi socket pool functions via dlsym, fixing the
    undefined references at link time.
  • python, lua: fix the bindings, which were missing the "start" method,
    had a duplicate "spec" entry and a broken context capsule destructor.
fosrl/newt (fosrl/newt)

v1.17.0

Compare Source

Container Images

  • GHCR: ghcr.io/fosrl/newt@sha256:3465d85200cceb0f46dad8e63a40b69ec043a81df66ed0c514714302e9b83dde
  • Docker Hub: docker.io/fosrl/newt@sha256:3465d85200cceb0f46dad8e63a40b69ec043a81df66ed0c514714302e9b83dde
    Tag: 1.17.0

What's Changed

  • Add support for local endpoint interface allowlist
  • Add aliased SITE_ prefixed env vars
  • Add support for importing into the CLI package for running there with pangolin up site
  • Fix crashing with nil pointer checks
  • Fix accept bare site addresses in client WireGuard config by @​totalolage in #​435
  • Update dependencies

New Contributors

Full Changelog: fosrl/newt@1.16.0...1.17.0

anchore/grype (github.com/anchore/grype)

v0.119.0

Compare Source

Added Features
  • Expose distro-fixed dropped matches via ignoredMatches so --show-suppressed can surface them [Issue #​3450] [PR #​3705 @​philroche]
  • Licensing: copyright owner missing, needed for Debian packaging [Issue #​3501]
Bug Fixes
  • fixes typo in cpe example input for cpe-direct scan [PR #​3679 @​zhill]
  • --by-cve: which advisory record survives the merge varies between runs [Issue #​3630]
Additional Changes
Dependencies

54 dependency changes (54 updated). 6 vulnerabilities remediated.

🟢 Remediated (6)

Updated (54 packages)
  • cloud.google.com/go/auth v0.22.0 → v0.23.2
  • cloud.google.com/go/iam v1.11.0 → v1.12.0
  • cloud.google.com/go/logging v1.18.0 → v1.19.0
  • cloud.google.com/go/monitoring v1.29.0 → v1.30.0
  • cloud.google.com/go/storage v1.64.0 → v1.65.1
  • github.com/CycloneDX/cyclonedx-go v0.11.0 → v0.12.0
  • github.com/anchore/go-sync v0.1.1 → v0.1.2
  • github.com/anchore/stereoscope v0.3.1 → v0.3.2
  • github.com/anchore/syft v1.51.1 → v1.52.0
  • github.com/aws/aws-sdk-go-v2 v1.43.4 → v1.44.0
  • github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.16 → v1.7.20
  • github.com/aws/aws-sdk-go-v2/config v1.32.35 → v1.32.40
  • github.com/aws/aws-sdk-go-v2/credentials v1.19.34 → v1.19.39
  • github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.35 → v1.18.40
  • github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.35 → v1.4.40
  • github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.35 → v2.7.40
  • github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.36 → v1.4.41
  • github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.15 → v1.13.19
  • github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.28 → v1.10.0
  • github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.35 → v1.13.40
  • github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.36 → v1.19.41
  • github.com/aws/aws-sdk-go-v2/service/s3 v1.106.5 → v1.108.0
  • github.com/aws/aws-sdk-go-v2/service/signin v1.5.4 → v1.6.0
  • github.com/aws/aws-sdk-go-v2/service/sso v1.33.4 → v1.34.0
  • github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.4 → v1.39.0
  • github.com/aws/aws-sdk-go-v2/service/sts v1.45.4 → v1.46.0
  • github.com/aws/smithy-go v1.27.6 → v1.28.1
  • github.com/containerd/containerd/v2 v2.3.4 → v2.3.5 (🟢 remediated GHSA-7jxh-36q5-gcqv)
  • github.com/docker/cli v29.7.2+incompatible → v29.8.0+incompatible
  • github.com/google/go-containerregistry v0.21.9 → v0.22.1
  • github.com/googleapis/enterprise-certificate-proxy v0.3.19 → v0.3.20
  • github.com/googleapis/gax-go/v2 v2.23.0 → v2.24.0
  • github.com/gpustack/gguf-parser-go v0.25.0 → v0.26.3
  • github.com/hashicorp/go-getter v1.8.8 → v1.8.9
  • github.com/klauspost/compress v1.19.2 → v1.20.0
  • github.com/moby/moby/api v1.55.0 → v1.56.0
  • github.com/moby/moby/client v0.5.1 → v0.6.0
  • github.com/pandatix/go-cvss v0.6.2 → v0.6.4
  • github.com/terminalstatic/go-xsd-validate v0.1.6 → v0.1.8
  • golang.org/x/crypto v0.55.0 → v0.56.0 (🟢 remediated GO-2026-6354, GO-2026-6355)
  • golang.org/x/mod v0.40.0 → v0.41.0
  • golang.org/x/time v0.15.0 → v0.16.0
  • google.golang.org/api v0.292.0 → v0.294.0
  • google.golang.org/genproto v0.0.0-aa98bba → v0.0.0-e75dac1
  • google.golang.org/genproto/googleapis/api v0.0.0-925bb5d → v0.0.0-e75dac1
  • google.golang.org/genproto/googleapis/rpc v0.0.0-6ac0973 → v0.0.0-08b0e42
  • google.golang.org/grpc v1.83.0 → v1.83.2 (🟢 remediated GHSA-2v4p-qf9q-27wj, GHSA-qc2q-p7wx-3px3, GHSA-vp52-pcj8-j9qc)
  • google.golang.org/protobuf v1.36.12-0.f2248ac → v1.36.12
  • modernc.org/cc/v4 v4.29.1 → v4.29.2
  • modernc.org/ccgo/v4 v4.34.6 → v4.35.0
  • modernc.org/gc/v3 v3.1.4 → v3.1.5
  • modernc.org/libc v1.74.4 → v1.75.6
  • modernc.org/memory v1.11.0 → v1.12.1
  • modernc.org/sqlite v1.56.0 → v1.58.0

(Full Changelog)

v0.118.0

Compare Source

Added Features
Bug Fixes
Dependencies

72 dependency changes (70 updated, 1 added, 1 removed). 3 vulnerabilities remediated.

🟢 Remediated (3)

Updated (70 packages)
  • cel.dev/expr v0.25.1 → v0.25.2
  • cloud.google.com/go/auth v0.18.2 → v0.22.0
  • cloud.google.com/go/iam v1.5.3 → v1.11.0
  • cloud.google.com/go/logging v1.13.1 → v1.18.0
  • cloud.google.com/go/longrunning v0.8.0 → v1.2.0
  • cloud.google.com/go/monitoring v1.24.3 → v1.29.0
  • cloud.google.com/go/storage v1.61.3 → v1.64.0
  • cloud.google.com/go/trace v1.11.7 → v1.16.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.32.0 → v1.33.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0 → v0.57.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock v0.55.0 → v0.57.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0 → v0.57.0
  • github.com/anchore/stereoscope v0.3.0 → v0.3.1
  • github.com/anchore/syft v1.51.0 → v1.51.1
  • github.com/aws/aws-sdk-go-v2 v1.41.5 → v1.43.4
  • github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.8 → v1.7.16
  • github.com/aws/aws-sdk-go-v2/config v1.32.12 → v1.32.35
  • github.com/aws/aws-sdk-go-v2/credentials v1.19.12 → v1.19.34
  • github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.20 → v1.18.35
  • github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.21 → v1.4.35
  • github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.21 → v2.7.35
  • github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.22 → v1.4.36
  • github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.7 → v1.13.15
  • github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.13 → v1.9.28
  • github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.21 → v1.13.35
  • github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.21 → v1.19.36
  • github.com/aws/aws-sdk-go-v2/service/s3 v1.97.3 → v1.106.5
  • github.com/aws/aws-sdk-go-v2/service/signin v1.0.8 → v1.5.4
  • github.com/aws/aws-sdk-go-v2/service/sso v1.30.13 → v1.33.4
  • github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.17 → v1.38.4
  • github.com/aws/aws-sdk-go-v2/service/sts v1.41.9 → v1.45.4
  • github.com/aws/smithy-go v1.24.2 → v1.27.6
  • github.com/containerd/containerd/v2 v2.3.3 → v2.3.4
  • github.com/containerd/platforms v1.0.0-rc.4 → v1.0.0-rc.5
  • github.com/docker/cli v29.6.1+incompatible → v29.7.2+incompatible
  • github.com/docker/go-connections v0.7.0 → v0.8.1
  • github.com/fatih/color v1.18.0 → v1.19.0
  • github.com/google/go-containerregistry v0.21.7 → v0.21.9
  • github.com/google/pprof v0.0.0-6e76a2b → v0.0.0-ef3492d
  • github.com/googleapis/enterprise-certificate-proxy v0.3.14 → v0.3.19
  • github.com/googleapis/gax-go/v2 v2.17.0 → v2.23.0
  • github.com/hashicorp/aws-sdk-go-base/v2 v2.0.0-beta.72 → v2.0.0-beta.74
  • github.com/hashicorp/go-getter v1.8.6 → v1.8.8
  • github.com/hashicorp/go-version v1.8.0 → v1.9.0
  • github.com/klauspost/compress v1.19.1 → v1.19.2
  • github.com/mattn/go-isatty v0.0.20 → v0.0.24
  • github.com/moby/moby/client v0.5.0 → v0.5.1
  • github.com/spiffe/go-spiffe/v2 v2.6.0 → v2.7.0
  • github.com/stretchr/objx v0.5.2 → v0.5.3
  • github.com/stretchr/testify v1.11.1 → v1.12.1
  • go.opentelemetry.io/contrib/detectors/gcp v1.43.0 → v1.44.0
  • go.opentelemetry.io/otel v1.43.0 → v1.44.0 (🟢 remediated GO-2026-5158)
  • go.opentelemetry.io/otel/exporters/stdout/stdoutmetric v1.40.0 → v1.44.0
  • go.opentelemetry.io/otel/metric v1.43.0 → v1.44.0
  • go.opentelemetry.io/otel/sdk v1.43.0 → v1.44.0
  • go.opentelemetry.io/otel/sdk/metric v1.43.0 → v1.44.0
  • go.opentelemetry.io/otel/trace v1.43.0 → v1.44.0
  • golang.org/x/crypto v0.54.0 → v0.55.0
  • golang.org/x/mod v0.38.0 → v0.40.0 (🟢 remediated GO-2026-6179, GO-2026-6180)
  • golang.org/x/net v0.57.0 → v0.58.0
  • golang.org/x/text v0.40.0 → v0.41.0
  • golang.org/x/tools v0.48.0 → v0.49.0
  • google.golang.org/api v0.271.0 → v0.292.0
  • google.golang.org/genproto v0.0.0-8636f87 → v0.0.0-aa98bba
  • google.golang.org/genproto/googleapis/api v0.0.0-afd174a → v0.0.0-925bb5d
  • google.golang.org/genproto/googleapis/rpc v0.0.0-afd174a → v0.0.0-6ac0973
  • google.golang.org/grpc v1.82.1 → v1.83.0
  • modernc.org/cc/v4 v4.29.0 → v4.29.1
  • modernc.org/libc v1.74.1 → v1.74.4
  • modernc.org/sqlite v1.55.0 → v1.56.0
Added (1 package)
  • go.opentelemetry.io/otel/metric/x v0.66.0
Removed (1 package)
  • github.com/aws/aws-sdk-go-v2/internal/ini v1.8.6

(Full Changelog)

v0.117.0

Compare Source

Added Features
Bug Fixes
Dependencies

11 dependency changes (11 updated). 2 vulnerabilities remediated.

🟢 Remediated (2)

Updated (11 packages)
  • github.com/anchore/syft v1.50.0 → v1.51.0
  • github.com/diskfs/go-diskfs v1.9.3 → v1.9.4
  • github.com/gabriel-vasile/mimetype v1.4.13 → v1.4.15
  • github.com/go-git/go-billy/v5 v5.9.0 → v5.9.1
  • github.com/go-git/go-git/v5 v5.19.1 → v5.19.2 (🟢 remediated GHSA-hc8v-wwc9-vgxm, GHSA-qgq7-7hm3-q39j)
  • github.com/klauspost/compress v1.19.0 → v1.19.1
  • github.com/magiconair/properties v1.8.10 → v1.18.11
  • github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 → v6.0.3
  • github.com/ulikunitz/xz v0.5.15 → v0.5.16
  • go.yaml.in/yaml/v3 v3.0.4 → v3.0.5
  • modernc.org/sqlite v1.54.0 → v1.55.0

(Full Changelog)

v0.116.1

Compare Source

Bug Fixes
Dependencies

30 dependency changes (30 updated). 1 vulnerability remediated.

🟢 Remediated (1)

Updated (30 packages)
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.31.0 → v1.32.0
  • github.com/anchore/stereoscope v0.2.2 → v0.3.0
  • github.com/anchore/syft v1.48.0 → v1.50.0
  • github.com/cncf/xds/go v0.0.0-ee656c7 → v0.0.0-dba9d58
  • github.com/containerd/containerd/v2 v2.3.2 → v2.3.3
  • github.com/docker/cli v29.5.3+incompatible → v29.6.1+incompatible
  • github.com/envoyproxy/go-control-plane/envoy v1.36.0 → v1.37.0
  • github.com/envoyproxy/protoc-gen-validate v1.3.0 → v1.3.3
  • github.com/gkampitakis/go-snaps v0.5.22 → v0.5.23
  • github.com/gpustack/gguf-parser-go v0.24.1 → v0.25.0
  • github.com/moby/moby/api v1.54.2 → v1.55.0
  • github.com/moby/moby/client v0.4.1 → v0.5.0
  • github.com/pelletier/go-toml/v2 v2.3.1 → v2.4.3
  • go.opentelemetry.io/contrib/detectors/gcp v1.39.0 → v1.43.0
  • golang.org/x/crypto v0.53.0 → v0.54.0
  • golang.org/x/mod v0.37.0 → v0.38.0
  • golang.org/x/net v0.56.0 → v0.57.0
  • golang.org/x/sync v0.21.0 → v0.22.0
  • golang.org/x/sys v0.46.0 → v0.47.0
  • golang.org/x/term v0.44.0 → v0.45.0
  • golang.org/x/text v0.39.0 → v0.40.0
  • golang.org/x/tools v0.47.0 → v0.48.0
  • google.golang.org/genproto/googleapis/api v0.0.0-9d38bb4 → v0.0.0-afd174a
  • google.golang.org/genproto/googleapis/rpc v0.0.0-6f92a3b → v0.0.0-afd174a
  • google.golang.org/grpc v1.80.0 → v1.82.1 (🟢 remediated GHSA-hrxh-6v49-42gf)
  • modernc.org/cc/v4 v4.28.4 → v4.29.0
  • modernc.org/ccgo/v4 v4.34.4 → v4.34.6
  • modernc.org/gc/v3 v3.1.3 → v3.1.4
  • modernc.org/libc v1.73.4 → v1.74.1
  • modernc.org/sqlite v1.53.0 → v1.54.0

(Full Changelog)

v0.116.0

Compare Source

Added Features
Bug Fixes
  • regenerate v6.1.8 blob and sql schemas [PR #​3574 @​spiffcs]
  • rhel version streams [PR #​3572 @​kzantow]
  • Grype doesn't match u-boot in SBOM if type is set to firmware [Issue #​2537]
  • Ignore Go compiler affecting CVE when Docker image only contains a binary compiled with Go [Issue #​1782]
  • Zarf scans emit warnings for consistently unreadable files (i.e., included non-SBOMs) [Issue #​3516] [PR #​3545 @​brandtkeller]
  • Fail parsing github actions [Issue #​3220]
  • Go vulnerability returned when installed version is greater than fixed version [Issue #​3520]
Dependencies

14 dependency changes (11 updated, 3 added).

Updated (11 packages)
  • github.com/anchore/go-rpmdb v0.1.0 → v0.2.0
  • github.com/anchore/syft v1.46.0 → v1.48.0
  • github.com/klauspost/compress v1.18.6 → v1.19.0
  • golang.org/x/te

❗ Important

✂ PR body was truncated to here.

@renovate
renovate Bot force-pushed the renovate/dependencies branch 3 times, most recently from 5ba679a to 8b58a61 Compare December 31, 2024 20:44
@renovate
renovate Bot force-pushed the renovate/dependencies branch 4 times, most recently from 490052d to 23754db Compare January 9, 2025 12:01
@renovate
renovate Bot force-pushed the renovate/dependencies branch 6 times, most recently from c9a1639 to 5aabad4 Compare January 17, 2025 07:19
@renovate
renovate Bot force-pushed the renovate/dependencies branch 5 times, most recently from 6e3a52e to 3c9057e Compare January 25, 2025 12:15
@renovate
renovate Bot force-pushed the renovate/dependencies branch 5 times, most recently from 37862c0 to ade8620 Compare February 5, 2025 00:08
@renovate
renovate Bot force-pushed the renovate/dependencies branch 7 times, most recently from 88a8ea0 to 849332e Compare February 12, 2025 12:33
@renovate
renovate Bot force-pushed the renovate/dependencies branch 8 times, most recently from dee5df0 to 2ed628e Compare March 10, 2025 09:42
@renovate
renovate Bot force-pushed the renovate/dependencies branch from 2ed628e to 8833055 Compare March 10, 2025 20:32
@smira smira closed this Apr 2, 2025
@smira
smira deleted the renovate/dependencies branch April 2, 2025 13:51
@smira
smira restored the renovate/dependencies branch April 2, 2025 15:12
@smira smira reopened this Apr 2, 2025
@github-project-automation github-project-automation Bot moved this to To Do in Planning Apr 2, 2025
@talos-bot talos-bot moved this from To Do to In Review in Planning Apr 2, 2025
@smira
smira force-pushed the renovate/dependencies branch from 8833055 to 9d222f7 Compare April 2, 2025 15:42
@smira smira removed this from Planning Apr 2, 2025
@renovate
renovate Bot force-pushed the renovate/dependencies branch 3 times, most recently from 95295d4 to 66ab4f9 Compare April 6, 2025 11:50
@renovate
renovate Bot force-pushed the renovate/dependencies branch 5 times, most recently from 929d827 to 83bdebd Compare April 17, 2025 13:15
@renovate
renovate Bot force-pushed the renovate/dependencies branch from 83bdebd to 1e5f791 Compare April 19, 2025 11:22
@renovate

renovate Bot commented Apr 24, 2026 •

Copy link
Copy Markdown
Author

ℹ️ Artifact update notice

File name: internal/grype-scan/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 120 additional dependencies were updated

Details:

Package Change
cel.dev/expr v0.25.1 -> v0.25.2
cloud.google.com/go/auth v0.18.1 -> v0.23.2
cloud.google.com/go/iam v1.5.3 -> v1.12.0
cloud.google.com/go/monitoring v1.24.3 -> v1.30.0
cloud.google.com/go/storage v1.60.0 -> v1.65.1
github.com/CycloneDX/cyclonedx-go v0.10.0 -> v0.12.0
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.30.0 -> v1.33.0
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0 -> v0.57.0
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0 -> v0.57.0
github.com/Masterminds/semver/v3 v3.4.0 -> v3.5.0
github.com/Microsoft/go-winio v0.6.2 -> v0.6.3-0.20251027160822-ad3df93bed29
github.com/Microsoft/hcsshim v0.14.0-rc.1 -> v0.15.0-rc.1
github.com/ProtonMail/go-crypto v1.4.0 -> v1.4.1
github.com/anchore/bubbly v0.2.0 -> v0.2.1
github.com/anchore/clio v0.1.0 -> v0.1.1
github.com/anchore/fangs v0.1.0 -> v0.1.1
github.com/anchore/go-collections v0.1.0 -> v0.1.1
github.com/anchore/go-homedir v0.1.0 -> v0.1.1
github.com/anchore/go-logger v0.1.0 -> v0.1.1
github.com/anchore/go-lzo v0.1.0 -> v0.1.1
github.com/anchore/go-macholibre v0.1.0 -> v0.1.1
github.com/anchore/go-rpmdb v0.1.0 -> v0.2.0
github.com/anchore/go-struct-converter v0.1.0 -> v0.2.0-rc2
github.com/anchore/go-sync v0.1.0 -> v0.1.2
github.com/anchore/stereoscope v0.1.22 -> v0.3.2
github.com/aws/aws-sdk-go-v2 v1.41.2 -> v1.44.0
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.4 -> v1.7.20
github.com/aws/aws-sdk-go-v2/config v1.32.10 -> v1.32.40
github.com/aws/aws-sdk-go-v2/credentials v1.19.10 -> v1.19.39
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.18 -> v1.18.40
github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.18 -> v1.4.40
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.18 -> v2.7.40
github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.17 -> v1.4.41
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.5 -> v1.13.19
github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.8 -> v1.10.0
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.18 -> v1.13.40
github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.17 -> v1.19.41
github.com/aws/aws-sdk-go-v2/service/s3 v1.96.0 -> v1.108.0
github.com/aws/aws-sdk-go-v2/service/signin v1.0.6 -> v1.6.0
github.com/aws/aws-sdk-go-v2/service/sso v1.30.11 -> v1.34.0
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.15 -> v1.39.0
github.com/aws/aws-sdk-go-v2/service/sts v1.41.7 -> v1.46.0
github.com/aws/smithy-go v1.24.1 -> v1.28.1
github.com/charmbracelet/colorprofile v0.4.1 -> v0.4.3
github.com/clipperhouse/displaywidth v0.10.0 -> v0.11.0
github.com/clipperhouse/uax29/v2 v2.6.0 -> v2.7.0
github.com/cncf/xds/go v0.0.0-20251210132809-ee656c7534f5 -> v0.0.0-20260202195803-dba9d589def2
github.com/containerd/cgroups/v3 v3.1.2 -> v3.1.3
github.com/containerd/containerd/api v1.10.0 -> v1.11.1
github.com/containerd/containerd/v2 v2.2.1 -> v2.3.5
github.com/containerd/continuity v0.4.5 -> v0.5.0
github.com/containerd/platforms v1.0.0-rc.2 -> v1.0.0-rc.5
github.com/containerd/plugin v1.0.0 -> v1.1.0
github.com/containerd/ttrpc v1.2.7 -> v1.2.8
github.com/cyphar/filepath-securejoin v0.6.0 -> v0.6.1
github.com/diskfs/go-diskfs v1.7.0 -> v1.9.4
github.com/docker/cli v29.3.0+incompatible -> v29.8.0+incompatible
github.com/docker/go-connections v0.6.0 -> v0.8.1
github.com/envoyproxy/go-control-plane/envoy v1.36.0 -> v1.37.0
github.com/envoyproxy/protoc-gen-validate v1.3.0 -> v1.3.3
github.com/fatih/color v1.18.0 -> v1.19.0
github.com/gabriel-vasile/mimetype v1.4.13 -> v1.4.15
github.com/github/go-spdx/v2 v2.4.0 -> v2.7.0
github.com/go-git/go-billy/v5 v5.8.0 -> v5.9.1
github.com/go-git/go-git/v5 v5.17.0 -> v5.19.2
github.com/go-jose/go-jose/v4 v4.1.3 -> v4.1.4
github.com/google/go-containerregistry v0.21.3 -> v0.22.1
github.com/google/pprof v0.0.0-20250630185457-6e76a2b096b5 -> v0.0.0-20260802141513-ef3492d7dac3
github.com/googleapis/enterprise-certificate-proxy v0.3.11 -> v0.3.20
github.com/googleapis/gax-go/v2 v2.17.0 -> v2.24.0
github.com/gookit/color v1.6.0 -> v1.6.1
github.com/gpustack/gguf-parser-go v0.24.0 -> v0.26.3
github.com/hashicorp/aws-sdk-go-base/v2 v2.0.0-beta.70 -> v2.0.0-beta.74
github.com/hashicorp/go-getter v1.8.5 -> v1.8.9
github.com/hashicorp/go-version v1.8.0 -> v1.9.0
github.com/klauspost/compress v1.18.5 -> v1.20.0
github.com/mattn/go-isatty v0.0.20 -> v0.0.24
github.com/mattn/go-runewidth v0.0.19 -> v0.0.21
github.com/moby/moby/api v1.54.0 -> v1.56.0
github.com/moby/moby/client v0.3.0 -> v0.6.0
github.com/openvex/go-vex v0.2.7 -> v0.2.8
github.com/package-url/packageurl-go v0.1.3 -> v0.1.5
github.com/pandatix/go-cvss v0.6.2 -> v0.6.4
github.com/pelletier/go-toml/v2 v2.2.4 -> v2.4.3
github.com/pierrec/lz4/v4 v4.1.22 -> v4.1.26
github.com/pjbgf/sha1cd v0.4.0 -> v0.6.0
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 -> v6.0.3
github.com/spdx/tools-golang v0.5.7 -> v0.6.0-rc4
github.com/spiffe/go-spiffe/v2 v2.6.0 -> v2.7.0
github.com/sylabs/sif/v2 v2.24.0 -> v2.24.1
github.com/ulikunitz/xz v0.5.15 -> v0.5.16
go.opentelemetry.io/contrib/detectors/gcp v1.39.0 -> v1.44.0
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.63.0 -> v0.68.0
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.62.0 -> v0.68.0
go.opentelemetry.io/otel v1.40.0 -> v1.44.0
go.opentelemetry.io/otel/metric v1.40.0 -> v1.44.0
go.opentelemetry.io/otel/sdk v1.40.0 -> v1.44.0
go.opentelemetry.io/otel/sdk/metric v1.40.0 -> v1.44.0
go.opentelemetry.io/otel/trace v1.40.0 -> v1.44.0
go.yaml.in/yaml/v3 v3.0.4 -> v3.0.5
golang.org/x/crypto v0.49.0 -> v0.56.0
golang.org/x/exp v0.0.0-20251023183803-a4bb9ffd2546 -> v0.0.0-20260410095643-746e56fc9e2f
golang.org/x/mod v0.34.0 -> v0.41.0
golang.org/x/net v0.52.0 -> v0.58.0
golang.org/x/sync v0.20.0 -> v0.22.0
golang.org/x/term v0.41.0 -> v0.45.0
golang.org/x/text v0.35.0 -> v0.41.0
golang.org/x/time v0.15.0 -> v0.16.0
golang.org/x/tools v0.43.0 -> v0.49.0
gonum.org/v1/gonum v0.16.0 -> v0.17.0
google.golang.org/api v0.267.0 -> v0.294.0
google.golang.org/genproto v0.0.0-20260128011058-8636f8732409 -> v0.0.0-20260715232425-e75dac1f907d
google.golang.org/genproto/googleapis/api v0.0.0-20260203192932-546029d2fa20 -> v0.0.0-20260715232425-e75dac1f907d
google.golang.org/genproto/googleapis/rpc v0.0.0-20260203192932-546029d2fa20 -> v0.0.0-20260819154853-08b0e4226688
google.golang.org/grpc v1.79.3 -> v1.83.2
google.golang.org/protobuf v1.36.11 -> v1.36.12
gorm.io/gorm v1.31.1 -> v1.31.2
modernc.org/libc v1.70.0 -> v1.75.6
modernc.org/memory v1.11.0 -> v1.12.1
modernc.org/sqlite v1.46.2 -> v1.58.0

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants