Skip to content

build(deps): update all non-major dependencies - #1253

Merged
favonia merged 1 commit into
mainfrom
renovate/all-minor-patch
Jul 27, 2026
Merged

build(deps): update all non-major dependencies#1253
favonia merged 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Age Confidence
actions/checkout action minor v6.0.3v6.1.0 age confidence
alpine (source) final minor 3.23.43.24.1 age confidence
docker/build-push-action action minor v7.2.0v7.3.0 age confidence
docker/login-action action minor v4.2.0v4.5.1 age confidence
docker/metadata-action action minor v6.1.0v6.2.0 age confidence
docker/setup-buildx-action action minor v4.1.0v4.2.0 age confidence
docker/setup-qemu-action action minor v4.1.0v4.2.0 age confidence
github.com/jellydator/ttlcache/v3 require patch v3.4.0v3.4.1 age confidence
github/codeql-action action minor v4.36.2v4.37.3 age confidence
go uses-with patch 1.26.41.26.5 age confidence
golang.org/x/net require minor v0.55.0v0.57.0 age confidence
golang.org/x/text require minor v0.37.0v0.40.0 age confidence
golangci/golangci-lint-action action minor v9.2.1v9.3.0 age confidence
ossf/scorecard-action action patch v2.4.3v2.4.4 age confidence
step-security/harden-runner action minor v2.19.4v2.20.0 age confidence
zizmorcore/zizmor-action action minor v0.5.6v0.6.1 age confidence

Release Notes

actions/checkout (actions/checkout)

v6.1.0

Compare Source

docker/build-push-action (docker/build-push-action)

v7.3.0

Compare Source

docker/login-action (docker/login-action)

v4.5.1

Compare Source

v4.5.0

Compare Source

v4.4.0

Compare Source

v4.3.0

Compare Source

Full Changelog: docker/login-action@v4.2.0...v4.3.0

docker/metadata-action (docker/metadata-action)

v6.2.0

Compare Source

docker/setup-buildx-action (docker/setup-buildx-action)

v4.2.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.1.0...v4.2.0

docker/setup-qemu-action (docker/setup-qemu-action)

v4.2.0

Compare Source

jellydator/ttlcache (github.com/jellydator/ttlcache/v3)

v3.4.1

Compare Source

What's Changed
New Contributors

Full Changelog: jellydator/ttlcache@v3.4.0...v3.4.1

github/codeql-action (github/codeql-action)

v4.37.3

Compare Source

No user facing changes.

v4.37.2

Compare Source

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #​4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #​4007

v4.37.1

Compare Source

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #​3956
  • Update default CodeQL bundle version to 2.26.1. #​4019

v4.37.0

Compare Source

  • Update default CodeQL bundle version to 2.26.0. #​3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@​ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #​3973

v4.36.3

Compare Source

No user facing changes.

actions/go-versions (go)

v1.26.5: 1.26.5

Compare Source

Go 1.26.5

golangci/golangci-lint-action (golangci/golangci-lint-action)

v9.3.0

Compare Source

What's Changed

Changes
Dependencies

Full Changelog: golangci/golangci-lint-action@v9.2.1...v9.3.0

ossf/scorecard-action (ossf/scorecard-action)

v2.4.4

Compare Source

What's Changed

This update bumps the Scorecard version to the v5.5.0 release. For a complete list of changes, please refer to the Scorecard v5.4.0 release notes and the Scorecard v5.5.0 release notes.

Full Changelog: ossf/scorecard-action@v2.4.3...v2.4.4

step-security/harden-runner (step-security/harden-runner)

v2.20.0

Compare Source

What's Changed
  • Support for block policy for MacOS and Windows GitHub-hosted runners
  • Support for Bitrise MacOS GitHub Actions runners
  • HTTPS monitoring support for Bun for Linux runners (enterprise tier)

Full Changelog: step-security/harden-runner@v2.19.4...v2.20.0

zizmorcore/zizmor-action (zizmorcore/zizmor-action)

v0.6.1

Compare Source

zizmor 1.28.0 is now the default version used by the action.

v0.6.0

Compare Source

zizmor 1.27.0 is now the default version used by the action.

What's Changed

New Contributors

Full Changelog: zizmorcore/zizmor-action@v0.5.7...v0.6.0

v0.5.7

Compare Source

1.26.1 is now available via the action
1.26.1 is now the default version of zizmor used by the action


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "on the first day instance on friday after 9pm"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate

renovate Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 4 additional dependencies were updated

Details:

Package Change
golang.org/x/mod v0.35.0 -> v0.37.0
golang.org/x/sync v0.20.0 -> v0.22.0
golang.org/x/sys v0.45.0 -> v0.47.0
golang.org/x/tools v0.44.0 -> v0.47.0

@codecov

codecov Bot commented Jul 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.59%. Comparing base (eb4d3a9) to head (bbaeb0d).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1253   +/-   ##
=======================================
  Coverage   98.59%   98.59%           
=======================================
  Files         102      102           
  Lines        6319     6319           
=======================================
  Hits         6230     6230           
  Misses         76       76           
  Partials       13       13           
Flag Coverage Δ
smoketests 11.84% <ø> (ø)
unittests 98.22% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from 61d4f74 to 5116666 Compare July 27, 2026 09:38
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 5116666 to bbaeb0d Compare July 27, 2026 09:44
@favonia
favonia merged commit ab1e960 into main Jul 27, 2026
36 checks passed
@favonia
favonia deleted the renovate/all-minor-patch branch July 27, 2026 09:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant