Renovate Bot
55f480b64a
Update dependency forgejo/release-notes-assistant to v1.7.2 (forgejo) ( #12924 )
2026-06-05 12:45:11 +02:00
Renovate Bot and Gusted
18f12ee159
Pin dependencies (forgejo) ( #12941 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12941
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-06-05 11:23:21 +02:00
Renovate Bot and Gusted
2394f1a4e4
Update vitest monorepo to v4.1.8 (forgejo) ( #12894 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12894
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-06-05 00:54:11 +02:00
Renovate Bot and Gusted
fc09cf1a33
Update forgejo/forgejo-build-publish to v5.7.1 (forgejo) ( #12925 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12925
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-06-05 00:38:31 +02:00
Renovate Bot
4c15c13ad6
Update actions/setup-forgejo to v3.2.0 (forgejo) ( #12926 )
2026-06-04 19:45:07 +02:00
Renovate Bot and Mathieu Fenniak
e2c2aa446f
Pin dependencies (forgejo) ( #12923 )
...
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [https://data.forgejo.org/actions/cache ](https://github.com/actions/cache ) | action | pin | `v5` → `v5.0.5` |
| [https://data.forgejo.org/actions/cascading-pr ](https://code.forgejo.org/actions/cascading-pr ) | action | pinDigest | → `b52d5b1` |
| [https://data.forgejo.org/actions/checkout ](https://github.com/actions/checkout ) | action | pin | `v6` → `v6.0.3` |
| [https://data.forgejo.org/actions/git-backporting ](https://code.forgejo.org/actions/git-backporting ) | action | pinDigest | → `08da0b0` |
| [https://data.forgejo.org/actions/setup-forgejo ](https://code.forgejo.org/actions/setup-forgejo ) | action | pinDigest | → `650f7cf` |
| [https://data.forgejo.org/actions/setup-go ](https://github.com/actions/setup-go ) | action | pin | `v6` → `v6.4.0` |
| [https://data.forgejo.org/actions/setup-node ](https://github.com/actions/setup-node ) | action | pin | `v6` → `v6.4.0` |
| [https://data.forgejo.org/forgejo/forgejo-build-publish ](https://code.forgejo.org/forgejo/forgejo-build-publish ) | action | pinDigest | → `970e852` |
| [https://data.forgejo.org/forgejo/set-milestone ](https://code.forgejo.org/forgejo/set-milestone ) | action | pinDigest | → `4010c1a` |
| [https://data.forgejo.org/forgejo/upload-artifact ](https://code.forgejo.org/forgejo/upload-artifact ) | action | pin | `v5` → `v5` |
| [https://data.forgejo.org/infrastructure/issue-action ](https://code.forgejo.org/infrastructure/issue-action ) | action | pinDigest | → `c668390` |
| [https://data.forgejo.org/infrastructure/next-digest ](https://code.forgejo.org/infrastructure/next-digest ) | action | pinDigest | → `e220261` |
| [https://data.forgejo.org/tj-actions/changed-files ](https://github.com/tj-actions/changed-files ) | action | pin | `v47` → `v47.0.6` |
Add the preset `:preserveSemverRanges` to your config if you don't want to pin your dependencies.
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions ) if that's undesired.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDguMiIsInVwZGF0ZWRJblZlciI6IjQzLjIwOC4yIiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12923
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-06-04 16:09:32 +02:00
Renovate Bot and Gusted
377c455062
Update module github.com/jackc/pgx/v5 to v5.10.0 (forgejo) ( #12914 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12914
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-06-03 04:28:30 +02:00
Renovate Bot and Gusted
eda4c387b8
Update go-openapi packages to v0.22.5 (forgejo) ( #12909 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12909
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-06-03 02:48:14 +02:00
Renovate Bot
4bdb8f9b6a
Update golang packages to v1.26.4 (forgejo) ( #12908 )
2026-06-03 02:21:47 +02:00
Renovate Bot
1d12151086
Update module github.com/editorconfig-checker/editorconfig-checker/v3/cmd/editorconfig-checker to v3.7.0 (forgejo) ( #12896 )
2026-06-02 16:04:13 +02:00
Renovate Bot and Gusted
667479c7b0
Update dependency @google/model-viewer to v4.3.0 (forgejo) ( #12895 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12895
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-06-02 14:45:57 +02:00
Renovate Bot
cbf653dad2
Update linters (forgejo) ( #12893 )
2026-06-02 14:10:40 +02:00
Renovate Bot and Gusted
c4520693aa
Update module github.com/SaveTheRbtz/zstd-seekable-format-go/pkg to v0.9.0 (forgejo) ( #12884 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12884
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-06-02 12:51:52 +02:00
Renovate Bot
2e8380025c
Update vitest monorepo to v4.1.7 (forgejo) ( #12860 )
2026-06-01 14:29:13 +02:00
Renovate Bot and Gusted
dcccb8baee
Update dependency webpack-cli to v7.0.3 (forgejo) ( #12839 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12839
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-06-01 11:12:47 +02:00
Renovate Bot
08f399172c
Update dependency @vue/test-utils to v2.4.10 (forgejo) ( #12858 )
2026-06-01 11:12:09 +02:00
Renovate Bot
167f022e8f
Update renovate Docker tag to v43.205.2 (forgejo) ( #12857 )
2026-06-01 11:10:19 +02:00
Renovate Bot and Gusted
3b7620ff43
Update dependency @stoplight/spectral-cli to v6.16.0 (forgejo) ( #12861 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12861
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-06-01 11:09:42 +02:00
Renovate Bot and Gusted
95602c7625
Update dependency vite-string-plugin to v2.0.4 (forgejo) ( #12859 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12859
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-06-01 11:09:13 +02:00
Renovate Bot and Gusted
2214be7f77
Update dependency @playwright/test to v1.60.0 (forgejo) ( #12849 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12849
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-31 20:20:28 +02:00
Renovate Bot
ba3f54b283
Update linters (forgejo) ( #12848 )
2026-05-31 18:09:30 +02:00
Renovate Bot
ff38c2ba7c
Update dependency @vitejs/plugin-vue to v6.0.7 (forgejo) ( #12847 )
2026-05-31 16:20:17 +02:00
Renovate Bot
74e8029ef7
Update dependency @axe-core/playwright to v4.11.3 (forgejo) ( #12846 )
2026-05-31 16:15:16 +02:00
Renovate Bot and Gusted
8ab43cbc4c
Update https://data.forgejo.org/forgejo/forgejo-build-publish action to v5.7.0 (forgejo) ( #12800 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12800
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-29 23:12:35 +02:00
Renovate Bot and Gusted
498a64cc0e
Update module github.com/go-swagger/go-swagger/cmd/swagger to v0.34.0 (forgejo) ( #12803 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12803
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-29 23:11:29 +02:00
Renovate Bot and Mathieu Fenniak
57fde010dd
Update module github.com/redis/go-redis/v9 to v9.20.0 (forgejo) ( #12804 )
...
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/ ) | [Confidence](https://docs.renovatebot.com/merge-confidence/ ) |
|---|---|---|---|
| [github.com/redis/go-redis/v9](https://github.com/redis/go-redis ) | `v9.19.0` → `v9.20.0` |  |  |
---
### Release Notes
<details>
<summary>redis/go-redis (github.com/redis/go-redis/v9)</summary>
### [`v9.20.0`](https://github.com/redis/go-redis/releases/tag/v9.20.0 ): 9.20.0
[Compare Source](https://github.com/redis/go-redis/compare/v9.19.0...v9.20.0 )
#### 🚀 Highlights
##### Redis 8.8 Support
This release adds support for **Redis 8.8**. The README's supported-versions list now includes Redis 8.8 alongside 8.0/8.2/8.4, and CI exercises the `8.8` client-libs-test image across the full suite (Makefile, build workflow, doctests, run-tests action, and docker-compose).
Coverage for the new commands that ship in the 8.x line, rounded out in this release:
- **`AR*` array data type** ([#​3813](https://github.com/redis/go-redis/pull/3813 )) — new array data structure, exposed via the `ArrayCmdable` interface (see the experimental-features highlight below).
- **`INCREX`** ([#​3816](https://github.com/redis/go-redis/pull/3816 )) — atomic increment with expiration in a single round-trip.
- **`XNACK`** ([#​3790](https://github.com/redis/go-redis/pull/3790 )) — explicit negative-acknowledge of pending stream entries.
- **`XAUTOCLAIM` PEL deletes** ([#​3798](https://github.com/redis/go-redis/pull/3798 )) — `XAUTOCLAIM`/`XAUTOCLAIMJUSTID` now return the list of deleted message IDs from the pending entries list.
- **`TS.RANGE` multiple aggregators** ([#​3791](https://github.com/redis/go-redis/pull/3791 )) — `TS.RANGE`/`TS.REVRANGE`/`TS.MRANGE`/`TS.MREVRANGE` accept multiple aggregators in a single call.
- **`Z(UNION|INTER|DIFF)` `COUNT` aggregator** ([#​3802](https://github.com/redis/go-redis/pull/3802 )) — `COUNT` reducer for sorted-set set operations.
- **`JSON.SET FPHA`** ([#​3797](https://github.com/redis/go-redis/pull/3797 )) — new `FPHA` argument that specifies the floating-point type for homogeneous FP arrays.
CI image bump ([#​3814](https://github.com/redis/go-redis/pull/3814 )) by [@​ofekshenawa](https://github.com/ofekshenawa ). Command coverage contributions by [@​cxljs](https://github.com/cxljs ), [@​elena-kolevska](https://github.com/elena-kolevska ), [@​Khukharr](https://github.com/Khukharr ), [@​ndyakov](https://github.com/ndyakov ), and [@​ofekshenawa](https://github.com/ofekshenawa ).
##### Stable RESP3 for RediSearch (`UnstableResp3` deprecated)
`FT.SEARCH`, `FT.AGGREGATE`, `FT.INFO`, `FT.SPELLCHECK`, and `FT.SYNDUMP` now parse RESP3 (map) responses into the same typed result objects as RESP2 — `Val()` and `Result()` work uniformly on both protocols, no flag required. Previously, RESP3 search responses required `UnstableResp3: true` and were returned as opaque maps accessible only via `RawResult()` / `RawVal()`.
As a result, the `UnstableResp3` option is now a **no-op** across every options struct (`Options`, `ClusterOptions`, `UniversalOptions`, `FailoverOptions`, `RingOptions`) and has been marked `// Deprecated:`. The field is retained for backwards compatibility — existing code that sets `UnstableResp3: true` will continue to compile and behave identically — but it will be removed in a future release and new code should not set it. `RawResult()` / `RawVal()` continue to work for callers that prefer the raw RESP payload.
([#​3741](https://github.com/redis/go-redis/pull/3741 )) by [@​ndyakov](https://github.com/ndyakov )
##### Experimental Array Data Structure Commands
Adds an experimental `ArrayCmdable` interface with the `AR*` command family (`ARSet`, `ARGet`, `ARGetRange`, `ARMSet`, `ARMGet`, `ARDel`, `ARDelRange`, `ARScan`, `ARSeek`, `ARNext`, `ARLastItems`, `ARGrep`, `ARGrepWithValues`, `ARInfo`/`ARInfoFull`, and typed reducers `AROpSum`/`AROpMin`/`AROpMax`/`AROpAnd`/`AROpOr`/`AROpXor`/`AROpMatch`/`AROpUsed`) for working with Redis 8.8's new array data type. **API is experimental and may change in a future release.**
([#​3813](https://github.com/redis/go-redis/pull/3813 )) by [@​cxljs](https://github.com/cxljs )
#### ✨ New Features
- **RESP3 search parser**: First-class RESP3 parsing for `FT.SEARCH`/`FT.AGGREGATE`/`FT.INFO`/`FT.SPELLCHECK`/`FT.SYNDUMP` responses with backwards compatibility for RESP2 ([#​3741](https://github.com/redis/go-redis/pull/3741 )) by [@​ndyakov](https://github.com/ndyakov )
- **INCREX**: New `INCREX` command support — atomic increment with expiration ([#​3816](https://github.com/redis/go-redis/pull/3816 )) by [@​ndyakov](https://github.com/ndyakov )
- **XNACK**: Client support for the `XNACK` stream command for explicitly negative-acknowledging pending entries ([#​3790](https://github.com/redis/go-redis/pull/3790 )) by [@​elena-kolevska](https://github.com/elena-kolevska )
- **TS range multiple aggregators**: `TS.RANGE`/`TS.REVRANGE`/`TS.MRANGE`/`TS.MREVRANGE` now accept multiple aggregators in a single call ([#​3791](https://github.com/redis/go-redis/pull/3791 )) by [@​elena-kolevska](https://github.com/elena-kolevska )
- **`XAutoClaim` deleted IDs**: `XAUTOCLAIM`/`XAUTOCLAIMJUSTID` now return the list of deleted message IDs from the PEL ([#​3798](https://github.com/redis/go-redis/pull/3798 )) by [@​Khukharr](https://github.com/Khukharr )
- **`JSON.SET FPHA`**: `JSON.SET` accepts a new `FPHA` argument that specifies the floating-point type for homogeneous floating-point arrays ([#​3797](https://github.com/redis/go-redis/pull/3797 )) by [@​ndyakov](https://github.com/ndyakov )
- **Sorted-set union/intersection COUNT**: `ZUNION`/`ZINTER`/`ZDIFF` aggregator now supports `COUNT` ([#​3802](https://github.com/redis/go-redis/pull/3802 )) by [@​ofekshenawa](https://github.com/ofekshenawa )
- **`FT.HYBRID` vector validation**: Validates hybrid-search vector input types and adds proper typed vector parameters ([#​3756](https://github.com/redis/go-redis/pull/3756 )) by [@​DengY11](https://github.com/DengY11 )
- **Cluster pool wait stats**: `ClusterClient.PoolStats()` now accumulates `WaitCount` and `WaitDurationNs` across all node pools (previously always zero) ([#​3809](https://github.com/redis/go-redis/pull/3809 )) by [@​LINKIWI](https://github.com/LINKIWI )
#### 🐛 Bug Fixes
- **TLS-only Cluster PubSub**: `CLUSTER SLOTS` port-0 entries now fall back to the origin endpoint's port, fixing `dial tcp <ip>:0: connection refused` on TLS-only clusters started with `--port 0 --tls-port <port>` (fixes [#​3726](https://github.com/redis/go-redis/issues/3726 )) ([#​3828](https://github.com/redis/go-redis/pull/3828 )) by [@​ndyakov](https://github.com/ndyakov )
- **Sharded PubSub reconnect routing**: `PubSub.conn()` now passes both regular (`c.channels`) and sharded (`c.schannels`) channels into the per-PubSub `newConn` closure. Previously, `ClusterClient.SSubscribe`-only PubSubs reconnected to a random node (because the routing closure saw an empty channel list), the `SSUBSCRIBE` was sent to the wrong shard, and the resulting `MOVED` reply was silently dropped ([#​3829](https://github.com/redis/go-redis/pull/3829 )) by [@​ndyakov](https://github.com/ndyakov )
- **ClusterClient `Watch` retry**: User errors returned from a `Watch` callback are no longer subjected to cluster-retry classification; transient cluster errors still retry, but a callback returning e.g. `net.ErrClosed` short-circuits immediately ([#​3821](https://github.com/redis/go-redis/pull/3821 )) by [@​obiyang](https://github.com/obiyang )
- **Sentinel concurrent-probe leak**: `MasterAddr`'s concurrent sentinel probe now closes the non-winning sentinel clients instead of leaking them ([#​3827](https://github.com/redis/go-redis/pull/3827 )) by [@​cxljs](https://github.com/cxljs )
- **Sentinel rediscovery loop on master-only setups**: `replicaAddrs` no longer tears down the cached sentinel client when the replica list is empty, eliminating a continuous rediscovery loop on master-only Sentinel deployments that flooded logs and added per-operation latency ([#​3795](https://github.com/redis/go-redis/pull/3795 )) by [@​shahyash2609](https://github.com/shahyash2609 )
- **Pool `CloseConn` hooks**: `Pool.CloseConn` now triggers registered hooks, fixing a memory leak when connections are closed explicitly rather than via the normal removal path ([#​3818](https://github.com/redis/go-redis/pull/3818 )) by [@​ndyakov](https://github.com/ndyakov )
- **Dial TCP error redirection**: Wrapped `dial tcp` errors are now correctly classified as redirectable so cluster routing can recover from a single unreachable node ([#​3810](https://github.com/redis/go-redis/pull/3810 )) by [@​vladisa88](https://github.com/vladisa88 )
- **Pool `Close` health checks**: `ConnPool.Close` now only runs health checks against idle connections, avoiding spurious activity on connections still in use ([#​3805](https://github.com/redis/go-redis/pull/3805 )) by [@​ndyakov](https://github.com/ndyakov )
- **VLinks return type**: Fixed the return type of `VLINKS`/`VLINKSWITHSCORES` vector-set replies ([#​3820](https://github.com/redis/go-redis/pull/3820 )) by [@​romanpovol](https://github.com/romanpovol )
#### 🧪 Testing & Infrastructure
- **Flaky tests**: Stabilized several flaky tests in the sentinel and pool suites ([#​3815](https://github.com/redis/go-redis/pull/3815 )) by [@​ndyakov](https://github.com/ndyakov )
- **Sentinel failover metric race**: Fixed a data race in the sentinel failover metric test ([#​3824](https://github.com/redis/go-redis/pull/3824 )) by [@​cxljs](https://github.com/cxljs )
- **`waitForSentinelClusterStable` post-conditions**: The sentinel test harness now waits for replicas to be fully connected (not just present in the count) and is robust to randomized spec ordering after failover specs, eliminating an intermittent `Expected master to equal slave` flake ([#​3830](https://github.com/redis/go-redis/pull/3830 )) by [@​ndyakov](https://github.com/ndyakov )
- **`govulncheck` workflow**: New scheduled GitHub Actions workflow runs `govulncheck` on every push, PR, and weekly, surfacing newly disclosed Go vulnerabilities even when no code changes ([#​3779](https://github.com/redis/go-redis/pull/3779 )) by [@​solardome](https://github.com/solardome )
- **CI Redis 8.8-rc1**: CI now exercises the 8.8-rc1 Redis image ([#​3814](https://github.com/redis/go-redis/pull/3814 )) by [@​ofekshenawa](https://github.com/ofekshenawa )
#### 🧰 Maintenance
- **`Cmd.Slot()` lookup refactor**: Caches the per-command `CommandInfo` and short-circuits keyless commands before the switch dispatch, removing redundant `Peek` calls ([#​3804](https://github.com/redis/go-redis/pull/3804 )) by [@​retr0-kernel](https://github.com/retr0-kernel )
- **stdlib `math/rand`**: Replaced `internal/rand` with `math/rand` from the standard library now that the minimum Go version is 1.24 ([#​3823](https://github.com/redis/go-redis/pull/3823 )) by [@​cxljs](https://github.com/cxljs )
- **ConnPool queue channel**: Removed the unused queue channel from `ConnPool`, trimming the pool's footprint ([#​3826](https://github.com/redis/go-redis/pull/3826 )) by [@​cxljs](https://github.com/cxljs )
- **Extra packages LICENSE**: Added a LICENSE file to each `extra/*` package ([#​3817](https://github.com/redis/go-redis/pull/3817 )) by [@​ndyakov](https://github.com/ndyakov )
- **README & CI image**: Documentation refresh and bumped the default CI image tag ([#​3822](https://github.com/redis/go-redis/pull/3822 )) by [@​ndyakov](https://github.com/ndyakov )
#### 👥 Contributors
We'd like to thank all the contributors who worked on this release!
[@​cxljs](https://github.com/cxljs ), [@​DengY11](https://github.com/DengY11 ), [@​elena-kolevska](https://github.com/elena-kolevska ), [@​Khukharr](https://github.com/Khukharr ), [@​LINKIWI](https://github.com/LINKIWI ), [@​ndyakov](https://github.com/ndyakov ), [@​obiyang](https://github.com/obiyang ), [@​ofekshenawa](https://github.com/ofekshenawa ), [@​retr0-kernel](https://github.com/retr0-kernel ), [@​romanpovol](https://github.com/romanpovol ), [@​shahyash2609](https://github.com/shahyash2609 ), [@​solardome](https://github.com/solardome ), [@​vladisa88](https://github.com/vladisa88 )
***
**Full Changelog**: <https://github.com/redis/go-redis/compare/v9.19.0...v9.20.0 >
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE5NS4xIiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12804
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-05-29 15:17:59 +02:00
Renovate Bot and Gusted
c731987887
Update dependency webpack to v5.107.2 (forgejo) ( #12798 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12798
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-29 05:05:15 +02:00
Renovate Bot and Mathieu Fenniak
c37f5a96a9
Update google.golang.org/grpc (indirect) to v1.79.3 [SECURITY] (forgejo) ( #12794 )
...
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/ ) | [Confidence](https://docs.renovatebot.com/merge-confidence/ ) |
|---|---|---|---|
| [google.golang.org/grpc](https://github.com/grpc/grpc-go ) | `v1.75.0` → `v1.79.3` |  |  |
---
### gRPC-Go has an authorization bypass via missing leading slash in :path
[CVE-2026-33186](https://nvd.nist.gov/vuln/detail/CVE-2026-33186 ) / [GHSA-p77j-4mvh-x3m3](https://github.com/advisories/GHSA-p77j-4mvh-x3m3 ) / [GO-2026-4762](https://pkg.go.dev/vuln/GO-2026-4762 )
<details>
<summary>More information</summary>
#### Details
##### Impact
_What kind of vulnerability is it? Who is impacted?_
It is an **Authorization Bypass** resulting from **Improper Input Validation** of the HTTP/2 `:path` pseudo-header.
The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, "deny" rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback "allow" rule was present.
**Who is impacted?**
This affects gRPC-Go servers that meet both of the following criteria:
1. They use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`.
2. Their security policy contains specific "deny" rules for canonical paths but allows other requests by default (a fallback "allow" rule).
The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server.
##### Patches
_Has the problem been patched? What versions should users upgrade to?_
Yes, the issue has been patched. The fix ensures that any request with a `:path` that does not start with a leading slash is immediately rejected with a `codes.Unimplemented` error, preventing it from reaching authorization interceptors or handlers with a non-canonical path string.
Users should upgrade to the following versions (or newer):
* **v1.79.3**
* The latest **master** branch.
It is recommended that all users employing path-based authorization (especially `grpc/authz`) upgrade as soon as the patch is available in a tagged release.
##### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
While upgrading is the most secure and recommended path, users can mitigate the vulnerability using one of the following methods:
##### 1. Use a Validating Interceptor (Recommended Mitigation)
Add an "outermost" interceptor to your server that validates the path before any other authorization logic runs:
```go
func pathValidationInterceptor(ctx context.Context, req any, info *grpc.UnaryServerInfo, handler grpc.UnaryHandler) (any, error) {
if info.FullMethod == "" || info.FullMethod[0] != '/' {
return nil, status.Errorf(codes.Unimplemented, "malformed method name")
}
return handler(ctx, req)
}
// Ensure this is the FIRST interceptor in your chain
s := grpc.NewServer(
grpc.ChainUnaryInterceptor(pathValidationInterceptor, authzInterceptor),
)
```
##### 2. Infrastructure-Level Normalization
If your gRPC server is behind a reverse proxy or load balancer (such as Envoy, NGINX, or an L7 Cloud Load Balancer), ensure it is configured to enforce strict HTTP/2 compliance for pseudo-headers and reject or normalize requests where the `:path` header does not start with a leading slash.
##### 3. Policy Hardening
Switch to a "default deny" posture in your authorization policies (explicitly listing all allowed paths and denying everything else) to reduce the risk of bypasses via malformed inputs.
#### Severity
- CVSS Score: 9.1 / 10 (Critical)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N`
#### References
- [https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3 ](https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3 )
- [https://nvd.nist.gov/vuln/detail/CVE-2026-33186 ](https://nvd.nist.gov/vuln/detail/CVE-2026-33186 )
- [https://github.com/grpc/grpc-go ](https://github.com/grpc/grpc-go )
This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-p77j-4mvh-x3m3 ) and the [GitHub Advisory Database](https://github.com/github/advisory-database ) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md )).
</details>
---
### Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc
[CVE-2026-33186](https://nvd.nist.gov/vuln/detail/CVE-2026-33186 ) / [GHSA-p77j-4mvh-x3m3](https://github.com/advisories/GHSA-p77j-4mvh-x3m3 ) / [GO-2026-4762](https://pkg.go.dev/vuln/GO-2026-4762 )
<details>
<summary>More information</summary>
#### Details
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc
#### Severity
Unknown
#### References
- [https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3 ](https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3 )
This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-4762 ) and the [Go Vulnerability Database](https://github.com/golang/vulndb ) ([CC-BY 4.0](https://github.com/golang/vulndb#license )).
</details>
---
### Release Notes
<details>
<summary>grpc/grpc-go (google.golang.org/grpc)</summary>
### [`v1.79.3`](https://github.com/grpc/grpc-go/releases/tag/v1.79.3 ): Release 1.79.3
[Compare Source](https://github.com/grpc/grpc-go/compare/v1.79.2...v1.79.3 )
### Security
- server: fix an authorization bypass where malformed :path headers (missing the leading slash) could bypass path-based restricted "deny" rules in interceptors like `grpc/authz`. Any request with a non-canonical path is now immediately rejected with an `Unimplemented` error. ([#​8981](https://github.com/grpc/grpc-go/issues/8981 ))
### [`v1.79.2`](https://github.com/grpc/grpc-go/releases/tag/v1.79.2 ): Release 1.79.2
[Compare Source](https://github.com/grpc/grpc-go/compare/v1.79.1...v1.79.2 )
### Bug Fixes
- stats: Prevent redundant error logging in health/ORCA producers by skipping stats/tracing processing when no stats handler is configured. ([#​8874](https://github.com/grpc/grpc-go/pull/8874 ))
### [`v1.79.1`](https://github.com/grpc/grpc-go/releases/tag/v1.79.1 ): Release 1.79.1
[Compare Source](https://github.com/grpc/grpc-go/compare/v1.79.0...v1.79.1 )
### Bug Fixes
- grpc: Remove the `-dev` suffix from the User-Agent header. ([#​8902](https://github.com/grpc/grpc-go/pull/8902 ))
### [`v1.79.0`](https://github.com/grpc/grpc-go/releases/tag/v1.79.0 ): Release 1.79.0
[Compare Source](https://github.com/grpc/grpc-go/compare/v1.78.0...v1.79.0 )
### API Changes
- mem: Add experimental API `SetDefaultBufferPool` to change the default buffer pool. ([#​8806](https://github.com/grpc/grpc-go/issues/8806 ))
- Special Thanks: [@​vanja-p](https://github.com/vanja-p )
- experimental/stats: Update `MetricsRecorder` to require embedding the new `UnimplementedMetricsRecorder` (a no-op struct) in all implementations for forward compatibility. ([#​8780](https://github.com/grpc/grpc-go/issues/8780 ))
### Behavior Changes
- balancer/weightedtarget: Remove handling of `Addresses` and only handle `Endpoints` in resolver updates. ([#​8841](https://github.com/grpc/grpc-go/issues/8841 ))
### New Features
- experimental/stats: Add support for asynchronous gauge metrics through the new `AsyncMetricReporter` and `RegisterAsyncReporter` APIs. ([#​8780](https://github.com/grpc/grpc-go/issues/8780 ))
- pickfirst: Add support for weighted random shuffling of endpoints, as described in [gRFC A113](https://github.com/grpc/proposal/pull/535 ).
- This is enabled by default, and can be turned off using the environment variable `GRPC_EXPERIMENTAL_PF_WEIGHTED_SHUFFLING`. ([#​8864](https://github.com/grpc/grpc-go/issues/8864 ))
- xds: Implement `:authority` rewriting, as specified in [gRFC A81](https://github.com/grpc/proposal/blob/master/A81-xds-authority-rewriting.md ). ([#​8779](https://github.com/grpc/grpc-go/issues/8779 ))
- balancer/randomsubsetting: Implement the `random_subsetting` LB policy, as specified in [gRFC A68](https://github.com/grpc/proposal/blob/master/A68-random-subsetting.md ). ([#​8650](https://github.com/grpc/grpc-go/issues/8650 ))
- Special Thanks: [@​marek-szews](https://github.com/marek-szews )
### Bug Fixes
- credentials/tls: Fix a bug where the port was not stripped from the authority override before validation. ([#​8726](https://github.com/grpc/grpc-go/issues/8726 ))
- Special Thanks: [@​Atul1710](https://github.com/Atul1710 )
- xds/priority: Fix a bug causing delayed failover to lower-priority clusters when a higher-priority cluster is stuck in `CONNECTING` state. ([#​8813](https://github.com/grpc/grpc-go/issues/8813 ))
- health: Fix a bug where health checks failed for clients using legacy compression options (`WithDecompressor` or `RPCDecompressor`). ([#​8765](https://github.com/grpc/grpc-go/issues/8765 ))
- Special Thanks: [@​sanki92](https://github.com/sanki92 )
- transport: Fix an issue where the HTTP/2 server could skip header size checks when terminating a stream early. ([#​8769](https://github.com/grpc/grpc-go/issues/8769 ))
- Special Thanks: [@​joybestourous](https://github.com/joybestourous )
- server: Propagate status detail headers, if available, when terminating a stream during request header processing. ([#​8754](https://github.com/grpc/grpc-go/issues/8754 ))
- Special Thanks: [@​joybestourous](https://github.com/joybestourous )
### Performance Improvements
- credentials/alts: Optimize read buffer alignment to reduce copies. ([#​8791](https://github.com/grpc/grpc-go/issues/8791 ))
- mem: Optimize pooling and creation of `buffer` objects. ([#​8784](https://github.com/grpc/grpc-go/issues/8784 ))
- transport: Reduce slice re-allocations by reserving slice capacity. ([#​8797](https://github.com/grpc/grpc-go/issues/8797 ))
### [`v1.78.0`](https://github.com/grpc/grpc-go/releases/tag/v1.78.0 ): Release 1.78.0
[Compare Source](https://github.com/grpc/grpc-go/compare/v1.77.0...v1.78.0 )
### Behavior Changes
- client: Align URL validation with Go 1.26+ to now reject target URLs with unbracketed colons in the hostname. ([#​8716](https://github.com/grpc/grpc-go/issues/8716 ))
- Special Thanks: [@​neild](https://github.com/neild )
- transport/client : Return status code `Unknown` on malformed grpc-status. ([#​8735](https://github.com/grpc/grpc-go/issues/8735 ))
- - xds/resolver:
- Drop previous route resources and report an error when no matching virtual host is found.
- Only log LDS/RDS configuration errors following a successful update and retain the last valid resource to prevent transient failures. ([#​8711](https://github.com/grpc/grpc-go/issues/8711 ))
### New Features
- stats/otel: Add backend service label to weighted round robin metrics as part of A89. ([#​8737](https://github.com/grpc/grpc-go/issues/8737 ))
- stats/otel: Add subchannel metrics (without the disconnection reason) to eventually replace the pickfirst metrics. ([#​8738](https://github.com/grpc/grpc-go/issues/8738 ))
- client: Wait for all pending goroutines to complete when closing a graceful switch balancer. ([#​8746](https://github.com/grpc/grpc-go/issues/8746 ))
- Special Thanks: [@​twz123](https://github.com/twz123 )
- client: Add `experimental.AcceptCompressors` so callers can restrict the `grpc-accept-encoding` header advertised for a call. ([#​8718](https://github.com/grpc/grpc-go/issues/8718 ))
- Special Thanks: [@​iblancasa](https://github.com/iblancasa )
### Bug Fixes
- xds: Fix a bug in `StringMatcher` where regexes would match incorrectly when ignore\_case is set to true. ([#​8723](https://github.com/grpc/grpc-go/issues/8723 ))
- client:
- Change connectivity state to CONNECTING when creating the name resolver (as part of exiting IDLE).
- Change connectivity state to TRANSIENT\_FAILURE if name resolver creation fails (as part of exiting IDLE).
- Change connectivity state to IDLE after idle timeout expires even when current state is TRANSIENT\_FAILURE.
- Fix a bug that resulted in `OnFinish` call option not being invoked for RPCs where stream creation failed. ([#​8710](https://github.com/grpc/grpc-go/issues/8710 ))
- xdsclient: Fix a race in the xdsClient that could lead to resource-not-found errors. ([#​8627](https://github.com/grpc/grpc-go/issues/8627 ))
### Performance Improvements
- mem: Round up to nearest 4KiB for pool allocations larger than 1MiB. ([#​8705](https://github.com/grpc/grpc-go/issues/8705 ))
- Special Thanks: [@​cjc25](https://github.com/cjc25 )
### [`v1.77.0`](https://github.com/grpc/grpc-go/releases/tag/v1.77.0 ): Release 1.77.0
[Compare Source](https://github.com/grpc/grpc-go/compare/v1.76.0...v1.77.0 )
### API Changes
- mem: Replace the `Reader` interface with a struct for better performance and maintainability. ([#​8669](https://github.com/grpc/grpc-go/issues/8669 ))
### Behavior Changes
- balancer/pickfirst: Remove support for the old `pick_first` LB policy via the environment variable `GRPC_EXPERIMENTAL_ENABLE_NEW_PICK_FIRST=false`. The new `pick_first` has been the default since `v1.71.0`. ([#​8672](https://github.com/grpc/grpc-go/issues/8672 ))
### Bug Fixes
- xdsclient: Fix a race condition in the ADS stream implementation that could result in `resource-not-found` errors, causing the gRPC client channel to move to `TransientFailure`. ([#​8605](https://github.com/grpc/grpc-go/issues/8605 ))
- client: Ignore HTTP status header for gRPC streams. ([#​8548](https://github.com/grpc/grpc-go/issues/8548 ))
- client: Set a read deadline when closing a transport to prevent it from blocking indefinitely on a broken connection. ([#​8534](https://github.com/grpc/grpc-go/issues/8534 ))
- Special Thanks: [@​jgold2-stripe](https://github.com/jgold2-stripe )
- client: Fix a bug where default port 443 was not automatically added to addresses without a specified port when sent to a proxy.
- Setting environment variable `GRPC_EXPERIMENTAL_ENABLE_DEFAULT_PORT_FOR_PROXY_TARGET=false` disables this change; please file a bug if any problems are encountered as we will remove this option soon. ([#​8613](https://github.com/grpc/grpc-go/issues/8613 ))
- balancer/pickfirst: Fix a bug where duplicate addresses were not being ignored as intended. ([#​8611](https://github.com/grpc/grpc-go/issues/8611 ))
- server: Fix a bug that caused overcounting of channelz metrics for successful and failed streams. ([#​8573](https://github.com/grpc/grpc-go/issues/8573 ))
- Special Thanks: [@​hugehoo](https://github.com/hugehoo )
- balancer/pickfirst: When configured, shuffle addresses in resolver updates that lack endpoints. Since gRPC automatically adds endpoints to resolver updates, this bug only affects custom LB policies that delegate to `pick_first` but don't set endpoints. ([#​8610](https://github.com/grpc/grpc-go/issues/8610 ))
- mem: Clear large buffers before re-using. ([#​8670](https://github.com/grpc/grpc-go/issues/8670 ))
### Performance Improvements
- transport: Reduce heap allocations to reduce time spent in garbage collection. ([#​8624](https://github.com/grpc/grpc-go/issues/8624 ), [#​8630](https://github.com/grpc/grpc-go/issues/8630 ), [#​8639](https://github.com/grpc/grpc-go/issues/8639 ), [#​8668](https://github.com/grpc/grpc-go/issues/8668 ))
- transport: Avoid copies when reading and writing Data frames. ([#​8657](https://github.com/grpc/grpc-go/issues/8657 ), [#​8667](https://github.com/grpc/grpc-go/issues/8667 ))
- mem: Avoid clearing newly allocated buffers. ([#​8670](https://github.com/grpc/grpc-go/issues/8670 ))
### New Features
- outlierdetection: Add metrics specified in [gRFC A91](https://github.com/grpc/proposal/blob/master/A91-outlier-detection-metrics.md ). ([#​8644](https://github.com/grpc/grpc-go/issues/8644 ))
- Special Thanks: [@​davinci26](https://github.com/davinci26 ), [@​PardhuKonakanchi](https://github.com/PardhuKonakanchi )
- stats/opentelemetry: Add support for optional label `grpc.lb.backend_service` in per-call metrics ([#​8637](https://github.com/grpc/grpc-go/issues/8637 ))
- xds: Add support for JWT Call Credentials as specified in [gRFC A97](https://github.com/grpc/proposal/blob/master/A97-xds-jwt-call-creds.md ). Set environment variable `GRPC_EXPERIMENTAL_XDS_BOOTSTRAP_CALL_CREDS=true` to enable this feature. ([#​8536](https://github.com/grpc/grpc-go/issues/8536 ))
- Special Thanks: [@​dimpavloff](https://github.com/dimpavloff )
- experimental/stats: Add support for up/down counters. ([#​8581](https://github.com/grpc/grpc-go/issues/8581 ))
### [`v1.76.0`](https://github.com/grpc/grpc-go/releases/tag/v1.76.0 ): Release 1.76.0
[Compare Source](https://github.com/grpc/grpc-go/compare/v1.75.1...v1.76.0 )
### Dependencies
- Minimum supported Go version is now 1.24 ([#​8509](https://github.com/grpc/grpc-go/issues/8509 ))
- Special Thanks: [@​kevinGC](https://github.com/kevinGC )
### Bug Fixes
- client: Return status `INTERNAL` when a server sends zero response messages for a unary or client-streaming RPC. ([#​8523](https://github.com/grpc/grpc-go/issues/8523 ))
- client: Fail RPCs with status `INTERNAL` instead of `UNKNOWN` upon receiving http headers with status 1xx and `END_STREAM` flag set. ([#​8518](https://github.com/grpc/grpc-go/issues/8518 ))
- Special Thanks: [@​vinothkumarr227](https://github.com/vinothkumarr227 )
- pick\_first: Fix race condition that could cause pick\_first to get stuck in `IDLE` state on backend address change. ([#​8615](https://github.com/grpc/grpc-go/issues/8615 ))
### New Features
- credentials: Add `credentials/jwt` package providing file-based JWT PerRPCCredentials (A97). ([#​8431](https://github.com/grpc/grpc-go/issues/8431 ))
- Special Thanks: [@​dimpavloff](https://github.com/dimpavloff )
### Performance Improvements
- client: Improve HTTP/2 header size estimate to reduce re-allocations. ([#​8547](https://github.com/grpc/grpc-go/issues/8547 ))
- encoding/proto: Avoid redundant message size calculation when marshaling. ([#​8569](https://github.com/grpc/grpc-go/issues/8569 ))
- Special Thanks: [@​rs-unity](https://github.com/rs-unity )
### [`v1.75.1`](https://github.com/grpc/grpc-go/releases/tag/v1.75.1 ): Release 1.75.1
[Compare Source](https://github.com/grpc/grpc-go/compare/v1.75.0...v1.75.1 )
### Bug Fixes
- transport: Fix a data race while copying headers for stats handlers in the std lib http2 server transport. ([#​8519](https://github.com/grpc/grpc-go/issues/8519 ))
- xdsclient:
- Fix a data race caused while reporting load to LRS. ([#​8483](https://github.com/grpc/grpc-go/pull/8483 ))
- Fix regression preventing empty node IDs when creating an LRS client. ([#​8483](https://github.com/grpc/grpc-go/issues/8483 ))
- server: Fix a regression preventing streams from being cancelled or timed out when blocked on flow control. ([#​8528](https://github.com/grpc/grpc-go/issues/8528 ))
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- ""
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE5NS4xIiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12794
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-05-28 22:15:59 +02:00
Renovate Bot and Gusted
c8fa66d42c
Update dependency clippie to v4.2.0 (forgejo) ( #12618 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12618
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-27 18:46:02 +02:00
7dea39659d
Update module code.forgejo.org/forgejo/runner/v12 to v12.10.2 (forgejo) ( #12759 )
...
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/ ) | [Confidence](https://docs.renovatebot.com/merge-confidence/ ) |
|---|---|---|---|
| [code.forgejo.org/forgejo/runner/v12](https://code.forgejo.org/forgejo/runner ) | `v12.10.1` → `v12.10.2` |  |  |
---
### Release Notes
<details>
<summary>forgejo/runner (code.forgejo.org/forgejo/runner/v12)</summary>
### [`v12.10.2`](https://code.forgejo.org/forgejo/runner/releases/tag/v12.10.2 )
[Compare Source](https://code.forgejo.org/forgejo/runner/compare/v12.10.1...v12.10.2 )
- [User guide](https://forgejo.org/docs/next/user/actions/overview/ )
- [Administrator guide](https://forgejo.org/docs/next/admin/actions/ )
- [Container images](https://code.forgejo.org/forgejo/-/packages/container/runner/versions )
Release Notes
***
<!--start release-notes-assistant-->
<!--URL:https://code.forgejo.org/forgejo/runner-- >
- bug fixes
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1523 ): <!--number 1523 --><!--line 0 --><!--description Zml4OiByZW1vdmUgY29udGFpbmVycyBhZnRlciBmYWlsZWQgc3RhcnQtdXA=-->fix: remove containers after failed start-up<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1519 ): <!--number 1519 --><!--line 0 --><!--description Zml4OiByZWplY3QgaW52YWxpZCBjcm9uIHNjaGVkdWxlcyB3aGlsZSBwYXJzaW5nIHdvcmtmbG93cw==-->fix: reject invalid cron schedules while parsing workflows<!--description-->
- other
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1532 ): <!--number 1532 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL3JoeXNkL2FjdGlvbmxpbnQgdG8gdjEuNy4xMg==-->Update module github.com/rhysd/actionlint to v1.7.12<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1531 ): <!--number 1531 --><!--line 0 --><!--description UmVwbGFjZSBOb2RlLmpzIHdpdGggZGF0YS5mb3JnZWpvLm9yZy9vY2kvbm9kZSAyNC10cml4aWU=-->Replace Node.js with data.forgejo.org/oci/node 24-trixie<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1530 ): <!--number 1530 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL2Nhc2NhZGluZy1wciBhY3Rpb24gdG8gdjIuMy4y-->Update <https://data.forgejo.org/actions/cascading-pr > action to v2.3.2<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1522 ): <!--number 1522 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL21vYnkvcGF0dGVybm1hdGNoZXIgdG8gdjAuNi4x-->Update module github.com/moby/patternmatcher to v0.6.1<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1529 ): <!--number 1529 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmcub3JnL3gvc3lzIHRvIHYwLjQ0LjAgW1NFQ1VSSVRZXQ==-->Update module golang.org/x/sys to v0.44.0 \[SECURITY]<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1527 ): <!--number 1527 --><!--line 0 --><!--description dGVzdDogdXBkYXRlIGFwdCBjYWNoZSBiZWZvcmUgaW5zdGFsbGluZyBwYWNrYWdlcyBpbiBQb2RtYW4gam9i-->test: update apt cache before installing packages in Podman job<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1521 ): <!--number 1521 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL21hdHRuL2dvLWlzYXR0eSB0byB2MC4wLjIy-->Update module github.com/mattn/go-isatty to v0.0.22<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1520 ): <!--number 1520 --><!--line 0 --><!--description VXBkYXRlIGRhdGEuZm9yZ2Vqby5vcmcvZm9yZ2Vqby9mb3JnZWpvIERvY2tlciB0YWcgdG8gdjExLjAuMTQ=-->Update data.forgejo.org/forgejo/forgejo Docker tag to v11.0.14<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1515 ): <!--number 1515 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBjb25uZWN0cnBjLmNvbS9jb25uZWN0IHRvIHYxLjE5LjI=-->Update module connectrpc.com/connect to v1.19.2<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1514 ): <!--number 1514 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjEuMTE=-->Update <https://data.forgejo.org/actions/setup-forgejo > action to v3.1.11<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1513 ): <!--number 1513 --><!--line 0 --><!--description VXBkYXRlIGRhdGEuZm9yZ2Vqby5vcmcvZm9yZ2Vqby9mb3JnZWpvIERvY2tlciB0YWcgdG8gdjExLjAuMTM=-->Update data.forgejo.org/forgejo/forgejo Docker tag to v11.0.13<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1512 ): <!--number 1512 --><!--line 0 --><!--description VXBkYXRlIGdvIHRvb2xjaGFpbiBkaXJlY3RpdmUgdG8gdjEuMjUuMTA=-->Update go toolchain directive to v1.25.10<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1503 ): <!--number 1503 --><!--line 0 --><!--description cmVmYWN0b3I6IHJlcGxhY2UgYmFja2VuZCBpZGVudGl0eSBjaGVja3Mgd2l0aCBjYXBhYmlsaXR5IHF1ZXJpZXM=-->refactor: replace backend identity checks with capability queries<!--description-->
<!--end release-notes-assistant-->
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE5NS4xIiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJydW4tZW5kLXRvLWVuZC10ZXN0cyIsInRlc3Qvbm90LW5lZWRlZCJdfQ==-->
Co-authored-by: Mathieu Fenniak <mathieu@fenniak.net >
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12759
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-05-27 17:46:33 +02:00
Renovate Bot
e435233c7f
Update https://data.forgejo.org/actions/setup-forgejo action to v3.1.12 (forgejo) ( #12763 )
2026-05-27 04:18:00 +02:00
Renovate Bot
2c7ce02da1
Update dependency forgejo/release-notes-assistant to v1.7.1 (forgejo) ( #12740 )
2026-05-26 01:50:01 +02:00
Renovate Bot and Gusted
e2c8c0d1f6
Update dependency katex to v0.17.0 (forgejo) ( #12741 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12741
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-26 01:01:55 +02:00
Renovate Bot
ed30c7de45
Update renovate Docker tag to v43.195.1 (forgejo) ( #12720 )
2026-05-25 13:01:57 +02:00
Renovate Bot and Gusted
8df8d2c776
Update dependency webpack to v5.107.1 (forgejo) ( #12721 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12721
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-25 12:35:44 +02:00
Renovate Bot and Mathieu Fenniak
3ee2f718a3
Lock file maintenance (forgejo) ( #12723 )
...
This PR contains the following updates:
| Update | Change |
|---|---|
| lockFileMaintenance | All locks refreshed |
🔧 This Pull Request updates lock files to use the latest dependency versions.
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM, only on Monday (`* 0-3 * * 1`)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions ) if that's undesired.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE5NS4xIiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12723
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-05-25 02:33:11 +02:00
Renovate Bot and Gusted
624ffd18d4
Update dependency webpack to v5.107.0 (forgejo) ( #12714 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12714
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-24 12:38:12 +02:00
Renovate Bot and Mathieu Fenniak
26f18a94ee
Replace Node.js with data.forgejo.org/oci/node 24-trixie (forgejo) ( #12713 )
...
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [data.forgejo.org/oci/node](https://hub.docker.com/_/node ) ([source](https://github.com/nodejs/docker-node )) | container | replacement | `24-bookworm` → `24-trixie` |
This is a special PR that replaces `data.forgejo.org/oci/node` with the community suggested minimal stable replacement version.
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- ""
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODIuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE4Mi4xIiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12713
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-05-24 01:16:58 +02:00
Renovate Bot and Gusted
0f449ff84f
Update dependency postcss to v8.5.15 (forgejo) ( #12693 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12693
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-23 18:12:24 +02:00
Renovate Bot and Mathieu Fenniak
37b3b3a243
Update https://data.forgejo.org/actions/cascading-pr action to v2.3.2 (forgejo) ( #12708 )
...
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [https://data.forgejo.org/actions/cascading-pr ](https://code.forgejo.org/actions/cascading-pr ) | action | patch | `v2.3.0` → `v2.3.2` |
---
### Release Notes
<details>
<summary>actions/cascading-pr (https://data.forgejo.org/actions/cascading-pr )</summary>
### [`v2.3.2`](https://code.forgejo.org/actions/cascading-pr/releases/tag/v2.3.2 )
[Compare Source](https://code.forgejo.org/actions/cascading-pr/compare/v2.3.1...v2.3.2 )
<!--start release-notes-assistant-->
<!--URL:https://code.forgejo.org/actions/cascading-pr-- >
- bug fixes
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/58 ): <!--number 58 --><!--line 0 --><!--description Zml4OiBjb21wYXRpYmxpdHkgd2l0aCBvY2kvbm9kZToyNC10cml4aWUgaW1hZ2U=-->fix: compatiblity with oci/node:24-trixie image<!--description-->
- other
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/57 ): <!--number 57 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL2Zvcmdlam8tcmVsZWFzZSBhY3Rpb24gdG8gdjIuMTIuMA==-->Update <https://data.forgejo.org/actions/forgejo-release > action to v2.12.0<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/56 ): <!--number 56 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjEuMTE=-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.1.11<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/55 ): <!--number 55 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjEuOA==-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.1.8<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/54 ): <!--number 54 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL2Zvcmdlam8tcmVsZWFzZSBhY3Rpb24gdG8gdjIuMTEuMw==-->Update <https://data.forgejo.org/actions/forgejo-release > action to v2.11.3<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/53 ): <!--number 53 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjEuNw==-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.1.7<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/52 ): <!--number 52 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL2Zvcmdlam8tcmVsZWFzZSBhY3Rpb24gdG8gdjIuMTEuMg==-->Update <https://data.forgejo.org/actions/forgejo-release > action to v2.11.2<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/50 ): <!--number 50 --><!--line 0 --><!--description VXBkYXRlIGFjdGlvbnMvY2hlY2tvdXQgYWN0aW9uIHRvIHY2-->Update actions/checkout action to v6<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/51 ): <!--number 51 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZm9yZ2Vqby1seGMgdG8gdjEz-->Update dependency forgejo-lxc to v13<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/49 ): <!--number 49 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL2Zvcmdlam8tcmVsZWFzZSBhY3Rpb24gdG8gdjIuMTEuMA==-->Update <https://data.forgejo.org/actions/forgejo-release > action to v2.11.0<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/48 ): <!--number 48 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjEuNg==-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.1.6<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/47 ): <!--number 47 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjEuNA==-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.1.4<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/46 ): <!--number 46 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL2Zvcmdlam8tcmVsZWFzZSBhY3Rpb24gdG8gdjIuMTAuMA==-->Update <https://data.forgejo.org/actions/forgejo-release > action to v2.10.0<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/45 ): <!--number 45 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjEuMQ==-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.1.1<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/43 ): <!--number 43 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjEuMA==-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.1.0<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/39 ): <!--number 39 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjAuNw==-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.0.7<!--description-->
<!--end release-notes-assistant-->
### [`v2.3.1`](https://code.forgejo.org/actions/cascading-pr/releases/tag/v2.3.1 )
[Compare Source](https://code.forgejo.org/actions/cascading-pr/compare/v2.3.0...v2.3.1 )
<!-- correcting for mislabeling v2.3.1 on first attempt -->
- fix
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/58 ): fix: compatiblity with oci/node:24-trixie image
<!--start release-notes-assistant-->
<!--URL:https://code.forgejo.org/actions/cascading-pr-- >
- other
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/57 ): <!--number 57 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL2Zvcmdlam8tcmVsZWFzZSBhY3Rpb24gdG8gdjIuMTIuMA==-->Update <https://data.forgejo.org/actions/forgejo-release > action to v2.12.0<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/56 ): <!--number 56 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjEuMTE=-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.1.11<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/55 ): <!--number 55 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjEuOA==-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.1.8<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/54 ): <!--number 54 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL2Zvcmdlam8tcmVsZWFzZSBhY3Rpb24gdG8gdjIuMTEuMw==-->Update <https://data.forgejo.org/actions/forgejo-release > action to v2.11.3<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/53 ): <!--number 53 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjEuNw==-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.1.7<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/52 ): <!--number 52 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL2Zvcmdlam8tcmVsZWFzZSBhY3Rpb24gdG8gdjIuMTEuMg==-->Update <https://data.forgejo.org/actions/forgejo-release > action to v2.11.2<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/50 ): <!--number 50 --><!--line 0 --><!--description VXBkYXRlIGFjdGlvbnMvY2hlY2tvdXQgYWN0aW9uIHRvIHY2-->Update actions/checkout action to v6<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/51 ): <!--number 51 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZm9yZ2Vqby1seGMgdG8gdjEz-->Update dependency forgejo-lxc to v13<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/49 ): <!--number 49 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL2Zvcmdlam8tcmVsZWFzZSBhY3Rpb24gdG8gdjIuMTEuMA==-->Update <https://data.forgejo.org/actions/forgejo-release > action to v2.11.0<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/48 ): <!--number 48 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjEuNg==-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.1.6<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/47 ): <!--number 47 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjEuNA==-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.1.4<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/46 ): <!--number 46 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL2Zvcmdlam8tcmVsZWFzZSBhY3Rpb24gdG8gdjIuMTAuMA==-->Update <https://data.forgejo.org/actions/forgejo-release > action to v2.10.0<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/45 ): <!--number 45 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjEuMQ==-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.1.1<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/43 ): <!--number 43 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjEuMA==-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.1.0<!--description-->
- [PR](https://code.forgejo.org/actions/cascading-pr/pulls/39 ): <!--number 39 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWZvcmdlam8gYWN0aW9uIHRvIHYzLjAuNw==-->Update <https://code.forgejo.org/actions/setup-forgejo > action to v3.0.7<!--description-->
<!--end release-notes-assistant-->
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODIuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE4Mi4xIiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12708
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-05-23 17:54:42 +02:00
Renovate Bot and Mathieu Fenniak
c749861d94
Update data.forgejo.org/oci/ci Docker tag to v2 (forgejo) ( #12692 )
...
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [data.forgejo.org/oci/ci](https://code.forgejo.org/forgejo/ci-image-builder ) | container | major | `1` → `2` |
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODIuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE4Mi4xIiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12692
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-05-23 03:00:43 +02:00
Renovate Bot and Mathieu Fenniak
1a108e8fbb
Update module golang.org/x/net to v0.55.0 [SECURITY] (forgejo) ( #12686 )
...
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/ ) | [Confidence](https://docs.renovatebot.com/merge-confidence/ ) |
|---|---|---|---|
| [golang.org/x/net](https://pkg.go.dev/golang.org/x/net ) | [`v0.54.0` → `v0.55.0`](https://cs.opensource.google/go/x/net/+/refs/tags/v0.54.0...refs/tags/v0.55.0 ) |  |  |
---
### Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html
[CVE-2026-42506](https://nvd.nist.gov/vuln/detail/CVE-2026-42506 ) / [GO-2026-5025](https://pkg.go.dev/vuln/GO-2026-5025 )
<details>
<summary>More information</summary>
#### Details
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
#### Severity
Unknown
#### References
- [https://go.dev/issue/79571 ](https://go.dev/issue/79571 )
- [https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 ](https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 )
- [https://go.dev/cl/781700 ](https://go.dev/cl/781700 )
This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-5025 ) and the [Go Vulnerability Database](https://github.com/golang/vulndb ) ([CC-BY 4.0](https://github.com/golang/vulndb#license )).
</details>
---
### Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
[CVE-2026-39821](https://nvd.nist.gov/vuln/detail/CVE-2026-39821 ) / [GO-2026-5026](https://pkg.go.dev/vuln/GO-2026-5026 )
<details>
<summary>More information</summary>
#### Details
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error.
This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
#### Severity
Unknown
#### References
- [https://go.dev/cl/767220 ](https://go.dev/cl/767220 )
- [https://go.dev/issue/78760 ](https://go.dev/issue/78760 )
- [https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 ](https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 )
This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-5026 ) and the [Go Vulnerability Database](https://github.com/golang/vulndb ) ([CC-BY 4.0](https://github.com/golang/vulndb#license )).
</details>
---
### Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
[CVE-2026-42502](https://nvd.nist.gov/vuln/detail/CVE-2026-42502 ) / [GO-2026-5027](https://pkg.go.dev/vuln/GO-2026-5027 )
<details>
<summary>More information</summary>
#### Details
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
#### Severity
Unknown
#### References
- [https://go.dev/issue/79572 ](https://go.dev/issue/79572 )
- [https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 ](https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 )
- [https://go.dev/cl/781701 ](https://go.dev/cl/781701 )
This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-5027 ) and the [Go Vulnerability Database](https://github.com/golang/vulndb ) ([CC-BY 4.0](https://github.com/golang/vulndb#license )).
</details>
---
### Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html
[CVE-2026-25680](https://nvd.nist.gov/vuln/detail/CVE-2026-25680 ) / [GO-2026-5028](https://pkg.go.dev/vuln/GO-2026-5028 )
<details>
<summary>More information</summary>
#### Details
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
#### Severity
Unknown
#### References
- [https://go.dev/cl/781702 ](https://go.dev/cl/781702 )
- [https://go.dev/issue/79573 ](https://go.dev/issue/79573 )
- [https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 ](https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 )
This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-5028 ) and the [Go Vulnerability Database](https://github.com/golang/vulndb ) ([CC-BY 4.0](https://github.com/golang/vulndb#license )).
</details>
---
### Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
[CVE-2026-25681](https://nvd.nist.gov/vuln/detail/CVE-2026-25681 ) / [GO-2026-5029](https://pkg.go.dev/vuln/GO-2026-5029 )
<details>
<summary>More information</summary>
#### Details
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
#### Severity
Unknown
#### References
- [https://go.dev/issue/79574 ](https://go.dev/issue/79574 )
- [https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 ](https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 )
- [https://go.dev/cl/781703 ](https://go.dev/cl/781703 )
This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-5029 ) and the [Go Vulnerability Database](https://github.com/golang/vulndb ) ([CC-BY 4.0](https://github.com/golang/vulndb#license )).
</details>
---
### Invoking duplicate attributes can cause XSS in golang.org/x/net/html
[CVE-2026-27136](https://nvd.nist.gov/vuln/detail/CVE-2026-27136 ) / [GO-2026-5030](https://pkg.go.dev/vuln/GO-2026-5030 )
<details>
<summary>More information</summary>
#### Details
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
#### Severity
Unknown
#### References
- [https://go.dev/issue/79575 ](https://go.dev/issue/79575 )
- [https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 ](https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 )
- [https://go.dev/cl/781685 ](https://go.dev/cl/781685 )
This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-5030 ) and the [Go Vulnerability Database](https://github.com/golang/vulndb ) ([CC-BY 4.0](https://github.com/golang/vulndb#license )).
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- ""
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODIuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE4Mi4xIiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12686
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-05-22 20:00:56 +02:00
Renovate Bot and Gusted
7054075be5
Update Node.js to v24.16.0 (forgejo) ( #12675 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12675
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-22 11:38:56 +02:00
Renovate Bot and Gusted
ede3bbe670
Update module golang.org/x/image to v0.41.0 (forgejo) ( #12673 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12673
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-22 11:13:22 +02:00
Renovate Bot and Mathieu Fenniak
294952b774
Update module golang.org/x/crypto to v0.52.0 (forgejo) ( #12676 )
...
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/ ) | [Confidence](https://docs.renovatebot.com/merge-confidence/ ) |
|---|---|---|---|
| [golang.org/x/crypto](https://pkg.go.dev/golang.org/x/crypto ) | [`v0.51.0` → `v0.52.0`](https://cs.opensource.google/go/x/crypto/+/refs/tags/v0.51.0...refs/tags/v0.52.0 ) |  |  |
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODIuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE4Mi4xIiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12676
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-05-22 04:38:13 +02:00
Renovate Bot and Gusted
7d0bac4b75
Update dependency katex to v0.16.47 (forgejo) ( #12617 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12617
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
Reviewed-by: Robert Wolff <mahlzahn@posteo.de >
2026-05-21 19:09:00 +02:00
Renovate Bot and Gusted
f4c319db0b
Update module code.forgejo.org/forgejo/levelqueue to v1.1.0 (forgejo) ( #12630 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12630
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-21 11:13:05 +02:00
Renovate Bot and Mathieu Fenniak
6fd667dcd8
Update module connectrpc.com/connect to v1.20.0 (forgejo) ( #12654 )
...
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/ ) | [Confidence](https://docs.renovatebot.com/merge-confidence/ ) |
|---|---|---|---|
| [connectrpc.com/connect](https://github.com/connectrpc/connect-go ) | `v1.19.2` → `v1.20.0` |  |  |
---
### Release Notes
<details>
<summary>connectrpc/connect-go (connectrpc.com/connect)</summary>
### [`v1.20.0`](https://github.com/connectrpc/connect-go/releases/tag/v1.20.0 )
[Compare Source](https://github.com/connectrpc/connect-go/compare/v1.19.2...v1.20.0 )
#### What's Changed
##### Other changes
- Bump minimum supported Go version to 1.25 by [@​jonbodner-buf](https://github.com/jonbodner-buf ) in [#​922](https://github.com/connectrpc/connect-go/issues/922 )
- Update Unary-Get query parameter order to match spec recommendation by [@​oliversun9](https://github.com/oliversun9 ) in [#​926](https://github.com/connectrpc/connect-go/issues/926 )
#### New Contributors
- [@​jonbodner-buf](https://github.com/jonbodner-buf ) made their first contribution in [#​922](https://github.com/connectrpc/connect-go/issues/922 )
**Full Changelog**: <https://github.com/connectrpc/connect-go/compare/v1.19.2...v1.20.0 >
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODIuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE4Mi4xIiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12654
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-05-21 01:45:45 +02:00
Renovate Bot and Gusted
0af02256ae
Update dependency postcss to v8.5.14 (forgejo) ( #12459 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12459
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-18 09:03:56 +02:00
Renovate Bot and Gusted
c3820b3bf7
Update renovate Docker tag to v43.182.1 (forgejo) ( #12610 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12610
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-18 06:42:51 +02:00
Renovate Bot and Gusted
3d4569b01b
Lock file maintenance (forgejo) ( #12515 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12515
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-18 03:19:38 +02:00
Renovate Bot and Gusted
3e077889e8
Update dependency @codemirror/view to v6.43.0 (forgejo) ( #12611 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12611
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-18 01:07:26 +02:00
Renovate Bot and Gusted
db5b475416
Update dependency katex to v0.16.46 (forgejo) ( #12603 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12603
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-17 00:58:15 +02:00
Renovate Bot
f4450f5015
Update dependency swagger-ui-dist to v5.32.6 (forgejo) ( #12590 )
2026-05-16 10:03:28 +02:00
Renovate Bot and Gusted
05d784bb38
Update module github.com/urfave/cli/v3 to v3.9.0 (forgejo) ( #12544 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12544
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-14 22:33:07 +02:00
Renovate Bot and Michael Kriese
cc146bfa8a
Update data.forgejo.org/forgejo/forgejo Docker tag to v11.0.14 (forgejo) ( #12543 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12543
Reviewed-by: Michael Kriese <michael.kriese@gmx.de >
2026-05-13 08:30:01 +02:00
Renovate Bot and Gusted
88fd372d9a
Update dependency mermaid to v11.15.0 [SECURITY] (forgejo) ( #12526 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12526
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-11 23:54:58 +02:00
Renovate Bot
2d5dd62cf3
Update renovate Docker tag to v43.170.20 (forgejo) ( #12516 )
2026-05-11 06:33:45 +02:00
Renovate Bot and Gusted
b21b173f6e
Update module golang.org/x/net to v0.54.0 (forgejo) ( #12485 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12485
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-11 05:22:59 +02:00
Renovate Bot and Gusted
3f0a8b4424
Update module golang.org/x/image to v0.40.0 (forgejo) ( #12484 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12484
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-11 03:37:09 +02:00
Renovate Bot and Gusted
dcf1e7ce09
Update module github.com/fsnotify/fsnotify to v1.10.1 (forgejo) ( #12416 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12416
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-11 03:07:16 +02:00
Renovate Bot and Gusted
a59879402e
Update dependency @codemirror/view to v6.42.1 (forgejo) ( #12514 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12514
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-11 02:38:10 +02:00
Renovate Bot
c25cbd6fc4
Update renovate Docker tag to v43.170.19 (forgejo) ( #12513 )
2026-05-11 02:30:23 +02:00
Renovate Bot
a4d623148d
Update dependency forgejo/release-notes-assistant to v1.7.0 (forgejo) ( #12501 )
2026-05-10 03:02:17 +02:00
Renovate Bot and Gusted
3fc3942356
Update CodeMirror (forgejo) ( #12498 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12498
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-10 01:32:13 +02:00
Renovate Bot
4e40724199
Update module golang.org/x/tools/cmd/deadcode to v0.45.0 (forgejo) ( #12488 )
2026-05-09 04:38:55 +02:00
Renovate Bot and Mathieu Fenniak
0b3192b8af
Update module golang.org/x/crypto to v0.51.0 (forgejo) ( #12483 )
...
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/ ) | [Confidence](https://docs.renovatebot.com/merge-confidence/ ) |
|---|---|---|---|
| [golang.org/x/crypto](https://pkg.go.dev/golang.org/x/crypto ) | [`v0.50.0` → `v0.51.0`](https://cs.opensource.google/go/x/crypto/+/refs/tags/v0.50.0...refs/tags/v0.51.0 ) |  |  |
---
> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/2779) for more information.
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNjAuNiIsInVwZGF0ZWRJblZlciI6IjQzLjE2MC42IiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12483
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-05-09 02:23:00 +02:00
Renovate Bot
326ae6ad67
Update go toolchain directive to v1.26.3 (forgejo) ( #12454 )
2026-05-07 20:04:54 +02:00
Renovate Bot and Gusted
69cf1f3333
Lock file maintenance (forgejo) ( #12408 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12408
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-06 14:55:06 +02:00
Renovate Bot and Mathieu Fenniak
09aaa129a2
Update https://data.forgejo.org/actions/setup-forgejo action to v3.1.11 (forgejo) ( #12429 )
...
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [https://data.forgejo.org/actions/setup-forgejo ](https://code.forgejo.org/actions/setup-forgejo ) | action | patch | `v3.1.10` → `v3.1.11` |
---
### Release Notes
<details>
<summary>actions/setup-forgejo (https://data.forgejo.org/actions/setup-forgejo )</summary>
### [`v3.1.11`](https://code.forgejo.org/actions/setup-forgejo/compare/v3.1.10...v3.1.11 )
[Compare Source](https://code.forgejo.org/actions/setup-forgejo/compare/v3.1.10...v3.1.11 )
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNjAuNiIsInVwZGF0ZWRJblZlciI6IjQzLjE2MC42IiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12429
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-05-06 05:22:06 +02:00
Renovate Bot and Mathieu Fenniak
4cebc5d1d5
Update module code.forgejo.org/forgejo/runner/v12 to v12.10.1 (forgejo) ( #12426 )
...
