Skip to content

fix(deps): update non-major-updates#1002

Merged
Wikid82 merged 3 commits intodevelopmentfrom
renovate/non-major-updates
May 7, 2026
Merged

fix(deps): update non-major-updates#1002
Wikid82 merged 3 commits intodevelopmentfrom
renovate/non-major-updates

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented May 6, 2026

This PR contains the following updates:

Package Type Update Change Age Confidence
benchmark-action/github-action-benchmark action patch v1.22.0v1.22.1 age confidence
docker/build-push-action action minor v6.18.0v6.19.2 age confidence
golangci/golangci-lint minor 2.11.42.12.1 age confidence
golangci/golangci-lint uses-with minor v2.11.4v2.12.1 age confidence
i18next (source) dependencies patch ^26.0.8^26.0.9 age confidence

Release Notes

benchmark-action/github-action-benchmark (benchmark-action/github-action-benchmark)

v1.22.1

Compare Source

  • fix scope tsconfig.build.json to src/ for reproducibility (#​352)
  • chore bump minimatch from 3.1.2 to 3.1.5 (#​347)
  • chore bump uuid and @​actions/core (#​350)
  • chore bump flatted from 3.2.4 to 3.4.2 (#​346)
  • chore bump js-yaml (#​344)
  • chore bump picomatch from 2.3.0 to 2.3.2 (#​342)
docker/build-push-action (docker/build-push-action)

v6.19.2

Compare Source

Full Changelog: docker/build-push-action@v6.19.1...v6.19.2

v6.19.1

Compare Source

Full Changelog: docker/build-push-action@v6.19.0...v6.19.1

v6.19.0

Compare Source

  • Scope default git auth token to github.com by @​crazy-max in #​1451
  • Bump brace-expansion from 1.1.11 to 1.1.12 in #​1396
  • Bump form-data from 2.5.1 to 2.5.5 in #​1391
  • Bump js-yaml from 3.14.1 to 3.14.2 in #​1429
  • Bump lodash from 4.17.21 to 4.17.23 in #​1446
  • Bump tmp from 0.2.3 to 0.2.4 in #​1398
  • Bump undici from 5.28.4 to 5.29.0 in #​1397

Full Changelog: docker/build-push-action@v6.18.0...v6.19.0

golangci/golangci-lint (golangci/golangci-lint)

v2.12.1

Compare Source

Released on 2026-05-01

  1. Linters bug fixes
    • gomodguard_v2: fix panic with migration suggestion
  2. Misc.
    • fix install.sh script (if you are still using an URL based on the branch master, please update to use https://golangci-lint.run/install.sh)

v2.12.0

Compare Source

Released on 2026-05-01

  1. New linters
  2. Linters new features or changes
    • dupl: from f665c8d to c99c5cf (extended detection)
    • funcorder: from 0.5.0 to 0.6.0 (new option: function)
    • goconst: add an option to ignore strings from tests
    • goconst: from 1.8.2 to 1.10.0 (extended detection)
    • gomodguard_v2: from 1.4.1 to 2.1.0 (major version with new configuration)
    • gosec: from 619ce21 to 2.26.1 (new checks: G124, G708, G709, G710)
    • govet: add inline analyzer
    • makezero: from 2.1.0 to 2.2.1 (support slice type aliases)
    • paralleltest: expose checkcleanup option
    • sloglint: from 0.11.1 to 0.12.0 (new options: allowed-keys, custom-funcs)
    • wsl_v5: from 5.6.0 to 5.8.0 (new option: cuddle-max-statements; new checks: after-decl, after-defer, after-expr, after-go, cuddle-group)
  3. Linters bug fixes
    • forbidigo: from 2.3.0 to 2.3.1
    • godot: from 1.5.4 to 1.5.6
    • govet-modernize: from 0.43.0 to 0.44.0
    • ireturn: from 0.4.0 to 0.4.1
    • rowserrcheck: from 1.1.1 to c5f79b8
  4. Misc.
    • Decrease cache entropy
    • Embed the JSON schema in the binary
    • Filter env vars when cloning the repository with the custom command
i18next/i18next (i18next)

v26.0.9

Compare Source

  • fix(types): unformatted interpolation values are now typed as string | number (was string). i18next stringifies values at runtime, so requiring callers to wrap numbers in String(...) for plain {{var}} placeholders was unnecessary friction — and could mask the real problem when a non-string value was passed alongside multiple interpolation slots (the t() overload resolution would fall through to the 3-arg form and report a confusing "not assignable to string" error against the options object). Typed format specifiers like {{x, number}}, {{x, currency}}, {{x, datetime}}, etc. keep their precise types; this only relaxes the no-format default. The count variable remains number-only

Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label May 6, 2026
@github-advanced-security
Copy link
Copy Markdown
Contributor

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 6, 2026

✅ Supply Chain Verification Results

PASSED

📦 SBOM Summary

  • Components: 1487

🔍 Vulnerability Scan

Severity Count
🔴 Critical 0
🟠 High 0
🟡 Medium 4
🟢 Low 2
Total 6

📎 Artifacts

  • SBOM (CycloneDX JSON) and Grype results available in workflow artifacts

Generated by Supply Chain Verification workflow • View Details

@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented May 6, 2026

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@codecov
Copy link
Copy Markdown

codecov Bot commented May 6, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

…mmary

The previous grep pattern never matched package-level failures from
gotestsum --format pkgname, which emits FAIL<tab><package> with no colon.
Panics and data race reports were also silently swallowed, causing the
CI failure summary to always print "No specific failures captured in output"
even when the test binary crashed.

Replace with a pattern covering individual assertion failures, package-level
failures, race detector reports, and test binary panics.

---

fix(test): guard goroutine lifecycle in server tests to prevent silent crashes

Three test hygiene gaps in the Orthrus test suite caused the package binary
to exit non-zero without emitting any --- FAIL: line, making CI failures
invisible until the grep fix above:

- A read-only keys directory test created a 0o555 subdirectory without
  restoring permissions before cleanup, triggering a TempDir removal panic.
  Added a t.Cleanup to mirror the pattern already used in the adjacent test.

- The WatchHeartbeat closed-session test started yamux goroutines without
  registering srv.Stop(), allowing goroutines to race against TempDir and
  DB cleanups after the test function returned.

- The handler test setup helper never cancelled the OrthrusServer context.
  Added t.Cleanup(srv.Stop) so every test using this helper benefits,
  consistent with the pattern established in the server test suite.
@Wikid82 Wikid82 merged commit d452b35 into development May 7, 2026
40 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants