X Tutup
Skip to content

chore(deps): update submodules#4940

Merged
cuixq merged 1 commit intogoogle:masterfrom
renovate-bot:renovate/submodules
Mar 10, 2026
Merged

chore(deps): update submodules#4940
cuixq merged 1 commit intogoogle:masterfrom
renovate-bot:renovate/submodules

Conversation

@renovate-bot
Copy link
Collaborator

@renovate-bot renovate-bot commented Mar 3, 2026

This PR contains the following updates:

Package Type Update Change
gcp/api/googleapis (changelog) digest c6628407988234
github/codeql-action action patch v4.32.5v4.32.6
ossf/osv-schema patch 1.7.31.7.5
osv-schema digest 09a17f862cec4e
osv/osv-schema (changelog) digest 09a17f862cec4e
zizmorcore/zizmor-action action patch v0.5.0v0.5.2

Release Notes

github/codeql-action (github/codeql-action)

v4.32.6

Compare Source

ossf/osv-schema (ossf/osv-schema)

v1.7.5

Compare Source

Schema Changes

New ecosystems added:
  • opam for the OCaml package manager ecosystem.
  • FreeBSD (including FreeBSD:base, FreeBSD:kernel, and
    FreeBSD:ports) for the FreeBSD operating system.
  • DHI for Docker Hardened Images.
  • CleanStart for the CleanStart ecosystem.
Schema clarification & updates:
  • Debian: Updated ecosystem description to explicitly support the
    sid (unstable) and experimental suites.
  • VSCode: Updated description to allow for registries to be
    specified within the ecosystem field.

New Contributors

Full Changelog: ossf/osv-schema@v1.7.4...v1.7.5

v1.7.4

Compare Source

Schema Changes

  • New database prefixes added:

    • DEBIAN for the Debian Security Tracker.
    • ALPINE for the Alpine Security Database.
    • JLSEC for the Julia Security Advisory Database.
    • EEF for the Erlang Ecosystem Foundation CNA Vulnerabilities.
  • New ecosystems added:

    • Julia for the Julia programming language.
    • VSCode for Visual Studio Code extensions.
  • Schema clarification:

    • A note was added to clarify that version strings in affected ranges might not exactly match upstream package versions, as they can be normalized or have build metadata stripped.

New Contributors

Full Changelog: ossf/osv-schema@v1.7.3...v1.7.4

zizmorcore/zizmor-action (zizmorcore/zizmor-action)

v0.5.2

Compare Source

What's Changed

  • zizmor 1.23.1 is now the default used by this action.

Full Changelog: zizmorcore/zizmor-action@v0.5.1...v0.5.2

v0.5.1

Compare Source

What's Changed

  • zizmor 1.23.0 is now the default used by this action.

Full Changelog: zizmorcore/zizmor-action@v0.5.0...v0.5.1


Configuration

📅 Schedule: Branch creation - "before 6am on wednesday" in timezone Australia/Sydney, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@forking-renovate forking-renovate bot added the dependencies Pull requests that update a dependency file label Mar 3, 2026
@renovate-bot renovate-bot force-pushed the renovate/submodules branch 8 times, most recently from d800104 to 1c4c096 Compare March 5, 2026 23:47
michaelkedar added a commit that referenced this pull request Mar 6, 2026
To prevent updating the schema version from requiring us to regenerate
the test files (blocking #4940), changed the worker tests to manually
remove the schema_version from the compared vulnerability files.
@renovate-bot renovate-bot force-pushed the renovate/submodules branch 5 times, most recently from 20327e2 to 9fabc58 Compare March 9, 2026 04:32
cuixq
cuixq previously approved these changes Mar 9, 2026
@renovate-bot renovate-bot force-pushed the renovate/submodules branch from 9fabc58 to 4e2d551 Compare March 9, 2026 05:16
@renovate-bot renovate-bot force-pushed the renovate/submodules branch 2 times, most recently from c1b7047 to 8313c96 Compare March 9, 2026 22:04
@cuixq cuixq merged commit 1f86322 into google:master Mar 10, 2026
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

X Tutup