fosrl / fosrl/pangolin-kube-controller
Dependency Dashboard
- Dominant language
- Go
- Stars
- 13
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.
[View this repository on the Mend.io Web Portal](https://developer.mend.io/github/fosrl/pangolin-kube-controller).
## Abandoned Dependencies
The following dependencies have not received updates for an extended period and may be unmaintained.
> [!NOTE]
Packages are marked as abandoned when they exceed the [`abandonmentThreshold`](https://docs.renovatebot.com/configuration-options/#abandonmentthreshold) since their last release. Unlike deprecated packages with official notices, abandonment is detected by release inactivity.
>
View abandoned dependencies (5)
| Datasource | Package | Last Updated |
|------------|------|-------------|
| github-actions | [deepsourcelabs/test-coverage-action](https://redirect.github.com/deepsourcelabs/test-coverage-action) | `2025-07-17` |
| github-actions | [pre-commit/action](https://redirect.github.com/pre-commit/action) | `2024-02-07` |
| gomod | [github.com/google/go-cmp](https://redirect.github.com/google/go-cmp) | `2025-02-21` |
| gomod | [sigs.k8s.io/yaml](https://redirect.github.com/kubernetes-sigs/yaml) | `2025-07-24` |
## Open
The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.
- [ ] [chore(deps): update docker](../pull/20) (`docker/dockerfile`, `golang`)
- [ ] [chore(deps): update golang](../pull/21) (`github.com/prometheus/client_golang`, `github.com/sirupsen/logrus`, `github.com/stretchr/testify`, `go.opentelemetry.io/contrib/instrumentation/runtime`, `go.opentelemetry.io/otel`, `go.opentelemetry.io/otel/exporters/prometheus`, `go.opentelemetry.io/otel/metric`, `go.opentelemetry.io/otel/sdk`, `go.opentelemetry.io/otel/sdk/metric`, `golang.org/x/sync`, `k8s.io/api`, `k8s.io/apiextensions-apiserver`, `k8s.io/apimachinery`, `k8s.io/client-go`, `sigs.k8s.io/controller-runtime`)
- [ ] [chore(deps): update github-actions](../pull/19) (`DavidAnson/markdownlint-cli2-action`, `actions/attest-build-provenance`, `actions/checkout`, `actions/setup-go`, `actions/setup-python`, `anchore/sbom-action`, `aquasecurity/trivy`, `docker/login-action`, `docker/setup-buildx-action`, `docker/setup-qemu-action`, `golangci/golangci-lint`, `hadolint/hadolint-action`, `renovatebot/github-action`, `reviewdog/action-actionlint`, `sigstore/cosign`, `softprops/action-gh-release`)
- [ ] **Click on this checkbox to rebase all open PRs at once**
## Detected Dependencies
dockerfile (2)
Dockerfile (2)
- `docker/dockerfile 1@sha256:87999aa3d42bdc6bea60565083ee17e86d1f3339802f543c0d03998580f9cb89` → [Updates: `1`]
- `gcr.io/distroless/static-debian12 sha256:61b7ccecebc7c474a531717de80a94709d20547cdcdaf740c25876f2a8e38b44` → [Updates: `undefined`]Dockerfile.scratch (1)
- `docker/dockerfile 1@sha256:87999aa3d42bdc6bea60565083ee17e86d1f3339802f543c0d03998580f9cb89` → [Updates: `1`]
github-actions (9)
.github/workflows/build-publish.yml (16)
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `docker/setup-qemu-action v4.2.0@96fe6ef7f33517b61c61be40b68a1882f3264fb8` → [Updates: `v4.3.0`]
- `docker/setup-buildx-action v4.2.0@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c` → [Updates: `v4.3.0`]
- `docker/login-action v4.4.0@af1e73f918a031802d376d3c8bbc3fe56130a9b0` → [Updates: `v4.6.0`]
- `docker/login-action v4.4.0@af1e73f918a031802d376d3c8bbc3fe56130a9b0` → [Updates: `v4.6.0`]
- `actions/setup-go v6.5.0@924ae3a1cded613372ab5595356fb5720e22ba16` → [Updates: `v7.0.0`]
- `sigstore/cosign-installer v4.1.2@6f9f17788090df1f26f669e9d70d6ae9567deba6`
- `aquasecurity/setup-trivy v0.3.1@81e514348e19b6112ce2a7e3ecbafe19c1e1f567`
- `actions/attest-build-provenance v4.1.1@0f67c3f4856b2e3261c31976d6725780e5e4c373` → [Updates: `v4.2.2`]
- `actions/attest-build-provenance v4.1.1@0f67c3f4856b2e3261c31976d6725780e5e4c373` → [Updates: `v4.2.2`]
- `actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a`
- `softprops/action-gh-release v3@3d0d9888cb7fd7b750713d6e236d1fcb99157228` → [Updates: `v3`]
- `actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a`
- `ubuntu 24.04`
- `sigstore/cosign v3.0.6` → [Updates: `v3.1.3`]
- `aquasecurity/trivy v0.72.0` → [Updates: `v0.74.0`].github/workflows/ci.yml (26)
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-go v6.5.0@924ae3a1cded613372ab5595356fb5720e22ba16` → [Updates: `v7.0.0`]
- `pre-commit/action v3.0.1@2c7b3805fd2a0fd8c1884dcaebf91fc102a13ecd`
- `golangci/golangci-lint-action v9.3.0@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a`
- `DavidAnson/markdownlint-cli2-action v24.0.0@8de2aa07cae85fd17c0b35642db70cf5495f1d25` → [Updates: `v24.2.0`]
- `actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1` → [Updates: `v7.0.0`]
- `hadolint/hadolint-action v3.3.0@2332a7b74a6de0dda2e2221d575162eba76ba5e5` → [Updates: `v3.5.0`]
- `reviewdog/action-actionlint v1.72@6fb7acc99f4a1008869fa8a0f09cfca740837d9d` → [Updates: `v1.74`, `v1.72`]
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-go v6.5.0@924ae3a1cded613372ab5595356fb5720e22ba16` → [Updates: `v7.0.0`]
- `actions/cache v6.1.0@55cc8345863c7cc4c66a329aec7e433d2d1c52a9`
- `deepsourcelabs/test-coverage-action v1.1.3@4284bb73a04adb39faaa6bfcc2d0e3dd137ffed7`
- `actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a`
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-go v6.5.0@924ae3a1cded613372ab5595356fb5720e22ba16` → [Updates: `v7.0.0`]
- `actions/cache v6.1.0@55cc8345863c7cc4c66a329aec7e433d2d1c52a9`
- `aquasecurity/trivy-action v0.36.0@ed142fd0673e97e23eac54620cfb913e5ce36c25`
- `aquasecurity/trivy-action v0.36.0@ed142fd0673e97e23eac54620cfb913e5ce36c25`
- `docker/setup-buildx-action v4.2.0@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c` → [Updates: `v4.3.0`]
- `docker/build-push-action v7.3.0@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a` → [Updates: `v7.4.0`]
- `aquasecurity/trivy-action v0.36.0@ed142fd0673e97e23eac54620cfb913e5ce36c25`
- `ubuntu 24.04`
- `golangci/golangci-lint v2.12.2` → [Updates: `v2.13.2`]
- `python 3.14`
- `ubuntu 24.04`
- `ubuntu 24.04`.github/workflows/commitlint.yml (3)
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `wagoid/commitlint-github-action v6@b948419dd99f3fd78a6548d48f94e3df7f6bf3ed`
- `ubuntu 24.04`.github/workflows/continuous-security.yml (12)
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-go v6.5.0@924ae3a1cded613372ab5595356fb5720e22ba16` → [Updates: `v7.0.0`]
- `actions/cache v6.1.0@55cc8345863c7cc4c66a329aec7e433d2d1c52a9`
- `golang/govulncheck-action v1.1.0@032d45514ae346b1db93c04b0c90b841c370344f`
- `aquasecurity/trivy-action v0.36.0@ed142fd0673e97e23eac54620cfb913e5ce36c25`
- `aquasecurity/trivy-action v0.36.0@ed142fd0673e97e23eac54620cfb913e5ce36c25`
- `docker/setup-buildx-action v4.2.0@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c` → [Updates: `v4.3.0`]
- `docker/build-push-action v7.3.0@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a` → [Updates: `v7.4.0`]
- `aquasecurity/trivy-action v0.36.0@ed142fd0673e97e23eac54620cfb913e5ce36c25`
- `anchore/sbom-action v0.24.0@e22c389904149dbc22b58101806040fa8d37a610` → [Updates: `v0.24.2`]
- `actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a`
- `ubuntu 24.04`.github/workflows/deepsource-coverage.yml (4)
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-go v6.5.0@924ae3a1cded613372ab5595356fb5720e22ba16` → [Updates: `v7.0.0`]
- `deepsourcelabs/test-coverage-action v1.1.3@4284bb73a04adb39faaa6bfcc2d0e3dd137ffed7`
- `ubuntu 24.04`.github/workflows/deprecation-check.yml (2)
- `actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7`]
- `ubuntu 24.04`.github/workflows/labels-sync.yml (1)
- `ubuntu 24.04`
.github/workflows/release.yml (2)
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `ubuntu 24.04`.github/workflows/renovate-validate.yml (3)
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `renovatebot/github-action v46.1.19@22e0a16091fc706b04affe6ae53d5e3358ac4023` → [Updates: `v46.3.0`]
- `ubuntu 24.04`
gomod (1)
go.mod (18)
- `go 1.26.2`
- `github.com/google/go-cmp v0.7.0`
- `github.com/prometheus/client_golang v1.23.2` → [Updates: `v1.24.1`]
- `github.com/sirupsen/logrus v1.9.4` → [Updates: `v1.10.2`]
- `github.com/stretchr/testify v1.11.1` → [Updates: `v1.12.1`]
- `go.opentelemetry.io/contrib/instrumentation/runtime v0.69.0` → [Updates: `v0.71.0`]
- `go.opentelemetry.io/otel v1.44.0` → [Updates: `v1.46.0`]
- `go.opentelemetry.io/otel/exporters/prometheus v0.66.0` → [Updates: `v0.68.0`]
- `go.opentelemetry.io/otel/metric v1.44.0` → [Updates: `v1.46.0`]
- `go.opentelemetry.io/otel/sdk v1.44.0` → [Updates: `v1.46.0`]
- `go.opentelemetry.io/otel/sdk/metric v1.44.0` → [Updates: `v1.46.0`]
- `golang.org/x/sync v0.22.0` → [Updates: `v0.23.0`]
- `k8s.io/api v0.36.2` → [Updates: `v0.37.0`]
- `k8s.io/apiextensions-apiserver v0.36.2` → [Updates: `v0.37.0`]
- `k8s.io/apimachinery v0.36.2` → [Updates: `v0.37.0`]
- `k8s.io/client-go v0.36.2` → [Updates: `v0.37.0`]
- `sigs.k8s.io/controller-runtime v0.24.1` → [Updates: `v0.25.0`]
- `sigs.k8s.io/yaml v1.6.0`
regex (2)
Dockerfile (1)
- `golang 1.26.5-alpine@sha256:0178a641fbb4858c5f1b48e34bdaabe0350a330a1b1149aabd498d0699ff5fb2` → [Updates: `1.27.1-alpine`]
Dockerfile.scratch (1)
- `golang 1.26.5-alpine@sha256:0178a641fbb4858c5f1b48e34bdaabe0350a330a1b1149aabd498d0699ff5fb2` → [Updates: `1.27.1-alpine`]
---
- [ ] Check this box to trigger a request for Renovate to run again on this repository
Contributor guide
Research direction
Start with the open pull requests #19, #20, and #21, then review the dependency entries for Dockerfile, Dockerfile.scratch, .github/workflows/, and go.mod. Check the listed Renovate updates and CI results; done means the relevant dependency updates are reviewed and the dashboard no longer has those open updates.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, github-actions, go, kubernetes
- Domain
- build-system, ci-cd, devops
- Issue type
- Refactor
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100