Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
chore(deps): lock file maintenance vulnfeeds (#2816)
This PR contains the following updates: | Package | Type | Update | Change | Age | Adoption | Passing | Confidence | |---|---|---|---|---|---|---|---| | | | lockFileMaintenance | All locks refreshed | | | | | | [cloud.google.com/go/secretmanager](https://redirect.github.com/googleapis/google-cloud-go) | require | patch | `v1.14.1` -> `v1.14.2` | [![age](https://developer.mend.io/api/mc/badges/age/go/cloud.google.com%2fgo%2fsecretmanager/v1.14.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/cloud.google.com%2fgo%2fsecretmanager/v1.14.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/cloud.google.com%2fgo%2fsecretmanager/v1.14.1/v1.14.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/cloud.google.com%2fgo%2fsecretmanager/v1.14.1/v1.14.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | | [github.com/atombender/go-jsonschema](https://redirect.github.com/atombender/go-jsonschema) | require | minor | `v0.16.0` -> `v0.17.0` | [![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fatombender%2fgo-jsonschema/v0.17.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/github.com%2fatombender%2fgo-jsonschema/v0.17.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/github.com%2fatombender%2fgo-jsonschema/v0.16.0/v0.17.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fatombender%2fgo-jsonschema/v0.16.0/v0.17.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | | [github.com/google/osv-scanner](https://redirect.github.com/google/osv-scanner) | require | patch | `v1.9.0` -> `v1.9.1` | [![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fgoogle%2fosv-scanner/v1.9.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/github.com%2fgoogle%2fosv-scanner/v1.9.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/github.com%2fgoogle%2fosv-scanner/v1.9.0/v1.9.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fgoogle%2fosv-scanner/v1.9.0/v1.9.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | 🔧 This Pull Request updates lock files to use the latest dependency versions. --- ### Release Notes <details> <summary>atombender/go-jsonschema (github.com/atombender/go-jsonschema)</summary> ### [`v0.17.0`](https://redirect.github.com/omissis/go-jsonschema/releases/tag/v0.17.0) [Compare Source](https://redirect.github.com/atombender/go-jsonschema/compare/v0.16.0...v0.17.0) #### Highlights - Implement pattern validation for strings - Implement numeric validation - Introduce unmarshalling for additional properties - Update go to 1.22.8 in ci and dev - Allow CustomNameTypes to specify nillability #### What's Changed - chore(deps): update actions/checkout digest to [`1d96c77`](https://redirect.github.com/atombender/go-jsonschema/commit/1d96c77) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/219](https://redirect.github.com/omissis/go-jsonschema/pull/219) - chore(deps): update actions/checkout digest to [`0ad4b8f`](https://redirect.github.com/atombender/go-jsonschema/commit/0ad4b8f) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/221](https://redirect.github.com/omissis/go-jsonschema/pull/221) - Allow `CustomNameType`s to specify nillability by [@​andrew-farries](https://redirect.github.com/andrew-farries) in [https://github.com/omissis/go-jsonschema/pull/220](https://redirect.github.com/omissis/go-jsonschema/pull/220) - chore(deps): update dependency golangci-lint to v1.58.0 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/222](https://redirect.github.com/omissis/go-jsonschema/pull/222) - fix(deps): update module golang.org/x/exp to v0.0.0-20240506185415-9bf2ced13842 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/223](https://redirect.github.com/omissis/go-jsonschema/pull/223) - chore(deps): update golang docker tag to v1.22.3 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/224](https://redirect.github.com/omissis/go-jsonschema/pull/224) - chore(deps): update actions/checkout digest to [`44c2b7a`](https://redirect.github.com/atombender/go-jsonschema/commit/44c2b7a) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/225](https://redirect.github.com/omissis/go-jsonschema/pull/225) - chore(deps): update dependency golangci-lint to v1.58.1 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/226](https://redirect.github.com/omissis/go-jsonschema/pull/226) - chore(deps): update actions/checkout digest to [`0ad4b8f`](https://redirect.github.com/atombender/go-jsonschema/commit/0ad4b8f) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/227](https://redirect.github.com/omissis/go-jsonschema/pull/227) - chore(deps): update dependency golangci-lint to v1.58.2 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/228](https://redirect.github.com/omissis/go-jsonschema/pull/228) - chore(deps): update actions/checkout digest to [`a5ac7e5`](https://redirect.github.com/atombender/go-jsonschema/commit/a5ac7e5) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/229](https://redirect.github.com/omissis/go-jsonschema/pull/229) - fix(deps): update golang.org/x/exp digest to [`4c93da0`](https://redirect.github.com/atombender/go-jsonschema/commit/4c93da0) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/230](https://redirect.github.com/omissis/go-jsonschema/pull/230) - chore(deps): update dependency golangci-lint to v1.59.0 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/232](https://redirect.github.com/omissis/go-jsonschema/pull/232) - fix(deps): update golang.org/x/exp digest to [`23cca88`](https://redirect.github.com/atombender/go-jsonschema/commit/23cca88) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/233](https://redirect.github.com/omissis/go-jsonschema/pull/233) - fix(deps): update golang.org/x/exp digest to [`404ba88`](https://redirect.github.com/atombender/go-jsonschema/commit/404ba88) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/234](https://redirect.github.com/omissis/go-jsonschema/pull/234) - fix(deps): update golang.org/x/exp digest to [`fd00a4e`](https://redirect.github.com/atombender/go-jsonschema/commit/fd00a4e) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/235](https://redirect.github.com/omissis/go-jsonschema/pull/235) - fix(deps): update golang.org/x/exp digest to [`fc45aab`](https://redirect.github.com/atombender/go-jsonschema/commit/fc45aab) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/236](https://redirect.github.com/omissis/go-jsonschema/pull/236) - chore(deps): update dependency golang to v1.22.4 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/237](https://redirect.github.com/omissis/go-jsonschema/pull/237) - docs: correct `go` version requirement by [@​jamietanna](https://redirect.github.com/jamietanna) in [https://github.com/omissis/go-jsonschema/pull/240](https://redirect.github.com/omissis/go-jsonschema/pull/240) - chore(deps): update goreleaser/goreleaser-action action to v6 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/238](https://redirect.github.com/omissis/go-jsonschema/pull/238) - chore(deps): update dependency golangci-lint to v1.59.1 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/245](https://redirect.github.com/omissis/go-jsonschema/pull/245) - chore(deps): update actions/checkout digest to [`692973e`](https://redirect.github.com/atombender/go-jsonschema/commit/692973e) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/247](https://redirect.github.com/omissis/go-jsonschema/pull/247) - fix(deps): update golang.org/x/exp digest to [`7f521ea`](https://redirect.github.com/atombender/go-jsonschema/commit/7f521ea) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/248](https://redirect.github.com/omissis/go-jsonschema/pull/248) - fix(deps): update module github.com/spf13/cobra to v1.8.1 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/249](https://redirect.github.com/omissis/go-jsonschema/pull/249) - fix(deps): update golang.org/x/exp digest to [`46b0784`](https://redirect.github.com/atombender/go-jsonschema/commit/46b0784) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/252](https://redirect.github.com/omissis/go-jsonschema/pull/252) - chore(deps): update dependency golang to v1.22.5 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/253](https://redirect.github.com/omissis/go-jsonschema/pull/253) - fix(deps): update module github.com/goccy/go-yaml to v1.12.0 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/254](https://redirect.github.com/omissis/go-jsonschema/pull/254) - fix(deps): update golang.org/x/exp digest to [`e3f2596`](https://redirect.github.com/atombender/go-jsonschema/commit/e3f2596) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/255](https://redirect.github.com/omissis/go-jsonschema/pull/255) - fix(deps): update golang.org/x/exp digest to [`8a7402a`](https://redirect.github.com/atombender/go-jsonschema/commit/8a7402a) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/256](https://redirect.github.com/omissis/go-jsonschema/pull/256) - chore(deps): update dependency golang to v1.22.6 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/258](https://redirect.github.com/omissis/go-jsonschema/pull/258) - fix(deps): update golang.org/x/exp digest to [`0cdaa3a`](https://redirect.github.com/atombender/go-jsonschema/commit/0cdaa3a) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/260](https://redirect.github.com/omissis/go-jsonschema/pull/260) - chore(deps): update dependency golang to v1.23.0 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/261](https://redirect.github.com/omissis/go-jsonschema/pull/261) - chore(deps): update dependency golangci-lint to v1.60.0 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/262](https://redirect.github.com/omissis/go-jsonschema/pull/262) - chore(deps): update dependency golangci-lint to v1.60.1 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/263](https://redirect.github.com/omissis/go-jsonschema/pull/263) - chore(deps): update dependency shfmt to v3.9.0 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/265](https://redirect.github.com/omissis/go-jsonschema/pull/265) - chore(deps): update dependency golangci-lint to v1.60.2 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/266](https://redirect.github.com/omissis/go-jsonschema/pull/266) - fix(deps): update golang.org/x/exp digest to [`778ce7b`](https://redirect.github.com/atombender/go-jsonschema/commit/778ce7b) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/267](https://redirect.github.com/omissis/go-jsonschema/pull/267) - fix(deps): update golang.org/x/exp digest to [`9b4947d`](https://redirect.github.com/atombender/go-jsonschema/commit/9b4947d) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/268](https://redirect.github.com/omissis/go-jsonschema/pull/268) - chore(deps): update dependency golangci-lint to v1.60.3 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/269](https://redirect.github.com/omissis/go-jsonschema/pull/269) - fix(deps): update golang.org/x/exp digest to [`e7e105d`](https://redirect.github.com/atombender/go-jsonschema/commit/e7e105d) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/270](https://redirect.github.com/omissis/go-jsonschema/pull/270) - chore(deps): update dependency golang to v1.23.1 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/271](https://redirect.github.com/omissis/go-jsonschema/pull/271) - chore(deps): update dependency golangci-lint to v1.61.0 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/273](https://redirect.github.com/omissis/go-jsonschema/pull/273) - chore: update deps [`2024091`](https://redirect.github.com/atombender/go-jsonschema/commit/20240914) by [@​omissis](https://redirect.github.com/omissis) in [https://github.com/omissis/go-jsonschema/pull/274](https://redirect.github.com/omissis/go-jsonschema/pull/274) - Add pattern, support reference constraints on primitives, and add number/integer constraints by [@​nolag](https://redirect.github.com/nolag) in [https://github.com/omissis/go-jsonschema/pull/264](https://redirect.github.com/omissis/go-jsonschema/pull/264) - fix(deps): update module github.com/stretchr/testify to v1 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/277](https://redirect.github.com/omissis/go-jsonschema/pull/277) - chore(deps): update dependency go to v1.23.2 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/286](https://redirect.github.com/omissis/go-jsonschema/pull/286) - chore(deps): update dependency golang to v1.23.2 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/287](https://redirect.github.com/omissis/go-jsonschema/pull/287) - fix(deps): update golang.org/x/exp digest to [`225e2ab`](https://redirect.github.com/atombender/go-jsonschema/commit/225e2ab) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/289](https://redirect.github.com/omissis/go-jsonschema/pull/289) - chore(deps): update actions/checkout digest to [`eef6144`](https://redirect.github.com/atombender/go-jsonschema/commit/eef6144) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/290](https://redirect.github.com/omissis/go-jsonschema/pull/290) - fix(deps): update golang.org/x/exp digest to [`f66d83c`](https://redirect.github.com/atombender/go-jsonschema/commit/f66d83c) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/292](https://redirect.github.com/omissis/go-jsonschema/pull/292) - chore(deps): update dependency shfmt to v3.10.0 by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/294](https://redirect.github.com/omissis/go-jsonschema/pull/294) - chore(deps): update actions/checkout digest to [`11bd719`](https://redirect.github.com/atombender/go-jsonschema/commit/11bd719) by [@​renovate](https://redirect.github.com/renovate) in [https://github.com/omissis/go-jsonschema/pull/298](https://redirect.github.com/omissis/go-jsonschema/pull/298) - Additional Properties do not get unmarshalled by [@​omissis](https://redirect.github.com/omissis) in [https://github.com/omissis/go-jsonschema/pull/278](https://redirect.github.com/omissis/go-jsonschema/pull/278) - update go to 1.22.8 by [@​omissis](https://redirect.github.com/omissis) in [https://github.com/omissis/go-jsonschema/pull/299](https://redirect.github.com/omissis/go-jsonschema/pull/299) #### New Contributors - [@​andrew-farries](https://redirect.github.com/andrew-farries) made their first contribution in [https://github.com/omissis/go-jsonschema/pull/220](https://redirect.github.com/omissis/go-jsonschema/pull/220) - [@​jamietanna](https://redirect.github.com/jamietanna) made their first contribution in [https://github.com/omissis/go-jsonschema/pull/240](https://redirect.github.com/omissis/go-jsonschema/pull/240) - [@​nolag](https://redirect.github.com/nolag) made their first contribution in [https://github.com/omissis/go-jsonschema/pull/264](https://redirect.github.com/omissis/go-jsonschema/pull/264) **Full Changelog**: omissis/go-jsonschema@v0.16.0...v0.17.0 </details> <details> <summary>google/osv-scanner (github.com/google/osv-scanner)</summary> ### [`v1.9.1`](https://redirect.github.com/google/osv-scanner/blob/HEAD/CHANGELOG.md#v191) [Compare Source](https://redirect.github.com/google/osv-scanner/compare/v1.9.0...v1.9.1) ##### Features: - [Feature #​1295](https://redirect.github.com/google/osv-scanner/pull/1295) Support offline database in fix subcommand. - [Feature #​1342](https://redirect.github.com/google/osv-scanner/pull/1342) Add `--experimental-offline-vulnerabilities` and `--experimental-no-resolve` flags. - [Feature #​1045](https://redirect.github.com/google/osv-scanner/pull/1045) Support private registries for Maven. - [Feature #​1226](https://redirect.github.com/google/osv-scanner/pull/1226) Support support `vulnerabilities.ignore` in package overrides. ##### Fixes: - [Bug #​604](https://redirect.github.com/google/osv-scanner/pull/604) Use correct path separator in SARIF output when on Windows. - [Bug #​330](https://redirect.github.com/google/osv-scanner/pull/330) Warn about and ignore duplicate entries in SBOMs. - [Bug #​1325](https://redirect.github.com/google/osv-scanner/pull/1325) Set CharsetReader and Entity when reading pom.xml. - [Bug #​1310](https://redirect.github.com/google/osv-scanner/pull/1310) Update spdx license ids. - [Bug #​1288](https://redirect.github.com/google/osv-scanner/pull/1288) Sort sbom packages by PURL. - [Bug #​1285](https://redirect.github.com/google/osv-scanner/pull/1285) Improve handling if `docker` exits with a non-zero code when trying to scan images ##### API Changes: - Deprecate auxillary public packages: As part of the V2 update described above, we have started deprecating some of the auxillary packages which are not commonly used to give us more room to make better API designs. These include: - `config` - `depsdev` - `grouper` - `spdx` </details> --- ### Configuration 📅 **Schedule**: Branch creation - "before 6am on wednesday" in timezone Australia/Sydney, Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/google/osv.dev). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4xMzMuMSIsInVwZGF0ZWRJblZlciI6IjM4LjEzNS4yIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: Holly Gong <[email protected]>
- Loading branch information