Update all dependencies - #37
Open
missingcharacter wants to merge 1 commit into
Open
missingcharacter wants to merge 1 commit into
missingcharacter wants to merge 1 commit into
Conversation
missingcharacter
force-pushed
the
renovate/all
branch
2 times, most recently
from
October 3, 2026 01:44
8ea7712 to
abef5bf
Compare
missingcharacter
force-pushed
the
renovate/all
branch
from
October 4, 2026 02:25
abef5bf to
73ffeea
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.8.1→5.8.21.18.33→2.0.223.265.0→3.267.03.13.15→3.14.81.98.1→1.99.02.0.9→2.0.101.15.8→1.16.50.12.21→0.12.23Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
kubernetes-sigs/kustomize (kustomize)
v5.8.2Compare Source
Introduction
In this release, we implemented refactoring to update dependencies and add new features.
This release adds the
kustomize edit add configurationandkustomize edit remove componentcommands. #6037 #6083The built-in OpenAPI schema is now loaded from a pre-compiled bundle embedded in the binary. #6190
The schema itself is still based on Kubernetes v1.21.2, so the output of
kustomize buildis not expected to change. If you notice any difference, please file an issue.Feature
#6037: feat: add support for 'kustomize edit add configuration' command
#6083: Add kustomize edit remove component command
fix
#6263: fix: report an error when the fetched openapi schema is not JSON
Dependencies
#6075: update go 1.25.7
#6078: bump go-git and x/crypt
#6085: update otel lib to v1.40.0
#6134: drop 'go-spew' dependencies and update dependencies
#6138: bump k8s.io/kube-openapi, drop github.com/mailru/easyjson
#6186: bump/go v1.26.5
#6187: update vuln dependencies at 2026/07
#6236: chore: bump stretch/testify pkg to remove old yaml dependencies
#6248: build(deps): bump golang.org/x/text from 0.38.0 to 0.41.0
#6249: build(deps): bump go.yaml.in/yaml/v2 from 2.4.2 to 2.4.4
#6251: build(deps): bump github.com/go-errors/errors from 1.4.2 to 1.5.1
#6254: build(deps): bump github.com/google/gnostic-models from 0.7.0 to 0.7.1
#6255: build(deps): bump google.golang.org/protobuf from 1.36.11 to 1.36.12
#6256: build(deps): bump golang.org/x/sys from 0.45.0 to 0.47.0
#6266: build(deps): bump golang.org/x/text from 0.41.0 to 0.42.0
#6267: build(deps): bump golang.org/x/sys from 0.47.0 to 0.48.0
#6273: bump go-git, kin-openapi and k8s.io
chore
#6190: chore: refactor read scheme to openapi from kubernetes api definition
#6274: build: use the golangci-lint v2 with release binary
#6305: Update kyaml to v0.21.2
#6306: Update cmd/config to v0.21.2
#6307: Update api to v0.21.2
anomalyco/opencode (opencode)
v2.0.22Compare Source
v2.0.21Compare Source
v2.0.20Compare Source
v2.0.19Compare Source
v2.0.18Compare Source
v2.0.17Compare Source
v2.0.16Compare Source
v2.0.15Compare Source
v2.0.14Compare Source
v2.0.13Compare Source
v2.0.12Compare Source
v2.0.11Compare Source
v2.0.10Compare Source
v2.0.9Compare Source
v2.0.8Compare Source
v2.0.7Compare Source
v2.0.6Compare Source
v2.0.5Compare Source
v2.0.4Compare Source
v2.0.3Compare Source
v2.0.2Compare Source
v2.0.1Compare Source
v2.0.0Compare Source
v1.18.34Compare Source
Core
Bugfixes
Thank you to 3 community contributors:
pulumi/pulumi (pulumi)
v3.267.0Compare Source
Bug Fixes
pulumi newruns failing to clone the templates repository #24939pulumi installfor Python plugins and policy packs that use the uv toolchain and a[build-system]table #24951v3.266.0Compare Source
Bug Fixes
pulumi newcredentials warning #24925Improvements
pulumi neopulumi_preview/pulumi_up tool results #24721#/providerdoc references in schema descriptions #24918Miscellaneous
workspace.Credentials.AccessTokensand read stored logins only from theaccountsobject ofcredentials.json#24922python/cpython (python)
v3.14.8Compare Source
v3.14.7Compare Source
v3.14.6Compare Source
v3.14.5Compare Source
v3.14.4Compare Source
v3.14.3Compare Source
v3.14.2Compare Source
v3.14.1Compare Source
v3.14.0Compare Source
v3.13.16Compare Source
rust-lang/rust (rust)
v1.99.0Compare Source
==========================
Language
raw_borrows_via_referenceslint that checks for references that decay immediately into raw borrowsunconditional_paniclint to function calls that panic when the chunks/windows size is zero#[unsafe(naked)]functions to define C-variadic functions (#![feature(c_variadic_naked_functions)]).Sized#[my_macro] mod foo;. This allows outlined modules (mod foo;) anywhere in the body of a custom attribute or derive macro.overflowing_literalslint with repeated negation. For instance, it will now no longer lint on--128_i8, which is already detected by thearithmetic_overflowlint.invalid_runtime_symbol_definitionsandsuspicious_runtime_symbol_definitionslints#[path]attributes on inline modulesunreachable_cfg_select_predicateslint as part ofunusedlint groupasm!on x86UnsafeCellcan be accessed without going throughgetinvalid_reference_castinglint was adjusted accordinglyglobal_asm!docattribute is used on a macro invocationCompiler
-Ctarget-cpuinto a target-modifier for AVR, AMDGCN and NVPTXstatic_position_independent_executableson all gnu targetsPlatform Support
riscv64-unknown-linux-muslto Tier 2 with host toolsRefer to Rust's platform support page
for more information on Rust's tiered platform support.
Libraries
RangeInclusive(a..=branges) is now optimized better in some circumstances. As a side effect of this, the behavior ofRangeInclusivevalues that has already been exhausted (as an iterator) has changed. For example, the return values ofstart()andend()on such ranges may return different values, and using such ranges as slice indexes may have different behavior. These behaviors were not guaranteed to be stable, so these changes are considered to not be breaking changes.transmute_copyto accept?Sizedtypestransmute_copyto use a non-unwinding panicescape_debug_extcore::fmt::NumBufferinalloc(andstd)Stabilized APIs
IntoIteratorforBox<[T; N]>IntoIteratorfor&Box<[T; N]>IntoIteratorfor&mut Box<[T; N]>VecDeque::retain_backcore::ffi::VaListBox::into_non_nullBox::from_non_nullVec::into_partsVec::from_partscore::mem::size_of_val_rawcore::mem::align_of_val_rawcore::alloc::Layout::for_value_rawString::from_utf8_lossy_ownedstring::FromUtf8Error::into_utf8_lossyFusedIterator for StepBy<I>std::fs::set_timesstd::fs::set_times_nofollowCargo
debug. This is a preparation for transitioning thedevprofile away from debugging to give a saner default for faster development iterations. Currently there is no difference betweendevanddebugprofiles. docs #17214default-featuresfield. For example,serde = { workspace = true, default-features = false }now turns off default features even when the workspace definition enables them. On earlier editions,default-features = falseis ignored with a warning. (RFC 3945) #17126See also the full Cargo changelog
Rustdoc
unused_footnote_definitionrustdoc lintCompatibility Notes
std::i32::MAXshould be accessed viai32::MAXinstead.no_mangle_generic_itemsinto hard errorPin::new_uncheckedhas had its safety invariants changed slightlyletpatterns typecheckunsupported()instead offrom_raw_os_error(22)#[repr(simd)]was accidentally allowed on macro invocations on stable RustBox::leak: tell people to avoid unleakingdoc(cfg())into account when filtering doctests'staticsemicolon_in_expressions_from_non_local_macros) even when the macro comes from another crate. Previously, such warnings only appeared for macros from the same crate, to avoid showing warnings that can't be fixed locally; however, this masked problems, as integration tests from the crate providing the macro get compiled as a separate crate, so tests often wouldn't reveal this issue. If you encounter a lint like this, please make sure to report it to the crate providing the macro so they can fix it; don't just silence it in your own crate.semicolon_in_expressions_from_macros: Lint on non-local macros toosemicolon_in_expressions_from_macrosinto a separate lintCIenvironment variable. #17220Internal Changes
These changes do not affect any public interfaces of Rust, but they represent
significant improvements to the performance or internals of rustc and related
tools.
sbt/sbt (sbt)
v2.0.10: 2.0.10Compare Source
changes with compatibility implications
sbtrunner script honorsJAVA_HOMEenvironment variable by @anatoliykmetyuk in #9825🚀 updates
🐛 bug fixes
pausefrom standard input by @anatoliykmetyuk in #9824behind the scenes
Full Changelog: sbt/sbt@v2.0.9...v2.0.10
hashicorp/terraform (terraform)
v1.16.5Compare Source
1.16.5 (September 30, 2026)
BUG FIXES:
Fixed a crash that happens when a tainted instance state is seen without a valid status (#39287)
resource-identity: fixed an issue where resource identity could be nil during delete (#39285)
v1.16.4Compare Source
1.16.4 (September 23, 2026)
BUG FIXES:
Fixed an issue where Terraform fails when rendering policy evaluation outcomes for older versions of Terraform Enterprise (#39095)
stacks: Fix invalid deferred error triggered by provider returning a deferral when a resource also has an unknown count/for_each. (#39237)
v1.16.3Compare Source
1.16.3 (September 16, 2026)
BUG FIXES:
Fix handling of destroy=false around create_before_destroy instances (#39169)
Fix function result comparison when there are multiple marks (#39170)
Filter logic for marks could cause values with multiple marks to erroneously fail validations (#39171)
Fix issue with import provider resolution (#39185)
v1.16.2Compare Source
1.16.2 (September 9, 2026)
BUG FIXES:
v1.16.1Compare Source
1.16.1 (September 2, 2026)
BUG FIXES:
cloud: Fixed a bug causing the CLI to pause indefinitely after a run task failure with pending policy evaluations (#38751)
Support referencing modules containing dynamic sources in Terraform Test (#38950)
stacks: Fixed validation to ensure the provider versions in the lock file and configuration are compatible. (#38829)
Fix panic when import identity references sensitive value (#39013)
import: Fixed a bug where import blocks would be ignored when multiple imports targeted different instances of a resource config using
for_eachorcount. (#39068)state show: Fix a panic when given an attribute path instead of a resource instance address (#39087)
Fix create_before_destroy ordering in some combinations of changes (#39091)
v1.16.0Compare Source
1.16.0 (August 26, 2026)
NEW FEATURES:
Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)
terraform_data: The newstoreblock can hold ephemeral and sensitive values across plan and apply. (#38298)Providers can now use nested blocks as computed values (#38305)
import:
importblocks inside modules are now supported. (#38352)Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)
Resource action triggers can now use
on_failuremodes ofhalt,taint, orcontinue. (#38722)ENHANCEMENTS:
state show: The
state showcommand can now produce machine-readable output when supplied with the-jsonflag (#23940)workspace: The
workspace listcommand can now produce machine-readable output when supplied with the-jsonflag (#38397)test: Terraform now reports which resources were left behind when
skip_cleanupis set. (#38449)stacks: Action configurations now have access to a
callersymbol containing the object value of the calling resource. (#38668)Actions can now use
before_destroyandafter_destroyevents. (#38668)cloud: Terraform now displays a summary of policy evaluation outcomes for
planandapplyruns against HCP Terraform. (#38715)policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during
init,plan, andapply, rather than requiring the plugin to read credentials itself. (#38716)graph: The
terraform graphcommand can now output graphs in Mermaid format using the-format=mermaidflag. (#38719)Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)
Resource
lifecycleblocks now supportdestroy = falseto prevent a resource from being destroyed. (#38784)The
contains()function can now test fornullvalues. (#38792)console: The
terraform consolecommand now accepts an optional-scope=<module address>flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)-invokecan now be combined with-targetto specify the calling resource instance when multiple resources trigger the same action. (#38845)The
terraform stackscommand now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neitherTF_STACKS_HOSTNAMEnorTF_CLOUD_HOSTNAMEis set (#38896)BUG FIXES:
importblocks now correctly respect provider local names. (#38338)terraform applyno longer panics when the plan contains a no-op change for a deposed resource that haslifecycle.preconditionorlifecycle.postconditionblocks. (#38586)workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)
test: Terraform now raises a warning when a file referenced via the
-filterflag does not exist. (#38603)init: Terraform no longer removes locks from the dependency lock file for providers configured as
dev_override. (#38634)init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)
Actions are now invoked with respect to all resource dependencies. (#38668)
Terraform now returns the correct error when an
importtarget exists in state but has no corresponding configuration. (#38782)The
merge()function no longer panics when passednullobjects. (#38792)Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid (#38894)
test: Optional ephemeral values do not have to be set at plan time (#38974)
NOTES:
-upgradeand-lockfile=readonlyflags are now raised earlier in the init process. (#38561)UPGRADE NOTES:
bastion_host_keyis now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)Previous Releases
For information on prior major and minor releases, refer to their changelogs:
v1.15.9Compare Source
1.15.9 (August 19, 2026)
BUG FIXES:
list,import,backend, andcloud) (#38994)NOTES:
.terraformignorefrom upload to a Terraform Enterprise or HCP Terraform during a run (#39036)astral-sh/uv (uv)
v0.12.23Compare Source
Released on 2026-10-03.
Python
Preview features
uv.lockwithout a workspace manifest usinguv sync --frozenwithfrozen-lockfile(#22018)uv.lockwithout a workspace manifest usinguv export --frozenwithfrozen-lockfile(#22007)uv.lockwithout a workspace manifest usinguv tree --frozenwithfrozen-lockfile(#22016)uv.lockwithout a workspace manifest usinguv workspace metadata --frozenwithfrozen-lockfile(#22017, #22018)Bug fixes
win_amd64wheels instead of building from source (#22099)v0.12.22Compare Source
Released on 2026-10-01.
Python
Enhancements
--offlineoption fromuv publishhelp (#22124)Preview features
--no-default-groupsinuv audit(#22090)uv auditoruv tool auditruns offline and hide the unsupported option from help (#22114)Configuration
UV_PYTHON_ARCHto select an interpreter architecture independently of its Python version (#22098)Performance
Bug fixes
Other changes
Configuration
📅 Schedule: (UTC)
* 0-3 * * *)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.