This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.<br>[View this repository on the Mend.io Web Portal](https://developer.mend.io/github/sigstore/sigstore-java). ## Config Migration Needed <!-- config-migration-pr-info --> See Config Migration PR: #1225. ## Awaiting Schedule The following updates are awaiting their schedule. To get an update now, click on a checkbox below. - [ ] <!-- unschedule-branch=renovate/info.picocli -->Update info.picocli to v4.7.7 (`info.picocli:picocli-codegen`, `info.picocli:picocli`) - [ ] <!-- unschedule-branch=renovate/actions-setup-java-5.x -->Update actions/setup-java action to v5.3.0 - [ ] <!-- unschedule-branch=renovate/com.diffplug.spotless -->Update com.diffplug.spotless to v8.7.0 (`com.diffplug.spotless`, `com.diffplug.spotless:com.diffplug.spotless.gradle.plugin`) - [ ] <!-- unschedule-branch=renovate/com.google.errorprone -->Update com.google.errorprone - [ ] <!-- unschedule-branch=renovate/com.google.guava -->Update com.google.guava - [ ] <!-- unschedule-branch=renovate/com.gradle.plugin-publish -->Update com.gradle.plugin-publish - [ ] <!-- unschedule-branch=renovate/com.gradleup.nmcp -->Update com.gradleup.nmcp - [ ] <!-- unschedule-branch=renovate/com.gradleup.nmcp.aggregation -->Update com.gradleup.nmcp.aggregation - [ ] <!-- unschedule-branch=renovate/com.gradleup.shadow -->Update com.gradleup.shadow - [ ] <!-- unschedule-branch=renovate/com.squareup.okhttp3 -->Update com.squareup.okhttp3 - [ ] <!-- unschedule-branch=renovate/commons-codec -->Update commons-codec - [ ] <!-- unschedule-branch=renovate/gradle-9.x -->Update Gradle to v9.6.0 - [ ] <!-- unschedule-branch=renovate/org.mockito -->Update org.mockito - [ ] <!-- unschedule-branch=renovate/protobuf_grpc -->Update protobuf_grpc (`io.grpc:protoc-gen-grpc-java`, `com.google.protobuf:protoc`, `io.grpc:grpc-bom`, `com.google.protobuf:protobuf-bom`, `com.google.protobuf`) - [ ] <!-- unschedule-branch=renovate/actions-checkout-7.x -->Update actions/checkout action to v7 - [ ] <!-- unschedule-branch=renovate/major-github-artifact-actions -->Update GitHub Artifact Actions (major) - [ ] <!-- unschedule-branch=renovate/gradle-actions-6.x -->Update gradle/actions action to v6 - [ ] <!-- unschedule-branch=renovate/major-net.ltgt.errorprone -->Update net.ltgt.errorprone (major) - [ ] <!-- unschedule-branch=renovate/major-no.nav.security -->Update no.nav.security (major) - [ ] <!-- unschedule-branch=renovate/major-org.jsonschema2dataclass -->Update org.jsonschema2dataclass (major) - [ ] <!-- unschedule-branch=renovate/major-org.junit -->Update org.junit (major) - [ ] <!-- create-all-awaiting-schedule-prs -->🔐 **Create all awaiting schedule PRs at once** 🔐 ## Detected Dependencies <details><summary>github-actions (10)</summary> <blockquote> <details><summary>.github/workflows/byob-slsa.yaml (1)</summary> - `AdamKorcz/java-slsa-generator main` </details> <details><summary>.github/workflows/ci.yaml (5)</summary> - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `actions/setup-go v6.4.0@4a3601121dd01d1626a1e23e37211e3254c1c06c` - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] - `go 1.26.x` </details> <details><summary>.github/workflows/cifuzz.yaml (3)</summary> - `google/oss-fuzz master` - `google/oss-fuzz master` - `actions/upload-artifact v6.0.0@b7c566a772e6b6bfb58ed0dc250532a479d7789f` → [Updates: `v7.0.1`] </details> <details><summary>.github/workflows/conformance.yml (6)</summary> - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `sigstore/sigstore-conformance v0.0.29@21533cde107c734ebc153c3e3a24d75fc9811a36` - `sigstore/sigstore-conformance v0.0.29@21533cde107c734ebc153c3e3a24d75fc9811a36` </details> <details><summary>.github/workflows/depsreview.yml</summary> </details> <details><summary>.github/workflows/examples.yaml (6)</summary> - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] </details> <details><summary>.github/workflows/gradle-wrapper-validation.yaml (2)</summary> - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] </details> <details><summary>.github/workflows/release-sigstore-gradle-plugin-from-tag.yaml (4)</summary> - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] </details> <details><summary>.github/workflows/release-sigstore-java-from-tag.yaml (6)</summary> - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] - `google-github-actions/auth v3.0.0@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093` - `google-github-actions/get-secretmanager-secrets v3.0.0@bc9c54b29fdffb8a47776820a7d26e77b379d262` </details> <details><summary>.github/workflows/tuf-conformance.yml (5)</summary> - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `theupdateframework/tuf-conformance v2.4.0@500c525c9ce287a472fd334fe8d885cace667d32` </details> </blockquote> </details> <details><summary>gradle (50)</summary> <blockquote> <details><summary>build-logic-commons/gradle-plugin/build.gradle.kts</summary> </details> <details><summary>build-logic-commons/gradle-plugin/src/main/kotlin/build-logic.kotlin-dsl-gradle-plugin.gradle.kts</summary> </details> <details><summary>build-logic-commons/gradle.properties</summary> </details> <details><summary>build-logic-commons/settings.gradle.kts</summary> </details> <details><summary>build-logic/basics/build.gradle.kts</summary> </details> <details><summary>build-logic/basics/src/main/kotlin/build-logic.repositories.gradle.kts</summary> </details> <details><summary>build-logic/basics/src/main/kotlin/build-logic.reproducible-builds.gradle.kts</summary> </details> <details><summary>build-logic/build-parameters/build.gradle.kts (1)</summary> - `org.gradlex.build-parameters 1.4.5` </details> <details><summary>build-logic/build.gradle.kts</summary> </details> <details><summary>build-logic/gradle.properties</summary> </details> <details><summary>build-logic/jvm/build.gradle.kts (6)</summary> - `com.diffplug.spotless:com.diffplug.spotless.gradle.plugin 8.6.0` → [Updates: `8.7.0`] - `com.github.vlsi.gradle-extensions:com.github.vlsi.gradle-extensions.gradle.plugin 3.0.2` - `de.thetaphi.forbiddenapis:de.thetaphi.forbiddenapis.gradle.plugin 3.10` - `org.jetbrains.dokka-javadoc:org.jetbrains.dokka-javadoc.gradle.plugin 2.2.0` - `com.github.autostyle:com.github.autostyle.gradle.plugin 4.0.1` - `net.ltgt.errorprone:net.ltgt.errorprone.gradle.plugin 4.4.0` → [Updates: `5.1.0`] </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.build-info.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.dokka-javadoc.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.errorprone.gradle.kts (2)</summary> - `com.google.errorprone:error_prone_core 2.46.0` → [Updates: `2.50.0`] - `com.google.guava:guava-beta-checker 1.0` </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.forbidden-apis.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.java-library.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.java.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.kotlin.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.spotless-base.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.test-junit5.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.testing.gradle.kts</summary> </details> <details><summary>build-logic/publishing/build.gradle.kts (3)</summary> - `dev.sigstore:sigstore-gradle-sign-plugin 2.2.0` - `com.gradle.plugin-publish:com.gradle.plugin-publish.gradle.plugin 2.0.0` → [Updates: `2.1.1`] - `com.gradleup.nmcp:com.gradleup.nmcp.gradle.plugin 1.4.0` → [Updates: `1.6.0`] </details> <details><summary>build-logic/publishing/src/main/kotlin/build-logic.depends-on-local-sigstore-java-repo.gradle.kts</summary> </details> <details><summary>build-logic/publishing/src/main/kotlin/build-logic.depends-on-local-sigstore-maven-plugin-repo.gradle.kts</summary> </details> <details><summary>build-logic/publishing/src/main/kotlin/build-logic.java-published-library.gradle.kts</summary> </details> <details><summary>build-logic/publishing/src/main/kotlin/build-logic.kotlin-dsl-published-gradle-plugin.gradle.kts</summary> </details> <details><summary>build-logic/publishing/src/main/kotlin/build-logic.publish-to-central.gradle.kts</summary> </details> <details><summary>build-logic/publishing/src/main/kotlin/build-logic.publish-to-tmp-maven-repo.gradle.kts</summary> </details> <details><summary>build-logic/publishing/src/main/kotlin/build-logic.signing.gradle.kts</summary> </details> <details><summary>build-logic/root-build/build.gradle.kts</summary> </details> <details><summary>build-logic/root-build/src/main/kotlin/build-logic.root-build.gradle.kts</summary> </details> <details><summary>build-logic/settings.gradle.kts</summary> </details> <details><summary>build.gradle.kts (2)</summary> - `com.gradleup.nmcp.aggregation 1.4.0` → [Updates: `1.6.0`] - `com.diffplug.spotless 8.6.0` → [Updates: `8.7.0`] </details> <details><summary>fuzzing/build.gradle.kts (2)</summary> - `com.code-intelligence:jazzer-api 0.30.0` - `com.google.guava:guava 33.5.0-jre` → [Updates: `33.6.0-jre`] </details> <details><summary>gradle.properties (1)</summary> - `dev.sigstore:sigstore-java 2.3.0` </details> <details><summary>sandbox/gradle-precompiled-plugin/build.gradle.kts</summary> </details> <details><summary>sandbox/gradle-precompiled-plugin/src/main/kotlin/sigstore-conventions.gradle.kts</summary> </details> <details><summary>sandbox/gradle-sign-file/build.gradle.kts</summary> </details> <details><summary>sandbox/gradle-sign-java-library/build.gradle.kts</summary> </details> <details><summary>sandbox/settings.gradle.kts</summary> </details> <details><summary>settings.gradle.kts (1)</summary> - `org.gradle.toolchains.foojay-resolver-convention 1.0.0` </details> <details><summary>sigstore-cli/build.gradle.kts (7)</summary> - `com.gradleup.shadow 9.0.0-rc3` → [Updates: `9.4.2`] - `info.picocli:picocli 4.7.6` → [Updates: `4.7.7`] - `com.google.guava:guava 33.5.0-jre` → [Updates: `33.6.0-jre`] - `com.google.oauth-client:google-oauth-client-bom 1.39.0` - `org.eclipse.jetty:jetty-server 12.1.10` - `org.slf4j:slf4j-simple 2.0.18` - `info.picocli:picocli-codegen 4.7.6` → [Updates: `4.7.7`] </details> <details><summary>sigstore-gradle/sigstore-gradle-sign-base-plugin/build.gradle.kts</summary> </details> <details><summary>sigstore-gradle/sigstore-gradle-sign-base-plugin/src/main/kotlin/dev.sigstore.sign-base.gradle.kts</summary> </details> <details><summary>sigstore-gradle/sigstore-gradle-sign-plugin/build.gradle.kts</summary> </details> <details><summary>sigstore-gradle/sigstore-gradle-sign-plugin/src/main/kotlin/dev.sigstore.sign.gradle.kts</summary> </details> <details><summary>sigstore-java/build.gradle.kts (25)</summary> - `org.jsonschema2dataclass 5.0.0` → [Updates: `6.1.0`] - `com.google.protobuf 0.9.6` → [Updates: `0.10.0`] - `org.immutables:gson 2.12.2` - `org.immutables:value-annotations 2.12.2` - `org.immutables:value 2.12.2` - `com.google.http-client:google-http-client-bom 2.1.0` - `io.github.erdtman:java-json-canonicalization 1.1` - `dev.sigstore:protobuf-specs 0.5.0` - `com.google.protobuf:protobuf-bom 4.33.4` → [Updates: `4.35.1`] - `io.grpc:grpc-bom 1.78.0` → [Updates: `1.82.0`] - `org.apache.tomcat:annotations-api 6.0.53` - `commons-codec:commons-codec 1.18.0` → [Updates: `1.22.0`] - `com.google.code.gson:gson 2.14.0` - `org.bouncycastle:bcutil-jdk18on 1.84` - `org.bouncycastle:bcpkix-jdk18on 1.84` - `com.google.oauth-client:google-oauth-client-bom 1.39.0` - `org.junit:junit-bom 5.14.4` → [Updates: `6.1.0`] - `org.mockito:mockito-bom 5.21.0` → [Updates: `5.23.0`] - `no.nav.security:mock-oauth2-server 0.5.10` → [Updates: `4.0.1`] - `com.squareup.okhttp3:mockwebserver 5.3.2` → [Updates: `5.4.0`] - `net.sourceforge.htmlunit:htmlunit 2.70.0` - `io.github.netmikey.logunit:logunit-core 2.0.0` - `io.github.netmikey.logunit:logunit-jul 2.0.0` - `com.google.protobuf:protoc 4.33.4` → [Updates: `4.35.1`] - `io.grpc:protoc-gen-grpc-java 1.78.0` → [Updates: `1.82.0`] </details> <details><summary>sigstore-maven-plugin/build.gradle.kts (7)</summary> - `org.gradlex.maven-plugin-development 1.0.3` - `org.apache.maven:maven-plugin-api 3.9.16` - `org.apache.maven:maven-core 3.9.16` - `org.apache.maven.plugin-tools:maven-plugin-annotations 3.15.2` - `org.bouncycastle:bcutil-jdk18on 1.84` - `org.apache.maven.plugins:maven-gpg-plugin 3.2.8` - `org.apache.maven.shared:maven-verifier 1.8.0` </details> <details><summary>sigstore-testkit/build.gradle.kts (4)</summary> - `com.google.code.gson:gson 2.14.0` - `com.google.guava:guava 33.5.0-jre` → [Updates: `33.6.0-jre`] - `org.junit:junit-bom 5.14.4` → [Updates: `6.1.0`] - `org.assertj:assertj-core 3.27.7` </details> <details><summary>tuf-cli/build.gradle.kts (7)</summary> - `com.gradleup.shadow 9.0.0-rc3` → [Updates: `9.4.2`] - `info.picocli:picocli 4.7.6` → [Updates: `4.7.7`] - `com.google.guava:guava 33.5.0-jre` → [Updates: `33.6.0-jre`] - `com.google.oauth-client:google-oauth-client-bom 1.39.0` - `org.eclipse.jetty:jetty-server 12.1.10` - `org.slf4j:slf4j-simple 2.0.18` - `info.picocli:picocli-codegen 4.7.6` → [Updates: `4.7.7`] </details> </blockquote> </details> <details><summary>gradle-wrapper (2)</summary> <blockquote> <details><summary>gradle/wrapper/gradle-wrapper.properties (1)</summary> - `gradle 9.5.1` → [Updates: `9.6.0`] </details> <details><summary>sandbox/gradle/wrapper/gradle-wrapper.properties (1)</summary> - `gradle 9.5.1` → [Updates: `9.6.0`] </details> </blockquote> </details> --- - [ ] <!-- manual job -->Check this box to trigger a request for Renovate to run again on this repository
This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
View this repository on the Mend.io Web Portal.
Config Migration Needed
See Config Migration PR: #1225.Awaiting Schedule
The following updates are awaiting their schedule. To get an update now, click on a checkbox below.
info.picocli:picocli-codegen,info.picocli:picocli)com.diffplug.spotless,com.diffplug.spotless:com.diffplug.spotless.gradle.plugin)io.grpc:protoc-gen-grpc-java,com.google.protobuf:protoc,io.grpc:grpc-bom,com.google.protobuf:protobuf-bom,com.google.protobuf)Detected Dependencies
github-actions (10)
gradle (50)
gradle-wrapper (2)