Skip to content

Bump dependencies - #159

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/minor
Open

Bump dependencies#159
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/minor

Conversation

@renovate

@renovate renovate Bot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Manager Type Update Change
actions/checkout github-actions action minor v6.0.3v6.1.0
actions/setup-dotnet github-actions action minor v5.3.0v5.4.0
docker-buildx regex run minor 0.34.10.36.0
docker-compose regex run minor 5.1.45.3.1
docker/login-action github-actions action minor v4.2.0v4.6.0
docker/setup-buildx-action github-actions action minor v4.1.0v4.2.0
docker/setup-qemu-action github-actions action minor v4.1.0v4.2.0
dotnet-sdk regex script patch 10.0.30110.0.302
dotnet-sdk regex task patch 10.0.30110.0.302
dotnet-sdk regex action patch 10.0.30110.0.302
mcr.microsoft.com/dotnet/sdk dockerfile final patch 10.0.301-resolute10.0.302-resolute

Release Notes

actions/checkout (actions/checkout)

v6.1.0

Compare Source

actions/setup-dotnet (actions/setup-dotnet)

v5.4.0

Compare Source

What's Changed
Enhancements
Documentation
Bug Fixes
Dependency Updates
New Contributors

Full Changelog: actions/setup-dotnet@v5...v5.4.0

docker/buildx (docker-buildx)

v0.36.0

Compare Source

Welcome to the v0.36.0 release of buildx!

Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

Contributors
  • CrazyMax
  • Tõnis Tiigi
  • Sebastiaan van Stijn
  • MohammadHasan Akbari
  • Matt Van Horn
  • amarkdotdev
  • Areeb Ahmed
  • Guillaume Lours
  • Paweł Gronowski
  • Pierre Gimalac
  • s3onghyun
Notables Changes
  • Default source policy can now validate the authenticity of BuildKit release images when creating docker-container builder with docker buildx create command. #​3961
  • Bake command now supports overriding declared secret sources. #​3962
  • Broken builder instances are now correctly handled on removal. #​3934
  • Bake now supports resolving files relative to the bake file location instead of the current working directory with BUILDX_BAKE_FILE_RELATIVE_PATHS=true. #​3935
  • Source policies now support new array.flatten builtin and OPA template strings. #​3913
  • Imagetools commands now do extra validation of the descriptor inputs from files. #​3933
  • Windows release binaries are now code-signed, matching the signing coverage already provided for macOS release artifacts. #​3978
  • Compose compatibility has been updated to v2.13.0. #​3929
  • Fix source policy support on Windows when loading local files inside policy. #​3944
  • Fix Kubernetes driver random load balancer support. #​3861
  • Fix Kubernetes driver builds hanging indefinitely when the remote exec stream ends. #​3966
  • Fix iidfile for containerd-backed Docker driver. #​3952
  • Fix authority pseudo-header when using remote driver. #​3928
  • Fix possible FD leak when using source policies. #​3943
Dependency Changes
  • github.com/Microsoft/go-winio v0.6.2 -> ad3df93
  • github.com/ProtonMail/go-crypto v1.3.0 -> v1.4.1
  • github.com/aws/aws-sdk-go-v2 v1.42.0 -> v1.43.0
  • github.com/aws/aws-sdk-go-v2/config v1.32.24 -> v1.32.31
  • github.com/aws/aws-sdk-go-v2/credentials v1.19.23 -> v1.19.30
  • github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.29 -> v1.18.31
  • github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.29 -> v1.4.31
  • github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.29 -> v2.7.31
  • github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.30 -> v1.4.32
  • github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.12 -> v1.13.13
  • github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.29 -> v1.13.31
  • github.com/aws/aws-sdk-go-v2/service/signin v1.1.5 -> v1.5.0
  • github.com/aws/aws-sdk-go-v2/service/sso v1.31.3 -> v1.33.0
  • github.com/aws/aws-sdk-go-v2/service/ssooidc v1.36.6 -> v1.38.0
  • github.com/aws/aws-sdk-go-v2/service/sts v1.43.3 -> v1.45.0
  • github.com/aws/smithy-go v1.27.2 -> v1.27.4
  • github.com/compose-spec/compose-go/v2 v2.10.2 -> v2.13.0
  • github.com/containerd/containerd/api v1.10.0 -> v1.11.1
  • github.com/containerd/containerd/v2 v2.2.4 -> v2.3.3
  • github.com/containerd/ttrpc v1.2.8 -> v1.2.9
  • github.com/docker/cli v29.5.3 -> v29.6.2
  • github.com/go-openapi/errors v0.22.7 -> v0.22.8
  • github.com/go-openapi/loads v0.23.3 -> v0.24.0
  • github.com/go-openapi/runtime v0.32.3 -> v0.32.4
  • github.com/go-openapi/spec v0.22.5 -> v0.22.6
  • github.com/go-openapi/strfmt v0.26.3 -> v0.26.4
  • github.com/go-openapi/swag v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/cmdutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/conv v0.26.0 -> v0.27.0
  • github.com/go-openapi/swag/fileutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/jsonname v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/jsonutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/loading v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/mangling v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/netutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/stringutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/typeutils v0.26.0 -> v0.27.0
  • github.com/go-openapi/swag/yamlutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/validate v0.25.3 -> v0.26.0
  • github.com/google/go-containerregistry v0.21.6 -> v0.21.7
  • github.com/klauspost/compress v1.18.6 -> v1.19.1
  • github.com/lestrrat-go/httprc/v3 v3.0.1 -> v3.0.2
  • github.com/lestrrat-go/jwx/v3 v3.0.11 -> v3.0.13
  • github.com/moby/buildkit v0.31.0 -> v0.32.0
  • github.com/moby/go-archive v0.2.0 -> v0.2.1
  • github.com/moby/moby/api v1.54.2 -> v1.55.0
  • github.com/moby/moby/client v0.4.1 -> v0.5.0
  • github.com/moby/policy-helpers d5411a9 -> 856be88
  • github.com/moby/sys/user v0.4.0 -> v0.4.1
  • github.com/open-policy-agent/opa v1.10.1 -> v1.14.1
  • github.com/segmentio/asm v1.2.0 -> v1.2.1
  • github.com/sigstore/rekor v1.5.2 -> v1.5.3
  • github.com/sigstore/rekor-tiles/v2 5d098a2 -> v2.3.0
  • github.com/sigstore/sigstore-go v1.2.1 -> v1.2.2
  • github.com/tonistiigi/fsutil 0257b33 -> 6d9dc2e
  • github.com/valyala/fastjson v1.6.4 -> v1.6.7
  • github.com/vektah/gqlparser/v2 v2.5.30 -> v2.5.32
  • golang.org/x/crypto v0.52.0 -> v0.54.0
  • golang.org/x/mod v0.36.0 -> v0.38.0
  • golang.org/x/net v0.55.0 -> v0.57.0
  • golang.org/x/sync v0.20.0 -> v0.22.0
  • golang.org/x/sys v0.45.0 -> v0.47.0
  • golang.org/x/term v0.43.0 -> v0.45.0
  • golang.org/x/text v0.37.0 -> v0.40.0
  • golang.org/x/tools v0.45.0 -> v0.47.0
  • google.golang.org/grpc v1.81.1 -> v1.82.1
  • google.golang.org/protobuf v1.36.11 -> f2248ac
  • k8s.io/api v0.35.4 -> v0.36.0
  • k8s.io/apimachinery v0.35.4 -> v0.36.0
  • k8s.io/client-go v0.35.4 -> v0.36.0
  • k8s.io/kube-openapi 589584f -> 5883c5e
  • k8s.io/streaming v0.36.0 new
  • k8s.io/utils bc988d5 -> 28399d8
  • sigs.k8s.io/structured-merge-diff/v6 v6.3.0 -> v6.3.2

Previous release can be found at v0.35.0

v0.35.0

Compare Source

buildx 0.35.0

Welcome to the v0.35.0 release of buildx!

Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

Contributors
  • CrazyMax
  • Tõnis Tiigi
  • Sebastiaan van Stijn
  • Areeb Ahmed
  • Jiří Moravčík
  • Sopho Merkviladze
  • Akihiro Suda
  • Jonathan A. Sternberg
Notable Changes
  • Local output now supports a mode=delete attribute for build and bake commands. This mode replaces the destination directory with the build result instead of merging it. Similar to the --delete flag in rsync. For safety, this mode is only allowed if the destination directory is a subdirectory of the working directory. To export to other destinations, --allow=buildx.local.delete needs to be provided or the action confirmed by the user in the TUI. When exporting multi-platform results, this mode requires BuildKit v0.31.0+. #​3883
  • Source policies now support the new exec proxy feature of BuildKit v0.31.0+ that captures the network traffic of your build steps. To opt in to network proxy, your Dockerfile.rego source policy needs to return caps: { "exec.proxy": true } in the evaluation decision. After opting in, you can control what network requests are allowed to be made by the run steps with policy rules for regular input.http sources, similar to how this was done for direct HTTP build sources before. You can also opt in your whole builder with --buildkitd-flags '--proxy-network' in buildx create. #​3895
  • Resource limits can now be set for CPU and memory using the --resource flag in build and the resource key in bake commands. This feature requires BuildKit v0.31.0+ and Dockerfile v1.25.0+. #​3876 #​3900
  • Fix possible "closed channel" panic. #​3886
Dependency Changes
  • github.com/aws/aws-sdk-go-v2 v1.41.7 -> v1.42.0
  • github.com/aws/aws-sdk-go-v2/config v1.32.17 -> v1.32.24
  • github.com/aws/aws-sdk-go-v2/credentials v1.19.16 -> v1.19.23
  • github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.23 -> v1.18.29
  • github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.23 -> v1.4.29
  • github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.23 -> v2.7.29
  • github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.24 -> v1.4.30
  • github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.9 -> v1.13.12
  • github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.23 -> v1.13.29
  • github.com/aws/aws-sdk-go-v2/service/signin v1.0.11 -> v1.1.5
  • github.com/aws/aws-sdk-go-v2/service/sso v1.30.17 -> v1.31.3
  • github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.21 -> v1.36.6
  • github.com/aws/aws-sdk-go-v2/service/sts v1.42.1 -> v1.43.3
  • github.com/aws/smithy-go v1.25.1 -> v1.27.2
  • github.com/containerd/containerd/v2 v2.2.3 -> v2.2.4
  • github.com/containerd/continuity v0.4.5 -> v0.5.0
  • github.com/containerd/platforms v1.0.0-rc.2 -> v1.0.0-rc.4
  • github.com/containerd/typeurl/v2 v2.2.3 -> v2.3.0
  • github.com/docker/cli v29.4.3 -> v29.5.3
  • github.com/docker/distribution v2.8.3 new
  • github.com/docker/docker-credential-helpers v0.9.5 -> v0.9.8
  • github.com/go-openapi/analysis v0.24.3 -> v0.25.2
  • github.com/go-openapi/jsonpointer v0.22.5 -> v0.23.1
  • github.com/go-openapi/jsonreference v0.21.5 -> v0.21.6
  • github.com/go-openapi/runtime v0.29.3 -> v0.32.3
  • github.com/go-openapi/runtime/server-middleware v0.30.0 new
  • github.com/go-openapi/spec v0.22.4 -> v0.22.5
  • github.com/go-openapi/strfmt v0.26.1 -> v0.26.3
  • github.com/go-openapi/swag v0.25.5 -> v0.26.0
  • github.com/go-openapi/swag/cmdutils v0.25.5 -> v0.26.0
  • github.com/go-openapi/swag/conv v0.25.5 -> v0.26.0
  • github.com/go-openapi/swag/fileutils v0.25.5 -> v0.26.0
  • github.com/go-openapi/swag/jsonname v0.25.5 -> v0.26.0
  • github.com/go-openapi/swag/jsonutils v0.25.5 -> v0.26.0
  • github.com/go-openapi/swag/loading v0.25.5 -> v0.26.0
  • github.com/go-openapi/swag/mangling v0.25.5 -> v0.26.0
  • github.com/go-openapi/swag/netutils v0.25.5 -> v0.26.0
  • github.com/go-openapi/swag/stringutils v0.25.5 -> v0.26.0
  • github.com/go-openapi/swag/typeutils v0.25.5 -> v0.26.0
  • github.com/go-openapi/swag/yamlutils v0.25.5 -> v0.26.0
  • github.com/go-openapi/validate v0.25.2 -> v0.25.3
  • github.com/google/certificate-transparency-go v1.3.2 -> v1.3.3
  • github.com/google/go-containerregistry v0.20.7 -> v0.21.6
  • github.com/gorilla/mux v1.8.1 new
  • github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 -> v2.29.0
  • github.com/in-toto/attestation v1.1.2 -> v1.2.0
  • github.com/moby/buildkit v0.30.0 -> v0.31.0
  • github.com/moby/policy-helpers a39d601 -> d5411a9
  • github.com/moby/sys/sequential v0.6.0 -> v0.7.0
  • github.com/pelletier/go-toml/v2 v2.2.4 -> v2.3.1
  • github.com/prometheus/common v0.66.1 -> v0.67.5
  • github.com/prometheus/procfs v0.17.0 -> v0.20.1
  • github.com/secure-systems-lab/go-securesystemslib v0.10.0 -> v0.11.0
  • github.com/sigstore/protobuf-specs v0.5.0 -> v0.5.1
  • github.com/sigstore/rekor v1.5.0 -> v1.5.2
  • github.com/sigstore/rekor-tiles/v2 v2.0.1 -> 5d098a2
  • github.com/sigstore/sigstore v1.10.5 -> v1.10.8
  • github.com/sigstore/sigstore-go v1.1.4 -> v1.2.1
  • github.com/sigstore/timestamp-authority/v2 v2.0.6 -> v2.1.2
  • github.com/theupdateframework/go-tuf/v2 v2.4.1 -> v2.4.2
  • github.com/tonistiigi/fsutil a2aa163 -> 0257b33
  • github.com/transparency-dev/formats 404c0d5 -> v0.1.1
  • github.com/youmark/pkcs8 a2c0da2 new
  • go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.68.0 -> v0.69.0
  • go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace v0.68.0 -> v0.69.0
  • go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.68.0 -> v0.69.0
  • go.opentelemetry.io/otel v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.42.0 -> v1.44.0
  • go.opentelemetry.io/otel/metric v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/sdk v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/sdk/metric v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/trace v1.43.0 -> v1.44.0
  • go.yaml.in/yaml/v2 v2.4.3 -> v2.4.4
  • google.golang.org/genproto/googleapis/api 6f92a3b -> 3dc84a4
  • google.golang.org/genproto/googleapis/rpc 6f92a3b -> 3dc84a4
  • google.golang.org/grpc v1.80.0 -> v1.81.1
  • google.golang.org/grpc/cmd/protoc-gen-go-grpc v1.5.1 -> v1.6.1
  • k8s.io/klog/v2 v2.130.1 -> v2.140.0

Previous release can be found at v0.34.1

docker/compose (docker-compose)

v5.3.1

Compare Source

What's Changed

🔧 Internal
⚙️ Dependencies

New Contributors

Full Changelog: docker/compose@v5.3.0...v5.3.1

v5.3.0

Compare Source

What's Changed

ℹ️ This release introduces native support for init containers.

✨ Improvements
🐛 Fixes
🔧 Internal
⚙️ Dependencies

New Contributors

Full Changelog: docker/compose@v5.2.0...v5.3.0

v5.2.0

Compare Source

What's Changed

ℹ️ This version introduces a new reconciliation algorithm between the observed state and the expected state.

If you experience any issues with a Compose workload that was previously working, please open an issue.

✨ Improvements
🐛 Fixes
🔧 Internal
⚙️ Dependencies

New Contributors

Full Changelog: docker/compose@v5.1.4...v5.2.0

docker/login-action (docker/login-action)

v4.6.0

Compare Source

v4.5.2

Compare Source

v4.5.1

Compare Source

v4.5.0

Compare Source

v4.4.0

Compare Source

v4.3.0

Compare Source

Full Changelog: docker/login-action@v4.2.0...v4.3.0

docker/setup-buildx-action (docker/setup-buildx-action)

v4.2.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.1.0...v4.2.0

docker/setup-qemu-action (docker/setup-qemu-action)

v4.2.0

Compare Source

dotnet/sdk (dotnet-sdk)

v10.0.302: .NET 10.0.10

Compare Source

Release

What's Changed

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Changes that only affect dependencies label Jun 18, 2026
@renovate
renovate Bot requested a review from gitfool as a code owner June 18, 2026 00:03
@renovate renovate Bot changed the title Bump dependencies to v0.35.0 Bump dependencies Jun 22, 2026
@renovate
renovate Bot force-pushed the renovate/minor branch 2 times, most recently from c062483 to 6eb738c Compare June 26, 2026 04:52
@renovate
renovate Bot force-pushed the renovate/minor branch 4 times, most recently from 91c1a4a to d89107d Compare July 7, 2026 14:11
@renovate
renovate Bot force-pushed the renovate/minor branch 5 times, most recently from 8d45f50 to 45a0d45 Compare July 21, 2026 02:43
@renovate
renovate Bot force-pushed the renovate/minor branch 7 times, most recently from 645b1dc to c268697 Compare July 29, 2026 18:55
@renovate
renovate Bot force-pushed the renovate/minor branch from c268697 to 41982bc Compare July 29, 2026 22:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Changes that only affect dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants