Skip to content

build(deps): bump the chainguard group across 1 directory with 3 updates#2001

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/chainguard-0065cdd032
Closed

build(deps): bump the chainguard group across 1 directory with 3 updates#2001
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/chainguard-0065cdd032

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the chainguard group with 2 updates in the / directory: chainguard.dev/apko and chainguard.dev/melange.

Updates chainguard.dev/apko from 1.2.15 to 1.2.18

Release notes

Sourced from chainguard.dev/apko's releases.

Release v1.2.18

Changelog

  • ebd9255d91996b81a9b88723efbc9d563cfd863c build(deps): bump k8s.io/apimachinery from 0.36.1 to 0.36.2 (#2279)

Release v1.2.17

Changelog

  • 8a34ba83954913da4b79bd8a40ff124782f8f2cb Match apk-tools' provider comparison ordering in the solver (#2271)
  • 6b57924d877dc28152db9f2da9ad3d0cb99ae7eb build(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#2264)
  • 5f564a223a51b616929ed196703913876c15a131 build(deps): bump chainguard-dev/actions from 1.6.19 to 1.6.22 (#2272)
  • a12506c066e3bac80f79412cd1aa3b12a6880ad6 build(deps): bump chainguard.dev/sdk from 0.1.55 to 0.1.57 (#2275)
  • b16043b42041f042965719cf4778895ed7cb5da5 build(deps): bump github/codeql-action from 4.36.0 to 4.36.2 (#2267)
  • 879c4e55e6e7cd73945e671c77ff0d322cd1f6bf build(deps): bump go.opentelemetry.io/otel from 1.43.0 to 1.44.0 (#2258)
  • 301fd0d625c79684d29b2de779b7fd882e8fd822 build(deps): bump go.opentelemetry.io/otel/trace from 1.43.0 to 1.44.0 (#2256)
  • cafdeae691a2964120fdf86389e3a794e38ccdb3 build(deps): bump go.step.sm/crypto from 0.81.0 to 0.82.0 (#2270)
  • a3baa98fd9e4dcee50e3ba777a63bcdd134c24ad build(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 (#2265)
  • 7fd8b427838dbe812616e798ce884ed45c40c0fd build(deps): bump golang.org/x/sys from 0.45.0 to 0.46.0 (#2266)
  • 620f3009eac5282e006b8b319be3c6f13510a02f build(deps): bump google.golang.org/api from 0.280.0 to 0.283.0 (#2262)
  • bdddef26c13348e24c8f2a274662f3bcd4def4e8 build(deps): bump gopkg.in/ini.v1 from 1.67.2 to 1.67.3 (#2273)
  • 1fe85deeaca6ba534aec2f88a0f68e644725216e expandapk: materialize uncompressed .dat.tar atomically (#2269)
  • ef578c30be29d5c1074cf6934e5dac58a84f6cc4 fix(auth): let chainctl write to terminal for interactive login (#2276)
  • be89e64e9c769e8d9d5a2446e9bc65db2d2b194b paths: preserve setuid/setgid/sticky bits in permissions (#2274)

Release v1.2.16

Changelog

  • f39c3fa47ca6af5ae27c1e466c5a841b9b80f8d9 build(deps): bump docker/setup-qemu-action from 4.0.0 to 4.1.0 (#2254)
  • 8bf905593d457345beafe51490dd28a619d0690a build(deps): bump github/codeql-action from 4.35.5 to 4.36.0 (#2246)
  • 003b4011dd3a7398b1d7b9dd51cea9a61f2a4915 build(deps): bump imjasonh/setup-crane from 0.5 to 0.6 (#2260)
Commits
  • ebd9255 build(deps): bump k8s.io/apimachinery from 0.36.1 to 0.36.2 (#2279)
  • 301fd0d build(deps): bump go.opentelemetry.io/otel/trace from 1.43.0 to 1.44.0 (#2256)
  • 879c4e5 build(deps): bump go.opentelemetry.io/otel from 1.43.0 to 1.44.0 (#2258)
  • cafdeae build(deps): bump go.step.sm/crypto from 0.81.0 to 0.82.0 (#2270)
  • a12506c build(deps): bump chainguard.dev/sdk from 0.1.55 to 0.1.57 (#2275)
  • a3baa98 build(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 (#2265)
  • 620f300 build(deps): bump google.golang.org/api from 0.280.0 to 0.283.0 (#2262)
  • ef578c3 fix(auth): let chainctl write to terminal for interactive login (#2276)
  • be89e64 paths: preserve setuid/setgid/sticky bits in permissions (#2274)
  • 6b57924 build(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#2264)
  • Additional commits viewable in compare view

Updates chainguard.dev/melange from 0.52.0 to 0.54.0

Release notes

Sourced from chainguard.dev/melange's releases.

Release v0.54.0

What's Changed

Full Changelog: chainguard-dev/melange@v0.53.3...v0.54.0

Release v0.53.3

What's Changed

Full Changelog: chainguard-dev/melange@v0.53.2...v0.53.3

Release v0.53.2

What's Changed

Full Changelog: chainguard-dev/melange@v0.53.1...v0.53.2

Release v0.53.1

What's Changed

Full Changelog: chainguard-dev/melange@v0.53.0...v0.53.1

Release v0.53.0

What's Changed

New Contributors

Full Changelog: chainguard-dev/melange@v0.52.1...v0.53.0

Release v0.52.1

What's Changed

... (truncated)

Commits
  • 7fb1d6a feat(git-checkout): log resolved clone URL after successful clone (#2572)
  • 24f25f7 build(deps): bump chainguard.dev/apko from 1.2.16 to 1.2.17 in the gomod grou...
  • d6b81b9 fix(qemu): pass SLIRP DNS address via kernel cmdline when QEMU_NET_CIDR is se...
  • ad5661f build(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 in the gomod grou...
  • ddad5a6 build(deps): bump the gomod group across 1 directory with 12 updates (#2567)
  • 496af91 fix(qemu): skip empty QEMU_NET_CIDR instead of erroring (#2568)
  • 65ed1ab feat(qemu): add QEMU_NET_CIDR to override SLIRP internal network (#2564)
  • 1b5764a ci: remove stale wolfi-presubmit package matrix entries (#2566)
  • 2486683 chore(source): allow GitHub verified signatures (#2565)
  • 20afeb1 fix(renovate): bump git-checkout regardless of tag if there is only one (#2562)
  • Additional commits viewable in compare view

Updates github.com/chainguard-dev/yam from 0.2.62 to 0.2.63

Commits
  • 1979b01 build(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#223)
  • 2cd6b4e build(deps): bump chainguard-dev/actions from 1.6.19 to 1.6.21 (#222)
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jun 18, 2026
Bumps the chainguard group with 2 updates in the / directory: [chainguard.dev/apko](https://github.com/chainguard-dev/apko) and [chainguard.dev/melange](https://github.com/chainguard-dev/melange).


Updates `chainguard.dev/apko` from 1.2.15 to 1.2.18
- [Release notes](https://github.com/chainguard-dev/apko/releases)
- [Changelog](https://github.com/chainguard-dev/apko/blob/main/NEWS.md)
- [Commits](chainguard-dev/apko@v1.2.15...v1.2.18)

Updates `chainguard.dev/melange` from 0.52.0 to 0.54.0
- [Release notes](https://github.com/chainguard-dev/melange/releases)
- [Changelog](https://github.com/chainguard-dev/melange/blob/main/NEWS.md)
- [Commits](chainguard-dev/melange@v0.52.0...v0.54.0)

Updates `github.com/chainguard-dev/yam` from 0.2.62 to 0.2.63
- [Commits](chainguard-dev/yam@v0.2.62...v0.2.63)

---
updated-dependencies:
- dependency-name: chainguard.dev/apko
  dependency-version: 1.2.17
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: chainguard
- dependency-name: chainguard.dev/melange
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: chainguard
- dependency-name: github.com/chainguard-dev/yam
  dependency-version: 0.2.63
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: chainguard
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): bump the chainguard group with 3 updates build(deps): bump the chainguard group across 1 directory with 3 updates Jun 23, 2026
@dependabot dependabot Bot force-pushed the dependabot/go_modules/chainguard-0065cdd032 branch from 8ca6b83 to 5bf409b Compare June 23, 2026 16:23
@dependabot @github

dependabot Bot commented on behalf of github Jun 26, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jun 26, 2026
@dependabot dependabot Bot deleted the dependabot/go_modules/chainguard-0065cdd032 branch June 26, 2026 16:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants