Skip to content

feat: add dependency-check/DependencyCheck#50599

Merged
suzuki-shunsuke merged 3 commits into
aquaproj:mainfrom
kapitoshka438:feat/dependency-check/DependencyCheck
Apr 16, 2026
Merged

feat: add dependency-check/DependencyCheck#50599
suzuki-shunsuke merged 3 commits into
aquaproj:mainfrom
kapitoshka438:feat/dependency-check/DependencyCheck

Conversation

@kapitoshka438

@kapitoshka438 kapitoshka438 commented Mar 18, 2026

Copy link
Copy Markdown
Contributor

Check List

Summary

Add dependency-check/DependencyCheck — OWASP Dependency-Check is a software composition analysis (SCA) utility that detects publicly disclosed vulnerabilities in application dependencies by checking them against the National Vulnerability Database (NVD).

Background

Asset Naming Convention

GitHub releases for this package follow a consistent naming pattern across all versions (v8.x through v12.x):

dependency-check-{version}-release.zip

Where {version} is the tag name without the v prefix. For example, tag v12.2.0 produces asset dependency-check-12.2.0-release.zip. The zip archive always extracts into a top-level dependency-check/ directory with the following structure relevant to aqua:

dependency-check/
└── bin/
    ├── dependency-check.sh   # Unix entry point (Linux, macOS)
    └── dependency-check.bat  # Windows entry point

No Standard Checksum Files

Releases provide only PGP signatures (.asc files) — no SHA256 or other hash files are published. Therefore checksum.enabled is set to false.

Fix Applied

  • Added dependency-check/DependencyCheck to registry.yaml and pkgs/dependency-check/DependencyCheck/registry.yaml with:
    • asset template using trimV to strip the v prefix from the version tag
    • files[].src pointing to dependency-check/bin/dependency-check.sh for Unix
    • Windows overrides pointing to dependency-check/bin/dependency-check.bat
    • checksum.enabled: false since only PGP signatures are available
  • Added pkgs/dependency-check/DependencyCheck/pkg.yaml with test entries for v12.2.0 (latest) and v8.1.1 (older version to cover version_overrides)

Test Result

argd t dependency-check/DependencyCheck passed for all platforms:

OS Arch Result
linux amd64
linux arm64
darwin amd64
darwin arm64
windows amd64
windows arm64

Summary by CodeRabbit

  • New Features
    • Added OWASP Dependency-Check as a distributable package in the registry.
    • Introduced version override rules to improve selection of appropriate release artifacts.
    • Added a Windows-specific artifact mapping to ensure cross-platform availability and consistent invocation.

@coderabbitai

coderabbitai Bot commented Mar 18, 2026

Copy link
Copy Markdown

Warning

Rate limit exceeded

@suzuki-shunsuke has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 15 minutes and 55 seconds before requesting another review.

Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 15 minutes and 55 seconds.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 323ea020-0d30-490d-9cc3-3fb84cf7ea9f

📥 Commits

Reviewing files that changed from the base of the PR and between 340e906 and 02c9351.

📒 Files selected for processing (3)
  • pkgs/dependency-check/DependencyCheck/pkg.yaml
  • pkgs/dependency-check/DependencyCheck/registry.yaml
  • registry.yaml
📝 Walkthrough

Walkthrough

Adds a new package manifest and registry entries for OWASP Dependency-Check: pkgs/dependency-check/DependencyCheck/pkg.yaml, pkgs/dependency-check/DependencyCheck/registry.yaml, and a top-level registry.yaml packages entry with asset/file mappings and OS-specific overrides.

Changes

Cohort / File(s) Summary
Package manifest
pkgs/dependency-check/DependencyCheck/pkg.yaml
Adds package manifest listing dependency-check/DependencyCheck@v12.2.0.
Package registry entry
pkgs/dependency-check/DependencyCheck/registry.yaml
Adds a github_release registry entry for dependency-check/DependencyCheck with version_constraint: "false", and version_overrides enabling version_constraint: "true" for asset: dependency-check-{{trimV .Version}}-release.zip (format: zip), mapping dependency-checkdependency-check/bin/dependency-check.sh, plus a goos: windows override mapping dependency-checkdependency-check/bin/dependency-check.bat.
Top-level registry list
registry.yaml
Inserts the same dependency-check github_release entry into the top-level packages list with identical override/asset/file details.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

  • refactor: fix lint errors #50398 — Similar change pattern switching top-level version_constraint to "false" and adding a version_overrides entry with "true" plus asset/format/files overrides.

Suggested labels

enhancement

Poem

🐰 I found a zip and gave a cheer,
Bin and bat tucked safely near,
A manifest placed, tidy and spry,
Releases lined up, versions fly,
I hop away with a carrot-high grin 🥕

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: adding the dependency-check/DependencyCheck package to the registry.
Description check ✅ Passed The description provides a comprehensive overview with all required checklist items completed, detailed background on asset naming and configuration rationale, test results across all platforms, and clear explanation of the implementation.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
pkgs/dependency-check/DependencyCheck/registry.yaml (1)

20-21: Drop redundant checksum block.

checksum.enabled: false is unnecessary here if checksum disabling is already the default; removing it keeps the manifest leaner.

♻️ Suggested cleanup
-        checksum:
-          enabled: false

As per coding guidelines, omit settings equivalent to default values.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@pkgs/dependency-check/DependencyCheck/registry.yaml` around lines 20 - 21,
Remove the redundant checksum block from registry.yaml: delete the "checksum:"
mapping and its "enabled: false" entry since disabling checksum is the default;
this cleans the manifest and avoids specifying default-equivalent settings.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@pkgs/dependency-check/DependencyCheck/pkg.yaml`:
- Around line 3-4: Remove the redundant older version entry for the
dependency-check package: locate the package block with "name:
dependency-check/DependencyCheck" that includes "version: v8.1.1" in pkg.yaml
and delete that version entry so only the latest version remains; ensure no
other references to v8.1.1 remain in the file and keep the single current/latest
version entry intact.

---

Nitpick comments:
In `@pkgs/dependency-check/DependencyCheck/registry.yaml`:
- Around line 20-21: Remove the redundant checksum block from registry.yaml:
delete the "checksum:" mapping and its "enabled: false" entry since disabling
checksum is the default; this cleans the manifest and avoids specifying
default-equivalent settings.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 7c1a0f73-63bb-4d8e-ab87-70408e75388d

📥 Commits

Reviewing files that changed from the base of the PR and between 32a0e89 and 83c5ae6.

📒 Files selected for processing (3)
  • pkgs/dependency-check/DependencyCheck/pkg.yaml
  • pkgs/dependency-check/DependencyCheck/registry.yaml
  • registry.yaml

Comment thread pkgs/dependency-check/DependencyCheck/pkg.yaml Outdated
@kapitoshka438 kapitoshka438 force-pushed the feat/dependency-check/DependencyCheck branch 2 times, most recently from 27c1d0d to 8a7fdb5 Compare March 19, 2026 18:55
@kapitoshka438

Copy link
Copy Markdown
Contributor Author

@coderabbitai resume

@coderabbitai

coderabbitai Bot commented Mar 23, 2026

Copy link
Copy Markdown
✅ Actions performed

Reviews resumed.

@kapitoshka438

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Mar 23, 2026

Copy link
Copy Markdown
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@kapitoshka438 kapitoshka438 force-pushed the feat/dependency-check/DependencyCheck branch from 8a7fdb5 to 340e906 Compare April 14, 2026 09:46
@github-actions

This comment was marked as resolved.

@kapitoshka438 kapitoshka438 force-pushed the feat/dependency-check/DependencyCheck branch from 340e906 to 209e268 Compare April 14, 2026 09:47
@suzuki-shunsuke suzuki-shunsuke added the enhancement New feature or request label Apr 16, 2026
@suzuki-shunsuke suzuki-shunsuke merged commit 7932093 into aquaproj:main Apr 16, 2026
19 checks passed
@suzuki-shunsuke suzuki-shunsuke added this to the v4.495.0 milestone Apr 16, 2026
@github-project-automation github-project-automation Bot moved this to Done in main Apr 16, 2026
@kapitoshka438 kapitoshka438 deleted the feat/dependency-check/DependencyCheck branch April 16, 2026 13:41
@suzuki-shunsuke

Copy link
Copy Markdown
Member

tmeijn pushed a commit to tmeijn/dotfiles that referenced this pull request May 7, 2026
This MR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [aquaproj/aqua-registry](https://github.com/aquaproj/aqua-registry) | minor | `v4.494.1` → `v4.508.0` |

MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot).

**Proposed changes to behavior should be submitted there as MRs.**

---

### Release Notes

<details>
<summary>aquaproj/aqua-registry (aquaproj/aqua-registry)</summary>

### [`v4.508.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.508.0)

[Compare Source](aquaproj/aqua-registry@v4.507.0...v4.508.0)

[Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.508.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.508.0) | <aquaproj/aqua-registry@v4.507.0...v4.508.0>

#### 🎉 New Packages

[#&#8203;53316](aquaproj/aqua-registry#53316) [runs-on/cli](https://github.com/runs-on/cli) - CLI for RunsOn [@&#8203;tvd0x2a](https://github.com/tvd0x2a)
[#&#8203;53298](aquaproj/aqua-registry#53298) [anthropics/anthropic-cli](https://github.com/anthropics/anthropic-cli) - The CLI for the Claude API [@&#8203;tak848](https://github.com/tak848)

#### Fixes

[#&#8203;53323](aquaproj/aqua-registry#53323) add `github_release_attestations` to where `github_immutable_release` is [@&#8203;scop](https://github.com/scop)

#### Security

[#&#8203;53324](aquaproj/aqua-registry#53324) jreleaser/jreleaser/standalone: SLSA provenance config [@&#8203;scop](https://github.com/scop)

### [`v4.507.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.507.0)

[Compare Source](aquaproj/aqua-registry@v4.506.0...v4.507.0)

[Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.507.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.507.0) | <aquaproj/aqua-registry@v4.506.0...v4.507.0>

#### 🎉 New Packages

[#&#8203;53232](aquaproj/aqua-registry#53232) [racket-lang.org/racket-minimal](https://github.com/racket-lang.org/racket-minimal): Minimal Racket distribution
[#&#8203;53227](aquaproj/aqua-registry#53227) [crates.io/wasmi\_cli](https://crates.io/crates/wasmi_cli): WebAssembly interpreter [@&#8203;2xdevv](https://github.com/2xdevv)

#### Fixes

[#&#8203;53217](aquaproj/aqua-registry#53217) aristocratos/btop: Support btop v1.4.7
[#&#8203;53266](aquaproj/aqua-registry#53266) steipete/gogcli: Rename to openclaw/gogcli

#### Security

[#&#8203;34119](aquaproj/aqua-registry#34119) jreleaser/jreleaser: SLSA provenance config [@&#8203;scop](https://github.com/scop)

### [`v4.506.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.506.0)

[Compare Source](aquaproj/aqua-registry@v4.505.0...v4.506.0)

[Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.506.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.506.0) | <aquaproj/aqua-registry@v4.505.0...v4.506.0>

#### 🎉 New Packages

[#&#8203;53191](aquaproj/aqua-registry#53191) [spinframework/spin](https://github.com/spinframework/spin) - Developer tool for building and running serverless WebAssembly applications [@&#8203;2xdevvc](https://github.com/2xdevvc)
[#&#8203;53156](aquaproj/aqua-registry#53156) [salesforce/reactive-grpc/protoc-gen-reactor-grpc](https://github.com/salesforce/reactive-grpc) - Reactor-gRPC is a set of gRPC bindings for reactive programming with Reactor [@&#8203;altaiezior](https://github.com/altaiezior)

#### Fixes

[#&#8203;53201](aquaproj/aqua-registry#53201) pnpm/pnpm: GitHub artifact attestations config and drop darwin/amd64 support [@&#8203;scop](https://github.com/scop)

### [`v4.505.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.505.0)

[Compare Source](aquaproj/aqua-registry@v4.504.0...v4.505.0)

[Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.505.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.505.0) | <aquaproj/aqua-registry@v4.504.0...v4.505.0>

#### 🎉 New Packages

[#&#8203;53147](aquaproj/aqua-registry#53147) [boostsecurityio/bagel](https://github.com/boostsecurityio/bagel): bagel, a CLI that inventories security-relevant metadata on developer workstations
[#&#8203;53136](aquaproj/aqua-registry#53136) [opencontainers/umoci](https://github.com/opencontainers/umoci) - umoci modifies Open Container images [@&#8203;2xdevv](https://github.com/2xdevv)
[#&#8203;53118](aquaproj/aqua-registry#53118) [levibostian/decaf](https://github.com/levibostian/decaf) - Calm & reliable automated deployments. No more coffee breaks to deploy your code [@&#8203;levibostian](https://github.com/levibostian)
[#&#8203;53105](aquaproj/aqua-registry#53105) [fillmore-labs/scopeguard](https://github.com/fillmore-labs/scopeguard): A Go static analyzer that identifies variables with unnecessarily wide scope and suggests moving them to tighter scopes

#### Fixes

[#&#8203;53143](aquaproj/aqua-registry#53143) anthropics/claude-code: Fix `gnu` to `glibc`
[#&#8203;53134](aquaproj/aqua-registry#53134) Update microsoft/edit for the v2.0.0 release asset layout and add the newly published macOS artifact [@&#8203;garysassano](https://github.com/garysassano)

### [`v4.504.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.504.0)

[Compare Source](aquaproj/aqua-registry@v4.503.0...v4.504.0)

[Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.504.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.504.0) | <aquaproj/aqua-registry@v4.503.0...v4.504.0>

#### 🎉 New Packages

[#&#8203;53067](aquaproj/aqua-registry#53067) [elixir-lsp/elixir-ls](https://github.com/elixir-lsp/elixir-ls) - A frontend-independent IDE "smartness" server for Elixir. Implements the "Language Server Protocol" standard and provides debugger support via the "Debug Adapter Protocol" [@&#8203;AlternateRT](https://github.com/AlternateRT)
[#&#8203;53056](aquaproj/aqua-registry#53056) [remoteoss/dexter](https://github.com/remoteoss/dexter) - A fast, full-featured Elixir LSP optimized for large codebases [@&#8203;AlternateRT](https://github.com/AlternateRT)
[#&#8203;53028](aquaproj/aqua-registry#53028) [entireio/git-sync](https://github.com/entireio/git-sync): Mirror git refs from a source remote to a target remote without a local checkout. Packfiles stream directly over Smart HTTP and an in-memory object store

#### Fixes

[#&#8203;53027](aquaproj/aqua-registry#53027) Re-scaffold owenlamont/ryl
[#&#8203;51570](aquaproj/aqua-registry#51570) dagu-org/dagu: Transfer the repository to dagucloud/dagu
[#&#8203;50517](aquaproj/aqua-registry#50517) errata-ai/vale: Transfer the repository to vale-cli/vale

#### Security

[#&#8203;53022](aquaproj/aqua-registry#53022) grafana/flint: GitHub artifact attestations config [@&#8203;scop](https://github.com/scop)
[#&#8203;53021](aquaproj/aqua-registry#53021) endevco/aube: GitHub artifact attestations config [@&#8203;scop](https://github.com/scop)
[#&#8203;53020](aquaproj/aqua-registry#53020) FairwindsOps/nova: cosign config [@&#8203;scop](https://github.com/scop)

### [`v4.503.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.503.0)

[Compare Source](aquaproj/aqua-registry@v4.502.0...v4.503.0)

[Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.503.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.503.0) | <aquaproj/aqua-registry@v4.502.0...v4.503.0>

#### 🎉 New Packages

[#&#8203;52982](aquaproj/aqua-registry#52982) [tursodatabase/turso-cli](https://github.com/tursodatabase/turso-cli) - Command line interface to the Turso Cloud [@&#8203;kabaodao](https://github.com/kabaodao)
[#&#8203;52971](aquaproj/aqua-registry#52971) [grafana/flint](https://github.com/grafana/flint) - Flint is a fast linter runner that keeps local and CI checks consistent with one binary, one config, and only the tools your repo declares [@&#8203;zeitlinger](https://github.com/zeitlinger)

### [`v4.502.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.502.0)

[Compare Source](aquaproj/aqua-registry@v4.501.0...v4.502.0)

[Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.502.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.502.0) | <aquaproj/aqua-registry@v4.501.0...v4.502.0>

#### 🎉 New Packages

[#&#8203;52943](aquaproj/aqua-registry#52943) [phrase/phrase-cli](https://github.com/phrase/phrase-cli) - CLI for the Phrase API [@&#8203;dsychin](https://github.com/dsychin)
[#&#8203;52913](aquaproj/aqua-registry#52913) [Feel-ix-343/markdown-oxide](https://github.com/Feel-ix-343/markdown-oxide) - PKM Markdown Language Server [@&#8203;TyceHerrman](https://github.com/TyceHerrman)
[#&#8203;52880](aquaproj/aqua-registry#52880) [OpenAPITools/openapi-generator](https://github.com/OpenAPITools/openapi-generator) - OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec (v2, v3) [@&#8203;ogaclejapan](https://github.com/ogaclejapan)

#### Fixes

[#&#8203;52947](aquaproj/aqua-registry#52947) Re-scaffold CircleCI-Public/circleci-cli. Use darwin/arm64 binaries

#### Security

[#&#8203;52877](aquaproj/aqua-registry#52877) UpCloudLtd/upcloud-cli: v3.32.0 is missing GH artifact attestations [@&#8203;scop](https://github.com/scop)

#### Documentation

[#&#8203;52944](aquaproj/aqua-registry#52944) Include link in MR template to docs for package execution [@&#8203;dsychin](https://github.com/dsychin)

### [`v4.501.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.501.0)

[Compare Source](aquaproj/aqua-registry@v4.500.0...v4.501.0)

[Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.501.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.501.0) | <aquaproj/aqua-registry@v4.500.0...v4.501.0>

#### 🎉 New Packages

[#&#8203;52722](aquaproj/aqua-registry#52722) [IohannRabeson/tmignore-rs](https://github.com/IohannRabeson/tmignore-rs) - Makes Time Machine respect .gitignore files [@&#8203;TyceHerrman](https://github.com/TyceHerrman)
[#&#8203;52723](aquaproj/aqua-registry#52723) [versity/versitygw](https://github.com/versity/versitygw) - A simple to deploy but feature rich S3 object storage server for your filesystem [@&#8203;TyceHerrman](https://github.com/TyceHerrman)
[#&#8203;52729](aquaproj/aqua-registry#52729) [matthart1983/netwatch](https://github.com/matthart1983/netwatch) - Real-time network diagnostics in your terminal. One command, zero config, instant visibility [@&#8203;TyceHerrman](https://github.com/TyceHerrman)
[#&#8203;52816](aquaproj/aqua-registry#52816) [solarwinds/swo-cli](https://github.com/solarwinds/swo-cli) - Standalone command line tool to retrieve and search recent app server logs from SolarWinds Observability [@&#8203;nirojan](https://github.com/nirojan)

#### Fixes

[#&#8203;52789](aquaproj/aqua-registry#52789) lycheeverse/lychee: Support lychee 0.24.0 or later [@&#8203;gaato](https://github.com/gaato)
[#&#8203;52821](aquaproj/aqua-registry#52821) Fix pnpm v11 assets [@&#8203;TyceHerrman](https://github.com/TyceHerrman)
[#&#8203;52858](aquaproj/aqua-registry#52858) Support WebAssembly/wabt 1.0.38 or later [@&#8203;thedaneeffect](https://github.com/thedaneeffect)
[#&#8203;52737](aquaproj/aqua-registry#52737) jdx/pitchfork: Transfer the repository to endevco/pitchfork

### [`v4.500.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.500.0)

[Compare Source](aquaproj/aqua-registry@v4.499.0...v4.500.0)

[Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.500.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.500.0) | <aquaproj/aqua-registry@v4.499.0...v4.500.0>

#### 🎉 New Packages

[#&#8203;52682](aquaproj/aqua-registry#52682) [jonwiggins/xmloxide](https://github.com/jonwiggins/xmloxide) - A pure Rust reimplementation of libxml2 [@&#8203;zeitlinger](https://github.com/zeitlinger)
[#&#8203;52681](aquaproj/aqua-registry#52681) [google/google-java-format](https://github.com/google/google-java-format) - Reformats Java source code to comply with Google Java Style [@&#8203;zeitlinger](https://github.com/zeitlinger)

#### Fixes

[#&#8203;52663](aquaproj/aqua-registry#52663) [#&#8203;52690](aquaproj/aqua-registry#52690) tstack/lnav: Support lnav v0.14.0 [@&#8203;TyceHerrman](https://github.com/TyceHerrman)

#### Security

[#&#8203;52701](aquaproj/aqua-registry#52701) bmf-san/ggc: Cosign config [@&#8203;scop](https://github.com/scop)

#### Documentation

[#&#8203;52848](aquaproj/aqua-registry#52848) Replace deprecated cmdx references [@&#8203;TyceHerrman](https://github.com/TyceHerrman)

### [`v4.499.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.499.0)

[Compare Source](aquaproj/aqua-registry@v4.498.0...v4.499.0)

[Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.499.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.499.0) | <aquaproj/aqua-registry@v4.498.0...v4.499.0>

#### 🎉 New Packages

[#&#8203;52642](aquaproj/aqua-registry#52642) [smol-machines/smolvm](https://github.com/smol-machines/smolvm) - Tool to build & run portable, lightweight, self-contained virtual machines [@&#8203;TyceHerrman](https://github.com/TyceHerrman)

#### Fixes

[#&#8203;52680](aquaproj/aqua-registry#52680) tombi-toml/tombi: Release artifacts format change [@&#8203;cailloumajor](https://github.com/cailloumajor)

#### Documentation

[#&#8203;52629](aquaproj/aqua-registry#52629) Clarify argd scaffold package support [@&#8203;TyceHerrman](https://github.com/TyceHerrman)

### [`v4.498.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.498.0)

[Compare Source](aquaproj/aqua-registry@v4.497.0...v4.498.0)

[Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.498.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.498.0) | <aquaproj/aqua-registry@v4.497.0...v4.498.0>

#### 🎉 New Packages

[#&#8203;52578](aquaproj/aqua-registry#52578) [lazywalker/rgrc](https://github.com/lazywalker/rgrc) - rgrc - Rusty Generic Colouriser - just like grc but fast [@&#8203;TyceHerrman](https://github.com/TyceHerrman)
[#&#8203;52557](aquaproj/aqua-registry#52557) [tak848/ccgate](https://github.com/tak848/ccgate) - LLM-powered PermissionRequest hook for Claude Code [@&#8203;izumin5210](https://github.com/izumin5210)
[#&#8203;52520](aquaproj/aqua-registry#52520) [grafana/gcx](https://github.com/grafana/gcx) - A CLI for managing Grafana Cloud resources. Optimized for agentic usage [@&#8203;yaroot](https://github.com/yaroot)

#### Fixes

[#&#8203;52531](aquaproj/aqua-registry#52531) awslabs/kubernetes-iteration-toolkit: Rename to awslabs/eks-perf-tests
[#&#8203;52512](aquaproj/aqua-registry#52512) elixir-lang/expert: Rename to expert-lsp/expert

### [`v4.497.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.497.0)

[Compare Source](aquaproj/aqua-registry@v4.496.0...v4.497.0)

[Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.497.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.497.0) | <aquaproj/aqua-registry@v4.496.0...v4.497.0>

#### 🎉 New Packages

[#&#8203;52476](aquaproj/aqua-registry#52476) [ricoberger/grafana-kubernetes-plugin](https://github.com/ricoberger/grafana-kubernetes-plugin) - The Grafana Kubernetes Plugin allows you to explore your Kubernetes resources and logs directly within Grafana [@&#8203;monotek](https://github.com/monotek)

#### Security

[#&#8203;52458](aquaproj/aqua-registry#52458) controlplaneio-fluxcd/flux-operator-mcp: GitHub Artifact Attestations config [@&#8203;scop](https://github.com/scop)
[#&#8203;52457](aquaproj/aqua-registry#52457) controlplaneio-fluxcd/flux-operator: GitHub Artifact Attestations config [@&#8203;scop](https://github.com/scop)

#### Fixes

[#&#8203;52425](aquaproj/aqua-registry#52425) go-delve/delve: Use GitHub release binaries for >= 1.26.2 [@&#8203;scop](https://github.com/scop)

### [`v4.496.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.496.0)

[Compare Source](aquaproj/aqua-registry@v4.495.0...v4.496.0)

[Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.496.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.496.0) | <aquaproj/aqua-registry@v4.495.0...v4.496.0>

#### 🎉 New Packages

[#&#8203;52322](aquaproj/aqua-registry#52322) [endevco/aube](https://github.com/endevco/aube) - A fast Node.js package manager [@&#8203;jdx](https://github.com/jdx)
[#&#8203;52237](aquaproj/aqua-registry#52237) [controlplaneio-fluxcd/flux-operator/flux-operator-mcp](https://github.com/controlplaneio-fluxcd/flux-operator) - GitOps on Autopilot Mode [@&#8203;monotek](https://github.com/monotek)
[#&#8203;52229](aquaproj/aqua-registry#52229) [LargeModGames/spotatui](https://github.com/LargeModGames/spotatui) - A fully standalone Spotify client for the terminal. Native streaming included, no daemon required [@&#8203;yudai-nkt](https://github.com/yudai-nkt)

#### Security

[#&#8203;52316](aquaproj/aqua-registry#52316) graelo/pumas: GitHub artifact attestations config [@&#8203;scop](https://github.com/scop)

#### Fixes

[#&#8203;52272](aquaproj/aqua-registry#52272) Re-scaffold skim-rs/skim. Windows Support
[#&#8203;52247](aquaproj/aqua-registry#52247) vmware-tanzu/velero: Rename to velero-io/velero

### [`v4.495.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.495.0)

[Compare Source](aquaproj/aqua-registry@v4.494.1...v4.495.0)

[Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.495.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.495.0) | <aquaproj/aqua-registry@v4.494.1...v4.495.0>

#### 🎉 New Packages

[#&#8203;52202](aquaproj/aqua-registry#52202) [android-sms-gateway/cli](https://github.com/android-sms-gateway/cli) - A command-line interface for working with SMS Gateway for Android [@&#8203;Ash258](https://github.com/Ash258)
[#&#8203;52151](aquaproj/aqua-registry#52151) [kiro.dev/kiro-cli](https://kiro.dev/docs/cli/installation/) - Kiro CLI is an agentic coding tool that lives in your terminal [@&#8203;garysassano](https://github.com/garysassano)
[#&#8203;51667](aquaproj/aqua-registry#51667) [controlplaneio-fluxcd/flux-operator](https://github.com/controlplaneio-fluxcd/flux-operator) - Flux Operator CLI allows you to manage the Flux Operator resources in your Kubernetes clusters. It provides a convenient way to interact with the operator and perform various operations [@&#8203;monotek](https://github.com/monotek)
[#&#8203;50599](aquaproj/aqua-registry#50599) [dependency-check/DependencyCheck](https://github.com/dependency-check/DependencyCheck) - OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies [@&#8203;kapitoshka438](https://github.com/kapitoshka438)

#### Fixes

[#&#8203;52149](aquaproj/aqua-registry#52149) Re-scaffold jreleaser/jreleaser/standalone
[#&#8203;52129](aquaproj/aqua-registry#52129) sigstore/cosign: Support cosign v2.6.3 [@&#8203;tmeijn](https://github.com/tmeijn)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this MR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box

---

This MR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzYuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJSZW5vdmF0ZSBCb3QiLCJhdXRvbWF0aW9uOmJvdC1hdXRob3JlZCIsImRlcGVuZGVuY3ktdHlwZTo6bWlub3IiXX0=-->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants