grafana / grafana/jsonnet-language-server

Dependency Dashboard

Open
#222 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
223
Forks
33
PR merge metrics
No merged PRs in 30d

Description

This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.

## Abandoned Dependencies

The following dependencies have not received updates for an extended period and may be unmaintained.

View abandoned dependencies (15)

> [!NOTE]
Packages are marked as abandoned when they exceed the [`abandonmentThreshold`](https://docs.renovatebot.com/configuration-options/#abandonmentthreshold) since their last release. Unlike deprecated packages with official notices, abandonment is detected by release inactivity.
>
| Datasource | Package | Last Updated |
|------------|------|-------------|
| gomod | [github.com/Masterminds/goutils](https://redirect.github.com/Masterminds/goutils) | `2021-02-04` |
| gomod | [github.com/Masterminds/sprig/v3](https://redirect.github.com/Masterminds/sprig) | `2024-08-29` |
| gomod | [github.com/davecgh/go-spew](https://redirect.github.com/davecgh/go-spew) | `2018-02-21` |
| gomod | [github.com/google/uuid](https://redirect.github.com/google/uuid) | `2024-01-23` |
| gomod | [github.com/hexops/gotextdiff](https://redirect.github.com/hexops/gotextdiff) | `2020-12-13` |
| gomod | [github.com/jdbaldry/go-language-server-protocol](https://redirect.github.com/jdbaldry/go-language-server-protocol) | `2021-10-13` |
| gomod | [github.com/mitchellh/copystructure](https://redirect.github.com/mitchellh/copystructure) | `2021-05-05` |
| gomod | [github.com/mitchellh/mapstructure](https://redirect.github.com/mitchellh/mapstructure) | `2022-04-20` |
| gomod | [github.com/mitchellh/reflectwalk](https://redirect.github.com/mitchellh/reflectwalk) | `2021-05-03` |
| gomod | [github.com/pkg/errors](https://redirect.github.com/pkg/errors) | `2020-01-14` |
| gomod | [github.com/pmezard/go-difflib](https://redirect.github.com/pmezard/go-difflib) | `2016-01-10` |
| gomod | [github.com/shopspring/decimal](https://redirect.github.com/shopspring/decimal) | `2024-04-12` |
| gomod | [golang.org/x/xerrors](https://go.googlesource.com/xerrors) | `2024-09-03` |
| gomod | [gopkg.in/yaml.v2](https://redirect.github.com/go-yaml/yaml) | `2022-05-27` |
| gomod | [gopkg.in/yaml.v3](https://redirect.github.com/go-yaml/yaml) | `2022-05-27` |

## Rate-Limited

The following updates are currently rate-limited. To force their creation now, click on a checkbox below.

- [ ] chore(deps): pin dependencies (`github.com/grafana/grafonnet/gen/grafonnet-latest`, `github.com/grafana/jsonnet-libs/ksonnet-util`, `github.com/jsonnet-libs/k8s-libsonnet/1.30`)
- [ ] chore(deps): update module github.com/mattn/go-isatty to v0.0.24
- [ ] chore(deps): update module github.com/stretchr/objx to v0.5.3
- [ ] chore(deps): update module github.com/fatih/color to v1.19.0
- [ ] chore(deps): update module github.com/masterminds/semver/v3 to v3.5.0
- [ ] chore(deps): update module github.com/puerkitobio/goquery to v1.13.0
- [ ] chore(deps): update module github.com/rs/zerolog to v1.35.1
- [ ] chore(deps): update module github.com/spf13/cast to v1.10.0
- [ ] chore(deps): update module sigs.k8s.io/yaml to v1.6.0
- [ ] fix(deps): update module github.com/google/go-jsonnet to v0.22.0
- [ ] fix(deps): update module github.com/sirupsen/logrus to v1.10.2
- [ ] fix(deps): update module github.com/stretchr/testify to v1.12.1
- [ ] chore(deps): update actions/checkout action to v7
- [ ] chore(deps): update actions/setup-go action to v7
- [ ] chore(deps): update module github.com/gobwas/glob to v1
- [ ] chore(deps): update module gopkg.in/yaml.v2 to v3
- [ ] chore(deps): lock file maintenance
- [ ] πŸ” **Create all rate-limited PRs at once** πŸ”

## Pending Status Checks

The following updates await pending status checks. To force their creation now, click on a checkbox below.

- [ ] chore(deps): update module github.com/huandu/xstrings to v1.6.0

## Open

The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.

- [ ] [fix(security/unknown/): update go toolchain directive to v1.25.13 [security]](../pull/261)
- [ ] [fix(security/unknown/): update module golang.org/x/crypto to v0.56.0 [security]](../pull/262)
- [ ] [fix(security/unknown/): update module golang.org/x/net to v0.56.0 [security]](../pull/263)
- [ ] [fix(security/unknown/): update module golang.org/x/sys to v0.44.0 [security]](../pull/264)
- [ ] [chore(deps): update golang.org/x/xerrors digest to 7835f81](../pull/269)
- [ ] [chore(deps): update module dario.cat/mergo to v1.0.2](../pull/272)
- [ ] [chore(deps): update module github.com/andybalholm/cascadia to v1.3.5](../pull/273)
- [ ] [chore(deps): update module github.com/mattn/go-colorable to v0.1.15](../pull/274)
- [ ] [chore(deps): update actions/checkout action to v4.4.0](../pull/255)
- [ ] [chore(deps): update actions/setup-go action to v5.6.0](../pull/256)
- [ ] [chore(deps): update goreleaser/goreleaser-action action to v6.4.0](../pull/257)
- [ ] [fix(deps): update module github.com/grafana/tanka to v0.39.0](../pull/259)
- [ ] [chore(deps): update goreleaser/goreleaser-action action to v7](../pull/260)
- [ ] [fix(deps): update module github.com/johanneskaufmann/html-to-markdown to v2](../pull/265)
- [ ] **Click on this checkbox to rebase all open PRs at once**

## PR Closed (Blocked)

The following updates are blocked by an existing closed PR. To recreate the PR, click on a checkbox below.

- [ ] [chore(deps): update golangci/golangci-lint-action action to v9](../pull/246)

## Vulnerabilities

> [!IMPORTANT]
> `90`/`91` CVEs have Renovate fixes.

gomod

go.mod

go

- [GO-2025-3749](https://osv.dev/vulnerability/GO-2025-3749) (fixed in >= 1.24.4)
- [GO-2025-3750](https://osv.dev/vulnerability/GO-2025-3750) (fixed in >= 1.24.4)
- [GO-2025-3751](https://osv.dev/vulnerability/GO-2025-3751) (fixed in >= 1.24.4)
- [GO-2025-3849](https://osv.dev/vulnerability/GO-2025-3849) (fixed in >= 1.24.6)
- [GO-2025-3956](https://osv.dev/vulnerability/GO-2025-3956) (fixed in >= 1.24.6)
- [GO-2025-4006](https://osv.dev/vulnerability/GO-2025-4006) (fixed in >= 1.24.8)
- [GO-2025-4007](https://osv.dev/vulnerability/GO-2025-4007) (fixed in >= 1.24.9)
- [GO-2025-4008](https://osv.dev/vulnerability/GO-2025-4008) (fixed in >= 1.24.8)
- [GO-2025-4009](https://osv.dev/vulnerability/GO-2025-4009) (fixed in >= 1.24.8)
- [GO-2025-4010](https://osv.dev/vulnerability/GO-2025-4010) (fixed in >= 1.24.8)
- [GO-2025-4011](https://osv.dev/vulnerability/GO-2025-4011) (fixed in >= 1.24.8)
- [GO-2025-4012](https://osv.dev/vulnerability/GO-2025-4012) (fixed in >= 1.24.8)
- [GO-2025-4013](https://osv.dev/vulnerability/GO-2025-4013) (fixed in >= 1.24.8)
- [GO-2025-4014](https://osv.dev/vulnerability/GO-2025-4014) (fixed in >= 1.24.8)
- [GO-2025-4015](https://osv.dev/vulnerability/GO-2025-4015) (fixed in >= 1.24.8)
- [GO-2025-4155](https://osv.dev/vulnerability/GO-2025-4155) (fixed in >= 1.24.11)
- [GO-2025-4175](https://osv.dev/vulnerability/GO-2025-4175) (fixed in >= 1.24.11)
- [GO-2026-4337](https://osv.dev/vulnerability/GO-2026-4337) (fixed in >= 1.24.13)
- [GO-2026-4340](https://osv.dev/vulnerability/GO-2026-4340) (fixed in >= 1.24.12)
- [GO-2026-4341](https://osv.dev/vulnerability/GO-2026-4341) (fixed in >= 1.24.12)
- [GO-2026-4342](https://osv.dev/vulnerability/GO-2026-4342) (fixed in >= 1.24.12)
- [GO-2026-4403](https://osv.dev/vulnerability/GO-2026-4403) (fixed in >= 1.24.3)
- [GO-2026-4601](https://osv.dev/vulnerability/GO-2026-4601) (fixed in >= 1.25.8)
- [GO-2026-4602](https://osv.dev/vulnerability/GO-2026-4602) (fixed in >= 1.25.8)
- [GO-2026-4603](https://osv.dev/vulnerability/GO-2026-4603) (fixed in >= 1.25.8)
- [GO-2026-4864](https://osv.dev/vulnerability/GO-2026-4864) (fixed in >= 1.25.9)
- [GO-2026-4865](https://osv.dev/vulnerability/GO-2026-4865) (fixed in >= 1.25.9)
- [GO-2026-4869](https://osv.dev/vulnerability/GO-2026-4869) (fixed in >= 1.25.9)
- [GO-2026-4870](https://osv.dev/vulnerability/GO-2026-4870) (fixed in >= 1.25.9)
- [GO-2026-4918](https://osv.dev/vulnerability/GO-2026-4918) (fixed in >= 1.25.10)
- [GO-2026-4946](https://osv.dev/vulnerability/GO-2026-4946) (fixed in >= 1.25.9)
- [GO-2026-4947](https://osv.dev/vulnerability/GO-2026-4947) (fixed in >= 1.25.9)
- [GO-2026-4970](https://osv.dev/vulnerability/GO-2026-4970) (fixed in >= 1.25.12)
- [GO-2026-4971](https://osv.dev/vulnerability/GO-2026-4971) (fixed in >= 1.25.10)
- [GO-2026-4976](https://osv.dev/vulnerability/GO-2026-4976) (fixed in >= 1.25.10)
- [GO-2026-4977](https://osv.dev/vulnerability/GO-2026-4977) (fixed in >= 1.25.10)
- [GO-2026-4980](https://osv.dev/vulnerability/GO-2026-4980) (fixed in >= 1.25.10)
- [GO-2026-4981](https://osv.dev/vulnerability/GO-2026-4981) (fixed in >= 1.25.10)
- [GO-2026-4982](https://osv.dev/vulnerability/GO-2026-4982) (fixed in >= 1.25.10)
- [GO-2026-4986](https://osv.dev/vulnerability/GO-2026-4986) (fixed in >= 1.25.10)
- [GO-2026-5026](https://osv.dev/vulnerability/GO-2026-5026) (fixed in >= 1.25.13)
- [GO-2026-5037](https://osv.dev/vulnerability/GO-2026-5037) (fixed in >= 1.25.11)
- [GO-2026-5038](https://osv.dev/vulnerability/GO-2026-5038) (fixed in >= 1.25.11)
- [GO-2026-5039](https://osv.dev/vulnerability/GO-2026-5039) (fixed in >= 1.25.11)
- [GO-2026-5856](https://osv.dev/vulnerability/GO-2026-5856) (fixed in >= 1.25.12)
- [GO-2026-5972](https://osv.dev/vulnerability/GO-2026-5972) (fixed in >= 1.25.13)
- [GO-2026-6088](https://osv.dev/vulnerability/GO-2026-6088) (fixed in >= 1.25.13)
- [GO-2026-6089](https://osv.dev/vulnerability/GO-2026-6089) (fixed in >= 1.25.13)
- [GO-2026-6090](https://osv.dev/vulnerability/GO-2026-6090) (fixed in >= 1.25.13)
- [GO-2026-6091](https://osv.dev/vulnerability/GO-2026-6091) (fixed in >= 1.25.13)
- [GO-2026-6218](https://osv.dev/vulnerability/GO-2026-6218) (fixed in >= 1.25.13)

golang.org/x/crypto

- [GHSA-45gg-vh54-h5m9](https://osv.dev/vulnerability/GHSA-45gg-vh54-h5m9) (fixed in >= 0.52.0)
- [GHSA-5cgq-3rg8-m6cv](https://osv.dev/vulnerability/GHSA-5cgq-3rg8-m6cv) (fixed in >= 0.52.0)
- [GHSA-78mq-xcr3-xm33](https://osv.dev/vulnerability/GHSA-78mq-xcr3-xm33) (fixed in >= 0.52.0)
- [GHSA-89gr-r52h-f8rx](https://osv.dev/vulnerability/GHSA-89gr-r52h-f8rx) (fixed in >= 0.52.0)
- [GHSA-9m57-25v3-79x9](https://osv.dev/vulnerability/GHSA-9m57-25v3-79x9) (fixed in >= 0.52.0)
- [GHSA-f5wc-c3c7-36mc](https://osv.dev/vulnerability/GHSA-f5wc-c3c7-36mc) (fixed in >= 0.52.0)
- [GHSA-jppx-rxg9-jmrx](https://osv.dev/vulnerability/GHSA-jppx-rxg9-jmrx) (fixed in >= 0.52.0)
- [GHSA-q4h4-gmj2-qvw2](https://osv.dev/vulnerability/GHSA-q4h4-gmj2-qvw2) (fixed in >= 0.52.0)
- [GHSA-qpw4-5x99-6vjp](https://osv.dev/vulnerability/GHSA-qpw4-5x99-6vjp) (fixed in >= 0.52.0)
- [GHSA-rm3j-f69w-wqmq](https://osv.dev/vulnerability/GHSA-rm3j-f69w-wqmq) (fixed in >= 0.52.0)
- [GHSA-vgwf-h737-ff37](https://osv.dev/vulnerability/GHSA-vgwf-h737-ff37) (fixed in >= 0.52.0)
- [GHSA-w879-237q-wc7r](https://osv.dev/vulnerability/GHSA-w879-237q-wc7r) (fixed in >= 0.52.0)
- [GHSA-x527-x647-q7gg](https://osv.dev/vulnerability/GHSA-x527-x647-q7gg) (fixed in >= 0.52.0)
- [GO-2026-5005](https://osv.dev/vulnerability/GO-2026-5005) (fixed in >= 0.52.0)
- [GO-2026-5006](https://osv.dev/vulnerability/GO-2026-5006) (fixed in >= 0.52.0)
- [GO-2026-5013](https://osv.dev/vulnerability/GO-2026-5013) (fixed in >= 0.52.0)
- [GO-2026-5014](https://osv.dev/vulnerability/GO-2026-5014) (fixed in >= 0.52.0)
- [GO-2026-5015](https://osv.dev/vulnerability/GO-2026-5015) (fixed in >= 0.52.0)
- [GO-2026-5016](https://osv.dev/vulnerability/GO-2026-5016) (fixed in >= 0.52.0)
- [GO-2026-5017](https://osv.dev/vulnerability/GO-2026-5017) (fixed in >= 0.52.0)
- [GO-2026-5018](https://osv.dev/vulnerability/GO-2026-5018) (fixed in >= 0.52.0)
- [GO-2026-5019](https://osv.dev/vulnerability/GO-2026-5019) (fixed in >= 0.52.0)
- [GO-2026-5020](https://osv.dev/vulnerability/GO-2026-5020) (fixed in >= 0.52.0)
- [GO-2026-5021](https://osv.dev/vulnerability/GO-2026-5021) (fixed in >= 0.52.0)
- [GO-2026-5023](https://osv.dev/vulnerability/GO-2026-5023) (fixed in >= 0.52.0)
- [GO-2026-5033](https://osv.dev/vulnerability/GO-2026-5033) (fixed in >= 0.52.0)
- [GO-2026-5932](https://osv.dev/vulnerability/GO-2026-5932)
- [GO-2026-6303](https://osv.dev/vulnerability/GO-2026-6303) (fixed in >= 0.55.0)
- [GO-2026-6354](https://osv.dev/vulnerability/GO-2026-6354) (fixed in >= 0.56.0)
- [GO-2026-6355](https://osv.dev/vulnerability/GO-2026-6355) (fixed in >= 0.56.0)

golang.org/x/net

- [GHSA-5cv4-jp36-h3mw](https://osv.dev/vulnerability/GHSA-5cv4-jp36-h3mw) (fixed in >= 0.55.0)
- [GO-2026-4918](https://osv.dev/vulnerability/GO-2026-4918) (fixed in >= 0.53.0)
- [GO-2026-5025](https://osv.dev/vulnerability/GO-2026-5025) (fixed in >= 0.55.0)
- [GO-2026-5026](https://osv.dev/vulnerability/GO-2026-5026) (fixed in >= 0.55.0)
- [GO-2026-5027](https://osv.dev/vulnerability/GO-2026-5027) (fixed in >= 0.55.0)
- [GO-2026-5028](https://osv.dev/vulnerability/GO-2026-5028) (fixed in >= 0.55.0)
- [GO-2026-5029](https://osv.dev/vulnerability/GO-2026-5029) (fixed in >= 0.55.0)
- [GO-2026-5030](https://osv.dev/vulnerability/GO-2026-5030) (fixed in >= 0.55.0)
- [GO-2026-5942](https://osv.dev/vulnerability/GO-2026-5942) (fixed in >= 0.56.0)

golang.org/x/sys

- [GO-2026-5024](https://osv.dev/vulnerability/GO-2026-5024) (fixed in >= 0.44.0)

## Detected Dependencies

github-actions (4)

.github/workflows/golangci-lint.yml (3)

- `actions/checkout v4.2.2@11bd71901bbe5b1630ceea73d27597364c9af683` β†’ [Updates: `v4.4.0`, `v7.0.1`]
- `golangci/golangci-lint-action v8.0.0@4afd733a84b1f43292c63897423277bb7f4313a9` β†’ [Updates: `v9.3.0`]
- `golangci/golangci-lint latest`

.github/workflows/jsonnetfmt.yml (2)

- `actions/checkout v4.2.2@11bd71901bbe5b1630ceea73d27597364c9af683` β†’ [Updates: `v4.4.0`, `v7.0.1`]
- `actions/setup-go v5.5.0@d35c59abb061a4a6fb18e82ac0862c26744d6ab5` β†’ [Updates: `v5.6.0`, `v7.0.0`]

.github/workflows/release.yml (3)

- `actions/checkout v4.2.2@11bd71901bbe5b1630ceea73d27597364c9af683` β†’ [Updates: `v4.4.0`, `v7.0.1`]
- `actions/setup-go v5.5.0@d35c59abb061a4a6fb18e82ac0862c26744d6ab5` β†’ [Updates: `v5.6.0`, `v7.0.0`]
- `goreleaser/goreleaser-action v6.3.0@9c156ee8a17a598857849441385a2041ef570552` β†’ [Updates: `v6.4.0`, `v7.2.3`]

.github/workflows/test.yml (2)

- `actions/checkout v4.2.2@11bd71901bbe5b1630ceea73d27597364c9af683` β†’ [Updates: `v4.4.0`, `v7.0.1`]
- `actions/setup-go v5.5.0@d35c59abb061a4a6fb18e82ac0862c26744d6ab5` β†’ [Updates: `v5.6.0`, `v7.0.0`]

gomod (1)

go.mod (38)

- `go 1.24.0`
- `go 1.24.2` β†’ [Updates: `1.25.13`]
- `github.com/JohannesKaufmann/html-to-markdown v1.6.0` β†’ [Updates: `v2.5.2`]
- `github.com/google/go-jsonnet v0.21.0` β†’ [Updates: `v0.22.0`]
- `github.com/grafana/tanka v0.32.1-0.20250521123240-fa219d35d24f@fa219d35d24f` β†’ [Updates: `v0.39.0`]
- `github.com/hexops/gotextdiff v1.0.3`
- `github.com/jdbaldry/go-language-server-protocol v0.0.0-20211013214444-3022da0884b2@3022da0884b2`
- `github.com/mitchellh/mapstructure v1.5.0`
- `github.com/sirupsen/logrus v1.9.3` β†’ [Updates: `v1.10.2`]
- `github.com/stretchr/testify v1.10.0` β†’ [Updates: `v1.12.1`]
- `dario.cat/mergo v1.0.1` β†’ [Updates: `v1.0.2`]
- `github.com/Masterminds/goutils v1.1.1`
- `github.com/Masterminds/semver/v3 v3.3.0` β†’ [Updates: `v3.5.0`]
- `github.com/Masterminds/sprig/v3 v3.3.0`
- `github.com/PuerkitoBio/goquery v1.9.2` β†’ [Updates: `v1.13.0`]
- `github.com/andybalholm/cascadia v1.3.2` β†’ [Updates: `v1.3.5`]
- `github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc@d8f796af33cc`
- `github.com/fatih/color v1.18.0` β†’ [Updates: `v1.19.0`]
- `github.com/gobwas/glob v0.2.3` β†’ [Updates: `v1.0.0`]
- `github.com/google/uuid v1.6.0`
- `github.com/huandu/xstrings v1.5.0` β†’ [Updates: `v1.6.0`]
- `github.com/mattn/go-colorable v0.1.13` β†’ [Updates: `v0.1.15`]
- `github.com/mattn/go-isatty v0.0.20` β†’ [Updates: `v0.0.24`]
- `github.com/mitchellh/copystructure v1.2.0`
- `github.com/mitchellh/reflectwalk v1.0.2`
- `github.com/pkg/errors v0.9.1`
- `github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2@5d4384ee4fb2`
- `github.com/rs/zerolog v1.34.0` β†’ [Updates: `v1.35.1`]
- `github.com/shopspring/decimal v1.4.0`
- `github.com/spf13/cast v1.7.0` β†’ [Updates: `v1.10.0`]
- `github.com/stretchr/objx v0.5.2` β†’ [Updates: `v0.5.3`]
- `golang.org/x/crypto v0.45.0` β†’ [Updates: `v0.56.0`]
- `golang.org/x/net v0.47.0` β†’ [Updates: `v0.56.0`]
- `golang.org/x/sys v0.38.0` β†’ [Updates: `v0.44.0`]
- `golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1@5ec99f83aff1` β†’ [Updates: `v0.0.0-20240903120638-7835f813f4da`]
- `gopkg.in/yaml.v2 v2.4.0` β†’ [Updates: `v3.0.1`]
- `gopkg.in/yaml.v3 v3.0.1`
- `sigs.k8s.io/yaml v1.4.0` β†’ [Updates: `v1.6.0`]

jsonnet-bundler (1)

pkg/server/testdata/jsonnetfile.json (3)

- `github.com/grafana/jsonnet-libs/ksonnet-util master` β†’ [Updates: `master`]
- `github.com/jsonnet-libs/k8s-libsonnet/1.30 main` β†’ [Updates: `main`]
- `github.com/grafana/grafonnet/gen/grafonnet-latest main` β†’ [Updates: `main`]

nix (1)

nix/flake.nix (2)

- `flake-utils lock file @ b1d9ab70662946ef0850d488da1c9019f3a9752a`
- `nixpkgs nixos-unstable` β†’ [Updates: `nixos-unstable`]

---
## Need help?
You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading the linked Renovate Dependency Dashboard documentation and reviewing the listed rate-limited, pending, open, blocked, and vulnerable updates. The issue contains no source files or tests to target; completion would require determining which dependency updates remain actionable and verifying the corresponding Renovate-generated changes.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, go
Domain
devops, security
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
10/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.