chore(deps): update all non-major dependencies - #2995
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
7 times, most recently
from
August 28, 2026 17:49
11ec514 to
234d009
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 28, 2026 23:04
234d009 to
3a3bfb6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.13.0→2.13.2v2.13.0→v2.13.2v2.13.0→v2.13.22→2.18.03.7.3→3.7.4d6550df→868c8e8v3.13.2-0.20260817215856-d6550df7ed8d→v3.14.027.1.2→27.4.124.19.0→v24.20.011.22.0+sha512.1ff870c4c6133dfd88fb2afc46dd13d47f09c9794b438c6fdb47ca98caf3bc16381ee0be93a091b8e3824cf01f889f46d7d9e20910fb0be1ab0fb5baa80dd621→11.24.011.22.0→11.24.03.5.41→3.5.42Release Notes
golangci/golangci-lint (golangci-lint)
v2.13.2Compare Source
Released on 2026-08-28
iface: from 1.5.0 to 1.5.1staticcheck: from 0.8.0 to 0.8.1unparam: from3f964bcto2fa3d84canonicalheader: from v1.1.2 to a temporary forkv2.13.1Compare Source
Released on 2026-08-20
ginkgolinter: from 0.23.1 to 0.24.0gofmt: fromd62b90etoe84e050staticcheck: from 0.8.0-rc.1 to 0.8.0wsl_v5: from 5.8.0 to 5.9.0goreleaser/goreleaser (goreleaser)
v2.18.0Compare Source
Announcement
Read the official announcement: Announcing GoReleaser v2.18.
Changelog
New Features
601cd87: feat(ko): support templating for local_domain, base_image, and repositories (#6741) (@mrueg)de88f38: feat(winget): support publishing additional locale manifests (#6733) (@MohammedAnasuddinZaid)cefbc6f: feat: add iru custom apps publisher (#6709) (@wimwenigerkind)1d6e7c0: feat: allow PR creation to use a different auth token (#6717) (@emily-curry)4c41ac0: feat: preflight checks (#6704) (@caarlos0)060260a: feat: release summary (#6810) (@caarlos0)82a5aba: feat: update to Go 1.27 (#6802) (@caarlos0)Security updates
b1cafd4: sec(deps): bump go-openapi/spec and go-openapi/validade (#6766) (@caarlos0)Bug fixes
1970443: fix(aur): expand description templates before escaping quotes (#6791) (@VXNCXNX and @caarlos0)a27402d: fix(blob): honor s3_force_path_style without a custom endpoint (#6789) (@VXNCXNX and @caarlos0)db65b99: fix(brew): a formula without a repository stops the ones after it (#6783) (@caarlos0)2b5fb31: fix(build): node windows targets get no .exe extension (#6777) (@VXNCXNX and @vxncxnx)951fc57: fix(cask): a cask without a repository stops the ones after it (#6785) (@caarlos0)54a6c8e: fix(cask): emit Casks that pass brew style (#6752) (@r0h1tb)2d6b235: fix(changelog): a commit matching two include filters is listed twice (#6773) (@VXNCXNX and @caarlos0)c4cc86f: fix(chocolatey): error on multiple archives for the same platform (#6792) (@VXNCXNX)1a246da: fix(config): type retry durations as strings in schema (#6801) (@skatkov)8be344b: fix(docker): add gpg-agent to the image (#6763) (@caarlos0)5282589: fix(dockers/v2): annotation scopes (#6800) (@CraigAstillRVU and @caarlos0)5560bb9: fix(flatpak): a disabled flatpak stops the ones after it (#6781) (@VXNCXNX)b68113a: fix(git): tag templates strip apostrophes from the message (#6779) (@VXNCXNX and @vxncxnx)1bc6ec7: fix(healthcheck): register upx and makeself dependency checkers (#6793) (@VXNCXNX)9d7d49f: fix(krew): a manifest without a name stops the ones after it (#6787) (@caarlos0)4276c51: fix(krew): apply the documented goarm default (#6775) (@VXNCXNX and @vxncxnx)9700230: fix(mcp): mcp.disable is documented but never read (#6795) (@VXNCXNX)1d79a09: fix(milestone): a milestone with close disabled stops the ones after it (#6778) (@VXNCXNX and @vxncxnx)2a0393d: fix(nfpm): don't set deb arch variant for goamd64 v1 (#6765) (@caarlos0)912704c: fix(nfpm): overrides ignore package_name, epoch, release and prerelease (#6782) (@VXNCXNX)3cf25c0: fix(nfpm): record the conventional extension, not the format name (#6776) (@VXNCXNX and @vxncxnx)ad028a3: fix(nix): a skipped nix entry stops the ones after it (#6788) (@VXNCXNX)b787cd2: fix(notarize): cap macOS notarization timeout at 20m (#6758) (@caarlos0)81a5509: fix(sign): artifacts: none masks real signing failures (#6790) (@VXNCXNX)4eb6037: fix(snapcraft): a disabled snap stops the ones after it (#6784) (@caarlos0)d93d0f1: fix(snapcraft): assumes, hooks and plugs are dropped when apps is omitted (#6780) (@VXNCXNX and @vxncxnx)b3bbd53: fix(srpm): make documented rpm fields actually configurable (#6762) (@caarlos0)7304fdb: fix(tmpl): register the documented join template function (#6772) (@VXNCXNX)6f88b00: fix(upload): a misconfigured upload stops the others (#6786) (@caarlos0)67e4c45: fix(winget): a skipped winget entry stops the ones after it (#6797) (@VXNCXNX)92453c1: fix(winget): count arm64 in the duplicate-archive check (#6774) (@VXNCXNX and @caarlos0)9a43dd0: fix(winget): fall back to the default description in additional locales (#6771) (@VXNCXNX)6127e0f: fix: do not panic decoding a commit whose message contains a log marker (#6738) (@arpitjain099)02cfda7: fix: lint (@caarlos0)b990083: fix: surface archive Close errors when writing release archives (#6690) (@SebTardif and @caarlos0)Documentation updates
33a3f22: docs(dockers_v2): clarify that build and push are a single step (#6742) (@caarlos0)1eb0ee9: docs: download SBOMs (#6803) (@caarlos0)16debcb: docs: many fixes (@caarlos0)ff2822a: docs: update dockers_v2 (@caarlos0)686946e: docs: use correct script for debconf (#6759) (@Daniel15)9921479: docs: use formats plural syntax (#6756) (@FelicianoTech)Other work
2b80858: chore: auto-update generated files (#6731) (@goreleaserbot)7df2cd5: chore: auto-update generated files (#6732) (@goreleaserbot)dd08c1f: chore: auto-update generated files (#6740) (@goreleaserbot)ee0e3c1: chore: auto-update generated files (#6744) (@goreleaserbot)cab7c6e: chore: auto-update generated files (#6769) (@goreleaserbot)39552ca: chore: auto-update generated files (#6794) (@goreleaserbot)4a82792: chore: auto-update generated files (#6798) (@goreleaserbot)ae88a14: chore: auto-update generated files (#6806) (@goreleaserbot)52494d9: chore: auto-update generated files (#6809) (@goreleaserbot)Full Changelog: goreleaser/goreleaser@v2.17.1...v2.18.0
Helping out
This release is only possible thanks to all the support of some awesome people!
Want to be one of them?
You can sponsor, get a Pro License or contribute with code.
Where to go next?
v2.17.1Compare Source
Announcement
Read the official announcement: Announcing GoReleaser v2.17.
Changelog
Bug fixes
a734383: fix(builder/go): parse GORISCV64 and GOPPC64 for riscv64 and ppc64le targets (#6698) (@upuddu)dfc7f06: fix(builders/go): sort targets (@caarlos0)7630cd1: fix(deps): go1.26.5 (@caarlos0)9dbb266: fix(notary): poll notarization status every 10s, not 10ns (#6726) (@caarlos0)1ebf881: fix: anchor goarm64 validation regex to reject invalid values (#6727) (@semx)70f6921: fix: migrate from deprecated s3/manager to s3/transfermanager (#6706) (@joeyberkovitz)Documentation updates
eafb0ec: docs(users): update charm domain (#6699) (@andreynering)ae4debb: docs: add /.well-known/security.txt (RFC 9116) (#6710) (@kobihikri)d3764c8: docs: fix typo (@caarlos0)742ae5f: docs: move images to a bucket (#6691) (@caarlos0)55a466e: docs: publish to GitLab package registries with the http upload pipe (#6697) (@ajuijas)65240d8: docs: update users (@caarlos0)Other work
0eb5b0f: chore(ci): update dependabot config (@caarlos0)4bcb2a5: chore(ci): update deps (@caarlos0)5f3f435: chore: auto-update generated files (#6693) (@goreleaserbot)9b85924: chore: auto-update generated files (#6694) (@goreleaserbot)1aab79e: chore: auto-update generated files (#6700) (@goreleaserbot)11d0150: chore: auto-update generated files (#6705) (@goreleaserbot)5747ca7: chore: auto-update generated files (#6707) (@goreleaserbot)83f4c19: chore: auto-update generated files (#6730) (@goreleaserbot)f3a0e63: chore: svu config (@caarlos0)Full Changelog: goreleaser/goreleaser@v2.17.0...v2.17.1
Helping out
This release is only possible thanks to all the support of some awesome people!
Want to be one of them?
You can sponsor, get a Pro License or contribute with code.
Where to go next?
v2.17.0Compare Source
Announcement
Read the official announcement: Announcing GoReleaser v2.17.
Changelog
New Features
31d4279: feat(brew,cask,krew,nix,scoop,winget): default pull request branch name (#6685) (@caarlos0)e5f075b: feat(dockers/v2): retry build (@caarlos0)cd5f16b: feat(nfpm): support msix packages (#6647) (@umaidshahid and @caarlos0)43be34a: feat(scm): allow a custom token on the release repository (#6689) (@caarlos0)5ed70f2: feat(winget): allow configuring the manifest locale (#6680) (@caarlos0)6f7175a: feat: Allow GOARM softfloat and hardfloat (#6198) (@MDr164 and @caarlos0)Security updates
b985ca8: sec(deps): bump go-pkcs12 to v0.7.2 (GO-2026-5052) (#6683) (@caarlos0)7c73b82: sec(deps): update golang.org/x/net (@caarlos0)Bug fixes
7d602ff: fix(builders): reject empty target string (#6679) (@sueun-dev)355d706: fix(client): skip merge-upstream when target repo is not a fork (#6646) (@jamessawle and @caarlos0)944bbb2: fix(deps): drop dep on docker/docker (#6682) (@caarlos0)a85ce26: fix(mcp): clean subfolder path (#6649) (@caarlos0)99a7173: fix(nfpm): produce valid arch for Termux packages (#6668) (@bltavares and @caarlos0)7200ec7: fix(winget): default head branch to a versioned template (#6684) (@Sanjays2402)6645820: fix: return error when go.mod is unreadable in CheckGoModPipe (#6644) (@SebTardif)Documentation updates
da7ce30: docs(casks): fix private-repo example broken by Homebrew 5.1.14 (#6639) (@caarlos0)09ebd03: docs(nfpm): note tilde ConventionalFileName (@caarlos0)ab7481e: docs: doc authoring skill (@caarlos0)b945ca3: docs: fix (@caarlos0)7e87fd3: docs: fix "lets" -> "let's" in quick-start guide (#6661) (@s3onghyun)698dae5: docs: fix typo in notarize.md (#6655) (@albertchae)f09c887: docs: good bye discord (@caarlos0)2642319: docs: improve home (@caarlos0)6b7710e: docs: updates (@caarlos0)Other work
2e6f200: chore: auto-update generated files (#6662) (@goreleaserbot)4bd4e38: chore: auto-update generated files (#6671) (@goreleaserbot)dcf5a6b: chore: auto-update generated files (#6675) (@goreleaserbot)baf110d: chore: auto-update generated files (#6688) (@goreleaserbot)3fa8a94: chore: godoc (@caarlos0)Full Changelog: goreleaser/goreleaser@v2.16.0...v2.17.0
Helping out
This release is only possible thanks to all the support of some awesome people!
Want to be one of them?
You can sponsor, get a Pro License or contribute with code.
Where to go next?
vektra/mockery (mockery)
v3.7.4Compare Source
What's Changed
New Contributors
Full Changelog: vektra/mockery@v3.7.3...v3.7.4
mvdan/sh (mvdan.cc/sh/v3)
v3.14.0Compare Source
This release drops support for Go 1.25 and includes many enhancements, particularly in the interpreter, which implements more shell features and fixes many divergences from Bash.
--detectto find shell files by executable bit or shebang - #944Preorder, an iterator over all nodes, complementingWalkencoding.TextUnmarshalerimplementations for each operator type${ foo;}and${|foo;}inside double quotes - #1368{varname}redirects, likeexec {fds[3]}>&-- #719${args[cmd,#]}- #1285#as the start of a comment inside[[ ]]tests - #1326thenordowith a semicolon when heredocs are pending - #1047!in arithmetic expressions, avoiding history expansion - #987SplitBracesreject malformed sequences and skip backslash escapes - #1330${=name},${~name}, and${^name}prefixes - #1238;|case terminator and leading parentheses for globs - #1293, #1279[globs in arrays - #1278, #1322">>", rather than integers - #1321BashOptsto set Bash options likeshopt- #962AccessHandlerto control file access checks, used by-randcd- #1318HandlerContext.LastExitStatus, and provide aHandlerContextto stat handlershelpandtimesbuiltins, as well as$-- #1398;∧;&case terminators - #1391-Ntest operator, and make-ntand-otfollow POSIX - #1340a=([5]=x)- #1373execfails withENOEXEC- #1065js/wasm, where subprocesses and pipes are unavailableexecwith no argumentsRunBracesSeqwith a config and error reporting, deprecatingBracesVariable.Indexesto describe sparse indexed arrays&&and||operators - #1371"${a[@]%o}"- #1081${!arr[@]}consistent with the quoted form - #672[as a literal character, like Bash - #1372[![:space:]]dashshebangs as POSIX shell for-ln=auto- #1307Consider becoming a sponsor if you benefit from the work that went into this release!
Binaries built on
go version go1.27.0 linux/amd64with:netlify/cli (netlify-cli)
v27.4.1Compare Source
Bug Fixes
v27.4.0Compare Source
Features
v27.3.1Compare Source
Bug Fixes
v27.3.0Compare Source
Features
Bug Fixes
nodejs/node (node)
v24.20.0: 2026-08-26, Version 24.20.0 'Krypton' (LTS), @aduh95Compare Source
Notable Changes
b12bcc9ae1] - (SEMVER-MINOR) async_hooks: addusingscopes toAsyncLocalStorage(Stephen Belanger) #61674e2eb88b36b] - (SEMVER-MINOR) buffer: addendparameter (Robert Nagy) #623901fefdda18e] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #647464a158cf1ab] - doc: add MikeMcC399 as collaborator (Mike McCready) #64656d4cafce076] - (SEMVER-MINOR) lib,permission: addpermission.drop(Rafael Gonzaga) #62672b3cfb55267] - (SEMVER-MINOR) loader: implement package maps (Maël Nison) #62239cd1eb3e60b] - (SEMVER-MINOR) src,permission: add--permission-audit(RafaelGSS) #6186928dc85d8d2] - (SEMVER-MINOR) stream: addnode:stream/iterimplementation (James M Snell) #62066d31c168740] - (SEMVER-MINOR) test_runner: addcontext.log()and test:log event (Moshe Atlow) #64389add1edbc42] - (SEMVER-MINOR) test_runner: reportentryFileinTestStreamevents (Moshe Atlow) #64309d937c8c6cd] - (SEMVER-MINOR) wasm: enable JSPI (Guy Bedford) #59941Commits
1822c0f335] - assert,util: fix TypeError on Maps with null keys (Paul Bouchon) #64441b12bcc9ae1] - (SEMVER-MINOR) async_hooks: add using scopes to AsyncLocalStorage (Stephen Belanger) #61674984260bf44] - async_hooks: use validateBoolean for trackPromises (Soul Lee) #64731ba2612cca2] - benchmark: fix calibrate-n option handling (Luan Muniz) #64146236dc4d2d7] - benchmark: add bytes variant to webstreams async-iterator (Matteo Collina) #64291b022a1419c] - benchmark: respect stream/iter broadcast backpressure (Trivikram Kamat) #63314a290f51f15] - (SEMVER-MINOR) benchmark: add benchmarks for experimental stream/iter (James M Snell) #62066465f2bfb74] - buffer: use Clamp conversion in Blob slice (Donghoon Kang) #6473974a22cd0c5] - buffer: validate copyArrayBuffer offsets against buffer length (Ilia Alshanetsky) #6390421e24208dc] - buffer: normalize lone "\r" in Blob native line endings (Daijiro Wachi) #64115ddacb3ff10] - buffer: fix Blob.stream() leaking source buffer (semimikoh) #6357749198d2313] - buffer: fix end parameter bugs in indexOf/lastIndexOf (Robert Nagy) #62711e2eb88b36b] - (SEMVER-MINOR) buffer: add end parameter (Robert Nagy) #62390e2e5c4fe88] - build: update binary-upload to use correct tarball name (Stewart X Addison) #65282b78a212553] - build: pin envinfo versions in github actions (Joyee Cheung) #64117094fb840aa] - build: add QUIC CI job for PRs matching QUIC related paths (Tim Perry) [#&Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.