This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
Repository Problems
Renovate tried to run on this repository, but found these problems.
⚠️ WARN: Cannot access vulnerability alerts. Please ensure permissions have been granted.
⚠️ WARN: Package lookup failures
Warning
Renovate failed to look up the following dependencies: Failed to look up github-tags package aquasecurity/trivy-action: no-result.
Files affected: .github/workflows/ocm-kit-release.yaml
Open
The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.
Detected Dependencies
dockerfile (1)
ocm-kit/Dockerfile (2)
golang 1.26@sha256:3aff6657219a4d9c14e27fb1d8976c49c29fddb70ba835014f477e1c70636647
gcr.io/distroless/static nonroot@sha256:963fa6c544fe5ce420f1f54fb88b6fb01479f054c8056d0f74cc2c6000df5240 → [Updates: nonroot]
github-actions (5)
.github/workflows/ocm-kit-release.yaml (11)
actions/checkout v7.0.1@3d3c42e5aac5ba805825da76410c181273ba90b1
actions/setup-go v7.0.0@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e
softprops/action-gh-release v3.0.2@3d0d9888cb7fd7b750713d6e236d1fcb99157228
actions/checkout v7.0.1@3d3c42e5aac5ba805825da76410c181273ba90b1
docker/setup-qemu-action v4.2.0@96fe6ef7f33517b61c61be40b68a1882f3264fb8
docker/setup-buildx-action v4.2.0@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c
sigstore/cosign-installer v4.1.2@6f9f17788090df1f26f669e9d70d6ae9567deba6
docker/login-action v4.5.2@371161bbe7024a29a25c5e19bfcbc0804fe9ad2c → [Updates: v4.6.0]
docker/metadata-action v6.2.0@dc802804100637a589fabce1cb79ff13a1411302
docker/build-push-action v7.3.0@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a
aquasecurity/trivy-action v0.36.0@ed142fd0673e97e23eac54620cfb913e5ce36c25
.github/workflows/ocm-kit.yaml (3)
actions/checkout v7.0.1@3d3c42e5aac5ba805825da76410c181273ba90b1
actions/setup-go v7.0.0@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e
golangci/golangci-lint-action v9.3.0@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a
.github/workflows/pull-request.yaml (5)
actions/github-script v9@3a2844b7e9c422d3c10d287c895573f7108da1b3
actions/checkout v7@3d3c42e5aac5ba805825da76410c181273ba90b1
actions/labeler v7@bf12e9b00b37c5c0ca2b87b79b2daf7891dbda13
codelytv/pr-size-labeler v1@095a41fca88b8764fd9e008ad269bcdb82bb38b9
agilepathway/pull-request-label-checker latest@sha256:14f5f3dfda922496d07d53494e2d2b42885165f90677a1c03d600059b7706a61
.github/workflows/renovate.yml (5)
actions/checkout v7.0.1@3d3c42e5aac5ba805825da76410c181273ba90b1
dawidd6/action-download-artifact v21@b6e2e70617bc3265edd6dab6c906732b2f1ae151
actions/create-github-app-token v3.2.0@bcd2ba49218906704ab6c1aa796996da409d3eb1
renovatebot/github-action v46.1.21@1a96852b0384df1837619d04c60b2d10d1f9ff08 → [Updates: v46.2.0]
actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
.github/workflows/stale.yaml (1)
open-component-model/.github main@327ea44865483bb8cf192c76b7574141aacb2b2d
gomod (1)
ocm-kit/go.mod (16)
go 1.26.4
github.com/Masterminds/sprig/v3 v3.3.0
github.com/opencontainers/go-digest v1.0.0
github.com/spf13/cobra v1.10.2
github.com/stretchr/testify v1.11.1
ocm.software/open-component-model/bindings/go/blob v0.0.13
ocm.software/open-component-model/bindings/go/configuration v0.0.15 → [Updates: v0.0.16]
ocm.software/open-component-model/bindings/go/credentials v0.0.14
ocm.software/open-component-model/bindings/go/ctf v0.4.1
ocm.software/open-component-model/bindings/go/descriptor/runtime v0.0.0-20260721102106-6e5e7c37fe13@6e5e7c37fe13 → [Updates: v0.0.0-20260729151447-3653a7d88979]
ocm.software/open-component-model/bindings/go/descriptor/v2 v2.0.3-alpha3
ocm.software/open-component-model/bindings/go/oci v0.0.48
ocm.software/open-component-model/bindings/go/runtime v0.0.8
oras.land/oras-go/v2 v2.6.2
sigs.k8s.io/yaml v1.6.0
github.com/ThalesGroup/crypto11 v1.6.1 → [Updates: v1.6.8]
regex (4)
ocm-kit/flake.nix (1)
go 1.26.4 → [Updates: 1.26.5]
ocm-kit/flake.nix (1)
go 1.26.4 → [Updates: 1.26.5]
ocm-kit/tools.lock (3)
github.com/golangci/golangci-lint/v2/cmd/golangci-lint v2.12.2
github.com/google/osv-scanner/v2/cmd/osv-scanner v2.4.0
ocm.software/open-component-model/cli v0.11.0 → [Updates: v0.12.0]
ocm-kit/tools.lock (3)
github.com/golangci/golangci-lint/v2/cmd/golangci-lint v2.12.2
github.com/google/osv-scanner/v2/cmd/osv-scanner v2.4.0
ocm.software/open-component-model/cli v0.11.0 → [Updates: v0.12.0]
renovate-config (1)
.github/renovate.json
This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
Repository Problems
Renovate tried to run on this repository, but found these problems.
Warning
Renovate failed to look up the following dependencies:
Failed to look up github-tags package aquasecurity/trivy-action: no-result.Files affected:
.github/workflows/ocm-kit-release.yamlOpen
The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.
github.com/ThalesGroup/crypto11,ocm.software/open-component-model/bindings/go/configuration,ocm.software/open-component-model/bindings/go/descriptor/runtime)Detected Dependencies
dockerfile (1)
github-actions (5)
gomod (1)
regex (4)
renovate-config (1)