Skip to content

chore(deps): weekly safe aqua updates · 7 packages - #3

Open
mendral-app[bot] wants to merge 1 commit into
mainfrom
mendral/deps/weekly-safe-aqua-20260803
Open

chore(deps): weekly safe aqua updates · 7 packages#3
mendral-app[bot] wants to merge 1 commit into
mainfrom
mendral/deps/weekly-safe-aqua-20260803

Conversation

@mendral-app

@mendral-app mendral-app Bot commented Aug 3, 2026

Copy link
Copy Markdown

Packages bumped

Package Old New Released
aquaproj/aqua-registry v4.530.0 v4.544.0 2026-07-26
golang/go go1.26.4 go1.26.5 2026-07-07
golang.org/x/vuln/cmd/govulncheck v1.5.0 v1.6.0 2026-07-09
golang.org/x/tools/cmd/deadcode v0.47.0 v0.48.0 2026-07-09
casey/just 1.55.1 1.57.0 2026-07-19
goreleaser/goreleaser v2.16.0 v2.17.1 2026-07-26
sigstore/cosign v3.1.1 v3.1.2 2026-07-17
Per-package details

aquaproj/aqua-registry v4.530.0 → v4.544.0

  • Metadata-only registry of tool definitions; purely additive new package entries and config updates.
  • No impact: the registry just enables aqua to resolve tools — no behavioral change to pinned versions.

golang/go go1.26.4 → go1.26.5

  • CVE-2026-39822 (os): Root escape via symlink + trailing slash — os.Root improperly followed symlinks.
  • CVE-2026-42505 (crypto/tls): Encrypted Client Hello privacy leak — ECH leaked pre-shared key identities.
  • Impact: Security patch release. This repo ships no Go code, but the pinned Go is used by govulncheck, deadcode, golangci-lint etc. No breaking changes.

golang.org/x/vuln v1.5.0 → v1.6.0

  • Resolves panics after vulnerability DB updates seen in v1.4.x; govulncheck improvements.
  • Impact: Used as govulncheck linting tool only. No breaking changes.

golang.org/x/tools v0.47.0 → v0.48.0

  • Standard tooling updates; stdlib index update for Go 1.27 RC2; analysis improvements.
  • Impact: Used as deadcode analysis tool only. No breaking changes.

casey/just 1.55.1 → 1.57.0

  • New: len() function, num_jobs(), --jobs option, [arg(min)]/[arg(max)] attributes.
  • Stricter validation: forbids duplicate groups, option names beginning with -, empty choose() alphabet, duplicate function parameters.
  • Impact: This repo's Justfile uses none of the now-forbidden patterns. Validation is stricter but well-formed justfiles (like ours) are unaffected.

goreleaser/goreleaser v2.16.0 → v2.17.1

  • Post-release verification pipe, RISC-V 64 packages, Windows .msix, templated Dockerfiles.
  • Security: go-pkcs12 bump (GO-2026-5052), golang.org/x/net update.
  • Impact: Used for release automation in other repos; this repo only pins it. No breaking changes.

sigstore/cosign v3.1.1 → v3.1.2

  • Bug fixes: empty cert PEM handling, predicate type validation, OCI 1.1 compatibility.
  • Deprecation warnings for --payload and --output-attestation (removal planned in v4, not v3).
  • Impact: Used for artifact signing in release workflows. Patch release, no behavior change.

Files modified

  • aqua.yaml — version bumps for 7 packages (6 tools + registry ref)
  • aqua-checksums.json — regenerated checksums for new versions
Skipped this ecosystem
Package Reason
aquaproj/aqua setup-aqua/action.yaml is content-pinned by limen baseline; AQUA_VERSION managed by limen convergence
cli/cli v2.97.0 released 2026-07-31, within 7-day cooldown; already at latest eligible (v2.96.0)
koalaman/shellcheck Already at latest (v0.11.0)
golangci/golangci-lint Already at latest eligible (v2.12.2)
google/yamlfmt Already at latest (v0.21.0)
lycheeverse/lychee Already at latest (lychee-v0.24.2)
gotestyourself/gotestsum Already at latest (v1.13.0)
jqlang/jq Already at latest (jq-1.8.2)
mikefarah/yq Already at latest (v4.53.3)
google/go-licenses Already at latest (v2.0.1)
vbatts/git-validation Already at latest (v1.2.2)
farcloser/godolint No newer release available (v0.1.0)
farcloser/limen Already at latest eligible (v0.0.9)
goccy/go-graphviz/cmd/dot Pseudo-version, intentionally pinned
actions/checkout Already at latest (v7.0.1)
actions/create-github-app-token Already at latest (v3.2.0)

Signed-off-by: mendral[bot] <mendral[bot]@users.noreply.github.com>
@mendral-app
mendral-app Bot force-pushed the mendral/deps/weekly-safe-aqua-20260803 branch from cbda4a9 to 373ba08 Compare August 3, 2026 09:47
@mendral-app mendral-app Bot changed the title chore(deps): weekly safe aqua updates · 8 packages chore(deps): weekly safe aqua updates · 7 packages Aug 3, 2026
@mendral-app
mendral-app Bot marked this pull request as ready for review August 3, 2026 09:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants