Skip to content

fix(deps): update non-major dependencies - #37

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major-dependencies
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major-dependencies

Conversation

@renovate

@renovate renovate Bot commented Aug 17, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
actions/checkout action patch v7.0.0 → v7.0.1
anyhow dependencies patch 1.0.101 → 1.0.104
aquasecurity/trivy-action action minor v0.35.0 → v0.36.0
cargo:cargo-tarpaulin tools patch 0.37.0 → 0.37.5
clap dependencies minor 4.5.57 → 4.6.7
dialoguer dependencies minor 0.10 → 0.12
getplumber/plumber action minor v0.4.8 → v0.5.17
github/codeql-action (changelog) action digest c4dd10e → 1190a97
github:mongodb/kingfisher tools minor 1.110.0 → v1.113.0
hk tools minor 1.54.0 → 1.58.1
jdx/mise-action action minor v4.2.4 → v4.3.0
pragent/pr-agent docker digest ea2ea90 → 3b039b1
which dependencies patch 8.0.5 → 8.0.6

Release Notes

actions/checkout (actions/checkout)

v7.0.1

Compare Source

dtolnay/anyhow (anyhow)

v1.0.104

Compare Source

  • Update syn dev-dependency to version 3

v1.0.103

Compare Source

  • Fix Stacked Borrows violation (UB) in Error::downcast_mut (#​451, #​452)

v1.0.102

Compare Source

aquasecurity/trivy-action (aquasecurity/trivy-action)

v0.36.0

Compare Source

What's Changed

New Contributors

Full Changelog: aquasecurity/trivy-action@v0.35.0...v0.36.0

xd009642/tarpaulin (cargo:cargo-tarpaulin)

v0.37.5

Compare Source

Changed
  • Improved performance of path filtering in llvm-profparsers

v0.37.4

Compare Source

Changed
  • LLVM engine tests now respect --timeout argument
  • Repeated -Clink-arg values are preserved when updating rustflags and rustdocflags
  • RUSTDOCFLAGS values are joined to existing values instead of overwriting
  • Projects with markdown relevant characters in the name now don't cause markdown misrendering
  • Improve HTML reports to fix some issues (light/dark button not working, long paths overrun layout)

v0.37.3

Compare Source

Changed
  • Use CARGO_ENCODED_RUST(DOC)FLAGS to avoid space splitting issues
  • Saturating add when adding two line hit counts together.

v0.37.2

Compare Source

Fixed
  • Fix LLVM 23 support for 32 bit profiles

v0.37.1

Compare Source

Added
  • LLVM 23 support to llvm engine
clap-rs/clap (clap)

v4.6.7

Compare Source

v4.6.6

Compare Source

Features
  • Add Command::get_overridden_usage

v4.6.5

Compare Source

v4.6.4

Compare Source

Internal
  • Update to syn v3

v4.6.3

Compare Source

Fixes
  • (derive) Allow "literal".function() as attribute values

v4.6.2

Compare Source

Fixes
  • (help) Say alias when there is only one

v4.6.1

Compare Source

Fixes
  • (derive) Ensure rebuilds happen when an read env variable is changed

v4.6.0

Compare Source

Compatibility
  • Update MSRV to 1.85

v4.5.61

Compare Source

Internal
  • Update dependencies

v4.5.60

Compare Source

Fixes
  • (help) Quote empty default values, possible values

v4.5.59

Compare Source

Fixes
  • Command::ignore_errors no longer masks help/version on subcommands

v4.5.58

Compare Source

console-rs/dialoguer (dialoguer)

v0.12.0: 0.12.0

Compare Source

What's Changed

v0.11.0: 0.11.0

Compare Source

What's Changed

getplumber/plumber (getplumber/plumber)

v0.5.17

Compare Source

✨ Features
  • analyze: accept the repository to scan as a positional target (14f3908)
📚 Documentation
  • show the positional target in the remote-scan examples (c991a47)

v0.5.16

Compare Source

🐛 Bug Fixes
  • docker: build the image binary for the target platform (8363ff5)
📚 Documentation
👷 CI/CD
  • release: add the scripts that pin the image digest at the tag (9fca2fe)
  • release: build the image before the tag, pin its digest in it (858a132)
  • release: pin v0.5.15 refs [skip ci] (20d607d)

v0.5.15

Compare Source

🐛 Bug Fixes
  • docker: build the image binary for the target platform (8363ff5)
📚 Documentation
👷 CI/CD
  • release: add the scripts that pin the image digest at the tag (9fca2fe)
  • release: build the image before the tag, pin its digest in it (858a132)
  • release: pin v0.5.15 refs [skip ci] (20d607d)

v0.5.14

Compare Source

🐛 Bug Fixes
  • cmd: banner reads "CI/CD Security Scanner for GitHub & GitLab" (806e12a)
  • cmd: banner reads just "CI/CD Security Scanner" (ad8cd33)
👷 CI/CD
  • release: pin v0.5.14 refs [skip ci] (8b4214b)

v0.5.13

Compare Source

🐛 Bug Fixes
  • gitlab: debug log keeps the GraphQL request side only (56c0924)
  • gitlab: resolve image references only from variables the job can see (e34aa5f)
👷 CI/CD
  • release: pin v0.5.13 refs [skip ci] (6932291)

v0.5.12

Compare Source

✨ Features
  • ir,github: carry if conditions for jobs, actions and run scripts (4195575), closes #​497
🐛 Bug Fixes
  • policies: resolve the cache-poisoning release path per trigger (37dd0f8), closes #​497
📚 Documentation
  • cache-poisoning: describe the per-trigger resolution and ISSUE-717 everywhere the control is documented (c626275), closes #​497
👷 CI/CD
  • release: pin v0.5.12 refs [skip ci] (6c3956c)

v0.5.11

Compare Source

✨ Features
  • config: trust the whole Microsoft Artifact Registry by default (cb8ce1c)
📚 Documentation
  • readme: fix the quick start for zero-config runs and homebrew 6 tap trust (bf30577)
👷 CI/CD
  • release: pin v0.5.11 refs [skip ci] (9984299)

v0.5.10

Compare Source

🐛 Bug Fixes
  • sarif: anchor a repository-level finding to the repository root (af21030), closes #​352
👷 CI/CD
  • release: pin v0.5.10 refs [skip ci] (3b6af14)

v0.5.9

Compare Source

🐛 Bug Fixes
  • control: a failed policy marks only the controls it emits, strict evaluation moves to the tests (7f3dd6c)
  • control: a policy that fails to evaluate degrades the run instead of passing it (ec9813e), closes #​489
  • policies: a recursive workspace upload packs .git, a Git dot-file does not (e52a267)
  • policies: an upload of a path under the workspace does not pack .git (07b0c26)
  • policies: artipacked handles several upload-artifact steps in one job (d4e9402), closes #​489
👷 CI/CD
  • release: pin v0.5.9 refs [skip ci] (c93bf1c)

v0.5.8

Compare Source

🐛 Bug Fixes
  • control: derive the disabled-control set from ControlsConfig (aa486ae)
♻️ Refactoring
  • one implementation for each duplicated helper (7295e37)
🔧 Chores
  • consistent naming, comment forms and signatures across packages (b8f9ab6)
📚 Documentation
  • package comments for every package, deprecated identity helper removed (e541e17)
✅ Tests
  • gitlab: pin NormalizeYAMLValue on nested, non-string-keyed and scalar input (04b4e21)
👷 CI/CD
  • release: pin v0.5.8 refs [skip ci] (22f7fcd)

v0.5.7

Compare Source

🐛 Bug Fixes
  • cmd: the bill mirrors the platform's byte and edge bounds, a bill the platform would refuse is omitted whole (d94a6c0)
  • gitlab,pbom: a component include carries its project, the bill of materials can key the component (34480c8)
✅ Tests
  • cmd: the edge bound is pinned through the services and runner tags terms (review) (7ba89d7)
👷 CI/CD
  • release: pin v0.5.7 refs [skip ci] (0dd46fb)

v0.5.6

Compare Source

🐛 Bug Fixes
  • cmd: the bill's bounds are measured on the wire section, an image naming more than 500 jobs omits the bill (91a74d9)
  • cmd: the platform push carries the pipeline bill of materials (bom, schema 1, bounded) (c0f1a21)
  • ir,gitlab,pbom: a job carries its runner tags, the bill of materials names each job's services and tags (1d3c9a6)
👷 CI/CD
  • release: pin v0.5.6 refs [skip ci] (ab18ada)

v0.5.5

Compare Source

🐛 Bug Fixes
  • catalog: the control catalog names the gitlab tier a control or a field requires (ask 56) (8130a2c)
  • configuration,policies: the default branch is a forbidden include version by default, mr fields lose descriptions (50a60b0)
  • control,configuration: CTRL-102 is named container images must not use forbidden reference, the name copies agree (7ebbb6a)
  • policies: every gitlab finding message reads as one clear sentence with its technical tokens quoted (c298ed0)
✅ Tests
  • policies: every rewritten label and message branch is rendered by the corpus, ISSUE-506 labels are complete (18d0215)
  • policies: the ISSUE-502 and ISSUE-601 message branches are asserted, the lint rejects empty backquotes (9abef9a), closes #​484
  • policies: the ISSUE-505 reasons are asserted and every string array in finding data passes the lint (c684a76)
  • policies: the squash clause of ISSUE-506 and every ISSUE-413 detail branch render through the lint (3ec811e)
👷 CI/CD
  • release: pin v0.5.5 refs [skip ci] (d874910)

v0.5.4

Compare Source

🐛 Bug Fixes
👷 CI/CD
  • release: pin v0.5.4 refs [skip ci] (5dbcedb)

v0.5.3

Compare Source

✨ Features
  • catalog: export toggle semantics for behavior-switch booleans (46c5014)
👷 CI/CD
  • release: pin v0.5.3 refs [skip ci] (a36dcb4)

v0.5.2

Compare Source

🐛 Bug Fixes
  • gitlab: a required template matches its identity from the ref, not only its file path (056e7c8)
  • gitlab: a versioned template include keeps its template identity when the tag listing fails (724aa10)
  • platform: a linked run never calls GitLab for an include the platform served without its observation (d990b31)
  • platform: a version fact the platform did not serve reads as platform_observation_missing, not as a failed probe (52e1c47)
👷 CI/CD
  • release: pin v0.5.2 refs [skip ci] (cd7ef86)

v0.5.1

Compare Source

✨ Features
  • identity: recipe version 6, one identity per rule for ISSUE-405, ISSUE-408 and ISSUE-417 (b4f43ed)
  • policies: one finding per rule for missing required templates, components and actions (row 107) (50f6cf7)
👷 CI/CD
  • release: pin v0.5.1 refs [skip ci] (0648860)

v0.5.0

Compare Source

🐛 Bug Fixes
  • component: run the plumber job on branch pipelines with an open MR and on plumber/ branches (045fe6f), closes #​476
📚 Documentation
👷 CI/CD
  • release: pin v0.5.0 refs [skip ci] (1472696)

v0.4.63

Compare Source

⚠ BREAKING CHANGES
  • identity: every ISSUE-406 and ISSUE-409 finding re-keys; a dismissal made under recipe version 4 no longer suppresses them and the platform re-detects the issue once.

Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_01FUFtr3m8zC2mVNKVTQvaNz

✨ Features
  • identity: recipe version 5, the override fingerprint keys ISSUE-406 and ISSUE-409 (38c87b0)
  • ir: fingerprint an include's override content from the overridden keys and their values (a8378a5)
  • policies: overridden findings carry the override fingerprint and the overridden jobs (e133aba)
🐛 Bug Fixes
  • ir: the override fingerprint hashes the whole local job block, nested keys included (12fac4c)
👷 CI/CD
  • release: pin v0.4.63 refs [skip ci] (9c6f60d)

v0.4.62

Compare Source

✨ Features
  • cmd: push a linked run that evaluated nothing, with the marker the platform records (row 63) (c713d04)
  • control: drive platform-mode collection from the union of the resolved policies (row 62) (f318bcb)
🐛 Bug Fixes
  • cmd: ignore --controls and --skip-controls on a linked run (row 64) (f93ed94)
  • cmd: terminal, exit code and docs follow the policy verdicts on a linked run (row 62) (9b5d4ff)
♻️ Refactoring
  • gitlab: export the multi-document CI parser as ParseGitlabCIConf (row 54) (0795790)
👷 CI/CD
  • release: pin v0.4.62 refs [skip ci] (1840df4)

v0.4.61

Compare Source

🐛 Bug Fixes
  • gitremote: eat every userinfo @​ up to the last one before the path (d370cbd)
  • platform: a served empty include list is complete attribution, not unknown (754ab69)
  • platform: use the includes the resolve endpoint serves (dc10a57)
✅ Tests
  • platform: pin the no-attribution branch of the includes served line (9b18a79)
  • platform: pin the wire-level decode of resolve response includes (4e2837d)
👷 CI/CD
  • release: pin v0.4.61 refs [skip ci] (cc366ec)

v0.4.60

Compare Source

✨ Features
  • configuration: export nullable on schema fields so an editor knows when unset is meaningful (6ce3630)
  • platform: require --platform-allow-http before sending credentials to a plain-http platform (fe0537c)
  • scoring: withhold the score when no control was evaluated (230a389)
🐛 Bug Fixes
  • cmd: keep the degraded-collection message ahead of the withheld score (d594e7f)
  • scoring: count a finding once per identity so the job and the platform score the same input (ed43bb5)
  • utils: strip userinfo from the parsed git remote so a token clone still matches the analyzed project (b571f61)
📚 Documentation
  • plans: cli batch 2, platform decision rows 41, 45, 46, 51, 52 (4148d57)
✅ Tests
  • cmd: assert the withheld-score gate line when controls exist but none was evaluated (7ecdabc)
  • cmd: pin the plain-http refusal on the GitHub analysis path (894a527)
👷 CI/CD
  • release: pin v0.4.60 refs [skip ci] (cb34e01)

v0.4.59

Compare Source

✨ Features
  • platform: decode policy min_points and the push response's global score into a verdict (83dbfba)
  • platform: evaluate resolved policies as first-class runs with no local fallback (1fedc61)
  • platform: in platform mode the resolved policies drive the log, the push and the exit code (8f4b6ba)
  • platform: local gates, thresholds and the degraded exit are inert in platform mode (551eac6)
  • platform: per-policy artifacts, badge and MR comment from the platform verdict (5ef59c2), closes #​467
  • platform: per-policy log sections and the platform verdict block (13d0da9)
🐛 Bug Fixes
  • platform: a --no-controls run is not platform mode in the summary (65ae90c)
  • platform: carry each run's not-evaluable marks in its policy report entry (d16571b)
  • platform: decode the gate strictly, only the global score tolerantly (ef0733a)
  • platform: honest verdict line, collection diagnostics and header in platform mode (db8aedf)
  • platform: inventory runs keep their guards in platform mode, pin the run-level dismissal mark (ee6de90)
  • platform: platform-mode artifacts carry only the policies' verdicts (b8c3411)
  • platform: tolerant gate decode and validated global letter (9c292fe)
  • platform: track the two image controls independently in pbom verdicts (2928548)
📚 Documentation
  • platform: platform mode evaluates only the platform's policies and takes its verdict (8ff0c69)
  • platform: replace em dashes and restore template backticks (f73aa78)
✅ Tests
  • platform: cover outputControlEntries's multi-policy accumulation (7e7fe68)
  • platform: cover the post-action and pbom summaries through the cmd path (7e334ba)
  • platform: cover the report's un-applied policy entry and min_points (93b6185)
  • platform: cover the union's not-evaluable swap and the degraded sections (e10cc50), closes #​220
  • platform: pin the notEvaluable key removal in platform-mode json reports (6cc5dd0)
👷 CI/CD
  • release: pin v0.4.59 refs [skip ci] (8da00d4)

v0.4.58

Compare Source

✨ Features
  • platform: propagate platform dismissals: match, mark, exclude from the score, push the marker (ffe94ce), closes #​447
  • scoring: report an enabled but unconfigured control as not_evaluable (config_required) (78ca84a), closes #​459
🐛 Bug Fixes
  • platform: declare the checkout safe for git and log why git failed (31fa6e7), closes #​464
  • platform: review follow-ups: pin the run-level dismissal path, harden the git helper, docs (d6e1b03)
📚 Documentation
  • platform: design and plan for the safe checkout, unconfigured controls and dismissal propagation (4ad52a0)
👷 CI/CD
  • release: pin v0.4.58 refs [skip ci] (65610c8)

v0.4.57

Compare Source

✨ Features
  • platform: export the score band and push final_points (95216ef)
👷 CI/CD
  • release: pin v0.4.57 refs [skip ci] (d7bb560)

v0.4.56

Compare Source

✨ Features
  • cidigest: add the wire-stable ci config digest_v1 replica (ADR-0034 rule 1) (3cb009c)
  • platform: decode project details, security policy, raw config and merge status from the snapshot (f0abae3)
  • platform: evaluate merge settings and security policy from the snapshot lanes (1892301)
  • platform: use the served merge status, ci errors and raw config (607912c)
🐛 Bug Fixes
  • platform: gate the served raw config on the anchor, validate the merge status (628c343)
  • platform: serve the raw config only at the snapshot's commit; name absent lanes (7faf706)
📚 Documentation
  • platform: design spec for platform-mode collection without a GitLab token (640128f)
  • platform: implementation plan for token-free platform-mode collection (7c9e6d1)
  • platform: rescope the platform-mode work to the snapshot lanes the cli does not consume yet (68c25e5)
👷 CI/CD
  • release: pin v0.4.56 refs [skip ci] (2c9b116)

v0.4.55

Compare Source

✨ Features
🐛 Bug Fixes
  • catalog: drop the false debug-trace default; the engine has no built-in list (6a7c2dd)
  • catalog: rendered-string cleanup, contract guard tests and CI deadcode exemption (#​458) (8317e03)
📚 Documentation
  • catalog: design spec and implementation plan for the catalog export (#​458) (6ebc83c)
👷 CI/CD
  • release: pin v0.4.55 refs [skip ci] (bad1d73)

v0.4.54

Compare Source

🐛 Bug Fixes
  • address review comment on #​442 (0d67cd6)
  • BUG: ISSUE-705 cannot see a ref-scoped type=gha buildx cache (scope= parameter ignored) (#​433) (25facb0)
👷 CI/CD
  • release: pin v0.4.54 refs [skip ci] (a5d3fd5)

v0.4.53

Compare Source

🐛 Bug Fixes
👷 CI/CD
  • release: pin v0.4.53 refs [skip ci] (b03e5d3)

v0.4.52

Compare Source

🐛 Bug Fixes
  • image: move to Alpine 3.23 and bump x/crypto to v0.56.0 to clear image CVEs (77425b9)
?

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Comment thread .github/workflows/kingfisher.yml Fixed
@github-actions

github-actions Bot commented Aug 17, 2026 •

Copy link
Copy Markdown

🛡️ Plumber — CI/CD Security Compliance

✅ No Critical-severity findings

🟠 High (15)

Code Location Source
ISSUE-701 ci/build
uses: dtolnay/rust-toolchain@stable
ISSUE-701 ci/coverage
uses: dtolnay/rust-toolchain@stable
ISSUE-701 ci/coverage
uses: codecov/codecov-action@v4
ISSUE-701 ci/security-audit
uses: dtolnay/rust-toolchain@stable
ISSUE-701 release-please/build_and_upload
uses: dtolnay/rust-toolchain@stable
ISSUE-701 release-please/release
uses: googleapis/release-please-action@v4
ISSUE-713 ci/build
uses: dtolnay/rust-toolchain@stable
ISSUE-713 ci/coverage
uses: dtolnay/rust-toolchain@stable
ISSUE-713 ci/security-audit
uses: dtolnay/rust-toolchain@stable
ISSUE-713 kingfisher/kingfisher
- uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0
ISSUE-713 release-please/build_and_upload
uses: dtolnay/rust-toolchain@stable
ISSUE-714 ci/build
uses: dtolnay/rust-toolchain@stable
ISSUE-714 ci/coverage
uses: dtolnay/rust-toolchain@stable
ISSUE-714 ci/security-audit
uses: dtolnay/rust-toolchain@stable
ISSUE-714 release-please/build_and_upload
uses: dtolnay/rust-toolchain@stable

🔵 Low (9)

Code Location Source
ISSUE-307 ci/build
- uses: actions/checkout@v4
ISSUE-307 ci/coverage
- uses: actions/checkout@v4
ISSUE-307 ci/dependency-scan
- uses: actions/checkout@v4
ISSUE-307 ci/security-audit
- uses: actions/checkout@v4
ISSUE-307 kingfisher/kingfisher
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
ISSUE-307 plumber/plumber
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
ISSUE-307 release-please/build_and_upload
uses: actions/checkout@v4
ISSUE-307 release-please/create_release
uses: actions/checkout@v4
ISSUE-307 release-please/release
uses: actions/checkout@v4

View this run

@renovate
renovate Bot force-pushed the renovate/non-major-dependencies branch 2 times, most recently from adac2bb to 1202fc0 Compare August 17, 2026 18:41
Comment thread .github/workflows/kingfisher.yml Fixed
@renovate
renovate Bot force-pushed the renovate/non-major-dependencies branch 4 times, most recently from e630acf to d5fb840 Compare August 25, 2026 20:11
fetch-depth: 0 # full history — Kingfisher defaults to --git-history full

- uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
- uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0
@renovate
renovate Bot force-pushed the renovate/non-major-dependencies branch 2 times, most recently from ae31dc4 to 1e6525c Compare August 28, 2026 10:05
security-events: write # upload SARIF to Code Scanning
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
pull-requests: write # post the compliance comment on PRs
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
@renovate
renovate Bot force-pushed the renovate/non-major-dependencies branch 5 times, most recently from 6403a41 to 6d0d4ac Compare September 5, 2026 21:52
@renovate
renovate Bot force-pushed the renovate/non-major-dependencies branch 8 times, most recently from 7a4c1a4 to bdc5d8c Compare September 14, 2026 10:24
@renovate
renovate Bot force-pushed the renovate/non-major-dependencies branch 4 times, most recently from 226c63e to 2b7b0d7 Compare September 17, 2026 23:40
@renovate
renovate Bot force-pushed the renovate/non-major-dependencies branch 11 times, most recently from 1906e8f to 28b93d1 Compare September 25, 2026 04:49
@renovate
renovate Bot force-pushed the renovate/non-major-dependencies branch 8 times, most recently from e653d4d to ede0c79 Compare October 1, 2026 04:37
@renovate
renovate Bot force-pushed the renovate/non-major-dependencies branch from ede0c79 to 957d7b9 Compare October 2, 2026 01:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant