-
Notifications
You must be signed in to change notification settings - Fork 2
build(aqua-proj): 🌊 minor aqua #97
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
main
Choose a base branch
from
renovate/aqua
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
+23
−23
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
sheldonhull
previously approved these changes
Oct 4, 2025
d4971e9
affaa7e to
d4971e9
Compare
d4971e9 to
d36ede4
Compare
d36ede4 to
6d6fd9e
Compare
6d6fd9e to
a312b72
Compare
a312b72 to
16ba134
Compare
16ba134 to
4a947d9
Compare
4a947d9 to
718f5ab
Compare
57f8356 to
50d6cf2
Compare
50d6cf2 to
71c49bb
Compare
71c49bb to
00f449c
Compare
00f449c to
7f0ca9d
Compare
7f0ca9d to
8fdc5a0
Compare
8fdc5a0 to
8393051
Compare
8393051 to
61519ca
Compare
61519ca to
482f91d
Compare
482f91d to
c9e5a29
Compare
c9e5a29 to
2f8e7c0
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.18.1->v1.38.0v2.42.2->v2.55.2v4.0.3->v4.0.4v4.296.0->v4.442.0v2.0.0->v2.1.1v2.65.0->v2.83.1v2.35.0->v2.37.1v17.2.0->v17.3.01.23.5->1.25.4v1.63.4->v1.64.8v2.5.1->v2.13.0v4.45.1->v4.49.2v1.21.0->v1.24.0v0.7.0->v0.9.2Release Notes
anchore/syft (anchore/syft)
v1.38.0Compare Source
Added Features
Bug Fixes
extrasstatements in Python PDM cataloger [#4352 @wagoodman]idorname(causing CycloneDX parser error) [#4363]Additional Changes
(Full Changelog)
v1.37.0Compare Source
Added Features
Bug Fixes
deinstalledstate should not be in SBOM [#3063 #4231 @rkirk-nos](Full Changelog)
v1.36.0Compare Source
Added Features
Bug Fixes
(Full Changelog)
v1.34.2Compare Source
Bug Fixes
(Full Changelog)
v1.34.1Compare Source
Added Features
Bug Fixes
(Full Changelog)
v1.33.0Compare Source
Added Features
(Full Changelog)
v1.32.0Compare Source
Added Features
Bug Fixes
Additional Changes
(Full Changelog)
v1.31.0Compare Source
Added Features
PackageSupplierin root of SPDX document generated by CLI [#3098 #4131 @spiffcs]Bug Fixes
Bundle-Licensefield of manifest [#3186](Full Changelog)
v1.30.0Compare Source
Added Features
Bug Fixes
(Full Changelog)
v1.29.1Compare Source
Bug Fixes
(Full Changelog)
v1.29.0Compare Source
Added Features
uv.lockfiles [#3268 #3763 @jkugler]Additional Changes
(Full Changelog)
v1.28.0Compare Source
Added Features
Additional Changes
(Full Changelog)
v1.27.1Compare Source
Bug Fixes
Additional Changes
(Full Changelog)
v1.27.0Compare Source
Added Features
Bug Fixes
status.d/[#3912](Full Changelog)
A HUGE thank you to @rezmoss for his help identifying and solving an issue causing excessive time and memory consumption with large numbers of symlinks! ❤️
v1.26.1Compare Source
Bug Fixes
(Full Changelog)
v1.26.0Compare Source
Added Features
Bug Fixes
pkg.JavaArchive.PomPropertiesis being populated even though nopom.propertiesfile was present for analysis [#3922 @wagoodman](Full Changelog)
v1.25.1Compare Source
Additional Changes
(Full Changelog)
v1.25.0Compare Source
Added Features
Bug Fixes
(Full Changelog)
v1.24.0Compare Source
Added Features
(devel)as the version should instead stubUNKNOWNbased on the compliance policy [#3324 #3873 @wagoodman]Bug Fixes
Additional Changes
(Full Changelog)
v1.23.1Compare Source
Additional Changes
(Full Changelog)
v1.23.0Compare Source
Added Features
Bug Fixes
go.modreplace directives [#3812 @VictorHuu](Full Changelog)
v1.22.0Compare Source
Added Features
Bug Fixes
(Full Changelog)
v1.21.0Compare Source
Added Features
Bug Fixes
fileresolver.containsPathallocates unnecessarily [#3729 #3730 @yoav-orca]Additional Changes
(Full Changelog)
v1.20.0Compare Source
Added Features
Bug Fixes
Additional Changes
(Full Changelog)
v1.19.0Compare Source
Added Features
Bug Fixes
:[#3577 #3596 @spiffcs @jkugler]Additional Changes
(Full Changelog)
aquaproj/aqua (aquaproj/aqua)
v2.55.2Compare Source
Performance Improvement
#4342 Skip packages that cannot provide the desired exe @refi64
Others
#4312 Update Go to 1.25.4
v2.55.1Compare Source
🐛 Bug Fixes
#4274 #4276 exec: Fix the command name (
args[0])Dependency Updates
#4220 #4266 Update github.com/google/go-github/v74 to v76
#4233 #4251 #4261 Update Go to 1.25.2
Others
Release Cosign Bundle file *.bundle
v2.55.0Compare Source
Features
#4195 #4213 Support verifying the integrity of GitHub Releases
https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/verifying-the-integrity-of-a-release
https://aquaproj.github.io/docs/reference/security/github-immutable-release
v2.54.1Compare Source
🐛 Bug Fixes
#4182 Fix a bug of
generate-registrycommand thatarm64is replaced toarmincorrectlyv2.54.0Compare Source
Features
#4173 ghtkn integration
https://aquaproj.github.io/docs/reference/security/ghtkn/
Now aqua can get a GitHub App User Access Token by ghtkn integration.
Stop risking token leaks - Use secure, short-lived GitHub tokens for local development.
Requirements
The ghtkn integration requires:
This feature doesn't depend on ghtkn CLI.
Limitation
The integration requires the user interaction when creating an access token via Device Flow, so it's unavailable in CI.
Set up
For more details, please see https://github.com/suzuki-shunsuke/ghtkn .
AQUA_GHTKN_ENABLED=trueexport AQUA_GHTKN_ENABLED=trueThen aqua gets a user access token using ghtkn Go SDK when aqua calls GitHub APIs.
v2.53.11Compare Source
Performance Improvement
#4159 Update github.com/gdamore/tcell/v2 to reduce startup time @refi64
Benchmark
aqua.yaml
v2.53.10Compare Source
🛡️ Starting from this release, Immutable Release is enabled!
#4147 Update Go to v1.25.1
#4145 Update aqua-proxy to v1.2.12
🐛 Bug Fixes
#4140 Fix error messages
v2.53.9Compare Source
Pull Requests | Issues | aquaproj/aqua@v2.53.8...v2.53.9
🐛 Bug Fixes
#4064 Fix a bug that environment variables aren't passed to
gh attestation verifyOthers
#4065 Update Go to v1.24.6
#4065 Update aqua-proxy to v1.2.11
v2.53.8Compare Source
Pull Requests | Issues | aquaproj/aqua@v2.53.7...v2.53.8
🐛 Bug Fixes
#4047 cp: Add missing .exe on Windows @W1M0R
v2.53.7Compare Source
Pull Requests | Issues | aquaproj/aqua@v2.53.6...v2.53.7
Fixes
#4038 Fix a bug that it fails to verify GitHub Artifact Attestations on GitHub Enterprise Server @yamoyamoto
v2.53.6Compare Source
Pull Requests | Issues | aquaproj/aqua@v2.53.5...v2.53.6
🐛 Bug Fixes
#4024 #4025 Fix a bug that aqua works without registries'
ref#4019 Set User-Agent to GitHub Release downloads @yanolab
v2.53.5Compare Source
Pull Requests | [Issues](h
Configuration
📅 Schedule: Branch creation - "after 10pm on monday,before 3am on monday" in timezone America/Chicago, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.