Skip to content

fix(deps): update all dependencies - #49

Merged
paralin merged 1 commit into
masterfrom
renovate/all
Jul 5, 2026
Merged

paralin merged 1 commit into
masterfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Jun 30, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence Type Update
github.com/aperturerobotics/protobuf-go-lite v0.14.0 → v0.15.0 age adoption passing confidence require minor
github.com/goreleaser/goreleaser/v2 v2.16.0 → v2.17.0 age adoption passing confidence require minor
github/codeql-action v4.36.2 → v4.36.3 age adoption passing confidence action patch

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

aperturerobotics/protobuf-go-lite (github.com/aperturerobotics/protobuf-go-lite)

v0.15.0

Compare Source

goreleaser/goreleaser (github.com/goreleaser/goreleaser/v2)

v2.17.0

Compare Source

github/codeql-action (github/codeql-action)

v4.36.3

Compare Source

No user facing changes.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate

renovate Bot commented Jun 30, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated

Details:

Package Change
github.com/aperturerobotics/json-iterator-lite v1.0.1-0.20251104042408-0c9eb8a3f726 -> v1.1.0
File name: tools/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 97 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.26.3 -> 1.26.4
charm.land/lipgloss/v2 v2.0.3 -> v2.0.5
cloud.google.com/go/auth v0.18.2 -> v0.20.0
cloud.google.com/go/iam v1.7.0 -> v1.11.0
cloud.google.com/go/longrunning v0.9.0 -> v1.0.0
cloud.google.com/go/monitoring v1.24.3 -> v1.25.0
cloud.google.com/go/storage v1.59.2 -> v1.62.2
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0 -> v1.21.1
github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2 -> v1.12.0
github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azkeys v1.4.0 -> v1.5.0
github.com/Azure/azure-sdk-for-go/sdk/storage/azblob v1.6.3 -> v1.6.4
github.com/AzureAD/microsoft-authentication-library-for-go v1.6.0 -> v1.7.2
github.com/aws/aws-sdk-go-v2 v1.41.7 -> v1.42.1
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.10 -> v1.7.14
github.com/aws/aws-sdk-go-v2/config v1.32.12 -> v1.32.20
github.com/aws/aws-sdk-go-v2/credentials v1.19.12 -> v1.19.19
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.20 -> v1.18.25
github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.23 -> v1.4.30
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.23 -> v2.7.30
github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.24 -> v1.4.31
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.9 -> v1.13.13
github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.15 -> v1.9.23
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.23 -> v1.13.30
github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.23 -> v1.19.31
github.com/aws/aws-sdk-go-v2/service/kms v1.50.3 -> v1.52.0
github.com/aws/aws-sdk-go-v2/service/s3 v1.101.0 -> v1.104.2
github.com/aws/aws-sdk-go-v2/service/signin v1.0.8 -> v1.1.1
github.com/aws/aws-sdk-go-v2/service/sso v1.30.13 -> v1.30.19
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.17 -> v1.36.2
github.com/aws/aws-sdk-go-v2/service/sts v1.41.9 -> v1.42.3
github.com/aws/smithy-go v1.25.1 -> v1.27.3
github.com/caarlos0/log v0.6.0 -> v0.6.2
github.com/cncf/xds/go v0.0.0-20251210132809-ee656c7534f5 -> v0.0.0-20260202195803-dba9d589def2
github.com/docker/cli v29.4.3+incompatible -> v29.5.3+incompatible
github.com/envoyproxy/go-control-plane/envoy v1.36.0 -> v1.37.0
github.com/envoyproxy/protoc-gen-validate v1.3.0 -> v1.3.3
github.com/fsnotify/fsnotify v1.9.0 -> v1.10.1
github.com/go-openapi/analysis v0.24.3 -> v0.25.2
github.com/go-openapi/jsonpointer v0.22.5 -> v0.23.1
github.com/go-openapi/jsonreference v0.21.5 -> v0.21.6
github.com/go-openapi/runtime v0.29.3 -> v0.32.3
github.com/go-openapi/spec v0.22.4 -> v0.22.5
github.com/go-openapi/strfmt v0.26.1 -> v0.26.3
github.com/go-openapi/swag v0.25.5 -> v0.26.0
github.com/go-openapi/swag/cmdutils v0.25.5 -> v0.26.0
github.com/go-openapi/swag/conv v0.25.5 -> v0.26.1
github.com/go-openapi/swag/fileutils v0.25.5 -> v0.26.0
github.com/go-openapi/swag/jsonname v0.25.5 -> v0.26.0
github.com/go-openapi/swag/jsonutils v0.25.5 -> v0.26.0
github.com/go-openapi/swag/loading v0.25.5 -> v0.26.0
github.com/go-openapi/swag/mangling v0.25.5 -> v0.26.0
github.com/go-openapi/swag/netutils v0.25.5 -> v0.26.0
github.com/go-openapi/swag/stringutils v0.25.5 -> v0.26.0
github.com/go-openapi/swag/typeutils v0.25.5 -> v0.26.1
github.com/go-openapi/swag/yamlutils v0.25.5 -> v0.26.0
github.com/go-openapi/validate v0.25.2 -> v0.25.3
github.com/google/go-containerregistry v0.21.6 -> v0.21.7
github.com/google/ko v0.18.2-0.20260407063826-ae9c7272d7de -> v0.19.1
github.com/google/pprof v0.0.0-20260115054156-294ebfa9ad83 -> v0.0.0-20260402051712-545e8a4df936
github.com/googleapis/enterprise-certificate-proxy v0.3.14 -> v0.3.16
github.com/googleapis/gax-go/v2 v2.21.0 -> v2.22.0
github.com/goreleaser/nfpm/v2 v2.46.3 -> v2.47.0
github.com/goreleaser/quill v0.0.0-20260503024558-dbc159c51d43 -> v0.0.0-20260630015114-8310f3e9a321
github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 -> v2.29.0
github.com/in-toto/attestation v1.1.2 -> v1.2.0
github.com/klauspost/compress v1.18.6 -> v1.19.0
github.com/moby/moby/api v1.54.2 -> v1.55.0
github.com/moby/moby/client v0.4.1 -> v0.5.0
github.com/secure-systems-lab/go-securesystemslib v0.10.0 -> v0.11.0
github.com/sigstore/cosign/v3 v3.0.6 -> v3.1.1
github.com/sigstore/protobuf-specs v0.5.0 -> v0.5.1
github.com/sigstore/rekor v1.5.1 -> v1.5.2
github.com/sigstore/rekor-tiles/v2 v2.2.1 -> v2.2.2-0.20260601073857-5d098a2b6443
github.com/sigstore/sigstore v1.10.5 -> v1.10.8
github.com/sigstore/sigstore-go v1.1.4 -> v1.2.0
github.com/sigstore/timestamp-authority/v2 v2.0.6 -> v2.1.2
github.com/slack-go/slack v0.23.1 -> v0.27.0
github.com/spiffe/go-spiffe/v2 v2.6.0 -> v2.7.0
github.com/theupdateframework/go-tuf/v2 v2.4.1 -> v2.4.2
github.com/transparency-dev/formats v0.1.0 -> v0.1.1
go.opentelemetry.io/contrib/detectors/gcp v1.40.0 -> v1.42.0
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.64.0 -> v0.68.0
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.67.0 -> v0.68.0
go.opentelemetry.io/otel v1.43.0 -> v1.44.0
go.opentelemetry.io/otel/metric v1.43.0 -> v1.44.0
go.opentelemetry.io/otel/sdk v1.43.0 -> v1.44.0
go.opentelemetry.io/otel/sdk/metric v1.43.0 -> v1.44.0
go.opentelemetry.io/otel/trace v1.43.0 -> v1.44.0
go.uber.org/zap v1.27.1 -> v1.28.0
go.yaml.in/yaml/v4 v4.0.0-rc.4 -> v4.0.0-rc.6
gocloud.dev v0.45.0 -> v0.46.0
google.golang.org/api v0.274.0 -> v0.283.0
google.golang.org/genproto v0.0.0-20260319201613-d00831a3d3e7 -> v0.0.0-20260406210006-6f92a3bedf2d
google.golang.org/genproto/googleapis/api v0.0.0-20260401024825-9d38bb4040a9 -> v0.0.0-20260526163538-3dc84a4a5aaa
google.golang.org/genproto/googleapis/rpc v0.0.0-20260401024825-9d38bb4040a9 -> v0.0.0-20260523011958-0a33c5d7ca68
google.golang.org/protobuf v1.36.11 -> v1.36.12-0.20260120151049-f2248ac996af
sigs.k8s.io/kind v0.31.0 -> v0.32.0
software.sslmate.com/src/go-pkcs12 v0.7.1 -> v0.7.3

@socket-security

socket-security Bot commented Jun 30, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgolang/​github.com/​goreleaser/​goreleaser/​v2@​v2.16.0 ⏵ v2.17.074 +1100100100100
Updatedgolang/​google.golang.org/​grpc@​v1.80.0 ⏵ v1.81.175 +1100100100100
Updatedgolang/​github.com/​aperturerobotics/​protobuf-go-lite@​v0.14.0 ⏵ v0.15.0100100100100100

View full report

@renovate
renovate Bot force-pushed the renovate/all branch from b4a2659 to 2e119a9 Compare July 2, 2026 10:42
@renovate renovate Bot changed the title fix(deps): update module github.com/aperturerobotics/protobuf-go-lite to v0.15.0 fix(deps): update all dependencies Jul 2, 2026
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate
renovate Bot force-pushed the renovate/all branch from 2e119a9 to 22bd77d Compare July 5, 2026 00:43
@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: golang github.com/envoyproxy/go-control-plane/envoy is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → golang/google.golang.org/grpc@v1.81.1 → golang/github.com/envoyproxy/go-control-plane/envoy@v1.37.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/github.com/envoyproxy/go-control-plane/envoy@v1.37.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: golang github.com/envoyproxy/go-control-plane/envoy is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → golang/google.golang.org/grpc@v1.81.1 → golang/github.com/envoyproxy/go-control-plane/envoy@v1.37.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/github.com/envoyproxy/go-control-plane/envoy@v1.37.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: golang github.com/envoyproxy/go-control-plane/envoy is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → golang/google.golang.org/grpc@v1.81.1 → golang/github.com/envoyproxy/go-control-plane/envoy@v1.37.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/github.com/envoyproxy/go-control-plane/envoy@v1.37.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: golang github.com/envoyproxy/go-control-plane/envoy is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → golang/google.golang.org/grpc@v1.81.1 → golang/github.com/envoyproxy/go-control-plane/envoy@v1.37.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/github.com/envoyproxy/go-control-plane/envoy@v1.37.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: golang github.com/envoyproxy/go-control-plane/envoy is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → golang/google.golang.org/grpc@v1.81.1 → golang/github.com/envoyproxy/go-control-plane/envoy@v1.37.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/github.com/envoyproxy/go-control-plane/envoy@v1.37.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: golang github.com/envoyproxy/go-control-plane/envoy is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → golang/google.golang.org/grpc@v1.81.1 → golang/github.com/envoyproxy/go-control-plane/envoy@v1.37.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/github.com/envoyproxy/go-control-plane/envoy@v1.37.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: golang github.com/go-openapi/runtime is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → golang/github.com/goreleaser/goreleaser/v2@v2.17.0 → golang/github.com/go-openapi/runtime@v0.32.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/github.com/go-openapi/runtime@v0.32.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: golang github.com/goreleaser/quill is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → golang/github.com/goreleaser/goreleaser/v2@v2.17.0 → golang/github.com/goreleaser/quill@v0.0.0-20260630015114-8310f3e9a321

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/github.com/goreleaser/quill@v0.0.0-20260630015114-8310f3e9a321. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@paralin
paralin merged commit 656082f into master Jul 5, 2026
7 of 8 checks passed
@paralin
paralin deleted the renovate/all branch July 5, 2026 02:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant