Skip to content

chore(deps): bump github.com/goreleaser/goreleaser/v2 from 2.17.0 to 2.18.2 in /tool-imports/goreleaser - #1268

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/tool-imports/goreleaser/github.com/goreleaser/goreleaser/v2-2.18.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/tool-imports/goreleaser/github.com/goreleaser/goreleaser/v2-2.18.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 23, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/goreleaser/goreleaser/v2 from 2.17.0 to 2.18.2.

Release notes

Sourced from github.com/goreleaser/goreleaser/v2's releases.

v2.18.2

Announcement

Read the official announcement: Announcing GoReleaser v2.18.

Changelog

Security updates

  • 8ec05d6e3633efafc67e41050006bc914549a555: sec(builds): redact secrets from builder subprocess output (@​caarlos0)

Bug fixes

  • f285d13455fac36c67788fb5030bd3cc0e21f550: fix(archive,sourcearchive,gio): backups, ZIP metadata, mtime and CPU variants (#7089) (@​caarlos0)
  • d4e9f25f48549a9e251d469ebd39a0e06fec8af1: fix(aur): several PKGBUILD and SRCINFO generation bugs (#7100) (@​caarlos0)
  • b428c4cb95f65ed7b4b6f8f02dbdc9435b8636bc: fix(aur): tell users how to fix a duplicate architecture (#7141) (@​caarlos0)
  • 2e991d20c0061eef2351e3516dba3dd3e16ece6b: fix(blob): KMS encryption limits and bucket lifetime on error (#7101) (@​caarlos0)
  • 7ba40dc5df23de102d7a944a3e75706bd763fc5c: fix(blob): stream unencrypted uploads instead of buffering files (#7134) (@​raviayadav and @​caarlos0)
  • 924f5eb065abb7bc41be5c3818a4e77c54cf419f: fix(brew,cask): formula escaping, token matching and binary stanzas (#7086) (@​caarlos0)
  • 7c77e11f1fb0300199101b38f135cd7e1f8da1a6: fix(build): resolve dependent hook environment entries and hook dir templates (#7078) (@​caarlos0)
  • d22c274b184de8d93087c5db7b472a5aa0b8dc45: fix(builder/go): give a single ellipsis main an exact output path (#7114) (@​caarlos0)
  • be63647e5a27c8ca3c9c85efa1c31df963d977c4: fix(builder/go): keep override env entries in a stable order (#7112) (@​caarlos0)
  • 4a635abc19befc4875f7e4cb000782742218f382: fix(builder/go): register the generated C header after compiling (#7113) (@​caarlos0)
  • 34619ef166edccca04b03e1c4b08baed9b6b7a1f: fix(builder/node,builder/bun): per-target SEA config, prebuild templates and target aliases (#7088) (@​caarlos0)
  • c87158e86743de5b9222e97a915969d194420bfb: fix(builder/rust,builder/zig): toolchain context and wrapped binary copying (#7080) (@​caarlos0)
  • 566bc69cddb5afe79d749e223adb33353103ea2b: fix(builder/uv,builder/poetry): match built artifact filenames (#7084) (@​caarlos0)
  • 13ebd4d1fe6aa97e8cc66fbc61cbe63031c832b7: fix(builders,partial): canonical artifact architectures and target matching (#7083) (@​caarlos0)
  • e1d9f7f06172ee70a0e8c1ffc0682f8739d09c1f: fix(cmd): auto-snapshot ordering, schema error reporting and --output selection (#7103) (@​caarlos0)
  • 591a0b8a68bf84fb563e67db42ced1379e737ff9: fix(cmd): correct check counting and init gitignore and failure handling (#7081) (@​caarlos0)
  • 4f4febfadaa9c4ca5dff864c1f1d1b74205d40d6: fix(docker): a bare platform means the baseline CPU variant (#7148) (@​caarlos0)
  • 000ae78f0c9d681d89c3b252c4abe0e1fbcefc9c: fix(docker): keep arm64 minor variants above the v8 baseline (#7149) (@​caarlos0)
  • d2f775e6fbd14a7a7bc51fed1795d55d90ffe632: fix(docker): quote entrypoint paths and forward arguments verbatim (#7073) (@​caarlos0)
  • f2b3611691b2ff8af819bdd70c4c8a0cabb77a3f: fix(docker): v1 wheel build IDs, push flags and empty manifests (#7077) (@​caarlos0)
  • ea7bc7a98535d404469fe91290a91149ffe0bd33: fix(docker): v2 build context, annotations and ARM64 handling (#7095) (@​caarlos0)
  • a1f860f5a8dacf0149a3bef045a0acb73e5262f7: fix(env,log): redact secrets across writes and honour force_token (#7104) (@​caarlos0)
  • 0d4fe16ae3cbde55f9fe73008bef98a7b399a74f: fix(exec,publish): cancellation, empty commands, SRPM artifacts and upload URLs (#7093) (@​caarlos0)
  • eba5886d2ccb56ba7a2fe743c9b08c753fa16f56: fix(flatpak,docker): quote install paths and respect project environment (#7085) (@​caarlos0)
  • a95c9a0d5319d501f9491863f3862f8378fa7d0f: fix(git): force column.ui=never so tag output is not columnized (#7127) (@​KR-Ravindra)
  • 2d7ecb255efe5c37a0673c4c08f4a187b3d4b1bf: fix(git): tag not in the local repository is not an error (#7124) (@​caarlos0)
  • aebed26f3f578ce53459baa25c6d92cd71544161: fix(git,changelog): metadata quoting, dirty detection, key cleanup and mailmap (#7102) (@​caarlos0)
  • dce409c023a9dac3eaaea15353355c561756ce75: fix(gitea,gitlab): pagination, subpath URLs, default branch, links and cancellation (#7097) (@​caarlos0)
  • 0348bfbcbf6cc0cc726c60ee767b3872bd3e749e: fix(github): UTF-8 safe truncation, draft reuse, asset replacement and token override (#7094) (@​caarlos0)
  • 0087e682cea2471c507826bbb5112e535a455628: fix(github): honor short Retry-After delays (#7110) (@​0jaspahwa)
  • f45f6298fc0c7258dd9d062aacdc622ca0ccd74c: fix(gomod): scope proxying to Go builds and validate the right module (#7096) (@​caarlos0)
  • cf292efd0f21c593a5bc58da6615eb1ad7e70b38: fix(healthcheck): handle blank and space-containing signer commands (#7076) (@​caarlos0)
  • edd3fd0cfd1607e0593b86367ce1c104f94d5193: fix(healthcheck): panic on dependency commands that are only shell syntax (#7106) (@​caarlos0)
  • 43c0c9420b7bbc9d736291c76b2c60365b5666db: fix(ko): repository image names, digest ordering and signing references (#7079) (@​caarlos0)
  • 6ceb354cd7e212d7ca65592003564abe7ab65bad: fix(mcp): support package transport URLs (#7090) (@​caarlos0)
  • acbfcf59ad35931f94d89ce0712c565e16cda986: fix(nfpm): per-format Lintian overrides and colliding filenames (#7099) (@​caarlos0)
  • 752bacae419bacad4980b3349ddd5a9af64b4d44: fix(nix): formatter output, string escaping and post_install (#7082) (@​caarlos0)
  • 05ee35f070528c7cba32425b3ac6346f6d156a17: fix(nix): template the description only once (#7146) (@​caarlos0)
  • a3a89033cc7f71b19919244ee21bb2bb54952c2c: fix(project): evaluate name candidates lazily (#7111) (@​0jaspahwa)

... (truncated)

Commits
  • 25a52e5 fix(sbom,sign): disambiguate every target variant in default names (#7144)
  • e99a557 fix(winget): do not allow multiple wingets with the same name (#7147)
  • e6d5fc5 docs: Add Kronk in USERS.md (#7151)
  • 498ccd1 test(gitea): cover release lookup for tags containing a slash (#7145)
  • 05ee35f fix(nix): template the description only once (#7146)
  • 000ae78 fix(docker): keep arm64 minor variants above the v8 baseline (#7149)
  • 4f4febf fix(docker): a bare platform means the baseline CPU variant (#7148)
  • b428c4c fix(aur): tell users how to fix a duplicate architecture (#7141)
  • 7ba40dc fix(blob): stream unencrypted uploads instead of buffering files (#7134)
  • d504faa chore(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 (#7139)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/goreleaser/goreleaser/v2](https://github.com/goreleaser/goreleaser) from 2.17.0 to 2.18.2.
- [Release notes](https://github.com/goreleaser/goreleaser/releases)
- [Commits](goreleaser/goreleaser@v2.17.0...v2.18.2)

---
updated-dependencies:
- dependency-name: github.com/goreleaser/goreleaser/v2
  dependency-version: 2.18.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 23, 2026
@dependabot
dependabot Bot requested a review from rhybrillou as a code owner September 23, 2026 16:06
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 23, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) September 23, 2026 16:07

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants