Skip to content

build(deps): bump the chainguard group across 1 directory with 4 updates#2008

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/chainguard-b9f29e2e98
Open

build(deps): bump the chainguard group across 1 directory with 4 updates#2008
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/chainguard-b9f29e2e98

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 26, 2026

Copy link
Copy Markdown
Contributor

Bumps the chainguard group with 3 updates in the / directory: chainguard.dev/apko, chainguard.dev/melange and github.com/chainguard-dev/clog.

Updates chainguard.dev/apko from 1.2.15 to 1.2.19

Release notes

Sourced from chainguard.dev/apko's releases.

Release v1.2.19

Changelog

  • e5786e98da1197260cc5e50720790f219275d94a Lower SBOM duplicate-package log from info to debug (#2293)
  • ed31a4b905bccd8c6c4d6aa30059e4fdaa0be6a1 build(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#2291)
  • 3c28f352b04ceca6f64a351c1b29d49ca7626a80 build(deps): bump chainguard-dev/actions from 1.6.22 to 1.6.24 (#2292)
  • d6207d87bc02b5ba9684d1bef6f4d4b0bce6baac build(deps): bump chainguard.dev/sdk from 0.1.57 to 0.1.74 (#2290)
  • fa27c7c1345e2d5ba79f095c1332eee19f8456f5 build(deps): bump go.step.sm/crypto from 0.82.0 to 0.83.0 (#2280)
  • c6336e444560d92e2ac8e49d04f812b71bb12009 build(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 (#2277)
  • bea498510167f23a17a8fd9646f94a231c566de5 build(deps): bump google.golang.org/api from 0.283.0 to 0.285.0 (#2287)
  • 5558f35b5b5fd27b50fe000f64395d8c6616216f paths: honor recursive for type: permissions, make uid/gid nullable (#2281)

Release v1.2.18

Changelog

  • ebd9255d91996b81a9b88723efbc9d563cfd863c build(deps): bump k8s.io/apimachinery from 0.36.1 to 0.36.2 (#2279)

Release v1.2.17

Changelog

  • 8a34ba83954913da4b79bd8a40ff124782f8f2cb Match apk-tools' provider comparison ordering in the solver (#2271)
  • 6b57924d877dc28152db9f2da9ad3d0cb99ae7eb build(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#2264)
  • 5f564a223a51b616929ed196703913876c15a131 build(deps): bump chainguard-dev/actions from 1.6.19 to 1.6.22 (#2272)
  • a12506c066e3bac80f79412cd1aa3b12a6880ad6 build(deps): bump chainguard.dev/sdk from 0.1.55 to 0.1.57 (#2275)
  • b16043b42041f042965719cf4778895ed7cb5da5 build(deps): bump github/codeql-action from 4.36.0 to 4.36.2 (#2267)
  • 879c4e55e6e7cd73945e671c77ff0d322cd1f6bf build(deps): bump go.opentelemetry.io/otel from 1.43.0 to 1.44.0 (#2258)
  • 301fd0d625c79684d29b2de779b7fd882e8fd822 build(deps): bump go.opentelemetry.io/otel/trace from 1.43.0 to 1.44.0 (#2256)
  • cafdeae691a2964120fdf86389e3a794e38ccdb3 build(deps): bump go.step.sm/crypto from 0.81.0 to 0.82.0 (#2270)
  • a3baa98fd9e4dcee50e3ba777a63bcdd134c24ad build(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 (#2265)
  • 7fd8b427838dbe812616e798ce884ed45c40c0fd build(deps): bump golang.org/x/sys from 0.45.0 to 0.46.0 (#2266)
  • 620f3009eac5282e006b8b319be3c6f13510a02f build(deps): bump google.golang.org/api from 0.280.0 to 0.283.0 (#2262)
  • bdddef26c13348e24c8f2a274662f3bcd4def4e8 build(deps): bump gopkg.in/ini.v1 from 1.67.2 to 1.67.3 (#2273)
  • 1fe85deeaca6ba534aec2f88a0f68e644725216e expandapk: materialize uncompressed .dat.tar atomically (#2269)
  • ef578c30be29d5c1074cf6934e5dac58a84f6cc4 fix(auth): let chainctl write to terminal for interactive login (#2276)
  • be89e64e9c769e8d9d5a2446e9bc65db2d2b194b paths: preserve setuid/setgid/sticky bits in permissions (#2274)

Release v1.2.16

Changelog

  • f39c3fa47ca6af5ae27c1e466c5a841b9b80f8d9 build(deps): bump docker/setup-qemu-action from 4.0.0 to 4.1.0 (#2254)
  • 8bf905593d457345beafe51490dd28a619d0690a build(deps): bump github/codeql-action from 4.35.5 to 4.36.0 (#2246)
  • 003b4011dd3a7398b1d7b9dd51cea9a61f2a4915 build(deps): bump imjasonh/setup-crane from 0.5 to 0.6 (#2260)
Commits
  • 5558f35 paths: honor recursive for type: permissions, make uid/gid nullable (#2281)
  • e5786e9 Lower SBOM duplicate-package log from info to debug (#2293)
  • c6336e4 build(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 (#2277)
  • fa27c7c build(deps): bump go.step.sm/crypto from 0.82.0 to 0.83.0 (#2280)
  • bea4985 build(deps): bump google.golang.org/api from 0.283.0 to 0.285.0 (#2287)
  • ed31a4b build(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#2291)
  • d6207d8 build(deps): bump chainguard.dev/sdk from 0.1.57 to 0.1.74 (#2290)
  • 3c28f35 build(deps): bump chainguard-dev/actions from 1.6.22 to 1.6.24 (#2292)
  • ebd9255 build(deps): bump k8s.io/apimachinery from 0.36.1 to 0.36.2 (#2279)
  • 301fd0d build(deps): bump go.opentelemetry.io/otel/trace from 1.43.0 to 1.44.0 (#2256)
  • Additional commits viewable in compare view

Updates chainguard.dev/melange from 0.52.0 to 0.54.0

Release notes

Sourced from chainguard.dev/melange's releases.

Release v0.54.0

What's Changed

Full Changelog: chainguard-dev/melange@v0.53.3...v0.54.0

Release v0.53.3

What's Changed

Full Changelog: chainguard-dev/melange@v0.53.2...v0.53.3

Release v0.53.2

What's Changed

Full Changelog: chainguard-dev/melange@v0.53.1...v0.53.2

Release v0.53.1

What's Changed

Full Changelog: chainguard-dev/melange@v0.53.0...v0.53.1

Release v0.53.0

What's Changed

New Contributors

Full Changelog: chainguard-dev/melange@v0.52.1...v0.53.0

Release v0.52.1

What's Changed

... (truncated)

Commits
  • 7fb1d6a feat(git-checkout): log resolved clone URL after successful clone (#2572)
  • 24f25f7 build(deps): bump chainguard.dev/apko from 1.2.16 to 1.2.17 in the gomod grou...
  • d6b81b9 fix(qemu): pass SLIRP DNS address via kernel cmdline when QEMU_NET_CIDR is se...
  • ad5661f build(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 in the gomod grou...
  • ddad5a6 build(deps): bump the gomod group across 1 directory with 12 updates (#2567)
  • 496af91 fix(qemu): skip empty QEMU_NET_CIDR instead of erroring (#2568)
  • 65ed1ab feat(qemu): add QEMU_NET_CIDR to override SLIRP internal network (#2564)
  • 1b5764a ci: remove stale wolfi-presubmit package matrix entries (#2566)
  • 2486683 chore(source): allow GitHub verified signatures (#2565)
  • 20afeb1 fix(renovate): bump git-checkout regardless of tag if there is only one (#2562)
  • Additional commits viewable in compare view

Updates github.com/chainguard-dev/clog from 1.8.0 to 1.8.1

Release notes

Sourced from github.com/chainguard-dev/clog's releases.

v1.8.1

What's Changed

New Contributors

Full Changelog: chainguard-dev/clog@v1.8.0...v1.8.1

Commits
  • 01a0244 fix: convert WARN string for cloud batch (#76)
  • e522bdd fix(ci): add persist-credentials: false and zizmor pedantic config (#69)
  • a29ba66 Bump step-security/harden-runner from 2.18.0 to 2.19.0 (#67)
  • f2e76c2 Bump step-security/harden-runner from 2.15.1 to 2.18.0 (#65)
  • ca1e61d chore(workflows): add actionlint and zizmor action linters [SECINT-75] (#61)
  • 0d6447e Bump step-security/harden-runner from 2.13.3 to 2.15.1 (#60)
  • See full diff in compare view

Updates github.com/chainguard-dev/yam from 0.2.62 to 0.2.63

Commits
  • 1979b01 build(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#223)
  • 2cd6b4e build(deps): bump chainguard-dev/actions from 1.6.19 to 1.6.21 (#222)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the chainguard group with 3 updates in the / directory: [chainguard.dev/apko](https://github.com/chainguard-dev/apko), [chainguard.dev/melange](https://github.com/chainguard-dev/melange) and [github.com/chainguard-dev/clog](https://github.com/chainguard-dev/clog).


Updates `chainguard.dev/apko` from 1.2.15 to 1.2.19
- [Release notes](https://github.com/chainguard-dev/apko/releases)
- [Changelog](https://github.com/chainguard-dev/apko/blob/main/NEWS.md)
- [Commits](chainguard-dev/apko@v1.2.15...v1.2.19)

Updates `chainguard.dev/melange` from 0.52.0 to 0.54.0
- [Release notes](https://github.com/chainguard-dev/melange/releases)
- [Changelog](https://github.com/chainguard-dev/melange/blob/main/NEWS.md)
- [Commits](chainguard-dev/melange@v0.52.0...v0.54.0)

Updates `github.com/chainguard-dev/clog` from 1.8.0 to 1.8.1
- [Release notes](https://github.com/chainguard-dev/clog/releases)
- [Commits](chainguard-dev/clog@v1.8.0...v1.8.1)

Updates `github.com/chainguard-dev/yam` from 0.2.62 to 0.2.63
- [Commits](chainguard-dev/yam@v0.2.62...v0.2.63)

---
updated-dependencies:
- dependency-name: chainguard.dev/apko
  dependency-version: 1.2.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: chainguard
- dependency-name: chainguard.dev/melange
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: chainguard
- dependency-name: github.com/chainguard-dev/clog
  dependency-version: 1.8.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: chainguard
- dependency-name: github.com/chainguard-dev/yam
  dependency-version: 0.2.63
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: chainguard
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jun 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants