Skip to content

chore(deps): update github actions - #51

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/github-actions
Oct 1, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
aqua uses-with minor v2.48.1 → v2.63.0
aws-actions/configure-aws-credentials action minor v6.2.3 → v6.3.0
masterpointio/actions workflow minor v0.3.0 → v0.4.0

Release Notes

aquaproj/aqua (aqua)

v2.63.0

Compare Source

Security

Fix a path traversal vulnerability GHSA-286g-rf2x-cv99.
When a package archive contained a GNU sparse file, aqua re-extracted the whole archive with the host tar, applying none of its own path or symlink containment. On hosts whose tar follows symlinks during extraction (e.g. BusyBox tar), a crafted archive could plant a symlink escaping the install directory and write a regular file through it. aqua now keeps the system tar out of the install directory: it validates the sparse member names, extracts them into a staging directory, and moves each to its verified destination itself.

Features

#​5117 Create timestamp files as group writable and document read only $AQUA_ROOT_DIR
#​5115 Support AQUA_DISABLE_TRACKING to disable the tracking of last used date times

Fixes

#​5237 Skip minisign verification if the host platform doesn't support minisign
#​5188 Ignore incomplete release assets in aqua gr
#​5178 Support files[].src in go_install packages
#​5171 Extract 7z archives that use the ARM64 filter
#​5161 signer_workflow is a literal path, not a regex

Others

#​5239 Fix Dockerfile build failure caused by a stale apt package index

v2.62.3

Compare Source

🐛 Bug Fixes

#​4840 update-checksum: Consider variants when enumerating package assets

v2.62.2

Compare Source

Features

#​5085 Update github.com/suzuki-shunsuke/ghtkn-go-sdk v0.4.1 to v0.5.0

https://github.com/suzuki-shunsuke/ghtkn-go-sdk/releases/tag/v0.5.0

v2.62.1

Compare Source

🐛 Bug Fixes

#​5048 unarchive: expand a pkg file into a non-existent destination
#​5051 installpackage: create package directories with the usual permissions

v2.62.0

Compare Source

Features

#​5024 Embed fallback X.509 roots to support sandboxed environments

Fixes

#​5018 More signature related filename extension exclusions @​scop
#​5025 Extract packages into a temp dir and rename atomically

Documentation

#​5023 Add a guide to use aqua with Claude Code's sandbox

v2.61.0

Compare Source

Features

#​5002 unarchive: Fall back to the system tar for GNU sparse tarballs
#​4971 genrate-registry: Prefer .sha512 > .sha256 > .sha1 > .md5 @​scop

v2.60.2

Compare Source

Improvements

Update ghtkn-go-sdk to v0.4.1

  • Disable the automatic device flow by default
  • Support min_expiration and backend.type in the configuration file
  • Add app names to error messages

🐛 Bug Fixes

#​4990 #​4992 unarchive: allow benign symlinks that point outside the extraction directory
#​4974 help: make the help message consistent

Refactoring

#​4958 Remove more GitHub release attestation support remnants @​scop

Documentation

#​4967 Checksum pattern extraction from first capturing group @​scop

v2.60.1

Compare Source

⚠️ Security Fixes

d5b02b2 fix(unarchive): prevent archive extraction from writing outside the destination
For more details, please see the security advisory.

⚠️ Release Asset Naming Convention for Cosign Was Changed
  • *.sig and *.pem files are no longer included in the release assets
  • *.bundle files are renamed to *.sigstore.json
Fixes

#​4938 Remove GitHub Release Attestation verification

v2.60.0

Compare Source

Features

#​4894 Update ghtkn-go-sdk to v0.3.0 to support new features suche as backends and disabling device flow

New Contributors

v2.59.1

Compare Source

Fixes

#​4865 gr: don't treat *.minisig as checksum files @​scop

v2.59.0

Compare Source

Features

#​4517 Get checksums from GitHub API Release Asset Digest

v2.58.1

Compare Source

Fixes

#​4786 checksum: Change the algorithm to sha256 when registry file isn't cached

v2.58.0

Compare Source

Features

#​4733 #​4742 #​4755 Add the variants override mechanism with libc detection

https://aquaproj.github.io/docs/reference/registry-config/overrides/#variants

#​4667 Refactor GitHub release attestations control naming @​scop

[!WARNING]
github_immutable_release was deprecated. Use github_release_attestations instead.

#​4634 Get a GitHub access token from AQUA_GITHUB_TOKEN and pass it to gh command if GH_TOKEN and GITHUB_TOKEN aren't set

Document

#​4729 Update edit URL in docusaurus configuration @​dsychin
#​4756 Add musl vs glibc section to registry style guide

v2.57.2

Compare Source

Fixes

#​4719 Fix jar support
#​4722 Map x86-64 to amd64
#​4688 Normalize CRLF line endings in checksum file parser

Documentation

#​4668 Deprecate signer-workflow @​scop
#​4663 JSON Schema: signer-workflow string format @​scop

v2.57.1

Compare Source

🐛 Bug Fixes

#​4659 Fix a bug that aqua update-checksum doesn't verify checksum files using tools like Cosign

v2.57.0

Compare Source

Features

#​4625 Support executing .jar

If aqua which returns a .jar file, aqua executes it by java -jar.
This requires java command.

Fixes

#​4629 Re-add env field to log

v2.56.7

Compare Source

Bug Fixes

#​4585 remove: fix a bug that -i doesn't work

Refactoring

#​4527 Refactor Checksum Verification

Document

#​4560 Fix typos and invalid links in documents @​kangetsu121

Dependency Updates
  • chore(deps): update dependency anchore/syft to v1.42.1 in #​4576
  • chore(deps): update dependency go to v1.26.0 in #​4550
  • fix(deps): update module golang.org/x/sys to v0.41.0 in #​4545
  • refactor: migrate to math/rand/v2 by @​scop in #​4547
  • fix(deps): update module golang.org/x/oauth2 to v0.35.0 in #​4541
  • fix(deps): update module github.com/expr-lang/expr to v1.17.8 in #​4564
  • fix(deps): update module github.com/suzuki-shunsuke/urfave-cli-v3-util to v0.2.2 in #​4574
  • chore(deps): update dependency sigstore/cosign to v3.0.5 in #​4578
  • fix(deps): update module github.com/google/go-github/v82 to v83 in #​4568
  • chore: update aqua-proxy to v1.2.13 in #​4588

v2.56.6

Compare Source

🐛 Bug Fixes

#​4510 Fix a bug that -log-color doesn't work
#​4526 aqua gr: Fix a bug that win32 are excluded

v2.56.5

Compare Source

🐛 Bug Fixes

#​4495 Fix a bug that aqua gr's -cmd option doesn't work

This was a bug of v2.56.2 ~ v2.56.4. #​4450

v2.56.4

Compare Source

🐛 Bub Fixes

#​4484 #​4485 Prevent duplicate log field output

v2.56.3

Compare Source

🐛 Bug Fixes

#​4475 cp: Fix a bug that command arguments are ignored and always all commands are copied
#​4476 update-aqua: Fix a bug that a command argument is ignored and always the latest version is installed

Others

#​4471 Update sigstore/cosign to v3.0.4

v2.56.2

Compare Source

Refactoring

#​4448 Replace logrus with slog
#​4450 Use urfave/cli/v3 Destination pattern for flag values

v2.56.1

Compare Source

Fixes

#​4436 gr: Exclude eabihf

v2.56.0

Compare Source

Features

#​4422 Get pseudo-versions from Go Proxy if no tagged version exists @​gizmoguy

Fixes

#​4401 Add YAML tags @​Shion1305
#​4404 Update golangci-lint to v2.7.2, with lint fixes @​Shion1305

Dependency Updates

#​4402 Update goreleaser to v2.13.1
#​4405 Update anchore/syft to v1.38.2
#​4406 Update Cosign to v3.0.3
#​4420 Update expr to v1.17.7
#​4424 Update goccy/go-yaml to v1.19.1

v2.55.3

Compare Source

Bug Fixes

#​4393 gr: Fix the support of sigstore and sigstore.json file extensions

Refactoring

#​4369 Enable tagalign rule in golangci-lint @​Shion1305
#​4394 chore(deps): migrate to go.yaml.in/yaml @​scop

v2.55.2

Compare Source

Performance Improvement

#​4342 Skip packages that cannot provide the desired exe @​refi64

Others

#​4312 Update Go to 1.25.4

v2.55.1

Compare Source

🐛 Bug Fixes

#​4274 #​4276 exec: Fix the command name (args[0])

Dependency Updates

#​4220 #​4266 Update github.com/google/go-github/v74 to v76
#​4233 #​4251 #​4261 Update Go to 1.25.2

Others

Release Cosign Bundle file *.bundle

v2.55.0

Compare Source

Features

#​4195 #​4213 Support verifying the integrity of GitHub Releases

https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/verifying-the-integrity-of-a-release
https://aquaproj.github.io/docs/reference/security/github-immutable-release

v2.54.1

Compare Source

🐛 Bug Fixes

#​4182 Fix a bug of generate-registry command that arm64 is replaced to arm incorrectly

v2.54.0

Compare Source

Features

#​4173 ghtkn integration

https://aquaproj.github.io/docs/reference/security/ghtkn/

Now aqua can get a GitHub App User Access Token by ghtkn integration.
Stop risking token leaks - Use secure, short-lived GitHub tokens for local development.

