Skip to content

Update all non-major dependencies - #19

Open
libops-renovate[bot] wants to merge 1 commit into
mainfrom
renovate.all-non-major-dependencies
Open

Update all non-major dependencies#19
libops-renovate[bot] wants to merge 1 commit into
mainfrom
renovate.all-non-major-dependencies

Conversation

@libops-renovate

@libops-renovatelibops-renovateBot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageUpdateChange
apache-activemq5patch5.19.85.19.10
apache-activemq6minor6.2.76.3.1
apache-tomcat11patch11.0.2311.0.25
apache-tomcat9patch9.0.1199.0.121
archivesspacepatch4.2.04.2.1
fcrepo6patch6.5.16.5.2
moby/buildkitminorv0.31.0v0.32.2
solr-ocrhighlightingminor0.9.50.10.1

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

archivesspace/archivesspace (archivesspace)

v4.2.1

Compare Source

Release notes for v4.2.1

This patch release contains a small number of bug fixes and improvements. It addresses several issues introduced in 4.2.0, mainly failures when trying to load records that have many linked records of specific types and the inability to start ArchivesSpace when using the embedded Derby database.

Please note that, while resolved for this release, version 4.2.1 will be the last to support this embedded database. The embedded database has always been intended only for testing purposes and not for production. Running with docker is now the supported way to get ArchivesSpace up and running with minimal requirements

Additionally, there are some very small locale file updates, a bug fix to a button color, replacements for two keyboard shortcuts that clashed with common shortcuts on Windows machines, and the addition of log rotation for Docker installs.

There are two community contributions in this release. Though MySQL is our only officially supported database, thanks to a community contribution by Will Martin, this release also restores full functionality for the bulk spreadsheet importers when using MariaDB. A community contribution from Mark Cooper updates the initialize plugin script to fix an issue that was preventing dependencies from installing upgraded versions of ArchivesSpace’s bundled gems.

Configurations and Migrations

This release includes no modifications to the configuration defaults file.

This release includes 0 new database migrations. The schema number for this release is UNCHANGED.

Other considerations (plugins etc.):
Derby based embedded Demo database deprecation

Version 4.2.1 will be the last to support the embedded derby database. The embedded database has always been intended only for testing purposes and not for production. Running with docker is now the supported way to get ArchivesSpace up and running with minimal requirements.

Plugin initializer updates

The plugin initializer has been updated to address the issue of plugins dragging newer copies of shared gems than those bundled in the core application. The updated mechanism discovers each installed plugin's transitive dependencies and bundle installs within constraints determined by versions embedded in the application war packages. The process fails if a dependency lands that isn't aligned with what core and the wars support. See [#​4054] for more details.

Community Contributions

Our thanks go out to these members of the community for their code contributions:

  • Will Martin:
  • Mark Cooper:

Total community contributions accepted: 2

JIRA Tickets and Pull Requests Completed
  • PR: 4097, 4158 - ANW-2759: ANW-2759 release notes generation improvements.
  • PR: 4148 - ANW-2717: ANW-2717 fix linking agents to resources on derby embedded demo db
  • PR: 4155 - ANW-2816: downloading Bulk AO updater spreadsheet times out for large resources
  • PR: 4127 - ANW-2706: ANW-2706 Fix Softserv-related button color bug when reorder mode auto-expand all is enabled
  • PR: 4126 - ANW-2740: don't override Windows & Linux browser keyboard commands for "cut text" and "save page"
  • PR: 4117: agent contact typo
  • PR: 4115, 4076 - ANW-2717: fix errors on embedded demo db (derby)
  • PR: 4113 - ANW-652: ANW-652 fix performance of classification show action on SUI
  • PR: 4110 - ANW-2762: Classification with 400+ Linked Records Can Cause Errors "total query size exceeds limit"
  • PR: 4071 - ANW-2727: ANW-2727 add docker log rotation for all services in docker
  • PR: 4054: Add new jruby initialize plugin script
  • PR: 4048: Update to repository processing note tool tip
  • PR: 4044 - ANW-2647: ANW-2647 maria db bulk import

Total Pull Requests accepted: 11
Total Jira Tickets closed: 9

fcrepo/fcrepo (fcrepo6)

v6.5.2

Compare Source

What's Changed

  • Prepare 6.5.2 on new 6.5-maintenance line (S3 backports + search perf + SDK bump) by @​Surfrdan in #​2319

Full Changelog: fcrepo/fcrepo@fcrepo-6.5.1...fcrepo-6.5.2

moby/buildkit (moby/buildkit)

v0.32.2

Compare Source

Welcome to the v0.32.2 release of buildkit!

Please try out the release binaries and report any issues at
https://github.com/moby/buildkit/issues.

Contributors
  • CrazyMax
Notable Changes
  • Revert the v0.32.1 OCI artifact attestation push-order workaround, restoring BuildKit's spec-aligned behavior of allowing referrers to be pushed before their subject manifests. #​7016
Dependency Changes

This release has no dependency changes

Previous release can be found at v0.32.1

v0.32.1

Compare Source

Welcome to the v0.32.1 release of buildkit!

Please try out the release binaries and report any issues at
https://github.com/moby/buildkit/issues.

Contributors
  • CrazyMax
Notable Changes
  • Fix archive extraction through implied parent directories and absolute symlinks. #​7005
  • Fix OCI artifact attestation pushes to registries that strictly validate subject references. #​7012
Dependency Changes
  • github.com/moby/go-archive v0.2.1 -> v0.2.0

Previous release can be found at v0.32.0

v0.32.0

Compare Source

Welcome to the v0.32.0 release of buildkit!

Please try out the release binaries and report any issues at
https://github.com/moby/buildkit/issues.

Contributors
  • Tõnis Tiigi
  • CrazyMax
  • Sebastiaan van Stijn
  • Akihiro Suda
  • Dawei Wei
  • Felix de Souza
  • Alberto Garcia Hierro
  • Devendra Kushwah
  • Giles Cope
  • Kunalbehbud
  • MohammadHasan Akbari
  • Natnael Gebremariam
  • Pierre Fenoll
  • Simon Aguilera
  • s3onghyun
Notable Changes
  • Built-in Dockerfile frontend has been updated to v1.26.0. changelog
  • Attestations now default to OCI artifact descriptors, use oci-artifacts=false if your registry does not support OCI artifacts. #​6914
  • Build steps can now opt out of default OpenTelemetry tracing or define custom tracing configuration. #​6958
  • Bolt database performance has been improved. #​6943
  • Included Runc container runtime has been updated to v1.4.3. #​6853
  • All remote cache backends now use OCI mediatypes for record descriptors. #​6913
  • Source policy identifiers are now normalized before sending them to policy evaluation. #​6909
  • SBOM scanner support for Windows has been added. #​6941
  • Session exporters now support an optional finalization callback after exports complete, allowing providers to run completion logic while gateway references are still available. #​6978
  • Lock contention in the LLB solver has been reduced. #​6917
  • Improve SSH support when using non-standard ports. #​6895
  • Improve validation of reading contents of invalid files via API. #​6903
  • Deprecated OTEL fallback variables OTEL_TRACE_PARENT, OTEL_TRACE_STATE are no longer supported. Use TRACEPARENT and TRACESTATE instead. #​6874
  • Fix possible cache miss issue on parallel builds with shared parts. #​6955
  • Fix chunked encoding support for S3-compatible remote cache backends. #​6970
  • Fix regression on handling OTEL_IGNORE_ERROR environment variable. #​6966
Dependency Changes
  • github.com/Microsoft/go-winio v0.6.2 -> ad3df93
  • github.com/Microsoft/hcsshim v0.14.1 -> v0.15.0-rc.1
  • github.com/ProtonMail/go-crypto v1.3.0 -> v1.4.1
  • github.com/aws/aws-sdk-go-v2 v1.42.0 -> v1.43.0
  • github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.13 -> v1.7.14
  • github.com/aws/aws-sdk-go-v2/config v1.32.24 -> v1.32.31
  • github.com/aws/aws-sdk-go-v2/credentials v1.19.23 -> v1.19.30
  • github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.29 -> v1.18.31
  • github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.2.9 -> v0.3.5
  • github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.29 -> v1.4.31
  • github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.29 -> v2.7.31
  • github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.30 -> v1.4.32
  • github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.12 -> v1.13.13
  • github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.22 -> v1.9.24
  • github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.29 -> v1.13.31
  • github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.29 -> v1.19.32
  • github.com/aws/aws-sdk-go-v2/service/s3 v1.103.3 -> v1.106.0
  • github.com/aws/aws-sdk-go-v2/service/signin v1.1.5 -> v1.5.0
  • github.com/aws/aws-sdk-go-v2/service/sso v1.31.3 -> v1.33.0
  • github.com/aws/aws-sdk-go-v2/service/ssooidc v1.36.6 -> v1.38.0
  • github.com/aws/aws-sdk-go-v2/service/sts v1.43.3 -> v1.45.0
  • github.com/aws/smithy-go v1.27.2 -> v1.27.4
  • github.com/containerd/containerd/api v1.10.0 -> v1.11.1
  • github.com/containerd/containerd/v2 v2.2.4 -> v2.3.3
  • github.com/containerd/plugin v1.0.0 -> v1.1.0
  • github.com/containerd/ttrpc v1.2.8 -> v1.2.9
  • github.com/docker/cli v29.5.3 -> v29.6.2
  • github.com/go-openapi/errors v0.22.7 -> v0.22.8
  • github.com/go-openapi/loads v0.23.3 -> v0.24.0
  • github.com/go-openapi/runtime v0.32.3 -> v0.32.4
  • github.com/go-openapi/spec v0.22.5 -> v0.22.6
  • github.com/go-openapi/strfmt v0.26.3 -> v0.26.4
  • github.com/go-openapi/swag v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/cmdutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/conv v0.26.0 -> v0.27.0
  • github.com/go-openapi/swag/fileutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/jsonname v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/jsonutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/loading v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/mangling v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/netutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/stringutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/swag/typeutils v0.26.0 -> v0.27.0
  • github.com/go-openapi/swag/yamlutils v0.26.0 -> v0.26.1
  • github.com/go-openapi/validate v0.25.3 -> v0.26.0
  • github.com/gohugoio/hashstructure v0.6.0 new
  • github.com/google/go-containerregistry v0.21.6 -> v0.21.7
  • github.com/klauspost/compress v1.18.6 -> v1.19.1
  • github.com/moby/go-archive v0.2.0 -> v0.2.1
  • github.com/moby/policy-helpersd5411a9 -> 856be88
  • github.com/moby/sys/mountfc52b72 -> v0.3.5
  • github.com/moby/sys/user v0.4.0 -> v0.4.1
  • github.com/sigstore/rekor v1.5.2 -> v1.5.3
  • github.com/sigstore/rekor-tiles/v25d098a2 -> v2.3.0
  • github.com/sigstore/sigstore-go v1.2.1 -> v1.2.2
  • github.com/tonistiigi/fsutil30cd4fc -> 6d9dc2e
  • go.etcd.io/bbolt v1.4.3 -> v1.5.0
  • go.opentelemetry.io/otel/exporters/prometheus v0.65.0 -> v0.66.0
  • golang.org/x/crypto v0.52.0 -> v0.54.0
  • golang.org/x/mod v0.36.0 -> v0.38.0
  • golang.org/x/net v0.55.0 -> v0.57.0
  • golang.org/x/sync v0.20.0 -> v0.22.0
  • golang.org/x/sys v0.45.0 -> v0.47.0
  • golang.org/x/term v0.43.0 -> v0.45.0
  • golang.org/x/text v0.37.0 -> v0.40.0
  • google.golang.org/grpc v1.81.1 -> v1.82.1
  • google.golang.org/protobuf v1.36.11 -> f2248ac

Previous release can be found at v0.31.2

v0.31.2

Compare Source

Welcome to the v0.31.2 release of buildkit!

This is a security patch release with four moderate and one low severity security fixes.

Please try out the release binaries and report any issues at
https://github.com/moby/buildkit/issues.

Contributors
  • Tõnis Tiigi
  • CrazyMax
  • Dawei Wei
Notable Changes
  • Git source checkout from a bundle file could lead to command injection. GHSA-hw3h-2gp9-cxpv
  • Possible panic when incorrect parameters sent from frontend. GHSA-qx3x-mv6r-52p6
  • LLB file operation can be tricked to remove /tmp directory contents. GHSA-32pv-7hq5-qhwq
  • Malicious client can bypass destination directory validation on local sources upload. GHSA-g2h8-426c-7976
  • WCOW cache mount source selector resolves NTFS junctions outside of cache root. GHSA-388v-wmr2-g2v2
  • Fix possible buildctl failures after successful builds over slow connhelper transports. #​6940
  • Fix possible daemon crash during concurrent builds. #​6916
Dependency Changes

Previous release can be found at v0.31.1

v0.31.1

Compare Source

buildkit 0.31.1

Welcome to the v0.31.1 release of buildkit!

This is a security patch release with two low severity security fixes.

Please try out the release binaries and report any issues at
https://github.com/moby/buildkit/issues.

Contributors
  • Tõnis Tiigi
Notable Changes
Dependency Changes

This release has no dependency changes

Previous release can be found at v0.31.0

dbmdz/solr-ocrhighlighting (solr-ocrhighlighting)

v0.10.1

Compare Source

Fixed

  • ALTO indexing is now more tolerant of whitespace inside of element
    declarations, fixing e.g. parsing of the Transkribus default ALTO formatting

v0.10.0: : Solr 10 compatibility, Hyphenation Fixes

Compare Source

Changed

  • Added compatibility with Solr 10
  • Automated tagged releases: CI now validates release metadata, publishes
    GitHub releases from the changelog, deploys versioned documentation and
    updates the Solr plugin repository metadata

Dependencies

  • Updated Solr to 10.0.0 and Lucene to 10.3.2
  • Updated Commons Text to 1.15.0, Commons IO to 2.22.0 and Guava to
    33.6.0-jre

Deprecated

  • WIP/pre-release builds from main are no longer published to GitHub
    Releases, the documentation site or the Solr plugin repository; use tagged
    releases instead

Fixed

  • Highlighting of hyphenated words when context was set to 0 lines, in this
    case we now include the line with the second part of the hyphenation on the
    next line.
  • Sometimes the second part of a hyphenated word in a fragment would get
    skipped

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Only on Wednesday (* * * * 3)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@libops-renovate
libops-renovateBotforce-pushed the renovate.all-non-major-dependencies branch 3 times, most recently from 24f6d34 to 737e4b0CompareJuly 26, 2026 11:40
@libops-renovate
libops-renovateBotforce-pushed the renovate.all-non-major-dependencies branch from a30463e to b4dd328CompareAugust 18, 2026 10:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants