Skip to content

chore(deps): Bump github.com/quay/claircore from 1.5.35 to 1.5.53 - #6342

Open
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/go_modules/github.com/quay/claircore-1.5.53
Open

chore(deps): Bump github.com/quay/claircore from 1.5.35 to 1.5.53#6342
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/go_modules/github.com/quay/claircore-1.5.53

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 23, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/quay/claircore from 1.5.35 to 1.5.53.

Release notes

Sourced from github.com/quay/claircore's releases.

v1.5.53 Release

v1.5.53 - 2026-07-17

  • claircore: support "not affected" vulnerability assertions

    The Red Hat VEX updater now ingests known_not_affected product status as inverted vulnerabilities.

  • acceptance: add the acceptance testing framework

  • postgres: add existence check to type in all cases

v1.5.52 Release

v1.5.52 - 2026-03-26

Nothing interesting happened this release.

v1.5.51 Release

v1.5.51 - 2026-03-24

  • indexer: align affectedManifests call with matcher definitions

... (truncated)

Changelog

Sourced from github.com/quay/claircore's changelog.

v1.5.53 - 2026-07-17

  • claircore: support "not affected" vulnerability assertions

    The Red Hat VEX updater now ingests known_not_affected product status as inverted vulnerabilities.

  • acceptance: add the acceptance testing framework

  • postgres: add existence check to type in all cases

v1.5.52 - 2026-03-26

Nothing interesting happened this release.

v1.5.51 - 2026-03-24

  • indexer: align affectedManifests call with matcher definitions

[v1.5.50] - 2026-03-02

... (truncated)

Commits
  • b14401b chore: v1.5.53 changelog bump
  • 910c3c5 chore(deps): bump github.com/klauspost/compress from 1.18.6 to 1.19.0
  • 40ee906 datastore/postgres: fix iterator exhaustion in alias insertion
  • 074c316 postgres: bulk-link vulnerability aliases in two statements
  • f70c12d postgres: alias insertion deadlock
  • 11818e7 chore(deps): bump golang.org/x/tools
  • 056d5d6 vex: warn and skip unparseable entries in knownAffectedVulnerabilities
  • c46bb83 chore(deps): bump modernc.org/sqlite from 1.52.0 to 1.53.0
  • a217808 aliases: widen the vulnerability FK columns in the alias tables from INTEGER ...
  • b8b6201 chore(deps): bump actions/checkout from 6 to 7
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [github.com/quay/claircore](https://github.com/quay/claircore) from 1.5.35 to 1.5.53.
- [Release notes](https://github.com/quay/claircore/releases)
- [Changelog](https://github.com/quay/claircore/blob/main/CHANGELOG.md)
- [Commits](quay/claircore@v1.5.35...v1.5.53)

---
updated-dependencies:
- dependency-name: github.com/quay/claircore
  dependency-version: 1.5.53
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@ksail-bot
ksail-bot Bot enabled auto-merge (squash) July 23, 2026 01:37
@github-actions

github-actions Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

MegaLinter analysis: Success

✅ Linters with no issues

actionlint, bash-exec, git_diff, hadolint, jscpd, jsonlint, lychee, markdown-table-formatter, markdownlint, prettier, prettier, shellcheck, shfmt, stylelint, syft, trivy-sbom, trufflehog, v8r, v8r, yamllint

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: 🫴 Ready

Development

Successfully merging this pull request may close these issues.

0 participants