grafana / grafana/jsonnet-language-server
Dependency Dashboard
- Dominant language
- Go
- Stars
- 223
- Forks
- 33
- PR merge metrics
- No merged PRs in 30d
Description
This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.
## Abandoned Dependencies
The following dependencies have not received updates for an extended period and may be unmaintained.
View abandoned dependencies (15)
> [!NOTE]
Packages are marked as abandoned when they exceed the [`abandonmentThreshold`](https://docs.renovatebot.com/configuration-options/#abandonmentthreshold) since their last release. Unlike deprecated packages with official notices, abandonment is detected by release inactivity.
>
| Datasource | Package | Last Updated |
|------------|------|-------------|
| gomod | [github.com/Masterminds/goutils](https://redirect.github.com/Masterminds/goutils) | `2021-02-04` |
| gomod | [github.com/Masterminds/sprig/v3](https://redirect.github.com/Masterminds/sprig) | `2024-08-29` |
| gomod | [github.com/davecgh/go-spew](https://redirect.github.com/davecgh/go-spew) | `2018-02-21` |
| gomod | [github.com/google/uuid](https://redirect.github.com/google/uuid) | `2024-01-23` |
| gomod | [github.com/hexops/gotextdiff](https://redirect.github.com/hexops/gotextdiff) | `2020-12-13` |
| gomod | [github.com/jdbaldry/go-language-server-protocol](https://redirect.github.com/jdbaldry/go-language-server-protocol) | `2021-10-13` |
| gomod | [github.com/mitchellh/copystructure](https://redirect.github.com/mitchellh/copystructure) | `2021-05-05` |
| gomod | [github.com/mitchellh/mapstructure](https://redirect.github.com/mitchellh/mapstructure) | `2022-04-20` |
| gomod | [github.com/mitchellh/reflectwalk](https://redirect.github.com/mitchellh/reflectwalk) | `2021-05-03` |
| gomod | [github.com/pkg/errors](https://redirect.github.com/pkg/errors) | `2020-01-14` |
| gomod | [github.com/pmezard/go-difflib](https://redirect.github.com/pmezard/go-difflib) | `2016-01-10` |
| gomod | [github.com/shopspring/decimal](https://redirect.github.com/shopspring/decimal) | `2024-04-12` |
| gomod | [golang.org/x/xerrors](https://go.googlesource.com/xerrors) | `2024-09-03` |
| gomod | [gopkg.in/yaml.v2](https://redirect.github.com/go-yaml/yaml) | `2022-05-27` |
| gomod | [gopkg.in/yaml.v3](https://redirect.github.com/go-yaml/yaml) | `2022-05-27` |
## Rate-Limited
The following updates are currently rate-limited. To force their creation now, click on a checkbox below.
- [ ] chore(deps): pin dependencies (`github.com/grafana/grafonnet/gen/grafonnet-latest`, `github.com/grafana/jsonnet-libs/ksonnet-util`, `github.com/jsonnet-libs/k8s-libsonnet/1.30`)
- [ ] chore(deps): update module github.com/mattn/go-isatty to v0.0.24
- [ ] chore(deps): update module github.com/stretchr/objx to v0.5.3
- [ ] chore(deps): update module github.com/fatih/color to v1.19.0
- [ ] chore(deps): update module github.com/masterminds/semver/v3 to v3.5.0
- [ ] chore(deps): update module github.com/puerkitobio/goquery to v1.13.0
- [ ] chore(deps): update module github.com/rs/zerolog to v1.35.1
- [ ] chore(deps): update module github.com/spf13/cast to v1.10.0
- [ ] chore(deps): update module sigs.k8s.io/yaml to v1.6.0
- [ ] fix(deps): update module github.com/google/go-jsonnet to v0.22.0
- [ ] fix(deps): update module github.com/sirupsen/logrus to v1.10.2
- [ ] fix(deps): update module github.com/stretchr/testify to v1.12.1
- [ ] chore(deps): update actions/checkout action to v7
- [ ] chore(deps): update actions/setup-go action to v7
- [ ] chore(deps): update module github.com/gobwas/glob to v1
- [ ] chore(deps): update module gopkg.in/yaml.v2 to v3
- [ ] chore(deps): lock file maintenance
- [ ] π **Create all rate-limited PRs at once** π
## Pending Status Checks
The following updates await pending status checks. To force their creation now, click on a checkbox below.
- [ ] chore(deps): update module github.com/huandu/xstrings to v1.6.0
## Open
The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.
- [ ] [fix(security/unknown/): update go toolchain directive to v1.25.13 [security]](../pull/261)
- [ ] [fix(security/unknown/): update module golang.org/x/crypto to v0.56.0 [security]](../pull/262)
- [ ] [fix(security/unknown/): update module golang.org/x/net to v0.56.0 [security]](../pull/263)
- [ ] [fix(security/unknown/): update module golang.org/x/sys to v0.44.0 [security]](../pull/264)
- [ ] [chore(deps): update golang.org/x/xerrors digest to 7835f81](../pull/269)
- [ ] [chore(deps): update module dario.cat/mergo to v1.0.2](../pull/272)
- [ ] [chore(deps): update module github.com/andybalholm/cascadia to v1.3.5](../pull/273)
- [ ] [chore(deps): update module github.com/mattn/go-colorable to v0.1.15](../pull/274)
- [ ] [chore(deps): update actions/checkout action to v4.4.0](../pull/255)
- [ ] [chore(deps): update actions/setup-go action to v5.6.0](../pull/256)
- [ ] [chore(deps): update goreleaser/goreleaser-action action to v6.4.0](../pull/257)
- [ ] [fix(deps): update module github.com/grafana/tanka to v0.39.0](../pull/259)
- [ ] [chore(deps): update goreleaser/goreleaser-action action to v7](../pull/260)
- [ ] [fix(deps): update module github.com/johanneskaufmann/html-to-markdown to v2](../pull/265)
- [ ] **Click on this checkbox to rebase all open PRs at once**
## PR Closed (Blocked)
The following updates are blocked by an existing closed PR. To recreate the PR, click on a checkbox below.
- [ ] [chore(deps): update golangci/golangci-lint-action action to v9](../pull/246)
## Vulnerabilities
> [!IMPORTANT]
> `90`/`91` CVEs have Renovate fixes.
gomod
go.mod
go
- [GO-2025-3749](https://osv.dev/vulnerability/GO-2025-3749) (fixed in >= 1.24.4)
- [GO-2025-3750](https://osv.dev/vulnerability/GO-2025-3750) (fixed in >= 1.24.4)
- [GO-2025-3751](https://osv.dev/vulnerability/GO-2025-3751) (fixed in >= 1.24.4)
- [GO-2025-3849](https://osv.dev/vulnerability/GO-2025-3849) (fixed in >= 1.24.6)
- [GO-2025-3956](https://osv.dev/vulnerability/GO-2025-3956) (fixed in >= 1.24.6)
- [GO-2025-4006](https://osv.dev/vulnerability/GO-2025-4006) (fixed in >= 1.24.8)
- [GO-2025-4007](https://osv.dev/vulnerability/GO-2025-4007) (fixed in >= 1.24.9)
- [GO-2025-4008](https://osv.dev/vulnerability/GO-2025-4008) (fixed in >= 1.24.8)
- [GO-2025-4009](https://osv.dev/vulnerability/GO-2025-4009) (fixed in >= 1.24.8)
- [GO-2025-4010](https://osv.dev/vulnerability/GO-2025-4010) (fixed in >= 1.24.8)
- [GO-2025-4011](https://osv.dev/vulnerability/GO-2025-4011) (fixed in >= 1.24.8)
- [GO-2025-4012](https://osv.dev/vulnerability/GO-2025-4012) (fixed in >= 1.24.8)
- [GO-2025-4013](https://osv.dev/vulnerability/GO-2025-4013) (fixed in >= 1.24.8)
- [GO-2025-4014](https://osv.dev/vulnerability/GO-2025-4014) (fixed in >= 1.24.8)
- [GO-2025-4015](https://osv.dev/vulnerability/GO-2025-4015) (fixed in >= 1.24.8)
- [GO-2025-4155](https://osv.dev/vulnerability/GO-2025-4155) (fixed in >= 1.24.11)
- [GO-2025-4175](https://osv.dev/vulnerability/GO-2025-4175) (fixed in >= 1.24.11)
- [GO-2026-4337](https://osv.dev/vulnerability/GO-2026-4337) (fixed in >= 1.24.13)
- [GO-2026-4340](https://osv.dev/vulnerability/GO-2026-4340) (fixed in >= 1.24.12)
- [GO-2026-4341](https://osv.dev/vulnerability/GO-2026-4341) (fixed in >= 1.24.12)
- [GO-2026-4342](https://osv.dev/vulnerability/GO-2026-4342) (fixed in >= 1.24.12)
- [GO-2026-4403](https://osv.dev/vulnerability/GO-2026-4403) (fixed in >= 1.24.3)
- [GO-2026-4601](https://osv.dev/vulnerability/GO-2026-4601) (fixed in >= 1.25.8)
- [GO-2026-4602](https://osv.dev/vulnerability/GO-2026-4602) (fixed in >= 1.25.8)
- [GO-2026-4603](https://osv.dev/vulnerability/GO-2026-4603) (fixed in >= 1.25.8)
- [GO-2026-4864](https://osv.dev/vulnerability/GO-2026-4864) (fixed in >= 1.25.9)
- [GO-2026-4865](https://osv.dev/vulnerability/GO-2026-4865) (fixed in >= 1.25.9)
- [GO-2026-4869](https://osv.dev/vulnerability/GO-2026-4869) (fixed in >= 1.25.9)
- [GO-2026-4870](https://osv.dev/vulnerability/GO-2026-4870) (fixed in >= 1.25.9)
- [GO-2026-4918](https://osv.dev/vulnerability/GO-2026-4918) (fixed in >= 1.25.10)
- [GO-2026-4946](https://osv.dev/vulnerability/GO-2026-4946) (fixed in >= 1.25.9)
- [GO-2026-4947](https://osv.dev/vulnerability/GO-2026-4947) (fixed in >= 1.25.9)
- [GO-2026-4970](https://osv.dev/vulnerability/GO-2026-4970) (fixed in >= 1.25.12)
- [GO-2026-4971](https://osv.dev/vulnerability/GO-2026-4971) (fixed in >= 1.25.10)
- [GO-2026-4976](https://osv.dev/vulnerability/GO-2026-4976) (fixed in >= 1.25.10)
- [GO-2026-4977](https://osv.dev/vulnerability/GO-2026-4977) (fixed in >= 1.25.10)
- [GO-2026-4980](https://osv.dev/vulnerability/GO-2026-4980) (fixed in >= 1.25.10)
- [GO-2026-4981](https://osv.dev/vulnerability/GO-2026-4981) (fixed in >= 1.25.10)
- [GO-2026-4982](https://osv.dev/vulnerability/GO-2026-4982) (fixed in >= 1.25.10)
- [GO-2026-4986](https://osv.dev/vulnerability/GO-2026-4986) (fixed in >= 1.25.10)
- [GO-2026-5026](https://osv.dev/vulnerability/GO-2026-5026) (fixed in >= 1.25.13)
- [GO-2026-5037](https://osv.dev/vulnerability/GO-2026-5037) (fixed in >= 1.25.11)
- [GO-2026-5038](https://osv.dev/vulnerability/GO-2026-5038) (fixed in >= 1.25.11)
- [GO-2026-5039](https://osv.dev/vulnerability/GO-2026-5039) (fixed in >= 1.25.11)
- [GO-2026-5856](https://osv.dev/vulnerability/GO-2026-5856) (fixed in >= 1.25.12)
- [GO-2026-5972](https://osv.dev/vulnerability/GO-2026-5972) (fixed in >= 1.25.13)
- [GO-2026-6088](https://osv.dev/vulnerability/GO-2026-6088) (fixed in >= 1.25.13)
- [GO-2026-6089](https://osv.dev/vulnerability/GO-2026-6089) (fixed in >= 1.25.13)
- [GO-2026-6090](https://osv.dev/vulnerability/GO-2026-6090) (fixed in >= 1.25.13)
- [GO-2026-6091](https://osv.dev/vulnerability/GO-2026-6091) (fixed in >= 1.25.13)
- [GO-2026-6218](https://osv.dev/vulnerability/GO-2026-6218) (fixed in >= 1.25.13)golang.org/x/crypto
- [GHSA-45gg-vh54-h5m9](https://osv.dev/vulnerability/GHSA-45gg-vh54-h5m9) (fixed in >= 0.52.0)
- [GHSA-5cgq-3rg8-m6cv](https://osv.dev/vulnerability/GHSA-5cgq-3rg8-m6cv) (fixed in >= 0.52.0)
- [GHSA-78mq-xcr3-xm33](https://osv.dev/vulnerability/GHSA-78mq-xcr3-xm33) (fixed in >= 0.52.0)
- [GHSA-89gr-r52h-f8rx](https://osv.dev/vulnerability/GHSA-89gr-r52h-f8rx) (fixed in >= 0.52.0)
- [GHSA-9m57-25v3-79x9](https://osv.dev/vulnerability/GHSA-9m57-25v3-79x9) (fixed in >= 0.52.0)
- [GHSA-f5wc-c3c7-36mc](https://osv.dev/vulnerability/GHSA-f5wc-c3c7-36mc) (fixed in >= 0.52.0)
- [GHSA-jppx-rxg9-jmrx](https://osv.dev/vulnerability/GHSA-jppx-rxg9-jmrx) (fixed in >= 0.52.0)
- [GHSA-q4h4-gmj2-qvw2](https://osv.dev/vulnerability/GHSA-q4h4-gmj2-qvw2) (fixed in >= 0.52.0)
- [GHSA-qpw4-5x99-6vjp](https://osv.dev/vulnerability/GHSA-qpw4-5x99-6vjp) (fixed in >= 0.52.0)
- [GHSA-rm3j-f69w-wqmq](https://osv.dev/vulnerability/GHSA-rm3j-f69w-wqmq) (fixed in >= 0.52.0)
- [GHSA-vgwf-h737-ff37](https://osv.dev/vulnerability/GHSA-vgwf-h737-ff37) (fixed in >= 0.52.0)
- [GHSA-w879-237q-wc7r](https://osv.dev/vulnerability/GHSA-w879-237q-wc7r) (fixed in >= 0.52.0)
- [GHSA-x527-x647-q7gg](https://osv.dev/vulnerability/GHSA-x527-x647-q7gg) (fixed in >= 0.52.0)
- [GO-2026-5005](https://osv.dev/vulnerability/GO-2026-5005) (fixed in >= 0.52.0)
- [GO-2026-5006](https://osv.dev/vulnerability/GO-2026-5006) (fixed in >= 0.52.0)
- [GO-2026-5013](https://osv.dev/vulnerability/GO-2026-5013) (fixed in >= 0.52.0)
- [GO-2026-5014](https://osv.dev/vulnerability/GO-2026-5014) (fixed in >= 0.52.0)
- [GO-2026-5015](https://osv.dev/vulnerability/GO-2026-5015) (fixed in >= 0.52.0)
- [GO-2026-5016](https://osv.dev/vulnerability/GO-2026-5016) (fixed in >= 0.52.0)
- [GO-2026-5017](https://osv.dev/vulnerability/GO-2026-5017) (fixed in >= 0.52.0)
- [GO-2026-5018](https://osv.dev/vulnerability/GO-2026-5018) (fixed in >= 0.52.0)
- [GO-2026-5019](https://osv.dev/vulnerability/GO-2026-5019) (fixed in >= 0.52.0)
- [GO-2026-5020](https://osv.dev/vulnerability/GO-2026-5020) (fixed in >= 0.52.0)
- [GO-2026-5021](https://osv.dev/vulnerability/GO-2026-5021) (fixed in >= 0.52.0)
- [GO-2026-5023](https://osv.dev/vulnerability/GO-2026-5023) (fixed in >= 0.52.0)
- [GO-2026-5033](https://osv.dev/vulnerability/GO-2026-5033) (fixed in >= 0.52.0)
- [GO-2026-5932](https://osv.dev/vulnerability/GO-2026-5932)
- [GO-2026-6303](https://osv.dev/vulnerability/GO-2026-6303) (fixed in >= 0.55.0)
- [GO-2026-6354](https://osv.dev/vulnerability/GO-2026-6354) (fixed in >= 0.56.0)
- [GO-2026-6355](https://osv.dev/vulnerability/GO-2026-6355) (fixed in >= 0.56.0)golang.org/x/net
- [GHSA-5cv4-jp36-h3mw](https://osv.dev/vulnerability/GHSA-5cv4-jp36-h3mw) (fixed in >= 0.55.0)
- [GO-2026-4918](https://osv.dev/vulnerability/GO-2026-4918) (fixed in >= 0.53.0)
- [GO-2026-5025](https://osv.dev/vulnerability/GO-2026-5025) (fixed in >= 0.55.0)
- [GO-2026-5026](https://osv.dev/vulnerability/GO-2026-5026) (fixed in >= 0.55.0)
- [GO-2026-5027](https://osv.dev/vulnerability/GO-2026-5027) (fixed in >= 0.55.0)
- [GO-2026-5028](https://osv.dev/vulnerability/GO-2026-5028) (fixed in >= 0.55.0)
- [GO-2026-5029](https://osv.dev/vulnerability/GO-2026-5029) (fixed in >= 0.55.0)
- [GO-2026-5030](https://osv.dev/vulnerability/GO-2026-5030) (fixed in >= 0.55.0)
- [GO-2026-5942](https://osv.dev/vulnerability/GO-2026-5942) (fixed in >= 0.56.0)golang.org/x/sys
- [GO-2026-5024](https://osv.dev/vulnerability/GO-2026-5024) (fixed in >= 0.44.0)
## Detected Dependencies
github-actions (4)
.github/workflows/golangci-lint.yml (3)
- `actions/checkout v4.2.2@11bd71901bbe5b1630ceea73d27597364c9af683` β [Updates: `v4.4.0`, `v7.0.1`]
- `golangci/golangci-lint-action v8.0.0@4afd733a84b1f43292c63897423277bb7f4313a9` β [Updates: `v9.3.0`]
- `golangci/golangci-lint latest`.github/workflows/jsonnetfmt.yml (2)
- `actions/checkout v4.2.2@11bd71901bbe5b1630ceea73d27597364c9af683` β [Updates: `v4.4.0`, `v7.0.1`]
- `actions/setup-go v5.5.0@d35c59abb061a4a6fb18e82ac0862c26744d6ab5` β [Updates: `v5.6.0`, `v7.0.0`].github/workflows/release.yml (3)
- `actions/checkout v4.2.2@11bd71901bbe5b1630ceea73d27597364c9af683` β [Updates: `v4.4.0`, `v7.0.1`]
- `actions/setup-go v5.5.0@d35c59abb061a4a6fb18e82ac0862c26744d6ab5` β [Updates: `v5.6.0`, `v7.0.0`]
- `goreleaser/goreleaser-action v6.3.0@9c156ee8a17a598857849441385a2041ef570552` β [Updates: `v6.4.0`, `v7.2.3`].github/workflows/test.yml (2)
- `actions/checkout v4.2.2@11bd71901bbe5b1630ceea73d27597364c9af683` β [Updates: `v4.4.0`, `v7.0.1`]
- `actions/setup-go v5.5.0@d35c59abb061a4a6fb18e82ac0862c26744d6ab5` β [Updates: `v5.6.0`, `v7.0.0`]
gomod (1)
go.mod (38)
- `go 1.24.0`
- `go 1.24.2` β [Updates: `1.25.13`]
- `github.com/JohannesKaufmann/html-to-markdown v1.6.0` β [Updates: `v2.5.2`]
- `github.com/google/go-jsonnet v0.21.0` β [Updates: `v0.22.0`]
- `github.com/grafana/tanka v0.32.1-0.20250521123240-fa219d35d24f@fa219d35d24f` β [Updates: `v0.39.0`]
- `github.com/hexops/gotextdiff v1.0.3`
- `github.com/jdbaldry/go-language-server-protocol v0.0.0-20211013214444-3022da0884b2@3022da0884b2`
- `github.com/mitchellh/mapstructure v1.5.0`
- `github.com/sirupsen/logrus v1.9.3` β [Updates: `v1.10.2`]
- `github.com/stretchr/testify v1.10.0` β [Updates: `v1.12.1`]
- `dario.cat/mergo v1.0.1` β [Updates: `v1.0.2`]
- `github.com/Masterminds/goutils v1.1.1`
- `github.com/Masterminds/semver/v3 v3.3.0` β [Updates: `v3.5.0`]
- `github.com/Masterminds/sprig/v3 v3.3.0`
- `github.com/PuerkitoBio/goquery v1.9.2` β [Updates: `v1.13.0`]
- `github.com/andybalholm/cascadia v1.3.2` β [Updates: `v1.3.5`]
- `github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc@d8f796af33cc`
- `github.com/fatih/color v1.18.0` β [Updates: `v1.19.0`]
- `github.com/gobwas/glob v0.2.3` β [Updates: `v1.0.0`]
- `github.com/google/uuid v1.6.0`
- `github.com/huandu/xstrings v1.5.0` β [Updates: `v1.6.0`]
- `github.com/mattn/go-colorable v0.1.13` β [Updates: `v0.1.15`]
- `github.com/mattn/go-isatty v0.0.20` β [Updates: `v0.0.24`]
- `github.com/mitchellh/copystructure v1.2.0`
- `github.com/mitchellh/reflectwalk v1.0.2`
- `github.com/pkg/errors v0.9.1`
- `github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2@5d4384ee4fb2`
- `github.com/rs/zerolog v1.34.0` β [Updates: `v1.35.1`]
- `github.com/shopspring/decimal v1.4.0`
- `github.com/spf13/cast v1.7.0` β [Updates: `v1.10.0`]
- `github.com/stretchr/objx v0.5.2` β [Updates: `v0.5.3`]
- `golang.org/x/crypto v0.45.0` β [Updates: `v0.56.0`]
- `golang.org/x/net v0.47.0` β [Updates: `v0.56.0`]
- `golang.org/x/sys v0.38.0` β [Updates: `v0.44.0`]
- `golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1@5ec99f83aff1` β [Updates: `v0.0.0-20240903120638-7835f813f4da`]
- `gopkg.in/yaml.v2 v2.4.0` β [Updates: `v3.0.1`]
- `gopkg.in/yaml.v3 v3.0.1`
- `sigs.k8s.io/yaml v1.4.0` β [Updates: `v1.6.0`]
jsonnet-bundler (1)
pkg/server/testdata/jsonnetfile.json (3)
- `github.com/grafana/jsonnet-libs/ksonnet-util master` β [Updates: `master`]
- `github.com/jsonnet-libs/k8s-libsonnet/1.30 main` β [Updates: `main`]
- `github.com/grafana/grafonnet/gen/grafonnet-latest main` β [Updates: `main`]
nix (1)
nix/flake.nix (2)
- `flake-utils lock file @ b1d9ab70662946ef0850d488da1c9019f3a9752a`
- `nixpkgs nixos-unstable` β [Updates: `nixos-unstable`]
---
## Need help?
You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reading the linked Renovate Dependency Dashboard documentation and reviewing the listed rate-limited, pending, open, blocked, and vulnerable updates. The issue contains no source files or tests to target; completion would require determining which dependency updates remain actionable and verifying the corresponding Renovate-generated changes.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions, go
- Domain
- devops, security
- Issue type
- Refactor
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 10/100