Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.35.1
->v1.37.0
0.58.2
->0.61.0
3.21.2
->3.21.3
v1.63.4
->v2.0.2
v3.17.0
->v3.17.2
Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
adrienverge/yamllint (adrienverge/yamllint)
v1.37.0
Compare Source
v1.36.2
Compare Source
v1.36.1
Compare Source
v1.36.0
Compare Source
aquasecurity/trivy (docker.io/aquasec/trivy)
v0.61.0
Compare Source
Features
Bug Fixes
dpkgs
(#8623) (346f5b3)--report all
(#8613) (dbb6f28)otherLicenses
without normalize (#8502) (e5072f1)--file-patterns
flag for all post analyzers (#7365) (8b88238)Performance Improvements
v0.60.0
Compare Source
Features
--vuln-severity-source
flag (#8269) (d464807)Bug Fixes
scope
fortrivy registry login
command (#8393) (8715e5d)PkgRelationships
(#8442) (f987e41)poetry
v2 support (#8323) (10cd98c)shortDescription
andfullDescription
fields for sarif reports (#8344) (3eb0b03)pkgFilePaths
map for all formats (#8380) (72ea4b0)v0.59.1
Compare Source
Changelog
9aabfd2
release: v0.59.1 [release/v0.59] (#8334)412c690
fix(misconf): do not log scanners when misconfig scanning is disabled [backport: release/v0.59] (#8349)98f9ba2
chore(deps): bump Go tov1.23.5
[backport: release/v0.59] (#8343)1741fdd
fix(python): addpoetry
v2 support [backport: release/v0.59] (#8335)3fd8e27
fix(sbom): preserve OS packages from multiple SBOMs [backport: release/v0.59] (#8333)v0.59.0
Compare Source
Features
--distro
flag to manually specify OS distribution for vulnerability scanning (#8070) (da17dc7)Bug Fixes
dpkg
packages with different filePaths from different layers (#8298) (846498d)--generate-default-config
command (#8046) (5e68bdc)BLOW_UNKNOWN
error to download DBs (#8060) (51f2123)project.*
props (#8050) (9d9f80d)usr/share/buildinfo/
dir to detect content sets (#8222) (f352f6b)unknown
dependencies (if exists) (#8104) (7558df7)hasExtractedLicensingInfos
field for licenses that are not listed in the SPDX (#8077) (aec8885)Performance Improvements
golangci/golangci-lint (golangci/golangci-lint)
v2.0.2
Compare Source
source
optionv2.0.1
Compare Source
golines
: fix settings during linter loadversion
field before the configurationforbidigo
: fix migrationv2.0.0
Compare Source
golangci-lint fmt
command with dedicated formatter configurationgolangci-lint migrate
command to help migration from v1 to v2 (cf. Migration guide)run.relative-path-mode
(cf. Migration guide)--fast-only
flag (cf. Migration guide)linters.exclusions.warn-unused
to log a warning if an exclusion rule is unused.golines
formatter https://github.com/segmentio/golinesstaticcheck
,stylecheck
,gosimple
into one linter (staticcheck
) (cf. Migration guide)go-critic
: from 0.12.0 to 0.13.0gomodguard
: from 1.3.5 to 1.4.1 (block explicit indirect dependencies)nilnil
: from 1.0.1 to 1.1.0 (new option:only-two
)perfsprint
: from 0.8.2 to 0.9.1 (checker name in the diagnostic message)staticcheck
: newquickfix
set of rulestestifylint
: from 1.5.2 to 1.6.0 (new options:equal-values
,suite-method-signature
,require-string-msg
)wsl
: from 4.5.0 to 4.6.0 (new option:allow-cuddle-used-in-block
)bidichk
: from 0.3.2 to 0.3.3errchkjson
: from 0.4.0 to 0.4.1errname
: from 1.0.0 to 1.1.0funlen
: fixignore-comments
optiongci
: from 0.13.5 to 0.13.6gosmopolitan
: from 1.2.2 to 1.3.0inamedparam
: from 0.1.3 to 0.2.0intrange
: from 0.3.0 to 0.3.1protogetter
: from 0.3.9 to 0.3.12unparam
: from8a5130c
to0df0534
golangci-lint config path --json
golangci-lint help linters --json
golangci-lint help formatters --json
golangci-lint linters --json
golangci-lint formatters --json
golangci-lint version --json
v1.64.8
Compare Source
v1.64.7
Compare Source
depguard
: from 2.2.0 to 2.2.1dupl
: from3e9179a
tof665c8d
gosec
: from 2.22.1 to 2.22.2staticcheck
: from 0.6.0 to 0.6.1v1.64.6
Compare Source
asciicheck
: from 0.4.0 to 0.4.1contextcheck
: from 1.1.5 to 1.1.6errcheck
: from 1.8.0 to 1.9.0exptostd
: from 0.4.1 to 0.4.2ginkgolinter
: from 0.19.0 to 0.19.1go-exhaustruct
: from 3.3.0 to 3.3.1gocheckcompilerdirectives
: from 1.2.1 to 1.3.0godot
: from 1.4.20 to 1.5.0perfsprint
: from 0.8.1 to 0.8.2revive
: from 1.6.1 to 1.7.0tagalign
: from 1.4.1 to 1.4.2v1.64.5
Compare Source
new-from-merge-base-flag
asciicheck
: from 0.3.0 to 0.4.0forcetypeassert
: from 0.1.0 to 0.2.0gosec
: from 2.22.0 to 2.22.1v1.64.4
Compare Source
gci
: fix standard packages list for go1.24v1.64.3
Compare Source
ginkgolinter
: from 0.18.4 to 0.19.0go-critic
: from 0.11.5 to 0.12.0revive
: from 1.6.0 to 1.6.1gci
: fix standard packages list for go1.24v1.64.2
Compare Source
This is the last minor release of golangci-lint v1.
The next release will be golangci-lint v2.
issues.new-from-merge-base
optionrun.relative-path-mode
optioncopyloopvar
: from 1.1.0 to 1.2.1 (support suggested fixes)exptostd
: from 0.3.1 to 0.4.1 (handlesgolang.org/x/exp/constraints.Ordered
)fatcontext
: from 0.5.3 to 0.7.1 (new option:check-struct-pointers
)perfsprint
: from 0.7.1 to 0.8.1 (new options:integer-format
,error-format
,string-format
,bool-format
, andhex-format
)revive
: from 1.5.1 to 1.6.0 (new rules:redundant-build-tag
,use-errors-new
. New optionearly-return.early-return
)go-errorlint
: from 1.7.0 to 1.7.1gochecknoglobals
: from 0.2.1 to 0.2.2godox
: from006bad1
to 1.1.0gosec
: from 2.21.4 to 2.22.0iface
: from 1.3.0 to 1.3.1nilnesserr
: from 0.1.1 to 0.1.2protogetter
: from 0.3.8 to 0.3.9sloglint
: from 0.7.2 to 0.9.0spancheck
: fix defaultStartSpanMatchersSlice
valuesstaticcheck
: from 0.5.1 to 0.6.0tenv
is deprecated and replaced byusetesting.os-setenv: true
.exportloopref
deprecation step 2depguard
configurationv1.64.1
Compare Source
Cancelled due to CI failure.
v1.64.0
Compare Source
Cancelled due to CI failure.
helm/helm (helm/helm)
v3.17.2
: Helm v3.17.2Compare Source
Helm v3.17.2 is a patch release. Users are encouraged to upgrade for the best experience. Users are encouraged to upgrade for the best experience.
The community keeps growing, and we'd love to see you there!
Installation and Upgrading
Download Helm v3.17.2. The common platform binaries are here:
This release was signed with
672C 657B E06B 4B30 969C 4A57 4614 49C2 5E36 B98E
and can be found at @mattfarina keybase account. Please use the attached signatures for verifying this release usinggpg
.The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash
.What's Next
Changelog
cc0bbbd
(Matt Farina)ecb7a74
(dependabot[bot])v3.17.1
: Helm v3.17.1Compare Source
Helm v3.17.1 is a patch release. Users are encouraged to upgrade for the best experience. Users are encouraged to upgrade for the best experience.
The community keeps growing, and we'd love to see you there!
Installation and Upgrading
Download Helm v3.17.1. The common platform binaries are here:
The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash
.What's Next
Changelog
980d8ac
(Ryan Hockstad)c23e3b6
(Ryan Hockstad)3110d5f
(Scott Rigby)9520c71
(Ryan Hockstad)ab7dedd
(dependabot[bot])a2d3602
(Jiasheng Zhu)Configuration
📅 Schedule: Branch creation - "on the first day of the month" in timezone Europe/Berlin, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.