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/ ) | [Confidence](https://docs.renovatebot.com/merge-confidence/ ) |
|---|---|---|---|
| [code.forgejo.org/forgejo/runner/v12](https://code.forgejo.org/forgejo/runner ) | `v12.10.0` → `v12.10.1` |  |  |
---
### Release Notes
<details>
<summary>forgejo/runner (code.forgejo.org/forgejo/runner/v12)</summary>
### [`v12.10.1`](https://code.forgejo.org/forgejo/runner/releases/tag/v12.10.1 )
[Compare Source](https://code.forgejo.org/forgejo/runner/compare/v12.10.0...v12.10.1 )
- [User guide](https://forgejo.org/docs/next/user/actions/overview/ )
- [Administrator guide](https://forgejo.org/docs/next/admin/actions/ )
- [Container images](https://code.forgejo.org/forgejo/-/packages/container/runner/versions )
Release Notes
***
<!--start release-notes-assistant-->
<!--URL:https://code.forgejo.org/forgejo/runner-- >
- features
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1509 ): <!--number 1509 --><!--line 0 --><!--description ZmVhdDogbWVyZ2UgcmV1c2FibGUgZXhwYW5zaW9uIGNhbGxlcidzICdpZicgaW50byBleHBhbmRlZCBqb2Jz-->feat: merge reusable expansion caller's 'if' into expanded jobs<!--description-->
- bug fixes
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1510 ): <!--number 1510 --><!--line 0 --><!--description Zml4OiB3b3JrZmxvdy1sZXZlbCAnZW52JyBpcyBsb3N0IGR1cmluZyBqb2IgcGFyc2luZw==-->fix: workflow-level 'env' is lost during job parsing<!--description-->
- other
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1511 ): <!--number 1511 --><!--line 0 --><!--description Y2hvcmU6IHVzZSBzcGVjaWZpYyB2ZXJzaW9uIG9mIGdvZnVtcHQsIG5vdCBsYXRlc3Q=-->chore: use specific version of gofumpt, not latest<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1508 ): <!--number 1508 --><!--line 0 --><!--description Y2hvcmU6IGluY3JlYXNlIHRoZSBsZW5ndGggb2YgdGhlIGNhY2hlIHRva2VuIGtleQ==-->chore: increase the length of the cache token key<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1504 ): <!--number 1504 --><!--line 0 --><!--description Y2hvcmU6IHJlbW92ZSBnby1naXQ=-->chore: remove go-git<!--description-->
- [PR](https://code.forgejo.org/forgejo/runner/pulls/1506 ): <!--number 1506 --><!--line 0 --><!--description cmVmYWN0b3I6IGRyb3AgdW51c2VkIENvbm5lY3RUb05ldHdvcmsgZnJvbSBDb250YWluZXIgaW50ZXJmYWNl-->refactor: drop unused ConnectToNetwork from Container interface<!--description-->
<!--end release-notes-assistant-->
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNjAuNiIsInVwZGF0ZWRJblZlciI6IjQzLjE2MC42IiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJydW4tZW5kLXRvLWVuZC10ZXN0cyIsInRlc3Qvbm90LW5lZWRlZCJdfQ==-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12426
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-05-05 22:39:01 +02:00
Renovate Bot
6f5bef54b0
Update dependency globals to v17.6.0 (forgejo) ( #12417 )
2026-05-05 09:43:48 +02:00
Renovate Bot and Gusted
0b2415a05a
Update module github.com/redis/go-redis/v9 to v9.19.0 (forgejo) ( #12309 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12309
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-04 05:15:07 +02:00
Renovate Bot and Mathieu Fenniak
ed32a0fb5a
Update https://data.forgejo.org/actions/setup-forgejo action to v3.1.10 (forgejo) ( #12406 )
...
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [https://data.forgejo.org/actions/setup-forgejo ](https://code.forgejo.org/actions/setup-forgejo ) | action | patch | `v3.1.9` → `v3.1.10` |
---
### Release Notes
<details>
<summary>actions/setup-forgejo (https://data.forgejo.org/actions/setup-forgejo )</summary>
### [`v3.1.10`](https://code.forgejo.org/actions/setup-forgejo/compare/v3.1.9...v3.1.10 )
[Compare Source](https://code.forgejo.org/actions/setup-forgejo/compare/v3.1.9...v3.1.10 )
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNjAuNiIsInVwZGF0ZWRJblZlciI6IjQzLjE2MC42IiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12406
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-05-04 03:50:11 +02:00
Renovate Bot and Gusted
780526b1a8
Update module github.com/go-sql-driver/mysql to v1.10.0 (forgejo) ( #12376 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12376
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-04 02:43:19 +02:00
Renovate Bot
76b83c4467
Update renovate Docker tag to v43.160.6 (forgejo) ( #12404 )
2026-05-04 02:05:26 +02:00
Renovate Bot and Gusted
d27cd9f722
Update dependency postcss to v8.5.13 (forgejo) ( #12405 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12405
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-04 00:54:05 +02:00
Renovate Bot and Gusted
d63724ceab
Update module github.com/blevesearch/bleve/v2 to v2.6.0 (forgejo) ( #12373 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12373
2026-05-03 07:29:02 +02:00
Renovate Bot and Gusted
e9710af24f
Update module code.forgejo.org/forgejo/runner/v12 to v12.10.0 (forgejo) ( #12392 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12392
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-03 06:22:22 +02:00
Renovate Bot and Gusted
a2557f0f42
Update module github.com/caddyserver/certmagic to v0.25.3 (forgejo) ( #12257 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12257
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-03 05:57:54 +02:00
Renovate Bot and Gusted
743b3b4cd9
Update module github.com/minio/minio-go/v7 to v7.1.0 (forgejo) ( #11959 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/11959
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-03 05:15:10 +02:00
Renovate Bot and Gusted
ee8ad6581c
Update module github.com/klauspost/compress to v1.18.6 (forgejo) ( #12372 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12372
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-03 04:07:02 +02:00
Renovate Bot and Gusted
8edcb8d4db
Update module github.com/fsnotify/fsnotify to v1.10.0 (forgejo) ( #12374 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12374
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-03 04:06:51 +02:00
Renovate Bot and Gusted
b6658076a9
Update dependency clippie to v4.1.15 (forgejo) ( #12371 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12371
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-05-02 03:07:26 +02:00
Renovate Bot
67250869d3
Update dependency @vitejs/plugin-vue to v6.0.6 (forgejo) ( #12360 )
2026-05-01 15:50:41 +02:00
Renovate Bot
cb05be1a09
Update dependency swagger-ui-dist to v5.32.5 (forgejo) ( #12363 )
2026-05-01 06:58:54 +02:00
Renovate Bot
b5e7a72e10
Update dependency @vue/test-utils to v2.4.9 (forgejo) ( #12361 )
2026-05-01 05:41:56 +02:00
Renovate Bot
948f8cc61a
Update dependency @stoplight/spectral-cli to v6.15.1 (forgejo) ( #12359 )
2026-05-01 04:14:12 +02:00
Renovate Bot
eb58d6c9d0
Update dependency @axe-core/playwright to v4.11.2 (forgejo) ( #12358 )
2026-05-01 01:58:09 +02:00
Renovate Bot and Gusted
e0777227d3
Update module github.com/meilisearch/meilisearch-go to v0.36.2 (forgejo) ( #12110 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12110
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-04-30 18:14:25 +02:00
Renovate Bot and Mathieu Fenniak
81c46e4a7c
Update module github.com/mattn/go-sqlite3 to v1.14.44 (forgejo) ( #12340 )
...
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/ ) | [Confidence](https://docs.renovatebot.com/merge-confidence/ ) |
|---|---|---|---|
| [github.com/mattn/go-sqlite3](https://github.com/mattn/go-sqlite3 ) | `v1.14.42` → `v1.14.44` |  |  |
---
### Release Notes
<details>
<summary>mattn/go-sqlite3 (github.com/mattn/go-sqlite3)</summary>
### [`v1.14.44`](https://github.com/mattn/go-sqlite3/compare/v1.14.43...v1.14.44 )
[Compare Source](https://github.com/mattn/go-sqlite3/compare/v1.14.43...v1.14.44 )
### [`v1.14.43`](https://github.com/mattn/go-sqlite3/compare/v1.14.42...v1.14.43 )
[Compare Source](https://github.com/mattn/go-sqlite3/compare/v1.14.42...v1.14.43 )
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNDEuNiIsInVwZGF0ZWRJblZlciI6IjQzLjE0MS42IiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12340
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-04-30 16:36:00 +02:00
Renovate Bot and Gusted
fd0a2086b0
Update dependency postcss to v8.5.12 (forgejo) ( #12337 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12337
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-04-30 03:31:02 +02:00
Renovate Bot and Gusted
32c9bbee08
Update data.forgejo.org/forgejo/forgejo Docker tag to v11.0.13 (forgejo) ( #12336 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12336
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-04-30 03:05:44 +02:00
Renovate Bot
90c4397d57
Update renovate Docker tag to v43.141.6 (forgejo) ( #12278 )
2026-04-27 14:58:51 +02:00
Renovate Bot and Mathieu Fenniak
94ef440a1c
Lock file maintenance (forgejo) ( #12279 )
...
This PR contains the following updates:
| Update | Change |
|---|---|
| lockFileMaintenance | All locks refreshed |
🔧 This Pull Request updates lock files to use the latest dependency versions.
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM, only on Monday (`* 0-3 * * 1`)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions ) if that's undesired.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzkuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE0MS42IiwidGFyZ2V0QnJhbmNoIjoiZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12279
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org >
2026-04-27 02:09:29 +02:00
Renovate Bot
0d94308619
Update dependency vue to v3.5.33 (forgejo) ( #12264 )
2026-04-26 14:11:23 +02:00
Renovate Bot and Gusted
10643ceb9b
Update dependency htmx.org to v2.0.10 (forgejo) ( #12256 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12256
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-04-25 01:06:51 +02:00
Renovate Bot and Gusted
9d275907c5
Update dependency @codemirror/view to v6.41.1 (forgejo) ( #12219 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12219
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-04-24 18:36:55 +02:00
Renovate Bot and Gusted
a562140896
Update dependency htmx.org to v2.0.9 (forgejo) ( #12248 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12248
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
2026-04-24 00:46:55 +02:00
Renovate Bot and Gusted
529b14291d
Update dependency clippie to v4.1.14 (forgejo) ( #12209 )
...
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12209
Reviewed-by: Gusted <gusted@noreply.codeberg.org >
Co-authored-by: Renovate Bot <bot@kriese.eu >
Co-committed-by: Renovate Bot <bot@kriese.eu >
2026-04-21 19:49:54 +02:00