osv-scanner
osv-scanner copied to clipboard
Dependency Dashboard
This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
View this repository on the Mend.io Web Portal.
Awaiting Schedule
The following updates are awaiting their schedule. To get an update now, click on a checkbox below.
- [ ] fix(deps): update osv-scanner minor (
github.com/ianlancetaylor/demangle,osv.dev/bindings/go) - [ ] chore(deps): update github/codeql-action action to v4.31.3
- [ ] chore(deps): lock file maintenance
Ignored or Blocked
The following updates are blocked by an existing closed PR. To recreate the PR, click on a checkbox below.
- [ ] fix(deps): update module github.com/charmbracelet/lipgloss to v2
Detected dependencies
bundler
docs/Gemfile
github-pages "~> 232"jekyll-feed "~> 0.15"tzinfo ">= 1", "< 3"wdm "~> 0.2.0"http_parser.rb "~> 0.8.0"webrick "~> 1.7"
dockerfile
action.dockerfile
golang 1.25.4-alpine3.21@sha256:3289aac2aac769e031d644313d094dbda745f28af81cd7a94137e73eefd58b33alpine 3.22@sha256:4b7ce07002c69e8f3d704a9c5d6fd3053be500b7f1c69fc0d80990c2ad8dd412Dockerfile
golang 1.25.4-alpine3.21@sha256:3289aac2aac769e031d644313d094dbda745f28af81cd7a94137e73eefd58b33alpine 3.22@sha256:4b7ce07002c69e8f3d704a9c5d6fd3053be500b7f1c69fc0d80990c2ad8dd412docs/docs.Dockerfile
ruby 3goreleaser-action.dockerfile
golang 1.25.4-alpine3.21@sha256:3289aac2aac769e031d644313d094dbda745f28af81cd7a94137e73eefd58b33goreleaser.dockerfile
golang 1.25.4-alpine3.21@sha256:3289aac2aac769e031d644313d094dbda745f28af81cd7a94137e73eefd58b33
github-actions
.github/workflows/checks.yml
actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/setup-go v6.0.0@44694675825211faa026b3c33043df3e48a5fa00actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/setup-go v6.0.0@44694675825211faa026b3c33043df3e48a5fa00actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/upload-artifact v5.0.0@330a01c490aca151604b8cf639adc76d48f6c5d4actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/download-artifact v6.0.0@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53actions/setup-go v6.0.0@44694675825211faa026b3c33043df3e48a5fa00actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/setup-go v6.0.0@44694675825211faa026b3c33043df3e48a5fa00docker/setup-qemu-action v3@c7c53464625b32c7a7e944ae62b3e17d2b600130docker/setup-buildx-action v3@e468171a9de216ec08956ac3ada2f0791b6bd435goreleaser/goreleaser-action v6.4.0@e435ccd777264be153ace6237001ef4d979d3a7a.github/workflows/codeql-analysis.yml
actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/setup-go v6.0.0@44694675825211faa026b3c33043df3e48a5fa00github/codeql-action v4.31.2@0499de31b99561a6d14a36a5f662c2a54f91beeegithub/codeql-action v4.31.2@0499de31b99561a6d14a36a5f662c2a54f91beeegithub/codeql-action v4.31.2@0499de31b99561a6d14a36a5f662c2a54f91beee.github/workflows/dependencies.yml
actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/setup-go v6.0.0@44694675825211faa026b3c33043df3e48a5fa00peter-evans/create-pull-request v7.0.8@271a8d0340265f705b14b6d32b9829c1cb33d45e.github/workflows/goreleaser-nightly.yml
actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/setup-go v6.0.0@44694675825211faa026b3c33043df3e48a5fa00docker/setup-qemu-action v3@c7c53464625b32c7a7e944ae62b3e17d2b600130docker/setup-buildx-action v3@e468171a9de216ec08956ac3ada2f0791b6bd435docker/login-action v3@5e57cd118135c172c3672efd75eb46360885c0efgoreleaser/goreleaser-action v6.4.0@e435ccd777264be153ace6237001ef4d979d3a7a.github/workflows/goreleaser.yml
actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/setup-go v6.0.0@44694675825211faa026b3c33043df3e48a5fa00docker/setup-qemu-action v3@c7c53464625b32c7a7e944ae62b3e17d2b600130docker/setup-buildx-action v3@e468171a9de216ec08956ac3ada2f0791b6bd435docker/login-action v3@5e57cd118135c172c3672efd75eb46360885c0efgoreleaser/goreleaser-action v6.4.0@e435ccd777264be153ace6237001ef4d979d3a7aslsa-framework/slsa-github-generator v2.1.0.github/workflows/links.yml
actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8tcort/github-action-markdown-link-check v1.1.1@f3d33029dca1c4a24b87e2df648f9f4604ef6533.github/workflows/lint-action/action.yml
golangci/golangci-lint-action v9.0.0@0a35821d5c230e903fcfe077583637dea1b27b47.github/workflows/osv-scanner-reusable-pr.yml
.github/workflows/osv-scanner-reusable.yml
.github/workflows/osv-scanner-unified-action.yml
.github/workflows/pr-check.yml
amannn/action-semantic-pull-request v6.1.1@48f256284bd46cdaab1048c3721360e808335d50.github/workflows/prerelease-check.yml
actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8tcort/github-action-markdown-link-check v1.1.1@f3d33029dca1c4a24b87e2df648f9f4604ef6533actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/setup-go v6.0.0@44694675825211faa026b3c33043df3e48a5fa00actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/setup-go v6.0.0@44694675825211faa026b3c33043df3e48a5fa00actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/upload-artifact v5.0.0@330a01c490aca151604b8cf639adc76d48f6c5d4actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/download-artifact v6.0.0@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53actions/setup-go v6.0.0@44694675825211faa026b3c33043df3e48a5fa00actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/setup-go v6.0.0@44694675825211faa026b3c33043df3e48a5fa00.github/workflows/renovate-validator.yml
actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/setup-node v6.0.0@2028fbc5c25fe9cf00d9f06a71cc4710d4507903.github/workflows/scorecards.yml
actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8ossf/scorecard-action v2.4.3@4eaacf0543bb3f2c246792bd56e8cdeffafb205aactions/upload-artifact v5.0.0@330a01c490aca151604b8cf639adc76d48f6c5d4github/codeql-action v4.31.2@0499de31b99561a6d14a36a5f662c2a54f91beee.github/workflows/snapshots.yml
actions/checkout v5.0.0@08c6903cd8c0fde910a37f88322edcfb5dd907a8actions/setup-go v6.0.0@44694675825211faa026b3c33043df3e48a5fa00peter-evans/create-pull-request v7.0.8@271a8d0340265f705b14b6d32b9829c1cb33d45e.github/workflows/staleness.yml
actions/stale v10.1.0@5f858e3efba33a5ca4407a664cc011ad407f2008.github/workflows/test-action/action.yml
codecov/codecov-action v5.5.1@5a1091511ad55cbe89839c7260b706298ca349f7
gomod
go.mod
go 1.25.4deps.dev/api/v3 v3.0.0-20251104021112-20ad94767ddf@20ad94767ddfdeps.dev/api/v3alpha v0.0.0-20251104021112-20ad94767ddf@20ad94767ddfdeps.dev/util/maven v0.0.0-20251104021112-20ad94767ddf@20ad94767ddfdeps.dev/util/resolve v0.0.0-20251104021112-20ad94767ddf@20ad94767ddfdeps.dev/util/semver v0.0.0-20251104021112-20ad94767ddf@20ad94767ddfgithub.com/BurntSushi/toml v1.5.0github.com/CycloneDX/cyclonedx-go v0.9.3github.com/charmbracelet/bubbles v0.21.0github.com/charmbracelet/bubbletea v1.3.10github.com/charmbracelet/glamour v0.10.0github.com/charmbracelet/lipgloss v1.1.1-0.20250404203927-76690c660834@76690c660834github.com/gkampitakis/go-snaps v0.5.15github.com/go-git/go-git/v5 v5.16.3github.com/goccy/go-yaml v1.18.0github.com/google/go-cmp v0.7.0github.com/ianlancetaylor/demangle v0.0.0-20250628045327-2d64ad6b7ec5@2d64ad6b7ec5github.com/jedib0t/go-pretty/v6 v6.7.1github.com/modelcontextprotocol/go-sdk v1.1.0github.com/muesli/reflow v0.3.0github.com/opencontainers/go-digest v1.0.0github.com/ossf/osv-schema/bindings/go v0.0.0-20251112210320-9fb6c8870ac1@9fb6c8870ac1github.com/owenrumney/go-sarif/v3 v3.3.0github.com/package-url/packageurl-go v0.1.3github.com/pandatix/go-cvss v0.6.2github.com/tidwall/gjson v1.18.0github.com/tidwall/pretty v1.2.1github.com/tidwall/sjson v1.2.5github.com/urfave/cli/v3 v3.6.0golang.org/x/net v0.47.0golang.org/x/sync v0.18.0golang.org/x/term v0.37.0google.golang.org/grpc v1.76.0google.golang.org/protobuf v1.36.10gopkg.in/ini.v1 v1.67.0gopkg.in/yaml.v3 v3.0.1osv.dev/bindings/go v0.0.0-20251113023009-27a98cf5463b@27a98cf5463b
- [ ] Check this box to trigger a request for Renovate to run again on this repository