Skip to content
This repository was archived by the owner on Sep 24, 2025. It is now read-only.

Conversation

@netic-renovate
Copy link
Contributor

@netic-renovate netic-renovate bot commented Jul 3, 2025

This PR contains the following updates:

Package Change Age Confidence Type Update
github.com/aquasecurity/trivy v0.63.0 -> v0.66.0 age confidence require minor
github.com/aquasecurity/trivy-operator v0.27.1 -> v0.28.0 age confidence require minor
github.com/spf13/cobra v1.9.1 -> v1.10.1 age confidence require minor
go (source) 1.24.4 -> 1.25.1 age confidence toolchain minor
k8s.io/api v0.33.2 -> v0.34.1 age confidence require minor
k8s.io/apimachinery v0.33.2 -> v0.34.1 age confidence require minor
k8s.io/client-go v0.33.2 -> v0.34.1 age confidence require minor
sigs.k8s.io/controller-runtime v0.21.0 -> v0.22.1 age confidence require minor

Release Notes

aquasecurity/trivy (github.com/aquasecurity/trivy)

v0.66.0

Compare Source

👉 Trivy v.66.0 release notes (click here)

⬇️ Download Trivy

Full changelog

v0.65.0

Compare Source

👉 Trivy v.65.0 release notes (click here)

⬇️ Download Trivy

Full changelog

v0.64.1

Compare Source

Changelog

  • 86ee3c1 release: v0.64.1 [release/v0.64] (#​9122)
  • 4e12722 fix(misconf): skip rewriting expr if attr is nil [backport: release/v0.64] (#​9127)
  • 9a7d384 fix(cli): Add more non-sensitive flags to telemetry [backport: release/v0.64] (#​9124)
  • 53adfba fix(rootio): check full version to detect root.io packages [backport: release/v0.64] (#​9120)
  • 8cf1bf9 fix(alma): parse epochs from rpmqa file [backport: release/v0.64] (#​9119)

v0.64.0

Compare Source

👉 Trivy v.64.0 release notes (click here)

⬇️ Download Trivy

Full changelog
aquasecurity/trivy-operator (github.com/aquasecurity/trivy-operator)

v0.28.0

Compare Source

What's Changed

✨ Notable Changes ✨
🐛 Notable Fixes 🐛
📝 Documentation && Miscellaneous 🔧
👒 Dependencies 👒
  • build(deps): bump ubi9/ubi-minimal from 0d7cfb0 to 295f920 in /build/trivy-operator by @​dependabot[bot] in #​2688
  • build(deps): bump alpine from 3.20.6 to 3.22.1 in /build/trivy-operator by @​dependabot[bot] in #​2687

New Contributors

Full Changelog: aquasecurity/trivy-operator@v0.27.3...v0.28.0

v0.27.3

Compare Source

What's Changed

🐛 Notable Fixes 🐛

New Contributors

Full Changelog: aquasecurity/trivy-operator@v0.27.2...v0.27.3

v0.27.2

Compare Source

What's Changed

🐛 Notable Fixes 🐛
📝 Documentation && Miscellaneous 🔧
👒 Dependencies 👒

Full Changelog: aquasecurity/trivy-operator@v0.27.1...v0.27.2

spf13/cobra (github.com/spf13/cobra)

v1.10.1

Compare Source

🐛 Fix

v1.0.9 of pflags brought back ParseErrorsWhitelist and marked it as deprecated

Full Changelog: spf13/cobra@v1.10.0...v1.10.1

v1.10.0

Compare Source

What's Changed

🚨 Attention!

This version of pflag carried a breaking change: it renamed ParseErrorsWhitelist to ParseErrorsAllowlist which can break builds if both pflag and cobra are dependencies in your project.

  • If you use both pflag and cobra, upgrade pflagto 1.0.8 andcobrato1.10.0`
  • or use the newer, fixed version of pflag v1.0.9 which keeps the deprecated ParseErrorsWhitelist

More details can be found here: #​2303 (comment)

✨ Features
🐛 Fix
🪠 Testing
📝 Docs

New Contributors

Full Changelog: spf13/cobra@v1.9.1...v1.9.2

kubernetes/api (k8s.io/api)

v0.34.1

Compare Source

v0.34.0

Compare Source

v0.33.5

Compare Source

v0.33.4

Compare Source

v0.33.3

Compare Source

kubernetes/apimachinery (k8s.io/apimachinery)

v0.34.1

Compare Source

v0.34.0

Compare Source

v0.33.5

Compare Source

v0.33.4

Compare Source

v0.33.3

Compare Source

kubernetes/client-go (k8s.io/client-go)

v0.34.1

Compare Source

v0.34.0

Compare Source

v0.33.5

Compare Source

v0.33.4

Compare Source

v0.33.3

Compare Source

kubernetes-sigs/controller-runtime (sigs.k8s.io/controller-runtime)

v0.22.1

Compare Source

What's Changed

Full Changelog: kubernetes-sigs/controller-runtime@v0.22.0...v0.22.1

v0.22.0

Compare Source

🔆 Highlights

⚠️ Breaking changes

✨ Features

🐛 Bugfixes

🌱 Other

📖 Documentation

Dependencies

Added
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp: v1.26.0
  • github.com/envoyproxy/go-control-plane/envoy: v1.32.4
  • github.com/envoyproxy/go-control-plane/ratelimit: v0.1.0
  • github.com/go-jose/go-jose/v4: v4.0.4
  • github.com/golang-jwt/jwt/v5: v5.2.2
  • github.com/grpc-ecosystem/go-grpc-middleware/providers/prometheus: v1.0.1
  • github.com/grpc-ecosystem/go-grpc-middleware/v2: v2.3.0
  • github.com/spiffe/go-spiffe/v2: v2.5.0
  • github.com/zeebo/errs: v1.4.0
  • go.etcd.io/raft/v3: v3.6.0
  • go.opentelemetry.io/contrib/detectors/gcp: v1.34.0
  • go.opentelemetry.io/otel/sdk/metric: v1.34.0
  • go.yaml.in/yaml/v2: v2.4.2
  • go.yaml.in/yaml/v3: v3.0.4
  • sigs.k8s.io/structured-merge-diff/v6: v6.3.0
Changed
  • cel.dev/expr: v0.19.1 → v0.24.0
  • cloud.google.com/go/compute/metadata: v0.5.0 → v0.6.0
  • github.com/cncf/xds/go: b4127c9 → 2f00578
  • github.com/cpuguy83/go-md2man/v2: v2.0.4 → v2.0.6
  • github.com/emicklei/go-restful/v3: v3.11.0 → v3.12.2
  • github.com/envoyproxy/go-control-plane: v0.13.0 → v0.13.4
  • github.com/envoyproxy/protoc-gen-validate: v1.1.0 → v1.2.1
  • github.com/fsnotify/fsnotify: v1.7.0 → v1.9.0
  • github.com/fxamacker/cbor/v2: v2.7.0 → v2.9.0
  • github.com/golang/glog: v1.2.2 → v1.2.4
  • github.com/google/cel-go: v0.23.2 → v0.26.0
  • github.com/google/gnostic-models: v0.6.9 → v0.7.0
  • github.com/grpc-ecosystem/grpc-gateway/v2: v2.24.0 → v2.26.3
  • github.com/jonboulle/clockwork: v0.4.0 → v0.5.0
  • github.com/modern-go/reflect2: v1.0.2 → 35a7c28
  • github.com/spf13/cobra: v1.8.1 → v1.9.1
  • github.com/spf13/pflag: v1.0.5 → v1.0.6
  • go.etcd.io/bbolt: v1.3.11 → v1.4.2
  • go.etcd.io/etcd/api/v3: v3.5.21 → v3.6.4
  • go.etcd.io/etcd/client/pkg/v3: v3.5.21 → v3.6.4
  • go.etcd.io/etcd/client/v3: v3.5.21 → v3.6.4
  • go.etcd.io/etcd/pkg/v3: v3.5.21 → v3.6.4
  • go.etcd.io/etcd/server/v3: v3.5.21 → v3.6.4
  • go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc: v0.58.0 → v0.60.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc: v1.33.0 → v1.34.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace: v1.33.0 → v1.34.0
  • go.opentelemetry.io/otel/metric: v1.33.0 → v1.35.0
  • go.opentelemetry.io/otel/sdk: v1.33.0 → v1.34.0
  • go.opentelemetry.io/otel/trace: v1.33.0 → v1.35.0
  • go.opentelemetry.io/otel: v1.33.0 → v1.35.0
  • go.opentelemetry.io/proto/otlp: v1.4.0 → v1.5.0
  • google.golang.org/genproto/googleapis/api: e6fa225a0af3ef
  • google.golang.org/genproto/googleapis/rpc: e6fa225a0af3ef
  • google.golang.org/grpc: v1.68.1 → v1.72.1
  • k8s.io/api: v0.33.0 → v0.34.0
  • k8s.io/apiextensions-apiserver: v0.33.0 → v0.34.0
  • k8s.io/apimachinery: v0.33.0 → v0.34.0
  • k8s.io/apiserver: v0.33.0 → v0.34.0
  • k8s.io/client-go: v0.33.0 → v0.34.0
  • k8s.io/code-generator: v0.33.0 → v0.34.0
  • k8s.io/component-base: v0.33.0 → v0.34.0
  • k8s.io/gengo/v2: 1244d3185fd79d
  • k8s.io/kms: v0.33.0 → v0.34.0
  • k8s.io/kube-openapi: c8a335af3f2b99
  • k8s.io/utils: 3ea5e8c4c0f3b2
  • sigs.k8s.io/json: 9aa6b5ecfa47c3
  • sigs.k8s.io/yaml: v1.4.0 → v1.6.0
Removed
  • github.com/census-instrumentation/opencensus-proto: v0.4.1
  • github.com/golang-jwt/jwt/v4: v4.5.2
  • github.com/grpc-ecosystem/go-grpc-middleware: v1.3.0
  • github.com/grpc-ecosystem/grpc-gateway: v1.16.0
  • go.etcd.io/etcd/client/v2: v2.305.21
  • go.etcd.io/etcd/raft/v3: v3.5.21
  • google.golang.org/genproto: ef43131
  • sigs.k8s.io/structured-merge-diff/v4: v4.6.0

New Contributors

Full Changelog: kubernetes-sigs/controller-runtime@v0.21.0...v0.22.0

Thanks to all our contributors! 😊


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@netic-renovate
Copy link
Contributor Author

netic-renovate bot commented Jul 3, 2025

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: go.sum
Command failed: go get -t ./...
go: gopkg.in/go-jose/go-jose.v4@v4.1.0: parsing go.mod:
	module declares its path as: github.com/go-jose/go-jose/v4
	        but was required as: gopkg.in/go-jose/go-jose.v4

@netic-renovate netic-renovate bot force-pushed the renovate/go-module-updates-minor branch from a5972a8 to 3e0f239 Compare July 7, 2025 06:39
@netic-renovate netic-renovate bot changed the title fix(deps): update module github.com/aquasecurity/trivy to v0.64.0 fix(deps): update module github.com/aquasecurity/trivy to v0.64.1 Jul 7, 2025
@netic-renovate netic-renovate bot force-pushed the renovate/go-module-updates-minor branch from 3e0f239 to ef9bfa6 Compare August 4, 2025 06:51
@netic-renovate netic-renovate bot changed the title fix(deps): update module github.com/aquasecurity/trivy to v0.64.1 fix(deps): update module github.com/aquasecurity/trivy to v0.65.0 Aug 4, 2025
@netic-renovate netic-renovate bot force-pushed the renovate/go-module-updates-minor branch from ef9bfa6 to 4c0de22 Compare August 8, 2025 06:45
@netic-renovate netic-renovate bot changed the title fix(deps): update module github.com/aquasecurity/trivy to v0.65.0 fix(deps): update go module updates minor Aug 8, 2025
@netic-renovate netic-renovate bot force-pushed the renovate/go-module-updates-minor branch from 4c0de22 to 44f4269 Compare August 14, 2025 06:44
@netic-renovate netic-renovate bot force-pushed the renovate/go-module-updates-minor branch 4 times, most recently from fd05bea to 6508665 Compare September 3, 2025 16:43
@netic-renovate netic-renovate bot force-pushed the renovate/go-module-updates-minor branch 4 times, most recently from 348f330 to 2c723b9 Compare September 10, 2025 08:40
@netic-renovate netic-renovate bot force-pushed the renovate/go-module-updates-minor branch from 2c723b9 to 0cf17fb Compare September 12, 2025 06:47
@netic-renovate netic-renovate bot added the renovate-auto-approve Enables auto approval for Renovate PRs label Sep 16, 2025
@KimNorgaard KimNorgaard merged commit 4352855 into main Sep 22, 2025
1 of 3 checks passed
@KimNorgaard KimNorgaard deleted the renovate/go-module-updates-minor branch September 22, 2025 09:38
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

renovate-auto-approve Enables auto approval for Renovate PRs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants