Skip to content

Update all dependencies - #36

Merged
missingcharacter merged 2 commits into
mainfrom
renovate/all
Sep 30, 2026
Merged

missingcharacter merged 2 commits into
mainfrom
renovate/all

Conversation

@missingcharacter

@missingcharacter missingcharacter commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

This PR contains the following updates:

Package Type Update Change
opencode tools major 1.18.32 → 2.0.20
pulumi tools minor 3.264.0 → 3.265.0
python tools minor 3.13.15 → 3.14.7
terraform tools minor 1.15.8 → 1.16.4
uv tools patch 0.12.19 → 0.12.21

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

anomalyco/opencode (opencode)

v2.0.20

Compare Source

v2.0.19

Compare Source

v2.0.18

Compare Source

v2.0.17

Compare Source

v2.0.16

Compare Source

v2.0.15

Compare Source

v2.0.14

Compare Source

v2.0.13

Compare Source

v2.0.12

Compare Source

v2.0.11

Compare Source

v2.0.10

Compare Source

v2.0.9

Compare Source

v2.0.8

Compare Source

v2.0.7

Compare Source

v2.0.6

Compare Source

v2.0.5

Compare Source

v2.0.4

Compare Source

v2.0.3

Compare Source

v2.0.2

Compare Source

v2.0.1

Compare Source

v2.0.0

Compare Source

v1.18.33

Compare Source

Core

Bugfixes
  • Cloudflare AI Gateway models now honor provider response and stream timeouts. (@​danlapid)
  • MCP browser launch failures are now reported when the launcher exits immediately.
  • Debug configuration output now redacts credentials and sensitive headers.
  • Gemini thinking defaults and effort options now match the supported controls across model generations. (@​markmcd)

Thank you to 5 community contributors:

pulumi/pulumi (pulumi)

v3.265.0

Compare Source

Features
  • [cli/auth] Add pulumi logout --all --delete-credentials-key to delete the key that encrypts stored credentials from the OS credential store #​24764
Bug Fixes
  • [programgen/python] Generate valid Python for output-dependent resource ranges #​24474
  • [cli/policy] Recover from partial installs & wait for parallel installs #​24705
  • [cli/install] Cancel cross-process waits with Ctrl-C #​24711
  • [engine] Report Unknown=true on the ReadResourceResponse when a Read is skipped because one of its dependencies failed during a --continue-on-error update, so SDKs can propagate unknowns to dependents rather than treating empty outputs as real #​24747
  • [cli/auth] Keep encrypted credentials in other PULUMI_HOME directories readable after pulumi logout --all or pulumi login in one of them #​24764
  • [engine] Report Unknown=true on the register response when an Import step is skipped because one of its dependencies failed during a --continue-on-error update, so SDKs propagate unknowns to dependents rather than treating empty outputs as real #​24774
  • [sdkgen/nodejs] Fix generated Node.js SDK compilation for self-referencing resource inputs #​24752
  • [pcl] Fix a panic when a PCL program indexes a tuple literal with an index equal to its length #​24755
  • [pcl] Fix a binder panic on nested tuple literals of different shapes, and unify collection literals that hold different constants into one collection type so they can be iterated #​24756
  • [pcl] Fix the length built-in in the PCL interpreter to accept objects and maps #​24757
  • [pcl] Add the range built-in to the PCL interpreter #​24758
  • [pcl] Type min and max as number when any argument is a non-integer literal #​24759
  • [pcl] Report an error when a number or bool literal is assigned to a property whose schema constant or enum does not admit it #​24761
  • [pcl] Report a type mismatch on a resource input property that the resource does not also declare as an output #​24765
  • [pcl] Allow a resource to be assigned to a plain property typed as a reference to its resource type #​24763
  • [pcl] Type a quoted string with no interpolation as a constant so string constants and string enums are validated at bind time #​24766
  • [programgen] Fix length on output values in generated programs, and count the keys of maps and objects in generated Node.js programs #​24757
  • [sdk/go] Fix policy analyzer config schema serialization for Go analyzers #​24775
  • [programgen] Fill the lists that range produces in Node.js programs #​24758
  • [pcl] Fix PCL type conversion checks whose result depended on whether the same types had been unified first #​24793
  • [sdk/nodejs] Fix closure serialization for __importStar-wrapped cached modules #​24797
Improvements
  • [pcl] Name the constant or the enum members a resource property admits when a literal does not match it #​24770
  • [cli/install] Authenticode-sign the Windows CLI and language host binaries #​24785
python/cpython (python)

v3.14.7

Compare Source

v3.14.6

Compare Source

v3.14.5

Compare Source

v3.14.4

Compare Source

v3.14.3

Compare Source

v3.14.2

Compare Source

v3.14.1

Compare Source

v3.14.0

Compare Source

hashicorp/terraform (terraform)

v1.16.4

Compare Source

1.16.4 (September 23, 2026)

BUG FIXES:

  • Fixed an issue where Terraform fails when rendering policy evaluation outcomes for older versions of Terraform Enterprise (#​39095)

  • stacks: Fix invalid deferred error triggered by provider returning a deferral when a resource also has an unknown count/for_each. (#​39237)

v1.16.3

Compare Source

1.16.3 (September 16, 2026)

BUG FIXES:

  • Fix handling of destroy=false around create_before_destroy instances (#​39169)

  • Fix function result comparison when there are multiple marks (#​39170)

  • Filter logic for marks could cause values with multiple marks to erroneously fail validations (#​39171)

  • Fix issue with import provider resolution (#​39185)

v1.16.2

Compare Source

1.16.2 (September 9, 2026)

BUG FIXES:

  • Fix panic in module installation when encoutering invalid module calls (#​39129)

v1.16.1

Compare Source

1.16.1 (September 2, 2026)

BUG FIXES:

  • cloud: Fixed a bug causing the CLI to pause indefinitely after a run task failure with pending policy evaluations (#​38751)

  • Support referencing modules containing dynamic sources in Terraform Test (#​38950)

  • stacks: Fixed validation to ensure the provider versions in the lock file and configuration are compatible. (#​38829)

  • Fix panic when import identity references sensitive value (#​39013)

  • import: Fixed a bug where import blocks would be ignored when multiple imports targeted different instances of a resource config using for_each or count. (#​39068)

  • state show: Fix a panic when given an attribute path instead of a resource instance address (#​39087)

  • Fix create_before_destroy ordering in some combinations of changes (#​39091)

v1.16.0

Compare Source

1.16.0 (August 26, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#​37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#​38298)

  • Providers can now use nested blocks as computed values (#​38305)

  • import: import blocks inside modules are now supported. (#​38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#​38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#​38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#​23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#​38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#​38449)

  • stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#​38668)

  • Actions can now use before_destroy and after_destroy events. (#​38668)

  • cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#​38715)

  • policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#​38716)

  • graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#​38719)

  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#​38778)

  • Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#​38784)

  • The contains() function can now test for null values. (#​38792)

  • console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#​31861)

  • -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#​38845)

  • The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#​38896)

BUG FIXES:

  • import blocks now correctly respect provider local names. (#​38338)

  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#​38586)

  • workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#​38594)

  • test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#​38603)

  • init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#​38634)

  • init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#​38656)

  • Actions are now invoked with respect to all resource dependencies. (#​38668)

  • Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#​38782)

  • The merge() function no longer panics when passed null objects. (#​38792)

  • Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid (#​38894)

  • test: Optional ephemeral values do not have to be set at plan time (#​38974)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#​38561)

UPGRADE NOTES:

  • bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#​38318)

Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.15.9

Compare Source

1.15.9 (August 19, 2026)

BUG FIXES:

  • validate: Child module validation has been fixed and will now raise errors or warning diagnostics for invalid blocks. (list, import, backend, and cloud) (#​38994)

NOTES:

  • Update go-slug to v0.18.3 to mitigate CVE-2026-14978, which is a Unicode normalization issue that could lead to files not being correctly excluded via .terraformignore from upload to a Terraform Enterprise or HCP Terraform during a run (#​39036)
astral-sh/uv (uv)

v0.12.21

Compare Source

Released on 2026-09-29.

Python
  • Update CPython to use OpenSSL 3.5.9 (#​22076)
Enhancements
  • Omit empty [manifest] tables from lockfiles that contain only manifest subtables (#​22070)
Preview features
  • Omit redundant runtime constraints from uv.lock, including those involving pre-releases, with the resolution-inputs preview feature (#​22004, #​22068)
Bug fixes
  • Prevent uv python pin --rm from removing a global .python-versions file without --global (#​21992)
  • Fix installed-package checks incorrectly reporting post-releases as incompatible with exclusive lower bounds on pre-releases (#​22049)

v0.12.20

Compare Source

Released on 2026-09-28.

Enhancements
  • Reuse lockfiles when dependency declarations are semantically equivalent (#​21951)
  • Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs (#​21990)
Preview features
  • Write normalized requirement declarations with the lockfile-normalization preview feature (#​21951)
  • Honor synthetic default groups when installing or syncing from pylock.toml (#​22003)
  • Resolve local paths in exported pylock.toml files relative to the output file (#​22042)
  • Install each package only once when repeated tool-install-locks requirements resolve to the same package (#​22000)
  • Reuse lock-without-metadata lockfiles for conflicting groups with distinct base and extra requirement specifiers (#​22055)
  • Use consistent root-package paths in uv workspace metadata and uv tree --format json output (#​22050)
Configuration
  • Continue searching XDG_CONFIG_DIRS after empty entries (#​21987)
Performance
  • Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems (#​22051)
Bug fixes
  • Apply hash constraints to every repeated requirement under --require-hashes and --verify-hashes (#​21996)
  • Allow metadata builds for first-party workspace projects under --no-build (#​21988)
  • Honor project exclusion flags with --all-packages, including --no-install-project and --no-emit-project (#​21994)
  • Restore pyproject.toml if uv upgrade fails or is interrupted (#​21983)
  • Generate working Nushell activation scripts for relocatable virtual environments (#​21979)
  • Prevent commands from running and changing state after displaying --show-settings (#​21989)
  • Treat UTF-16 requirements files containing only a byte-order mark as empty (#​21991)
  • Ignore unrecognized managed-Python implementation directories during uv python list and uv python upgrade instead of panicking (#​22033)
  • Avoid panics and incorrect rewriting when managed Python sysconfig paths merely start with /install (#​22036)
  • Report whitespace-only non-ASCII requirements as invalid instead of panicking (#​22035)
  • Avoid a resolver panic when trace logging an always-false constraint (#​22034)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@missingcharacter
missingcharacter merged commit c9070d5 into main Sep 30, 2026
1 check passed
@missingcharacter
missingcharacter deleted the renovate/all branch September 30, 2026 15:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants