Skip to content

Update all dependencies - #37

Open
missingcharacter wants to merge 1 commit into
mainfrom
renovate/all
Open

missingcharacter wants to merge 1 commit into
mainfrom
renovate/all

Conversation

@missingcharacter

@missingcharacter missingcharacter commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

This PR contains the following updates:

Package Type Update Change
kustomize tools patch 5.8.1 → 5.8.2
opencode tools major 1.18.33 → 2.0.22
pulumi tools minor 3.265.0 → 3.267.0
python tools minor 3.13.15 → 3.14.8
rust (source, changelog) tools minor 1.98.1 → 1.99.0
sbt tools patch 2.0.9 → 2.0.10
terraform tools minor 1.15.8 → 1.16.5
uv tools patch 0.12.21 → 0.12.23

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

kubernetes-sigs/kustomize (kustomize)

v5.8.2

Compare Source

Introduction

In this release, we implemented refactoring to update dependencies and add new features.

This release adds the kustomize edit add configuration and kustomize edit remove component commands. #​6037 #​6083
The built-in OpenAPI schema is now loaded from a pre-compiled bundle embedded in the binary. #​6190
The schema itself is still based on Kubernetes v1.21.2, so the output of kustomize build is not expected to change. If you notice any difference, please file an issue.

Feature

#​6037: feat: add support for 'kustomize edit add configuration' command
#​6083: Add kustomize edit remove component command

fix

#​6263: fix: report an error when the fetched openapi schema is not JSON

Dependencies

#​6075: update go 1.25.7
#​6078: bump go-git and x/crypt
#​6085: update otel lib to v1.40.0
#​6134: drop 'go-spew' dependencies and update dependencies
#​6138: bump k8s.io/kube-openapi, drop github.com/mailru/easyjson
#​6186: bump/go v1.26.5
#​6187: update vuln dependencies at 2026/07
#​6236: chore: bump stretch/testify pkg to remove old yaml dependencies
#​6248: build(deps): bump golang.org/x/text from 0.38.0 to 0.41.0
#​6249: build(deps): bump go.yaml.in/yaml/v2 from 2.4.2 to 2.4.4
#​6251: build(deps): bump github.com/go-errors/errors from 1.4.2 to 1.5.1
#​6254: build(deps): bump github.com/google/gnostic-models from 0.7.0 to 0.7.1
#​6255: build(deps): bump google.golang.org/protobuf from 1.36.11 to 1.36.12
#​6256: build(deps): bump golang.org/x/sys from 0.45.0 to 0.47.0
#​6266: build(deps): bump golang.org/x/text from 0.41.0 to 0.42.0
#​6267: build(deps): bump golang.org/x/sys from 0.47.0 to 0.48.0
#​6273: bump go-git, kin-openapi and k8s.io

chore

#​6190: chore: refactor read scheme to openapi from kubernetes api definition
#​6274: build: use the golangci-lint v2 with release binary
#​6305: Update kyaml to v0.21.2
#​6306: Update cmd/config to v0.21.2
#​6307: Update api to v0.21.2

anomalyco/opencode (opencode)

v2.0.22

Compare Source

v2.0.21

Compare Source

v2.0.20

Compare Source

v2.0.19

Compare Source

v2.0.18

Compare Source

v2.0.17

Compare Source

v2.0.16

Compare Source

v2.0.15

Compare Source

v2.0.14

Compare Source

v2.0.13

Compare Source

v2.0.12

Compare Source

v2.0.11

Compare Source

v2.0.10

Compare Source

v2.0.9

Compare Source

v2.0.8

Compare Source

v2.0.7

Compare Source

v2.0.6

Compare Source

v2.0.5

Compare Source

v2.0.4

Compare Source

v2.0.3

Compare Source

v2.0.2

Compare Source

v2.0.1

Compare Source

v2.0.0

Compare Source

v1.18.34

Compare Source

Core

Bugfixes
  • Send namespaced session and parent-session identity headers with model requests.
  • Re-sign locally compiled macOS binaries so they run reliably on macOS 27+. (@​ryangamerdev)
  • Sign macOS CLI release binaries with a Developer ID.

Thank you to 3 community contributors:

pulumi/pulumi (pulumi)

v3.267.0

Compare Source

Bug Fixes
  • [cli/new] Fix concurrent pulumi new runs failing to clone the templates repository #​24939
  • [sdk/python] Fix pulumi install for Python plugins and policy packs that use the uv toolchain and a [build-system] table #​24951

v3.266.0

Compare Source

Bug Fixes
  • [sdk/go] Use an explicit provider for resources from an extension package, instead of falling back to a default provider #​24702
  • [sdk/python] Use an explicit provider for resources from an extension package, instead of falling back to a default provider #​24702
  • [pcl] Order the members of a union type by a fixed structural order rather than by their printed form, so that a recursive object type prints all of its properties and diagnostics list union members consistently #​24804
  • [cli/new] Avoid printing the provider docs link twice in the pulumi new credentials warning #​24925
Improvements
  • [cli/neo] Report the console URL and update identifiers in pulumi neo pulumi_preview/pulumi_up tool results #​24721
  • [sdkgen] Support #/provider doc references in schema descriptions #​24918
Miscellaneous
  • [sdk/go] Remove workspace.Credentials.AccessTokens and read stored logins only from the accounts object of credentials.json #​24922
  • [sdk/dotnet] Upgrade dotnet to v3.114.1 #​24926
  • [java] Upgrade java to v1.37.3 #​24926
  • [yaml] Upgrade yaml to v1.38.8 #​24926
  • [hcl] Upgrade hcl to v0.18.3 #​24926
python/cpython (python)

v3.14.8

Compare Source

v3.14.7

Compare Source

v3.14.6

Compare Source

v3.14.5

Compare Source

v3.14.4

Compare Source

v3.14.3

Compare Source

v3.14.2

Compare Source

v3.14.1

Compare Source

v3.14.0

Compare Source

v3.13.16

Compare Source

rust-lang/rust (rust)

v1.99.0

Compare Source

==========================

Language

Compiler

Platform Support

Refer to Rust's platform support page
for more information on Rust's tiered platform support.

Libraries

Stabilized APIs

Cargo

  • Add a new built-in profile debug. This is a preparation for transitioning the dev profile away from debugging to give a saner default for faster development iterations. Currently there is no difference between dev and debug profiles. docs #​17214
  • Workspace members on edition 2024 or later can now override an inherited workspace dependency's default-features field. For example, serde = { workspace = true, default-features = false } now turns off default features even when the workspace definition enables them. On earlier editions, default-features = false is ignored with a warning. (RFC 3945) #​17126

See also the full Cargo changelog

Rustdoc

Compatibility Notes

Internal Changes

These changes do not affect any public interfaces of Rust, but they represent
significant improvements to the performance or internals of rustc and related
tools.

sbt/sbt (sbt)

v2.0.10: 2.0.10

Compare Source

changes with compatibility implications

🚀 updates

🐛 bug fixes

behind the scenes

Full Changelog: sbt/sbt@v2.0.9...v2.0.10

hashicorp/terraform (terraform)

v1.16.5

Compare Source

1.16.5 (September 30, 2026)

BUG FIXES:

  • Fixed a crash that happens when a tainted instance state is seen without a valid status (#​39287)

  • resource-identity: fixed an issue where resource identity could be nil during delete (#​39285)

v1.16.4

Compare Source

1.16.4 (September 23, 2026)

BUG FIXES:

  • Fixed an issue where Terraform fails when rendering policy evaluation outcomes for older versions of Terraform Enterprise (#​39095)

  • stacks: Fix invalid deferred error triggered by provider returning a deferral when a resource also has an unknown count/for_each. (#​39237)

v1.16.3

Compare Source

1.16.3 (September 16, 2026)

BUG FIXES:

  • Fix handling of destroy=false around create_before_destroy instances (#​39169)

  • Fix function result comparison when there are multiple marks (#​39170)

  • Filter logic for marks could cause values with multiple marks to erroneously fail validations (#​39171)

  • Fix issue with import provider resolution (#​39185)

v1.16.2

Compare Source

1.16.2 (September 9, 2026)

BUG FIXES:

  • Fix panic in module installation when encoutering invalid module calls (#​39129)

v1.16.1

Compare Source

1.16.1 (September 2, 2026)

BUG FIXES:

  • cloud: Fixed a bug causing the CLI to pause indefinitely after a run task failure with pending policy evaluations (#​38751)

  • Support referencing modules containing dynamic sources in Terraform Test (#​38950)

  • stacks: Fixed validation to ensure the provider versions in the lock file and configuration are compatible. (#​38829)

  • Fix panic when import identity references sensitive value (#​39013)

  • import: Fixed a bug where import blocks would be ignored when multiple imports targeted different instances of a resource config using for_each or count. (#​39068)

  • state show: Fix a panic when given an attribute path instead of a resource instance address (#​39087)

  • Fix create_before_destroy ordering in some combinations of changes (#​39091)

v1.16.0

Compare Source

1.16.0 (August 26, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#​37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#​38298)

  • Providers can now use nested blocks as computed values (#​38305)

  • import: import blocks inside modules are now supported. (#​38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#​38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#​38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#​23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#​38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#​38449)

  • stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#​38668)

  • Actions can now use before_destroy and after_destroy events. (#​38668)

  • cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#​38715)

  • policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#​38716)

  • graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#​38719)

  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#​38778)

  • Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#​38784)

  • The contains() function can now test for null values. (#​38792)

  • console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#​31861)

  • -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#​38845)

  • The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#​38896)

BUG FIXES:

  • import blocks now correctly respect provider local names. (#​38338)

  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#​38586)

  • workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#​38594)

  • test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#​38603)

  • init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#​38634)

  • init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#​38656)

  • Actions are now invoked with respect to all resource dependencies. (#​38668)

  • Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#​38782)

  • The merge() function no longer panics when passed null objects. (#​38792)

  • Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid (#​38894)

  • test: Optional ephemeral values do not have to be set at plan time (#​38974)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#​38561)

UPGRADE NOTES:

  • bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#​38318)

Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.15.9

Compare Source

1.15.9 (August 19, 2026)

BUG FIXES:

  • validate: Child module validation has been fixed and will now raise errors or warning diagnostics for invalid blocks. (list, import, backend, and cloud) (#​38994)

NOTES:

  • Update go-slug to v0.18.3 to mitigate CVE-2026-14978, which is a Unicode normalization issue that could lead to files not being correctly excluded via .terraformignore from upload to a Terraform Enterprise or HCP Terraform during a run (#​39036)
astral-sh/uv (uv)

v0.12.23

Compare Source

Released on 2026-10-03.

Python
Preview features
  • Sync from uv.lock without a workspace manifest using uv sync --frozen with frozen-lockfile (#​22018)
  • Export from uv.lock without a workspace manifest using uv export --frozen with frozen-lockfile (#​22007)
  • Inspect dependency trees from uv.lock without a workspace manifest using uv tree --frozen with frozen-lockfile (#​22016)
  • Inspect workspace metadata and optionally sync its environment from uv.lock without a workspace manifest using uv workspace metadata --frozen with frozen-lockfile (#​22017, #​22018)
Bug fixes
  • Reject alternate sources for workspace members across conflicting dependency selections, avoiding lockfiles that cannot be installed (#​22153)
  • Allow x86-64 Python interpreters running under emulation on Windows ARM64 to install compatible win_amd64 wheels instead of building from source (#​22099)

v0.12.22

Compare Source

Released on 2026-10-01.

Python
  • Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8 (#​22147)
Enhancements
  • Accept uppercase release suffixes in wheel platform tags (#​22113)
  • Record workspace-member default groups in lockfiles (#​22010, #​22103)
  • Record workspace-member dependency-group Python requirements in lockfiles (#​22044, #​22103)
  • Record default groups for non-project workspace roots in lockfiles (#​22104)
  • Record dependency-group Python requirements for non-project workspace roots in lockfiles (#​22104)
  • Format URLs and paths consistently in CLI messages (#​21937)
  • Hide the unsupported --offline option from uv publish help (#​22124)
Preview features
  • Honor --no-default-groups in uv audit (#​22090)
  • Report a clear error when uv audit or uv tool audit runs offline and hide the unsupported option from help (#​22114)
Configuration
  • Add UV_PYTHON_ARCH to select an interpreter architecture independently of its Python version (#​22098)
Performance
  • Reduce uv's binary size by compressing embedded Python download metadata (#​22126)
Bug fixes
  • Verify unchanged requirements against existing lockfile hashes when relocking (#​22083)
  • Honor dependency-group Python requirements at non-project workspace roots (#​22101)
  • Use each selected workspace member's recorded default groups during frozen sync (#​22015)
  • Avoid false entry-point warnings for required workspace members (#​22112)
Other changes
  • Raise the minimum supported Rust version for building uv to 1.97 and update the toolchain to Rust 1.99 (#​22121)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@missingcharacter
missingcharacter force-pushed the renovate/all branch 2 times, most recently from 8ea7712 to abef5bf Compare October 3, 2026 01:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants