chore(deps): update all non-major dependencies#2935
Merged
Conversation
Contributor
Author
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
The gomodTidy post-update option runs `go mod tidy` with Renovate's own Go image. Since that image moved to Go 1.26, every tidy rewrote the `go` directive in go.mod from 1.25.10 to 1.26.4, which breaks the whole 1.25.x CI matrix (GOTOOLCHAIN=local) and enables stricter vet checks. Constraining the Go version keeps Renovate on a 1.25 toolchain, which leaves the directive untouched.
github.com/planetscale/vtprotobuf declares `go 1.26.4` since the 2026-07-02 pseudo-version, which forced `go mod tidy` to bump the `go` directive of the main module and broke the whole 1.25.x CI matrix. Nothing imports this module (it is only pulled into the module graph by grpc/genproto), so requiring the older revision every other dependency already asks for keeps the graph buildable with Go 1.25.
Contributor
Author
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v7.0.0→v7.0.1v1.63.1→v1.64.0v1.34.0→v1.35.0v0.58.0→v0.59.0v0.58.0→v0.59.0v1.42.1→v1.43.0v1.32.30→v1.32.31v1.19.29→v1.19.30v1.18.30→v1.18.31v1.4.30→v1.4.31v2.7.30→v2.7.31v1.4.31→v1.4.32v1.9.23→v1.9.24v1.13.30→v1.13.31v1.19.31→v1.19.32v1.105.1→v1.106.0v1.4.1→v1.5.0v1.32.1→v1.33.0v1.37.1→v1.38.0v1.44.1→v1.45.0v1.27.3→v1.27.44bee191→7cc6674v2.5.0→v2.5.2v1.4.3→v1.4.4v0.3.18→v0.3.19v1.19.0→v1.19.1v0.0.22→v0.0.24v0.0.24→v0.0.27v0.5.15→v0.5.169ea1abe→764159dv0.288.0→v0.290.0f5fc221→b2f2020f5fc221→b2f2020f5fc221→b2f20203.7.1→3.7.219def06→dccf23f2255122→dccf23f11.13.0+sha512.88d94724d8f2e6c186744a5584c6e59ecac869ec7ba15e9cb4cd628e8dc7066820b2481d8ee3b51ea8da323a7378068aa58c556a3720d32b7c20a051d088363a→11.17.011.13.0→11.17.03.9.5→3.9.63.5.39→3.5.40Release Notes
actions/checkout (actions/checkout)
v7.0.1Compare Source
GoogleCloudPlatform/opentelemetry-operations-go (github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric)
v0.59.0Compare Source
What's Changed
New Contributors
Full Changelog: GoogleCloudPlatform/opentelemetry-operations-go@v0.58.0...v0.59.0
aws/aws-sdk-go-v2 (github.com/aws/aws-sdk-go-v2)
v1.43.0Compare Source
Module Highlights
github.com/aws/aws-sdk-go-v2/service/autoscaling: v1.61.0github.com/aws/aws-sdk-go-v2/service/backup: v1.53.0github.com/aws/aws-sdk-go-v2/service/bedrockruntime: v1.43.0github.com/aws/aws-sdk-go-v2/service/cloudformation: v1.70.0github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.59.0github.com/aws/aws-sdk-go-v2/service/connect: v1.146.0github.com/aws/aws-sdk-go-v2/service/ec2: v1.271.0github.com/aws/aws-sdk-go-v2/service/iam: v1.51.0github.com/aws/aws-sdk-go-v2/service/kafka: v1.46.0github.com/aws/aws-sdk-go-v2/service/resourcegroupstaggingapi: v1.31.0github.com/aws/aws-sdk-go-v2/service/wafv2: v1.70.0aws/smithy-go (github.com/aws/smithy-go)
v1.27.4Compare Source
dlclark/regexp2 (github.com/dlclark/regexp2/v2)
v2.5.2Compare Source
v2.5.1Compare Source
go-logr/logr (github.com/go-logr/logr)
v1.4.4Compare Source
What's Changed
New Contributors
Full Changelog: go-logr/logr@v1.4.3...v1.4.4
googleapis/enterprise-certificate-proxy (github.com/googleapis/enterprise-certificate-proxy)
v0.3.19Compare Source
What's Changed
Full Changelog: googleapis/enterprise-certificate-proxy@v0.3.17...v0.3.19
klauspost/compress (github.com/klauspost/compress)
v1.19.1Compare Source
What's Changed
Peekinstead ofReadBytefor thebufio.Readerdecode path by @joechenrh in #1169New Contributors
Full Changelog: klauspost/compress@v1.19.0...v1.19.1
mattn/go-isatty (github.com/mattn/go-isatty)
v0.0.24Compare Source
v0.0.23Compare Source
mattn/go-runewidth (github.com/mattn/go-runewidth)
v0.0.27Compare Source
v0.0.26Compare Source
v0.0.25Compare Source
ulikunitz/xz (github.com/ulikunitz/xz)
v0.5.16Compare Source
googleapis/google-api-go-client (google.golang.org/api)
v0.290.0Compare Source
Features
v0.289.0Compare Source
Features
vektra/mockery (mockery)
v3.7.2Compare Source
What's Changed
New Contributors
Full Changelog: vektra/mockery@v3.7.1...v3.7.2
pnpm/pnpm (pnpm)
v11.17.0: pnpm 11.17Compare Source
Minor Changes
Added a new setting,
update.githubActionsServer, for specifying the base URL of the GitHub server that hosts the repositories of the GitHub Actions referenced by the workflow files (for example, a GitHub Enterprise Server). When the setting is not defined, the URL is read from theGITHUB_SERVER_URLenvironment variable, falling back tohttps://github.com. The URL must use thehttps://orhttp://protocol #13220.pnpm outdatedandpnpm updateno longer fail when the refs of a GitHub Action's repository cannot be read (for example, when the action's repository is private or hosted on a different GitHub server). Such actions are now skipped with a warning.Setting
update.githubActionstofalsenow makespnpm outdatedand the interactivepnpm updateskip GitHub Actions dependencies.Patch Changes
The token poll for web-based authentication no longer reads the body of non-OK or still-pending (HTTP 202) responses, and caps the token response body it does read at 64 KiB, so a malicious or compromised registry cannot exhaust memory through the poll pnpm/pnpm#12721.
Fixed
catalog:references in dependencies and overrides failing to resolve when installing through a pnpr server, which errored with "No catalog entry '' was found for catalog 'default'." even though the catalog entry existed. Also fixed a crash on Windows when installing a nested workspace member (e.g.packages/foo) through a pnpr server #13232.Republished every package: the tarballs published by the v11.13.1 through v11.16.0 releases were missing most of their compiled files due to a packing bug #13164.
Revert script ordering change for
pnpm run --sequential /regex/Support the
from-gitargument in thepnpm versioncommand.When the authentication URL cannot be rendered as a QR code (for example when it exceeds the maximum QR data capacity), web-based login now displays the URL alone with a warning instead of aborting authentication pnpm/pnpm#12721.
Platinum Sponsors
Gold Sponsors
v11.16.0: pnpm 11.16Compare Source
Minor Changes
The first release of a package now publishes the version written in its manifest verbatim, instead of bumping off it.
pnpm version -randpnpm change statuscheck the registry for each release's current version; when that version is not yet published, the package debuts at it and its pending changesets apply only from the next release. A newly added package seeded at1100.0.0with aminorchangeset is therefore published as1100.0.0rather than skipping straight to1100.1.0.Added a
--changesetflag topnpm update. Setupdate.changesettotrueinpnpm-workspace.yamlto enable this behavior by default, and use--no-changesetto override the setting for one update. After the update completes, pnpm writes a.changeset/pnpm-update-<suffix>.mdfile declaring a patch bump for every workspace package whosedependenciesoroptionalDependencieswere changed by the update and a major bump whenpeerDependencieschanged, including packages that consume an updated catalog entry via thecatalog:protocol. Private packages, packages without a name, and packages listed in theignorearray of.changeset/config.jsonare skipped. If.changeset/config.jsondoes not exist, a warning is printed and no changeset is generated.Added GitHub Actions dependencies to
pnpm outdatedand interactivepnpm update. Non-interactive updates can include them with--include-github-actionsor by settingupdate.githubActionstotrueinpnpm-workspace.yaml. Updated actions are pinned to exact commit hashes with their release tags preserved in comments.Added
updateandauditsettings sections topnpm-workspace.yaml, superseding the awkwardly namedupdateConfig,auditConfig, and top-levelauditLevelsettings:update.ignoreDepslists dependency name patterns thatpnpm updateandpnpm outdatedshould skip.audit.levelandaudit.ignoretunepnpm audit.The deprecated
updateConfig,auditConfig, andauditLevelsettings keep working until the next major version. When both a new section value and its deprecated counterpart are set, the new section takes precedence and a warning is printed. Both the TypeScript CLI and the Rust config surface (pacquet) recognize the new sections.Patch Changes
pnpm add --save-exact/--save-prefixandpnpm updatewriting a package's version with thepeerDependenciesrange's prefix (e.g.^19.2.7instead of the requested19.2.7) whenever the same package also appeared inpeerDependencies. A realdependencies/devDependencies/optionalDependenciesentry now takes precedence over a same-namedpeerDependenciesentry when computing the current specifiers #13108.Platinum Sponsors
Gold Sponsors
v11.15.1Compare Source
v11.15.0: pnpm 11.15Compare Source
Minor Changes
peerDependenciesMeta(for exampledebug'ssupports-colorpeer) are now resolved from a satisfying version already present in the dependency graph, the same way explicitly declared optional peer dependencies are. Previously such peers were only resolved this way when the package's metadata was read back from the lockfile, so an unrelated dependency change could rewrite peer resolutions across the whole lockfile.Patch Changes
Updated
adm-zipto prevent crafted ZIP archives from causing excessive memory allocation.pnpm version -rno longer writes a versioning-ledger entry with no consumed intents as a bareintents:key, which the next run failed to read withERR_PNPM_INVALID_VERSIONING_LEDGER. Empty intent lists are now written asintents: [], and the ledger reader accepts the bare form left by earlier releases.Fixed pnpr workspace resolution to preserve project names and versions for
workspace:dependencies.Platinum Sponsors
Gold Sponsors
This PR was generated by Mend Renovate. View the repository job log.