Dependency Dashboard
- Dominant language
- Go
- Stars
- 12
- Forks
- 1
- Avg merge
- 23m
- Merged PRs (30d)
- 1
Description
This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.
## Abandoned Dependencies
The following dependencies have not received updates for an extended period and may be unmaintained.
View abandoned dependencies (22)
> [!NOTE]
Packages are marked as abandoned when they exceed the [`abandonmentThreshold`](https://docs.renovatebot.com/configuration-options/#abandonmentthreshold) since their last release. Unlike deprecated packages with official notices, abandonment is detected by release inactivity.
>
| Datasource | Package | Last Updated |
|------------|------|-------------|
| gomod | [github.com/beorn7/perks](https://redirect.github.com/beorn7/perks) | `2019-07-31` |
| gomod | [github.com/cespare/xxhash/v2](https://redirect.github.com/cespare/xxhash) | `2024-04-04` |
| gomod | [github.com/davecgh/go-spew](https://redirect.github.com/davecgh/go-spew) | `2018-02-21` |
| gomod | [github.com/dustin/go-humanize](https://redirect.github.com/dustin/go-humanize) | `2023-01-10` |
| gomod | [github.com/efficientgo/tools/core](https://redirect.github.com/efficientgo/tools) | `2023-05-05` |
| gomod | [github.com/go-kit/log](https://redirect.github.com/go-kit/log) | `2022-05-14` |
| gomod | [github.com/gogo/protobuf](https://redirect.github.com/gogo/protobuf) | `2021-01-10` |
| gomod | [github.com/google/uuid](https://redirect.github.com/google/uuid) | `2024-01-23` |
| gomod | [github.com/json-iterator/go](https://redirect.github.com/json-iterator/go) | `2021-09-11` |
| gomod | [github.com/minio/md5-simd](https://redirect.github.com/minio/md5-simd) | `2021-02-16` |
| gomod | [github.com/minio/sha256-simd](https://redirect.github.com/minio/sha256-simd) | `2023-05-24` |
| gomod | [github.com/mitchellh/go-homedir](https://redirect.github.com/mitchellh/go-homedir) | `2019-01-27` |
| gomod | [github.com/modern-go/concurrent](https://redirect.github.com/modern-go/concurrent) | `2018-03-06` |
| gomod | [github.com/modern-go/reflect2](https://redirect.github.com/modern-go/reflect2) | `2021-09-11` |
| gomod | [github.com/munnerz/goautoneg](https://redirect.github.com/munnerz/goautoneg) | `2019-10-10` |
| gomod | [github.com/opentracing/opentracing-go](https://redirect.github.com/opentracing/opentracing-go) | `2020-07-01` |
| gomod | [github.com/pkg/errors](https://redirect.github.com/pkg/errors) | `2020-01-14` |
| gomod | [github.com/pmezard/go-difflib](https://redirect.github.com/pmezard/go-difflib) | `2016-01-10` |
| gomod | [github.com/rs/xid](https://redirect.github.com/rs/xid) | `2024-08-23` |
| gomod | [go.uber.org/goleak](https://redirect.github.com/uber-go/goleak) | `2023-10-24` |
| gomod | [gopkg.in/yaml.v2](https://redirect.github.com/go-yaml/yaml) | `2022-05-27` |
| gomod | [gopkg.in/yaml.v3](https://redirect.github.com/go-yaml/yaml) | `2022-05-27` |
## Rate-Limited
The following updates are currently rate-limited. To force their creation now, click on a checkbox below.
- [ ] chore(deps): update google.golang.org/genproto digest to f61a6ca
- [ ] fix(deps): update github.com/thanos-io/objstore digest to 44aca71
- [ ] chore(deps): update module google.golang.org/protobuf to v1.36.12
- [ ] chore(deps): update module gopkg.in/ini.v1 to v1.67.3
- [ ] fix(deps): update module github.com/prometheus/client_model to v0.6.3
- [ ] chore(deps): update aws-sdk-go-v2 monorepo (`github.com/aws/aws-sdk-go-v2`, `github.com/aws/aws-sdk-go-v2/config`, `github.com/aws/aws-sdk-go-v2/credentials`, `github.com/aws/aws-sdk-go-v2/feature/ec2/imds`, `github.com/aws/aws-sdk-go-v2/internal/configsources`, `github.com/aws/aws-sdk-go-v2/internal/endpoints/v2`, `github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding`, `github.com/aws/aws-sdk-go-v2/service/internal/presigned-url`, `github.com/aws/aws-sdk-go-v2/service/signin`, `github.com/aws/aws-sdk-go-v2/service/sso`, `github.com/aws/aws-sdk-go-v2/service/ssooidc`, `github.com/aws/aws-sdk-go-v2/service/sts`)
- [ ] chore(deps): update module cloud.google.com/go to v0.123.0
- [ ] chore(deps): update module cloud.google.com/go/iam to v1.13.0
- [ ] chore(deps): update module cloud.google.com/go/storage to v1.67.1
- [ ] chore(deps): update module github.com/aws/smithy-go to v1.28.1
- [ ] chore(deps): update module github.com/googlecloudplatform/opentelemetry-operations-go/exporter/metric to v0.62.0
- [ ] chore(deps): update module github.com/minio/minio-go/v7 to v7.3.0
- [ ] chore(deps): update module github.com/prometheus/client_golang to v1.24.1
- [ ] chore(deps): update module github.com/prometheus/procfs to v0.22.0
- [ ] chore(deps): update module github.com/rogpeppe/go-internal to v1.16.0
- [ ] chore(deps): update module github.com/rs/xid to v1.6.0
- [ ] chore(deps): update module github.com/sirupsen/logrus to v1.10.2
- [ ] chore(deps): update module github.com/spiffe/go-spiffe/v2 to v2.8.1
- [ ] chore(deps): update module github.com/twmb/franz-go/pkg/kmsg to v1.13.1
- [ ] chore(deps): update module go.opentelemetry.io/otel/sdk/metric to v1.46.0
- [ ] chore(deps): update module golang.org/x/sync to v0.23.0
- [ ] chore(deps): update opentelemetry-go-contrib monorepo (`go.opentelemetry.io/contrib/detectors/gcp`, `go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc`)
- [ ] fix(deps): update module github.com/prometheus/common to v0.71.0
- [ ] fix(deps): update module github.com/prometheus/prometheus to v0.314.0
- [ ] fix(deps): update module github.com/stretchr/testify to v1.12.1
- [ ] chore(deps): update actions/setup-go action to v7
- [ ] chore(deps): update module github.com/klauspost/cpuid to v2
- [ ] chore(deps): update module github.com/minio/sha256-simd to v1
- [ ] chore(deps): update module github.com/twmb/franz-go/pkg/kmsg to v2
- [ ] chore(deps): update module go.yaml.in/yaml/v2 to v3
- [ ] chore(deps): update module gopkg.in/yaml.v2 to v3
- [ ] π **Create all rate-limited PRs at once** π
## Pending Status Checks
The following updates await pending status checks. To force their creation now, click on a checkbox below.
- [ ] [fix(deps): update github.com/grafana/dskit digest to 407dda1](../pull/100)
## Open
The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.
- [ ] [fix(security/unknown/): update module github.com/klauspost/compress to v1.18.7 [security]](../pull/121)
- [ ] [fix(security/unknown/): update module golang.org/x/crypto to v0.56.0 [security]](../pull/106)
- [ ] [fix(security/unknown/): update module golang.org/x/net to v0.56.0 [security]](../pull/107)
- [ ] [fix(security/unknown/): update module golang.org/x/sys to v0.44.0 [security]](../pull/108)
- [ ] [fix(security/unknown/): update module golang.org/x/text to v0.39.0 [security]](../pull/119)
- [ ] [chore(deps): pin dependencies](../pull/99) (`actions/checkout`, `actions/setup-go`)
- [ ] [chore(deps): update github.com/efficientgo/tools/core digest to 6b73929](../pull/116)
- [ ] [chore(deps): update module github.com/dustin/go-humanize to v1.0.1](../pull/117)
- [ ] [chore(deps): update module github.com/go-logfmt/logfmt to v0.6.1](../pull/120)
- [ ] [chore(deps): update module github.com/minio/md5-simd to v1.1.2](../pull/122)
- [ ] [chore(deps): update module github.com/minio/sha256-simd to v0.1.2](../pull/123)
- [ ] [chore(deps): update module github.com/pierrec/lz4/v4 to v4.1.29](../pull/124)
- [ ] [fix(deps): update module github.com/twmb/franz-go to v1.21.6](../pull/102)
- [ ] [chore(deps): update actions/checkout action to v7](../pull/114)
- [ ] **Click on this checkbox to rebase all open PRs at once**
## PR Closed (Blocked)
The following updates are blocked by an existing closed PR. To recreate the PR, click on a checkbox below.
- [ ] [fix(deps): update module github.com/twmb/franz-go/pkg/kadm to v1.18.0](../pull/69)
## Vulnerabilities
> [!IMPORTANT]
> `41`/`42` CVEs have Renovate fixes.
gomod
go.mod
github.com/klauspost/compress
- [GO-2026-5841](https://osv.dev/vulnerability/GO-2026-5841) (fixed in >= 1.18.7)
golang.org/x/crypto
- [GHSA-45gg-vh54-h5m9](https://osv.dev/vulnerability/GHSA-45gg-vh54-h5m9) (fixed in >= 0.52.0)
- [GHSA-5cgq-3rg8-m6cv](https://osv.dev/vulnerability/GHSA-5cgq-3rg8-m6cv) (fixed in >= 0.52.0)
- [GHSA-78mq-xcr3-xm33](https://osv.dev/vulnerability/GHSA-78mq-xcr3-xm33) (fixed in >= 0.52.0)
- [GHSA-89gr-r52h-f8rx](https://osv.dev/vulnerability/GHSA-89gr-r52h-f8rx) (fixed in >= 0.52.0)
- [GHSA-9m57-25v3-79x9](https://osv.dev/vulnerability/GHSA-9m57-25v3-79x9) (fixed in >= 0.52.0)
- [GHSA-f5wc-c3c7-36mc](https://osv.dev/vulnerability/GHSA-f5wc-c3c7-36mc) (fixed in >= 0.52.0)
- [GHSA-jppx-rxg9-jmrx](https://osv.dev/vulnerability/GHSA-jppx-rxg9-jmrx) (fixed in >= 0.52.0)
- [GHSA-q4h4-gmj2-qvw2](https://osv.dev/vulnerability/GHSA-q4h4-gmj2-qvw2) (fixed in >= 0.52.0)
- [GHSA-qpw4-5x99-6vjp](https://osv.dev/vulnerability/GHSA-qpw4-5x99-6vjp) (fixed in >= 0.52.0)
- [GHSA-rm3j-f69w-wqmq](https://osv.dev/vulnerability/GHSA-rm3j-f69w-wqmq) (fixed in >= 0.52.0)
- [GHSA-vgwf-h737-ff37](https://osv.dev/vulnerability/GHSA-vgwf-h737-ff37) (fixed in >= 0.52.0)
- [GHSA-w879-237q-wc7r](https://osv.dev/vulnerability/GHSA-w879-237q-wc7r) (fixed in >= 0.52.0)
- [GHSA-x527-x647-q7gg](https://osv.dev/vulnerability/GHSA-x527-x647-q7gg) (fixed in >= 0.52.0)
- [GO-2026-5005](https://osv.dev/vulnerability/GO-2026-5005) (fixed in >= 0.52.0)
- [GO-2026-5006](https://osv.dev/vulnerability/GO-2026-5006) (fixed in >= 0.52.0)
- [GO-2026-5013](https://osv.dev/vulnerability/GO-2026-5013) (fixed in >= 0.52.0)
- [GO-2026-5014](https://osv.dev/vulnerability/GO-2026-5014) (fixed in >= 0.52.0)
- [GO-2026-5015](https://osv.dev/vulnerability/GO-2026-5015) (fixed in >= 0.52.0)
- [GO-2026-5016](https://osv.dev/vulnerability/GO-2026-5016) (fixed in >= 0.52.0)
- [GO-2026-5017](https://osv.dev/vulnerability/GO-2026-5017) (fixed in >= 0.52.0)
- [GO-2026-5018](https://osv.dev/vulnerability/GO-2026-5018) (fixed in >= 0.52.0)
- [GO-2026-5019](https://osv.dev/vulnerability/GO-2026-5019) (fixed in >= 0.52.0)
- [GO-2026-5020](https://osv.dev/vulnerability/GO-2026-5020) (fixed in >= 0.52.0)
- [GO-2026-5021](https://osv.dev/vulnerability/GO-2026-5021) (fixed in >= 0.52.0)
- [GO-2026-5023](https://osv.dev/vulnerability/GO-2026-5023) (fixed in >= 0.52.0)
- [GO-2026-5033](https://osv.dev/vulnerability/GO-2026-5033) (fixed in >= 0.52.0)
- [GO-2026-5932](https://osv.dev/vulnerability/GO-2026-5932)
- [GO-2026-6303](https://osv.dev/vulnerability/GO-2026-6303) (fixed in >= 0.55.0)
- [GO-2026-6354](https://osv.dev/vulnerability/GO-2026-6354) (fixed in >= 0.56.0)
- [GO-2026-6355](https://osv.dev/vulnerability/GO-2026-6355) (fixed in >= 0.56.0)golang.org/x/net
- [GHSA-5cv4-jp36-h3mw](https://osv.dev/vulnerability/GHSA-5cv4-jp36-h3mw) (fixed in >= 0.55.0)
- [GO-2026-4918](https://osv.dev/vulnerability/GO-2026-4918) (fixed in >= 0.53.0)
- [GO-2026-5025](https://osv.dev/vulnerability/GO-2026-5025) (fixed in >= 0.55.0)
- [GO-2026-5026](https://osv.dev/vulnerability/GO-2026-5026) (fixed in >= 0.55.0)
- [GO-2026-5027](https://osv.dev/vulnerability/GO-2026-5027) (fixed in >= 0.55.0)
- [GO-2026-5028](https://osv.dev/vulnerability/GO-2026-5028) (fixed in >= 0.55.0)
- [GO-2026-5029](https://osv.dev/vulnerability/GO-2026-5029) (fixed in >= 0.55.0)
- [GO-2026-5030](https://osv.dev/vulnerability/GO-2026-5030) (fixed in >= 0.55.0)
- [GO-2026-5942](https://osv.dev/vulnerability/GO-2026-5942) (fixed in >= 0.56.0)golang.org/x/sys
- [GO-2026-5024](https://osv.dev/vulnerability/GO-2026-5024) (fixed in >= 0.44.0)
golang.org/x/text
- [GO-2026-5970](https://osv.dev/vulnerability/GO-2026-5970) (fixed in >= 0.39.0)
## Detected Dependencies
github-actions (1)
.github/workflows/ci.yaml (12)
- `actions/checkout v5` β [Updates: `v7`, `v5`]
- `actions/setup-go v5` β [Updates: `v7`, `v5`]
- `actions/checkout v5` β [Updates: `v7`, `v5`]
- `actions/setup-go v5` β [Updates: `v7`, `v5`]
- `actions/checkout v5` β [Updates: `v7`, `v5`]
- `actions/setup-go v5` β [Updates: `v7`, `v5`]
- `ubuntu 24.04`
- `go 1.25.7`
- `ubuntu 24.04`
- `go 1.25.7`
- `ubuntu 24.04`
- `go 1.25.7`
gomod (1)
go.mod (73)
- `go 1.25.5`
- `github.com/go-kit/log v0.2.1`
- `github.com/grafana/dskit v0.0.0-20230914143233-4b32fbf08128@4b32fbf08128` β [Updates: `v0.0.0-20230914143233-4b32fbf08128`]
- `github.com/prometheus/client_model v0.6.2` β [Updates: `v0.6.3`]
- `github.com/prometheus/common v0.67.5` β [Updates: `v0.71.0`]
- `github.com/prometheus/prometheus v0.311.3` β [Updates: `v0.314.0`]
- `github.com/stretchr/testify v1.11.1` β [Updates: `v1.12.1`]
- `github.com/thanos-io/objstore v0.0.0-20220809103346-8ef1f215e2bf@8ef1f215e2bf` β [Updates: `v0.0.0-20260907152334-44aca71316b7`]
- `github.com/twmb/franz-go v1.15.4` β [Updates: `v1.21.6`]
- `github.com/twmb/franz-go/pkg/kadm v1.10.0` β [Updates: `v1.18.0`]
- `gopkg.in/yaml.v3 v3.0.1`
- `cloud.google.com/go v0.120.0` β [Updates: `v0.123.0`]
- `cloud.google.com/go/iam v1.5.2` β [Updates: `v1.13.0`]
- `cloud.google.com/go/storage v1.50.0` β [Updates: `v1.67.1`]
- `github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.50.0` β [Updates: `v0.62.0`]
- `github.com/aws/aws-sdk-go-v2 v1.41.4` β [Updates: `v1.47.0`]
- `github.com/aws/aws-sdk-go-v2/config v1.32.12` β [Updates: `v1.33.4`]
- `github.com/aws/aws-sdk-go-v2/credentials v1.19.12` β [Updates: `v1.20.4`]
- `github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.20` β [Updates: `v1.20.0`]
- `github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.20` β [Updates: `v1.5.3`]
- `github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.20` β [Updates: `v2.8.3`]
- `github.com/aws/aws-sdk-go-v2/internal/ini v1.8.6`
- `github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.7` β [Updates: `v1.13.19`]
- `github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.20` β [Updates: `v1.14.3`]
- `github.com/aws/aws-sdk-go-v2/service/signin v1.0.8` β [Updates: `v1.10.0`]
- `github.com/aws/aws-sdk-go-v2/service/sso v1.30.13` β [Updates: `v1.38.0`]
- `github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.17` β [Updates: `v1.43.0`]
- `github.com/aws/aws-sdk-go-v2/service/sts v1.41.9` β [Updates: `v1.50.0`]
- `github.com/aws/smithy-go v1.24.2` β [Updates: `v1.28.1`]
- `github.com/beorn7/perks v1.0.1`
- `github.com/cespare/xxhash/v2 v2.3.0`
- `github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc@d8f796af33cc`
- `github.com/dustin/go-humanize v1.0.0` β [Updates: `v1.0.1`]
- `github.com/efficientgo/tools/core v0.0.0-20220225185207-fe763185946b@fe763185946b` β [Updates: `v0.0.0-20230505153745-6b7392939a60`]
- `github.com/go-logfmt/logfmt v0.6.0` β [Updates: `v0.6.1`]
- `github.com/gogo/protobuf v1.3.2`
- `github.com/google/uuid v1.6.0`
- `github.com/grafana/regexp v0.0.0-20250905093917-f7b3be9d1853@f7b3be9d1853`
- `github.com/json-iterator/go v1.1.12`
- `github.com/klauspost/compress v1.18.5` β [Updates: `v1.18.7`]
- `github.com/klauspost/cpuid v1.3.1` β [Updates: `v2.4.0`]
- `github.com/minio/md5-simd v1.1.0` β [Updates: `v1.1.2`]
- `github.com/minio/minio-go/v7 v7.0.23` β [Updates: `v7.3.0`]
- `github.com/minio/sha256-simd v0.1.1` β [Updates: `v0.1.2`, `v1.0.1`]
- `github.com/mitchellh/go-homedir v1.1.0`
- `github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd@bacd9c7ef1dd`
- `github.com/modern-go/reflect2 v1.0.3-0.20250322232337-35a7c28c31ee@35a7c28c31ee`
- `github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822@a7dc8b61c822`
- `github.com/opentracing/opentracing-go v1.2.0`
- `github.com/pierrec/lz4/v4 v4.1.19` β [Updates: `v4.1.29`]
- `github.com/pkg/errors v0.9.1`
- `github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2@5d4384ee4fb2`
- `github.com/prometheus/client_golang v1.23.2` β [Updates: `v1.24.1`]
- `github.com/prometheus/procfs v0.17.0` β [Updates: `v0.22.0`]
- `github.com/rogpeppe/go-internal v1.13.1` β [Updates: `v1.16.0`]
- `github.com/rs/xid v1.2.1` β [Updates: `v1.6.0`]
- `github.com/sirupsen/logrus v1.9.4` β [Updates: `v1.10.2`]
- `github.com/spiffe/go-spiffe/v2 v2.6.0` β [Updates: `v2.8.1`]
- `github.com/twmb/franz-go/pkg/kmsg v1.7.0` β [Updates: `v1.13.1`, `v2.0.1`]
- `go.opentelemetry.io/contrib/detectors/gcp v1.34.0` β [Updates: `v1.46.0`]
- `go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.61.0` β [Updates: `v0.71.0`]
- `go.opentelemetry.io/otel/sdk/metric v1.34.0` β [Updates: `v1.46.0`]
- `go.uber.org/goleak v1.3.0`
- `go.yaml.in/yaml/v2 v2.4.4` β [Updates: `v3.0.5`]
- `golang.org/x/crypto v0.49.0` β [Updates: `v0.56.0`]
- `golang.org/x/net v0.52.0` β [Updates: `v0.56.0`]
- `golang.org/x/sync v0.20.0` β [Updates: `v0.23.0`]
- `golang.org/x/sys v0.42.0` β [Updates: `v0.44.0`]
- `golang.org/x/text v0.35.0` β [Updates: `v0.39.0`]
- `google.golang.org/genproto v0.0.0-20250603155806-513f23925822@513f23925822` β [Updates: `v0.0.0-20260911204522-f61a6ca850bd`]
- `google.golang.org/protobuf v1.36.11` β [Updates: `v1.36.12`]
- `gopkg.in/ini.v1 v1.67.1` β [Updates: `v1.67.3`]
- `gopkg.in/yaml.v2 v2.4.0` β [Updates: `v3.0.1`]
---
## Need help?
You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with the Renovate Dependency Dashboard documentation and the repository's go.mod and GitHub Actions references. The issue lists many abandoned, rate-limited, vulnerable, and already-created dependency updates, with linked pull requests. There is no single requested change or defined completion condition; the existing pull requests indicate that the work is already underway.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions, go
- Domain
- devops, tooling
- Issue type
- Refactor
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 10/100