← Home

renovate

Automated dependency updates. Flexible so you don't need to be.

67
Versions
AGPL-3.0-only
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

Verified SLSA provenance attestation npm registry signatures No source commit

Maintainers

jamietannaviceice

Keywords

automatedazurebazelbitbucketbuildkitedependenciesdependencydockergiteagithubgitlabmanagementmeteornodenpmoutdatedphppnpmpythonupdateyarn

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
license copyleft-license:AGPL-3.0-only AI (license): Renovate's declared license; stable across all versions. ai
publish-pattern new-deps-added AI (publish-pattern): lru-cache is a well-known, widely-trusted package; addition is benign for this established project. ai
source-diff large-new-source-files AI (source-diff): Renovate is a large, actively developed project; incremental file additions are routine across its 8960+ versions. ai
publish-pattern dormant-publish AI (publish-pattern): Renovate publishes extremely frequently via CI; dormancy signal is a false positive for this package. ai
dependencies unvetted-dep:conventional-commits-detector AI (dependencies): Standard utility dep for renovate; no risk signal. ai
dependencies unvetted-dep:changelog-filename-regex AI (dependencies): Legitimate, stable dependency of renovate; no security concerns. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a well-known TypeScript runtime helper; declared in package.json as a runtime dep, stable false positive. ai
dependencies unvetted-dep:@renovatebot/good-enough-parser AI (dependencies): First-party @renovatebot scoped package; expected dependency. ai
dependencies unvetted-dep:@renovatebot/detect-tools AI (dependencies): First-party @renovatebot scoped package; expected dependency. ai
dependencies unvetted-dep:emojibase-regex AI (dependencies): Emoji regex library; legitimate renovate dependency. ai
dependencies unvetted-dep:@renovatebot/pgp AI (dependencies): First-party renovatebot package for PGP operations. ai
dependencies unvetted-dep:parse-link-header AI (dependencies): HTTP Link header parser; legitimate renovate dependency. ai
dependencies unvetted-dep:ae-cvss-calculator AI (dependencies): CVSS scoring library used for vulnerability assessment. ai
dependencies unvetted-dep:@aws-sdk/client-rds AI (dependencies): Official AWS SDK package; legitimate renovate dependency. ai
dependencies unvetted-dep:moo AI (dependencies): Legitimate lexer library; stable renovate dependency. ai
dependencies unvetted-dep:graph-data-structure AI (dependencies): Graph library for dependency resolution. ai
dependencies unvetted-dep:@pnpm/parse-overrides AI (dependencies): Official pnpm package for overrides parsing. ai
dependencies unvetted-dep:json-dup-key-validator AI (dependencies): JSON validation utility; legitimate renovate dependency. ai
dependencies unvetted-dep:@renovatebot/osv-offline AI (dependencies): First-party renovatebot package for offline OSV vulnerability data. ai
dependencies unvetted-dep:@renovatebot/ruby-semver AI (dependencies): First-party renovatebot package for Ruby semver handling. ai
dependencies unvetted-dep:@baszalmstra/rattler AI (dependencies): Conda/rattler package for conda ecosystem support. ai
dependencies unvetted-dep:handlebars AI (dependencies): Well-known templating library; used by renovate for PR templates. ai
dependencies unvetted-dep:markdown-it AI (dependencies): Established markdown parser; legitimate renovate dependency. ai
dependencies unvetted-dep:jsonc-weaver AI (dependencies): Legitimate JSON manipulation library for renovate config handling. ai
dependencies unvetted-dep:@breejs/later AI (dependencies): Scheduling library used for renovate schedule features. ai
dependencies unvetted-dep:find-packages AI (dependencies): pnpm ecosystem package for workspace discovery. ai
dependencies unvetted-dep:semver-stable AI (dependencies): Semver utility; legitimate renovate dependency. ai
dependencies unvetted-dep:@cdktf/hcl2json AI (dependencies): HashiCorp CDK for Terraform package; used for HCL parsing. ai
dependencies unvetted-dep:@qnighy/marshal AI (dependencies): Ruby marshal parser; used for Gemfile.lock parsing. ai

Versions (showing 67 of 471)

Version Deps Published
43.24.2 118 / 89
43.24.1 118 / 89
43.24.0 118 / 89
43.23.0 118 / 89
43.22.0 118 / 89
43.21.0 118 / 89
43.20.1 118 / 89
43.20.0 118 / 89
43.19.2 118 / 89
43.19.1 118 / 89
43.19.0 118 / 89
43.18.0 118 / 90
43.17.1 118 / 91
43.17.0 118 / 91
43.16.0 118 / 91
43.15.3 118 / 91
43.15.2 118 / 91
43.15.1 118 / 91
43.15.0 118 / 91
43.14.2 118 / 91
43.14.1 118 / 91
43.14.0 118 / 91
43.13.0 118 / 91
43.12.1 118 / 91
43.12.0 118 / 91
43.11.1 118 / 91
43.11.0 118 / 91
43.10.4 118 / 91
43.10.3 118 / 91
43.10.2 118 / 91
43.10.1 118 / 91
43.10.0 118 / 91
43.9.0 118 / 91
43.8.5 118 / 91
43.8.4 118 / 91
43.8.3 118 / 91
43.8.2 118 / 91
43.8.1 118 / 91
43.8.0 118 / 91
43.7.0 118 / 91
43.6.3 118 / 91
43.6.2 118 / 91
43.6.1 118 / 91
43.6.0 118 / 91
43.5.6 118 / 91
43.5.5 118 / 91
43.5.4 118 / 91
43.5.3 118 / 91
43.5.2 118 / 91
43.5.1 118 / 91
43.5.0 118 / 91
43.4.5 118 / 91
43.4.4 118 / 91
42.99.0 118 / 91
42.98.0 118 / 91
42.97.7 118 / 91
42.97.6 118 / 91
42.97.5 118 / 91
42.97.4 118 / 91
42.97.3 118 / 91
42.97.2 118 / 91
42.97.1 118 / 91
42.97.0 118 / 91
42.96.6 118 / 91
42.96.5 118 / 91
42.96.4 118 / 91
42.96.3 118 / 91

v43.24.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.24.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.24.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.23.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.22.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.21.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.20.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.20.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.19.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.19.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.19.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.18.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.17.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.17.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.15.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.15.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.15.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.15.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.14.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.14.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.14.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.13.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.12.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.12.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.11.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.11.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.10.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.10.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.10.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.10.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.8.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.8.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.8.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.6.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.5.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.5.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.5.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.4.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.4.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v42.99.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v42.98.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v42.97.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v42.97.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v42.97.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v42.97.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v42.97.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v42.97.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v42.97.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v42.97.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v42.96.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v42.96.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v42.96.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v42.96.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.