Skip to content

Update product-os/flowzone action to v23 - #712

Open
klutchell-renovate[bot] wants to merge 2 commits into
mainfrom
renovate/product-os-flowzone-23.x
Open

Update product-os/flowzone action to v23#712
klutchell-renovate[bot] wants to merge 2 commits into
mainfrom
renovate/product-os-flowzone-23.x

Conversation

@klutchell-renovate

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
product-os/flowzone action major v22.12.91v23.0.8

Release Notes

product-os/flowzone (product-os/flowzone)

v23.0.8

Compare Source

Update dependency docker/buildx to v0.36.0

Notable changes
  • CrazyMax
  • Tõnis Tiigi
  • Sebastiaan van Stijn
  • MohammadHasan Akbari
  • Matt Van Horn
  • amarkdotdev
  • Areeb Ahmed
  • Guillaume Lours
  • Paweł Gronowski
  • Pierre Gimalac
  • s3onghyun
  • Default source policy can now validate the authenticity of BuildKit release images when creating docker-container builder with docker buildx create command. #​3961
  • Bake command now supports overriding declared secret sources. #​3962
  • Broken builder instances are now correctly handled on removal. #​3934
  • Bake now supports resolving files relative to the bake file location instead of the current working directory with BUILDX_BAKE_FILE_RELATIVE_PATHS=true. #​3935
  • Source policies now support new array.flatten builtin and OPA template strings. #​3913
  • Imagetools commands now do extra validation of the descriptor inputs from files. #​3933
  • Windows release binaries are now code-signed, matching the signing coverage already provided for macOS release artifacts. #​3978
  • Compose compatibility has been updated to v2.13.0. #​3929
  • Fix source policy support on Windows when loading local files inside policy. #​3944
  • Fix Kubernetes driver random load balancer support. #​3861
  • Fix Kubernetes driver builds hanging indefinitely when the remote exec stream ends. #​3966
  • Fix iidfile for containerd-backed Docker driver. #​3952
  • Fix authority pseudo-header when using remote driver. #​3928
  • Fix possible FD leak when using source policies. #​3943
  • github.com/Microsoft/go-winio v0.6.2 -> ad3df93
  • github.com/ProtonMail/go-crypto v1.3.0 -> v1.4.1
  • github.com/aws/aws-sdk-go-v2 v1.42.0 -> v1.43.0
  • github.com/aws/aws-sdk-go-v2/config v1.32.24 -> v1.32.31
  • github.com/aws/aws-sdk-go-v2/credentials v1.19.23 -> v1.19.30
  • github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.29 -> v1.18.31
  • github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.29 -> v1.4.31
  • github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.29 -> v2.7.31
  • github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.30 -> v1.4.32
  • github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.12 -> v1.13.13
  • github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.29 -> v1.13.31
  • github.com/aws/aws-sdk-go-v2/service/signin v1.1.5 -> v1.5.0
  • github.com/aws/aws-sdk-go-v2/service/sso v1.31.3 -> v1.33.0
  • github.com/aws/aws-sdk-go-v2/service/ssooidc v1.36.6 -> v1.38.0
  • github.com/aws/aws-sdk-go-v2/service/sts v1.43.3 -> v1.45.0
  • github.com/aws/smithy-go v1.27.2 -> v1.27.4
  • github.com/compose-spec/compose-go/v2 v2.10.2 -> v2.13.0
  • github.com/containerd/containerd/api v1.10.0 -> v1.11.1
  • github.com/containerd/containerd/v2 v2.2.4 -> v2.3.3
  • github.com/containerd/ttrpc v1.2.8 -> v1.2.9
  • github.com/docker/cli v29.5.3 -> v29.6.2
  • github.com/go-openapi/errors v0.22.7 -> v0.22.8
  • github.com/go-openapi/loads v0.23.3 -> v0.24.0
  • github.com/go-openapi/runtime v0.32.3 -> v0.32.4
  • github.com/go-openapi/spec v0.22.5 -> v0.22.6
  • github.com/go-openapi/strfmt v0.26.3 -> v0.26.4
  • github.com/go-openapi/swag v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/cmdutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/conv v0.26.0 -> v0.27.0
  • github.com/go-openapi/swag/fileutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/jsonname v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/jsonutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/loading v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/mangling v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/netutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/stringutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/typeutils v0.26.0 -> v0.27.0
  • github.com/go-openapi/swag/yamlutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/validate v0.25.3 -> v0.26.0
  • github.com/google/go-containerregistry v0.21.6 -> v0.21.7
  • github.com/klauspost/compress v1.18.6 -> v1.19.1
  • github.com/lestrrat-go/httprc/v3 v3.0.1 -> v3.0.2
  • github.com/lestrrat-go/jwx/v3 v3.0.11 -> v3.0.13
  • github.com/moby/buildkit v0.31.0 -> v0.32.0
  • github.com/moby/go-archive v0.2.0 -> v0.2.1
  • github.com/moby/moby/api v1.54.2 -> v1.55.0
  • github.com/moby/moby/client v0.4.1 -> v0.5.0
  • github.com/moby/policy-helpers d5411a9 -> 856be88
  • github.com/moby/sys/user v0.4.0 -> v0.4.1
  • github.com/open-policy-agent/opa v1.10.1 -> v1.14.1
  • github.com/segmentio/asm v1.2.0 -> v1.2.1
  • github.com/sigstore/rekor v1.5.2 -> v1.5.3
  • github.com/sigstore/rekor-tiles/v2 5d098a2 -> v2.3.0
  • github.com/sigstore/sigstore-go v1.2.1 -> v1.2.2
  • github.com/tonistiigi/fsutil 0257b33 -> 6d9dc2e
  • github.com/valyala/fastjson v1.6.4 -> v1.6.7
  • github.com/vektah/gqlparser/v2 v2.5.30 -> v2.5.32
  • golang.org/x/crypto v0.52.0 -> v0.54.0
  • golang.org/x/mod v0.36.0 -> v0.38.0
  • golang.org/x/net v0.55.0 -> v0.57.0
  • golang.org/x/sync v0.20.0 -> v0.22.0
  • golang.org/x/sys v0.45.0 -> v0.47.0
  • golang.org/x/term v0.43.0 -> v0.45.0
  • golang.org/x/text v0.37.0 -> v0.40.0
  • golang.org/x/tools v0.45.0 -> v0.47.0
  • google.golang.org/grpc v1.81.1 -> v1.82.1
  • google.golang.org/protobuf v1.36.11 -> f2248ac
  • k8s.io/api v0.35.4 -> v0.36.0
  • k8s.io/apimachinery v0.35.4 -> v0.36.0
  • k8s.io/client-go v0.35.4 -> v0.36.0
  • k8s.io/kube-openapi 589584f -> 5883c5e
  • k8s.io/streaming v0.36.0 new
  • k8s.io/utils bc988d5 -> 28399d8
  • sigs.k8s.io/structured-merge-diff/v6 v6.3.0 -> v6.3.2
docker/buildx (docker/buildx)
v0.36.0

Compare Source

Welcome to the v0.36.0 release of buildx!

Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

Contributors
  • CrazyMax
  • Tõnis Tiigi
  • Sebastiaan van Stijn
  • MohammadHasan Akbari
  • Matt Van Horn
  • amarkdotdev
  • Areeb Ahmed
  • Guillaume Lours
  • Paweł Gronowski
  • Pierre Gimalac
  • s3onghyun
Notables Changes
  • Default source policy can now validate the authenticity of BuildKit release images when creating docker-container builder with docker buildx create command. #​3961
  • Bake command now supports overriding declared secret sources. #​3962
  • Broken builder instances are now correctly handled on removal. #​3934
  • Bake now supports resolving files relative to the bake file location instead of the current working directory with BUILDX_BAKE_FILE_RELATIVE_PATHS=true. #​3935
  • Source policies now support new array.flatten builtin and OPA template strings. #​3913
  • Imagetools commands now do extra validation of the descriptor inputs from files. #​3933
  • Windows release binaries are now code-signed, matching the signing coverage already provided for macOS release artifacts. #​3978
  • Compose compatibility has been updated to v2.13.0. #​3929
  • Fix source policy support on Windows when loading local files inside policy. #​3944
  • Fix Kubernetes driver random load balancer support. #​3861
  • Fix Kubernetes driver builds hanging indefinitely when the remote exec stream ends. #​3966
  • Fix iidfile for containerd-backed Docker driver. #​3952
  • Fix authority pseudo-header when using remote driver. #​3928
  • Fix possible FD leak when using source policies. #​3943
Dependency Changes
  • github.com/Microsoft/go-winio v0.6.2 -> ad3df93
  • github.com/ProtonMail/go-crypto v1.3.0 -> v1.4.1
  • github.com/aws/aws-sdk-go-v2 v1.42.0 -> v1.43.0
  • github.com/aws/aws-sdk-go-v2/config v1.32.24 -> v1.32.31
  • github.com/aws/aws-sdk-go-v2/credentials v1.19.23 -> v1.19.30
  • github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.29 -> v1.18.31
  • github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.29 -> v1.4.31
  • github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.29 -> v2.7.31
  • github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.30 -> v1.4.32
  • github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.12 -> v1.13.13
  • github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.29 -> v1.13.31
  • github.com/aws/aws-sdk-go-v2/service/signin v1.1.5 -> v1.5.0
  • github.com/aws/aws-sdk-go-v2/service/sso v1.31.3 -> v1.33.0
  • github.com/aws/aws-sdk-go-v2/service/ssooidc v1.36.6 -> v1.38.0
  • github.com/aws/aws-sdk-go-v2/service/sts v1.43.3 -> v1.45.0
  • github.com/aws/smithy-go v1.27.2 -> v1.27.4
  • github.com/compose-spec/compose-go/v2 v2.10.2 -> v2.13.0
  • github.com/containerd/containerd/api v1.10.0 -> v1.11.1
  • github.com/containerd/containerd/v2 v2.2.4 -> v2.3.3
  • github.com/containerd/ttrpc v1.2.8 -> v1.2.9
  • github.com/docker/cli v29.5.3 -> v29.6.2
  • github.com/go-openapi/errors v0.22.7 -> v0.22.8
  • github.com/go-openapi/loads v0.23.3 -> v0.24.0
  • github.com/go-openapi/runtime v0.32.3 -> v0.32.4
  • github.com/go-openapi/spec v0.22.5 -> v0.22.6
  • github.com/go-openapi/strfmt v0.26.3 -> v0.26.4
  • github.com/go-openapi/swag v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/cmdutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/conv v0.26.0 -> v0.27.0
  • github.com/go-openapi/swag/fileutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/jsonname v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/jsonutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/loading v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/mangling v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/netutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/stringutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/typeutils v0.26.0 -> v0.27.0
  • github.com/go-openapi/swag/yamlutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/validate v0.25.3 -> v0.26.0
  • github.com/google/go-containerregistry v0.21.6 -> v0.21.7
  • github.com/klauspost/compress v1.18.6 -> v1.19.1
  • github.com/lestrrat-go/httprc/v3 v3.0.1 -> v3.0.2
  • github.com/lestrrat-go/jwx/v3 v3.0.11 -> v3.0.13
  • github.com/moby/buildkit v0.31.0 -> v0.32.0
  • github.com/moby/go-archive v0.2.0 -> v0.2.1
  • github.com/moby/moby/api v1.54.2 -> v1.55.0
  • github.com/moby/moby/client v0.4.1 -> v0.5.0
  • github.com/moby/policy-helpers d5411a9 -> 856be88
  • github.com/moby/sys/user v0.4.0 -> v0.4.1
  • github.com/open-policy-agent/opa v1.10.1 -> v1.14.1
  • github.com/segmentio/asm v1.2.0 -> v1.2.1
  • github.com/sigstore/rekor v1.5.2 -> v1.5.3
  • github.com/sigstore/rekor-tiles/v2 5d098a2 -> v2.3.0
  • github.com/sigstore/sigstore-go v1.2.1 -> v1.2.2
  • github.com/tonistiigi/fsutil 0257b33 -> 6d9dc2e
  • github.com/valyala/fastjson v1.6.4 -> v1.6.7
  • github.com/vektah/gqlparser/v2 v2.5.30 -> v2.5.32
  • golang.org/x/crypto v0.52.0 -> v0.54.0
  • golang.org/x/mod v0.36.0 -> v0.38.0
  • golang.org/x/net v0.55.0 -> v0.57.0
  • golang.org/x/sync v0.20.0 -> v0.22.0
  • golang.org/x/sys v0.45.0 -> v0.47.0
  • golang.org/x/term v0.43.0 -> v0.45.0
  • golang.org/x/text v0.37.0 -> v0.40.0
  • golang.org/x/tools v0.45.0 -> v0.47.0
  • google.golang.org/grpc v1.81.1 -> v1.82.1
  • google.golang.org/protobuf v1.36.11 -> f2248ac
  • k8s.io/api v0.35.4 -> v0.36.0
  • k8s.io/apimachinery v0.35.4 -> v0.36.0
  • k8s.io/client-go v0.35.4 -> v0.36.0
  • k8s.io/kube-openapi 589584f -> 5883c5e
  • k8s.io/streaming v0.36.0 new
  • k8s.io/utils bc988d5 -> 28399d8
  • sigs.k8s.io/structured-merge-diff/v6 v6.3.0 -> v6.3.2

Previous release can be found at v0.35.0

List of commits

1410915 (Update dependency docker/buildx to v0.36.0, 2026-07-30)

v23.0.7

Compare Source

aa1a3fd (Stop describing the push trigger as optional, 2026-07-29)
700c37d (Keep 'skip ci' out of the version commit subject, 2026-07-30)

v23.0.6

Compare Source

Update actions/setup-node action to v7

Notable changes
actions/setup-node (actions/setup-node)
v7.0.0

Compare Source

What's Changed
Enhancements:
Bug fixes:
Documentation updates:
Dependency update:
New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

v7

Compare Source

List of commits

310bc9a (Update actions/setup-node action to v7, 2026-07-29)

v23.0.5

Compare Source

Update actions/setup-python action to v7

Notable changes
actions/setup-python (actions/setup-python)
v7.0.0

Compare Source

What's Changed
Enhancements
Bug Fix
Dependency Upgrade
New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

v7

Compare Source

List of commits

db8a4c0 (Update actions/setup-python action to v7, 2026-07-29)

v23.0.4

Compare Source

Update dependency node-24 to v24.18.1

Notable changes
nodejs/node (node-24)
v24.18.1: 2026-07-29, Version 24.18.1 'Krypton' (LTS), @​&#​8203;juanarbol

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High
  • (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
  • (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
  • (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
  • (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
  • (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium
  • (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
  • (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
  • (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
  • (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
  • (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
  • deps: update llhttp to 9.4.3 (Paolo Insogna)
  • deps: update undici to 7.29.0 (Node.js GitHub Bot)
Commits
List of commits

9b9ba49 (Update dependency node-24 to v24.18.1, 2026-07-29)

v23.0.3

Compare Source

8b72c6a (Do not require pull-requests: read from callers, 2026-07-29)

v23.0.2

Compare Source

Update dependency node to v24.18.1

Notable changes
nodejs/node (node)
v24.18.1: 2026-07-29, Version 24.18.1 'Krypton' (LTS), @​&#​8203;juanarbol

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High
  • (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
  • (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
  • (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
  • (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
  • (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium
  • (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
  • (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
  • (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
  • (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
  • (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
  • deps: update llhttp to 9.4.3 (Paolo Insogna)
  • deps: update undici to 7.29.0 (Node.js GitHub Bot)
Commits
List of commits

742dc98 (Update dependency node to v24.18.1, 2026-07-29)

v23.0.1

Compare Source

Update dependency node-26 to v26.5.1

Notable changes
nodejs/node (node-26)
v26.5.1: 2026-07-29, Version 26.5.1 (Current), @​&#​8203;RafaelGSS

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
  • (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
  • (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
  • (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
  • (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium
  • (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
  • (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
  • (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
  • (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
  • (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
  • deps: update llhttp to 9.4.3 (Paolo Insogna)
  • deps: update undici to 8.9.0 (Node.js GitHub Bot)
Commits

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • Only on Sunday and Saturday (* * * * 0,6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

Signed-off-by: Kyle Harding <kyle@balena.io>
@klutchell-renovate

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant