This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.<br>[View this repository on the Mend.io Web Portal](https://developer.mend.io/github/sigstore/sigstore-java). ## Config Migration Needed <!-- config-migration-pr-info --> See Config Migration PR: #1225. ## Awaiting Schedule The following updates are awaiting their schedule. To get an update now, click on a checkbox below. - [ ] <!-- unschedule-branch=renovate/info.picocli -->Update info.picocli to v4.7.7 (`info.picocli:picocli-codegen`, `info.picocli:picocli`) - [ ] <!-- unschedule-branch=renovate/actions-setup-java-5.x -->Update actions/setup-java action to v5.3.0 - [ ] <!-- unschedule-branch=renovate/com.diffplug.spotless -->Update com.diffplug.spotless to v8.7.0 (`com.diffplug.spotless`, `com.diffplug.spotless:com.diffplug.spotless.gradle.plugin`) - [ ] <!-- unschedule-branch=renovate/com.google.errorprone -->Update com.google.errorprone to v2.50.0 - [ ] <!-- unschedule-branch=renovate/com.google.guava -->Update com.google.guava to v33.6.0-jre - [ ] <!-- unschedule-branch=renovate/com.gradle.plugin-publish -->Update com.gradle.plugin-publish to v2.1.1 - [ ] <!-- unschedule-branch=renovate/com.gradleup.nmcp -->Update com.gradleup.nmcp to v1.5.0 - [ ] <!-- unschedule-branch=renovate/com.gradleup.nmcp.aggregation -->Update com.gradleup.nmcp.aggregation to v1.5.0 - [ ] <!-- unschedule-branch=renovate/com.gradleup.shadow -->Update com.gradleup.shadow to v9.4.2 - [ ] <!-- unschedule-branch=renovate/com.squareup.okhttp3 -->Update com.squareup.okhttp3 to v5.4.0 - [ ] <!-- unschedule-branch=renovate/commons-codec -->Update commons-codec to v1.22.0 - [ ] <!-- unschedule-branch=renovate/gradle-9.x -->Update Gradle to v9.6.0 - [ ] <!-- unschedule-branch=renovate/org.mockito -->Update org.mockito to v5.23.0 - [ ] <!-- unschedule-branch=renovate/protobuf_grpc -->Update protobuf_grpc (`io.grpc:protoc-gen-grpc-java`, `com.google.protobuf:protoc`, `io.grpc:grpc-bom`, `com.google.protobuf:protobuf-bom`, `com.google.protobuf`) - [ ] <!-- unschedule-branch=renovate/actions-checkout-7.x -->Update actions/checkout action to v7 - [ ] <!-- unschedule-branch=renovate/major-github-artifact-actions -->Update GitHub Artifact Actions to v7 - [ ] <!-- unschedule-branch=renovate/gradle-actions-6.x -->Update gradle/actions action to v6 - [ ] <!-- unschedule-branch=renovate/major-net.ltgt.errorprone -->Update net.ltgt.errorprone to v5 - [ ] <!-- unschedule-branch=renovate/major-no.nav.security -->Update no.nav.security to v4 - [ ] <!-- unschedule-branch=renovate/major-org.jsonschema2dataclass -->Update org.jsonschema2dataclass to v6 - [ ] <!-- unschedule-branch=renovate/major-org.junit -->Update org.junit to v6 - [ ] <!-- create-all-awaiting-schedule-prs -->🔐 **Create all awaiting schedule PRs at once** 🔐 ## Detected Dependencies <details><summary>github-actions (10)</summary> <blockquote> <details><summary>.github/workflows/byob-slsa.yaml (1)</summary> - `AdamKorcz/java-slsa-generator main` </details> <details><summary>.github/workflows/ci.yaml (5)</summary> - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `actions/setup-go v6.4.0@4a3601121dd01d1626a1e23e37211e3254c1c06c` - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] - `go 1.26.x` </details> <details><summary>.github/workflows/cifuzz.yaml (3)</summary> - `google/oss-fuzz master` - `google/oss-fuzz master` - `actions/upload-artifact v6.0.0@b7c566a772e6b6bfb58ed0dc250532a479d7789f` → [Updates: `v7.0.1`] </details> <details><summary>.github/workflows/conformance.yml (6)</summary> - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `sigstore/sigstore-conformance v0.0.29@21533cde107c734ebc153c3e3a24d75fc9811a36` - `sigstore/sigstore-conformance v0.0.29@21533cde107c734ebc153c3e3a24d75fc9811a36` </details> <details><summary>.github/workflows/depsreview.yml</summary> </details> <details><summary>.github/workflows/examples.yaml (6)</summary> - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] </details> <details><summary>.github/workflows/gradle-wrapper-validation.yaml (2)</summary> - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] </details> <details><summary>.github/workflows/release-sigstore-gradle-plugin-from-tag.yaml (4)</summary> - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] </details> <details><summary>.github/workflows/release-sigstore-java-from-tag.yaml (6)</summary> - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] - `google-github-actions/auth v3.0.0@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093` - `google-github-actions/get-secretmanager-secrets v3.0.0@bc9c54b29fdffb8a47776820a7d26e77b379d262` </details> <details><summary>.github/workflows/tuf-conformance.yml (5)</summary> - `actions/checkout v6.0.3@df4cb1c069e1874edd31b4311f1884172cec0e10` → [Updates: `v7.0.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `gradle/actions v5.0.2@0723195856401067f7a2779048b490ace7a47d7c` → [Updates: `v6.2.0`] - `actions/setup-java v5.2.0@be666c2fcd27ec809703dec50e508c2fdc7f6654` → [Updates: `v5.3.0`] - `theupdateframework/tuf-conformance v2.4.0@500c525c9ce287a472fd334fe8d885cace667d32` </details> </blockquote> </details> <details><summary>gradle (50)</summary> <blockquote> <details><summary>build-logic-commons/gradle-plugin/build.gradle.kts</summary> </details> <details><summary>build-logic-commons/gradle-plugin/src/main/kotlin/build-logic.kotlin-dsl-gradle-plugin.gradle.kts</summary> </details> <details><summary>build-logic-commons/gradle.properties</summary> </details> <details><summary>build-logic-commons/settings.gradle.kts</summary> </details> <details><summary>build-logic/basics/build.gradle.kts</summary> </details> <details><summary>build-logic/basics/src/main/kotlin/build-logic.repositories.gradle.kts</summary> </details> <details><summary>build-logic/basics/src/main/kotlin/build-logic.reproducible-builds.gradle.kts</summary> </details> <details><summary>build-logic/build-parameters/build.gradle.kts (1)</summary> - `org.gradlex.build-parameters 1.4.5` </details> <details><summary>build-logic/build.gradle.kts</summary> </details> <details><summary>build-logic/gradle.properties</summary> </details> <details><summary>build-logic/jvm/build.gradle.kts (6)</summary> - `com.diffplug.spotless:com.diffplug.spotless.gradle.plugin 8.6.0` → [Updates: `8.7.0`] - `com.github.vlsi.gradle-extensions:com.github.vlsi.gradle-extensions.gradle.plugin 3.0.2` - `de.thetaphi.forbiddenapis:de.thetaphi.forbiddenapis.gradle.plugin 3.10` - `org.jetbrains.dokka-javadoc:org.jetbrains.dokka-javadoc.gradle.plugin 2.2.0` - `com.github.autostyle:com.github.autostyle.gradle.plugin 4.0.1` - `net.ltgt.errorprone:net.ltgt.errorprone.gradle.plugin 4.4.0` → [Updates: `5.1.0`] </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.build-info.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.dokka-javadoc.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.errorprone.gradle.kts (2)</summary> - `com.google.errorprone:error_prone_core 2.46.0` → [Updates: `2.50.0`] - `com.google.guava:guava-beta-checker 1.0` </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.forbidden-apis.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.java-library.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.java.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.kotlin.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.spotless-base.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.test-junit5.gradle.kts</summary> </details> <details><summary>build-logic/jvm/src/main/kotlin/build-logic.testing.gradle.kts</summary> </details> <details><summary>build-logic/publishing/build.gradle.kts (3)</summary> - `dev.sigstore:sigstore-gradle-sign-plugin 2.2.0` - `com.gradle.plugin-publish:com.gradle.plugin-publish.gradle.plugin 2.0.0` → [Updates: `2.1.1`] - `com.gradleup.nmcp:com.gradleup.nmcp.gradle.plugin 1.4.0` → [Updates: `1.5.0`] </details> <details><summary>build-logic/publishing/src/main/kotlin/build-logic.depends-on-local-sigstore-java-repo.gradle.kts</summary> </details> <details><summary>build-logic/publishing/src/main/kotlin/build-logic.depends-on-local-sigstore-maven-plugin-repo.gradle.kts</summary> </details> <details><summary>build-logic/publishing/src/main/kotlin/build-logic.java-published-library.gradle.kts</summary> </details> <details><summary>build-logic/publishing/src/main/kotlin/build-logic.kotlin-dsl-published-gradle-plugin.gradle.kts</summary> </details> <details><summary>build-logic/publishing/src/main/kotlin/build-logic.publish-to-central.gradle.kts</summary> </details> <details><summary>build-logic/publishing/src/main/kotlin/build-logic.publish-to-tmp-maven-repo.gradle.kts</summary> </details> <details><summary>build-logic/publishing/src/main/kotlin/build-logic.signing.gradle.kts</summary> </details> <details><summary>build-logic/root-build/build.gradle.kts</summary> </details> <details><summary>build-logic/root-build/src/main/kotlin/build-logic.root-build.gradle.kts</summary> </details> <details><summary>build-logic/settings.gradle.kts</summary> </details> <details><summary>build.gradle.kts (2)</summary> - `com.gradleup.nmcp.aggregation 1.4.0` → [Updates: `1.5.0`] - `com.diffplug.spotless 8.6.0` → [Updates: `8.7.0`] </details> <details><summary>fuzzing/build.gradle.kts (2)</summary> - `com.code-intelligence:jazzer-api 0.30.0` - `com.google.guava:guava 33.5.0-jre` → [Updates: `33.6.0-jre`] </details> <details><summary>gradle.properties (1)</summary> - `dev.sigstore:sigstore-java 2.3.0` </details> <details><summary>sandbox/gradle-precompiled-plugin/build.gradle.kts</summary> </details> <details><summary>sandbox/gradle-precompiled-plugin/src/main/kotlin/sigstore-conventions.gradle.kts</summary> </details> <details><summary>sandbox/gradle-sign-file/build.gradle.kts</summary> </details> <details><summary>sandbox/gradle-sign-java-library/build.gradle.kts</summary> </details> <details><summary>sandbox/settings.gradle.kts</summary> </details> <details><summary>settings.gradle.kts (1)</summary> - `org.gradle.toolchains.foojay-resolver-convention 1.0.0` </details> <details><summary>sigstore-cli/build.gradle.kts (7)</summary> - `com.gradleup.shadow 9.0.0-rc3` → [Updates: `9.4.2`] - `info.picocli:picocli 4.7.6` → [Updates: `4.7.7`] - `com.google.guava:guava 33.5.0-jre` → [Updates: `33.6.0-jre`] - `com.google.oauth-client:google-oauth-client-bom 1.39.0` - `org.eclipse.jetty:jetty-server 12.1.10` - `org.slf4j:slf4j-simple 2.0.18` - `info.picocli:picocli-codegen 4.7.6` → [Updates: `4.7.7`] </details> <details><summary>sigstore-gradle/sigstore-gradle-sign-base-plugin/build.gradle.kts</summary> </details> <details><summary>sigstore-gradle/sigstore-gradle-sign-base-plugin/src/main/kotlin/dev.sigstore.sign-base.gradle.kts</summary> </details> <details><summary>sigstore-gradle/sigstore-gradle-sign-plugin/build.gradle.kts</summary> </details> <details><summary>sigstore-gradle/sigstore-gradle-sign-plugin/src/main/kotlin/dev.sigstore.sign.gradle.kts</summary> </details> <details><summary>sigstore-java/build.gradle.kts (25)</summary> - `org.jsonschema2dataclass 5.0.0` → [Updates: `6.1.0`] - `com.google.protobuf 0.9.6` → [Updates: `0.10.0`] - `org.immutables:gson 2.12.2` - `org.immutables:value-annotations 2.12.2` - `org.immutables:value 2.12.2` - `com.google.http-client:google-http-client-bom 2.1.0` - `io.github.erdtman:java-json-canonicalization 1.1` - `dev.sigstore:protobuf-specs 0.5.0` - `com.google.protobuf:protobuf-bom 4.33.4` → [Updates: `4.35.1`] - `io.grpc:grpc-bom 1.78.0` → [Updates: `1.82.0`] - `org.apache.tomcat:annotations-api 6.0.53` - `commons-codec:commons-codec 1.18.0` → [Updates: `1.22.0`] - `com.google.code.gson:gson 2.14.0` - `org.bouncycastle:bcutil-jdk18on 1.84` - `org.bouncycastle:bcpkix-jdk18on 1.84` - `com.google.oauth-client:google-oauth-client-bom 1.39.0` - `org.junit:junit-bom 5.14.4` → [Updates: `6.1.0`] - `org.mockito:mockito-bom 5.21.0` → [Updates: `5.23.0`] - `no.nav.security:mock-oauth2-server 0.5.10` → [Updates: `4.0.1`] - `com.squareup.okhttp3:mockwebserver 5.3.2` → [Updates: `5.4.0`] - `net.sourceforge.htmlunit:htmlunit 2.70.0` - `io.github.netmikey.logunit:logunit-core 2.0.0` - `io.github.netmikey.logunit:logunit-jul 2.0.0` - `com.google.protobuf:protoc 4.33.4` → [Updates: `4.35.1`] - `io.grpc:protoc-gen-grpc-java 1.78.0` → [Updates: `1.82.0`] </details> <details><summary>sigstore-maven-plugin/build.gradle.kts (7)</summary> - `org.gradlex.maven-plugin-development 1.0.3` - `org.apache.maven:maven-plugin-api 3.9.16` - `org.apache.maven:maven-core 3.9.16` - `org.apache.maven.plugin-tools:maven-plugin-annotations 3.15.2` - `org.bouncycastle:bcutil-jdk18on 1.84` - `org.apache.maven.plugins:maven-gpg-plugin 3.2.8` - `org.apache.maven.shared:maven-verifier 1.8.0` </details> <details><summary>sigstore-testkit/build.gradle.kts (4)</summary> - `com.google.code.gson:gson 2.14.0` - `com.google.guava:guava 33.5.0-jre` → [Updates: `33.6.0-jre`] - `org.junit:junit-bom 5.14.4` → [Updates: `6.1.0`] - `org.assertj:assertj-core 3.27.7` </details> <details><summary>tuf-cli/build.gradle.kts (7)</summary> - `com.gradleup.shadow 9.0.0-rc3` → [Updates: `9.4.2`] - `info.picocli:picocli 4.7.6` → [Updates: `4.7.7`] - `com.google.guava:guava 33.5.0-jre` → [Updates: `33.6.0-jre`] - `com.google.oauth-client:google-oauth-client-bom 1.39.0` - `org.eclipse.jetty:jetty-server 12.1.10` - `org.slf4j:slf4j-simple 2.0.18` - `info.picocli:picocli-codegen 4.7.6` → [Updates: `4.7.7`] </details> </blockquote> </details> <details><summary>gradle-wrapper (2)</summary> <blockquote> <details><summary>gradle/wrapper/gradle-wrapper.properties (1)</summary> - `gradle 9.5.1` → [Updates: `9.6.0`] </details> <details><summary>sandbox/gradle/wrapper/gradle-wrapper.properties (1)</summary> - `gradle 9.5.1` → [Updates: `9.6.0`] </details> </blockquote> </details> --- - [ ] <!-- manual job -->Check this box to trigger a request for Renovate to run again on this repository
This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
View this repository on the Mend.io Web Portal.
Config Migration Needed
See Config Migration PR: #1225.Awaiting Schedule
The following updates are awaiting their schedule. To get an update now, click on a checkbox below.
info.picocli:picocli-codegen,info.picocli:picocli)com.diffplug.spotless,com.diffplug.spotless:com.diffplug.spotless.gradle.plugin)io.grpc:protoc-gen-grpc-java,com.google.protobuf:protoc,io.grpc:grpc-bom,com.google.protobuf:protobuf-bom,com.google.protobuf)Detected Dependencies
github-actions (10)
gradle (50)
gradle-wrapper (2)