Skip to content

chore(deps): update ⬆️ vet-packages - #1100

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/vet-packages
Oct 7, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/vet-packages

Conversation

@renovate

@renovate renovate Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Age Adoption Passing Confidence
aqua:aquasecurity/trivy tools minor 0.74.0 → 0.75.0 age adoption passing confidence
pipx:semgrep (changelog) tools minor 1.178.0 → 1.179.0 age adoption passing confidence

Release notes are maintained in a PR comment by the renovate-release-notes-comment workflow.


Configuration

📅 Schedule: (in timezone America/Los_Angeles)

  • Branch creation
    • Between 03:00 AM and 05:59 AM (* 3-5 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from scottames as a code owner October 7, 2026 10:24
@renovate renovate Bot added the dependencies label Oct 7, 2026
@renovate
renovate Bot enabled auto-merge (squash) October 7, 2026 10:24
@scottames-github-bot

Copy link
Copy Markdown
Contributor

Renovate Release Notes

Generated from Renovate's update table by the renovate-release-notes-comment workflow.

Packages that cannot be summarized from GitHub releases are listed explicitly below.

aquasecurity/trivy (aqua:aquasecurity/trivy)

v0.75.0: v0.75.0

Compare Source

⚡ Highlights ⚡

👉 aquasecurity/trivy#11333

Changelog

https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0750-2026-10-01

semgrep/semgrep (pipx:semgrep)

v1.179.0: Release v1.179.0

Compare Source

1.179.0 - 2026-10-01

### Added

  • Semgrep Supply Chain now parses Bun bun.lock lockfiles (text format, lockfileVersion 1) paired with a package.json manifest, including the dependency relationships between packages. The deprecated binary bun.lockb format is still unsupported. (SC-2419)

### Changed

  • Pro: Stabilize file processing order in inter-file analysis, which was previously arbitrary but deterministic. We believe this is very unlikely to affect findings but there is a theoretical path by which it could in certain rare cases. (stabilize)

  • c grammar update (v0.24.2):

    • No verified user-facing improvements: Agent feature assessment was not run for this grammar.

    (c-v0.24.2)

  • cpp grammar update (v0.23.4):

    • C++ target parsing now supports attributes on namespace definitions and preserves their arguments in the AST.
    • C++ target parsing now supports reference typedef declarators, including references to arrays and functions.
    • C++ target parsing now supports C++20 lambda pack init-captures such as [...values = args] and [&...values = args]. Capture-sensitive matching remains an existing limitation.
    • C++ target parsing now supports GNU inline-assembly output operands that are expressions, including pointer dereferences and array accesses.
    • C++ target parsing now supports composite type arguments in alignas declarations, such as alignas(int *), while preserving the alignment argument.
    • C++ target parsing now accepts single-digit hexadecimal escapes in string literals, such as "\xA", while retaining support for longer hexadecimal escapes.

    (cpp-v0.23.4)

  • Update the html grammar to v0.23.2. (html-v0.23.2)

  • r grammar update (v1.3.0):

    • R target parsing now supports unary and binary help expressions (?) and exponentiation written with **.
    • R target parsing correctly represents hexadecimal fractional and exponent literals, including imaginary forms, and decimal or exponent notation with the L suffix.
    • R target parsing now supports quoted namespace and slot names, such as "base"::"mean" and x@​"slot".
    • R parsing preserves else branches placed on a new line within braced expressions.
    • R string parsing preserves literal newlines and excludes raw-string delimiters from string values. Short hexadecimal and Unicode escape spellings are accepted; escape decoding remains unchanged.
    • R parsing preserves omitted argument positions in calls and subscripts, and retains the indexed expression for single-index subscripts.

    (r-v1.3.0)

  • sfapex grammar update (v2.3):

    • Apex target parsing now supports null-coalescing expressions using ??, preserving both operands.
    • Apex target parsing now supports DML operations with explicit as user and as system security modes, retaining the mode, operation targets, and optional upsert key.
    • Apex target parsing now supports numeric package-version expressions such as Package.Version.1.2.
    • Apex target parsing now recognizes the webservice modifier and annotations with empty argument lists.
    • Apex target parsing now accepts whitespace within relational and shift operators, including compound shift assignments.
    • Embedded SOQL parsing in Apex now supports dotted TYPEOF operands, functions such as convertTimezone, and HAVING comparisons on grouped fields.
    • Apex target parsing now supports multiple top-level method declarations followed by executable statements in anonymous Apex.
    • Apex parsing now preserves native java: qualifiers on types and supports java:-prefixed field-access expressions.
    • Apex patterns now distinguish safe navigation (?.) from ordinary field and method access (.).

    (sfapex-v2.3)

### Fixed

  • Python: except A, B: and except A, B, C: (PEP 758, Python 3.14) and the
    except* forms of both are now parsed as a tuple of exception types, like
    except (A, B):, rather than as the Python 2 except A as B: or a parse
    error. except* is now handled by Semgrep's primary Python parser too, so
    exception groups no longer depend on the fallback parser. Note that Python
    2's except A, e: is no longer read as except A as e:, even for python2.
    One limitation remains: the vendored tree-sitter Python grammar still accepts
    only a single comma, so except A, B, C: is still a parse error there. The
    menhir parser runs first and handles it, so this only surfaces if the
    tree-sitter fallback is reached; upgrading the vendored grammar is follow-up
    work. (gh-11906)
  • Fix Dockerfile parsing for environment-expanded EXPOSE ports with TCP/UDP protocols. (gh-11934)
  • Semgrep now allows PyJWT 2.15 and later (pyjwt[crypto]>=2.15.0,<3) instead of
    pinning ~=2.13.0, so installs pick up a PyJWT release with fixes for known
    vulnerabilities, and projects that require a newer PyJWT can install Semgrep. (gh-11953)

@renovate
renovate Bot merged commit 0d0d8d0 into main Oct 7, 2026
6 checks passed
@renovate
renovate Bot deleted the renovate/vet-packages branch October 7, 2026 10:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants