fix(mise): update mise tools (patch) #572
No reviewers
Labels
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
webgrip/homelab-cluster!572
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "renovate/patch-mise-tools"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
4.2.3→4.2.44.0.11→4.0.121.16.6→1.16.70.12.3→0.12.4📦 Grouped update: confirm the group is operationally coherent before merging.
Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.
Releasedis the upstream publish time.—means this datasource reports no release timestamp — normal for ghcr.io, quay.io and private/proxy registries — sominimumReleaseAgecannot hold the update back and it is eligible as soon as checks pass. A real date means the soak is enforced: add this update type'sminimumReleaseAgetoReleasedto get the eligibility moment.Homelab soak tiers: patch 1d, minor 3d, digest/vulnerability 0 days; platform-critical minors 7d + dashboard approval; talos/** always manual. A green PR merges on the first hourly Renovate run after its soak expires.
Release Notes
helm/helm (aqua:helm/helm)
v4.2.4: Helm v4.2.4Compare Source
Helm v4.2.4 is a patch release. Users are encouraged to upgrade for the best experience.
The community keeps growing, and we'd love to see you there!
Notable Changes
Installation and Upgrading
Download Helm v4.2.4. The common platform binaries are here:
This release was signed with
208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155and can be found at @scottrigby keybase account. Please use the attached signatures for verifying this release usinggpg.The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash.What's Next
Changelog
3900f43(Scott Rigby)f7c6e8f(Terry Howe)035a2c3(dependabot[bot])f76a5f4(Gates Wang)5a7c6c7(Will Noble)2281848(Will Noble)2c979a1(Jakub Jaruszewski)2bd2c66(kimsungmin1)183a540(kimsm28)08d8da1(kimsm28)9655b5a(kimsm28)430dfac(Terry Howe)9569605(kimsm28)63f2b68(kimsm28)f7488c0(kimsm28)8fe78fb(kimsm28)d0670d2(kimsm28)804256e(kimsungmin1)d79bceb(kimsungmin1)d34fcd9(kimsungmin1)9fbd190(kimsungmin1)9275661(kimsungmin1)fef91f3(kimsungmin1)e89ce68(Mohammad Abdolirad)ff1ac83(Sebastien Tardif)4b4dedb(Sebastien Tardif)7c80103(Sebastien Tardif)ecc9cd2(Jeaeun Kim)f6211ba(Jeaeun Kim)3507ea5(Jeaeun Kim)helm template --debugwith--show-only211ffae(Jeaeun Kim)51a9837(Matheus Pimenta)83a8b70(Matheus Pimenta)Full Changelog: https://github.com/helm/helm/compare/v4.2.3...v4.2.4
kubescape/kubescape (aqua:kubescape/kubescape)
v4.0.12Compare Source
Changelog
6849abbCel engine docs (#2756)0b25d70Guard against unresolvable group/version in resource handler (#2609)68b6a71Increase test coverage for GetWriter and LogOutputFile functions (#2586)2a2253aPropagate printer and command errors (#2908)9e98840Recover from panics in readJsonFile (#2604)95a70f2Refactor: remove Getters and PolicyIdentifier from ScanInfo (#2768)e79237cRefactor: use distribution/reference for image parsing (#2776)61a8054Remove Helm binary dependency from kustomize tests (#2926)2763c21Remove stale "Add score" TODO fromprocessorhandlerutils.go(#2924)957998bRemoved dead code in urlloader and urlloader_test and add some test c… (#2590)4cc055eSecurity/batch dependency fixes 2 (#2897)5b4f1a6Support scoped registry auth for image scans (#2696)2088a8cTest case added for validation (#2585)fad6e64Unify scan stdin input handling (#2875)dd98504[fix] : non-deterministic namespace bucketing caused by mid-scan resource count mutation (#2587)6561a47[fix] : streaming collector dropping host-sensor fallback, silently passing controls it never evaluated (#2797)1abd9d8anonymizer: pin and document the intentional cross-prefix hash-suffix sharing (was: hash prefix+value) (#2687)6bab3decautils: test: cover test for readYamlFile and readJsonFile (#2526)1b93a71chore(ci): update pinned GitHub Actions off deprecated Node 20 releases (#2973)d23abbfchore(deps): tidy go.mod for backoff import (#3022)bb83cd6chore(printer): remove the unused v1 PrometheusPrinter (#2985)a6a0898chore: evaluate rego with RegoV1 (drop v0 compat shim) (#2359)ca0d57bchore: remove dead Float16ToInt function (#2643)4a1d822chore: remove dead code loadConfigFromData (#2948)4363b2bchore: remove deprecated SA2WLIDmap from RBAC utils (#2957)64915fechore: remove orphaned firstNonEmpty doc comment (#2945)bbf9183ci: run unit tests on every PR, not just tag pushes (#2606)2e0d1a9enhancement: propagate context.Context in getter interfaces (#2775)39752e1feat : add DELETE /v1/scan to cancel an in-flight scan (#2562)9a91904feat(cautils): add ParseDurationEnvVar (#2779)b3192bcfeat(context): propagate context through tenant config initialization and Kubernetes API calls (#2739)881ba33feat(core): implement concurrent and deduplicated image scan pipeline (KS-ADV-02) (#2759)b3f1542feat(csv): add remediation path evidence columns to CSV scan output (#2900)77aca1efeat(exceptions): prefer cloud exceptions over CRD (#2317)5c6fb28feat(hostsensor): optimize query with paging, rate limits, and cache (#2864)53899b7feat(html): show current field values in evidence paths (#3032)5bdca12feat(imagescan): support scanning local offline tarball images (#2995)29aefd1feat(mcp): add headless framework security scanner tool (#2528)1d2709efeat(mcp): add local IaC scanner tool (#2545)b5bf09afeat(mcpserver): add scan_container_image tool for on-demand vulnerability scanning (KS-INT-03) (#2708)dbd32e8feat(patch): support all image scan output formats (#2910)cbf3818feat(printer): add markdown output format (#3025)de8d7a1feat(printer): surface current field value alongside failed paths in scan output (#2882)531ab67feat(resourcesprioritization): support configurable workload kinds and dynamic pod template spec detection (#2720)eed57f0feat(scan): add --api-version flag to workload scan command (#2829)1201b17feat(scan): add --label-selector flag to filter collected resources (#2830)0513520feat(scan): support parsing apiVersion in workload identifier (#2581)830edecfeat(streaming): Add resource streaming for large clusters to reduce memory usage (#2645)1225145feat(version): add --output json flag (#2793)0a8dacffeat: Automated In-Cluster Private Registry Credential Resolver (#2832)164d228feat: add --only-fixable flag to gate scan image severity threshold on fix availability (#2891)8a49128feat: add Azure AKS support to ListEntitiesForPolicies resource mapping (#3012)9c9c839feat: add CSV output format printer for scan results (#2743)9b69c84feat: add YAML output format to kubescape list (#2852)03d0f73feat: add configurable config view output formats (#2987)64b54e2feat: add csv output for list command (#2989)1431870feat: add fallback support for OpenShift external registry routes (#2576)f73b3a7feat: give CEL findings the remediation paths their Rego equivalents carry (#2533)2121daafeat: implement Runtime Profile Drift Detection and Remediation (KS-ADV-01) (#2803)c22523dfeat: introduce Container Image Vulnerability (CIV) Adaptor for Azure Container Registry (#2778)d5cd5e9feat: introduce native GCP Artifact Registry vulnerability adaptor (Phase 2) (#2801)cc83086feat: scan kubernetes_manifest resources in Terraform files (#2947)b1071cefeat: scan typed kubernetes_* resources in Terraform files (#719) (#3019)d3e90b7feat: spend one CEL cost budget per policy the way admission does (#2560)053ca1dfeat: support all output formats for image scans (#2786)f6ff896feat: support yaml as an output format (#2625)9387a73fix(anonymizer): replace broken type assertions with IWorkload-based container deserialization (#2991)5afb9c3fix(cache): publish policy files atomically (#2878)2ff4225fix(cautils): add warning log for invalid useUntilKubescapeVersion semver (#2703)715efa3fix(cautils): avoid standalone renders of owned Helm dependencies (#2849)3cb0df0fix(cautils): clone trailing remote inputs for local-first scans (#2933)a10dceafix(cautils): expand offline Kubernetes list envelopes (#2820)5951348fix(cautils): propagate marshal error in updateConfigFile (#2766)88d24b7fix(cautils): record individual formats in scan metadata (#2932)4f4a861fix(cautils): remove dead nil-check in setHeaders (#2682)dfc8387fix(cautils): report the bound port from GetPortForwardLocalhost (#2761)a48e3fffix(cautils): resolve git metadata when scanning from a linked worktree (#2721)b9c2fc7fix(cautils): return error when worktree root cannot be resolved in NewLocalGitRepository (#2651)0ee5c13fix(cautils): return non-NotFound errors from legacy ConfigMap lookup (#3018)8f54073fix(cautils): sort copies in StringSlicesAreEqual to avoid mutating caller slices (#2750)b45925dfix(cautils): stop LocalGitRepository exposing a nil-embedded panic to callers (#2722)cbc5d22fix(cautils): stop Policies.Set from mutating the caller's frameworks slice (#2681)0f7e72cfix(cautils): stop ReportV2ToV1 from mutating the caller's shared resources (#2837)9f55d1efix(cautils): stop conflating insecureSkipTLS with plainHTTP in helm registry client (#2690)45362e2fix(cautils): synchronize access to global KSCloudAPIConnector to resolve data race (#2767)fab61c5fix(cautils): use filesystem check instead of .json string heuristic in setUseArtifactsFrom (#3009)529e872fix(cel): guard optional field paths so valid workloads are evaluated, not skipped (#2535)111444efix(cel): resolve namespaceObject from collected namespaces and honor admission scoping offline (#2713)b721999fix(cel): select remediation paths by workload kind (#2564)9a26b8efix(cel): use messageExpression for CEL message bodies, verify bundleControlIDs both ways (#2610)884cd0afix(cmd): close temporary file handle after streaming stdin in scan commands (#2799)247caf5fix(config): preserve higher-priority tenant settings (#2876)293140dfix(core): add timeout to HTTP client in OperatorAdapter to prevent connection hang (#2827)af7bf70fix(core): align scan attribution with explicit kubeconfig (#2841)0324553fix(core): allow operator scan with multiple app=operator pods (#2593)1bd379efix(core): cancel streaming producer context on early evaluation error (#2814) (#2815)fa48eecfix(core): correct grammar in download empty-response errors (#2642)2816cd1fix(core): correct unknown command error message in List() (#2621)aa46aeafix(core): detect multipart SBOM output collisions (#2930)10e16a2fix(core): download --output bare .json path no longer falls back to ~/.kubescape (#2818)1cf701ffix(core): escape inner quotes in FixPathToValidYamlExpression string values (#2670)0408fe0fix(core): expand ScanAll frameworks before resolving cache paths (#2792)8db604afix(core): ignore unusable image pull secret credentials (#2927)8b973a8fix(core): limit ScanAll expansion to framework scans and dedupe UseFrom (#2795)f212468fix(core): log swallowed errors when loading cached/cluster config (#2736)06aec0cfix(core): make ProgressHandler.Stop() complete the progress bar (#2738)1be5e2bfix(core): parse digest-pinned image references correctly for exceptions (#2686)a102e7bfix(core): preserve non-zero risk score rounding in HTML report (#2727) (#2733)1e24a1efix(core): prevent sub-100 compliance scores formatting as 100.00 (#2728) (#2740)414fce3fix(core): recurse convertYamlToJson into map[string]any values (#2834)4df639dfix(core): remove racy re-check of global cluster connection state (#2617)0e6ea57fix(core): reset HostSensorEnabled when explicit host scanner fails to init (#2819)ebb29b1fix(core): return cluster connection failures from Scan instead of terminating (#2788)5011ad2fix(core): return error when io.ReadAll fails in NewFixHandler (#2706)0767f52fix(core): shut down the exception event broadcaster after each scan (#2762)2cda81afix(core): skip image scanner initialization when no images (#2845)e8b95cafix(core): stop nilling global os.Stdout/os.Stderr during copa patch (#2638)6aea45cfix(core): stop port-forward when startup fails to avoid goroutine leak (#2835)d9061d8fix(core): treat closed/non-interactive stdin as refusal in userConfirmed to prevent CPU spin (#2712)d07136afix(core): use restrictive permissions for created output directories (#2648)40cdc51fix(core): wire --address flag into buildkit client options for patch (#2735)9b1011ffix(coverage): sort partial GVR pull diagnostics (#2934)982d37dfix(csv): guarantee a flush attempt on every ActionPrint exit path (#2981)f4a102efix(diff): reject invalid scan reports (#2877)b069dfffix(diff): sort ChangeSet buckets so diff output is reproducible (#2734)89e13e9fix(downloader): add 10-minute timeout to background context to prevent hangs (#3014)f16991afix(downloader): add bounded retry with backoff for artifact downloads (#3016)bb653fcfix(downloader): aggregate errors in download loop to catch swallowed failures (#3011)2f506d2fix(downloader): exit non-zero on download failures (#2969)f737503fix(downloader): exit non-zero when an artifact download fails (#2918)c83e430fix(fixhandler): guard nil resource lookup and off-by-one slice bound (#2597)8ceb00cfix(fixhandler): preserve accepted base path spelling (#2678)ba25377fix(fixhandler): prevent path traversal when resolving resource paths (#2637)4de213cfix(fixhandler): quote NaN and Inf fix values so yq expressions parse (#2714)adcce93fix(fixhandler): skip document node when resolving a line to replace (#2896)9eb525dfix(git): make remote workspaces concurrency safe (#2548)cfea0f3fix(git): support detached HEAD repository metadata (#2567)7f266cefix(hostsensor): avoid mutating shared Kubernetes config (#2938)354d693fix(hostsensor): key cache by cluster identity and gate it behind opt-in TTL (#2914)9d6122ffix(http): bound scan admission and request bodies (#2547)f576421fix(httphandler): advertise Allow: GET on Metrics 405 response (#2647)fcc38a7fix(httphandler): harden metrics query handling (#2635)63c1e55fix(httphandler): make pprof debug server opt-in and loopback-only (#2639)7fbd475fix(httphandler): preserve non-JSON HTTP scan results (#2936)a1dd01ffix(httphandler): retain scan ID in synchronous responses (#2931)1933525fix(httphandler): stop sending wrong HTTP status from Status handler (#2649)ccfdcfffix(imagescan): close the previous gRPC client on repeated GCP Login calls (#2982)f0af65dfix(imagescan): prevent gRPC connection leak in GCP adaptor (#2954)7ab5cdafix(imagescan): properly reject unsupported token credentials in cloud adaptors (#2943)a7105f9fix(imagescan): scope pull secrets to cluster scans (#2964)1c848e5fix(imagescan): standardize partial-failure handling across cloud adaptors (#2941)2de9215fix(imagescan): support enhanced ECR scan findings (#2966)5a1933cfix(junit): report compliance scores in test suites (#2565)893152bfix(listener): fail fast when server port is busy (#2636)68baa89fix(locationresolver): add context to yaml evaluation errors (#2615)f8e1522fix(locationresolver): guard nil candidateNodes.Back() (#2583)2b37fa2fix(locationresolver): split fix paths on the first '=' rather than the last (#2850)9be4cfcfix(mcp): graceful error handling for legacy MCP tools (#2748)0b285eefix(mcpserver): handle malformed tool arguments safely (#2566)ba0ef22fix(mcpserver): reject empty resource URI segments (#2616)a2cad42fix(mcpserver): retry client init instead of caching first error (#2629)e5fde5efix(opaprocessor): keep resource snapshot stable during rules (#2667)dd5c4abfix(opaprocessor): register OPA builtins once per process, not once per scan (#2624)7c2f0befix(opaprocessor): resolve namespaceObject for CEL admission evaluation (#2603)2ed1337fix(opaprocessor): scrub stringData field in Secret resources (#2757)5bb04b6fix(operator): make GetRequestPayload side-effect-free, default --frameworks to all at the flag (#3006)2e16774fix(operator): propagate --namespace flag to scan subcommands- #2 (#2591)ed8a7b2fix(operator): resolve cluster name after context selection (#2939)d5f1047fix(operator): scope examples to the scan subcommand (#2915)7eb555cfix(output): drop truncated image label from scan hints (#2568)bfd14eefix(patch): surface package install failures instead of exporting an empty image (#2574)3b0df5afix(paths): anchor reported paths to the git root when git metadata is unusable (#2600)ffbdcb6fix(policyhandler): bound registry growth with idle eviction (#2909)d5d0fbefix(policyhandler): reset the PolicyHandler singleton when clusterName changes (#2742)70465c3fix(prerequisites): exit non-zero when cluster data collection fails (#2997)3b79e42fix(printer): avoid perfect score rounding (#2665)1852bdffix(printer): clean temp dir in fallback tests (#2634)d63fe81fix(printer): handle GetContainers errors when resolving container names (#2539)a70e74cfix(printer): keep PDF footnote markers consistent between table and legend (#3004)4b2af05fix(printer): keep yaml compliance score below perfect (#2726)8145c4dfix(printer): label the report with the context the scan actually used (#2898)9480989fix(printer): parse SARIF doc index on the last colon, not the second field (#2685)7f7a839fix(printer): prevent nil-pointer panics and report truncation when resources are missing (#2700)70c147ffix(printer): prevent silent data loss on CSV write errors (#2959)90041c4fix(printer): separate name and version in package score map key (#2692)5f14bbefix(printer): write leading newline to the configured output writer (#2595)3a20a2dfix(prometheus): group metric samples by family in the exposition output (#3021)ad8ed8afix(prometheus): report compliance scores in gauges (#2580)661a008fix(reportcrypto): stop rewriting plaintext values during decryption (#2998)3ce2e75fix(resourcehandler): check HTTP status code in httpGet (dead-code hardening) (#2674)fa6daa5fix(resourcehandler): classify missing LIST resources using typed Kubernetes errors (#2903)a9b8ee3fix(resourcehandler): count returned items in cluster size estimate (#2886)e55c8cdfix(resourcehandler): discover nested Kustomize directories in broad scans (#2888)fba88cafix(resourcehandler): honor discovered scope when streaming resources (#2821)5c11f2dfix(resourcehandler): let Kustomize own referenced Helm charts (#2855)cf467d6fix(resourcehandler): log warnings on directory discovery errors in LoadResourcesFromNestedKustomizeDirectories (#2906)fbe6a02fix(resourcehandler): propagate file stream cancellation (#2935)080d7eafix(resourcehandler): propagate streaming LIST failures (#2771)6fa40d3fix(resourcehandler): render nested Kustomize configurations (#2860)935fd08fix(resourcehandler): repair NewOPASessionObj call broken by merge (#2783)67644bcfix(resourcehandler): resolve offline resources from manifests (#2752)c94cf66fix(resourcehandler): scan Agent Sandbox and Substrate CRDs consistently (#2618)1dd1a16fix(results): preserve enrichment in programmatic and HTTP output (#2862)caf9bfffix(resultshandling): handle unscored score sentinel in summary table compliance column (#2791)675fa7afix(resultshandling): make finalized report ordering deterministic (#2773)421a3a2fix(sarif): avoid image output stdout deadlock (#2967)1e6f191fix(sarif): guard delta walk against out-of-range line and segment indexes (#2865)82fd592fix(sarif): render and patch image scan SARIF in memory instead of reopening the writer (#2984)a4d84f9fix(sarif): use rune count for multi-byte line length in fix regions (#2552)a01225afix(scan): accept local inputs for workload scans (#2746)a3b91fcfix(scan): dynamically build supported formats error message (#2870)2d455b8fix(scan): enforce image thresholds in explicit subcommands (#2929)8ff9e3afix(scan): honor only-fixable in combined image scans (#2928)70e1b1afix(scan): remove unreachable code branch in scan command RunE (#3040)37c6a97fix(scan): return errors instead of using logger.Fatal (#2857)c9f1b71fix(scan): surface manifest loading failures (#2546)faaa417fix(scan): validate threshold ranges in scan control command (#2916)d0b6c87fix(shared): prioritize auth conflict error over missing password (#3042)d4c60d9fix(storage): propagate workload scan update errors (#2937)adf94affix(streaming): initialize cluster metadata before policy planning (#2956)f53ed2cfix(streaming): restore host-sensor InfoMap and namespace resource counting in streaming collector (#2808) (#2809)72bf965fix(tableprinter): truncate control/resource names on a rune boundary (#2676)04b0dcdfix(vap): bound deploy-library downloads with a default timeout (#3001)2ee6fa2fix: (#2631)4badc2afix: add epsilon tolerance to Float32ToIntFloor for float32 precision loss (#2669)816cd7bfix: change break to continue in helm workloads loader (#2605)ec9397ffix: correct grammar in download empty-response errors (#2644)66d0319fix: correct typos in variable names and filenames (#2744)871dbd0fix: count returned items in cluster-size estimates (#2847)16cc4e2fix: don't crash or auto-submit when no backend is configured (#2556)f9fa233fix: enforce image severity threshold on combined scans (#2894)2f4ee30fix: include initContainers and ephemeralContainers in image scan (#2979) (#2980)1f020a5fix: mark CRD-only controls not evaluated after partial discovery failure (#2839)6153bbffix: populate ClusterName in JSON reports (#2866)4c0cf77fix: register deprecated flags to prevent unknown flag errors (#2868)d21b1fafix: remove double space in download control error message (#2664)82a6d27fix: replace control merge loops with assignment to clear stale controls (#3049) (#3051)699e25dfix: resolve CRD exception deduplication dropping non-overlapping policies (#2805)b786bf7fix: resolve HTTPPost connection leak on error by draining response body (#2807)20f0e65fix: resolve data race in display spinner (#2975) (#2978)6730f78fix: resolve review feedback for CycloneDX/SPDX SBOM output formats (#2883)95c2e8bfix: return error when control inputs are nil or empty (#2601)87824e8fix: return values for IKubescape List and Download (#2794)f15bf09fix: use %w for standard error wrapping (#2823)feb5309fix: wrap DEK error, enforce image severity thresholds, and refactor error formats (#2902)2f0d55bperf(opaprocessor): index a scope's resources once instead of per rule (#2976)08b8bdeperf(sarif): cache per-file work when collecting fixes and locations (#2921)191d3darefactor(cautils): simplify StringSlicesAreEqual and assert its result in the non-mutation test (#2755)95055a8refactor(core): expose cluster connection failure as a sentinel error (#2810)15896c1refactor(core): simplify grouping logic and add test coverage (#2679)d5318c3refactor(policyhandler): make PolicyHandler stateless per request to eliminate scanMu blocking (#2899)0ec3037refactor(resourcehandler): use canonical path containment for kustomize exclusion (#2907)814a2b7refactor(scan): deduplicate flag validation boilerplate (#3047)176fd42refactor(scan): remove deprecated flags and update documentation (#2608)4faa7d2refactor: remove dead count variable and simplify insertControls (#2753)469969fremove duplicate tests3b1ba0eremove unused PostRun hook from scan command (#2661)1afd537security: batch dependency vulnerability fixes (Batch 1 + 2) (#2895)c61755dtest(cautils): cover tenant configuration lifecycle (#2550)5b6bf88test(cautils): fix path-quoting and permission-bit assumptions on Windows (#2952)658f1bftest(cautils): remove Helm binary dependency in kustomize tests (#2983)9a47830test(cautils): resolve symlinks on temp dirs used as expected paths (#2977)3329157test(cautils): use t.Setenv so env vars are restored between runs (#2785)02f71f7test(core): cover Fix() orchestration end to end (#2614)e8f6bc9test(core): cover NewOperatorAdapter, httpPostOperatorScanRequest, OperatorScan (#2613)a0a1ac5test(core): expand image patch helper coverage (#2543)32f7896test(hostsensorutils): cover CRD resource collection and CollectResources (#2588)1bfc940test(junit): add integration test for compliance score through ActionPrint (#2572)9780175test(mcpserver): cover tool and resource dispatch (#2541)4416603test(printer): add coverage for JSON printer v1 ActionPrint, Score, CloseWriter (#2558)950c5dbtest(printer): cover pretty-printer behavior (#2549)aafee26test(printer): keep pretty writer outputs in tempdir (#2718)e9f11a4test(reportcrypto): cover container metadata decryption (#2542)dc6ac26test(resourcehandler): cover Kubernetes resource lookup (#2551)795f868test(scan): explicitly test file-path without chart-path (#3044)c9372e0test-core-download-coverage (#2571)99a66cftest-httphandler-listener-setup-coverage (#2570)Released by GoReleaser.
pypa/pipx (pipx)
v1.16.7Compare Source
What's Changed
New Contributors
Full Changelog: https://github.com/pypa/pipx/compare/1.16.6...1.16.7
astral-sh/uv (uv)
v0.12.4Compare Source
Released on 2026-08-13.
Enhancements
Requires-Python: >= 3.5.*(#21012)Preview features
uv check --no-install-projectand respectUV_NO_INSTALL_PROJECTto install dependencies without building or installing the project (#21085)uv checkhonor uv's color and progress settings, including quiet mode (#21086)Performance
Bug fixes
pythonw.exelaunchers for virtual environments created from managed Python minor-version links (#19235)uv lockto proceed when.venvis an unusable project environment (#21068)fork-strategywhen ordering forks created fromenvironmentsor existing lockfileresolution-markers(#21000)!=3.11.*, !=3.12.*inuv.lock(#21045)uv addupdates it (#21008)PYTHONEXECUTABLEand__PYVENV_LAUNCHER__overrides (#21075)uv version --bumpvalues (#21076)Configuration
📅 Schedule: (in timezone Europe/Amsterdam)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.
048e99b741bf0959d5e5fix(mise): update tool aqua:kubescape/kubescape (4.0.11 ➔ 4.0.12)to fix(mise): update mise tools (patch)bf0959d5e5afcb1a1f11afcb1a1f11de1848c468View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.