grafana / grafana/walqueue

Dependency Dashboard

Open
#62 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
9
Forks
0
PR merge metrics
No merged PRs in 30d

Description

This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.

## Abandoned Dependencies

The following dependencies have not received updates for an extended period and may be unmaintained.

View abandoned dependencies (14)

> [!NOTE]
Packages are marked as abandoned when they exceed the [`abandonmentThreshold`](https://docs.renovatebot.com/configuration-options/#abandonmentthreshold) since their last release. Unlike deprecated packages with official notices, abandonment is detected by release inactivity.
>
| Datasource | Package | Last Updated |
|------------|------|-------------|
| gomod | [github.com/beorn7/perks](https://redirect.github.com/beorn7/perks) | `2019-07-31` |
| gomod | [github.com/cespare/xxhash/v2](https://redirect.github.com/cespare/xxhash) | `2024-04-04` |
| gomod | [github.com/davecgh/go-spew](https://redirect.github.com/davecgh/go-spew) | `2018-02-21` |
| gomod | [github.com/dennwc/varint](https://redirect.github.com/dennwc/varint) | `2019-06-16` |
| gomod | [github.com/go-kit/log](https://redirect.github.com/go-kit/log) | `2022-05-14` |
| gomod | [github.com/gogo/protobuf](https://redirect.github.com/gogo/protobuf) | `2021-01-10` |
| gomod | [github.com/google/uuid](https://redirect.github.com/google/uuid) | `2024-01-23` |
| gomod | [github.com/jpillora/backoff](https://redirect.github.com/jpillora/backoff) | `2019-10-03` |
| gomod | [github.com/kr/text](https://redirect.github.com/kr/text) | `2020-02-14` |
| gomod | [github.com/munnerz/goautoneg](https://redirect.github.com/munnerz/goautoneg) | `2019-10-10` |
| gomod | [github.com/mwitkow/go-conntrack](https://redirect.github.com/mwitkow/go-conntrack) | `2019-07-16` |
| gomod | [github.com/pmezard/go-difflib](https://redirect.github.com/pmezard/go-difflib) | `2016-01-10` |
| gomod | [go.uber.org/atomic](https://redirect.github.com/uber-go/atomic) | `2023-05-03` |
| gomod | [gopkg.in/yaml.v3](https://redirect.github.com/go-yaml/yaml) | `2022-05-27` |

## Rate-Limited

The following updates are currently rate-limited. To force their creation now, click on a checkbox below.

- [ ] chore(deps): update golang.org/x/exp digest to 85c1c22
- [ ] fix(deps): update module github.com/prometheus/client_model to v0.6.3
- [ ] chore(deps): update module github.com/prometheus/procfs to v0.22.0
- [ ] chore(deps): update module github.com/rogpeppe/go-internal to v1.16.0
- [ ] chore(deps): update module golang.org/x/oauth2 to v0.37.0
- [ ] fix(deps): update module github.com/prometheus/client_golang to v1.24.1
- [ ] fix(deps): update module github.com/prometheus/common to v0.71.0
- [ ] fix(deps): update module github.com/stretchr/testify to v1.12.1
- [ ] fix(deps): update module golang.design/x/chann to v0.2.1
- [ ] chore(deps): update actions/checkout action to v7
- [ ] chore(deps): update actions/setup-go action to v7
- [ ] chore(deps): update module go.yaml.in/yaml/v2 to v3
- [ ] 🔐 **Create all rate-limited PRs at once** 🔐

## Pending Status Checks

The following updates await pending status checks. To force their creation now, click on a checkbox below.

- [ ] [fix(deps): update github.com/prometheus/client_golang/exp digest to d2f148b](../pull/89)

## Open

The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.

- [ ] [fix(security/unknown/): update module github.com/klauspost/compress to v1.18.7 [security]](../pull/103)
- [ ] [fix(security/unknown/): update go toolchain directive to v1.25.13 [security]](../pull/93)
- [ ] [fix(security/unknown/): update module github.com/prometheus/prometheus to v0.311.3 [security]](../pull/92)
- [ ] [fix(security/unknown/): update module golang.org/x/net to v0.56.0 [security]](../pull/94)
- [ ] [fix(security/unknown/): update module golang.org/x/sys to v0.44.0 [security]](../pull/95)
- [ ] [fix(security/unknown/): update module golang.org/x/text to v0.39.0 [security]](../pull/102)
- [ ] [chore(deps): update actions/checkout digest to d23441a](../pull/86)
- [ ] [chore(deps): update actions/setup-go digest to 924ae3a](../pull/87)
- [ ] [chore(deps): update golangci/golangci-lint-action digest to 9fae48a](../pull/88)
- [ ] [chore(deps): update module github.com/go-logfmt/logfmt to v0.6.1](../pull/101)
- [ ] [chore(deps): update module github.com/golang-jwt/jwt/v5 to v5.3.1](../pull/104)
- [ ] [chore(deps): update module go.yaml.in/yaml/v2 to v2.4.4](../pull/105)
- [ ] [chore(deps): update module google.golang.org/protobuf to v1.36.12](../pull/106)
- [ ] [fix(deps): update module github.com/deneonet/benc to v1.1.8](../pull/91)
- [ ] [chore(deps): update dependency golangci/golangci-lint to v2.13.2](../pull/99)
- [ ] **Click on this checkbox to rebase all open PRs at once**

## PR Closed (Blocked)

The following updates are blocked by an existing closed PR. To recreate the PR, click on a checkbox below.

- [ ] [fix(deps): update module github.com/tinylib/msgp to v1.6.4](../pull/66)
- [ ] [chore(deps): update golangci/golangci-lint-action action to v9](../pull/69)

## Vulnerabilities

> [!IMPORTANT]
> `50`/`50` CVEs have Renovate fixes.

gomod

go.mod

go

- [GO-2026-4337](https://osv.dev/vulnerability/GO-2026-4337) (fixed in >= 1.24.13)
- [GO-2026-4601](https://osv.dev/vulnerability/GO-2026-4601) (fixed in >= 1.25.8)
- [GO-2026-4602](https://osv.dev/vulnerability/GO-2026-4602) (fixed in >= 1.25.8)
- [GO-2026-4603](https://osv.dev/vulnerability/GO-2026-4603) (fixed in >= 1.25.8)
- [GO-2026-4864](https://osv.dev/vulnerability/GO-2026-4864) (fixed in >= 1.25.9)
- [GO-2026-4865](https://osv.dev/vulnerability/GO-2026-4865) (fixed in >= 1.25.9)
- [GO-2026-4869](https://osv.dev/vulnerability/GO-2026-4869) (fixed in >= 1.25.9)
- [GO-2026-4870](https://osv.dev/vulnerability/GO-2026-4870) (fixed in >= 1.25.9)
- [GO-2026-4918](https://osv.dev/vulnerability/GO-2026-4918) (fixed in >= 1.25.10)
- [GO-2026-4946](https://osv.dev/vulnerability/GO-2026-4946) (fixed in >= 1.25.9)
- [GO-2026-4947](https://osv.dev/vulnerability/GO-2026-4947) (fixed in >= 1.25.9)
- [GO-2026-4970](https://osv.dev/vulnerability/GO-2026-4970) (fixed in >= 1.25.12)
- [GO-2026-4971](https://osv.dev/vulnerability/GO-2026-4971) (fixed in >= 1.25.10)
- [GO-2026-4976](https://osv.dev/vulnerability/GO-2026-4976) (fixed in >= 1.25.10)
- [GO-2026-4977](https://osv.dev/vulnerability/GO-2026-4977) (fixed in >= 1.25.10)
- [GO-2026-4980](https://osv.dev/vulnerability/GO-2026-4980) (fixed in >= 1.25.10)
- [GO-2026-4981](https://osv.dev/vulnerability/GO-2026-4981) (fixed in >= 1.25.10)
- [GO-2026-4982](https://osv.dev/vulnerability/GO-2026-4982) (fixed in >= 1.25.10)
- [GO-2026-4986](https://osv.dev/vulnerability/GO-2026-4986) (fixed in >= 1.25.10)
- [GO-2026-5026](https://osv.dev/vulnerability/GO-2026-5026) (fixed in >= 1.25.13)
- [GO-2026-5037](https://osv.dev/vulnerability/GO-2026-5037) (fixed in >= 1.25.11)
- [GO-2026-5038](https://osv.dev/vulnerability/GO-2026-5038) (fixed in >= 1.25.11)
- [GO-2026-5039](https://osv.dev/vulnerability/GO-2026-5039) (fixed in >= 1.25.11)
- [GO-2026-5856](https://osv.dev/vulnerability/GO-2026-5856) (fixed in >= 1.25.12)
- [GO-2026-5972](https://osv.dev/vulnerability/GO-2026-5972) (fixed in >= 1.25.13)
- [GO-2026-6088](https://osv.dev/vulnerability/GO-2026-6088) (fixed in >= 1.25.13)
- [GO-2026-6089](https://osv.dev/vulnerability/GO-2026-6089) (fixed in >= 1.25.13)
- [GO-2026-6090](https://osv.dev/vulnerability/GO-2026-6090) (fixed in >= 1.25.13)
- [GO-2026-6091](https://osv.dev/vulnerability/GO-2026-6091) (fixed in >= 1.25.13)
- [GO-2026-6218](https://osv.dev/vulnerability/GO-2026-6218) (fixed in >= 1.25.13)

github.com/klauspost/compress

- [GO-2026-5841](https://osv.dev/vulnerability/GO-2026-5841) (fixed in >= 1.18.7)

github.com/prometheus/prometheus

- [GHSA-8rm2-7qqf-34qm](https://osv.dev/vulnerability/GHSA-8rm2-7qqf-34qm) (fixed in >= 0.311.3)
- [GHSA-fw8g-cg8f-9j28](https://osv.dev/vulnerability/GHSA-fw8g-cg8f-9j28) (fixed in >= 0.311.3)
- [GHSA-vffh-x6r8-xx99](https://osv.dev/vulnerability/GHSA-vffh-x6r8-xx99) (fixed in >= 0.311.2-0.20260410083055-07c6232d159b)
- [GHSA-wg65-39gg-5wfj](https://osv.dev/vulnerability/GHSA-wg65-39gg-5wfj) (fixed in >= 0.311.3)
- [GO-2026-5264](https://osv.dev/vulnerability/GO-2026-5264) (fixed in >= 0.311.3)
- [GO-2026-5381](https://osv.dev/vulnerability/GO-2026-5381) (fixed in >= 0.311.3)
- [GO-2026-5662](https://osv.dev/vulnerability/GO-2026-5662) (fixed in >= 0.311.2-0.20260410083055-07c6232d159b)
- [GO-2026-5710](https://osv.dev/vulnerability/GO-2026-5710) (fixed in >= 0.311.3)

golang.org/x/net

- [GHSA-5cv4-jp36-h3mw](https://osv.dev/vulnerability/GHSA-5cv4-jp36-h3mw) (fixed in >= 0.55.0)
- [GO-2026-4918](https://osv.dev/vulnerability/GO-2026-4918) (fixed in >= 0.53.0)
- [GO-2026-5025](https://osv.dev/vulnerability/GO-2026-5025) (fixed in >= 0.55.0)
- [GO-2026-5026](https://osv.dev/vulnerability/GO-2026-5026) (fixed in >= 0.55.0)
- [GO-2026-5027](https://osv.dev/vulnerability/GO-2026-5027) (fixed in >= 0.55.0)
- [GO-2026-5028](https://osv.dev/vulnerability/GO-2026-5028) (fixed in >= 0.55.0)
- [GO-2026-5029](https://osv.dev/vulnerability/GO-2026-5029) (fixed in >= 0.55.0)
- [GO-2026-5030](https://osv.dev/vulnerability/GO-2026-5030) (fixed in >= 0.55.0)
- [GO-2026-5942](https://osv.dev/vulnerability/GO-2026-5942) (fixed in >= 0.56.0)

golang.org/x/sys

- [GO-2026-5024](https://osv.dev/vulnerability/GO-2026-5024) (fixed in >= 0.44.0)

golang.org/x/text

- [GO-2026-5970](https://osv.dev/vulnerability/GO-2026-5970) (fixed in >= 0.39.0)

## Detected Dependencies

github-actions (2)

.github/workflows/lint.yml (4)

- `actions/checkout v6@8e8c483db84b4bee98b60c0593521ed34d9990e8` → [Updates: `v7`, `v6`]
- `actions/setup-go v6@4dc6199c7b1a012772edbd06daecab0f50c9053c` → [Updates: `v7`, `v6`]
- `golangci/golangci-lint-action v7@1481404843c368bc19ca9406f87d6e0fc97bdcfd` → [Updates: `v9`, `v7`]
- `golangci/golangci-lint v2.0` → [Updates: `v2.13.2`]

.github/workflows/test.yml (2)

- `actions/checkout v6@8e8c483db84b4bee98b60c0593521ed34d9990e8` → [Updates: `v7`, `v6`]
- `actions/setup-go v6@4dc6199c7b1a012772edbd06daecab0f50c9053c` → [Updates: `v7`, `v6`]

gomod (1)

go.mod (42)

- `go 1.24.9`
- `go 1.24.12` → [Updates: `1.25.13`]
- `github.com/deneonet/benc v1.1.7` → [Updates: `v1.1.8`]
- `github.com/go-kit/log v0.2.1`
- `github.com/gogo/protobuf v1.3.2`
- `github.com/golang/snappy v1.0.0`
- `github.com/klauspost/compress v1.18.2` → [Updates: `v1.18.7`]
- `github.com/prometheus/client_golang v1.23.2` → [Updates: `v1.24.1`]
- `github.com/prometheus/client_model v0.6.2` → [Updates: `v0.6.3`]
- `github.com/prometheus/common v0.67.4` → [Updates: `v0.71.0`]
- `github.com/prometheus/prometheus v0.309.1` → [Updates: `v0.311.3`]
- `github.com/stretchr/testify v1.11.1` → [Updates: `v1.12.1`]
- `github.com/tinylib/msgp v1.3.0` → [Updates: `v1.6.4`]
- `go.uber.org/atomic v1.11.0`
- `golang.design/x/chann v0.1.2` → [Updates: `v0.2.1`]
- `github.com/cespare/xxhash/v2 v2.3.0`
- `github.com/elastic/go-freelru v0.16.0`
- `github.com/prometheus/client_golang/exp v0.0.0-20251212205219-7ba246a648ca@7ba246a648ca` → [Updates: `v0.0.0-20260914085653-d2f148ba5de4`]
- `github.com/beorn7/perks v1.0.1`
- `github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc@d8f796af33cc`
- `github.com/dennwc/varint v1.0.0`
- `github.com/go-logfmt/logfmt v0.6.0` → [Updates: `v0.6.1`]
- `github.com/golang-jwt/jwt/v5 v5.3.0` → [Updates: `v5.3.1`]
- `github.com/google/uuid v1.6.0`
- `github.com/grafana/regexp v0.0.0-20250905093917-f7b3be9d1853@f7b3be9d1853`
- `github.com/jpillora/backoff v1.0.0`
- `github.com/kr/text v0.2.0`
- `github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822@a7dc8b61c822`
- `github.com/mwitkow/go-conntrack v0.0.0-20190716064945-2f068394615f@2f068394615f`
- `github.com/philhofer/fwd v1.2.0`
- `github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2@5d4384ee4fb2`
- `github.com/prometheus/procfs v0.16.1` → [Updates: `v0.22.0`]
- `github.com/rogpeppe/go-internal v1.14.1` → [Updates: `v1.16.0`]
- `go.yaml.in/yaml/v2 v2.4.3` → [Updates: `v2.4.4`, `v3.0.5`]
- `golang.org/x/exp v0.0.0-20250808145144-a408d31f581a@a408d31f581a` → [Updates: `v0.0.0-20260908205506-85c1c2202aba`]
- `golang.org/x/net v0.48.0` → [Updates: `v0.56.0`]
- `golang.org/x/oauth2 v0.34.0` → [Updates: `v0.37.0`]
- `golang.org/x/sys v0.39.0` → [Updates: `v0.44.0`]
- `golang.org/x/text v0.32.0` → [Updates: `v0.39.0`]
- `google.golang.org/protobuf v1.36.11` → [Updates: `v1.36.12`]
- `gopkg.in/yaml.v3 v3.0.1`
- `github.com/deneonet/benc v1.1.7` → [Updates: `v1.1.8`]

---
## Need help?
You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.