chore(deps): update bump-dependencies - #8
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. 🚀 New features to boost your workflow:
|
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
from
April 8, 2026 01:46
01b4f16 to
fb4f2c4
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
5 times, most recently
from
April 19, 2026 09:32
79df3ce to
122e719
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
from
May 7, 2026 21:07
122e719 to
8cba5c8
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
3 times, most recently
from
June 4, 2026 03:40
ef491a3 to
f0ba0dc
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
from
June 20, 2026 12:09
f0ba0dc to
e251a98
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
from
July 15, 2026 18:50
e251a98 to
be07967
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
from
July 15, 2026 19:03
be07967 to
d3c2c68
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
2 times, most recently
from
July 17, 2026 20:14
e2972a2 to
866c59d
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
3 times, most recently
from
July 19, 2026 00:38
61bf22f to
95bed66
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
from
July 26, 2026 12:39
95bed66 to
de0439d
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
from
August 2, 2026 17:57
de0439d to
4fd905f
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
2 times, most recently
from
August 8, 2026 12:23
f49da48 to
a4c0af5
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
from
August 8, 2026 16:28
a4c0af5 to
75720dc
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
from
August 8, 2026 21:03
75720dc to
d1d24ee
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
from
August 9, 2026 09:57
d1d24ee to
6fe013c
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
from
August 18, 2026 14:39
6fe013c to
f90aae3
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
2 times, most recently
from
August 20, 2026 18:41
b426a12 to
bc4227c
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
3 times, most recently
from
August 30, 2026 13:45
007ff66 to
dd76dbb
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
from
September 2, 2026 09:53
dd76dbb to
e4cabab
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
from
September 15, 2026 18:07
e4cabab to
2187167
Compare
renovate
Bot
force-pushed
the
renovate.bump-dependencies
branch
from
September 17, 2026 05:13
2187167 to
b1d1df8
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v2.12.2→v2.13.2v2.17.0→v2.18.2Release Notes
golangci/golangci-lint (golangci/golangci-lint)
v2.13.2Compare Source
Released on 2026-08-28
iface: from 1.5.0 to 1.5.1staticcheck: from 0.8.0 to 0.8.1unparam: from3f964bcto2fa3d84canonicalheader: from v1.1.2 to a temporary forkv2.13.1Compare Source
Released on 2026-08-20
ginkgolinter: from 0.23.1 to 0.24.0gofmt: fromd62b90etoe84e050staticcheck: from 0.8.0-rc.1 to 0.8.0wsl_v5: from 5.8.0 to 5.9.0v2.13.0Compare Source
Released on 2026-08-19
dupword: from 0.1.7 to 0.1.8 (new optionskip-raw-strings)errcheck: from 1.10.0 to 1.20.0exhaustruct_v5: from 4.0.0 to 5.0.2 (new configuration)exhaustruct: deprecated and replaced byexhaustruct_v5fatcontext: from 0.9.0 to 0.10.0 (new options:check-loops,check-function-literals)goconst: from 1.10.0 to 1.11.0 (new options:ignore-map-keys,exclude-types)gofumpt: from 0.9.2 to 0.11.0 (new options:extra.group-params,extra.clothe-returns,extra.balance-calls)gomoddirectives: from 0.8.0 to 0.9.0 (new option:replace-allow-all)gosec: from 2.26.1 to 2.27.1govet-modernize: from 0.44.0 to 0.49.0 (fmtappendfis removed. New analyzersatomictypes,embedlit,errorsastype,importcomment,reflecttypeassert,slicesclip, andslicesbackward.waitgroupis renamedwaitgroupgo)iface: from 1.4.3 to 1.5.0 (new analyzer:unusedmethod)noinlineerr: from 1.0.5 to 1.0.6nonamedreturns: from 1.0.6 to 1.0.8 (new option:allow-unused-named-returns)recvcheck: from 0.2.0 to 0.3.0 (new default exclusions)unparam: from5beb8c8to3f964bcclickhouse-go-linter: from 1.2.0 to 1.2.1errname: from 1.1.1 to 1.1.2exhaustruct: from 5.0.2 to 5.0.3funcorder: add missingFunctionfieldginkgolinter: from 0.23.0 to 0.23.1gocheckcompilerdirectives: from 1.3.0 to 1.4.0gocritic: from 0.14.3 to 0.14.4gomoddirectives: add missingIgnoreForbiddenfieldiface: from 1.4.2 to 1.4.3mirror: from 1.3.0 to 1.3.3nilnil: from 1.1.1 to 1.1.2protogetter: from 0.3.20 to 0.3.21goreleaser/goreleaser (goreleaser/goreleaser)
v2.18.2Compare Source
Announcement
Read the official announcement: Announcing GoReleaser v2.18.
Changelog
Security updates
8ec05d6: sec(builds): redact secrets from builder subprocess output (@caarlos0)Bug fixes
f285d13: fix(archive,sourcearchive,gio): backups, ZIP metadata, mtime and CPU variants (#7089) (@caarlos0)d4e9f25: fix(aur): several PKGBUILD and SRCINFO generation bugs (#7100) (@caarlos0)b428c4c: fix(aur): tell users how to fix a duplicate architecture (#7141) (@caarlos0)2e991d2: fix(blob): KMS encryption limits and bucket lifetime on error (#7101) (@caarlos0)7ba40dc: fix(blob): stream unencrypted uploads instead of buffering files (#7134) (@raviayadav and @caarlos0)924f5eb: fix(brew,cask): formula escaping, token matching and binary stanzas (#7086) (@caarlos0)7c77e11: fix(build): resolve dependent hook environment entries and hook dir templates (#7078) (@caarlos0)d22c274: fix(builder/go): give a single ellipsis main an exact output path (#7114) (@caarlos0)be63647: fix(builder/go): keep override env entries in a stable order (#7112) (@caarlos0)4a635ab: fix(builder/go): register the generated C header after compiling (#7113) (@caarlos0)34619ef: fix(builder/node,builder/bun): per-target SEA config, prebuild templates and target aliases (#7088) (@caarlos0)c87158e: fix(builder/rust,builder/zig): toolchain context and wrapped binary copying (#7080) (@caarlos0)566bc69: fix(builder/uv,builder/poetry): match built artifact filenames (#7084) (@caarlos0)13ebd4d: fix(builders,partial): canonical artifact architectures and target matching (#7083) (@caarlos0)e1d9f7f: fix(cmd): auto-snapshot ordering, schema error reporting and --output selection (#7103) (@caarlos0)591a0b8: fix(cmd): correct check counting and init gitignore and failure handling (#7081) (@caarlos0)4f4febf: fix(docker): a bare platform means the baseline CPU variant (#7148) (@caarlos0)000ae78: fix(docker): keep arm64 minor variants above the v8 baseline (#7149) (@caarlos0)d2f775e: fix(docker): quote entrypoint paths and forward arguments verbatim (#7073) (@caarlos0)f2b3611: fix(docker): v1 wheel build IDs, push flags and empty manifests (#7077) (@caarlos0)ea7bc7a: fix(docker): v2 build context, annotations and ARM64 handling (#7095) (@caarlos0)a1f860f: fix(env,log): redact secrets across writes and honour force_token (#7104) (@caarlos0)0d4fe16: fix(exec,publish): cancellation, empty commands, SRPM artifacts and upload URLs (#7093) (@caarlos0)eba5886: fix(flatpak,docker): quote install paths and respect project environment (#7085) (@caarlos0)a95c9a0: fix(git): force column.ui=never so tag output is not columnized (#7127) (@KR-Ravindra)2d7ecb2: fix(git): tag not in the local repository is not an error (#7124) (@caarlos0)aebed26: fix(git,changelog): metadata quoting, dirty detection, key cleanup and mailmap (#7102) (@caarlos0)dce409c: fix(gitea,gitlab): pagination, subpath URLs, default branch, links and cancellation (#7097) (@caarlos0)0348bfb: fix(github): UTF-8 safe truncation, draft reuse, asset replacement and token override (#7094) (@caarlos0)0087e68: fix(github): honor short Retry-After delays (#7110) (@0jaspahwa)f45f629: fix(gomod): scope proxying to Go builds and validate the right module (#7096) (@caarlos0)cf292ef: fix(healthcheck): handle blank and space-containing signer commands (#7076) (@caarlos0)edd3fd0: fix(healthcheck): panic on dependency commands that are only shell syntax (#7106) (@caarlos0)43c0c94: fix(ko): repository image names, digest ordering and signing references (#7079) (@caarlos0)6ceb354: fix(mcp): support package transport URLs (#7090) (@caarlos0)acbfcf5: fix(nfpm): per-format Lintian overrides and colliding filenames (#7099) (@caarlos0)752baca: fix(nix): formatter output, string escaping and post_install (#7082) (@caarlos0)05ee35f: fix(nix): template the description only once (#7146) (@caarlos0)a3a8903: fix(project): evaluate name candidates lazily (#7111) (@0jaspahwa)25a52e5: fix(sbom,sign): disambiguate every target variant in default names (#7144) (@caarlos0)c62e59f: fix(scripts): correct pre-commit hook exit status, quoting and restaging (#7074) (@caarlos0)e0418e8: fix(sign,sbom,universalbinary): universal binary signing, per-variant names and duplicate slices (#7091) (@caarlos0)06bf150: fix(slack,smtp,config): cancellation, message escaping and block round-trips (#7092) (@caarlos0)cb8a445: fix(tmpl): deduplicate aggregate errors and stop mutating input (#7075) (@caarlos0)e99a557: fix(winget): do not allow multiple wingets with the same name (#7147) (@caarlos0)52e4c58: fix(winget,krew): manifest validation and executable paths (#7087) (@caarlos0)b15ccce: fix: address regressions since v2.18.1 (#7107) (@caarlos0)ac548c1: refactor: simplify internal code and test setup (#7068) (@caarlos0)Documentation updates
385916d: docs(builder/go): explain that ellipsis discovery uses the host context (#7115) (@caarlos0)e6d5fc5: docs: Add Kronk in USERS.md (#7151) (@gandarez)4faacf5: docs: fix configuration examples and reference mismatches (#7066) (@caarlos0)Other work
7d055fd: chore: auto-update generated files (#7070) (@goreleaserbot)7748fa7: chore: auto-update generated files (#7123) (@goreleaserbot)2ab3100: chore: auto-update generated files (#7129) (@goreleaserbot)46d055b: chore: cc maintainer on winget pull requests (#7071) (@caarlos0)c3afaa0: chore: fix lint on main (#7105) (@caarlos0)7c44449: chore: lint fixes (@caarlos0)Full Changelog: goreleaser/goreleaser@v2.18.1...v2.18.2
Helping out
This release is only possible thanks to all the support of some awesome people!
Want to be one of them?
You can sponsor, get a Pro License or contribute with code.
Where to go next?
v2.18.1Compare Source
Announcement
Read the official announcement: Announcing GoReleaser v2.18.
Changelog
Security updates
628c889: sec(deps): bump golang.org/x/crypto and golang.org/x/mod (#6872) (@caarlos0)Bug fixes
e38e2fd: fix(archive): report stripped binary paths (#6820) (@davicbtoliveira)315a4fd: fix(aursources): clarify error and document source.enabled requirement (#6816) (@0jaspahwa)b7f1239: fix(cask): deprecate url.verified (#6871) (@caarlos0)2c613de: fix(chocolatey): a skipped chocolatey entry stops the ones after it (#6853) (@hktitof)33cc363: fix(client): apply the commit config per command (#6852) (@caarlos0)db7a1e6: fix(client): stop TestGitLabRateLimitRetryAfter racing the clock (#6846) (@caarlos0)c8126af: fix(cmd): drop setup's unused return value (#6845) (@caarlos0)d951018: fix(docker): only use wheels of the configured ids (#6860) (@caarlos0)0a6f83e: fix(git): report repository detection errors (#6869) (@caarlos0)edcfdec: fix(gitlab): own the retries, and honor replace_existing_artifacts (#6843) (@caarlos0)f5edd73: fix(gomod): don't read the module path from stderr (#6864) (@caarlos0)35051e4: fix(sign): warn when the signer writes no file, fail in v3 (#6842) (@caarlos0)e1a1e9c: fix: map every 32-bit ARM variant to Termux's "arm" (#6857) (@dylanpulver)Documentation updates
e5730eb: docs: fix broken commands, dead links, and inaccurate options (#6841) (@caarlos0)Other work
8afe0bb: chore: auto-update generated files (#6811) (@goreleaserbot)c1493d3: chore: auto-update generated files (#6812) (@goreleaserbot)3294442: chore: auto-update generated files (#6861) (@goreleaserbot)6e40871: chore: update to Go 1.27.1 (#6859) (@caarlos0)4181c4f: perf(git): ask git once (#6850) (@caarlos0)dcbe117: perf(node): faster dist extraction, and stop leaking it into TMPDIR (#6844) (@caarlos0)36e43dd: perf: skip needless docker probes; make the ko registry test hermetic (#6827) (@caarlos0)Full Changelog: goreleaser/goreleaser@v2.18.0...v2.18.1
Helping out
This release is only possible thanks to all the support of some awesome people!
Want to be one of them?
You can sponsor, get a Pro License or contribute with code.
Where to go next?
v2.18.0Compare Source
Announcement
Read the official announcement: Announcing GoReleaser v2.18.
Changelog
New Features
601cd87: feat(ko): support templating for local_domain, base_image, and repositories (#6741) (@mrueg)de88f38: feat(winget): support publishing additional locale manifests (#6733) (@MohammedAnasuddinZaid)cefbc6f: feat: add iru custom apps publisher (#6709) (@wimwenigerkind)1d6e7c0: feat: allow PR creation to use a different auth token (#6717) (@emily-curry)4c41ac0: feat: preflight checks (#6704) (@caarlos0)060260a: feat: release summary (#6810) (@caarlos0)82a5aba: feat: update to Go 1.27 (#6802) (@caarlos0)Security updates
b1cafd4: sec(deps): bump go-openapi/spec and go-openapi/validade (#6766) (@caarlos0)Bug fixes
1970443: fix(aur): expand description templates before escaping quotes (#6791) (@VXNCXNX and @caarlos0)a27402d: fix(blob): honor s3_force_path_style without a custom endpoint (#6789) (@VXNCXNX and @caarlos0)db65b99: fix(brew): a formula without a repository stops the ones after it (#6783) (@caarlos0)2b5fb31: fix(build): node windows targets get no .exe extension (#6777) (@VXNCXNX and @vxncxnx)951fc57: fix(cask): a cask without a repository stops the ones after it (#6785) (@caarlos0)54a6c8e: fix(cask): emit Casks that pass brew style (#6752) (@r0h1tb)2d6b235: fix(changelog): a commit matching two include filters is listed twice (#6773) (@VXNCXNX and @caarlos0)c4cc86f: fix(chocolatey): error on multiple archives for the same platform (#6792) (@VXNCXNX)1a246da: fix(config): type retry durations as strings in schema (#6801) (@skatkov)8be344b: fix(docker): add gpg-agent to the image (#6763) (@caarlos0)5282589: fix(dockers/v2): annotation scopes (#6800) (@CraigAstillRVU and @caarlos0)5560bb9: fix(flatpak): a disabled flatpak stops the ones after it (#6781) (@VXNCXNX)b68113a: fix(git): tag templates strip apostrophes from the message (#6779) (@VXNCXNX and @vxncxnx)1bc6ec7: fix(healthcheck): register upx and makeself dependency checkers (#6793) (@VXNCXNX)9d7d49f: fix(krew): a manifest without a name stops the ones after it (#6787) (@caarlos0)4276c51: fix(krew): apply the documented goarm default (#6775) (@VXNCXNX and @vxncxnx)9700230: fix(mcp): mcp.disable is documented but never read (#6795) (@VXNCXNX)1d79a09: fix(milestone): a milestone with close disabled stops the ones after it (#6778) (@VXNCXNX and @vxncxnx)2a0393d: fix(nfpm): don't set deb arch variant for goamd64 v1 (#6765) (@caarlos0)912704c: fix(nfpm): overrides ignore package_name, epoch, release and prerelease (#6782) (@VXNCXNX)3cf25c0: fix(nfpm): record the conventional extension, not the format name (#6776) (@VXNCXNX and @vxncxnx)ad028a3: fix(nix): a skipped nix entry stops the ones after it (#6788) (@VXNCXNX)b787cd2: fix(notarize): cap macOS notarization timeout at 20m (#6758) (@caarlos0)81a5509: fix(sign): artifacts: none masks real signing failures (#6790) (@VXNCXNX)4eb6037: fix(snapcraft): a disabled snap stops the ones after it (#6784) (@caarlos0)d93d0f1: fix(snapcraft): assumes, hooks and plugs are dropped when apps is omitted (#6780) (@VXNCXNX and @vxncxnx)b3bbd53: fix(srpm): make documented rpm fields actually configurable (#6762) (@caarlos0)7304fdb: fix(tmpl): register the documented join template function (#6772) (@VXNCXNX)6f88b00: fix(upload): a misconfigured upload stops the others (#6786) (@caarlos0)67e4c45: fix(winget): a skipped winget entry stops the ones after it (#6797) (@VXNCXNX)92453c1: fix(winget): count arm64 in the duplicate-archive check (#6774) (@VXNCXNX and @caarlos0)9a43dd0: fix(winget): fall back to the default description in additional locales (#6771) (@VXNCXNX)6127e0f: fix: do not panic decoding a commit whose message contains a log marker (#6738) (@arpitjain099)02cfda7: fix: lint (@caarlos0)b990083: fix: surface archive Close errors when writing release archives (#6690) (@SebTardif and @caarlos0)Documentation updates
33a3f22: docs(dockers_v2): clarify that build and push are a single step (#6742) (@caarlos0)1eb0ee9: docs: download SBOMs (#6803) (@caarlos0)16debcb: docs: many fixes (@caarlos0)ff2822a: docs: update dockers_v2 (@caarlos0)686946e: docs: use correct script for debconf (#6759) (@Daniel15)9921479: docs: use formats plural syntax (#6756) (@FelicianoTech)Other work
2b80858: chore: auto-update generated files (#6731) (@goreleaserbot)7df2cd5: chore: auto-update generated files (#6732) (@goreleaserbot)dd08c1f: chore: auto-update generated files (#6740) (@goreleaserbot)ee0e3c1: chore: auto-update generated files (#6744) (@goreleaserbot)cab7c6e: chore: auto-update generated files (#6769) (@goreleaserbot)39552ca: chore: auto-update generated files (#6794) (@goreleaserbot)4a82792: chore: auto-update generated files (#6798) (@goreleaserbot)ae88a14: chore: auto-update generated files (#6806) (@goreleaserbot)52494d9: chore: auto-update generated files (#6809) (@goreleaserbot)Full Changelog: goreleaser/goreleaser@v2.17.1...v2.18.0
Helping out
This release is only possible thanks to all the support of some awesome people!
Want to be one of them?
You can sponsor, get a Pro License or contribute with code.
Where to go next?
v2.17.1Compare Source
Announcement
Read the official announcement: Announcing GoReleaser v2.17.
Changelog
Bug fixes
a734383: fix(builder/go): parse GORISCV64 and GOPPC64 for riscv64 and ppc64le targets (#6698) (@upuddu)dfc7f06: fix(builders/go): sort targets (@caarlos0)7630cd1: fix(deps): go1.26.5 (@caarlos0)9dbb266: fix(notary): poll notarization status every 10s, not 10ns (#6726) (@caarlos0)1ebf881: fix: anchor goarm64 validation regex to reject invalid values (#6727) (@semx)70f6921: fix: migrate from deprecated s3/manager to s3/transfermanager (#6706) (@joeyberkovitz)Documentation updates
eafb0ec: docs(users): update charm domain (#6699) (@andreynering)ae4debb: docs: add /.well-known/security.txt (RFC 9116) (#6710) (@kobihikri)d3764c8: docs: fix typo (@caarlos0)742ae5f: docs: move images to a bucket (#6691) (@caarlos0)55a466e: docs: publish to GitLab package registries with the http upload pipe (#6697) (@ajuijas)65240d8: docs: update users (@caarlos0)Other work
0eb5b0f: chore(ci): update dependabot config (@caarlos0)4bcb2a5: chore(ci): update deps (@caarlos0)5f3f435: chore: auto-update generated files (#6693) (@goreleaserbot)9b85924: chore: auto-update generated files (#6694) (@goreleaserbot)1aab79e: chore: auto-update generated files (#6700) (@goreleaserbot)11d0150: chore: auto-update generated files (#6705) (@goreleaserbot)5747ca7: chore: auto-update generated files (#6707) (@goreleaserbot)83f4c19: chore: auto-update generated files (#6730) (@goreleaserbot)f3a0e63: chore: svu config (@caarlos0)Full Changelog: goreleaser/goreleaser@v2.17.0...v2.17.1
Helping out
This release is only possible thanks to all
Configuration
📅 Schedule: (UTC)
* * * * 3)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.