Skip to content

Update all dependencies - #35

Merged
missingcharacter merged 3 commits into
mainfrom
renovate/all
Sep 25, 2026
Merged

missingcharacter merged 3 commits into
mainfrom
renovate/all

Conversation

@missingcharacter

@missingcharacter missingcharacter commented Sep 15, 2026 •

Copy link
Copy Markdown
Owner

This PR contains the following updates:

Package Type Update Change
gradle tools minor 9.7.1 → 9.8.0
kubectl tools patch 1.37.0 → 1.37.1
opam tools minor 2.5.2 → 2.6.0
opencode tools major 1.18.29 → 2.0.16
pulumi tools minor 3.262.0 → 3.264.0
python tools minor 3.13.15 → 3.14.7
ruby (source) tools patch 4.0.6 → 4.0.7
sbt tools patch 2.0.8 → 2.0.9
terraform tools minor 1.15.8 → 1.16.4
uv tools patch 0.12.13 → 0.12.19

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

gradle/gradle-distributions (gradle)

v9.8.0: 9.8.0

Compare Source

See the release in the gradle/gradle repository.

Release notes

Checksums

bin: bafd5ce9cfaea0fbccfdc8439a1ac42fbd4cd9c89dc9a988228d8a2639a58e6c
all: 46ac66d47f30f3dacfdf306e0b714a91a34fb94a22ba0a744b280933f47bc0cf
docs: dbd2318595bc63b243205aa0fedb517845aa3df2574f3b4c9d38f132f13cdea5
src: c15b7b5878c5e9717aa8919013627bb04acf9633bb4a582c2f7eefd82b702343
wrapper: 238e777fcddd7e34f9708186085def2abd6e08e658505b38718d79d74c21abd5

kubernetes/kubernetes (kubectl)

v1.37.1

Compare Source

See kubernetes-announce@. Additional binary downloads are linked in the CHANGELOG.

See the CHANGELOG for more details.

ocaml/opam (opam)

v2.6.0

Compare Source

This is the final release of opam 2.6.0.

Binaries and full archive are signed by the opam dev team (fingerprint 92C5 26AE 50DF 3947 0EB2 911B ED4C F1CA 67CB AA92).
To verify the authenticity of one of these files, run the following commands:

curl -fsSLO https://opam.ocaml.org/opam-dev-pubkey.pgp
gpg --import opam-dev-pubkey.pgp
gpg --verify *.sig

Changelog:

Changes

To get the detailed list of changes compared to 2.5.2, you can look at the pre-releases' release notes:

For a more descriptive and simplified list of changes, please read our blog post.


Special thanks to the Haematology department and Bone Marrow Transplant Unit of the NHS Greater Glasgow for making this release possible <3

anomalyco/opencode (opencode)

v2.0.16

Compare Source

v2.0.15

Compare Source

v2.0.14

Compare Source

v2.0.13

Compare Source

v2.0.12

Compare Source

v2.0.11

Compare Source

v2.0.10

Compare Source

v2.0.9

Compare Source

v2.0.8

Compare Source

v2.0.7

Compare Source

v2.0.6

Compare Source

v2.0.5

Compare Source

v2.0.4

Compare Source

v2.0.3

Compare Source

v2.0.2

Compare Source

v2.0.1

Compare Source

v2.0.0

Compare Source

v1.18.32

Compare Source

Core

Bugfixes
  • Fixed Bedrock image attachments so they are only hoisted for Claude, Nova, and Llama 4 models.
  • Fixed Together AI streaming usage reporting.

Thank you to 1 community contributor:

v1.18.31

Compare Source

Core

Bugfixes
  • Restored ACP session model, effort, mode, and reasoning chunk boundaries when loading, resuming, or forking sessions. (@​JacobNWolf)

TUI

Bugfixes
  • Show remote config authentication errors during startup and exit with a failure status.

Extensions

Improvements
  • Request summarized adaptive thinking for GitHub Copilot models.

Thank you to 4 community contributors:

v1.18.30

Compare Source

Core

Improvements
  • Added the Astra system prompt for GPT-6 models.
Bugfixes
  • Preserved Bedrock DeepSeek model IDs, including ARN-based IDs, so they resolve correctly. (@​YeEmrick)
  • Updated the Azure provider SDK to pick up compatibility fixes.
  • Updated the OpenAI provider SDK to pick up compatibility fixes.
  • Added reasoning effort variants for supported GitLab GPT and Claude models. (@​far-ouq)

Thank you to 3 community contributors:

pulumi/pulumi (pulumi)

v3.264.0

Compare Source

Features
  • [sdk/python] Add component state migration callbacks to ResourceOptions #​24331
  • [cli/deployment] Allow pulumi deployment settings edit to configure git authentication, dependency caching, template sources and drift remediation #​24528
  • [cli/deployment] Allow pulumi deployment settings edit to configure tag triggers, review stack labels and the version control integration #​24527
  • [backend/service] Enable component state migrations for Pulumi Cloud updates using journal v2 #​24458
  • [sdk/go] Add component state migration callbacks to resource options #​24519
  • [sdk/nodejs] Add component state migration callbacks to resource options #​24715
Bug Fixes
  • [sdk/python] Discover plugins from the current uv workspace member’s dependencies #​24706
  • [cli] Suppress the Neo diagnostic help prompt for informational messages #​24743
  • [cli] Run the pulumi new credentials preflight for parameterized providers #​24669
  • [cli/env] Reference pulumi env rather than the retired standalone esc CLI in pulumi env messages and help text #​24699
  • [cli/deployment] Allow pulumi deployment settings edit to move a stack configured against a repository URL onto a version control integration #​24529
  • [cli/deployment] Stop pulumi deployment settings get padding its output for labels it does not print #​24448
  • [sdk/go] Serialize ESC boolean schemas as their equivalent object forms ({} for "always", {"not":{}} for "never") instead of bare JSON booleans, so schema-carrying payloads are valid instances of the OpenAPI models that describe them #​24613
  • [sdk/go] Run Go policy remediations only at the remediate enforcement level #​24647
  • [engine] Avoid trying to delete resources PendingReplacement #​24588
  • [backend/diy] Fix path handling with absolute paths #​24628
  • [pkg] Interpret documentation references on lazily-loaded packages after they are fully bound, and resolve references to members that have not been loaded yet #​24682
  • [engine] Update the partially created resource instead of creating another one when an OnError hook retries a create #​24684
  • [engine] Preserve root-first state ordering between chained state migration callbacks #​24695
  • [sdk/go] Propagate the dependsOn resource option on ReadResource calls #​24725
  • [pcl] Propagate the dependsOn resource option on read blocks #​24725
  • [cli/neo] Skip the redundant preview step when pulumi neo runs the pulumi_up tool #​24719
  • [sdkgen/go] Set the default plugin version when the schema sets a Go language option #​24733
  • [cli/package] Stop leaking package processes from pulumi package get-schema #​24741
  • [cli] Remove the prompt to create a first project after an interactive login #​24742
  • [engine] When a Read is skipped because one of its dependencies failed during a --continue-on-error update, return the resource's last-known outputs to the SDK if it is already present in state, rather than an empty output map #​24745
Improvements
  • [backend/service] Improve startup performance #​24417
  • [sdk/go] Remove policyx.ResourceValidationArgs.DryRun as it was never correctly set #​24673
  • [engine] Report planned and applied state migrations through user-facing diagnostics #​24713
  • [cli] Make all commands start slightly faster #​24736
Miscellaneous
  • [engine] Retire the SKIP value from the RegisterResourceResponse.Result protobuf enum; dependency-skipped resources now report FAIL to the SDK, which matches how every language SDK already interpreted SKIP #​24688
  • [java] Upgrade java to v1.37.2 #​24729
  • [hcl] Upgrade hcl to v0.18.1 #​24729
  • [yaml] Upgrade yaml to v1.38.7 #​24735
  • [hcl] Upgrade hcl to v0.18.2 #​24735
  • [sdk/dotnet] Upgrade dotnet to v3.114.0 #​24737
  • [yaml] Upgrade yaml to v1.38.7 #​24737
  • [hcl] Upgrade hcl to v0.18.2 #​24737

v3.263.0

Compare Source

Bug Fixes
  • [cli/deployment] Stop pulumi deployment settings edit overwriting the source of stacks that use a provider other than GitHub, take --path-filter once per filter rather than splitting it on commas, and report an unconfigured stack from get instead of failing #​24526
  • [engine] Fix remote component provider state migrations being skipped when the caller also supplies migrations #​24620
  • [engine] Forward caller error hooks to remote component providers #​24622
  • [cli/do] Error sooner if string values can't be cast to numeric/boolean inputs #​24643
  • [build] Restore pr# based downloads #​24649
  • [sdk/nodejs] Fix a panic in the pnpm package manager when pnpm config get allowBuilds prints null #​24674
Improvements
  • [cli] Document automatic plugin installation and list the valid KIND values in pulumi plugin install --help #​24630
  • [cli/plugin] Describe what pulumi plugin ls does and does not list in its help text #​24631
  • [cli] Reframe pulumi plugin help around automatic plugin installation and link the plugin-authoring docs #​24632
  • [cli] Protect resources retained by pulumi state promote so a subsequent update cannot delete them before the generated code is added to the program #​24640
  • [cli/env] Prompt for the ESC project and environment names in pulumi env setup, ask how to authenticate before choosing an access level, and print a success message when setup completes #​24662
Miscellaneous
python/cpython (python)

v3.14.7

Compare Source

v3.14.6

Compare Source

v3.14.5

Compare Source

v3.14.4

Compare Source

v3.14.3

Compare Source

v3.14.2

Compare Source

v3.14.1

Compare Source

v3.14.0

Compare Source

ruby/ruby (ruby)

v4.0.7: 4.0.7

Compare Source

What's Changed

Note: This list is automatically generated by tool/gen-github-release.rb. Because of this, some commits may be missing.

Full Changelog

sbt/sbt (sbt)

v2.0.9: 2.0.9

Compare Source

🐛 bug fixes

Full Changelog: sbt/sbt@v2.0.8...v2.0.9

hashicorp/terraform (terraform)

v1.16.4

Compare Source

1.16.4 (September 23, 2026)

BUG FIXES:

  • Fixed an issue where Terraform fails when rendering policy evaluation outcomes for older versions of Terraform Enterprise (#​39095)

  • stacks: Fix invalid deferred error triggered by provider returning a deferral when a resource also has an unknown count/for_each. (#​39237)

v1.16.3

Compare Source

1.16.3 (September 16, 2026)

BUG FIXES:

  • Fix handling of destroy=false around create_before_destroy instances (#​39169)

  • Fix function result comparison when there are multiple marks (#​39170)

  • Filter logic for marks could cause values with multiple marks to erroneously fail validations (#​39171)

  • Fix issue with import provider resolution (#​39185)

v1.16.2

Compare Source

1.16.2 (September 9, 2026)

BUG FIXES:

  • Fix panic in module installation when encoutering invalid module calls (#​39129)

v1.16.1

Compare Source

1.16.1 (September 2, 2026)

BUG FIXES:

  • cloud: Fixed a bug causing the CLI to pause indefinitely after a run task failure with pending policy evaluations (#​38751)

  • Support referencing modules containing dynamic sources in Terraform Test (#​38950)

  • stacks: Fixed validation to ensure the provider versions in the lock file and configuration are compatible. (#​38829)

  • Fix panic when import identity references sensitive value (#​39013)

  • import: Fixed a bug where import blocks would be ignored when multiple imports targeted different instances of a resource config using for_each or count. (#​39068)

  • state show: Fix a panic when given an attribute path instead of a resource instance address (#​39087)

  • Fix create_before_destroy ordering in some combinations of changes (#​39091)

v1.16.0

Compare Source

1.16.0 (August 26, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#​37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#​38298)

  • Providers can now use nested blocks as computed values (#​38305)

  • import: import blocks inside modules are now supported. (#​38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#​38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#​38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#​23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#​38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#​38449)

  • stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#​38668)

  • Actions can now use before_destroy and after_destroy events. (#​38668)

  • cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#​38715)

  • policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#​38716)

  • graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#​38719)

  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#​38778)

  • Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#​38784)

  • The contains() function can now test for null values. (#​38792)

  • console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#​31861)

  • -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#​38845)

  • The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#​38896)

BUG FIXES:

  • import blocks now correctly respect provider local names. (#​38338)

  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#​38586)

  • workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#​38594)

  • test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#​38603)

  • init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#​38634)

  • init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#​38656)

  • Actions are now invoked with respect to all resource dependencies. (#​38668)

  • Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#​38782)

  • The merge() function no longer panics when passed null objects. (#​38792)

  • Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid (#​38894)

  • test: Optional ephemeral values do not have to be set at plan time (#​38974)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#​38561)

UPGRADE NOTES:

  • bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#​38318)

Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.15.9

Compare Source

1.15.9 (August 19, 2026)

BUG FIXES:

  • validate: Child module validation has been fixed and will now raise errors or warning diagnostics for invalid blocks. (list, import, backend, and cloud) (#​38994)

NOTES:

  • Update go-slug to v0.18.3 to mitigate CVE-2026-14978, which is a Unicode normalization issue that could lead to files not being correctly excluded via .terraformignore from upload to a Terraform Enterprise or HCP Terraform during a run (#​39036)
astral-sh/uv (uv)

v0.12.19

Compare Source

Released on 2026-09-24.

Python
  • Add PyPy 3.11.16 and 3.12.14 (#​21847)
  • Update GraalPy 3.13.0 to build 25.4.4 (#​21847)
Enhancements
  • Format upload URLs with backticks in uv publish errors (#​21934)
Preview features
  • Run build-backend hooks with lazy imports on CPython 3.15 and later using the build-lazy-imports preview feature (#​21967)
  • Omit unused resolution settings from uv.lock and ignore changes to them when checking lockfile freshness with the resolution-inputs preview feature (#​21913)
Bug fixes
  • Preserve signed and encoded query parameters in direct-URL metadata to avoid reinstalling unchanged packages (#​21971)
  • Recognize 1.0.0 as satisfying ===1 during installed-package checks, matching resolution (#​21931)
  • Avoid collisions between Git checkout readiness markers and .ok files in dependencies (#​21891)
  • Preserve always-false python_version markers when parsing their serialized form (#​21939)
Rust API
  • Restore the public FlatDistributions export and its BTreeMap conversion for downstream resolvers (#​21965)
Documentation
  • Make individual preview-feature reference entries linkable by name (#​21950)

v0.12.18

Compare Source

Released on 2026-09-22.

This release addresses GHSA-2cv4-cqwr-gwf7, which is a path traversal weakness during wheel installation on Windows. No other platforms are affected by this advisory.

Enhancements
  • Add --output-format json to uv pip install and uv pip sync, including for --dry-run and --check (#​21893)
  • Add --check to uv pip install and uv pip sync to report planned changes without modifying the environment (#​21844)
  • Identify failures from get_requires_for_build_* hooks correctly in build errors (#​21881)
Preview features
  • Validate build requirements for uv build --no-build-isolation with --preview-features build-dependency-check; use --skip-dependency-check to opt out (#​21880)
Performance
  • Speed up uv_build editable wheel creation by omitting compression from temporary wheels (#​21918)
Bug fixes
  • Select package versions with wheels compatible with each Python resolution fork, correctly interpreting generic and stable-ABI wheel tags (#​21835, #​21836)
  • Restore project, script, and lock files when uv add, uv remove, or uv version fails or is interrupted (#​21860, #​21856)
  • Use configured dependency-metadata when checking whether installed requirements are satisfied (#​21843)
  • Reject archive entries that normalize to absolute Windows paths (#​21923)
  • Recognize distribution filenames and archive extensions when URL fragments contain ? (#​21920)
  • Generate correctly lowercased platform tags for BSD and Haiku releases (#​21853)
  • Avoid rebuilding a Windows relative path into an absolute form (#​21923)

v0.12.17

Compare Source

Released on 2026-09-18.

Enhancements
  • Reject unsupported Git archive paths in lockfiles with a clear error instead of panicking during frozen exports (#​21780)
Preview features
  • Set minimum glibc and musl versions that universal resolutions must support with minimum-libc-version (#​21651)
  • Reject pylock.toml files whose wheel filenames do not match their declared package names or versions (#​20746)
  • Keep uv workspace metadata read-only unless --sync is provided (#​21821)
  • Apply uv check lock modes when retrieving workspace metadata (#​21821)
Performance
  • Speed up builds with many exclusion patterns by avoiding quadratic deduplication (#​21650)
  • Reduce resolver allocations when deduplicating package and distribution requests (#​21810)
Bug fixes
  • Prevent required-environments from selecting package versions whose wheels require a newer macOS version than the configured Darwin baseline (#​21825)
Documentation
  • Clarify the 0.12.14 and 0.12.15 release notes (#​21817)

v0.12.16

Compare Source

Released on 2026-09-17.

Python
  • Add Pyodide 314.0.7, 0.29.5, and 0.27.8 (#​21741)
Enhancements
  • Verify downloaded wheels and source distributions against hashes supplied by package indexes (#​21562)
  • Allow build-constraint-dependencies entries to include hashes for verifying downloaded build dependencies (#​21467)
  • Honor Darwin platform_release markers in required-environments using macOS wheel deployment targets (#​21766)
  • Reject unsupported Git URL schemes while parsing lockfiles instead of panicking during frozen exports (#​21779)
Preview features
  • Support lock-without-metadata across all dependency types while retaining package.metadata for remote URL dependencies to enable offline validation (#​21163)
  • Honor configured and command-line index settings, including credentials, in uv upgrade (#​21776)
  • Allow uv check to run in projects that are not managed by uv and outside workspaces (#​21777)
  • Respect --python and UV_PYTHON when selecting the Python version for uv check (#​21744)
Bug fixes
  • Redact Azure shared access signatures from displayed and logged URLs (#​21755)
  • Check archive sizes from pylock.toml before reusing cached distributions (#​21609)
  • Keep user-authored local dependency paths relative in lockfiles when backend metadata reports absolute paths (#​20631)
  • Use the bundled uv_build backend only when its version matches active version pins (#​21742)
  • Handle malformed index URLs without panicking when credentials are configured (#​21784)
  • Report a configuration error instead of panicking for proxy URLs without a host (#​21781)
  • Return a credential-redacted error instead of panicking when a URL cannot be converted to a path (#​21783)

v0.12.15

Compare Source

Released on 2026-09-15.

Performance
  • Speed up cold-cache resolution and HTTP cache revalidation by batching cache writes (#​21675)
Bug fixes
  • Fix regressions in 0.12.14 when installing to symlinked destinations or using uv pip install --target . (#​21699)

v0.12.14

Compare Source

Released on 2026-09-15.

Enhancements
  • Resume interrupted downloads with HTTP Range requests when supported (#​21570)
  • Use a consistent format for error rendering (#​17110)
  • Render error and warning causes with compact cause: labels (#​21599, #​21603)
  • Show underlying causes and hints in user warnings (#​21565)
  • Show resolver hints for failed uv tool upgrade operations (#​21566)
Preview features
  • Export multiple dependency selections from a shared lockfile in one uv export --batch invocation with the batch-export preview feature (#​21618)
Performance
  • Speed up dependency resolution from local wheelhouses by reading wheel metadata in a single blocking task (#​21619)
  • Speed up cold resolution against large package indexes by parsing Simple API responses in bounded background workers (#​21593)
  • Speed up warm-cache resolution by decoding fresh HTTP cache entries in the cache-read task (#​21621)
Bug fixes
  • Select releases that satisfy required-environments within each resolver fork instead of combining incompatible wheel coverage across forks (#​21672)
  • Install packages with paths longer than MAX_PATH on Windows systems without long-path support enabled (#​21625)
  • Prevent uv python install from overwriting valid unmanaged Python symlinks with relative targets on Unix (#​21639)
  • Redact credentials and signatures from missing-path-segment URL errors (#​21616)
  • Avoid exceeding the configured retry budget when cached HTTP responses fail revalidation (#​21640)
  • Prefer bin/python over bin/python3 when discovering interpreters in Unix environments (#​21559)
  • Classify package-operation exit codes by their underlying cause: return 1 for expected failures and 2 for recognized operational and internal failures (#​17110)
  • Suppress managed-Python fallback warnings under --quiet (#​21565)
  • Keep failed uv tool upgrade errors visible with -q while suppressing them with -qq (#​21566)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@missingcharacter
missingcharacter force-pushed the renovate/all branch 7 times, most recently from c66ac97 to c9ff408 Compare September 22, 2026 01:27
@missingcharacter
missingcharacter force-pushed the renovate/all branch 2 times, most recently from b2bdfc9 to 09ff951 Compare September 24, 2026 01:05
@missingcharacter
missingcharacter merged commit dfb95a9 into main Sep 25, 2026
1 check passed
@missingcharacter
missingcharacter deleted the renovate/all branch September 25, 2026 01:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants