Skip to content

chore(deps): update pre-commit hook mongodb/kingfisher to v1.112.0 - #4691

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/mongodb-kingfisher-1.x
Open

chore(deps): update pre-commit hook mongodb/kingfisher to v1.112.0#4691
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/mongodb-kingfisher-1.x

Conversation

@renovate

@renovate renovate Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
mongodb/kingfisher repository minor v1.110.0v1.112.0

Note: The pre-commit manager in Renovate is not supported by the pre-commit maintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.


Release Notes

mongodb/kingfisher (mongodb/kingfisher)

v1.112.0

Compare Source

  • Added offline Ethereum key/BIP-39 detection with explicit local-validation outcomes, inspired by #​468 from @​audityourcontracts.
  • Hardened validation caching and panic handling to avoid secret exposure.
  • Fixed remote Git URL scans hanging with --jobs 1. #​469

v1.111.0

Compare Source

  • Reduced Git scan metadata memory usage by interning repeated committer names and email addresses.
  • Reduced peak memory during large scans by bounding Git delta caches per worker and streaming matcher chunks; --jobs now controls the scanner worker pool.
  • Added first-class validation outcomes and --validation-filter actionable, allowing active credentials and high-confidence assumed-valid secrets such as private keys to remain visible together without labeling assumed findings active. --only-valid remains strict active filtering. Thanks @​wing-cheng. #​440
  • Expanded GCP coverage with validated generic and Express Mode API keys, GCS HMAC key pairs, and Application Default Credentials, drawing on Veles and Betterleaks.
  • Hardened GCP validation with Google-only OAuth endpoints, read-only multi-API key probes, and concise responses that avoid exposing minted access tokens or bucket metadata.
  • Fixed alert webhooks reporting a temporary stdin file instead of an explicitly requested non-path scan target in non-interactive runs. #​452
  • Fixed kingfisher scan - <path> discarding the sibling paths when staging stdin; stdin now replaces only the - placeholder.
  • Fixed direct validation for Atlassian API keys using the documented Organizations API. #​461
  • Fixed self-hosted Bitbucket scans to recognize http-labeled HTTPS clone links instead of falling back to SSH. #​462
  • Added Jira Cloud and Confluence Cloud scanning improvements, including complete pagination, full issue descriptions, and --all support. Thanks @​Safenein. #​460
  • Renamed "Access Map" to "Blast Radius" throughout the CLI, HTML and pretty reporters, the standalone and report viewers, and documentation; the --access-map flag, --blast-radius alias, and access_map JSON field names remain unchanged for backwards compatibility.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Only on Saturday (* * * * 6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Third-party library dependencies. label Aug 8, 2026
@renovate
renovate Bot enabled auto-merge (squash) August 8, 2026 09:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Third-party library dependencies.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants