Bulk dependency updates (Renovate) #8

Open
gitea_admin wants to merge 7 commits from feat/renovate-update-bulk into main
Owner

Consolidates 6 open Renovate PRs into one branch, applied and verified in order (Go deps, then Dockerfile bumps, then CI-only bumps):

Incorporated:

  • #3 feat(deps): update module github.com/prometheus/client_golang v1.23.2 -> v1.24.1
  • #4 feat(deps): update opentelemetry-go monorepo v1.43.0 -> v1.46.0 (had a go.mod/go.sum conflict with #3, resolved by combining both bumps; followed by go mod tidy to reconcile go.sum, committed separately)
  • #2 feat(container): update image docker.io/library/golang 1.25 -> 1.27 (builder stage)
  • #1 feat(container): update image docker.io/library/alpine 3.20 -> 3.24 (final stage) -- verified both Dockerfile base images landed correctly without clobbering each other
  • #6 ci(github-action)!: Update action actions/checkout v4.4.0 -> v7.0.1 (MAJOR)
  • #7 ci(github-action)!: Update action actions/setup-go v4.3.0 -> v7.0.0 (MAJOR)

Left out: none -- all 6 open Renovate PRs are incorporated.

Verification performed:

  • go build ./... and go vet ./... clean after the prometheus/otel dependency bumps, and again after all commits landed
  • go mod tidy run to reconcile go.sum after combining the two dependency bumps (dropped one now-unneeded indirect entry)
  • Confirmed both Dockerfile base images (golang builder + alpine final stage) reflect their respective bumps correctly
  • Confirmed all .forgejo/workflows/*.yml still parse as valid YAML after the actions/checkout and actions/setup-go major bumps, and that all action references consistently point to the new major versions
  • Final full check: go build ./..., go vet ./..., go test ./... all pass (this module has no CGO dependencies, so no CGO_ENABLED=1 was needed)

Once merged, the original #1, #2, #3, #4, #6, #7 branches/PRs can be closed.

Consolidates 6 open Renovate PRs into one branch, applied and verified in order (Go deps, then Dockerfile bumps, then CI-only bumps): **Incorporated:** - #3 `feat(deps): update module github.com/prometheus/client_golang v1.23.2 -> v1.24.1` - #4 `feat(deps): update opentelemetry-go monorepo v1.43.0 -> v1.46.0` (had a go.mod/go.sum conflict with #3, resolved by combining both bumps; followed by `go mod tidy` to reconcile go.sum, committed separately) - #2 `feat(container): update image docker.io/library/golang 1.25 -> 1.27` (builder stage) - #1 `feat(container): update image docker.io/library/alpine 3.20 -> 3.24` (final stage) -- verified both Dockerfile base images landed correctly without clobbering each other - #6 `ci(github-action)!: Update action actions/checkout v4.4.0 -> v7.0.1` (MAJOR) - #7 `ci(github-action)!: Update action actions/setup-go v4.3.0 -> v7.0.0` (MAJOR) **Left out:** none -- all 6 open Renovate PRs are incorporated. **Verification performed:** - `go build ./...` and `go vet ./...` clean after the prometheus/otel dependency bumps, and again after all commits landed - `go mod tidy` run to reconcile go.sum after combining the two dependency bumps (dropped one now-unneeded indirect entry) - Confirmed both Dockerfile base images (golang builder + alpine final stage) reflect their respective bumps correctly - Confirmed all `.forgejo/workflows/*.yml` still parse as valid YAML after the actions/checkout and actions/setup-go major bumps, and that all action references consistently point to the new major versions - Final full check: `go build ./...`, `go vet ./...`, `go test ./...` all pass (this module has no CGO dependencies, so no `CGO_ENABLED=1` was needed) Once merged, the original #1, #2, #3, #4, #6, #7 branches/PRs can be closed.
All checks were successful
service-dmarc-sts CI / build-and-push (pull_request) Successful in 1m50s
Go lint / lint (pull_request) Successful in 2m5s
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feat/renovate-update-bulk:feat/renovate-update-bulk
git switch feat/renovate-update-bulk

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff feat/renovate-update-bulk
git switch feat/renovate-update-bulk
git rebase main
git switch main
git merge --ff-only feat/renovate-update-bulk
git switch feat/renovate-update-bulk
git rebase main
git switch main
git merge --no-ff feat/renovate-update-bulk
git switch main
git merge --squash feat/renovate-update-bulk
git switch main
git merge --ff-only feat/renovate-update-bulk
git switch main
git merge feat/renovate-update-bulk
git push origin main
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
dmarc-ing/service-dmarc-sts!8
No description provided.