fosrl / fosrl/pangolin-kube-controller

Dependency Dashboard

Open
#5 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
13
Forks
3
PR merge metrics
No merged PRs in 30d

Description

This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.
[View this repository on the Mend.io Web Portal](https://developer.mend.io/github/fosrl/pangolin-kube-controller).

## Abandoned Dependencies

The following dependencies have not received updates for an extended period and may be unmaintained.

> [!NOTE]
Packages are marked as abandoned when they exceed the [`abandonmentThreshold`](https://docs.renovatebot.com/configuration-options/#abandonmentthreshold) since their last release. Unlike deprecated packages with official notices, abandonment is detected by release inactivity.
>

View abandoned dependencies (5)

| Datasource | Package | Last Updated |
|------------|------|-------------|
| github-actions | [deepsourcelabs/test-coverage-action](https://redirect.github.com/deepsourcelabs/test-coverage-action) | `2025-07-17` |
| github-actions | [pre-commit/action](https://redirect.github.com/pre-commit/action) | `2024-02-07` |
| gomod | [github.com/google/go-cmp](https://redirect.github.com/google/go-cmp) | `2025-02-21` |
| gomod | [sigs.k8s.io/yaml](https://redirect.github.com/kubernetes-sigs/yaml) | `2025-07-24` |

## Open

The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.

- [ ] [chore(deps): update docker](../pull/20) (`docker/dockerfile`, `golang`)
- [ ] [chore(deps): update golang](../pull/21) (`github.com/prometheus/client_golang`, `github.com/sirupsen/logrus`, `github.com/stretchr/testify`, `go.opentelemetry.io/contrib/instrumentation/runtime`, `go.opentelemetry.io/otel`, `go.opentelemetry.io/otel/exporters/prometheus`, `go.opentelemetry.io/otel/metric`, `go.opentelemetry.io/otel/sdk`, `go.opentelemetry.io/otel/sdk/metric`, `golang.org/x/sync`, `k8s.io/api`, `k8s.io/apiextensions-apiserver`, `k8s.io/apimachinery`, `k8s.io/client-go`, `sigs.k8s.io/controller-runtime`)
- [ ] [chore(deps): update github-actions](../pull/19) (`DavidAnson/markdownlint-cli2-action`, `actions/attest-build-provenance`, `actions/checkout`, `actions/setup-go`, `actions/setup-python`, `anchore/sbom-action`, `aquasecurity/trivy`, `docker/login-action`, `docker/setup-buildx-action`, `docker/setup-qemu-action`, `golangci/golangci-lint`, `hadolint/hadolint-action`, `renovatebot/github-action`, `reviewdog/action-actionlint`, `sigstore/cosign`, `softprops/action-gh-release`)
- [ ] **Click on this checkbox to rebase all open PRs at once**

## Detected Dependencies

dockerfile (2)

Dockerfile (2)

- `docker/dockerfile 1@sha256:87999aa3d42bdc6bea60565083ee17e86d1f3339802f543c0d03998580f9cb89` → [Updates: `1`]
- `gcr.io/distroless/static-debian12 sha256:61b7ccecebc7c474a531717de80a94709d20547cdcdaf740c25876f2a8e38b44` → [Updates: `undefined`]

Dockerfile.scratch (1)

- `docker/dockerfile 1@sha256:87999aa3d42bdc6bea60565083ee17e86d1f3339802f543c0d03998580f9cb89` → [Updates: `1`]

github-actions (9)

.github/workflows/build-publish.yml (16)

- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `docker/setup-qemu-action v4.2.0@96fe6ef7f33517b61c61be40b68a1882f3264fb8` → [Updates: `v4.3.0`]
- `docker/setup-buildx-action v4.2.0@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c` → [Updates: `v4.3.0`]
- `docker/login-action v4.4.0@af1e73f918a031802d376d3c8bbc3fe56130a9b0` → [Updates: `v4.6.0`]
- `docker/login-action v4.4.0@af1e73f918a031802d376d3c8bbc3fe56130a9b0` → [Updates: `v4.6.0`]
- `actions/setup-go v6.5.0@924ae3a1cded613372ab5595356fb5720e22ba16` → [Updates: `v7.0.0`]
- `sigstore/cosign-installer v4.1.2@6f9f17788090df1f26f669e9d70d6ae9567deba6`
- `aquasecurity/setup-trivy v0.3.1@81e514348e19b6112ce2a7e3ecbafe19c1e1f567`
- `actions/attest-build-provenance v4.1.1@0f67c3f4856b2e3261c31976d6725780e5e4c373` → [Updates: `v4.2.2`]
- `actions/attest-build-provenance v4.1.1@0f67c3f4856b2e3261c31976d6725780e5e4c373` → [Updates: `v4.2.2`]
- `actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a`
- `softprops/action-gh-release v3@3d0d9888cb7fd7b750713d6e236d1fcb99157228` → [Updates: `v3`]
- `actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a`
- `ubuntu 24.04`
- `sigstore/cosign v3.0.6` → [Updates: `v3.1.3`]
- `aquasecurity/trivy v0.72.0` → [Updates: `v0.74.0`]

.github/workflows/ci.yml (26)

- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-go v6.5.0@924ae3a1cded613372ab5595356fb5720e22ba16` → [Updates: `v7.0.0`]
- `pre-commit/action v3.0.1@2c7b3805fd2a0fd8c1884dcaebf91fc102a13ecd`
- `golangci/golangci-lint-action v9.3.0@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a`
- `DavidAnson/markdownlint-cli2-action v24.0.0@8de2aa07cae85fd17c0b35642db70cf5495f1d25` → [Updates: `v24.2.0`]
- `actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1` → [Updates: `v7.0.0`]
- `hadolint/hadolint-action v3.3.0@2332a7b74a6de0dda2e2221d575162eba76ba5e5` → [Updates: `v3.5.0`]
- `reviewdog/action-actionlint v1.72@6fb7acc99f4a1008869fa8a0f09cfca740837d9d` → [Updates: `v1.74`, `v1.72`]
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-go v6.5.0@924ae3a1cded613372ab5595356fb5720e22ba16` → [Updates: `v7.0.0`]
- `actions/cache v6.1.0@55cc8345863c7cc4c66a329aec7e433d2d1c52a9`
- `deepsourcelabs/test-coverage-action v1.1.3@4284bb73a04adb39faaa6bfcc2d0e3dd137ffed7`
- `actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a`
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-go v6.5.0@924ae3a1cded613372ab5595356fb5720e22ba16` → [Updates: `v7.0.0`]
- `actions/cache v6.1.0@55cc8345863c7cc4c66a329aec7e433d2d1c52a9`
- `aquasecurity/trivy-action v0.36.0@ed142fd0673e97e23eac54620cfb913e5ce36c25`
- `aquasecurity/trivy-action v0.36.0@ed142fd0673e97e23eac54620cfb913e5ce36c25`
- `docker/setup-buildx-action v4.2.0@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c` → [Updates: `v4.3.0`]
- `docker/build-push-action v7.3.0@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a` → [Updates: `v7.4.0`]
- `aquasecurity/trivy-action v0.36.0@ed142fd0673e97e23eac54620cfb913e5ce36c25`
- `ubuntu 24.04`
- `golangci/golangci-lint v2.12.2` → [Updates: `v2.13.2`]
- `python 3.14`
- `ubuntu 24.04`
- `ubuntu 24.04`

.github/workflows/commitlint.yml (3)

- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `wagoid/commitlint-github-action v6@b948419dd99f3fd78a6548d48f94e3df7f6bf3ed`
- `ubuntu 24.04`

.github/workflows/continuous-security.yml (12)

- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-go v6.5.0@924ae3a1cded613372ab5595356fb5720e22ba16` → [Updates: `v7.0.0`]
- `actions/cache v6.1.0@55cc8345863c7cc4c66a329aec7e433d2d1c52a9`
- `golang/govulncheck-action v1.1.0@032d45514ae346b1db93c04b0c90b841c370344f`
- `aquasecurity/trivy-action v0.36.0@ed142fd0673e97e23eac54620cfb913e5ce36c25`
- `aquasecurity/trivy-action v0.36.0@ed142fd0673e97e23eac54620cfb913e5ce36c25`
- `docker/setup-buildx-action v4.2.0@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c` → [Updates: `v4.3.0`]
- `docker/build-push-action v7.3.0@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a` → [Updates: `v7.4.0`]
- `aquasecurity/trivy-action v0.36.0@ed142fd0673e97e23eac54620cfb913e5ce36c25`
- `anchore/sbom-action v0.24.0@e22c389904149dbc22b58101806040fa8d37a610` → [Updates: `v0.24.2`]
- `actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a`
- `ubuntu 24.04`

.github/workflows/deepsource-coverage.yml (4)

- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-go v6.5.0@924ae3a1cded613372ab5595356fb5720e22ba16` → [Updates: `v7.0.0`]
- `deepsourcelabs/test-coverage-action v1.1.3@4284bb73a04adb39faaa6bfcc2d0e3dd137ffed7`
- `ubuntu 24.04`

.github/workflows/deprecation-check.yml (2)

- `actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7`]
- `ubuntu 24.04`

.github/workflows/labels-sync.yml (1)

- `ubuntu 24.04`

.github/workflows/release.yml (2)

- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `ubuntu 24.04`

.github/workflows/renovate-validate.yml (3)

- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `renovatebot/github-action v46.1.19@22e0a16091fc706b04affe6ae53d5e3358ac4023` → [Updates: `v46.3.0`]
- `ubuntu 24.04`

gomod (1)

go.mod (18)

- `go 1.26.2`
- `github.com/google/go-cmp v0.7.0`
- `github.com/prometheus/client_golang v1.23.2` → [Updates: `v1.24.1`]
- `github.com/sirupsen/logrus v1.9.4` → [Updates: `v1.10.2`]
- `github.com/stretchr/testify v1.11.1` → [Updates: `v1.12.1`]
- `go.opentelemetry.io/contrib/instrumentation/runtime v0.69.0` → [Updates: `v0.71.0`]
- `go.opentelemetry.io/otel v1.44.0` → [Updates: `v1.46.0`]
- `go.opentelemetry.io/otel/exporters/prometheus v0.66.0` → [Updates: `v0.68.0`]
- `go.opentelemetry.io/otel/metric v1.44.0` → [Updates: `v1.46.0`]
- `go.opentelemetry.io/otel/sdk v1.44.0` → [Updates: `v1.46.0`]
- `go.opentelemetry.io/otel/sdk/metric v1.44.0` → [Updates: `v1.46.0`]
- `golang.org/x/sync v0.22.0` → [Updates: `v0.23.0`]
- `k8s.io/api v0.36.2` → [Updates: `v0.37.0`]
- `k8s.io/apiextensions-apiserver v0.36.2` → [Updates: `v0.37.0`]
- `k8s.io/apimachinery v0.36.2` → [Updates: `v0.37.0`]
- `k8s.io/client-go v0.36.2` → [Updates: `v0.37.0`]
- `sigs.k8s.io/controller-runtime v0.24.1` → [Updates: `v0.25.0`]
- `sigs.k8s.io/yaml v1.6.0`

regex (2)

Dockerfile (1)

- `golang 1.26.5-alpine@sha256:0178a641fbb4858c5f1b48e34bdaabe0350a330a1b1149aabd498d0699ff5fb2` → [Updates: `1.27.1-alpine`]

Dockerfile.scratch (1)

- `golang 1.26.5-alpine@sha256:0178a641fbb4858c5f1b48e34bdaabe0350a330a1b1149aabd498d0699ff5fb2` → [Updates: `1.27.1-alpine`]

---

- [ ] Check this box to trigger a request for Renovate to run again on this repository

Contributor guide

Open the contributing guide

Research direction

Start with the open pull requests #19, #20, and #21, then review the dependency entries for Dockerfile, Dockerfile.scratch, .github/workflows/, and go.mod. Check the listed Renovate updates and CI results; done means the relevant dependency updates are reviewed and the dashboard no longer has those open updates.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, github-actions, go, kubernetes
Domain
build-system, ci-cd, devops
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.