← Home

renovate

Automated dependency updates. Flexible so you don't need to be.

51
Versions
AGPL-3.0-only
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

jamietannaviceice

Keywords

automatedazurebazelbitbucketbuildkitedependenciesdependencydockergiteagithubgitlabmanagementmeteornodenpmoutdatedphppnpmpythonupdateyarn

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
license copyleft-license:AGPL-3.0-only AI (license): Renovate's declared license; stable across all versions. ai
publish-pattern new-deps-added AI (publish-pattern): lru-cache is a well-known, widely-trusted package; addition is benign for this established project. ai
source-diff large-new-source-files AI (source-diff): Renovate is a large, actively developed project; incremental file additions are routine across its 8960+ versions. ai
publish-pattern dormant-publish AI (publish-pattern): Renovate publishes extremely frequently via CI; dormancy signal is a false positive for this package. ai
dependencies unvetted-dep:conventional-commits-detector AI (dependencies): Standard utility dep for renovate; no risk signal. ai
dependencies unvetted-dep:changelog-filename-regex AI (dependencies): Legitimate, stable dependency of renovate; no security concerns. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a well-known TypeScript runtime helper; declared in package.json as a runtime dep, stable false positive. ai
dependencies unvetted-dep:@renovatebot/good-enough-parser AI (dependencies): First-party @renovatebot scoped package; expected dependency. ai
dependencies unvetted-dep:@renovatebot/detect-tools AI (dependencies): First-party @renovatebot scoped package; expected dependency. ai
dependencies unvetted-dep:emojibase-regex AI (dependencies): Emoji regex library; legitimate renovate dependency. ai
dependencies unvetted-dep:@renovatebot/pgp AI (dependencies): First-party renovatebot package for PGP operations. ai
dependencies unvetted-dep:parse-link-header AI (dependencies): HTTP Link header parser; legitimate renovate dependency. ai
dependencies unvetted-dep:ae-cvss-calculator AI (dependencies): CVSS scoring library used for vulnerability assessment. ai
dependencies unvetted-dep:@aws-sdk/client-rds AI (dependencies): Official AWS SDK package; legitimate renovate dependency. ai
dependencies unvetted-dep:moo AI (dependencies): Legitimate lexer library; stable renovate dependency. ai
dependencies unvetted-dep:graph-data-structure AI (dependencies): Graph library for dependency resolution. ai
dependencies unvetted-dep:@pnpm/parse-overrides AI (dependencies): Official pnpm package for overrides parsing. ai
dependencies unvetted-dep:json-dup-key-validator AI (dependencies): JSON validation utility; legitimate renovate dependency. ai
dependencies unvetted-dep:@renovatebot/osv-offline AI (dependencies): First-party renovatebot package for offline OSV vulnerability data. ai
dependencies unvetted-dep:@renovatebot/ruby-semver AI (dependencies): First-party renovatebot package for Ruby semver handling. ai
dependencies unvetted-dep:@baszalmstra/rattler AI (dependencies): Conda/rattler package for conda ecosystem support. ai
dependencies unvetted-dep:handlebars AI (dependencies): Well-known templating library; used by renovate for PR templates. ai
dependencies unvetted-dep:markdown-it AI (dependencies): Established markdown parser; legitimate renovate dependency. ai
dependencies unvetted-dep:jsonc-weaver AI (dependencies): Legitimate JSON manipulation library for renovate config handling. ai
dependencies unvetted-dep:@breejs/later AI (dependencies): Scheduling library used for renovate schedule features. ai
dependencies unvetted-dep:find-packages AI (dependencies): pnpm ecosystem package for workspace discovery. ai
dependencies unvetted-dep:semver-stable AI (dependencies): Semver utility; legitimate renovate dependency. ai
dependencies unvetted-dep:@cdktf/hcl2json AI (dependencies): HashiCorp CDK for Terraform package; used for HCL parsing. ai
dependencies unvetted-dep:@qnighy/marshal AI (dependencies): Ruby marshal parser; used for Gemfile.lock parsing. ai

Versions (showing 51 of 467)

View all versions
Version Deps Published
43.285.3 118 / 76
43.285.2 118 / 76
43.285.1 118 / 76
43.285.0 118 / 76
43.284.1 118 / 76
43.284.0 118 / 76
43.283.0 118 / 76
43.282.0 118 / 76
43.281.1 118 / 76
43.281.0 118 / 76
43.280.5 118 / 76
43.280.4 118 / 76
43.280.3 118 / 76
43.280.2 118 / 76
43.280.1 118 / 76
43.280.0 118 / 76
43.279.2 118 / 76
43.279.1 118 / 76
43.279.0 118 / 76
43.278.5 118 / 76
43.278.4 118 / 76
43.278.3 118 / 76
43.278.2 118 / 76
43.278.1 118 / 76
43.278.0 118 / 76
43.277.1 117 / 76
43.277.0 117 / 76
43.276.0 117 / 76
43.275.2 117 / 76
43.275.1 117 / 76
43.275.0 117 / 76
43.274.0 117 / 76
43.273.0 117 / 76
43.272.9 117 / 76
43.272.8 117 / 76
43.272.7 117 / 76
43.272.6 117 / 76
43.272.5 117 / 76
43.272.4 117 / 76
43.272.3 117 / 76
43.272.2 117 / 76
43.272.1 117 / 76
43.272.0 117 / 76
43.271.3 117 / 76
43.271.2 117 / 76
43.271.1 117 / 76
43.271.0 117 / 76
43.270.2 117 / 76
43.270.1 117 / 76
43.270.0 117 / 76
43.269.3 117 / 76

v43.285.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.285.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.285.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.285.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.284.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.284.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.283.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.282.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.281.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.281.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.280.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.280.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.280.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.280.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.280.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.280.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.279.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.279.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.279.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.278.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.278.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.278.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.278.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.278.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.278.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.277.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.277.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.276.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.275.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.275.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.275.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.274.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.273.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.272.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.272.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.272.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.272.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.272.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.272.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.272.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.272.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.272.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.272.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.271.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.271.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.271.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.271.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.270.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.270.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.270.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.269.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.