Skip to content

fix(deps): update all non-major dependencies#99

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-minor-patch-digest-pin
Open

fix(deps): update all non-major dependencies#99
renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-minor-patch-digest-pin

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Aug 18, 2025

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Age Confidence
actions/setup-go action minor v6.3.0v6.4.0 age confidence
alpine final patch 3.23.33.23.4 age confidence
alpine stage patch 3.23.33.23.4 age confidence
codecov/codecov-action action patch v5.5.2v5.5.4 age confidence
elgohr/Publish-Docker-Github-Action (changelog) action digest 4feac4d1c2f28c
github.com/go-vela/server require minor v0.27.5v0.28.3 age confidence
github.com/urfave/cli/v3 require minor v3.7.0v3.8.0 age confidence
github/codeql-action action minor v4.32.5v4.35.2 age confidence
gohugoio/hugo minor 0.157.00.160.1 age confidence
reviewdog/action-golangci-lint action minor v2.8.0v2.10 age confidence

Release Notes

actions/setup-go (actions/setup-go)

v6.4.0

Compare Source

What's Changed
Enhancement
  • Add go-download-base-url input for custom Go distributions by @​gdams in #​721
Dependency update
Documentation update
New Contributors

Full Changelog: actions/setup-go@v6...v6.4.0

codecov/codecov-action (codecov/codecov-action)

v5.5.4

Compare Source

This is a mirror of v5.5.2. v6 will be released which requires node24

What's Changed

Full Changelog: codecov/codecov-action@v5.5.3...v5.5.4

v5.5.3

Compare Source

What's Changed

Full Changelog: codecov/codecov-action@v5.5.2...v5.5.3

go-vela/server (github.com/go-vela/server)

v0.28.3

Compare Source

What's Changed

Full Changelog: go-vela/server@v0.28.2...v0.28.3

v0.28.2

Compare Source

What's Changed

Full Changelog: go-vela/server@v0.28.1...v0.28.2

v0.28.1

Compare Source

What's Changed

Full Changelog: go-vela/server@v0.28.0...v0.28.1

v0.28.0

Compare Source

What's Changed

Full Changelog: go-vela/server@v0.27.5...v0.28.0

urfave/cli (github.com/urfave/cli/v3)

v3.8.0

Compare Source

What's Changed

New Contributors

Full Changelog: urfave/cli@v3.7.0...v3.8.0

github/codeql-action (github/codeql-action)

v4.35.2

Compare Source

  • The undocumented TRAP cache cleanup feature that could be enabled using the CODEQL_ACTION_CLEANUP_TRAP_CACHES environment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing the trap-caching: false input to the init Action. #​3795
  • The Git version 2.36.0 requirement for improved incremental analysis now only applies to repositories that contain submodules. #​3789
  • Python analysis on GHES no longer extracts the standard library, relying instead on models of the standard library. This should result in significantly faster extraction and analysis times, while the effect on alerts should be minimal. #​3794
  • Fixed a bug in the validation of OIDC configurations for private registries that was added in CodeQL Action 4.33.0 / 3.33.0. #​3807
  • Update default CodeQL bundle version to 2.25.2. #​3823

v4.35.1

Compare Source

v4.35.0

Compare Source

v4.34.1

Compare Source

  • Downgrade default CodeQL bundle version to 2.24.3 due to issues with a small percentage of Actions and JavaScript analyses. #​3762

v4.34.0

Compare Source

  • Added an experimental change which disables TRAP caching when improved incremental analysis is enabled, since improved incremental analysis supersedes TRAP caching. This will improve performance and reduce Actions cache usage. We expect to roll this change out to everyone in March. #​3569
  • We are rolling out improved incremental analysis to C/C++ analyses that use build mode none. We expect this rollout to be complete by the end of April 2026. #​3584
  • Update default CodeQL bundle version to 2.25.0. #​3585

v4.33.0

Compare Source

  • Upcoming change: Starting April 2026, the CodeQL Action will skip collecting file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. Pull request analyses will log a warning about this upcoming change. #​3562

    To opt out of this change:

    • Repositories owned by an organization: Create a custom repository property with the name github-codeql-file-coverage-on-prs and the type "True/false", then set this property to true in the repository's settings. For more information, see Managing custom properties for repositories in your organization. Alternatively, if you are using an advanced setup workflow, you can set the CODEQL_ACTION_FILE_COVERAGE_ON_PRS environment variable to true in your workflow.
    • User-owned repositories using default setup: Switch to an advanced setup workflow and set the CODEQL_ACTION_FILE_COVERAGE_ON_PRS environment variable to true in your workflow.
    • User-owned repositories using advanced setup: Set the CODEQL_ACTION_FILE_COVERAGE_ON_PRS environment variable to true in your workflow.
  • Fixed a bug which caused the CodeQL Action to fail loading repository properties if a "Multi select" repository property was configured for the repository. #​3557

  • The CodeQL Action now loads custom repository properties on GitHub Enterprise Server, enabling the customization of features such as github-codeql-disable-overlay that was previously only available on GitHub.com. #​3559

  • Once private package registries can be configured with OIDC-based authentication for organizations, the CodeQL Action will now be able to accept such configurations. #​3563

  • Fixed the retry mechanism for database uploads. Previously this would fail with the error "Response body object should not be disturbed or locked". #​3564

  • A warning is now emitted if the CodeQL Action detects a repository property whose name suggests that it relates to the CodeQL Action, but which is not one of the properties recognised by the current version of the CodeQL Action. #​3570

v4.32.6

Compare Source

gohugoio/hugo (gohugoio/hugo)

v0.160.1

Compare Source

What's Changed

v0.160.0

Compare Source

Now you can inject CSS vars, e.g. from the configuration, into your stylesheets when building with css.Build. Also, now all the render hooks has a .Position method, now also more accurate and effective.

Bug fixes

Improvements

Dependency Updates

Documentation

v0.159.2

Compare Source

Note that the security fix below is not a potential threat if you either:

EDIT IN: This release also adds release archives for non-extended-withdeploy builds.

What's Changed

v0.159.1

Compare Source

The regression fixed in this release isn't new, but it's so subtle that we thought we'd release this sooner rather than later. For some time now, the minifier we use have stripped namespaced attributes in SVGs, which broke dynamic constructs using e.g. AlpineJS' x-bind: namespace (library used by Hugo's documentation site).

To fix this, the upstream library has hadded a keepNamespaces slice option. It was not possible to find a default that would make all happy, so we opted for an option that at least would make AlpineJS sites work out of the box:

 [minify.tdewolff.svg]
      keepNamespaces = ['', 'x-bind']

What's Changed

v0.159.0

Compare Source

This release greatly improves and simplifies management of Node.js/npm dependencies in a multi-module setup. See this page for more information.

Note

  • Replace deprecated site.Data with hugo.Data in tests a8fca59 @​bep
  • Replace deprecated excludeFiles and includeFiles with files in tests 182b104 @​bep
  • Replace deprecated :filename with :contentbasename in the permalinks test eb11c3d @​bep

Bug fixes

Improvements

Dependency Updates

Documentation

v0.158.0

Compare Source

This release adds css.Build, native and very fast bundling/transformation/minifying of CSS resources. Also see the new strings.ReplacePairs, a very fast option if you need to do many string replacements.

Notes

Deprecations

The methods and config options are deprecated and will be removed in a future Hugo release.

Also see this article

Language configuration
  • languageCode → Use locale instead.
  • languages.<lang>.languageCode → Use languages.<lang>.locale instead.
  • languages.<lang>.languageName → Use languages.<lang>.label instead.
  • languages.<lang>.languageDirection → Use languages.<lang>.direction instead.
Language methods
  • .Site.LanguageCode → Use .Site.Language.Locale instead.
  • .Language.LanguageCode → Use .Language.Locale instead.
  • .Language.LanguageName → Use .Language.Label instead.
  • .Language.LanguageDirection → Use .Language.Direction instead.

Bug fixes

Improvements

Dependency Updates

reviewdog/action-golangci-lint (reviewdog/action-golangci-lint)

v2.10

Compare Source

v2.10.0

Compare Source

What's Changed

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot requested a review from a team as a code owner August 18, 2025 15:48
@renovate renovate Bot added the dependencies Indicates a change to dependencies label Aug 18, 2025
@codecov
Copy link
Copy Markdown

codecov Bot commented Aug 18, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 21.52%. Comparing base (f20bb6b) to head (cd22ee7).

❌ Your project check has failed because the head coverage (21.52%) is below the target coverage (90.00%). You can increase the head coverage or adjust the target coverage.

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##             main      #99   +/-   ##
=======================================
  Coverage   21.52%   21.52%           
=======================================
  Files           7        7           
  Lines         432      432           
=======================================
  Hits           93       93           
  Misses        337      337           
  Partials        2        2           
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@renovate renovate Bot changed the title chore(deps): update github/codeql-action action to v3.29.10 chore(deps): update all non-major dependencies Aug 20, 2025
@renovate renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 3 times, most recently from 8efe7cb to 6f79143 Compare August 27, 2025 17:37
@renovate renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch from 6f79143 to 351184a Compare August 31, 2025 09:21
@renovate renovate Bot changed the title chore(deps): update all non-major dependencies fix(deps): update all non-major dependencies Aug 31, 2025
@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented Aug 31, 2025

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 2 additional dependencies were updated

Details:

Package Change
golang.org/x/sys v0.34.0 -> v0.35.0
golang.org/x/text v0.27.0 -> v0.28.0

@renovate renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 4 times, most recently from ddb72be to b0512fd Compare September 10, 2025 18:39
@renovate renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 4 times, most recently from 6f2b7f1 to 5101ce6 Compare September 26, 2025 21:23
@renovate renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 3 times, most recently from a9a2a9b to bce8d65 Compare October 9, 2025 01:07
@renovate renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 4 times, most recently from e3a04e2 to 314229d Compare October 17, 2025 17:52
@renovate renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 3 times, most recently from b5d6d61 to 89bfc7a Compare October 24, 2025 19:55
@renovate renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 2 times, most recently from b8ec20e to a47494e Compare October 30, 2025 20:42
@renovate renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 7 times, most recently from b9089b0 to ad7c6d5 Compare December 20, 2025 18:35
@renovate renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 3 times, most recently from 4880ca3 to c2d0d9d Compare December 29, 2025 01:10
@renovate renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 4 times, most recently from cd302a0 to 18fb3f3 Compare January 2, 2026 17:27
@renovate renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 4 times, most recently from 2d07ed4 to c0a15aa Compare January 12, 2026 18:00
@renovate renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 2 times, most recently from 5901086 to 1f6bfb2 Compare January 18, 2026 04:45
@renovate renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 6 times, most recently from 22ab7a4 to 2679ab0 Compare January 30, 2026 13:28
@renovate renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 2 times, most recently from 94bc4c8 to c78c312 Compare February 2, 2026 21:13
@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented Mar 31, 2026

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 3 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.25.7 -> 1.26.1
github.com/klauspost/compress v1.17.11 -> v1.18.2
golang.org/x/sys v0.39.0 -> v0.43.0
golang.org/x/text v0.32.0 -> v0.36.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Indicates a change to dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants