Update all dependencies - #35
Merged
Merged
Conversation
missingcharacter
force-pushed
the
renovate/all
branch
7 times, most recently
from
September 22, 2026 01:27
c66ac97 to
c9ff408
Compare
missingcharacter
force-pushed
the
renovate/all
branch
2 times, most recently
from
September 24, 2026 01:05
b2bdfc9 to
09ff951
Compare
missingcharacter
force-pushed
the
renovate/all
branch
from
September 25, 2026 01:10
09ff951 to
999edfd
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
9.7.1→9.8.01.37.0→1.37.12.5.2→2.6.01.18.29→2.0.163.262.0→3.264.03.13.15→3.14.74.0.6→4.0.72.0.8→2.0.91.15.8→1.16.40.12.13→0.12.19Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
gradle/gradle-distributions (gradle)
v9.8.0: 9.8.0Compare Source
See the release in the gradle/gradle repository.
Release notes
Checksums
bin: bafd5ce9cfaea0fbccfdc8439a1ac42fbd4cd9c89dc9a988228d8a2639a58e6c
all: 46ac66d47f30f3dacfdf306e0b714a91a34fb94a22ba0a744b280933f47bc0cf
docs: dbd2318595bc63b243205aa0fedb517845aa3df2574f3b4c9d38f132f13cdea5
src: c15b7b5878c5e9717aa8919013627bb04acf9633bb4a582c2f7eefd82b702343
wrapper: 238e777fcddd7e34f9708186085def2abd6e08e658505b38718d79d74c21abd5
kubernetes/kubernetes (kubectl)
v1.37.1Compare Source
See kubernetes-announce@. Additional binary downloads are linked in the CHANGELOG.
See the CHANGELOG for more details.
ocaml/opam (opam)
v2.6.0Compare Source
This is the final release of opam 2.6.0.
Binaries and full archive are signed by the opam dev team (fingerprint
92C5 26AE 50DF 3947 0EB2 911B ED4C F1CA 67CB AA92).To verify the authenticity of one of these files, run the following commands:
Changelog:
Changes
opam-root-versionto 2.6 [#7146 @kit-ty-kate]To get the detailed list of changes compared to 2.5.2, you can look at the pre-releases' release notes:
For a more descriptive and simplified list of changes, please read our blog post.
Special thanks to the Haematology department and Bone Marrow Transplant Unit of the NHS Greater Glasgow for making this release possible <3
anomalyco/opencode (opencode)
v2.0.16Compare Source
v2.0.15Compare Source
v2.0.14Compare Source
v2.0.13Compare Source
v2.0.12Compare Source
v2.0.11Compare Source
v2.0.10Compare Source
v2.0.9Compare Source
v2.0.8Compare Source
v2.0.7Compare Source
v2.0.6Compare Source
v2.0.5Compare Source
v2.0.4Compare Source
v2.0.3Compare Source
v2.0.2Compare Source
v2.0.1Compare Source
v2.0.0Compare Source
v1.18.32Compare Source
Core
Bugfixes
Thank you to 1 community contributor:
v1.18.31Compare Source
Core
Bugfixes
TUI
Bugfixes
Extensions
Improvements
Thank you to 4 community contributors:
v1.18.30Compare Source
Core
Improvements
Bugfixes
Thank you to 3 community contributors:
pulumi/pulumi (pulumi)
v3.264.0Compare Source
Features
pulumi deployment settings editto configure git authentication, dependency caching, template sources and drift remediation #24528pulumi deployment settings editto configure tag triggers, review stack labels and the version control integration #24527Bug Fixes
pulumi newcredentials preflight for parameterized providers #24669pulumi envrather than the retired standaloneescCLI inpulumi envmessages and help text #24699pulumi deployment settings editto move a stack configured against a repository URL onto a version control integration #24529pulumi deployment settings getpadding its output for labels it does not print #24448{}for "always",{"not":{}}for "never") instead of bare JSON booleans, so schema-carrying payloads are valid instances of the OpenAPI models that describe them #24613remediateenforcement level #24647PendingReplacement#24588OnErrorhook retries a create #24684dependsOnresource option onReadResourcecalls #24725dependsOnresource option onreadblocks #24725pulumi neoruns thepulumi_uptool #24719pulumi package get-schema#24741--continue-on-errorupdate, return the resource's last-known outputs to the SDK if it is already present in state, rather than an empty output map #24745Improvements
policyx.ResourceValidationArgs.DryRunas it was never correctly set #24673Miscellaneous
v3.263.0Compare Source
Bug Fixes
pulumi deployment settings editoverwriting the source of stacks that use a provider other than GitHub, take--path-filteronce per filter rather than splitting it on commas, and report an unconfigured stack fromgetinstead of failing #24526pnpm config get allowBuildsprintsnull#24674Improvements
pulumi plugin install --help#24630pulumi plugin lsdoes and does not list in its help text #24631pulumi pluginhelp around automatic plugin installation and link the plugin-authoring docs #24632pulumi state promoteso a subsequent update cannot delete them before the generated code is added to the program #24640pulumi env setup, ask how to authenticate before choosing an access level, and print a success message when setup completes #24662Miscellaneous
python/cpython (python)
v3.14.7Compare Source
v3.14.6Compare Source
v3.14.5Compare Source
v3.14.4Compare Source
v3.14.3Compare Source
v3.14.2Compare Source
v3.14.1Compare Source
v3.14.0Compare Source
ruby/ruby (ruby)
v4.0.7: 4.0.7Compare Source
What's Changed
Coverage.startand ruby/debug - Ruby - Ruby Issue Tracking SystemBUNDLER_SETUPcan evaluate gemspecs before main-box RubyGems initialization - Ruby - Ruby Issue Tracking Systemaws-sdk-ec2in Ruby 4.0.6 - Ruby - Ruby Issue Tracking Systemfiber_switchwith transfer-terminated async tasks on 3.4.10 - Ruby - Ruby Issue Tracking Systemvm_call_iseq_setup_kwparm_nokwarg/def_iseq_ptr) on Ruby 4.0.6 — Rails CI - Ruby - Ruby Issue Tracking SystemCoverage.line_stubclobbers already-collected coverage data - Ruby - Ruby Issue Tracking SystemNote: This list is automatically generated by tool/gen-github-release.rb. Because of this, some commits may be missing.
Full Changelog
sbt/sbt (sbt)
v2.0.9: 2.0.9Compare Source
🐛 bug fixes
semanticdbTargetRootin the compile cache key by @christianharrington in #9711Full Changelog: sbt/sbt@v2.0.8...v2.0.9
hashicorp/terraform (terraform)
v1.16.4Compare Source
1.16.4 (September 23, 2026)
BUG FIXES:
Fixed an issue where Terraform fails when rendering policy evaluation outcomes for older versions of Terraform Enterprise (#39095)
stacks: Fix invalid deferred error triggered by provider returning a deferral when a resource also has an unknown count/for_each. (#39237)
v1.16.3Compare Source
1.16.3 (September 16, 2026)
BUG FIXES:
Fix handling of destroy=false around create_before_destroy instances (#39169)
Fix function result comparison when there are multiple marks (#39170)
Filter logic for marks could cause values with multiple marks to erroneously fail validations (#39171)
Fix issue with import provider resolution (#39185)
v1.16.2Compare Source
1.16.2 (September 9, 2026)
BUG FIXES:
v1.16.1Compare Source
1.16.1 (September 2, 2026)
BUG FIXES:
cloud: Fixed a bug causing the CLI to pause indefinitely after a run task failure with pending policy evaluations (#38751)
Support referencing modules containing dynamic sources in Terraform Test (#38950)
stacks: Fixed validation to ensure the provider versions in the lock file and configuration are compatible. (#38829)
Fix panic when import identity references sensitive value (#39013)
import: Fixed a bug where import blocks would be ignored when multiple imports targeted different instances of a resource config using
for_eachorcount. (#39068)state show: Fix a panic when given an attribute path instead of a resource instance address (#39087)
Fix create_before_destroy ordering in some combinations of changes (#39091)
v1.16.0Compare Source
1.16.0 (August 26, 2026)
NEW FEATURES:
Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)
terraform_data: The newstoreblock can hold ephemeral and sensitive values across plan and apply. (#38298)Providers can now use nested blocks as computed values (#38305)
import:
importblocks inside modules are now supported. (#38352)Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)
Resource action triggers can now use
on_failuremodes ofhalt,taint, orcontinue. (#38722)ENHANCEMENTS:
state show: The
state showcommand can now produce machine-readable output when supplied with the-jsonflag (#23940)workspace: The
workspace listcommand can now produce machine-readable output when supplied with the-jsonflag (#38397)test: Terraform now reports which resources were left behind when
skip_cleanupis set. (#38449)stacks: Action configurations now have access to a
callersymbol containing the object value of the calling resource. (#38668)Actions can now use
before_destroyandafter_destroyevents. (#38668)cloud: Terraform now displays a summary of policy evaluation outcomes for
planandapplyruns against HCP Terraform. (#38715)policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during
init,plan, andapply, rather than requiring the plugin to read credentials itself. (#38716)graph: The
terraform graphcommand can now output graphs in Mermaid format using the-format=mermaidflag. (#38719)Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)
Resource
lifecycleblocks now supportdestroy = falseto prevent a resource from being destroyed. (#38784)The
contains()function can now test fornullvalues. (#38792)console: The
terraform consolecommand now accepts an optional-scope=<module address>flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)-invokecan now be combined with-targetto specify the calling resource instance when multiple resources trigger the same action. (#38845)The
terraform stackscommand now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neitherTF_STACKS_HOSTNAMEnorTF_CLOUD_HOSTNAMEis set (#38896)BUG FIXES:
importblocks now correctly respect provider local names. (#38338)terraform applyno longer panics when the plan contains a no-op change for a deposed resource that haslifecycle.preconditionorlifecycle.postconditionblocks. (#38586)workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)
test: Terraform now raises a warning when a file referenced via the
-filterflag does not exist. (#38603)init: Terraform no longer removes locks from the dependency lock file for providers configured as
dev_override. (#38634)init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)
Actions are now invoked with respect to all resource dependencies. (#38668)
Terraform now returns the correct error when an
importtarget exists in state but has no corresponding configuration. (#38782)The
merge()function no longer panics when passednullobjects. (#38792)Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid (#38894)
test: Optional ephemeral values do not have to be set at plan time (#38974)
NOTES:
-upgradeand-lockfile=readonlyflags are now raised earlier in the init process. (#38561)UPGRADE NOTES:
bastion_host_keyis now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)Previous Releases
For information on prior major and minor releases, refer to their changelogs:
v1.15.9Compare Source
1.15.9 (August 19, 2026)
BUG FIXES:
list,import,backend, andcloud) (#38994)NOTES:
.terraformignorefrom upload to a Terraform Enterprise or HCP Terraform during a run (#39036)astral-sh/uv (uv)
v0.12.19Compare Source
Released on 2026-09-24.
Python
Enhancements
uv publisherrors (#21934)Preview features
build-lazy-importspreview feature (#21967)uv.lockand ignore changes to them when checking lockfile freshness with theresolution-inputspreview feature (#21913)Bug fixes
1.0.0as satisfying===1during installed-package checks, matching resolution (#21931).okfiles in dependencies (#21891)python_versionmarkers when parsing their serialized form (#21939)Rust API
FlatDistributionsexport and itsBTreeMapconversion for downstream resolvers (#21965)Documentation
v0.12.18Compare Source
Released on 2026-09-22.
This release addresses GHSA-2cv4-cqwr-gwf7, which is a path traversal weakness during wheel installation on Windows. No other platforms are affected by this advisory.
Enhancements
--output-format jsontouv pip installanduv pip sync, including for--dry-runand--check(#21893)--checktouv pip installanduv pip syncto report planned changes without modifying the environment (#21844)get_requires_for_build_*hooks correctly in build errors (#21881)Preview features
uv build --no-build-isolationwith--preview-features build-dependency-check; use--skip-dependency-checkto opt out (#21880)Performance
uv_buildeditable wheel creation by omitting compression from temporary wheels (#21918)Bug fixes
uv add,uv remove, oruv versionfails or is interrupted (#21860, #21856)dependency-metadatawhen checking whether installed requirements are satisfied (#21843)?(#21920)v0.12.17Compare Source
Released on 2026-09-18.
Enhancements
Preview features
minimum-libc-version(#21651)pylock.tomlfiles whose wheel filenames do not match their declared package names or versions (#20746)uv workspace metadataread-only unless--syncis provided (#21821)uv checklock modes when retrieving workspace metadata (#21821)Performance
Bug fixes
required-environmentsfrom selecting package versions whose wheels require a newer macOS version than the configured Darwin baseline (#21825)Documentation
v0.12.16Compare Source
Released on 2026-09-17.
Python
Enhancements
build-constraint-dependenciesentries to include hashes for verifying downloaded build dependencies (#21467)platform_releasemarkers inrequired-environmentsusing macOS wheel deployment targets (#21766)Preview features
lock-without-metadataacross all dependency types while retainingpackage.metadatafor remote URL dependencies to enable offline validation (#21163)uv upgrade(#21776)uv checkto run in projects that are not managed by uv and outside workspaces (#21777)--pythonandUV_PYTHONwhen selecting the Python version foruv check(#21744)Bug fixes
pylock.tomlbefore reusing cached distributions (#21609)uv_buildbackend only when its version matches active version pins (#21742)v0.12.15Compare Source
Released on 2026-09-15.
Performance
Bug fixes
0.12.14when installing to symlinked destinations or usinguv pip install --target .(#21699)v0.12.14Compare Source
Released on 2026-09-15.
Enhancements
cause:labels (#21599, #21603)uv tool upgradeoperations (#21566)Preview features
uv export --batchinvocation with thebatch-exportpreview feature (#21618)Performance
Bug fixes
required-environmentswithin each resolver fork instead of combining incompatible wheel coverage across forks (#21672)MAX_PATHon Windows systems without long-path support enabled (#21625)uv python installfrom overwriting valid unmanaged Python symlinks with relative targets on Unix (#21639)bin/pythonoverbin/python3when discovering interpreters in Unix environments (#21559)1for expected failures and2for recognized operational and internal failures (#17110)--quiet(#21565)uv tool upgradeerrors visible with-qwhile suppressing them with-qq(#21566)Configuration
📅 Schedule: (UTC)
* 0-3 * * *)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.