-
Notifications
You must be signed in to change notification settings - Fork 285
Open
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency fileinfrainfrastructure bugs/FRsinfrastructure bugs/FRs
Description
This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
View this repository on the Mend.io Web Portal.
Awaiting Schedule
The following updates are awaiting their schedule. To get an update now, click on a checkbox below.
- chore(deps): update gcp/api/googleapis digest to c83d354
- chore(deps): update node.js to 3a09aa6
- fix(deps): update go-libraries (
github.com/go-git/go-git/v6,google.golang.org/genproto/googleapis/api,k8s.io/apimachinery) - fix(deps): update module github.com/gkampitakis/go-snaps to v0.5.20
- fix(deps): update vulnfeeds-go (
github.com/gkampitakis/go-snaps,github.com/go-git/go-git/v5,google.golang.org/api) - fix(deps): update website (
webpack,whitenoise) - chore(deps): update actions/setup-go action to v6.3.0
- fix(deps): update gcp-indexer-go (
github.com/go-git/go-git/v5,google.golang.org/api) - chore(deps): update actions/upload-artifact action to v7
- fix(deps): update module cloud.google.com/go/pubsub to v2
- chore(deps): lock file maintenance
- chore(deps): lock file maintenance
- chore(deps): lock file maintenance
- chore(deps): lock file maintenance
- chore(deps): lock file maintenance
- chore(deps): lock file maintenance
- 🔐 Create all awaiting schedule PRs at once 🔐
Open
The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.
- chore(deps): update terraform to ~> 7.21.0 (
google,google-beta) - fix(deps): update module github.com/charmbracelet/lipgloss to v2
- fix(deps): update vulnfeeds-go major (major) (
github.com/charmbracelet/lipgloss,github.com/google/osv-scanner,gopkg.in/yaml.v2) - chore(deps): lock file maintenance
- Click on this checkbox to rebase all open PRs at once
Detected Dependencies
bundler (1)
docs/Gemfile (6)
github-pages lock file @ 232jekyll-feed "~> 0.12"tzinfo ">= 1", "< 3"wdm "~> 0.2.0"http_parser.rb "~> 0.8.0"webrick "~> 1.7"
cloudbuild (10)
bindings/cloudbuild.yaml
cloudbuild.yaml
docker/terraform/cloudbuild.yaml
gcp/api/cloudbuild.yaml
gcp/website/cloudbuild.yaml
gcp/workers/cloudbuild.yaml
go/cloudbuild.yaml
osv/cloudbuild.yaml
vulnfeeds/cloudbuild.yaml
vulnfeeds/pypi/cloudbuild.yaml
dockerfile (36)
actions/analyze/Dockerfile
docker/ci/Dockerfile
docker/deployment/Dockerfile (1)
ubuntu 24.04@sha256:d1e2e92c075e5ca139d51a140fff46f84315c0fdce203eab2807c7e495eff4f9docker/terraform/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5gcr.io/google.com/cloudsdktool/google-cloud-cli alpine@sha256:d2f3fd4000e4c9c641ab75898da682b771528f60f08f65e0c3a88fcdff2eaf92docker/worker-base/Dockerfile (1)
ubuntu 24.04@sha256:d1e2e92c075e5ca139d51a140fff46f84315c0fdce203eab2807c7e495eff4f9docs/docs.Dockerfile (1)
ruby 3→ [Updates:4]gcp/api/Dockerfile
gcp/api/Dockerfile.esp (1)
gcr.io/endpoints-release/endpoints-runtime 2gcp/indexer/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5gcr.io/distroless/base-debian12 sha256:937c7eaaf6f3f2d38a1f8c4aeff326f0c56e4593ea152e9e8f74d976dde52f56gcp/website/Dockerfile (1)
node 24.14@sha256:dcac36e9d0d3049214862dac30af9f1ee86fccaa8d3bd3a0399b59d6f1bec0eb→ [Updates:24.14]gcp/workers/alias/Dockerfile
gcp/workers/cron/Dockerfile
gcp/workers/exporter/Dockerfile
gcp/workers/importer/Dockerfile
gcp/workers/linter/Dockerfile (1)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5gcp/workers/oss_fuzz_importer/Dockerfile
gcp/workers/oss_fuzz_worker/Dockerfile
gcp/workers/recoverer/Dockerfile
gcp/workers/staging_api_test/Dockerfile
gcp/workers/worker/Dockerfile
go/cmd/custommetrics/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5gcr.io/distroless/static-debian12 sha256:20bc6c0bc4d625a22a8fde3e55f6515709b32055ef8fb9cfbddaa06d1760f838go/cmd/exporter/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5gcr.io/distroless/static-debian12 sha256:20bc6c0bc4d625a22a8fde3e55f6515709b32055ef8fb9cfbddaa06d1760f838go/cmd/generatesitemap/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5gcr.io/distroless/static-debian12 sha256:20bc6c0bc4d625a22a8fde3e55f6515709b32055ef8fb9cfbddaa06d1760f838go/cmd/gitter/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5alpine 3.23@sha256:25109184c71bdad752c8312a8623239686a9a2071e8825f20acb8f2198c3f659go/cmd/importer/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5alpine 3.23@sha256:25109184c71bdad752c8312a8623239686a9a2071e8825f20acb8f2198c3f659go/cmd/recordchecker/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5gcr.io/distroless/static-debian12 sha256:20bc6c0bc4d625a22a8fde3e55f6515709b32055ef8fb9cfbddaa06d1760f838go/cmd/relations/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5gcr.io/distroless/static-debian12 sha256:20bc6c0bc4d625a22a8fde3e55f6515709b32055ef8fb9cfbddaa06d1760f838vulnfeeds/cmd/combine-to-osv/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5gcr.io/google.com/cloudsdktool/google-cloud-cli alpine@sha256:d2f3fd4000e4c9c641ab75898da682b771528f60f08f65e0c3a88fcdff2eaf92vulnfeeds/cmd/converters/alpine/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5gcr.io/google.com/cloudsdktool/google-cloud-cli alpine@sha256:d2f3fd4000e4c9c641ab75898da682b771528f60f08f65e0c3a88fcdff2eaf92vulnfeeds/cmd/converters/cve/cve5/bulk-converter/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5gcr.io/google.com/cloudsdktool/google-cloud-cli alpine@sha256:d2f3fd4000e4c9c641ab75898da682b771528f60f08f65e0c3a88fcdff2eaf92vulnfeeds/cmd/converters/cve/nvd-cve-osv/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5gcr.io/google.com/cloudsdktool/google-cloud-cli alpine@sha256:d2f3fd4000e4c9c641ab75898da682b771528f60f08f65e0c3a88fcdff2eaf92vulnfeeds/cmd/converters/debian/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5gcr.io/google.com/cloudsdktool/google-cloud-cli alpine@sha256:d2f3fd4000e4c9c641ab75898da682b771528f60f08f65e0c3a88fcdff2eaf92vulnfeeds/cmd/mirrors/cpe-repo-gen/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5gcr.io/google.com/cloudsdktool/google-cloud-cli alpine@sha256:d2f3fd4000e4c9c641ab75898da682b771528f60f08f65e0c3a88fcdff2eaf92vulnfeeds/cmd/mirrors/debian-copyright-mirror/Dockerfile (1)
gcr.io/google.com/cloudsdktool/google-cloud-cli alpine@sha256:d2f3fd4000e4c9c641ab75898da682b771528f60f08f65e0c3a88fcdff2eaf92vulnfeeds/cmd/mirrors/download-cves/Dockerfile (2)
golang 1.26.0-alpine@sha256:d4c4845f5d60c6a974c6000ce58ae079328d03ab7f721a0734277e69905473e5gcr.io/google.com/cloudsdktool/google-cloud-cli alpine@sha256:d2f3fd4000e4c9c641ab75898da682b771528f60f08f65e0c3a88fcdff2eaf92vulnfeeds/tools/debian/Dockerfile (1)
gcr.io/google.com/cloudsdktool/google-cloud-cli alpine@sha256:d2f3fd4000e4c9c641ab75898da682b771528f60f08f65e0c3a88fcdff2eaf92
git-submodules (1)
.gitmodules (2)
gcp/api/googleapis c662840a94dbdf708caa44893a2d49119cdd391c→ [Updates:undefined]osv/osv-schema 09a17f85b44a24ec25d29f5b482ea57667b71f48
github-actions (11)
.github/workflows/codeql-analysis.yml (4)
actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83ddgithub/codeql-action v4.32.4@89a39a4e59826350b863aa6b6252a07ad50cf83egithub/codeql-action v4.32.4@89a39a4e59826350b863aa6b6252a07ad50cf83egithub/codeql-action v4.32.4@89a39a4e59826350b863aa6b6252a07ad50cf83e.github/workflows/issue-signposting.yml
.github/workflows/links.yml (2)
actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83ddtcort/github-action-markdown-link-check v1.1.2@e7c7a18363c842693fadde5d41a3bd3573a7a225.github/workflows/lint.yaml (5)
actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83ddactions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83ddactions/setup-python v6.2.0@a309ff8b426b58ec0e2a45f0f869d46889d02405actions/setup-go v6.2.0@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5→ [Updates:v6.3.0]hashicorp/setup-terraform v4.0.0@5e8dbf3c6d9deaf4193ca7a8fb23f2ac83bb6c85.github/workflows/osv-scanner-unified.yml
.github/workflows/pr-check.yml (1)
amannn/action-semantic-pull-request v6.1.1@48f256284bd46cdaab1048c3721360e808335d50.github/workflows/publish-to-pypi.yaml (3)
actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83ddactions/setup-python v6.2.0@a309ff8b426b58ec0e2a45f0f869d46889d02405pypa/gh-action-pypi-publish v1.13.0@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e.github/workflows/renovate-validator.yml (2)
actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83ddactions/setup-node v6.2.0@6044e13b5dc448c55e2357c09f80417699197238.github/workflows/scorecards.yml (4)
actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83ddossf/scorecard-action v2.4.3@4eaacf0543bb3f2c246792bd56e8cdeffafb205aactions/upload-artifact v6.0.0@b7c566a772e6b6bfb58ed0dc250532a479d7789f→ [Updates:v7.0.0]github/codeql-action v4.32.4@89a39a4e59826350b863aa6b6252a07ad50cf83e.github/workflows/snapshots.yml (3)
actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83ddactions/setup-go v6.2.0@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5→ [Updates:v6.3.0]peter-evans/create-pull-request v8.1.0@c0f553fe549906ede9cf27b5156039d195d2ece0.github/workflows/staleness.yml (1)
actions/stale v10.2.0@b5d41d4e1d5dceea10e7104786b73624c18a190f
gomod (8)
bindings/go/go.mod (7)
go 1.26.0gitlite.zycloud.tk/google/go-cmp v0.7.0gitlite.zycloud.tk/ossf/osv-schema/bindings/go v0.0.0-20260129002236-09a17f85b44a@09a17f85b44agolang.org/x/sync v0.19.0google.golang.org/genproto/googleapis/api v0.0.0-20260223185530-2f722ef697dc@2f722ef697dc→ [Updates:v0.0.0-20260226221140-a57be14db171]google.golang.org/grpc v1.79.1google.golang.org/protobuf v1.36.11docs/go.mod (4)
go 1.26.0gitlite.zycloud.tk/grpc-ecosystem/grpc-gateway/v2 v2.28.0google.golang.org/grpc/cmd/protoc-gen-go-grpc v1.6.1google.golang.org/protobuf v1.36.11gcp/indexer/go.mod (10)
go 1.26.0cloud.google.com/go/datastore v1.22.0cloud.google.com/go/pubsub v1.50.1→ [Updates:v2.4.0]cloud.google.com/go/storage v1.60.0gitlite.zycloud.tk/go-git/go-git/v5 v5.16.5→ [Updates:v5.17.0]github.com/golang/glog v1.2.5gitlite.zycloud.tk/google/go-cmp v0.7.0golang.org/x/sync v0.19.0google.golang.org/api v0.268.0→ [Updates:v0.269.0]gopkg.in/yaml.v3 v3.0.1go/go.mod (23)
go 1.26.0cloud.google.com/go/datastore v1.22.0cloud.google.com/go/monitoring v1.24.3cloud.google.com/go/pubsub/v2 v2.4.0cloud.google.com/go/storage v1.60.0gitlite.zycloud.tk/GoogleCloudPlatform/opentelemetry-operations-go/exporter/trace v1.31.0gitlite.zycloud.tk/charmbracelet/lipgloss v1.1.0→ [Updates:v2.0.0]github.com/go-git/go-git/v6 v6.0.0-20260223163356-097ea99c34a7@097ea99c34a7→ [Updates:v6.0.0-20260227233803-efde8c49a5e2]github.com/google/go-cmp v0.7.0gitlite.zycloud.tk/hashicorp/go-retryablehttp v0.7.8gitlite.zycloud.tk/ossf/osv-schema/bindings/go v0.0.0-20260129002236-09a17f85b44a@09a17f85b44agitlite.zycloud.tk/tidwall/gjson v1.18.0gitlite.zycloud.tk/xeipuuv/gojsonschema v1.2.0go.opentelemetry.io/contrib/detectors/gcp v1.40.0go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.65.0go.opentelemetry.io/otel v1.40.0go.opentelemetry.io/otel/sdk v1.40.0go.opentelemetry.io/otel/trace v1.40.0golang.org/x/sync v0.19.0google.golang.org/api v0.269.0google.golang.org/genproto/googleapis/api v0.0.0-20260223185530-2f722ef697dc@2f722ef697dc→ [Updates:v0.0.0-20260226221140-a57be14db171]google.golang.org/protobuf v1.36.11k8s.io/apimachinery v0.35.1→ [Updates:v0.35.2]tools/apitester/go.mod (7)
go 1.26.0gitlite.zycloud.tk/gkampitakis/go-snaps v0.5.19→ [Updates:v0.5.20]github.com/google/go-cmp v0.7.0gitlite.zycloud.tk/tidwall/gjson v1.18.0gitlite.zycloud.tk/tidwall/pretty v1.2.1gitlite.zycloud.tk/tidwall/sjson v1.2.5gopkg.in/dnaeon/go-vcr.v4 v4.0.6tools/datastore-remover/go.mod (3)
go 1.26.0cloud.google.com/go/datastore v1.22.0google.golang.org/api v0.269.0tools/indexer-api-caller/go.mod (1)
go 1.26.0vulnfeeds/go.mod (17)
go 1.26.0cloud.google.com/go/secretmanager v1.16.0cloud.google.com/go/storage v1.60.0gitlite.zycloud.tk/aquasecurity/go-pep440-version v0.0.1gitlite.zycloud.tk/atombender/go-jsonschema v0.22.0gitlite.zycloud.tk/charmbracelet/lipgloss v1.1.0→ [Updates:v2.0.0]github.com/gkampitakis/go-snaps v0.5.19→ [Updates:v0.5.20]github.com/go-git/go-git/v5 v5.16.5→ [Updates:v5.17.0]github.com/google/go-cmp v0.7.0gitlite.zycloud.tk/google/osv-scanner v1.9.2→ [Updates:v2.3.3]github.com/knqyf263/go-cpe v0.0.0-20230627041855-cb0794d06872@cb0794d06872gitlite.zycloud.tk/ossf/osv-schema/bindings/go v0.0.0-20260129002236-09a17f85b44a@09a17f85b44agitlite.zycloud.tk/sethvargo/go-retry v0.3.0google.golang.org/api v0.268.0→ [Updates:v0.269.0]google.golang.org/protobuf v1.36.11gopkg.in/dnaeon/go-vcr.v4 v4.0.6gopkg.in/yaml.v2 v2.4.0→ [Updates:v3.0.1]
npm (1)
gcp/website/frontend3/package.json (19)
@github/clipboard-copy-element 1.3.0@hotwired/turbo 8.0.23@material/data-table 14.0.0@material/layout-grid 14.0.0@material/theme 14.0.0@material/web ^2.0.0lit 3.3.2copy-webpack-plugin ^13.0.0css-loader ^7.1.3html-webpack-plugin ^5.6.6mini-css-extract-plugin ^2.10.0raw-loader ^4.0.2sass ^1.97.3sass-loader ^16.0.0style-loader ^4.0.0webpack ^5.104.1→ [Updates:^5.104.1]webpack-bundle-analyzer ^5.0.0webpack-cli ^6.0.0webpack-dev-server ^5.2.3
poetry (8)
gcp/api/pyproject.toml (7)
google-cloud-ndb ==2.4.0google-cloud-logging ==3.13.0packaging ==26.0requests ==2.32.5mypy-protobuf ^5.0.0yapf *pylint *gcp/functions/pypi/pyproject.toml (4)
cryptography ==46.0.5google-cloud-secret-manager ==2.26.0osv ==0.1.2requests ==2.32.5gcp/website/pyproject.toml (19)
Flask ==3.1.3Flask-Caching ==2.3.1Flask-Compress ==1.23werkzeug ==3.1.6google-auth ==2.48.0google-cloud-ndb ==2.4.0google-cloud-logging ==3.13.0google-cloud-storage ==3.9.0jinja2 ==3.1.6markdown2 ==2.5.4markupsafe ==3.0.3packageurl-python ==0.17.6redis ==6.4.0requests ==2.32.5gunicorn ==25.1.0whitenoise ==6.11.0→ [Updates:==6.12.0]cvss ==3.6yapf *pylint *gcp/workers/oss_fuzz_worker/pyproject.toml (14)
google-auth-httplib2 ==0.3.0google-api-python-client ==2.190.0google-cloud-pubsub ==2.35.0google-cloud-ndb ==2.4.0google-cloud-storage ==3.9.0pyyaml ==6.0.3redis ==6.4.0packageurl-python ==0.17.6pygit2 ==1.19.1requests ==2.32.5jsonschema ==4.26.0vanir ==1.0.2yapf *pylint *gcp/workers/worker/pyproject.toml (14)
google-auth-httplib2 ==0.3.0google-api-python-client ==2.190.0google-cloud-pubsub ==2.35.0google-cloud-ndb ==2.4.0google-cloud-storage ==3.9.0pyyaml ==6.0.3redis ==6.4.0packageurl-python ==0.17.6pygit2 ==1.19.1requests ==2.32.5jsonschema ==4.26.0vanir ==1.0.2yapf *pylint *pyproject.toml (19)
google-cloud-ndb >=2.3google-cloud-logging >=3.10google-cloud-pubsub >=2.31.1google-cloud-storage >=2.17semver >=3.0packageurl-python >=0.17.0pyyaml >=6.0pygit2 >=1.14.0attrs >=23.2jsonschema >=4.0grpcio >=1.0packaging-legacy >=23.0.post0requests >=2.32yapf *pylint *grpcio-tools *mypy-protobuf ^5.0.0vcrpy *hypothesis *tools/datafix/pyproject.toml (6)
google-cloud-ndb ==2.4.0google-cloud-storage ==3.9.0pyyaml ==6.0.3google-cloud-pubsub >=2.25.2yapf *pylint *vulnfeeds/tools/debian/debian_converter/pyproject.toml (5)
markdownify ==1.2.2pandas ==3.0.1python-dateutil ==2.9.0.post0yapf *pylint *
regex (3)
deployment/terraform/environments/oss-vdb-test/main.tf (1)
gcr.io/endpoints-release/endpoints-runtime-serverless 2.55.0deployment/terraform/environments/oss-vdb/main.tf (1)
gcr.io/endpoints-release/endpoints-runtime-serverless 2.55.0gcp/workers/linter/Dockerfile (1)
osv-schema main@09a17f85b44a24ec25d29f5b482ea57667b71f48
terraform (3)
deployment/terraform/environments/oss-vdb-test/main.tf (4)
external ~> 2.3.3google ~> 7.17.0→ [Updates:~> 7.21.0]google-beta ~> 7.17.0→ [Updates:~> 7.21.0]null ~> 3.2.2deployment/terraform/environments/oss-vdb/main.tf (4)
external ~> 2.3.3google ~> 7.17.0→ [Updates:~> 7.21.0]google-beta ~> 7.17.0→ [Updates:~> 7.21.0]null ~> 3.2.2deployment/terraform/modules/osv/website.tf (1)
terraform-google-modules/lb-http/google ~> 14.0
- Check this box to trigger a request for Renovate to run again on this repository
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency fileinfrainfrastructure bugs/FRsinfrastructure bugs/FRs