Skip to content

chore(deps): update dependency mongodb/kingfisher to v2.5.0 - #488

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/mongodb-kingfisher-2.x
Sep 19, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/mongodb-kingfisher-2.x

Conversation

@renovate

@renovate renovate Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
mongodb/kingfisher minor v2.2.0v2.5.0
mongodb/kingfisher repository minor v2.2.0v2.5.0

Note: The pre-commit manager in Renovate is not supported by the pre-commit maintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.


Release Notes

mongodb/kingfisher (mongodb/kingfisher)

v2.5.0

Compare Source

  • Behavior change: scan --branch <ref> now scans all reachable history by default, finding secrets deleted in later commits, including merged history. Use --git-history none to retain snapshot-only scanning; explicit diff options keep their existing scope. Full-history scans may need more time and memory, and history enumeration shares the repository’s --git-repo-timeout budget. #​503

v2.4.0

Compare Source

  • Fixed scans missing secrets in UTF-16 and UTF-32 files, including little-/big-endian files with or without a BOM.
  • Hardened the HTML report viewer with safer imported-data rendering, restricted external links, and a tighter browser security policy.

v2.3.0

Compare Source

  • Improved report filtering, grouped selection, command copying, and finding details in the local viewer and standalone HTML reports.
  • Fixed probabilistic deduplication dropping unique findings by confirming duplicates with exact keys.
  • Recorded terminal scan coverage for streamed non-Git inputs, including Docker images.
  • Pinned release Docker images to the requested release version.
  • Limited the pretty report's REPOSITORY COVERAGE section to scans that request --audit-log.
  • Fixed --no-dedup scans to reuse validation results across duplicate findings and parallel scan phases.
  • Fixed dependent-secret validation stalls and duplicate provider requests caused by concurrent waiters.
  • Added overlay-derived bare detection for contextual Betterleaks API-key rules (DeepSeek, Kimi, ZAI, and Voyage AI).
  • Fixed CredentialUri TLS-mode handling, dependency-aware deduplication, and ambiguous dependency pairing so validation does not guess an endpoint. #​500
  • Reused dependent validation when credential and dependency values match across source locations.
  • Made direct validation reject ambiguous short rule selectors instead of trying an unintended rule. #​500

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Only on Saturday (* * * * 6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Third-party library dependencies. label Sep 19, 2026
@renovate
renovate Bot enabled auto-merge (rebase) September 19, 2026 06:00
@renovate
renovate Bot merged commit 5d1e9ab into main Sep 19, 2026
7 checks passed
@renovate
renovate Bot deleted the renovate/mongodb-kingfisher-2.x branch September 19, 2026 06:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Third-party library dependencies.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants