Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.8.3
->v0.9.4
v1.28.3
->v1.29.5
v8.21.2
->v8.23.3
v1.13.0
->v1.14.1
0.30.0
->0.31.1
v1.7.4
->v1.7.7
Note: The
pre-commit
manager in Renovate is not supported by thepre-commit
maintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.Release Notes
astral-sh/ruff-pre-commit (astral-sh/ruff-pre-commit)
v0.9.4
Compare Source
See: https://github.com/astral-sh/ruff/releases/tag/0.9.4
v0.9.3
Compare Source
See: https://github.com/astral-sh/ruff/releases/tag/0.9.3
v0.9.2
Compare Source
See: https://github.com/astral-sh/ruff/releases/tag/0.9.2
v0.9.1
Compare Source
See: https://github.com/astral-sh/ruff/releases/tag/0.9.1
v0.9.0
Compare Source
See: https://github.com/astral-sh/ruff/releases/tag/0.9.0
v0.8.6
Compare Source
See: https://github.com/astral-sh/ruff/releases/tag/0.8.6
v0.8.5
Compare Source
See: https://github.com/astral-sh/ruff/releases/tag/0.8.5
v0.8.4
Compare Source
See: https://github.com/astral-sh/ruff/releases/tag/0.8.4
crate-ci/typos (crate-ci/typos)
v1.29.5
Compare Source
[1.29.5] - 2025-01-30
Internal
v1.29.4
Compare Source
[1.29.4] - 2025-01-03
v1.29.3
Compare Source
[1.29.3] - 2025-01-02
v1.29.2
Compare Source
v1.29.1
Compare Source
[1.29.1] - 2025-01-02
Fixes
deriver
v1.29.0
Compare Source
[1.29.0] - 2024-12-31
Features
Performance
v1.28.4
Compare Source
[1.28.4] - 2024-12-16
Features
--format sarif
supportgitleaks/gitleaks (gitleaks/gitleaks)
v8.23.3
Compare Source
Changelog
3188ad6
Don't exit with error if git repacking is required (#1711)7fc11bb
refactor(config): use non-capture groups for allowlists (#1735)36c52c6
chore: Enhancecurl-auth-user
to detect empty usernames or passwords (#1726)1f323d8
fix(cmd): read log-opts before GitLogCmd (#1730)v8.23.2
Compare Source
Changelog
d88bc09
facebook keyword3fdaefd
fix(meraki): restrict keyword case (#1722)f3ae52e
feat(generic-api-key): detect base64 (#1598)d6a828a
great branch name (#1721)d2ffffe
fix(git): remove .git suffix for links (#1716)a43dc0d
chore: refine generic-api-key fps + trace logging (#1720)69ed20e
fix(generate): move newline out of char range (#1719)52b895a
newline literal (#1718)3f4d91f
build: support either stdlib or 3rd-party regexp (#1706)049f5b2
chore(detect): update trace logging (#1713)7a6183d
feat(git): redact passwords from remote URL (#1709)3c7f3f0
feat(git): include link in report (#1698)0e3f4f7
chore: reduce generic-api-key fps (#1707)3ed8567
blorpe977850
added new rule for cisco meraki api key (#1700)ad7a4fb
feat: general fp tweaks (#1703)b2cf03c
chore(generate): use \x60 instead of literal (#1702)a3f623c
chore(regex): simplify secretPrefix, suffix (#1620)cc71bb1
update version for pre-commit in README.md (#1699)v8.23.1
Compare Source
Changelog
7bad9f7
chore(gcp): add firebase example keys to the gcp-api-key allowlists (#1635)977236c
fix: unaligned 64-bit atomic operation panic (#1696)a211b16
force push to master everyday0e5f644
feat(config): disable extended rule (#1535)f320a60
style: prevent globbing and word splitting (#1543)c4526b2
refactor(generic-api-key): remove hard-coded 'magic' (#1600)748076d
chore(generate): add failing test case (#1690)v8.23.0
Compare Source
Changelog
db8e5e6
feat(generate): use multiple allowlists (#1691)973c794
chore(rules): include fps in reference (#1471)f0d4499
Add comma as operator for GenerateSemiGenericRegex (#1679)ab38a46
refactor: central logger (#1692)b022d1c
friendship ended with tinesREAD THIS!!! The default gitleaks config now uses
[[rules.allowlists]]
v8.22.1
Compare Source
Changelog
b69b515
Entropy trace (#1659)7357adc
build: add 'toolchain' to go.mod (#1682)4c3da6e
refactor(detect): create readUntilSafeBoundary + add tests (#1676)dbe3746
twitter really does suck ass now7edfc6b
chore(tests): test cases for generate.go (#1623)efe40ca
fix: only use non-empty secret groups (#1632)7cb5f6f
build: upgrade sprig v2->v3 (#1674)2930537
fix: generate report file even if no findings (#1673)v8.22.0
Compare Source
Changelog
a91c671
replace std library regex engine with go-re2 (#1669)This bumps the gitleaks binary size from around 8.5MB to 15MB but yields 2-4x speedup. Worth it imo. If you feel strongly against this change feel free to open an issue where we can discuss the tradeoffs in more depth. Credit to @ahrav
v8.21.4
Compare Source
Changelog
906085f
Update golang version to 1.23 (#1672)8a83062
log bytes (#1670)v8.21.3
Compare Source
Changelog
a9e6d8c
go mod 1.232f73a3e
Ensure keywords are downcased (#1633)f696605
feat: add settlemint api keys detection (#1663)0bf13fc
feat(dir): better chunking (#1665)83e99ba
feat(report): allow user-defined templates (#1650)e393d29
Add support for GitLab routable tokens (#1656)263ce82
Add freemius secret key detection (#1611)3c0e068
fix(kubernetes): only match 'kind: secret' (#1649)f3adda0
feat: use STDOUT when report file not specified (#1642)ed205a5
fix(dir): skip opening file&dir if allowlist matches (#1653)6018012
fix: increase chunk size 10kb -> 100kb (#1652)7f77987
feat: detect sentry.io tokens in the new format (#1640)48a2e0e
refactor: pre-commit hooks (#1627)4e303d0
fix(easypost): only detect tokens of correct length (#1628)c1add1d
feat(dir): continue on permission error (#1621)202106a
Add human readable description for curl rules (#1625)8e94f98
Add option to includeLine
field in report (#1616)dbb42a7
hm (great comment)2599460
Update README.md8ffb980
nop for stupid build4181ad6
Add new jira api token pattern (#1601)48ea14b
feat: update global & generic allowlist (#1618)81f0002
fix(vault-service-token): ensure that TPS contains digits (#1614)c11adc9
Generate comprehensive secret samples (#1484)d1d9054
fix(aws): detect token in url (#1615)5fe58bf
fix(rules): entropy, uppercase in samples (#1593)5c2e813
feat: tweak rules (#1608)pre-commit/mirrors-mypy (pre-commit/mirrors-mypy)
v1.14.1
Compare Source
v1.14.0
Compare Source
python-jsonschema/check-jsonschema (python-jsonschema/check-jsonschema)
v0.31.1
Compare Source
renovate (2025-01-26)
gitlab
andrenovate
hooks to use--regex-variant nonunicode
. Thanks :user:quentin-ag
and :user:Callek
for reporting! (:issue:
516
, :issue:518
)ruamel.yaml
version to a range,>=0.18.10,<0.19.0
.v0.31.0
Compare Source
Update vendored schemas: azure-pipelines, bamboo-spec, buildkite, circle-ci,
dependabot, gitlab-ci, mergify, readthedocs, renovate, taskfile (2025-01-07)
Drop support for Python 3.8
Rename
--format-regex
to--regex-variant
and convert--format-regex
to a deprecated alias.It will be removed in a future release.
Regular expression interpretation in
"pattern"
,"patternProperties"
, and"format": "regex"
usages now uses unicode-mode JS regular expressions bydefault. (:issue:
353
)--regex-variant nonunicode
to get non-unicode JS regularexpressions, the default behavior from previous versions.
features. Validators are now always modified with the
jsonschema
library's
extend()
API to control thepattern
andpatternProperties
keywords.rhysd/actionlint (rhysd/actionlint)
v1.7.7
Compare Source
ubuntu-24.04-arm
ubuntu-22.04-arm
[Changes][v1.7.7]
v1.7.6
Compare Source
jobs.<job_id>.steps.with.args
jobs.<job_id>.steps.with.entrypoint
jobs.<job_id>.services.<service_id>.env
[Changes][v1.7.6]
v1.7.5
Compare Source
${{ }}
placeholders following the 'Context availability' table in the official document.jobs.<job>.env
allowsgithub
context butjobs.<job>.services.<service>.env
doesn't allow any contexts. Now actionlint can catch the mistake.OK.
github
context is available here.ERROR: No context is available here.
fromJSON()
call. This pattern is popular to create array or object constants because GitHub Actions does not provide the literal syntax for them. See the document for more details. (#464)ERROR: Key 'mac' does not exist in the object returned by the fromJSON()
ERROR: Broken JSON string passed to fromJSON.
Configuration
📅 Schedule: Branch creation - "before 5am on Saturday every 4 weeks of the year starting on the 2th week" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.