Skip to content

chore(deps): update all-ci-dependencies#267

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-ci-dependencies
Open

chore(deps): update all-ci-dependencies#267
renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-ci-dependencies

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Oct 23, 2025

This PR contains the following updates:

Package Type Update Change
actions/checkout action patch v5.0.0v5.0.1
actions/setup-go action minor v5.5.0v5.6.0
aquasecurity/trivy-action action minor 0.33.1v0.35.0
capsule minor 0.11.00.12.4
codecov/codecov-action action patch v5.5.1v5.5.4
securego/gosec action minor v2.22.10v2.25.0

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

actions/checkout (actions/checkout)

v5.0.1

Compare Source

What's Changed

Full Changelog: actions/checkout@v5...v5.0.1

actions/setup-go (actions/setup-go)

v5.6.0

Compare Source

What's Changed

Full Changelog: actions/setup-go@v5...v5.6.0

aquasecurity/trivy-action (aquasecurity/trivy-action)

v0.35.0: Release: v0.35.0

Compare Source

This release is a duplicate of 0.35.0 which was not compromised.

As part of our response to the recent supply chain attack, we have migrated all tags to use the v prefix (e.g., v0.35.0 instead of 0.35.0). Going forward, all new releases will use the v prefix convention.

We have intentionally kept the 0.35.0 tag intact to avoid breaking existing workflows that depend on it.

If you are currently using 0.35.0, your workflows are safe — no action is required.

v0.35.0

Compare Source

What's Changed

Full Changelog: aquasecurity/trivy-action@0.34.2...0.35.0

v0.34.0

Compare Source

projectcapsule/capsule (capsule)

v0.12.4

Compare Source

Changelog

🐛 Bug fixes
🛠 Dependency updates

Full Changelog: projectcapsule/capsule@v0.12.3...v0.12.4

Check out what's new in this release

Docker Images

  • ghcr.io/projectcapsule/capsule:0.12.4
  • ghcr.io/projectcapsule/capsule:latest

Helm Chart
View this release on Artifact Hub or use the OCI helm chart:

  • ghcr.io/projectcapsule/charts/capsule:0.12.4

Review the Major Changes section first before upgrading to a new version

[!IMPORTANT]
Kubernetes compatibility

Note that the Capsule project offers support only for the latest minor version of Kubernetes.
Backwards compatibility with older versions of Kubernetes and OpenShift is offered by vendors.

Kubernetes version Minimum required
v1.34 >= 1.34.0

Thanks to all the contributors! 🚀 🦄

v0.12.3

Compare Source

Changelog

🐛 Bug fixes

Full Changelog: projectcapsule/capsule@v0.12.2...v0.12.3

Check out what's new in this release

Docker Images

  • ghcr.io/projectcapsule/capsule:0.12.3
  • ghcr.io/projectcapsule/capsule:latest

Helm Chart
View this release on Artifact Hub or use the OCI helm chart:

  • ghcr.io/projectcapsule/charts/capsule:0.12.3

Review the Major Changes section first before upgrading to a new version

[!IMPORTANT]
Kubernetes compatibility

Note that the Capsule project offers support only for the latest minor version of Kubernetes.
Backwards compatibility with older versions of Kubernetes and OpenShift is offered by vendors.

Kubernetes version Minimum required
v1.34 >= 1.34.0

Thanks to all the contributors! 🚀 🦄

v0.12.2

Compare Source

Changelog

🐛 Bug fixes
🛠 Dependency updates

Full Changelog: projectcapsule/capsule@v0.12.1...v0.12.2

Check out what's new in this release

Docker Images

  • ghcr.io/projectcapsule/capsule:0.12.2
  • ghcr.io/projectcapsule/capsule:latest

Helm Chart
View this release on Artifact Hub or use the OCI helm chart:

  • ghcr.io/projectcapsule/charts/capsule:0.12.2

Review the Major Changes section first before upgrading to a new version

[!IMPORTANT]
Kubernetes compatibility

Note that the Capsule project offers support only for the latest minor version of Kubernetes.
Backwards compatibility with older versions of Kubernetes and OpenShift is offered by vendors.

Kubernetes version Minimum required
v1.34 >= 1.34.0

Thanks to all the contributors! 🚀 🦄

v0.12.1

Compare Source

Changelog

🐛 Bug fixes

Full Changelog: projectcapsule/capsule@v0.12.0...v0.12.1

Check out what's new in this release

Docker Images

  • ghcr.io/projectcapsule/capsule:0.12.1
  • ghcr.io/projectcapsule/capsule:latest

Helm Chart
View this release on Artifact Hub or use the OCI helm chart:

  • ghcr.io/projectcapsule/charts/capsule:0.12.1

Review the Major Changes section first before upgrading to a new version

[!IMPORTANT]
Kubernetes compatibility

Note that the Capsule project offers support only for the latest minor version of Kubernetes.
Backwards compatibility with older versions of Kubernetes and OpenShift is offered by vendors.

Kubernetes version Minimum required
v1.34 >= 1.34.0

Thanks to all the contributors! 🚀 🦄

v0.12.0

Compare Source

Changelog

✨ New Features
🐛 Bug fixes
🛠 Dependency updates

Full Changelog: projectcapsule/capsule@v0.11.1...v0.12.0

Check out what's new in this release

Docker Images

  • ghcr.io/projectcapsule/capsule:0.12.0
  • ghcr.io/projectcapsule/capsule:latest

Helm Chart
View this release on Artifact Hub or use the OCI helm chart:

  • ghcr.io/projectcapsule/charts/capsule:0.12.0

Review the Major Changes section first before upgrading to a new version

[!IMPORTANT]
Kubernetes compatibility

Note that the Capsule project offers support only for the latest minor version of Kubernetes.
Backwards compatibility with older versions of Kubernetes and OpenShift is offered by vendors.

Kubernetes version Minimum required
v1.34 >= 1.34.0

Thanks to all the contributors! 🚀 🦄

v0.11.2

Compare Source

v0.11.1

Compare Source

Changelog

✨ New Features
🐛 Bug fixes
🛠 Dependency updates

Full Changelog: projectcapsule/capsule@v0.11.0...v0.11.1

Docker Images

  • ghcr.io/projectcapsule/capsule:0.11.1
  • ghcr.io/projectcapsule/capsule:latest

Helm Chart
View this release on Artifact Hub or use the OCI helm chart:

  • ghcr.io/projectcapsule/charts/capsule:0.11.1

Review the Major Changes section first before upgrading to a new version

[!IMPORTANT]
Kubernetes compatibility

Note that the Capsule project offers support only for the latest minor version of Kubernetes.
Backwards compatibility with older versions of Kubernetes and OpenShift is offered by vendors.

Kubernetes version Minimum required
v1.34 >= 1.34.0

Thanks to all the contributors! 🚀 🦄

codecov/codecov-action (codecov/codecov-action)

v5.5.4

Compare Source

This is a mirror of v5.5.2. v6 will be released which requires node24

What's Changed

Full Changelog: codecov/codecov-action@v5.5.3...v5.5.4

v5.5.3

Compare Source

What's Changed

Full Changelog: codecov/codecov-action@v5.5.2...v5.5.3

v5.5.2

Compare Source

What's Changed

Full Changelog: https://github.com/codecov/codecov-action/compare/v5.5.1..v5.5.2

securego/gosec (securego/gosec)

v2.25.0

Compare Source

Changelog

v2.24.7

Compare Source

Changelog

  • bb17e42 Ignore nosec comments in action integration workflow to generate some warnings (#​1573)
  • e1502ad Add a workflow for action integration test (#​1571)
  • f8691bd fix(sarif): avoid invalid null relationships in SARIF output (#​1569)
  • ade1d0e chore: migrate gosec container image references to GHCR (#​1567)

v2.24.6

Compare Source

Changelog

  • 88835e8 Update gorelease to use the latest cosign bundle argument (#​1565)

v2.24.5

Compare Source

v2.24.4

Compare Source

v2.24.3

Compare Source

v2.24.2

Compare Source

v2.24.1

Compare Source

v2.24.0

Compare Source

Changelog

  • 271492b fix: G704 false positive on const URL (#​1551)
  • 1341aea fix(G705): eliminate false positive for non-HTTP io.Writer (#​1550)
  • f2262c8 G120: avoid false positive when MaxBytesReader is applied in middleware (#​1547)
  • 5b580c7 Fix G602 regression coverage for issue #​1545 and stabilize G117 TOML test dependency (#​1546)
  • eba2d15 taint: skip context.Context arguments during taint propagation to fix false positives (#​1543)
  • a6381c1 test: add missing rules to formatter report tests (#​1540)
  • fea9725 chore(deps): update all dependencies (#​1541)
  • f3e2fac Regenrate the TLS config rule (#​1539)
  • 200461f Improve documentation (#​1538)
  • 078a62a Expand analyzer-core test coverage for orchestration, go/analysis adapter logic, and taint integration (#​1537)
  • ffdc620 Add unit tests for CLI orchestration, TLS config generation, and SSA cache behavior (#​1536)
  • c13a486 Add G707 taint analyzer for SMTP command/header injection (#​1535)
  • f61ed31 Add G123 analyzer for tls.VerifyPeerCertificate resumption bypass risk (#​1534)
  • b568aa1 Add G122 SSA analyzer for filepath.Walk/WalkDir symlink TOCTOU race risks (#​1532)
  • 1735e5a fix(G602): avoid false positives for range-over-array indexing (#​1531)
  • caf93d0 Improve taint analyzer performance with shared SSA cache, parallel analyzer execution, and CI regression guard (#​1530)
  • bd11fbe fix: taint analysis false positives with G703,G705 (#​1522)
  • e34e8dd Extend the G117 rule to cover other types of serialization such as yaml/xml/toml (#​1529)
  • b940702 Fix the G117 rule to take the JSON serialization into account (#​1528)
  • 4f84627 (docs) fix justification format (#​1524)
  • 36ba72b Add G121 analyzer for unsafe CORS bypass patterns in CrossOriginProtection (#​1521)
  • 238f982 Add G120 SSA analyzer for unbounded form parsing in HTTP handlers (#​1520)
  • 89cde27 Add G119 analyzer for unsafe redirect header propagation in CheckRedirect callbacks (#​1519)
  • 14fdd9c Fix G115 false positives and negatives (Issue #​1501) (#​1518)
  • cec54ec chore(deps): update all dependencies (#​1517)
  • 2b2077e Add G118 SSA analyzer for context propagation failures that can cause goroutine/resource leaks (#​1516)
  • a7666f3 Add G113: Detect HTTP Request Smuggling via conflicting headers (CVE-2025-22891, CWE-444) (#​1515)
  • 47f8b52 Add G408: SSH PublicKeyCallback Authentication Bypass Analyzer (#​1513)
  • 4f1f362 Add more unit tests to improve coverage (#​1512)
  • 9344582 Improve test coverage in various areas (#​1511)
  • 8d1b2c6 Imprve the test coverage (#​1510)
  • 993c1c4 Fix incorrect detection of fixed iv in G407 (#​1509)
  • 8668b74 Add support for go 1.26.x and removed support for go 1.24.x (#​1508)
  • 514225c Fix the sonar report to follow the latest schema (#​1507)
  • 000384e fix: broken taint analysis causing false positives (#​1506)
  • 616192c fix: panic on float constants in overflow analyzer (#​1505)
  • 79956a3 fix: panic when scanning multi-module repos from root (#​1504)
  • 5736e8b fix: G602 false positive for array element access (#​1499)
  • 1b7e1e9 Update gosec to version v2.23.0 in the Github action (#​1496)

v2.23.0

Compare Source

Changelog

v2.22.11

Compare Source

Changelog


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@codecov
Copy link
Copy Markdown

codecov Bot commented Oct 23, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
see 30 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate renovate Bot force-pushed the renovate/all-ci-dependencies branch from ca4489a to bc7d82d Compare October 26, 2025 18:05
@renovate renovate Bot changed the title chore(deps): update helm release capsule to v0.11.1 chore(deps): update helm release capsule to v0.11.2 Oct 26, 2025
@renovate renovate Bot force-pushed the renovate/all-ci-dependencies branch from bc7d82d to b33e0d4 Compare November 17, 2025 16:45
@renovate renovate Bot changed the title chore(deps): update helm release capsule to v0.11.2 chore(deps): update all-ci-dependencies Nov 17, 2025
@renovate renovate Bot force-pushed the renovate/all-ci-dependencies branch 6 times, most recently from 452df29 to 0257e92 Compare December 11, 2025 20:30
@renovate renovate Bot force-pushed the renovate/all-ci-dependencies branch 2 times, most recently from 28fd0ab to 6c561be Compare December 19, 2025 15:36
@renovate renovate Bot force-pushed the renovate/all-ci-dependencies branch 2 times, most recently from 17a0925 to d5be166 Compare February 12, 2026 23:33
@renovate renovate Bot force-pushed the renovate/all-ci-dependencies branch 2 times, most recently from d083627 to efdf2ea Compare February 27, 2026 13:58
@renovate renovate Bot force-pushed the renovate/all-ci-dependencies branch 5 times, most recently from 56af019 to 3570570 Compare March 7, 2026 03:02
@renovate renovate Bot force-pushed the renovate/all-ci-dependencies branch 5 times, most recently from 7ae2779 to f9eaad9 Compare March 23, 2026 13:30
@renovate renovate Bot force-pushed the renovate/all-ci-dependencies branch 3 times, most recently from f948e35 to c93e00c Compare April 2, 2026 14:11
@renovate renovate Bot force-pushed the renovate/all-ci-dependencies branch 7 times, most recently from 7c1c7e5 to ba0645b Compare April 19, 2026 13:56
@renovate renovate Bot force-pushed the renovate/all-ci-dependencies branch from ba0645b to 3b644bc Compare April 21, 2026 19:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants