Skip to content

build(deps): bump the chainguard group across 1 directory with 3 updates#2001

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/chainguard-0065cdd032
Open

build(deps): bump the chainguard group across 1 directory with 3 updates#2001
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/chainguard-0065cdd032

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the chainguard group with 2 updates in the / directory: chainguard.dev/apko and chainguard.dev/melange.

Updates chainguard.dev/apko from 1.2.15 to 1.2.18

Release notes

Sourced from chainguard.dev/apko's releases.

Release v1.2.18

Changelog

  • ebd9255d91996b81a9b88723efbc9d563cfd863c build(deps): bump k8s.io/apimachinery from 0.36.1 to 0.36.2 (#2279)

Release v1.2.17

Changelog

  • 8a34ba83954913da4b79bd8a40ff124782f8f2cb Match apk-tools' provider comparison ordering in the solver (#2271)
  • 6b57924d877dc28152db9f2da9ad3d0cb99ae7eb build(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#2264)
  • 5f564a223a51b616929ed196703913876c15a131 build(deps): bump chainguard-dev/actions from 1.6.19 to 1.6.22 (#2272)
  • a12506c066e3bac80f79412cd1aa3b12a6880ad6 build(deps): bump chainguard.dev/sdk from 0.1.55 to 0.1.57 (#2275)
  • b16043b42041f042965719cf4778895ed7cb5da5 build(deps): bump github/codeql-action from 4.36.0 to 4.36.2 (#2267)
  • 879c4e55e6e7cd73945e671c77ff0d322cd1f6bf build(deps): bump go.opentelemetry.io/otel from 1.43.0 to 1.44.0 (#2258)
  • 301fd0d625c79684d29b2de779b7fd882e8fd822 build(deps): bump go.opentelemetry.io/otel/trace from 1.43.0 to 1.44.0 (#2256)
  • cafdeae691a2964120fdf86389e3a794e38ccdb3 build(deps): bump go.step.sm/crypto from 0.81.0 to 0.82.0 (#2270)
  • a3baa98fd9e4dcee50e3ba777a63bcdd134c24ad build(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 (#2265)
  • 7fd8b427838dbe812616e798ce884ed45c40c0fd build(deps): bump golang.org/x/sys from 0.45.0 to 0.46.0 (#2266)
  • 620f3009eac5282e006b8b319be3c6f13510a02f build(deps): bump google.golang.org/api from 0.280.0 to 0.283.0 (#2262)
  • bdddef26c13348e24c8f2a274662f3bcd4def4e8 build(deps): bump gopkg.in/ini.v1 from 1.67.2 to 1.67.3 (#2273)
  • 1fe85deeaca6ba534aec2f88a0f68e644725216e expandapk: materialize uncompressed .dat.tar atomically (#2269)
  • ef578c30be29d5c1074cf6934e5dac58a84f6cc4 fix(auth): let chainctl write to terminal for interactive login (#2276)
  • be89e64e9c769e8d9d5a2446e9bc65db2d2b194b paths: preserve setuid/setgid/sticky bits in permissions (#2274)

Release v1.2.16

Changelog

  • f39c3fa47ca6af5ae27c1e466c5a841b9b80f8d9 build(deps): bump docker/setup-qemu-action from 4.0.0 to 4.1.0 (#2254)
  • 8bf905593d457345beafe51490dd28a619d0690a build(deps): bump github/codeql-action from 4.35.5 to 4.36.0 (#2246)
  • 003b4011dd3a7398b1d7b9dd51cea9a61f2a4915 build(deps): bump imjasonh/setup-crane from 0.5 to 0.6 (#2260)
Commits
  • ebd9255 build(deps): bump k8s.io/apimachinery from 0.36.1 to 0.36.2 (#2279)
  • 301fd0d build(deps): bump go.opentelemetry.io/otel/trace from 1.43.0 to 1.44.0 (#2256)
  • 879c4e5 build(deps): bump go.opentelemetry.io/otel from 1.43.0 to 1.44.0 (#2258)
  • cafdeae build(deps): bump go.step.sm/crypto from 0.81.0 to 0.82.0 (#2270)
  • a12506c build(deps): bump chainguard.dev/sdk from 0.1.55 to 0.1.57 (#2275)
  • a3baa98 build(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 (#2265)
  • 620f300 build(deps): bump google.golang.org/api from 0.280.0 to 0.283.0 (#2262)
  • ef578c3 fix(auth): let chainctl write to terminal for interactive login (#2276)
  • be89e64 paths: preserve setuid/setgid/sticky bits in permissions (#2274)
  • 6b57924 build(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#2264)
  • Additional commits viewable in compare view

Updates chainguard.dev/melange from 0.52.0 to 0.54.0

Release notes

Sourced from chainguard.dev/melange's releases.

Release v0.54.0

What's Changed

Full Changelog: chainguard-dev/melange@v0.53.3...v0.54.0

Release v0.53.3

What's Changed

Full Changelog: chainguard-dev/melange@v0.53.2...v0.53.3

Release v0.53.2

What's Changed

Full Changelog: chainguard-dev/melange@v0.53.1...v0.53.2

Release v0.53.1

What's Changed

Full Changelog: chainguard-dev/melange@v0.53.0...v0.53.1

Release v0.53.0

What's Changed

New Contributors

Full Changelog: chainguard-dev/melange@v0.52.1...v0.53.0

Release v0.52.1

What's Changed

... (truncated)

Commits
  • 7fb1d6a feat(git-checkout): log resolved clone URL after successful clone (#2572)
  • 24f25f7 build(deps): bump chainguard.dev/apko from 1.2.16 to 1.2.17 in the gomod grou...
  • d6b81b9 fix(qemu): pass SLIRP DNS address via kernel cmdline when QEMU_NET_CIDR is se...
  • ad5661f build(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 in the gomod grou...
  • ddad5a6 build(deps): bump the gomod group across 1 directory with 12 updates (#2567)
  • 496af91 fix(qemu): skip empty QEMU_NET_CIDR instead of erroring (#2568)
  • 65ed1ab feat(qemu): add QEMU_NET_CIDR to override SLIRP internal network (#2564)
  • 1b5764a ci: remove stale wolfi-presubmit package matrix entries (#2566)
  • 2486683 chore(source): allow GitHub verified signatures (#2565)
  • 20afeb1 fix(renovate): bump git-checkout regardless of tag if there is only one (#2562)
  • Additional commits viewable in compare view

Updates github.com/chainguard-dev/yam from 0.2.62 to 0.2.63

Commits
  • 1979b01 build(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#223)
  • 2cd6b4e build(deps): bump chainguard-dev/actions from 1.6.19 to 1.6.21 (#222)
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jun 18, 2026
Bumps the chainguard group with 2 updates in the / directory: [chainguard.dev/apko](https://github.com/chainguard-dev/apko) and [chainguard.dev/melange](https://github.com/chainguard-dev/melange).


Updates `chainguard.dev/apko` from 1.2.15 to 1.2.18
- [Release notes](https://github.com/chainguard-dev/apko/releases)
- [Changelog](https://github.com/chainguard-dev/apko/blob/main/NEWS.md)
- [Commits](chainguard-dev/apko@v1.2.15...v1.2.18)

Updates `chainguard.dev/melange` from 0.52.0 to 0.54.0
- [Release notes](https://github.com/chainguard-dev/melange/releases)
- [Changelog](https://github.com/chainguard-dev/melange/blob/main/NEWS.md)
- [Commits](chainguard-dev/melange@v0.52.0...v0.54.0)

Updates `github.com/chainguard-dev/yam` from 0.2.62 to 0.2.63
- [Commits](chainguard-dev/yam@v0.2.62...v0.2.63)

---
updated-dependencies:
- dependency-name: chainguard.dev/apko
  dependency-version: 1.2.17
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: chainguard
- dependency-name: chainguard.dev/melange
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: chainguard
- dependency-name: github.com/chainguard-dev/yam
  dependency-version: 0.2.63
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: chainguard
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): bump the chainguard group with 3 updates build(deps): bump the chainguard group across 1 directory with 3 updates Jun 23, 2026
@dependabot dependabot Bot force-pushed the dependabot/go_modules/chainguard-0065cdd032 branch from 8ca6b83 to 5bf409b Compare June 23, 2026 16:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants