-
Notifications
You must be signed in to change notification settings - Fork 2.9k
chore(deps): bump the common group across 1 directory with 19 updates #10050
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Bumps the common group with 18 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github.com/BurntSushi/toml](https://github.com/BurntSushi/toml) | `1.5.0` | `1.6.0` | | [github.com/GoogleCloudPlatform/docker-credential-gcr/v2](https://github.com/GoogleCloudPlatform/docker-credential-gcr) | `2.1.30` | `2.1.31` | | [github.com/bmatcuk/doublestar/v4](https://github.com/bmatcuk/doublestar) | `4.9.1` | `4.9.2` | | [github.com/containerd/containerd/v2](https://github.com/containerd/containerd) | `2.2.0` | `2.2.1` | | [github.com/gocsaf/csaf/v3](https://github.com/gocsaf/csaf) | `3.5.0` | `3.5.1` | | [github.com/hashicorp/go-getter](https://github.com/hashicorp/go-getter) | `1.8.3` | `1.8.4` | | [github.com/open-policy-agent/opa](https://github.com/open-policy-agent/opa) | `1.11.0` | `1.12.2` | | [github.com/secure-systems-lab/go-securesystemslib](https://github.com/secure-systems-lab/go-securesystemslib) | `0.9.1` | `0.10.0` | | [github.com/spdx/tools-golang](https://github.com/spdx/tools-golang) | `0.5.5` | `0.5.7` | | [github.com/tetratelabs/wazero](https://github.com/tetratelabs/wazero) | `1.10.1` | `1.11.0` | | [github.com/zclconf/go-cty-yaml](https://github.com/zclconf/go-cty-yaml) | `1.1.0` | `1.2.0` | | [golang.org/x/mod](https://github.com/golang/mod) | `0.31.0` | `0.32.0` | | [golang.org/x/term](https://github.com/golang/term) | `0.38.0` | `0.39.0` | | [golang.org/x/text](https://github.com/golang/text) | `0.32.0` | `0.33.0` | | [helm.sh/helm/v3](https://github.com/helm/helm) | `3.19.2` | `3.19.4` | | [k8s.io/api](https://github.com/kubernetes/api) | `0.34.2` | `0.35.0` | | [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) | `1.40.1` | `1.43.0` | | [github.com/nikolalohinski/gonja/v2](https://github.com/nikolalohinski/gonja) | `2.4.2` | `2.5.1` | Updates `github.com/BurntSushi/toml` from 1.5.0 to 1.6.0 - [Release notes](https://github.com/BurntSushi/toml/releases) - [Commits](BurntSushi/toml@v1.5.0...v1.6.0) Updates `github.com/GoogleCloudPlatform/docker-credential-gcr/v2` from 2.1.30 to 2.1.31 - [Release notes](https://github.com/GoogleCloudPlatform/docker-credential-gcr/releases) - [Commits](GoogleCloudPlatform/docker-credential-gcr@v2.1.30...v2.1.31) Updates `github.com/bmatcuk/doublestar/v4` from 4.9.1 to 4.9.2 - [Release notes](https://github.com/bmatcuk/doublestar/releases) - [Commits](bmatcuk/doublestar@v4.9.1...v4.9.2) Updates `github.com/containerd/containerd/v2` from 2.2.0 to 2.2.1 - [Release notes](https://github.com/containerd/containerd/releases) - [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md) - [Commits](containerd/containerd@v2.2.0...v2.2.1) Updates `github.com/gocsaf/csaf/v3` from 3.5.0 to 3.5.1 - [Release notes](https://github.com/gocsaf/csaf/releases) - [Changelog](https://github.com/gocsaf/csaf/blob/main/docs/release-process-hints.md) - [Commits](gocsaf/csaf@v3.5.0...v3.5.1) Updates `github.com/hashicorp/go-getter` from 1.8.3 to 1.8.4 - [Release notes](https://github.com/hashicorp/go-getter/releases) - [Commits](hashicorp/go-getter@v1.8.3...v1.8.4) Updates `github.com/open-policy-agent/opa` from 1.11.0 to 1.12.2 - [Release notes](https://github.com/open-policy-agent/opa/releases) - [Changelog](https://github.com/open-policy-agent/opa/blob/main/CHANGELOG.md) - [Commits](open-policy-agent/opa@v1.11.0...v1.12.2) Updates `github.com/secure-systems-lab/go-securesystemslib` from 0.9.1 to 0.10.0 - [Release notes](https://github.com/secure-systems-lab/go-securesystemslib/releases) - [Commits](secure-systems-lab/go-securesystemslib@v0.9.1...v0.10.0) Updates `github.com/spdx/tools-golang` from 0.5.5 to 0.5.7 - [Release notes](https://github.com/spdx/tools-golang/releases) - [Changelog](https://github.com/spdx/tools-golang/blob/main/RELEASE-NOTES.md) - [Commits](spdx/tools-golang@v0.5.5...v0.5.7) Updates `github.com/tetratelabs/wazero` from 1.10.1 to 1.11.0 - [Release notes](https://github.com/tetratelabs/wazero/releases) - [Commits](wazero/wazero@v1.10.1...v1.11.0) Updates `github.com/zclconf/go-cty-yaml` from 1.1.0 to 1.2.0 - [Changelog](https://github.com/zclconf/go-cty-yaml/blob/master/CHANGELOG.md) - [Commits](zclconf/go-cty-yaml@v1.1.0...v1.2.0) Updates `golang.org/x/mod` from 0.31.0 to 0.32.0 - [Commits](golang/mod@v0.31.0...v0.32.0) Updates `golang.org/x/term` from 0.38.0 to 0.39.0 - [Commits](golang/term@v0.38.0...v0.39.0) Updates `golang.org/x/text` from 0.32.0 to 0.33.0 - [Release notes](https://github.com/golang/text/releases) - [Commits](golang/text@v0.32.0...v0.33.0) Updates `helm.sh/helm/v3` from 3.19.2 to 3.19.4 - [Release notes](https://github.com/helm/helm/releases) - [Commits](helm/helm@v3.19.2...v3.19.4) Updates `k8s.io/api` from 0.34.2 to 0.35.0 - [Commits](kubernetes/api@v0.34.2...v0.35.0) Updates `k8s.io/utils` from 0.0.0-20250820121507-0af2bda4dd1d to 0.0.0-20251002143259-bc988d571ff4 - [Commits](https://github.com/kubernetes/utils/commits) Updates `modernc.org/sqlite` from 1.40.1 to 1.43.0 - [Commits](https://gitlab.com/cznic/sqlite/compare/v1.40.1...v1.43.0) Updates `github.com/nikolalohinski/gonja/v2` from 2.4.2 to 2.5.1 - [Commits](NikolaLohinski/gonja@v2.4.2...v2.5.1) --- updated-dependencies: - dependency-name: github.com/BurntSushi/toml dependency-version: 1.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: common - dependency-name: github.com/GoogleCloudPlatform/docker-credential-gcr/v2 dependency-version: 2.1.31 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common - dependency-name: github.com/bmatcuk/doublestar/v4 dependency-version: 4.9.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common - dependency-name: github.com/containerd/containerd/v2 dependency-version: 2.2.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common - dependency-name: github.com/gocsaf/csaf/v3 dependency-version: 3.5.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common - dependency-name: github.com/hashicorp/go-getter dependency-version: 1.8.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common - dependency-name: github.com/open-policy-agent/opa dependency-version: 1.12.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: common - dependency-name: github.com/secure-systems-lab/go-securesystemslib dependency-version: 0.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: common - dependency-name: github.com/spdx/tools-golang dependency-version: 0.5.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common - dependency-name: github.com/tetratelabs/wazero dependency-version: 1.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: common - dependency-name: github.com/zclconf/go-cty-yaml dependency-version: 1.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: common - dependency-name: golang.org/x/mod dependency-version: 0.32.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: common - dependency-name: golang.org/x/term dependency-version: 0.39.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: common - dependency-name: golang.org/x/text dependency-version: 0.33.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: common - dependency-name: helm.sh/helm/v3 dependency-version: 3.19.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common - dependency-name: k8s.io/api dependency-version: 0.35.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: common - dependency-name: k8s.io/utils dependency-version: 0.0.0-20251002143259-bc988d571ff4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common - dependency-name: modernc.org/sqlite dependency-version: 1.43.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: common - dependency-name: github.com/nikolalohinski/gonja/v2 dependency-version: 2.5.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: common ... Signed-off-by: dependabot[bot] <[email protected]>
|
Kubernetes removed But Removed updating |
|
@nikpivkin, could you take a look at the update for |
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the common group with 18 updates in the / directory:
1.5.01.6.02.1.302.1.314.9.14.9.22.2.02.2.13.5.03.5.11.8.31.8.41.11.01.12.20.9.10.10.00.5.50.5.71.10.11.11.01.1.01.2.00.31.00.32.00.38.00.39.00.32.00.33.03.19.23.19.41.40.11.43.02.4.22.5.1Updates
github.com/BurntSushi/tomlfrom 1.5.0 to 1.6.0Release notes
Sourced from github.com/BurntSushi/toml's releases.
Commits
5253492Enable TOML 1.1 by default (#457)e954445Reject duplicate arrays (#455)6b16cbdUpdate toml-test test cases from upstream (#456)011fa2bEnsure constant format strings in wf calls4b439bfRemove itemNila473c12Add test for out of range float64b535ff8Add some boring tests for lex.go6011ef0Remove unreachable condition in lexTableNameStartc8ca9e6Remove unreachable condition1121f81Make tomlv read from stdinUpdates
github.com/GoogleCloudPlatform/docker-credential-gcr/v2from 2.1.30 to 2.1.31Release notes
Sourced from github.com/GoogleCloudPlatform/docker-credential-gcr/v2's releases.
Commits
96df16cBump github.com/sirupsen/logrus from 1.8.1 to 1.8.3 (#184)e6984d0Update version string tests to match version format (#185)Updates
github.com/bmatcuk/doublestar/v4from 4.9.1 to 4.9.2Release notes
Sourced from github.com/bmatcuk/doublestar/v4's releases.
Commits
3dc8306Merge branch 'toga4-fix-brace-exp-with-meta'4db19e2fix tests4ef2b00fix: escape meta characters in paths during brace expansionb191bb9test: add failing tests for brace expansion with meta char directories9fded31notes about globbingUpdates
github.com/containerd/containerd/v2from 2.2.0 to 2.2.1Release notes
Sourced from github.com/containerd/containerd/v2's releases.
... (truncated)
Commits
dea7da5Merge pull request #12677 from dmcgowan/prepare-2.2.1f6bae1fPrepare release notes for v2.2.1b77253fMerge pull request #12701 from k8s-infra-cherrypick-robot/cherry-pick-12699-t...c22cf5dcri,nri: pass any linux security profile to plugins.d7532decri,nri: pass any linux RDT constraints to plugins.ef36e61cri,nri: pass any linux net devices to plugins.d56faf4cri,nri: pass any linux scheduler attributes to plugins.e1824d2cri,nri: pass any linux I/O priority to plugins.01d5490go.{mod,sum}: bump NRI deps to v0.11.0, re-vendor.815932aMerge pull request #12697 from thaJeztah/release_2.2_backport_bump_semconvUpdates
github.com/gocsaf/csaf/v3from 3.5.0 to 3.5.1Release notes
Sourced from github.com/gocsaf/csaf/v3's releases.
Commits
586524aUpdate 3rd party libraries. (#711)52ce6bcfix: engine is invalid when name is missing (#710)Updates
github.com/hashicorp/go-getterfrom 1.8.3 to 1.8.4Release notes
Sourced from github.com/hashicorp/go-getter's releases.
Commits
576ab86[chore] : Bump the go group across 1 directory with 12 updates (#575)efec2dbMerge pull request #574 from hashicorp/dependabot/github_actions/actions-36c6...7ccb947[chore] : Bump the actions group across 1 directory with 6 updates228ad65fix: allow downloading S3 files from MinIO over http (#570)5cb8b18Merge pull request #567 from hashicorp/dependabot/github_actions/actions-92ca...f358fa6Merge pull request #571 from hashicorp/compliance/update-headers376d40c[COMPLIANCE] Update Copyright and License Headers9d34fba[chore] : Bump the actions group across 1 directory with 3 updatesfd63a33Merge pull request #566 from hashicorp/compliance/update-headersac8218d[COMPLIANCE] Update Copyright and License HeadersUpdates
github.com/open-policy-agent/opafrom 1.11.0 to 1.12.2Release notes
Sourced from github.com/open-policy-agent/opa's releases.
... (truncated)
Changelog
Sourced from github.com/open-policy-agent/opa's changelog.
... (truncated)
Commits
89c6537Release v1.12.292dd54dRelease v1.12.1fb09d24Revert "topdown: makeregex.replacerespect cancellation"d61ac38Prepare v1.12.0 release (#8144)5a0dc47Template string performance improvements and more (#8143)f5c3743perf: reduce allocations handling terms (#8116)d80ffc4website: Show playground errors7e1c361oracle: Use typed targets for specific matchers (#8138)629cbd8String interpolation docs (#8129)9c52121ast/parser: avoid allocating slices for variadic optionsUpdates
github.com/secure-systems-lab/go-securesystemslibfrom 0.9.1 to 0.10.0Commits
93d7e1cMerge pull request #139 from secure-systems-lab/dependabot/github_actions/gol...b2fe7dfMerge pull request #138 from secure-systems-lab/dependabot/github_actions/act...7e9f79echore(deps): bump golangci/golangci-lint-action from 8.0.0 to 9.2.01552d12chore(deps): bump actions/setup-go from 5.5.0 to 6.1.0d1d5111Merge pull request #137 from secure-systems-lab/dependabot/go_modules/golang....04d651eMerge pull request #136 from secure-systems-lab/dependabot/github_actions/act...145f8c2chore(deps): bump golang.org/x/crypto from 0.45.0 to 0.46.0e8de185Merge pull request #127 from secure-systems-lab/dependabot/go_modules/github....a50b13echore(deps): bump actions/checkout from 6.0.0 to 6.0.1c24bdcechore(deps): bump github.com/stretchr/testify from 1.10.0 to 1.11.1Updates
github.com/spdx/tools-golangfrom 0.5.5 to 0.5.7Release notes
Sourced from github.com/spdx/tools-golang's releases.
Commits
28116d2fix: fail parsing if the required prefix isn't present for IDs (#275)3d64f16build(deps): Bump actions/checkout from 5 to 6 (#271)254d7a7fix: Fix prefixDocumentId() to use correct prefix (#272)e6786a8fix: ExternalDocumentRef in JSON serialization (#269)49501adbuild(deps): Bump github.com/anchore/go-struct-converter from 0.0.0-202211181...e95cf7fbuild(deps): Bump sigs.k8s.io/yaml from 1.5.0 to 1.6.0 (#259)eabe60cbuild(deps): Bump actions/checkout from 4 to 5 (#260)72d8e33build(deps): Bump github.com/stretchr/testify from 1.10.0 to 1.11.1 (#264)d6b5d35build(deps): Bump actions/setup-go from 5 to 6 (#265)916d962build(deps): Bump sigs.k8s.io/yaml from 1.4.0 to 1.5.0 (#258)Updates
github.com/tetratelabs/wazerofrom 1.10.1 to 1.11.0Release notes
Sourced from github.com/tetratelabs/wazero's releases.
Commits
fe2e751Use golang.org/x/sys (#2443)9286448Update Wasm 2.0 spec tests. (#2458)af80797Add go-libtiff to users.md (#2457)77db968Change version policy to two versions. (#2448)275c9a0Simplify utimens. (#2449)5e7c35eFix race condition in refCount initialization (#2447)cc1ca4cStreamline build tags: remove tinygo, cgo (#2446)Updates
github.com/zclconf/go-cty-yamlfrom 1.1.0 to 1.2.0Changelog
Sourced from github.com/zclconf/go-cty-yaml's changelog.
Commits
85d6bcav1.2.0 release229f481Allow a !!merge key to be used with a sequence of mappings5da71a8Add GitHub funding metadataUpdates
golang.org/x/modfrom 0.31.0 to 0.32.0Commits
4c04067go.mod: update golang.org/x dependenciesUpdates
golang.org/x/termfrom 0.38.0 to 0.39.0Commits
a7e5b04go.mod: update golang.org/x dependencies943f25dx/term: handle transpose9b991ddx/term: handle delete keyUpdates
golang.org/x/textfrom 0.32.0 to 0.33.0Commits
536231ago.mod: update golang.org/x dependenciesUpdates
helm.sh/helm/v3from 3.19.2 to 3.19.4Release notes
Sourced from helm.sh/helm/v3's releases.
... (truncated)
Commits
7cfb6e4Use latest patch release of Go in releases59c951fchore(deps): bump github.com/gofrs/flock from 0.12.1 to 0.13.0d45f3f1chore(deps): bump github.com/cyphar/filepath-securejoind459544chore(deps): bump golang.org/x/crypto from 0.44.0 to 0.45.0becd387chore(deps): bump golang.org/x/term from 0.36.0 to 0.37.0edb1579chore(deps): bump the k8s-io group with 7 updatesUpdates
k8s.io/utilsfrom 0.0.0-20250820121507-0af2bda4dd1d to 0.0.0-20251002143259-bc988d571ff4Commits
Updates
modernc.org/sqlitefrom 1.40.1 to 1.43.0Commits
9e521c1builder.json: test += openbsd/arm64234b299builder.json: test += openbsd/amd64cc1c971make vendor # [email protected]27cd881add conn.IsReadOnly, closes #242cbcb1c2README: add sponsorsa1e867blib/mutex.go: robustness++168ece1adjust int time haqndling, closes #24005f0a52Merge branch 'fix-241' into 'master'f8f5a75fix TOCTOU interrupt race8f3ecadretract v1.42.0, revert to v1.41.0 stateUpdates
github.com/nikolalohinski/gonja/v2from 2.4.2 to 2.5.1Commits
8cd324efix: make sure int to float comparison behave correctlyc31cb4efeat(builtins): add missing builtin tests for python paritye85c8b1adding support to supress loggingDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions