Skip to content

build(deps): bump chainguard.dev/apko from 1.2.33 to 1.2.36 - #468

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/chainguard.dev/apko-1.2.36
Closed

build(deps): bump chainguard.dev/apko from 1.2.33 to 1.2.36#468
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/chainguard.dev/apko-1.2.36

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 12, 2026

Copy link
Copy Markdown
Contributor

Bumps chainguard.dev/apko from 1.2.33 to 1.2.36.

Release notes

Sourced from chainguard.dev/apko's releases.

Release v1.2.36

Changelog

  • a811f4c76e9ff2ecd54e73e497e5a3940f396af8 Group codeql-action bumps in dependabot config (#2382)
  • f413050331260961fceb34c1f4033b5c304fe7cc apk: refuse to record a package with an empty name (#2390)
  • 463030d849b086c32faf5c815ea3c205f6577979 apk: terminate the orphan walk at the filesystem root (#2389)
  • 503ebdd55785c4ef3e2ce1b30c05b2b42357ac06 build(deps): bump chainguard-dev/actions/setup-registry from 1.6.29 to 1.6.30 (#2380)
  • b23ffba8fb1743c4405710dd87592999f01c7561 build(deps): bump chainguard.dev/sdk from 0.1.164 to 0.1.170 (#2385)
  • d4db67575cb71f33445a7bf35211f759a9a3d4e9 build(deps): bump github/codeql-action from 4.37.4 to 4.37.5 (#2381)
  • 8982953431551d20478bb8240205322ecab3d8bc build(deps): bump go.opentelemetry.io/otel from 1.44.0 to 1.45.0 (#2384)
  • cae7a8efbcb93e10910fbda35a114c1e01bed426 build(deps): bump step-security/harden-runner from 2.20.0 to 2.20.1 (#2387)
  • ee954e3e308c504a3fe7c8e7d5ced9ca6b7d66fa build(deps): bump the codeql group across 1 directory with 2 updates (#2386)

Release v1.2.35

Changelog

  • 550f63fb7bf13a7c13fcfdc1dcd9c9d3d0263e9f Disable Go module caching in goreleaser workflows (#2375)
  • 766682c7e7f87cc932ff02abeb889f5eab5edc9f fix(apk): honour offline mode in InitDB key discovery without a cache (#2377)

Release v1.2.34

Changelog

  • ac39f22c43742c607180a0548f8cb88db73d86fd apk: handle Alpine key fetches without a cache (#2374)
  • 3232315d776d35f54f1d817606c4bfa791afefed build: add a disk cache opt-out (#2373)
Commits
  • f413050 apk: refuse to record a package with an empty name (#2390)
  • 463030d apk: terminate the orphan walk at the filesystem root (#2389)
  • b23ffba build(deps): bump chainguard.dev/sdk from 0.1.164 to 0.1.170 (#2385)
  • 8982953 build(deps): bump go.opentelemetry.io/otel from 1.44.0 to 1.45.0 (#2384)
  • ee954e3 build(deps): bump the codeql group across 1 directory with 2 updates (#2386)
  • cae7a8e build(deps): bump step-security/harden-runner from 2.20.0 to 2.20.1 (#2387)
  • a811f4c Group codeql-action bumps in dependabot config (#2382)
  • d4db675 build(deps): bump github/codeql-action from 4.37.4 to 4.37.5 (#2381)
  • 503ebdd build(deps): bump chainguard-dev/actions/setup-registry from 1.6.29 to 1.6.30...
  • 766682c fix(apk): honour offline mode in InitDB key discovery without a cache (#2377)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [chainguard.dev/apko](https://github.com/chainguard-dev/apko) from 1.2.33 to 1.2.36.
- [Release notes](https://github.com/chainguard-dev/apko/releases)
- [Changelog](https://github.com/chainguard-dev/apko/blob/main/NEWS.md)
- [Commits](chainguard-dev/apko@v1.2.33...v1.2.36)

---
updated-dependencies:
- dependency-name: chainguard.dev/apko
  dependency-version: 1.2.36
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 12, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 31, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #473.

@dependabot dependabot Bot closed this Aug 31, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/chainguard.dev/apko-1.2.36 branch August 31, 2026 13:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants