renovate
59542c4e6f
chore(deps): update golang:1.27.1 docker digest to 45639bc ( #197 )
dancefetcher / build (push) Successful in 2m2s
dancefetcher / deploy-prod (push) Successful in 27s
2026-10-06 05:20:43 +00:00
argoyle
482011aef0
chore(k8s): take the image reference from build-tools ( #196 )
...
dancefetcher / build (push) Successful in 4m42s
dancefetcher / deploy-prod (push) Successful in 28s
## Summary
`k8s/deploy.yaml` takes the image from build-tools: `image: ${IMAGE}` instead of the hard-coded `oci.unbound.se/dancefinder/dancefetcher:${COMMIT}`.
`deploy` substitutes `${IMAGE}` with `<registry>/<owner>/<name>:<tag>`, where the registry comes from the build-tools config and the tag is the value `${COMMIT}` gets today. The rendered reference is unchanged. Moving off `oci.unbound.se` later becomes one change in infra.
Validated on shiny/time-service#864 : merged and deployed to AWS staging and Frostmoln staging with the same image. Prerequisites, all merged:
- unboundsoftware/infra#1808 : registry in `BUILDTOOLS_FROSTMOLN_STAGING`
- shiny/acctest#952 : acctest pins build-tools to the Gitea registry
🤖 Generated with [Claude Code](https://claude.com/claude-code )
Reviewed-on: https://gitea.unbound.se/dancefinder/dancefetcher/pulls/196
2026-10-02 22:40:48 +00:00
renovate
bbd6edd301
chore(deps): update golang:1.27.1 docker digest to 2c9f73f ( #195 )
dancefetcher / build (push) Successful in 5m16s
dancefetcher / deploy-prod (push) Successful in 32s
2026-09-19 04:14:24 +00:00
renovate
56d13f386b
chore(deps): update go toolchain directive to v1.27.1 ( #194 )
dancefetcher / deploy-prod (push) Skipped
dancefetcher / build (push) Failing after 36s
2026-09-04 00:19:59 +00:00
renovate
009fd2549d
chore(deps): update golang docker tag to v1.27.1 ( #193 )
dancefetcher / build (push) Successful in 4m43s
dancefetcher / deploy-prod (push) Successful in 26s
2026-09-02 01:12:46 +00:00
renovate
cb393f09ea
chore(deps): update golang:1.27.0 docker digest to 47526c1 ( #192 )
dancefetcher / build (push) Successful in 3m53s
dancefetcher / deploy-prod (push) Successful in 27s
2026-08-25 09:19:17 +00:00
renovate
dccc2416d1
chore(deps): update go toolchain directive to v1.27.0 ( #191 )
dancefetcher / build (push) Successful in 4m2s
dancefetcher / deploy-prod (push) Successful in 27s
2026-08-22 00:18:49 +00:00
renovate
798fb8aa7c
chore(deps): update golang docker tag to v1.27.0 ( #190 )
dancefetcher / build (push) Successful in 10m1s
dancefetcher / deploy-prod (push) Successful in 31s
2026-08-19 21:22:20 +00:00
renovate
01882cd0ca
chore(deps): update golang docker tag to v1.26.7 ( #189 )
dancefetcher / build (push) Successful in 9m31s
dancefetcher / deploy-prod (push) Successful in 27s
2026-08-19 20:15:07 +00:00
renovate
526fc28a49
chore(deps): update go toolchain directive to v1.26.6 [security] ( #188 )
dancefetcher / build (push) Successful in 7m12s
dancefetcher / deploy-prod (push) Successful in 28s
2026-08-14 02:03:32 +00:00
renovate
6a8617ca9a
chore(deps): update golang docker tag to v1.26.6 ( #187 )
dancefetcher / build (push) Successful in 5m45s
dancefetcher / deploy-prod (push) Successful in 27s
2026-08-13 21:18:17 +00:00
renovate
c88aa38907
chore(deps): update golang:1.26.5 docker digest to e8ab809 ( #186 )
dancefetcher / build (push) Successful in 12m1s
dancefetcher / deploy-prod (push) Successful in 37s
2026-08-11 01:19:44 +00:00
renovate
95fdc4b55b
chore(deps): update golang:1.26.5 docker digest to 046e320 ( #185 )
dancefetcher / build (push) Successful in 6m39s
dancefetcher / deploy-prod (push) Successful in 27s
2026-08-08 04:15:20 +00:00
renovate
828d5c38eb
chore(deps): update golang:1.26.5 docker digest to adde241 ( #184 )
dancefetcher / build (push) Successful in 6m33s
dancefetcher / deploy-prod (push) Successful in 27s
2026-07-14 06:13:43 +00:00
renovate
3d545d1901
chore(deps): update golang docker tag to v1.26.5 ( #183 )
dancefetcher / build (push) Successful in 6m39s
dancefetcher / deploy-prod (push) Successful in 26s
2026-07-11 01:12:29 +00:00
renovate
5ac469772f
chore(deps): update go toolchain directive to v1.26.5 [security] ( #181 )
dancefetcher / build (push) Successful in 9m2s
dancefetcher / deploy-prod (push) Successful in 31s
2026-07-08 17:14:22 +00:00
renovate
90b7974a20
chore(deps): update golang:1.26.4 docker digest to f83d235 ( #180 )
dancefetcher / build (push) Successful in 8m36s
dancefetcher / deploy-prod (push) Successful in 50s
2026-06-24 06:49:05 +00:00
renovate
558ad7a5a5
chore(deps): update actions/checkout action to v7 ( #179 )
...
dancefetcher / build (push) Successful in 9m9s
dancefetcher / deploy-prod (push) Successful in 42s
This PR contains the following updates:
| Package | Type | Update | Change | Pending |
|---|---|---|---|---|
| [actions/checkout](https://github.com/actions/checkout ) | action | major | `v6` → `v7` | `v7.0.0` |
---
### Release Notes
<details>
<summary>actions/checkout (actions/checkout)</summary>
### [`v7.0.0`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700 )
[Compare Source](https://github.com/actions/checkout/compare/v7.0.0...v7.0.0 )
- Block checking out fork PR for pull\_request\_target and workflow\_run by [@​aiqiaoy](https://github.com/aiqiaoy ) in [#​2454](https://github.com/actions/checkout/pull/2454 )
- Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by [@​dependabot](https://github.com/dependabot )\[bot] in [#​2458](https://github.com/actions/checkout/pull/2458 )
- Bump flatted from 3.3.1 to 3.4.2 by [@​dependabot](https://github.com/dependabot )\[bot] in [#​2460](https://github.com/actions/checkout/pull/2460 )
- Bump js-yaml from 4.1.0 to 4.2.0 by [@​dependabot](https://github.com/dependabot )\[bot] in [#​2461](https://github.com/actions/checkout/pull/2461 )
- Bump [@​actions/core](https://github.com/actions/core ) and [@​actions/tool-cache](https://github.com/actions/tool-cache ) and Remove uuid by [@​dependabot](https://github.com/dependabot )\[bot] in [#​2459](https://github.com/actions/checkout/pull/2459 )
- upgrade module to esm and update dependencies by [@​aiqiaoy](https://github.com/aiqiaoy ) in [#​2463](https://github.com/actions/checkout/pull/2463 )
- Bump the minor-npm-dependencies group across 1 directory with 3 updates by [@​dependabot](https://github.com/dependabot )\[bot] in [#​2462](https://github.com/actions/checkout/pull/2462 )
### [`v7`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700 )
[Compare Source](https://github.com/actions/checkout/compare/v6.0.3...v7.0.0 )
- Block checking out fork PR for pull\_request\_target and workflow\_run by [@​aiqiaoy](https://github.com/aiqiaoy ) in [#​2454](https://github.com/actions/checkout/pull/2454 )
- Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by [@​dependabot](https://github.com/dependabot )\[bot] in [#​2458](https://github.com/actions/checkout/pull/2458 )
- Bump flatted from 3.3.1 to 3.4.2 by [@​dependabot](https://github.com/dependabot )\[bot] in [#​2460](https://github.com/actions/checkout/pull/2460 )
- Bump js-yaml from 4.1.0 to 4.2.0 by [@​dependabot](https://github.com/dependabot )\[bot] in [#​2461](https://github.com/actions/checkout/pull/2461 )
- Bump [@​actions/core](https://github.com/actions/core ) and [@​actions/tool-cache](https://github.com/actions/tool-cache ) and Remove uuid by [@​dependabot](https://github.com/dependabot )\[bot] in [#​2459](https://github.com/actions/checkout/pull/2459 )
- upgrade module to esm and update dependencies by [@​aiqiaoy](https://github.com/aiqiaoy ) in [#​2463](https://github.com/actions/checkout/pull/2463 )
- Bump the minor-npm-dependencies group across 1 directory with 3 updates by [@​dependabot](https://github.com/dependabot )\[bot] in [#​2462](https://github.com/actions/checkout/pull/2462 )
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMjAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjIyMC4wIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->
Reviewed-on: https://gitea.unbound.se/dancefinder/dancefetcher/pulls/179
Co-authored-by: Renovate Bot <renovate@unbound.se >
Co-committed-by: Renovate Bot <renovate@unbound.se >
2026-06-20 19:39:12 +00:00
renovate
ef8e68d209
chore(deps): update golang:1.26.4 docker digest to 62df9f3 ( #178 )
dancefetcher / build (push) Successful in 11m33s
dancefetcher / deploy-prod (push) Successful in 52s
2026-06-11 06:25:14 +00:00
renovate
6b1762d786
chore(deps): update golang docker tag to v1.26.4 ( #177 )
dancefetcher / build (push) Successful in 9m12s
dancefetcher / deploy-prod (push) Successful in 42s
2026-06-05 23:20:10 +00:00
renovate
92e42f4e61
chore(deps): update go toolchain directive to v1.26.4 [security] ( #175 )
...
dancefetcher / build (push) Successful in 11m53s
dancefetcher / deploy-prod (push) Successful in 54s
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [go](https://go.dev/ ) ([source](https://github.com/golang/go )) | toolchain | patch | `1.26.3` → `1.26.4` |
---
### Inefficient candidate hostname parsing in crypto/x509
[CVE-2026-27145](https://nvd.nist.gov/vuln/detail/CVE-2026-27145 ) / [GO-2026-5037](https://pkg.go.dev/vuln/GO-2026-5037 )
<details>
<summary>More information</summary>
#### Details
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname.
With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
#### Severity
Unknown
#### References
- [https://go.dev/cl/783621 ](https://go.dev/cl/783621 )
- [https://go.dev/issue/79694 ](https://go.dev/issue/79694 )
- [https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw ](https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw )
This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-5037 ) and the [Go Vulnerability Database](https://github.com/golang/vulndb ) ([CC-BY 4.0](https://github.com/golang/vulndb#license )).
</details>
---
### Quadratic complexity in WordDecoder.DecodeHeader in mime
[CVE-2026-42504](https://nvd.nist.gov/vuln/detail/CVE-2026-42504 ) / [GO-2026-5038](https://pkg.go.dev/vuln/GO-2026-5038 )
<details>
<summary>More information</summary>
#### Details
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
#### Severity
Unknown
#### References
- [https://go.dev/issue/79217 ](https://go.dev/issue/79217 )
- [https://go.dev/cl/774481 ](https://go.dev/cl/774481 )
- [https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw ](https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw )
This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-5038 ) and the [Go Vulnerability Database](https://github.com/golang/vulndb ) ([CC-BY 4.0](https://github.com/golang/vulndb#license )).
</details>
---
### Arbitrary inputs are included in errors without any escaping in net/textproto
[CVE-2026-42507](https://nvd.nist.gov/vuln/detail/CVE-2026-42507 ) / [GO-2026-5039](https://pkg.go.dev/vuln/GO-2026-5039 )
<details>
<summary>More information</summary>
#### Details
When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.
#### Severity
Unknown
#### References
- [https://go.dev/issue/79346 ](https://go.dev/issue/79346 )
- [https://go.dev/cl/777060 ](https://go.dev/cl/777060 )
- [https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw ](https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw )
This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-5039 ) and the [Go Vulnerability Database](https://github.com/golang/vulndb ) ([CC-BY 4.0](https://github.com/golang/vulndb#license )).
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- ""
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate ).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDIuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIwMi4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->
Reviewed-on: https://gitea.unbound.se/dancefinder/dancefetcher/pulls/175
Co-authored-by: Renovate Bot <renovate@unbound.se >
Co-committed-by: Renovate Bot <renovate@unbound.se >
2026-06-03 05:40:03 +00:00
renovate
e498f5d12f
chore(deps): update golang:1.26.3 docker digest to 54d3246 ( #174 )
dancefetcher / build (push) Successful in 19m11s
dancefetcher / deploy-prod (push) Successful in 1m2s
2026-05-20 06:21:44 +00:00
renovate
7770d3ae24
chore(deps): update golang docker tag to v1.26.3 ( #173 )
dancefetcher / build (push) Successful in 7m3s
dancefetcher / deploy-prod (push) Successful in 42s
2026-05-11 23:13:54 +00:00
renovate
01380bfb07
chore(deps): update go toolchain directive to v1.26.3 ( #172 )
dancefetcher / build (push) Successful in 7m54s
dancefetcher / deploy-prod (push) Successful in 47s
2026-05-10 00:15:09 +00:00
renovate
4749b56088
chore(deps): update golang:1.26.2 docker digest to e1203b8 ( #171 )
dancefetcher / build (push) Successful in 10m30s
dancefetcher / deploy-prod (push) Successful in 47s
2026-04-22 08:17:02 +00:00
renovate
f429e3bd16
chore(deps): update golang docker tag to v1.26.2 ( #170 )
dancefetcher / build (push) Successful in 10m22s
dancefetcher / deploy-prod (push) Successful in 50s
2026-04-10 22:55:25 +00:00
renovate
bea8a99de5
chore(deps): update dependency go to v1.26.2 ( #169 )
dancefetcher / build (push) Successful in 20m50s
dancefetcher / deploy-prod (push) Successful in 1m6s
2026-04-10 01:22:50 +00:00
renovate
ed8c5add07
chore(deps): update golang:1.26.1 docker digest to 5ba1126 ( #168 )
dancefetcher / build (push) Successful in 8m53s
dancefetcher / deploy-prod (push) Successful in 45s
2026-04-07 05:30:16 +00:00
renovate
20d3cc12b4
chore(deps): update golang:1.26.1 docker digest to 984bf90 ( #167 )
dancefetcher / build (push) Successful in 14m31s
dancefetcher / deploy-prod (push) Successful in 52s
2026-03-17 02:18:58 +00:00
renovate
28809f6f15
chore(deps): update golang docker tag to v1.26.1 ( #166 )
dancefetcher / build (push) Successful in 6m48s
dancefetcher / deploy-prod (push) Successful in 1m4s
2026-03-06 02:18:41 +00:00
renovate
45e6ef8802
chore(deps): update dependency go to v1.26.1 ( #165 )
dancefetcher / deploy-prod (push) Successful in 1m20s
dancefetcher / build (push) Successful in 5m42s
2026-03-06 01:16:31 +00:00
argoyle
7e9fffa7d0
Merge pull request 'fix(k8s): remove CPU limits to resolve KubeCPUOvercommit alert' ( #164 ) from remove-cpu-limits into master
...
dancefetcher / build (push) Successful in 5m17s
dancefetcher / deploy-prod (push) Successful in 44s
Reviewed-on: https://gitea.unbound.se/dancefinder/dancefetcher/pulls/164
2026-03-01 11:27:27 +00:00