1
0
mirror of https://github.com/goreleaser/goreleaser.git synced 2025-10-08 23:12:05 +02:00
Commit Graph

7083 Commits

Author SHA1 Message Date
Carlos Alexandro Becker
24f73e8db9 ci: scorecard.yml pin fix
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-24 00:40:28 -03:00
Carlos Alexandro Becker
2f82c947e0 ci: better pinning
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-24 00:11:02 -03:00
Carlos Alexandro Becker
f525352160 ci: fix nightly.yml
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 23:26:10 -03:00
Carlos Alexandro Becker
c1164bb72c ci: fix nightly.yml
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 21:48:31 -03:00
dependabot[bot]
a3138e7ec7 chore(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 (#6112)
Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action)
from 2.4.1 to 2.4.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/ossf/scorecard-action/releases">ossf/scorecard-action's
releases</a>.</em></p>
<blockquote>
<h2>v2.4.2</h2>
<h2>What's Changed</h2>
<p>This update bumps the Scorecard version to the v5.2.1 release. For a
complete list of changes, please refer to the Scorecard <a
href="https://github.com/ossf/scorecard/releases/tag/v5.2.0">v5.2.0</a>
and <a
href="https://github.com/ossf/scorecard/releases/tag/v5.2.1">v5.2.1</a>
release notes.</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/ossf/scorecard-action/compare/v2.4.1...v2.4.2">https://github.com/ossf/scorecard-action/compare/v2.4.1...v2.4.2</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="05b42c6244"><code>05b42c6</code></a>
🌱 bump docker to ghcr v2.4.2 (<a
href="https://redirect.github.com/ossf/scorecard-action/issues/1548">#1548</a>)</li>
<li><a
href="b225da6b2b"><code>b225da6</code></a>
Bump github.com/ossf/scorecard/v5 from v5.2.0 to v5.2.1 (<a
href="https://redirect.github.com/ossf/scorecard-action/issues/1550">#1550</a>)</li>
<li><a
href="9399f6f424"><code>9399f6f</code></a>
🌱 Bump the docker-images group across 1 directory with 2
updates (<a
href="https://redirect.github.com/ossf/scorecard-action/issues/1">#1</a>...</li>
<li><a
href="e1daa8c5c7"><code>e1daa8c</code></a>
🌱 Bump the github-actions group across 1 directory with 5
updates (#...</li>
<li><a
href="9fe6511b9b"><code>9fe6511</code></a>
🌱 Bump golang.org/x/net from 0.39.0 to 0.40.0 (<a
href="https://redirect.github.com/ossf/scorecard-action/issues/1542">#1542</a>)</li>
<li><a
href="25b9cd9cd1"><code>25b9cd9</code></a>
🌱 Bump github.com/ossf/scorecard/v5 from v5.1.1 to v5.2.0 (<a
href="https://redirect.github.com/ossf/scorecard-action/issues/1547">#1547</a>)</li>
<li><a
href="18cc9b8130"><code>18cc9b8</code></a>
🌱 Bump golang.org/x/net from 0.38.0 to 0.39.0 (<a
href="https://redirect.github.com/ossf/scorecard-action/issues/1536">#1536</a>)</li>
<li><a
href="db7814227b"><code>db78142</code></a>
🌱 Bump the github-actions group with 2 updates (<a
href="https://redirect.github.com/ossf/scorecard-action/issues/1538">#1538</a>)</li>
<li><a
href="de386ed459"><code>de386ed</code></a>
🌱 Bump golang from 1.24.1 to 1.24.2 in the docker-images group
(<a
href="https://redirect.github.com/ossf/scorecard-action/issues/1534">#1534</a>)</li>
<li><a
href="5b7cedba4e"><code>5b7cedb</code></a>
🌱 Bump github.com/sigstore/cosign/v2 from 2.4.3 to 2.5.0 (<a
href="https://redirect.github.com/ossf/scorecard-action/issues/1537">#1537</a>)</li>
<li>Additional commits viewable in <a
href="f49aabe0b5...05b42c6244">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ossf/scorecard-action&package-manager=github_actions&previous-version=2.4.1&new-version=2.4.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-23 23:02:23 +00:00
Carlos Alexandro Becker
798a9279db fix: lint
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 16:51:11 -03:00
Carlos Alexandro Becker
33423e62c9 test: improve fuzz tests
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 16:45:32 -03:00
Carlos Alexandro Becker
295cda7af7 test: fuzz
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 16:38:12 -03:00
Carlos Alexandro Becker
9c71861a6e test: fuzz tests for tmpl, artifact
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 15:56:37 -03:00
Carlos Alexandro Becker
5af8776fad ci: fix build.yml
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 15:36:43 -03:00
Carlos Alexandro Becker
f075f54645 ci: fix docs.yml and generate.yml
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 15:32:22 -03:00
dependabot[bot]
c8311e1be8 chore(deps): bump actions/upload-artifact from 4.6.1 to 4.6.2 (#6110)
Bumps
[actions/upload-artifact](https://github.com/actions/upload-artifact)
from 4.6.1 to 4.6.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/upload-artifact/releases">actions/upload-artifact's
releases</a>.</em></p>
<blockquote>
<h2>v4.6.2</h2>
<h2>What's Changed</h2>
<ul>
<li>Update to use artifact 2.3.2 package &amp; prepare for new
upload-artifact release by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/upload-artifact/pull/685">actions/upload-artifact#685</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/upload-artifact/pull/685">actions/upload-artifact#685</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/upload-artifact/compare/v4...v4.6.2">https://github.com/actions/upload-artifact/compare/v4...v4.6.2</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="ea165f8d65"><code>ea165f8</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/upload-artifact/issues/685">#685</a>
from salmanmkc/salmanmkc/3-new-upload-artifacts-release</li>
<li><a
href="08396203c1"><code>0839620</code></a>
Prepare for new release of actions/upload-artifact with new toolkit
cache ver...</li>
<li>See full diff in <a
href="4cec3d8aa0...ea165f8d65">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/upload-artifact&package-manager=github_actions&previous-version=4.6.1&new-version=4.6.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-23 18:28:58 +00:00
Carlos Alexandro Becker
064569886f ci: fix nightly.yml
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 15:27:39 -03:00
Carlos Alexandro Becker
096bf286ec ci: fix gitleaks.yml
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 15:25:40 -03:00
Carlos Alexandro Becker
7041786044 ci: fix gitleaks.yml
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 15:22:12 -03:00
Carlos Alexandro Becker
80889195cb ci: fix grype.yml
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 15:18:46 -03:00
Carlos Alexandro Becker
823595a3bd ci: build.yml perms
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 15:14:52 -03:00
Carlos Alexandro Becker
821cd7abb9 docs: pin mkdocs-material image, add it to dependabot
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 15:10:39 -03:00
Carlos Alexandro Becker
3eea0d7752 ci(sec): improve workflows perms
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 15:06:26 -03:00
Carlos Alexandro Becker
0ef2b3f1a7 ci(sec): improve workflows
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 15:04:41 -03:00
Carlos Alexandro Becker
8c958d5828 ci: scorecard job 2025-09-23 14:49:06 -03:00
Carlos Alexandro Becker
b5b14f7b4a ci: cleanup openssf action
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 14:47:28 -03:00
Carlos Alexandro Becker
f6d9cc2c8b ci: add openssf action
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 14:45:20 -03:00
Carlos Alexandro Becker
2295a847f7 ci: add openssf action
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 14:41:32 -03:00
Carlos Alexandro Becker
6c80f9d2f4 chore: schema update
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-23 14:24:58 -03:00
Carlos Alexandro Becker
44b0d91479 docs: fix title 2025-09-23 13:54:23 -03:00
dependabot[bot]
d053661fe8 chore(deps): bump gitlab.com/gitlab-org/api/client-go from 0.147.0 to 0.148.0 (#6109)
Bumps
[gitlab.com/gitlab-org/api/client-go](https://gitlab.com/gitlab-org/api/client-go)
from 0.147.0 to 0.148.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://gitlab.com/gitlab-org/api/client-go/tags">gitlab.com/gitlab-org/api/client-go's
releases</a>.</em></p>
<blockquote>
<h2>v0.148.0</h2>
<h1><a
href="https://gitlab.com/gitlab-org/api/client-go/compare/v0.147.1...v0.148.0">0.148.0</a>
(2025-09-23)</h1>
<h3>Features</h3>
<ul>
<li><strong>ResourceGroup:</strong> add <code>newest_ready_first</code>
to resource group <code>process_mode</code> (<a
href="fc8f7431da">fc8f743</a>)</li>
</ul>
<h2>v0.147.1</h2>
<h2><a
href="https://gitlab.com/gitlab-org/api/client-go/compare/v0.147.0...v0.147.1">0.147.1</a>
(2025-09-22)</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>client:</strong> use default retry policy from retryablehttp
(<a
href="2a72511311">2a72511</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://gitlab.com/gitlab-org/api/client-go/blob/main/CHANGELOG.md">gitlab.com/gitlab-org/api/client-go's
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://gitlab.com/gitlab-org/api/client-go/compare/v0.147.1...v0.148.0">0.148.0</a>
(2025-09-23)</h1>
<h3>Features</h3>
<ul>
<li><strong>ResourceGroup:</strong> add <code>newest_ready_first</code>
to resource group <code>process_mode</code> (<a
href="fc8f7431da">fc8f743</a>)</li>
</ul>
<h2><a
href="https://gitlab.com/gitlab-org/api/client-go/compare/v0.147.0...v0.147.1">0.147.1</a>
(2025-09-22)</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>client:</strong> use default retry policy from retryablehttp
(<a
href="2a72511311">2a72511</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="3558d3b9fe"><code>3558d3b</code></a>
chore(release): 0.148.0 [skip ci]</li>
<li><a
href="0da9441600"><code>0da9441</code></a>
Merge branch 'add-newest-ready-first-to-resource-group-process-mode'
into 'main'</li>
<li><a
href="fc8f7431da"><code>fc8f743</code></a>
feat(ResourceGroup): add <code>newest_ready_first</code> to resource
group <code>process_mode</code></li>
<li><a
href="5ae628595a"><code>5ae6285</code></a>
chore(release): 0.147.1 [skip ci]</li>
<li><a
href="2762ea0207"><code>2762ea0</code></a>
Merge branch 'use-retryablehttp-default-retry-policy' into 'main'</li>
<li><a
href="2a72511311"><code>2a72511</code></a>
fix(client): use default retry policy from retryablehttp</li>
<li>See full diff in <a
href="https://gitlab.com/gitlab-org/api/client-go/compare/v0.147.0...v0.148.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=gitlab.com/gitlab-org/api/client-go&package-manager=go_modules&previous-version=0.147.0&new-version=0.148.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-23 08:40:26 +00:00
Carlos Alexandro Becker
f63a01c9c8 docs: icons on smaller screens 2025-09-22 10:56:12 -03:00
dependabot[bot]
75b302cc5e chore(deps): bump gitlab.com/gitlab-org/api/client-go from 0.146.0 to 0.147.0 (#6108)
Bumps
[gitlab.com/gitlab-org/api/client-go](https://gitlab.com/gitlab-org/api/client-go)
from 0.146.0 to 0.147.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://gitlab.com/gitlab-org/api/client-go/tags">gitlab.com/gitlab-org/api/client-go's
releases</a>.</em></p>
<blockquote>
<h2>v0.147.0</h2>
<h1><a
href="https://gitlab.com/gitlab-org/api/client-go/compare/v0.146.0...v0.147.0">0.147.0</a>
(2025-09-22)</h1>
<h3>Features</h3>
<ul>
<li><strong>Project:</strong> add resource_group_default_process_mode
(<a
href="7804fafa18">7804faf</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://gitlab.com/gitlab-org/api/client-go/blob/main/CHANGELOG.md">gitlab.com/gitlab-org/api/client-go's
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://gitlab.com/gitlab-org/api/client-go/compare/v0.146.0...v0.147.0">0.147.0</a>
(2025-09-22)</h1>
<h3>Features</h3>
<ul>
<li><strong>Project:</strong> add resource_group_default_process_mode
(<a
href="7804fafa18">7804faf</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="1b7f4d1832"><code>1b7f4d1</code></a>
chore(release): 0.147.0 [skip ci]</li>
<li><a
href="2b455d539f"><code>2b455d5</code></a>
Merge branch 'renovate/golangci-golangci-lint-2.x' into 'main'</li>
<li><a
href="9a999ca95b"><code>9a999ca</code></a>
Merge branch 'add-default-resource-group-process-mode-to-project' into
'main'</li>
<li><a
href="7804fafa18"><code>7804faf</code></a>
feat(Project): add resource_group_default_process_mode</li>
<li><a
href="fb8017b434"><code>fb8017b</code></a>
chore(deps): update golangci/golangci-lint docker tag to v2.5.0</li>
<li>See full diff in <a
href="https://gitlab.com/gitlab-org/api/client-go/compare/v0.146.0...v0.147.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=gitlab.com/gitlab-org/api/client-go&package-manager=go_modules&previous-version=0.146.0&new-version=0.147.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-22 08:36:00 +00:00
dependabot[bot]
b4d7c91de4 chore(deps): bump github.com/mark3labs/mcp-go from 0.39.1 to 0.40.0 (#6107)
Bumps [github.com/mark3labs/mcp-go](https://github.com/mark3labs/mcp-go)
from 0.39.1 to 0.40.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/mark3labs/mcp-go/releases">github.com/mark3labs/mcp-go's
releases</a>.</em></p>
<blockquote>
<h2>Release v0.40.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(get-server-tools): add GetTools method for retrieve
MCPServer.tools by <a
href="https://github.com/ValeriiStepanets"><code>@​ValeriiStepanets</code></a>
in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/437">mark3labs/mcp-go#437</a></li>
<li>fix: don't share mutex between tools/resources by <a
href="https://github.com/tjhop"><code>@​tjhop</code></a> in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/574">mark3labs/mcp-go#574</a></li>
<li>docs(server): Correct custom endpoint example for streamable HTTP
transport by <a
href="https://github.com/IAmSurajBobade"><code>@​IAmSurajBobade</code></a>
in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/577">mark3labs/mcp-go#577</a></li>
<li>feat: add NewToolResultJSON by <a
href="https://github.com/changkun"><code>@​changkun</code></a> in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/550">mark3labs/mcp-go#550</a></li>
<li>Do not panic on nil io by <a
href="https://github.com/sam-at-luther"><code>@​sam-at-luther</code></a>
in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/446">mark3labs/mcp-go#446</a></li>
<li>Remove useless allocations; use (*Type)(nil) instead by <a
href="https://github.com/mikeschinkel"><code>@​mikeschinkel</code></a>
in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/545">mark3labs/mcp-go#545</a></li>
<li>improve streamable http sse logging by <a
href="https://github.com/ethanoroshiba"><code>@​ethanoroshiba</code></a>
in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/508">mark3labs/mcp-go#508</a></li>
<li>feat!: add context.Context to TokenStore methods by <a
href="https://github.com/sd2k"><code>@​sd2k</code></a> in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/557">mark3labs/mcp-go#557</a></li>
<li>Detect Pong from MCP Client and skip Session ID validation by <a
href="https://github.com/struckoff"><code>@​struckoff</code></a> in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/539">mark3labs/mcp-go#539</a></li>
<li>feat: implement MCP elicitation support (<a
href="https://redirect.github.com/mark3labs/mcp-go/issues/413">#413</a>)
by <a href="https://github.com/JBUinfo"><code>@​JBUinfo</code></a> in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/548">mark3labs/mcp-go#548</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/ValeriiStepanets"><code>@​ValeriiStepanets</code></a>
made their first contribution in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/437">mark3labs/mcp-go#437</a></li>
<li><a
href="https://github.com/IAmSurajBobade"><code>@​IAmSurajBobade</code></a>
made their first contribution in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/577">mark3labs/mcp-go#577</a></li>
<li><a href="https://github.com/changkun"><code>@​changkun</code></a>
made their first contribution in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/550">mark3labs/mcp-go#550</a></li>
<li><a
href="https://github.com/sam-at-luther"><code>@​sam-at-luther</code></a>
made their first contribution in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/446">mark3labs/mcp-go#446</a></li>
<li><a
href="https://github.com/mikeschinkel"><code>@​mikeschinkel</code></a>
made their first contribution in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/545">mark3labs/mcp-go#545</a></li>
<li><a
href="https://github.com/ethanoroshiba"><code>@​ethanoroshiba</code></a>
made their first contribution in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/508">mark3labs/mcp-go#508</a></li>
<li><a href="https://github.com/struckoff"><code>@​struckoff</code></a>
made their first contribution in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/539">mark3labs/mcp-go#539</a></li>
<li><a href="https://github.com/JBUinfo"><code>@​JBUinfo</code></a> made
their first contribution in <a
href="https://redirect.github.com/mark3labs/mcp-go/pull/548">mark3labs/mcp-go#548</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/mark3labs/mcp-go/compare/v0.39.1...v0.40.0">https://github.com/mark3labs/mcp-go/compare/v0.39.1...v0.40.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="281377ec19"><code>281377e</code></a>
fmt</li>
<li><a
href="e7f084c9b8"><code>e7f084c</code></a>
feat: implement MCP elicitation support (<a
href="https://redirect.github.com/mark3labs/mcp-go/issues/413">#413</a>)
(<a
href="https://redirect.github.com/mark3labs/mcp-go/issues/548">#548</a>)</li>
<li><a
href="32887533d9"><code>3288753</code></a>
Detect Pong from MCP Client and skip Session ID validation (<a
href="https://redirect.github.com/mark3labs/mcp-go/issues/539">#539</a>)</li>
<li><a
href="d70b8d2717"><code>d70b8d2</code></a>
feat!: add context.Context to TokenStore methods (<a
href="https://redirect.github.com/mark3labs/mcp-go/issues/557">#557</a>)</li>
<li><a
href="c87c957a7a"><code>c87c957</code></a>
improve streamable http sse logging (<a
href="https://redirect.github.com/mark3labs/mcp-go/issues/508">#508</a>)</li>
<li><a
href="a6f260bd6e"><code>a6f260b</code></a>
Remove useless allocations; use (*Type)(nil) instead (<a
href="https://redirect.github.com/mark3labs/mcp-go/issues/545">#545</a>)</li>
<li><a
href="cb23bd1e37"><code>cb23bd1</code></a>
Do not panic on nil io (<a
href="https://redirect.github.com/mark3labs/mcp-go/issues/446">#446</a>)</li>
<li><a
href="840879b8db"><code>840879b</code></a>
feat: add NewToolResultJSON (<a
href="https://redirect.github.com/mark3labs/mcp-go/issues/550">#550</a>)</li>
<li><a
href="47e941967f"><code>47e9419</code></a>
Fix Custom Endpoint example (<a
href="https://redirect.github.com/mark3labs/mcp-go/issues/577">#577</a>)</li>
<li><a
href="71a5805144"><code>71a5805</code></a>
fix: don't share mutex between tools/resources (<a
href="https://redirect.github.com/mark3labs/mcp-go/issues/574">#574</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/mark3labs/mcp-go/compare/v0.39.1...v0.40.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/mark3labs/mcp-go&package-manager=go_modules&previous-version=0.39.1&new-version=0.40.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-22 08:34:52 +00:00
dependabot[bot]
49a0340cb5 chore(deps): bump cachix/install-nix-action from 31.6.1 to 31.6.2 (#6106)
Bumps
[cachix/install-nix-action](https://github.com/cachix/install-nix-action)
from 31.6.1 to 31.6.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/cachix/install-nix-action/releases">cachix/install-nix-action's
releases</a>.</em></p>
<blockquote>
<h2>v31.6.2</h2>
<h2>What's Changed</h2>
<ul>
<li>nix: 2.31.1 -&gt; 2.31.2 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/cachix/install-nix-action/pull/256">cachix/install-nix-action#256</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/cachix/install-nix-action/compare/v31...v31.6.2">https://github.com/cachix/install-nix-action/compare/v31...v31.6.2</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="a809471b5c"><code>a809471</code></a>
Merge pull request <a
href="https://redirect.github.com/cachix/install-nix-action/issues/256">#256</a>
from cachix/create-pull-request/patch</li>
<li><a
href="d5f1c043d0"><code>d5f1c04</code></a>
nix: 2.31.1 -&gt; 2.31.2</li>
<li>See full diff in <a
href="7be5dee142...a809471b5c">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=cachix/install-nix-action&package-manager=github_actions&previous-version=31.6.1&new-version=31.6.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-22 08:28:38 +00:00
Carlos Alexandro Becker
78ec122301 docs(sec): threat model
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-20 16:15:54 -03:00
actions-user
30d911507d chore: auto-update generated files 2025-09-20 08:09:15 +00:00
Carlos Alexandro Becker
1423799913 ci: moderator cleanup
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-19 23:31:25 -03:00
Chris Blum
269a76b03d docs: fedora move exclude to repo config (#6103)
Fedora: Move the OSS/Pro exclude config to the repo config That way it
works even with yum update later on

**If applied, this commit will...**
Provide a better outcome for people using goreleaser on Fedora (like me)

**Why is this change being made?**
The install instructions are not optimal and I keep getting
goreleaser-pro installed when I do yum update
2025-09-19 14:28:54 -03:00
dependabot[bot]
4cbd028c26 chore(deps): bump gitlab.com/gitlab-org/api/client-go from 0.145.0 to 0.146.0 (#6100)
Bumps
[gitlab.com/gitlab-org/api/client-go](https://gitlab.com/gitlab-org/api/client-go)
from 0.145.0 to 0.146.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://gitlab.com/gitlab-org/api/client-go/tags">gitlab.com/gitlab-org/api/client-go's
releases</a>.</em></p>
<blockquote>
<h2>v0.146.0</h2>
<h1><a
href="https://gitlab.com/gitlab-org/api/client-go/compare/v0.145.0...v0.146.0">0.146.0</a>
(2025-09-18)</h1>
<h3>Features</h3>
<ul>
<li><strong>pipelines:</strong> Add compile-time type-safe pipeline
inputs support (<a
href="4b30e60260">4b30e60</a>),
closes <a
href="https://gitlab.com/gitlab-org/api/client-go/issues/2154">gitlab-org/api/client-go#2154</a></li>
<li><strong>PipelinesService:</strong> Add support for pipeline inputs
with type validation (<a
href="ab3056f403">ab3056f</a>),
closes <a
href="https://gitlab.com/gitlab-org/api/client-go/issues/2154">gitlab-org/api/client-go#2154</a></li>
<li><strong>PipelineTriggersService:</strong> Add support for pipeline
inputs to trigger API (<a
href="9ad770e49e">9ad770e</a>),
closes <a
href="https://gitlab.com/gitlab-org/api/client-go/issues/2154">gitlab-org/api/client-go#2154</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://gitlab.com/gitlab-org/api/client-go/blob/main/CHANGELOG.md">gitlab.com/gitlab-org/api/client-go's
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://gitlab.com/gitlab-org/api/client-go/compare/v0.145.0...v0.146.0">0.146.0</a>
(2025-09-18)</h1>
<h3>Features</h3>
<ul>
<li><strong>pipelines:</strong> Add compile-time type-safe pipeline
inputs support (<a
href="4b30e60260">4b30e60</a>),
closes <a
href="https://gitlab.com/gitlab-org/api/client-go/issues/2154">gitlab-org/api/client-go#2154</a></li>
<li><strong>PipelinesService:</strong> Add support for pipeline inputs
with type validation (<a
href="ab3056f403">ab3056f</a>),
closes <a
href="https://gitlab.com/gitlab-org/api/client-go/issues/2154">gitlab-org/api/client-go#2154</a></li>
<li><strong>PipelineTriggersService:</strong> Add support for pipeline
inputs to trigger API (<a
href="9ad770e49e">9ad770e</a>),
closes <a
href="https://gitlab.com/gitlab-org/api/client-go/issues/2154">gitlab-org/api/client-go#2154</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="7108931a3b"><code>7108931</code></a>
chore(release): 0.146.0 [skip ci]</li>
<li><a
href="a4ca419374"><code>a4ca419</code></a>
Merge branch 'fforster/pipeline-inputs' into 'main'</li>
<li><a
href="6242a7dc40"><code>6242a7d</code></a>
refactor(PipelinesService): Move interface assetion into the test
file</li>
<li><a
href="4b30e60260"><code>4b30e60</code></a>
feat(pipelines): Add compile-time type-safe pipeline inputs support</li>
<li><a
href="9ad770e49e"><code>9ad770e</code></a>
feat(PipelineTriggersService): Add support for pipeline inputs to
trigger API</li>
<li><a
href="ab3056f403"><code>ab3056f</code></a>
feat(PipelinesService): Add support for pipeline inputs with type
validation</li>
<li><a
href="1af9b22dd7"><code>1af9b22</code></a>
Merge branch 'renovate/node-24.x' into 'main'</li>
<li><a
href="c078b17bfa"><code>c078b17</code></a>
chore(deps): update node docker tag to v24</li>
<li><a
href="ea0d0f7bf8"><code>ea0d0f7</code></a>
Merge branch 'remove-dependency-proxy' into 'main'</li>
<li><a
href="4c1543a428"><code>4c1543a</code></a>
ci(no-release): remove dependency proxy from pipeline</li>
<li>See full diff in <a
href="https://gitlab.com/gitlab-org/api/client-go/compare/v0.145.0...v0.146.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=gitlab.com/gitlab-org/api/client-go&package-manager=go_modules&previous-version=0.145.0&new-version=0.146.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-19 08:23:55 +00:00
dependabot[bot]
05fb8f2f8f chore(deps): bump github.com/charmbracelet/fang from 0.4.1 to 0.4.2 (#6101)
Bumps
[github.com/charmbracelet/fang](https://github.com/charmbracelet/fang)
from 0.4.1 to 0.4.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/charmbracelet/fang/releases">github.com/charmbracelet/fang's
releases</a>.</em></p>
<blockquote>
<h2>v0.4.2</h2>
<h2>Changelog</h2>
<hr />
<p><!-- raw HTML omitted --><!-- raw HTML omitted --><!-- raw HTML
omitted --></p>
<p>Thoughts? Questions? We love hearing from you. Feel free to reach out
on <a href="https://x.com/charmcli">X</a>, <a
href="https://charm.land/discord">Discord</a>, <a
href="https://charm.land/slack">Slack</a>, <a
href="https://mastodon.social/@charmcli">The Fediverse</a>, <a
href="https://bsky.app/profile/charm.land">Bluesky</a>.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="055c2e3dda"><code>055c2e3</code></a>
chore: bump dependencies to fix <a
href="https://redirect.github.com/charmbracelet/fang/issues/73">#73</a></li>
<li>See full diff in <a
href="https://github.com/charmbracelet/fang/compare/v0.4.1...v0.4.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/charmbracelet/fang&package-manager=go_modules&previous-version=0.4.1&new-version=0.4.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-19 08:22:29 +00:00
dependabot[bot]
ed82758bd2 chore(deps): bump cargo-bins/cargo-binstall from cf49c6dbd5eb6865966cf4fae3ab1ecfb82ed87e to 6c16d05d76228d6ebb51c9db4595e86015d8df9d (#6099)
Bumps
[cargo-bins/cargo-binstall](https://github.com/cargo-bins/cargo-binstall)
from cf49c6dbd5eb6865966cf4fae3ab1ecfb82ed87e to
6c16d05d76228d6ebb51c9db4595e86015d8df9d.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/cargo-bins/cargo-binstall/blob/main/install-from-binstall-release.ps1">cargo-bins/cargo-binstall's
changelog</a>.</em></p>
<blockquote>
<p>$ErrorActionPreference = &quot;Stop&quot;
Set-PSDebug -Trace 1
$tmpdir = $Env:TEMP
$BINSTALL_VERSION = $Env:BINSTALL_VERSION
if ($BINSTALL_VERSION -and $BINSTALL_VERSION -notlike 'v*') {
# prefix version with v
$BINSTALL_VERSION = &quot;v$BINSTALL_VERSION&quot;
}</p>
<h1>Fetch binaries from <code>[..]/releases/latest/download/[..]</code>
if <em>no</em> version is</h1>
<h1>given, otherwise from
<code>[..]/releases/download/VERSION/[..]</code>. Note the shifted</h1>
<h1>location of '/download'.</h1>
<p>$base_url = if (-not $BINSTALL_VERSION) {
&quot;<a
href="https://github.com/cargo-bins/cargo-binstall/releases/latest/download/cargo-binstall-">https://github.com/cargo-bins/cargo-binstall/releases/latest/download/cargo-binstall-</a>&quot;
} else {
&quot;<a
href="https://github.com/cargo-bins/cargo-binstall/releases/download/$BINSTALL_VERSION/cargo-binstall-">https://github.com/cargo-bins/cargo-binstall/releases/download/$BINSTALL_VERSION/cargo-binstall-</a>&quot;
}</p>
<p>$proc_arch =
[Environment]::GetEnvironmentVariable(&quot;PROCESSOR_ARCHITECTURE&quot;,
[EnvironmentVariableTarget]::Machine)
if ($proc_arch -eq &quot;AMD64&quot;) {
$arch = &quot;x86_64&quot;
} elseif ($proc_arch -eq &quot;ARM64&quot;) {
$arch = &quot;aarch64&quot;
} else {
Write-Host &quot;Unsupported Architecture: $type&quot; -ForegroundColor
Red
[Environment]::Exit(1)
}
$url = &quot;$base_url$arch-pc-windows-msvc.zip&quot;
Invoke-WebRequest $url -OutFile $tmpdir\cargo-binstall.zip
Expand-Archive -Force $tmpdir\cargo-binstall.zip $tmpdir\cargo-binstall
Write-Host &quot;&quot;</p>
<p>$ps = Start-Process -PassThru -Wait
&quot;$tmpdir\cargo-binstall\cargo-binstall.exe&quot;
&quot;--self-install&quot;
if ($ps.ExitCode -ne 0) {
Invoke-Expression &quot;$tmpdir\cargo-binstall\cargo-binstall.exe -y
--force cargo-binstall&quot;
}</p>
<p>Remove-Item -Force $tmpdir\cargo-binstall.zip
Remove-Item -Recurse -Force $tmpdir\cargo-binstall
$cargo_home = if ($Env:CARGO_HOME -ne $null) { $Env:CARGO_HOME } else {
&quot;$HOME.cargo&quot; }
if ($Env:Path -split &quot;;&quot; -notcontains
&quot;$cargo_home\bin&quot;) {
if (($Env:CI -ne $null) -and ($Env:GITHUB_PATH -ne $null)) {
Add-Content -Path &quot;$Env:GITHUB_PATH&quot; -Value
&quot;$cargo_home\bin&quot;
} else {
Write-Host &quot;&quot;
Write-Host &quot;Your path is missing $cargo_home\bin, you might want to
add it.&quot; -ForegroundColor Red
Write-Host &quot;&quot;
}
}</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="6c16d05d76"><code>6c16d05</code></a>
dep: Upgrade transitive dependencies (<a
href="https://redirect.github.com/cargo-bins/cargo-binstall/issues/2314">#2314</a>)</li>
<li>See full diff in <a
href="cf49c6dbd5...6c16d05d76">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-19 08:15:48 +00:00
Kai
fd5a30f7d4 docs: fix inconsistency about symlink in nfpm.md (#6094)
This PR fixs inconsistency between comment and actual configuration in
nfpm symlink example.
2025-09-18 22:06:34 -03:00
Carlos Alexandro Becker
f195f3ced5 fix(sbom): --enrich=all should be the default (#6095)
currently the generated SBOMs might not be too useful without enriching,
as they won't have dependencies licenses and things like that.

enriching fixes it. It's done on goreleaser `main`, not sure if we
should make this the default or not 🤔

you can verify a SBOM with:

```sh
jq -r '.components[] | .name + " " + ([.licenses[]?.license.id] | join(","))' file.sbom.json
```

Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-18 22:06:09 -03:00
dependabot[bot]
627614245a chore(deps): bump cargo-bins/cargo-binstall from d020f1115f5ef21c966a766b15e98f8aad36a049 to cf49c6dbd5eb6865966cf4fae3ab1ecfb82ed87e (#6097)
Bumps
[cargo-bins/cargo-binstall](https://github.com/cargo-bins/cargo-binstall)
from d020f1115f5ef21c966a766b15e98f8aad36a049 to
cf49c6dbd5eb6865966cf4fae3ab1ecfb82ed87e.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/cargo-bins/cargo-binstall/blob/main/install-from-binstall-release.ps1">cargo-bins/cargo-binstall's
changelog</a>.</em></p>
<blockquote>
<p>$ErrorActionPreference = &quot;Stop&quot;
Set-PSDebug -Trace 1
$tmpdir = $Env:TEMP
$BINSTALL_VERSION = $Env:BINSTALL_VERSION
if ($BINSTALL_VERSION -and $BINSTALL_VERSION -notlike 'v*') {
# prefix version with v
$BINSTALL_VERSION = &quot;v$BINSTALL_VERSION&quot;
}</p>
<h1>Fetch binaries from <code>[..]/releases/latest/download/[..]</code>
if <em>no</em> version is</h1>
<h1>given, otherwise from
<code>[..]/releases/download/VERSION/[..]</code>. Note the shifted</h1>
<h1>location of '/download'.</h1>
<p>$base_url = if (-not $BINSTALL_VERSION) {
&quot;<a
href="https://github.com/cargo-bins/cargo-binstall/releases/latest/download/cargo-binstall-">https://github.com/cargo-bins/cargo-binstall/releases/latest/download/cargo-binstall-</a>&quot;
} else {
&quot;<a
href="https://github.com/cargo-bins/cargo-binstall/releases/download/$BINSTALL_VERSION/cargo-binstall-">https://github.com/cargo-bins/cargo-binstall/releases/download/$BINSTALL_VERSION/cargo-binstall-</a>&quot;
}</p>
<p>$proc_arch =
[Environment]::GetEnvironmentVariable(&quot;PROCESSOR_ARCHITECTURE&quot;,
[EnvironmentVariableTarget]::Machine)
if ($proc_arch -eq &quot;AMD64&quot;) {
$arch = &quot;x86_64&quot;
} elseif ($proc_arch -eq &quot;ARM64&quot;) {
$arch = &quot;aarch64&quot;
} else {
Write-Host &quot;Unsupported Architecture: $type&quot; -ForegroundColor
Red
[Environment]::Exit(1)
}
$url = &quot;$base_url$arch-pc-windows-msvc.zip&quot;
Invoke-WebRequest $url -OutFile $tmpdir\cargo-binstall.zip
Expand-Archive -Force $tmpdir\cargo-binstall.zip $tmpdir\cargo-binstall
Write-Host &quot;&quot;</p>
<p>$ps = Start-Process -PassThru -Wait
&quot;$tmpdir\cargo-binstall\cargo-binstall.exe&quot;
&quot;--self-install&quot;
if ($ps.ExitCode -ne 0) {
Invoke-Expression &quot;$tmpdir\cargo-binstall\cargo-binstall.exe -y
--force cargo-binstall&quot;
}</p>
<p>Remove-Item -Force $tmpdir\cargo-binstall.zip
Remove-Item -Recurse -Force $tmpdir\cargo-binstall
$cargo_home = if ($Env:CARGO_HOME -ne $null) { $Env:CARGO_HOME } else {
&quot;$HOME.cargo&quot; }
if ($Env:Path -split &quot;;&quot; -notcontains
&quot;$cargo_home\bin&quot;) {
if (($Env:CI -ne $null) -and ($Env:GITHUB_PATH -ne $null)) {
Add-Content -Path &quot;$Env:GITHUB_PATH&quot; -Value
&quot;$cargo_home\bin&quot;
} else {
Write-Host &quot;&quot;
Write-Host &quot;Your path is missing $cargo_home\bin, you might want to
add it.&quot; -ForegroundColor Red
Write-Host &quot;&quot;
}
}</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="cf49c6dbd5"><code>cf49c6d</code></a>
docs: edited the link to the tag badge (<a
href="https://redirect.github.com/cargo-bins/cargo-binstall/issues/2313">#2313</a>)</li>
<li>See full diff in <a
href="d020f1115f...cf49c6dbd5">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-18 08:19:14 +00:00
actions-user
4ec2fc327f chore: auto-update generated files 2025-09-18 02:52:08 +00:00
actions-user
d3d28a6aa7 chore: auto-update generated files v2.12.2 2025-09-18 02:07:53 +00:00
Carlos Alexandro Becker
cf8154aeab ci: enrich SBOMs
this will actually get the licenses of each dependency and put them in
the SBOMs.

You can verify that with:

	jq -r '.components[] | .name + " " + ([.licenses[]?.license.id] | join(","))' goreleaser_*.sbom.json

Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-17 13:39:45 -03:00
dependabot[bot]
803c6f1be9 chore(deps): bump actions/checkout from 4.3.0 to 5.0.0 (#6093)
Bumps [actions/checkout](https://github.com/actions/checkout) from 4.3.0
to 5.0.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/releases">actions/checkout's
releases</a>.</em></p>
<blockquote>
<h2>v5.0.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Update actions checkout to use node 24 by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
<li>Prepare v5.0.0 release by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2238">actions/checkout#2238</a></li>
</ul>
<h2>⚠️ Minimum Compatible Runner Version</h2>
<p><strong>v2.327.1</strong><br />
<a
href="https://github.com/actions/runner/releases/tag/v2.327.1">Release
Notes</a></p>
<p>Make sure your runner is updated to this version or newer to use this
release.</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v4...v5.0.0">https://github.com/actions/checkout/compare/v4...v5.0.0</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<h2>V5.0.0</h2>
<ul>
<li>Update actions checkout to use node 24 by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
</ul>
<h2>V4.3.0</h2>
<ul>
<li>docs: update README.md by <a
href="https://github.com/motss"><code>@​motss</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li>
<li>Add internal repos for checking out multiple repositories by <a
href="https://github.com/mouismail"><code>@​mouismail</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li>
<li>Documentation update - add recommended permissions to Readme by <a
href="https://github.com/benwells"><code>@​benwells</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li>
<li>Adjust positioning of user email note and permissions heading by <a
href="https://github.com/joshmgross"><code>@​joshmgross</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li>
<li>Update README.md by <a
href="https://github.com/nebuk89"><code>@​nebuk89</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li>
<li>Update CODEOWNERS for actions by <a
href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li>
<li>Update package dependencies by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li>
</ul>
<h2>v4.2.2</h2>
<ul>
<li><code>url-helper.ts</code> now leverages well-known environment
variables by <a href="https://github.com/jww3"><code>@​jww3</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li>
<li>Expand unit test coverage for <code>isGhes</code> by <a
href="https://github.com/jww3"><code>@​jww3</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li>
</ul>
<h2>v4.2.1</h2>
<ul>
<li>Check out other refs/* by commit if provided, fall back to ref by <a
href="https://github.com/orhantoy"><code>@​orhantoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li>
</ul>
<h2>v4.2.0</h2>
<ul>
<li>Add Ref and Commit outputs by <a
href="https://github.com/lucacome"><code>@​lucacome</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1180">actions/checkout#1180</a></li>
<li>Dependency updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>- <a
href="https://redirect.github.com/actions/checkout/pull/1777">actions/checkout#1777</a>,
<a
href="https://redirect.github.com/actions/checkout/pull/1872">actions/checkout#1872</a></li>
</ul>
<h2>v4.1.7</h2>
<ul>
<li>Bump the minor-npm-dependencies group across 1 directory with 4
updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1739">actions/checkout#1739</a></li>
<li>Bump actions/checkout from 3 to 4 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1697">actions/checkout#1697</a></li>
<li>Check out other refs/* by commit by <a
href="https://github.com/orhantoy"><code>@​orhantoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1774">actions/checkout#1774</a></li>
<li>Pin actions/checkout's own workflows to a known, good, stable
version. by <a href="https://github.com/jww3"><code>@​jww3</code></a> in
<a
href="https://redirect.github.com/actions/checkout/pull/1776">actions/checkout#1776</a></li>
</ul>
<h2>v4.1.6</h2>
<ul>
<li>Check platform to set archive extension appropriately by <a
href="https://github.com/cory-miller"><code>@​cory-miller</code></a> in
<a
href="https://redirect.github.com/actions/checkout/pull/1732">actions/checkout#1732</a></li>
</ul>
<h2>v4.1.5</h2>
<ul>
<li>Update NPM dependencies by <a
href="https://github.com/cory-miller"><code>@​cory-miller</code></a> in
<a
href="https://redirect.github.com/actions/checkout/pull/1703">actions/checkout#1703</a></li>
<li>Bump github/codeql-action from 2 to 3 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1694">actions/checkout#1694</a></li>
<li>Bump actions/setup-node from 1 to 4 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1696">actions/checkout#1696</a></li>
<li>Bump actions/upload-artifact from 2 to 4 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1695">actions/checkout#1695</a></li>
<li>README: Suggest <code>user.email</code> to be
<code>41898282+github-actions[bot]@users.noreply.github.com</code> by <a
href="https://github.com/cory-miller"><code>@​cory-miller</code></a> in
<a
href="https://redirect.github.com/actions/checkout/pull/1707">actions/checkout#1707</a></li>
</ul>
<h2>v4.1.4</h2>
<ul>
<li>Disable <code>extensions.worktreeConfig</code> when disabling
<code>sparse-checkout</code> by <a
href="https://github.com/jww3"><code>@​jww3</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1692">actions/checkout#1692</a></li>
<li>Add dependabot config by <a
href="https://github.com/cory-miller"><code>@​cory-miller</code></a> in
<a
href="https://redirect.github.com/actions/checkout/pull/1688">actions/checkout#1688</a></li>
<li>Bump the minor-actions-dependencies group with 2 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1693">actions/checkout#1693</a></li>
<li>Bump word-wrap from 1.2.3 to 1.2.5 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1643">actions/checkout#1643</a></li>
</ul>
<h2>v4.1.3</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="08c6903cd8"><code>08c6903</code></a>
Prepare v5.0.0 release (<a
href="https://redirect.github.com/actions/checkout/issues/2238">#2238</a>)</li>
<li><a
href="9f265659d3"><code>9f26565</code></a>
Update actions checkout to use node 24 (<a
href="https://redirect.github.com/actions/checkout/issues/2226">#2226</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/checkout/compare/v4.3.0...08c6903cd8c0fde910a37f88322edcfb5dd907a8">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/checkout&package-manager=github_actions&previous-version=4.3.0&new-version=5.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-17 08:16:07 +00:00
Carlos Alexandro Becker
058b35866c ci: pin all actions (#6092)
this pins all GitHub actions using their respective hashes.

Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-17 01:32:51 -03:00
Carlos Alexandro Becker
cc52cbf63f ci: add moderator (#6091)
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-17 00:54:05 -03:00
Carlos Alexandro Becker
5d46c964ad ci(sec): improve codeql (#6090)
<!--

Hi, thanks for contributing!

Please make sure you read our CONTRIBUTING guide.

Also, add tests and the respective documentation changes as well.

-->


<!-- If applied, this commit will... -->

...

<!-- Why is this change being made? -->

...

<!-- # Provide links to any relevant tickets, URLs or other resources
-->

...

Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-16 14:32:15 -03:00
Carlos Alexandro Becker
63d810557f fix(dockers/v2): properly support pywheel (#6089)
it was not working properly.

Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2025-09-16 10:57:40 -03:00
dependabot[bot]
9327f94e3d chore(deps): bump mkdocs-material from 9.6.19 to 9.6.20 in /www (#6088)
Bumps [mkdocs-material](https://github.com/squidfunk/mkdocs-material)
from 9.6.19 to 9.6.20.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/squidfunk/mkdocs-material/releases">mkdocs-material's
releases</a>.</em></p>
<blockquote>
<h2>mkdocs-material-9.6.20</h2>
<ul>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8446">#8446</a>:
Deprecation warning as of Python 3.14 in Emoji extension</li>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8440">#8440</a>:
<code>&amp;</code> character not escaped in search highlighting</li>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8439">#8439</a>:
FontAwesome icons color not set in social cards (regression)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG">mkdocs-material's
changelog</a>.</em></p>
<blockquote>
<p>mkdocs-material-9.6.20 (2025-09-05)</p>
<ul>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8446">#8446</a>:
Deprecation warning as of Python 3.14 in Emoji extension</li>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8440">#8440</a>:
<code>&amp;</code> character not escaped in search highlighting</li>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8439">#8439</a>:
FontAwesome icons color not set in social cards (regression)</li>
</ul>
<p>mkdocs-material-9.6.19 (2025-09-07)</p>
<ul>
<li>Added support for Python 3.14</li>
<li>Updated Bahasa Malaysia translations</li>
</ul>
<p>mkdocs-material-9.6.18 (2025-08-22)</p>
<ul>
<li>Updated Azerbaijani translations</li>
<li>Fixed last compat issues with [minijinja], now 100% compatible</li>
</ul>
<p>mkdocs-material-9.6.17 (2025-08-15)</p>
<ul>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8396">#8396</a>:
Videos do not autoplay when inside a content tab</li>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8394">#8394</a>:
Stroke width not effective in Mermaid.js diagrams</li>
<li>Fixed disappearing version selector when hiding page title</li>
</ul>
<p>mkdocs-material-9.6.16 (2025-07-26)</p>
<ul>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8349">#8349</a>:
Info plugin doesn't correctly detect virtualenv in some cases</li>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8334">#8334</a>:
Find-in-page detects matches in hidden search result list</li>
</ul>
<p>mkdocs-material-9.6.15 (2025-07-01)</p>
<ul>
<li>Updated Mongolian translations</li>
<li>Improved semantic markup of &quot;edit this page&quot; button</li>
<li>Improved info plugin virtual environment resolution</li>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8291">#8291</a>:
Large font size setting throws of breakpoints in JavaScript</li>
</ul>
<p>mkdocs-material-9.6.14 (2025-05-13)</p>
<ul>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8215">#8215</a>:
Social plugin crashes when CairoSVG is updated to 2.8</li>
</ul>
<p>mkdocs-material-9.6.13 (2025-05-10)</p>
<ul>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8204">#8204</a>:
Annotations showing list markers in print view</li>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8153">#8153</a>:
Improve style of cardinality symbols in Mermaid.js ER diagrams</li>
</ul>
<p>mkdocs-material-9.6.12 (2025-04-17)</p>
<ul>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8158">#8158</a>:
Flip footnote back reference icon for right-to-left languages</li>
</ul>
<p>mkdocs-material-9.6.11 (2025-04-01)</p>
<ul>
<li>Updated Docker image to latest Alpine Linux</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="f0b0b5931a"><code>f0b0b59</code></a>
Prepare 9.6.20 release</li>
<li><a
href="900981b6f8"><code>900981b</code></a>
Fixed deprecation warning as of Python 3.14 in Emoji extension</li>
<li><a
href="ed0026322f"><code>ed00263</code></a>
Documentation (<a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8443">#8443</a>)</li>
<li><a
href="a4f42bbfcd"><code>a4f42bb</code></a>
Updated Premium sponsors</li>
<li><a
href="63d7e746be"><code>63d7e74</code></a>
Fixed FontAwesome icons having fill attributes</li>
<li><a
href="ee678455e9"><code>ee67845</code></a>
Fixed &amp; not escaped in search highlighting</li>
<li>See full diff in <a
href="https://github.com/squidfunk/mkdocs-material/compare/9.6.19...9.6.20">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=mkdocs-material&package-manager=pip&previous-version=9.6.19&new-version=9.6.20)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-16 10:44:06 -03:00