chore: Update Infrastructure dependencies#2055
Conversation
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
2c117cf to
57a4a09
Compare
57a4a09 to
515e5bc
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2055 +/- ##
=======================================
Coverage 87.13% 87.13%
=======================================
Files 2251 2251
Lines 130302 130302
=======================================
Hits 113533 113533
Misses 16754 16754
Partials 15 15 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
515e5bc to
a21c7e4
Compare
a21c7e4 to
0e8183c
Compare
0e8183c to
041e4ab
Compare
041e4ab to
ad4241a
Compare
c5020b8 to
e696953
Compare
e696953 to
59a696f
Compare
59a696f to
dd79da8
Compare
dd79da8 to
2feed2e
Compare
2feed2e to
bbb9fca
Compare
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
Aureliolo
left a comment
There was a problem hiding this comment.
Decision: Infra dep batch (Docker images, GHA actions); CI green after regenerating 4 CLI compose goldens for the busybox 1.37→1.38-musl bump; no behavioural changes outside the digest/tag refresh.
Changelog digest:
Covered the Renovate "infra" group: busybox 1.37→1.38-musl, dhi.io/postgres digest rotation, dhi.io/nats digest rotation, docker/build-push-action v7.1→v7.2, docker/metadata-action v6.0→v6.1, docker/setup-buildx-action v4.0→v4.1, ghcr.io/astral-sh/uv 0.11.15→0.11.16, github/codeql-action v4.35.5→v4.36.0, golangci/golangci-lint-action v9.2.0→v9.2.1, actions/node-versions 24.15.0→24.16.0, postgres service pinDigest.
- Relevant security wins (auto-adopted, no code change): uv 0.11.16 wheel-hint secret-leak fix + unsafe entry-point rejection (flows into backend + fine-tune builds via the Dockerfile uv stage); github/codeql-action v4.36 bumps minimum CodeQL bundle to 2.19.4; golangci-lint-action v9.2.1 is the first immutable release (future v9.2.z bumps become pure digest changes).
- Relevant test fix (this commit): regenerated cli/testdata/compose_{default,custom_ports,sandbox,digest_pins}.yml so the busybox 1.38-musl digest matches the new compose template.
- Reviewed but not relevant: docker/build-push-action v7.2 + metadata-action v6.1 have empty release notes; setup-buildx v4.1 is internal actions-toolkit/dependency churn only; codeql v4.36 SHA-256 OID support is irrelevant until GitHub rolls SHA-256 (not soon); actions/node-versions 24.16 is a Node patch transparent to our build.
Follow-ups: a single bundled issue covers the recurring weekly toil from these digest rotations (mask @sha256:[0-9a-f]{64} and version-suffixed tags in the compose golden-file comparison so a digest bump no longer requires UPDATE_GOLDEN=1) and the deferred full litestar 2.22 controller migration.
This PR contains the following updates:
1.37-musl→1.38-musle545a82→5ce86b96aa59b8→21d6e88v7.1.0→v7.2.0v6.0.0→v6.1.0v4.0.0→v4.1.00.11.15→0.11.16v4.35.5→v4.36.0v9.2.0→v9.2.124.15.0→24.16.096d56f7Release Notes
docker/build-push-action (docker/build-push-action)
v7.2.0Compare Source
docker/metadata-action (docker/metadata-action)
v6.1.0Compare Source
docker/setup-buildx-action (docker/setup-buildx-action)
v4.1.0Compare Source
Full Changelog: docker/setup-buildx-action@v4.0.0...v4.1.0
astral-sh/uv (ghcr.io/astral-sh/uv)
v0.11.16Compare Source
Released on 2026-05-21.
Enhancements
Preview features
Configuration
UV_NO_SYSTEM_CONFIG(#19476)Bug fixes
uv-build(#19495)Documentation
github/codeql-action (github/codeql-action)
v4.36.0Compare Source
golangci/golangci-lint-action (golangci/golangci-lint-action)
v9.2.1Compare Source
What's Changed
IMPORTANT: this is the first immutable release.
Changes
Dependencies
Full Changelog: golangci/golangci-lint-action@v9.2.0...v9.2.1
actions/node-versions (node)
v24.16.0: 24.16.0Compare Source
Node.js 24.16.0
Configuration
📅 Schedule: (in timezone Etc/UTC)
* 0-6 * * 6)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.