This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.<br>[View this repository on the Mend.io Web Portal](https://developer.mend.io/github/ZupIT/horusec). ## Config Migration Needed - [ ] <!-- create-config-migration-pr --> Select this checkbox to let Renovate create an automated Config Migration PR. ## Rate-Limited The following updates are currently rate-limited. To force their creation now, click on a checkbox below. - [ ] <!-- unlimit-branch=renovate/go-1.x -->deps:chore - update dependency go to 1.26 - [ ] <!-- unlimit-branch=renovate/github.com-bmatcuk-doublestar-v4-4.x -->deps:chore - update module github.com/bmatcuk/doublestar/v4 to v4.10.0 - [ ] <!-- unlimit-branch=renovate/github.com-briandowns-spinner-1.x -->deps:chore - update module github.com/briandowns/spinner to v1.23.2 - [ ] <!-- unlimit-branch=renovate/github.com-go-enry-go-enry-v2-2.x -->deps:chore - update module github.com/go-enry/go-enry/v2 to v2.9.6 - [ ] <!-- unlimit-branch=renovate/github.com-google-uuid-1.x -->deps:chore - update module github.com/google/uuid to v1.6.0 - [ ] <!-- unlimit-branch=renovate/github.com-iancoleman-strcase-0.x -->deps:chore - update module github.com/iancoleman/strcase to v0.3.0 - [ ] <!-- unlimit-branch=renovate/github.com-magefile-mage-1.x -->deps:chore - update module github.com/magefile/mage to v1.17.2 - [ ] <!-- unlimit-branch=renovate/github.com-opencontainers-image-spec-1.x -->deps:chore - update module github.com/opencontainers/image-spec to v1.1.1 - [ ] <!-- unlimit-branch=renovate/github.com-sirupsen-logrus-1.x -->deps:chore - update module github.com/sirupsen/logrus to v1.9.4 - [ ] <!-- unlimit-branch=renovate/github.com-spf13-cobra-1.x -->deps:chore - update module github.com/spf13/cobra to v1.10.2 - [ ] <!-- unlimit-branch=renovate/github.com-spf13-viper-1.x -->deps:chore - update module github.com/spf13/viper to v1.21.0 - [ ] <!-- unlimit-branch=renovate/github.com-stretchr-testify-1.x -->deps:chore - update module github.com/stretchr/testify to v1.11.1 - [ ] <!-- unlimit-branch=renovate/php-8.x -->deps:chore - update php Docker tag to v8.5 - [ ] <!-- unlimit-branch=renovate/ruby-3.x -->deps:chore - update ruby Docker tag to v3.4 - [ ] <!-- unlimit-branch=renovate/actions-checkout-6.x -->deps:chore - update actions/checkout action to v6 - [ ] <!-- unlimit-branch=renovate/actions-setup-go-6.x -->deps:chore - update actions/setup-go action to v6 - [ ] <!-- unlimit-branch=renovate/azul-zulu-openjdk-alpine-25.x -->deps:chore - update azul/zulu-openjdk-alpine Docker tag to v25 - [ ] <!-- unlimit-branch=renovate/crazy-max-ghaction-import-gpg-7.x -->deps:chore - update crazy-max/ghaction-import-gpg action to v7 - [ ] <!-- unlimit-branch=renovate/dev-drprasad-delete-tag-and-release-1.x -->deps:chore - update dev-drprasad/delete-tag-and-release action to v1 - [ ] <!-- unlimit-branch=renovate/docker-29.x -->deps:chore - update docker Docker tag to v29 - [ ] <!-- unlimit-branch=renovate/docker-build-push-action-7.x -->deps:chore - update docker/build-push-action action to v7 - [ ] <!-- unlimit-branch=renovate/docker-login-action-4.x -->deps:chore - update docker/login-action action to v4 - [ ] <!-- unlimit-branch=renovate/docker-setup-buildx-action-4.x -->deps:chore - update docker/setup-buildx-action action to v4 - [ ] <!-- unlimit-branch=renovate/docker-setup-qemu-action-4.x -->deps:chore - update docker/setup-qemu-action action to v4 - [ ] <!-- unlimit-branch=renovate/endbug-add-and-commit-10.x -->deps:chore - update EndBug/add-and-commit action to v10 - [ ] <!-- unlimit-branch=renovate/goreleaser-goreleaser-action-7.x -->deps:chore - update goreleaser/goreleaser-action action to v7 - [ ] <!-- unlimit-branch=renovate/major-dotnet-monorepo -->deps:chore - update mcr.microsoft.com/dotnet/sdk Docker tag to v10 - [ ] <!-- unlimit-branch=renovate/github.com-docker-docker-28.x -->deps:chore - update module github.com/docker/docker to v28 - [ ] <!-- unlimit-branch=renovate/github.com-onsi-ginkgo-2.x -->deps:chore - update module github.com/onsi/ginkgo to v2 - [ ] <!-- unlimit-branch=renovate/node-24.x -->deps:chore - update Node.js to v24 - [ ] <!-- unlimit-branch=renovate/ruby-4.x -->deps:chore - update ruby Docker tag to v4 - [ ] <!-- unlimit-branch=renovate/softprops-action-gh-release-3.x -->deps:chore - update softprops/action-gh-release action to v3 - [ ] <!-- create-all-rate-limited-prs -->🔐 **Create all rate-limited PRs at once** 🔐 --- > [!WARNING] > Renovate failed to look up the following dependencies: `Failed to look up github-tags package ZupIT/zup-dco-validator: no-result`. > > Files affected: `.github/workflows/dco.yaml` --- ## Open The following updates have all been created. To force a retry/rebase of any, click on a checkbox below. - [ ] <!-- rebase-branch=renovate/github.com-gocarina-gocsv-digest -->[deps:chore - update github.com/gocarina/gocsv digest to c264028](../pull/1179) - [ ] <!-- rebase-branch=renovate/azul-zulu-openjdk-alpine-17.x -->[deps:chore - update azul/zulu-openjdk-alpine Docker tag to v17.0.19](../pull/1173) - [ ] <!-- rebase-branch=renovate/github.com-docker-docker-20.x -->[deps:chore - update module github.com/docker/docker to v20.10.27+incompatible](../pull/1209) - [ ] <!-- rebase-branch=renovate/github.com-spf13-pflag-1.x -->[deps:chore - update module github.com/spf13/pflag to v1.0.10](../pull/1181) - [ ] <!-- rebase-branch=renovate/github.com-zupit-horusec-engine-1.x -->[deps:chore - update module github.com/ZupIT/horusec-engine to v1.0.2](../pull/1093) - [ ] <!-- rebase-branch=renovate/alpine-3.x -->[deps:chore - update alpine Docker tag to v3.23.4](../pull/1123) - [ ] <!-- rebase-branch=renovate/elixir-1.x -->[deps:chore - update elixir Docker tag to v1.19](../pull/1182) - [ ] <!-- rebase-branch=renovate/golang-1.x -->[deps:chore - update golang Docker tag](../pull/1047) - [ ] <!-- rebase-branch=renovate/github.com-onsi-gomega-1.x -->[deps:chore - update module github.com/onsi/gomega to v1.41.0](../pull/1095) - [ ] <!-- rebase-branch=renovate/zricethezav-gitleaks-8.x -->[deps:chore - update zricethezav/gitleaks Docker tag to v8.30.1](../pull/1092) - [ ] <!-- rebase-all-open-prs -->**Click on this checkbox to rebase all open PRs at once** ## Detected Dependencies <details><summary>dockerfile (15)</summary> <blockquote> <details><summary>deployments/Dockerfile (2)</summary> - `golang 1.17-alpine` → [Updates: `1.26-alpine`] - `docker 20.10-dind` → [Updates: `29.5-dind`] </details> <details><summary>deployments/Dockerfile-gorelease-amd64 (1)</summary> - `horuszup/docker-amd64 20.10-git` </details> <details><summary>deployments/Dockerfile-gorelease-arm64 (1)</summary> - `horuszup/docker-arm64 20.10-git` </details> <details><summary>internal/services/formatters/c/deployments/Dockerfile (1)</summary> - `python 3.10.4-alpine3.14` </details> <details><summary>internal/services/formatters/csharp/deployments/Dockerfile (1)</summary> - `mcr.microsoft.com/dotnet/sdk 6.0-alpine` → [Updates: `10.0-alpine`] </details> <details><summary>internal/services/formatters/elixir/deployments/Dockerfile (1)</summary> - `elixir 1.13-alpine` → [Updates: `1.19-alpine`] </details> <details><summary>internal/services/formatters/generic/deployments/Dockerfile (2)</summary> - `azul/zulu-openjdk-alpine 17` → [Updates: `17.0.19`, `25.0.3`] - `python 3.10.4-alpine3.14` </details> <details><summary>internal/services/formatters/go/deployments/Dockerfile (1)</summary> - `golang 1.17.8-alpine` → [Updates: `1.26.3-alpine`] </details> <details><summary>internal/services/formatters/hcl/deployments/Dockerfile (1)</summary> - `python 3.10.4-alpine3.14` </details> <details><summary>internal/services/formatters/javascript/deployments/Dockerfile (1)</summary> - `node 17.6.0-alpine` → [Updates: `24.16.0-alpine`] </details> <details><summary>internal/services/formatters/leaks/deployments/Dockerfile (1)</summary> - `zricethezav/gitleaks v8.8.7` → [Updates: `v8.30.1`] </details> <details><summary>internal/services/formatters/php/deployments/Dockerfile (1)</summary> - `php 8.1-alpine` → [Updates: `8.5-alpine`] </details> <details><summary>internal/services/formatters/python/deployments/Dockerfile (1)</summary> - `python 3.10.4-alpine3.14` </details> <details><summary>internal/services/formatters/ruby/deployments/Dockerfile (1)</summary> - `ruby 3.1-alpine` → [Updates: `3.4-alpine`, `4.0-alpine`] </details> <details><summary>internal/services/formatters/shell/deployments/Dockerfile (1)</summary> - `alpine 3.16.0` → [Updates: `3.23.4`] </details> </blockquote> </details> <details><summary>github-actions (26)</summary> <blockquote> <details><summary>.github/workflows/build.yaml (4)</summary> - `actions/checkout v3` → [Updates: `v6`] - `actions/setup-go v3` → [Updates: `v6`] - `goreleaser/goreleaser-action v2` → [Updates: `v7`] - `go 1.17` → [Updates: `1.26`] </details> <details><summary>.github/workflows/coverage.yml (3)</summary> - `actions/checkout v3` → [Updates: `v6`] - `actions/setup-go v3` → [Updates: `v6`] - `go 1.17` → [Updates: `1.26`] </details> <details><summary>.github/workflows/dco.yaml (1)</summary> - `ZupIT/zup-dco-validator v1.1` </details> <details><summary>.github/workflows/deploy-cli-language.yml (4)</summary> - `actions/setup-go v3` → [Updates: `v6`] - `actions/checkout v3` → [Updates: `v6`] - `EndBug/add-and-commit v8` → [Updates: `v10`] - `go 1.17` → [Updates: `1.26`] </details> <details><summary>.github/workflows/e2e.yml (3)</summary> - `actions/checkout v3` → [Updates: `v6`] - `actions/setup-go v3` → [Updates: `v6`] - `docker-practice/actions-setup-docker v1` </details> <details><summary>.github/workflows/go-tidy.yml (3)</summary> - `actions/checkout v3` → [Updates: `v6`] - `actions/setup-go v3` → [Updates: `v6`] - `go 1.17` → [Updates: `1.26`] </details> <details><summary>.github/workflows/license.yaml (3)</summary> - `actions/checkout v3` → [Updates: `v6`] - `actions/setup-go v3` → [Updates: `v6`] - `go 1.17` → [Updates: `1.26`] </details> <details><summary>.github/workflows/lint.yml (3)</summary> - `actions/checkout v3` → [Updates: `v6`] - `actions/setup-go v3` → [Updates: `v6`] - `go 1.17` → [Updates: `1.26`] </details> <details><summary>.github/workflows/release-alpha.yml (12)</summary> - `actions/checkout v3` → [Updates: `v6`] - `actions/setup-go v3` → [Updates: `v6`] - `docker/login-action v1` → [Updates: `v4`] - `docker/setup-buildx-action v1` → [Updates: `v4`] - `docker/setup-qemu-action v1` → [Updates: `v4`] - `sigstore/cosign-installer main` - `crazy-max/ghaction-import-gpg v4` → [Updates: `v7`] - `docker/build-push-action v3` → [Updates: `v7`] - `goreleaser/goreleaser-action v2` → [Updates: `v7`] - `dev-drprasad/delete-tag-and-release v0.2.1` → [Updates: `v1.1`] - `softprops/action-gh-release v1` → [Updates: `v3`] - `go 1.17` → [Updates: `1.26`] </details> <details><summary>.github/workflows/release-beta.yml (7)</summary> - `actions/checkout v3` → [Updates: `v6`] - `actions/setup-go v3` → [Updates: `v6`] - `docker/login-action v1` → [Updates: `v4`] - `sigstore/cosign-installer main` - `crazy-max/ghaction-import-gpg v4` → [Updates: `v7`] - `goreleaser/goreleaser-action v2` → [Updates: `v7`] - `go 1.17` → [Updates: `1.26`] </details> <details><summary>.github/workflows/release-final.yml (7)</summary> - `actions/checkout v3` → [Updates: `v6`] - `actions/setup-go v3` → [Updates: `v6`] - `docker/login-action v1` → [Updates: `v4`] - `sigstore/cosign-installer main` - `crazy-max/ghaction-import-gpg v4` → [Updates: `v7`] - `goreleaser/goreleaser-action v2` → [Updates: `v7`] - `go 1.17` → [Updates: `1.26`] </details> <details><summary>.github/workflows/release-rc.yml (7)</summary> - `actions/checkout v3` → [Updates: `v6`] - `actions/setup-go v3` → [Updates: `v6`] - `docker/login-action v1` → [Updates: `v4`] - `sigstore/cosign-installer main` - `crazy-max/ghaction-import-gpg v4` → [Updates: `v7`] - `goreleaser/goreleaser-action v2` → [Updates: `v7`] - `go 1.17` → [Updates: `1.26`] </details> <details><summary>.github/workflows/security.yml (1)</summary> - `actions/checkout v3` → [Updates: `v6`] </details> <details><summary>.github/workflows/test.yml (3)</summary> - `actions/checkout v3` → [Updates: `v6`] - `actions/setup-go v3` → [Updates: `v6`] - `docker-practice/actions-setup-docker v1` </details> <details><summary>.github/workflows/update-horusec-c.yml (4)</summary> - `actions/checkout v3` → [Updates: `v6`] - `sigstore/cosign-installer main` - `docker/login-action v1` → [Updates: `v4`] - `docker/build-push-action v3` → [Updates: `v7`] </details> <details><summary>.github/workflows/update-horusec-csharp.yml (4)</summary> - `actions/checkout v3` → [Updates: `v6`] - `sigstore/cosign-installer main` - `docker/login-action v1` → [Updates: `v4`] - `docker/build-push-action v3` → [Updates: `v7`] </details> <details><summary>.github/workflows/update-horusec-elixir.yml (4)</summary> - `actions/checkout v3` → [Updates: `v6`] - `sigstore/cosign-installer main` - `docker/login-action v1` → [Updates: `v4`] - `docker/build-push-action v3` → [Updates: `v7`] </details> <details><summary>.github/workflows/update-horusec-generic.yml (4)</summary> - `actions/checkout v3` → [Updates: `v6`] - `sigstore/cosign-installer main` - `docker/login-action v1` → [Updates: `v4`] - `docker/build-push-action v3` → [Updates: `v7`] </details> <details><summary>.github/workflows/update-horusec-go.yml (4)</summary> - `actions/checkout v3` → [Updates: `v6`] - `sigstore/cosign-installer main` - `docker/login-action v1` → [Updates: `v4`] - `docker/build-push-action v3` → [Updates: `v7`] </details> <details><summary>.github/workflows/update-horusec-hcl.yml (4)</summary> - `actions/checkout v3` → [Updates: `v6`] - `sigstore/cosign-installer main` - `docker/login-action v1` → [Updates: `v4`] - `docker/build-push-action v3` → [Updates: `v7`] </details> <details><summary>.github/workflows/update-horusec-js.yml (4)</summary> - `actions/checkout v3` → [Updates: `v6`] - `sigstore/cosign-installer main` - `docker/login-action v1` → [Updates: `v4`] - `docker/build-push-action v3` → [Updates: `v7`] </details> <details><summary>.github/workflows/update-horusec-leaks.yml (4)</summary> - `actions/checkout v3` → [Updates: `v6`] - `sigstore/cosign-installer main` - `docker/login-action v1` → [Updates: `v4`] - `docker/build-push-action v3` → [Updates: `v7`] </details> <details><summary>.github/workflows/update-horusec-php.yml (4)</summary> - `actions/checkout v3` → [Updates: `v6`] - `sigstore/cosign-installer main` - `docker/login-action v1` → [Updates: `v4`] - `docker/build-push-action v3` → [Updates: `v7`] </details> <details><summary>.github/workflows/update-horusec-python.yml (4)</summary> - `actions/checkout v3` → [Updates: `v6`] - `sigstore/cosign-installer main` - `docker/login-action v1` → [Updates: `v4`] - `docker/build-push-action v3` → [Updates: `v7`] </details> <details><summary>.github/workflows/update-horusec-ruby.yml (4)</summary> - `actions/checkout v3` → [Updates: `v6`] - `sigstore/cosign-installer main` - `docker/login-action v1` → [Updates: `v4`] - `docker/build-push-action v3` → [Updates: `v7`] </details> <details><summary>.github/workflows/update-horusec-shell.yml (4)</summary> - `actions/checkout v3` → [Updates: `v6`] - `sigstore/cosign-installer main` - `docker/login-action v1` → [Updates: `v4`] - `docker/build-push-action v3` → [Updates: `v7`] </details> </blockquote> </details> <details><summary>gomod (1)</summary> <blockquote> <details><summary>go.mod (21)</summary> - `go 1.17` - `github.com/ZupIT/horusec-devkit v1.0.24` - `github.com/ZupIT/horusec-engine v1.0.1` → [Updates: `v1.0.2`] - `github.com/bmatcuk/doublestar/v4 v4.0.2` → [Updates: `v4.10.0`] - `github.com/briandowns/spinner v1.18.0` → [Updates: `v1.23.2`] - `github.com/docker/docker v20.10.9+incompatible` → [Updates: `v20.10.27+incompatible`, `v28.5.2+incompatible`] - `github.com/go-enry/go-enry/v2 v2.8.2` → [Updates: `v2.9.6`] - `github.com/go-ozzo/ozzo-validation/v4 v4.3.0` - `github.com/gocarina/gocsv v0.0.0-20220304222734-caabc5f00d30@caabc5f00d30` → [Updates: `v0.0.0-20260523204920-c264028e67ea`] - `github.com/google/uuid v1.3.0` → [Updates: `v1.6.0`] - `github.com/iancoleman/strcase v0.2.0` → [Updates: `v0.3.0`] - `github.com/magefile/mage v1.13.0` → [Updates: `v1.17.2`] - `github.com/manifoldco/promptui v0.9.0` - `github.com/onsi/ginkgo v1.16.5` → [Updates: `v2.29.0`] - `github.com/onsi/gomega v1.18.1` → [Updates: `v1.41.0`] - `github.com/opencontainers/image-spec v1.0.2` → [Updates: `v1.1.1`] - `github.com/sirupsen/logrus v1.8.1` → [Updates: `v1.9.4`] - `github.com/spf13/cobra v1.4.0` → [Updates: `v1.10.2`] - `github.com/spf13/pflag v1.0.5` → [Updates: `v1.0.10`] - `github.com/spf13/viper v1.10.1` → [Updates: `v1.21.0`] - `github.com/stretchr/testify v1.7.3` → [Updates: `v1.11.1`] </details> </blockquote> </details> --- - [ ] <!-- manual job -->Check this box to trigger a request for Renovate to run again on this repository
This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
View this repository on the Mend.io Web Portal.
Config Migration Needed
Rate-Limited
The following updates are currently rate-limited. To force their creation now, click on a checkbox below.
Warning
Renovate failed to look up the following dependencies:
Failed to look up github-tags package ZupIT/zup-dco-validator: no-result.Files affected:
.github/workflows/dco.yamlOpen
The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.
Detected Dependencies
dockerfile (15)
github-actions (26)
gomod (1)