Requirements

The ghtkn integration requires:

  • Keyring

This feature doesn't depend on ghtkn CLI.

Limitation

The integration requires the user interaction when creating an access token via Device Flow, so it's unavailable in CI.

Set up

For more details, please see https://github.com/suzuki-shunsuke/ghtkn .

  1. Create a GitHub App
  2. Create a configuration file of ghtkn
  3. Set the environment variable AQUA_GHTKN_ENABLED=true
export AQUA_GHTKN_ENABLED=true

Then aqua gets a user access token using ghtkn Go SDK when aqua calls GitHub APIs.

v2.53.11

Compare Source

Performance Improvement

#​4159 Update github.com/gdamore/tcell/v2 to reduce startup time @​refi64

Benchmark
$ git rev-parse HEAD
380a2334230ec9fd22adac3f4e137a4cf47d42b2

$ go version
go version go1.25.1 darwin/arm64

$ hyperfine --version
hyperfine 1.19.0

$ ls dist                         
aqua  aqua-25310

aqua.yaml

registries:
- type: standard
  ref: v4.408.0 # renovate: depName=aquaproj/aqua-registry
packages:
- name: suzuki-shunsuke/mkghtag@v0.1.11
- name: suzuki-shunsuke/cmdx@v2.0.2
$ hyperfine --warmup=20 -N 'dist/aqua'{-25310,}' exec -- mkghtag -version'
Benchmark 1: dist/aqua-25310 exec -- mkghtag -version
  Time (mean ± σ):      24.7 ms ±   1.3 ms    [User: 2.7 ms, System: 1.6 ms]
  Range (min … max):    23.5 ms …  29.6 ms    125 runs
 
  Warning: Statistical outliers were detected. Consider re-running this benchmark on a quiet system without any interferences from other programs. It might help to use the '--warmup' or '--prepare' options.
 
Benchmark 2: dist/aqua exec -- mkghtag -version
  Time (mean ± σ):      10.8 ms ±   1.4 ms    [User: 2.4 ms, System: 1.6 ms]
  Range (min … max):     9.2 ms …  17.1 ms    250 runs
 
Summary
  dist/aqua exec -- mkghtag -version ran
    2.30 ± 0.33 times faster than dist/aqua-25310 exec -- mkghtag -version
$ hyperfine --warmup=20 -N 'dist/aqua'{-25310,}' exec -- cmdx -v'         
Benchmark 1: dist/aqua-25310 exec -- cmdx -v
  Time (mean ± σ):      25.7 ms ±   1.3 ms    [User: 3.5 ms, System: 1.7 ms]
  Range (min … max):    24.5 ms …  31.7 ms    120 runs
 
  Warning: Statistical outliers were detected. Consider re-running this benchmark on a quiet system without any interferences from other programs. It might help to use the '--warmup' or '--prepare' options.
 
Benchmark 2: dist/aqua exec -- cmdx -v
  Time (mean ± σ):      11.2 ms ±   1.0 ms    [User: 3.1 ms, System: 1.6 ms]
  Range (min … max):    10.2 ms …  15.9 ms    253 runs
 
  Warning: Statistical outliers were detected. Consider re-running this benchmark on a quiet system without any interferences from other programs. It might help to use the '--warmup' or '--prepare' options.
 
Summary
  dist/aqua exec -- cmdx -v ran
    2.30 ± 0.24 times faster than dist/aqua-25310 exec -- cmdx -v

v2.53.10

Compare Source

🛡️ Starting from this release, Immutable Release is enabled!

#​4147 Update Go to v1.25.1
#​4145 Update aqua-proxy to v1.2.12

🐛 Bug Fixes

#​4140 Fix error messages

v2.53.9

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.53.8...v2.53.9

🐛 Bug Fixes

#​4064 Fix a bug that environment variables aren't passed to gh attestation verify

Others

#​4065 Update Go to v1.24.6
#​4065 Update aqua-proxy to v1.2.11

go1.24.6 (released 2025-08-06) includes security fixes to the database/sql and os/exec packages, as well as bug fixes to the runtime.
See the Go 1.24.6 milestone on our issue tracker for details.

v2.53.8

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.53.7...v2.53.8

🐛 Bug Fixes

#​4047 cp: Add missing .exe on Windows @​W1M0R

v2.53.7

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.53.6...v2.53.7

Fixes

#​4038 Fix a bug that it fails to verify GitHub Artifact Attestations on GitHub Enterprise Server @​yamoyamoto

v2.53.6

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.53.5...v2.53.6

🐛 Bug Fixes

#​4024 #​4025 Fix a bug that aqua works without registries' ref
#​4019 Set User-Agent to GitHub Release downloads @​yanolab

[!WARNING]
About #​4019 , unfortunately the bug is still remaining. But maybe #​4019 mitigates the bug to some extent.

v2.53.5

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.53.4...v2.53.5

#​4008 Fix Homebrew tap to remove the quarantine bit from the binary on a post install hook

v2.53.4

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.53.3...v2.53.4

#​3995 Add license files of Go and Go modules to released assets
#​3995 Release SBOM
#​3995 Update Go to 1.24.5
#​3996 Update aqua-proxy to v1.2.10

v2.53.3

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.53.2...v2.53.3

🐛 Bug Fixes

#​3957 Fix Shell Completion

Dependency Updates

#​3956 Cosign v2.5.2
#​3942 github.com/urfave/cli/v3 v3.3.8

Refactoring

#​3949 apply gopls modernize improvements @​scop

v2.53.2

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.53.1...v2.53.2

🐛 Bug Fixes

#​3932 Fix the issue that aqua can't be installed by go install

v2.53.1

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.53.0...v2.53.1

🐛 Bug Fixes

#​3926 checksum: Fix a bug that checksums of awslabs/amazon-ecr-credential-helper are wrong

Others

#​3924 gr: Map arm to arm64

v2.53.0

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.52.0...v2.53.0

Features

#​3920 Retry HTTP requests for robustness

v2.52.0

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.51.2...v2.52.0

Features

#​3890 feat(generate-registry): cosign bundle support @​scop

Update dependencies

#​3915 Update golang.org/x/sync to v0.15.0
#​3876 #​3903 #​3912 Update github.com/expr-lang/expr to v1.17.5
#​3905 Update github.com/goccy/go-yaml to v1.18.0
#​3881 Update github.com/mholt/archives to v0.1.2
#​3870 Update github.com/google/go-github/v71 to v72

Others

#​3891 chore(golangci-lint): remove gofmt, it's a gofumpt subset @​scop

v2.51.2

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.51.1...v2.51.2

🐛 Bug Fixes

#​3868 Fix version command

Dependency Updates

update module github.com/urfave/cli/v3 to v3.3.3 (#​3866)
golang.org/x/term to v0.32.0 (#​3863)

v2.51.1

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.51.0...v2.51.1

Features

#​3852 #​3853 Support managing a GitHub access token using Keyring

You can now manage a GitHub Access token using secret store such as Windows Credential Manager, macOS Keychain, and GNOME Keyring.

  1. Configure a GitHub Access token by aqua token set command:
$ aqua token set
Enter a GitHub access token: # Input GitHub Access token

or you can also pass a GitHub Access token via standard input:

echo "<github access token>" | aqua tokn set -stdin
  1. Enable the feature by setting the environment variable AQUA_KEYRING_ENABLED:
export AQUA_KEYRING_ENABLED=true

Note that if the environment variable GITHUB_TOKEN is set, this feature gets disabled.

You can remove a GitHub Access token from keyring by aqua token rm command:

aqua token rm

v2.51.0

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.50.1...v2.51.0

[!WARNING]
We intended to add a new command token in this release, but we forgot it.
Please use v2.51.1 or newer.

v2.50.1

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.50.0...v2.50.1

Improve the performance of command execution

#​3826

This release improves the performance of aqua which and aqua exec command.

aqua which read registries, but the standard registry is very large (about 2MB) so it makes the performance worse.
Furthermore, the standard registry gets larger every time we improve the standard registry.

To solve the problem, this pull request introduces the cache mechanism of packages by aqua.yaml.
aqua creates a cache file per aqua.yaml into $(aqua root-dir)/registry-cache/<base64 encoded aqua.yaml absolute path>.json.

The structure of cache files is:

{
  "absolute path of registry.yaml": {
    "package name": {
      "type": "github_release",
      // ...
    }
  }
}

If a registry type is local, a cache file isn't created.
Cache files are much smaller than the standard registry, so aqua can read them much faster.
If packages aren't found in cache files, aqua reads the original registries and updates cache files.
aqua removes unused records from cache.

Bench mark
$ hyperfine --warmup 3 "/Users/shunsukesuzuki/go/bin/aqua which golangci-lint" "/Users/shunsukesuzuki/.local/share/aquaproj-aqua/internal/pkgs/github_release/github.com/aquaproj/aqua/v2.50.1-1/aqua_darwin_arm64.tar.gz/aqua which golangci-lint" "/Users/shunsukesuzuki/.local/share/aquaproj-aqua/internal/pkgs/github_release/github.com/aquaproj/aqua/v2.50.0/aqua_darwin_arm64.tar.gz/aqua which golangci-lint"
Benchmark 1: /Users/shunsukesuzuki/go/bin/aqua which golangci-lint
  Time (mean ± σ):      25.0 ms ±   3.5 ms    [User: 21.4 ms, System: 3.7 ms]
  Range (min … max):    21.6 ms …  45.4 ms    77 runs
 
  Warning: Statistical outliers were detected. Consider re-running this benchmark on a quiet system without any interferences from other programs. It might help to use the '--warmup' or '--prepare' options.
 
Benchmark 2: /Users/shunsukesuzuki/.local/share/aquaproj-aqua/internal/pkgs/github_release/github.com/aquaproj/aqua/v2.50.1-1/aqua_darwin_arm64.tar.gz/aqua which golangci-lint
  Time (mean ± σ):      41.7 ms ±   4.5 ms    [User: 41.1 ms, System: 5.3 ms]
  Range (min … max):    37.2 ms …  62.3 ms    55 runs
 
  Warning: Statistical outliers were detected. Consider re-running this benchmark on a quiet system without any interferences from other programs. It might help to use the '--warmup' or '--prepare' options.
 
Benchmark 3: /Users/shunsukesuzuki/.local/share/aquaproj-aqua/internal/pkgs/github_release/github.com/aquaproj/aqua/v2.50.0/aqua_darwin_arm64.tar.gz/aqua which golangci-lint
  Time (mean ± σ):      42.8 ms ±   4.0 ms    [User: 41.9 ms, System: 5.6 ms]
  Range (min … max):    39.4 ms …  55.4 ms    43 runs
 
  Warning: The first benchmarking run for this command was significantly slower than the rest (54.4 ms). This could be caused by (filesystem) caches that were not filled until after the first run. You are already using the '--warmup' option which helps to fill these caches before the actual benchmark. You can either try to increase the warmup count further or re-run this benchmark on a quiet system in case it was a random outlier. Alternatively, consider using the '--prepare' option to clear the caches before each timing run.
 
Summary
  /Users/shunsukesuzuki/go/bin/aqua which golangci-lint ran
    1.67 ± 0.29 times faster than /Users/shunsukesuzuki/.local/share/aquaproj-aqua/internal/pkgs/github_release/github.com/aquaproj/aqua/v2.50.1-1/aqua_darwin_arm64.tar.gz/aqua which golangci-lint
    1.71 ± 0.29 times faster than /Users/shunsukesuzuki/.local/share/aquaproj-aqua/internal/pkgs/github_release/github.com/aquaproj/aqua/v2.50.0/aqua_darwin_arm64.tar.gz/aqua which golangci-lint
Others

#​3840 chore: update aqua-proxy to v1.2.9
#​3839 chore: update urfave-cli-v3-util to v0.0.4

v2.50.0

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.49.0...v2.50.0

Features

#​3794 GitHub Artifact Attestations: Non-default predicate type support @​scop

v2.49.0

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.48.3...v2.49.0

Features

#​3780 Support creating hardlinks

v2.48.3

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.48.2...v2.48.3

🐛 Bug Fixes

#​3774 Fix aqua version command

v2.48.2

Compare Source

Pull Requests | Issues | aquaproj/aqua@v2.48.1...v2.48.2

🐛 Bug Fixes

#​3771 Fix fish completion
#​3750 generate-registry: Fix panic if version isn't semver

Improvement

#​3772 Improve -v option and version command
#​3740 checksum: don't treat *.bundle as checksum @​scop

aws-actions/configure-aws-credentials (aws-actions/configure-aws-credentials)

v6.3.0

Compare Source

v6.2.4

Compare Source

masterpointio/actions (masterpointio/actions)

v0.4.0

Compare Source

Features
  • discover and test every module in tf-test workflow (#​4) (5ca743a)
Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "after 9am on the first day of the month"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the auto-upgrade label Oct 1, 2026
@renovate
renovate Bot requested a review from a team as a code owner October 1, 2026 18:05
@renovate
renovate Bot requested a review from gberenice October 1, 2026 18:05
@renovate renovate Bot added the auto-upgrade label Oct 1, 2026
@renovate
renovate Bot enabled auto-merge (squash) October 1, 2026 18:06
@renovate
renovate Bot merged commit ac7cc42 into main Oct 1, 2026
4 checks passed
@renovate
renovate Bot deleted the renovate/github-actions branch October 1, 2026 20:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants