Skip to content

Conversation

@renovate
Copy link

@renovate renovate bot commented Dec 25, 2024

Note: This PR body was truncated due to platform limits.

Update Request | Renovate Bot

This PR contains the following updates:

Package Type Update Change Age Adoption Passing Confidence
actions/stale action digest 9971854a21a081
fosrl/newt patch 1.8.01.8.1 age adoption passing confidence
git://git.kernel.org/pub/scm/utils/mdadm/mdadm.git minor 4.44.5 age adoption passing confidence
github.com/anchore/grype indirect minor v0.0.0-00010101000000-000000000000v0.104.3 age adoption passing confidence
github.com/anchore/syft indirect minor v1.28.0v1.39.0 age adoption passing confidence
github.com/dsseng/grype replace digest 21977929b7e8e2
github.com/dsseng/syft replace minor v1.26.2-0.20250703101014-f39c35d156d9v1.38.0 age adoption passing confidence
github.com/gomodule/redigo replace major v0.0.0-20150301180006-535138d7bcd7v1.9.3 age adoption passing confidence
google/gvisor patch 20251208.020251215.0 age adoption passing confidence
https://gitlab.gnome.org/GNOME/glib.git patch 2.87.02.87.1 age adoption passing confidence
https://sourceware.org/git/glibc.git minor 2.412.42 age adoption passing confidence
netbirdio/netbird minor 0.60.90.61.2 age adoption passing confidence
tailscale/tailscale patch 1.92.31.92.5 age adoption passing confidence

Release Notes

fosrl/newt (fosrl/newt)

v1.8.1

Compare Source

Container Images

  • GHCR: ghcr.io/fosrl/newt@sha256:c05a8383fc8370e6211f0ab84e37993848aae224322d0c5aede7d3368414bdd0
  • Docker Hub: docker.io/fosrl/newt@sha256:c05a8383fc8370e6211f0ab84e37993848aae224322d0c5aede7d3368414bdd0
    Digest: sha256:c05a8383fc8370e6211f0ab84e37993848aae224322d0c5aede7d3368414bdd0

What's Changed

  • chore(nix): add nix hash update automation by @​water-sucks in #​217
  • Fix health check leaking socket binds

Full Changelog: fosrl/newt@1.8.0...1.8.1

anchore/grype (github.com/anchore/grype)

v0.104.3

Compare Source

Bug Fixes

(Full Changelog)

v0.104.2

Compare Source

Bug Fixes
Additional Changes

(Full Changelog)

v0.104.1

Compare Source

Bug Fixes
Additional Changes

(Full Changelog)

v0.104.0

Compare Source

Added Features
Bug Fixes
Additional Changes

(Full Changelog)

v0.103.0

Compare Source

Added Features

(Full Changelog)

v0.102.0

Compare Source

Added Features
Bug Fixes
  • Bitnami packages with CPEs are not matched against CPE-based vulnerabilities [#​2997]
Additional Changes

(Full Changelog)

v0.101.1

Compare Source

Bug Fixes
  • Panic error scanning images with v0.101.0 on some java dependencies [#​3002]

(Full Changelog)

v0.101.0

Compare Source

Added Features
Bug Fixes
  • Issue installing Grype using documented curl command [#​2985]
  • Advisory ID blank in JSON output [#​2965]
Additional Changes

(Full Changelog)

v0.100.0

Compare Source

Added Features

(Full Changelog)

v0.99.1

Compare Source

Bug Fixes

(Full Changelog)

v0.99.0

Compare Source

Added Features
Bug Fixes
Breaking Changes

(Full Changelog)

v0.98.0

Compare Source

Added Features

(Full Changelog)

v0.97.2

Compare Source

Grype v0.97.2

Added Features
Bug Fixes

(Full Changelog)

v0.97.1

Compare Source

Bug Fixes

(Full Changelog)

v0.97.0

Compare Source

Added Features
Bug Fixes
Additional Changes

(Full Changelog)

v0.96.1

Compare Source

Syft Improvments
  • Update to latest version of syft v1.29.0
Performance Improvements

(Full Changelog)

v0.96.0

Compare Source

Added Features
Bug Fixes
Additional Changes

(Full Changelog)

v0.95.0

Compare Source

Added Features
Bug Fixes
Additional Changes

(Full Changelog)

v0.94.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v0.93.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v0.92.2

Compare Source

Bug Fixes
Additional Changes

(Full Changelog)

v0.92.1

Compare Source

(Full Changelog)

v0.92.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v0.91.2

Compare Source

Bug Fixes

(Full Changelog)

v0.91.1

Compare Source

Bug Fixes
Additional Changes

(Full Changelog)

v0.91.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v0.90.0

Compare Source

Added Features

(Full Changelog)

v0.89.1

Compare Source

Bug Fixes

(Full Changelog)

v0.89.0

Compare Source

[!IMPORTANT]
As of Grype v0.88.0, the listing file which hosts the URLs of databases to download has migrated from https://toolbox-data.anchore.io/grype/databases/listing.json to https://grype.anchore.io/databases/v6/latest.json.

Added Features
Bug Fixes

(Full Changelog)

v0.88.0

Compare Source

[!IMPORTANT]
With #​2126 the listing file which hosts the URLs of databases to download has migrated from https://toolbox-data.anchore.io/grype/databases/listing.json to https://grype.anchore.io/databases/v6/latest.json.

Added Features
Bug Fixes
Breaking Changes
Additional Changes

(Full Changelog)

v0.87.0

Compare Source

Added Features
Bug Fixes

(Full Changelog)

v0.86.1

Compare Source

Security Fixes
Bug Fixes
Additional Changes

(Full Changelog)

v0.86.0

Compare Source

Added Features
Bug Fixes
Breaking Changes
Additional Changes

(Full Changelog)

v0.85.0

Compare Source

Added Features
Bug Fixes
Additional Changes

(Full Changelog)

v0.84.0

Compare Source

Added Features
Bug Fixes
Additional Changes

(Full Changelog)

v0.83.0

Compare Source

Added Features

(Full Changelog)

v0.82.2

Compare Source

Bug Fixes
Additional Changes

(Full Changelog)

v0.82.1

Compare Source

Bug Fixes

@renovate renovate bot force-pushed the renovate/dependencies branch 3 times, most recently from 5ba679a to 8b58a61 Compare December 31, 2024 20:44
@renovate renovate bot force-pushed the renovate/dependencies branch 4 times, most recently from 490052d to 23754db Compare January 9, 2025 12:01
@renovate renovate bot force-pushed the renovate/dependencies branch 6 times, most recently from c9a1639 to 5aabad4 Compare January 17, 2025 07:19
@renovate renovate bot force-pushed the renovate/dependencies branch 5 times, most recently from 6e3a52e to 3c9057e Compare January 25, 2025 12:15
@renovate renovate bot force-pushed the renovate/dependencies branch 5 times, most recently from 37862c0 to ade8620 Compare February 5, 2025 00:08
@renovate renovate bot force-pushed the renovate/dependencies branch 7 times, most recently from 88a8ea0 to 849332e Compare February 12, 2025 12:33
@renovate renovate bot force-pushed the renovate/dependencies branch 4 times, most recently from ccc9c39 to 961336f Compare November 25, 2025 04:05
@renovate renovate bot force-pushed the renovate/dependencies branch 12 times, most recently from 1d801da to e577dec Compare December 1, 2025 09:45
@renovate renovate bot force-pushed the renovate/dependencies branch from e577dec to 60f946a Compare December 18, 2025 13:45
@renovate
Copy link
Author

renovate bot commented Dec 18, 2025

ℹ️ Artifact update notice

File name: internal/grype-scan/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 56 additional dependencies were updated

Details:

Package Change
github.com/CycloneDX/cyclonedx-go v0.9.2 -> v0.9.3
github.com/ProtonMail/go-crypto v1.2.0 -> v1.3.0
github.com/STARRY-S/zip v0.2.1 -> v0.2.3
github.com/anchore/go-collections v0.0.0-20240216171411-9321230ce537 -> v0.0.0-20251016125210-a3c352120e8c
github.com/anchore/stereoscope v0.1.6 -> v0.1.13
github.com/andybalholm/brotli v1.1.2-0.20250424173009-453214e765f3 -> v1.2.0
github.com/bmatcuk/doublestar/v4 v4.8.1 -> v4.9.1
github.com/bodgit/sevenzip v1.6.0 -> v1.6.1
github.com/charmbracelet/bubbletea v1.3.6 -> v1.3.10
github.com/charmbracelet/x/ansi v0.9.3 -> v0.10.1
github.com/containerd/containerd v1.7.27 -> v1.7.29
github.com/cyphar/filepath-securejoin v0.4.1 -> v0.6.0
github.com/diskfs/go-diskfs v1.6.1-0.20250601133945-2af1c7ece24c -> v1.7.0
github.com/docker/cli v28.3.0+incompatible -> v28.5.2+incompatible
github.com/docker/docker v28.3.2+incompatible -> v28.5.2+incompatible
github.com/docker/docker-credential-helpers v0.9.3 -> v0.9.4
github.com/docker/go-connections v0.5.0 -> v0.6.0
github.com/fatih/color v1.17.0 -> v1.18.0
github.com/gabriel-vasile/mimetype v1.4.9 -> v1.4.11
github.com/github/go-spdx/v2 v2.3.3 -> v2.3.4
github.com/go-git/go-git/v5 v5.16.2 -> v5.16.3
github.com/go-viper/mapstructure/v2 v2.3.0 -> v2.4.0
github.com/gohugoio/hashstructure v0.5.0 -> v0.6.0
github.com/gookit/color v1.5.4 -> v1.6.0
github.com/hashicorp/go-getter v1.7.8 -> v1.8.3
github.com/hashicorp/hcl/v2 v2.23.0 -> v2.24.0
github.com/jedib0t/go-pretty/v6 v6.6.7 -> v6.7.2
github.com/mattn/go-runewidth v0.0.16 -> v0.0.19
github.com/mholt/archives v0.1.3 -> v0.1.5
github.com/minio/minlz v1.0.0 -> v1.0.1
github.com/nwaples/rardecode/v2 v2.1.0 -> v2.2.0
github.com/olekukonko/errors v0.0.0-20250405072817-4e6d85265da6 -> v1.1.0
github.com/olekukonko/ll v0.0.8 -> v0.1.2
github.com/olekukonko/tablewriter v1.0.8 -> v1.1.1
github.com/opencontainers/selinux v1.11.0 -> v1.13.0
github.com/sorairolake/lzip-go v0.3.5 -> v0.3.8
github.com/spf13/afero v1.14.0 -> v1.15.0
github.com/spf13/cobra v1.9.1 -> v1.10.1
github.com/spf13/pflag v1.0.6 -> v1.0.9
github.com/sylabs/sif/v2 v2.21.1 -> v2.22.0
github.com/ulikunitz/xz v0.5.12 -> v0.5.15
github.com/vbatts/go-mtree v0.5.4 -> v0.6.0
github.com/zclconf/go-cty v1.14.0 -> v1.16.3
golang.org/x/crypto v0.40.0 -> v0.44.0
golang.org/x/exp v0.0.0-20250408133849-7e4ce0ab07d0 -> v0.0.0-20250620022241-b7579e27df2b
golang.org/x/mod v0.26.0 -> v0.30.0
golang.org/x/net v0.42.0 -> v0.47.0
golang.org/x/sync v0.16.0 -> v0.18.0
golang.org/x/sys v0.34.0 -> v0.38.0
golang.org/x/term v0.33.0 -> v0.37.0
golang.org/x/text v0.27.0 -> v0.31.0
golang.org/x/time v0.12.0 -> v0.14.0
golang.org/x/tools v0.35.0 -> v0.39.0
google.golang.org/protobuf v1.36.4 -> v1.36.6
modernc.org/libc v1.65.10 -> v1.66.10
modernc.org/sqlite v1.38.0 -> v1.40.0

@renovate renovate bot force-pushed the renovate/dependencies branch 7 times, most recently from bfb5a79 to 9001c5a Compare December 25, 2025 12:37
@renovate renovate bot force-pushed the renovate/dependencies branch 3 times, most recently from 5b4ea90 to 8157af3 Compare January 4, 2026 04:13
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate bot force-pushed the renovate/dependencies branch from 8157af3 to 4b931e2 Compare January 7, 2026 07:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants