Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Dec 10, 2025

This PR contains the following updates:

Package Change Age Confidence
github.com/sigstore/sigstore-go v1.1.3 -> v1.1.4 age confidence

Release Notes

sigstore/sigstore-go (github.com/sigstore/sigstore-go)

v1.1.4

Compare Source

What's Changed

  • Update rekor-tiles version path in #​531
  • Bump production Sigstore TUF root to latest in #​537
  • Bump staging Sigstore TUF root to latest in #​538
  • Bump deps for sigstore libraries in #​543

Full Changelog: sigstore/sigstore-go@v1.1.3...v1.1.4


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
Copy link
Contributor Author

renovate bot commented Dec 10, 2025

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 27 additional dependencies were updated

Details:

Package Change
github.com/go-openapi/analysis v0.23.0 -> v0.24.1
github.com/go-openapi/errors v0.22.2 -> v0.22.4
github.com/go-openapi/jsonpointer v0.21.1 -> v0.22.1
github.com/go-openapi/jsonreference v0.21.0 -> v0.21.3
github.com/go-openapi/loads v0.22.0 -> v0.23.2
github.com/go-openapi/runtime v0.28.0 -> v0.29.2
github.com/go-openapi/spec v0.21.0 -> v0.22.1
github.com/go-openapi/strfmt v0.23.0 -> v0.25.0
github.com/go-openapi/swag v0.24.1 -> v0.25.4
github.com/go-openapi/swag/cmdutils v0.24.0 -> v0.25.4
github.com/go-openapi/swag/conv v0.24.0 -> v0.25.4
github.com/go-openapi/swag/fileutils v0.24.0 -> v0.25.4
github.com/go-openapi/swag/jsonname v0.24.0 -> v0.25.4
github.com/go-openapi/swag/jsonutils v0.24.0 -> v0.25.4
github.com/go-openapi/swag/loading v0.24.0 -> v0.25.4
github.com/go-openapi/swag/mangling v0.24.0 -> v0.25.4
github.com/go-openapi/swag/netutils v0.24.0 -> v0.25.4
github.com/go-openapi/swag/stringutils v0.24.0 -> v0.25.4
github.com/go-openapi/swag/typeutils v0.24.0 -> v0.25.4
github.com/go-openapi/swag/yamlutils v0.24.0 -> v0.25.4
github.com/go-openapi/validate v0.24.0 -> v0.25.1
github.com/sigstore/rekor v1.4.2 -> v1.4.3
github.com/sigstore/sigstore v1.9.6-0.20250729224751-181c5d3339b3 -> v1.10.0
github.com/theupdateframework/go-tuf/v2 v2.2.0 -> v2.3.0
github.com/transparency-dev/formats v0.0.0-20250825093915-4fde0c3c9ab1 -> v0.0.0-20251017110053-404c0d5b696c
go.mongodb.org/mongo-driver v1.17.4 -> v1.17.6
google.golang.org/genproto/googleapis/rpc v0.0.0-20250929231259-57b25ae835d4 -> v0.0.0-20251103181224-f26f9409b101

@github-actions
Copy link

github-actions bot commented Dec 10, 2025

🔒 MCP Security Scan Results

✅ adb-mysql-mcp-server

  • Status: Passed
  • Tools scanned: 3
  • Result: No security issues detected

✅ agentql-mcp

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ arxiv-mcp-server

  • Status: Passed
  • Tools scanned: 4
  • Result: No security issues detected

✅ astra-db-mcp

  • Status: Passed
  • Tools scanned: 16
  • Result: No security issues detected

✅ aws-diagram

  • Status: Passed
  • Tools scanned: 3
  • Result: No security issues detected

✅ aws-documentation

  • Status: Passed
  • Tools scanned: 3
  • Result: No security issues detected

✅ blender-mcp

  • Status: Passed
  • Tools scanned: 21
  • Result: No security issues detected

✅ brightdata-mcp

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ browserbase-mcp-server

  • Status: Passed
  • Tools scanned: 9
  • Result: No security issues detected

❌ chroma-mcp

  • Status: Failed
  • Tools scanned: 13
  • Vulnerabilities found: 1

Security issues detected:

Allowed issues (not blocking):

  • [TF002] Destructive toxic flow detected. The same agent has access to at least one tool that produces untrusted content and one tool that can behave destructively. For more information, see https://explorer.invariantlabs.ai/docs/mcp-scan/issue-code-reference/#TF002 (Allowed: ChromaDB is a vector database that requires both read and write operations for managing embeddings and collections)
  • [W004] The MCP server is not in our registry. (Allowed: Server not in Invariant Labs registry - we verify provenance independently via our own checks.)

✅ chrome-devtools-mcp

  • Status: Passed
  • Tools scanned: 26
  • Result: No security issues detected

✅ context7

  • Status: Passed
  • Tools scanned: 2
  • Result: No security issues detected

✅ graphlit-mcp-server

  • Status: Passed
  • Tools scanned: 71
  • Result: No security issues detected

✅ heroku-mcp-server

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ ida-pro-mcp

  • Status: Passed
  • Tools scanned: 48
  • Result: No security issues detected

✅ launchdarkly-mcp-server

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ magic-mcp

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ mcp-clickhouse

  • Status: Passed
  • Tools scanned: 3
  • Result: No security issues detected

✅ mcp-jetbrains

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ mcp-neo4j-aura-manager

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ mcp-neo4j-cypher

  • Status: Passed
  • Tools scanned: 3
  • Result: No security issues detected

✅ mcp-neo4j-memory

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ mcp-server-box

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ mcp-server-circleci

  • Status: Passed
  • Tools scanned: 16
  • Result: No security issues detected

✅ mcp-server-neon

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

❌ netbird

  • Status: Failed
  • Tools scanned: 0
  • Vulnerabilities found: 1

Security issues detected:

  • [W003] Could not identify the MCP server.

✅ notion

  • Status: Passed
  • Tools scanned: 19
  • Result: No security issues detected

✅ onchain-mcp

  • Status: Passed
  • Tools scanned: 10
  • Result: No security issues detected

✅ pagerduty-mcp

  • Status: Passed
  • Tools scanned: 37
  • Result: No security issues detected

✅ phoenix-mcp

  • Status: Passed
  • Tools scanned: 19
  • Result: No security issues detected

✅ playwright-mcp

  • Status: Passed
  • Tools scanned: 22
  • Result: No security issues detected

✅ sentry-mcp-server

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ supabase-mcp-server

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ tavily-mcp

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

Summary: Scanned 34 MCP server(s), found 2 security issue(s).

⚠️ Action Required: Security issues were detected. Please review and address them before merging.

@renovate renovate bot force-pushed the renovate/github.com-sigstore-sigstore-go-1.x branch from 76e7302 to 8925f77 Compare December 15, 2025 16:58
@renovate renovate bot force-pushed the renovate/github.com-sigstore-sigstore-go-1.x branch from 8925f77 to 95676d6 Compare December 17, 2025 13:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant