chore(deps): bump the go-minor-patch group across 1 directory with 24 updates#98
Open
dependabot[bot] wants to merge 1 commit into
Open
chore(deps): bump the go-minor-patch group across 1 directory with 24 updates#98dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Contributor
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
… updates Bumps the go-minor-patch group with 16 updates in the / directory: | Package | From | To | | --- | --- | --- | | [chainguard.dev/apko](https://github.com/chainguard-dev/apko) | `1.2.7` | `1.2.12` | | [chainguard.dev/melange](https://github.com/chainguard-dev/melange) | `0.48.2` | `0.50.6` | | [cloud.google.com/go/iam](https://github.com/googleapis/google-cloud-go) | `1.7.0` | `1.11.0` | | [github.com/Masterminds/semver/v3](https://github.com/Masterminds/semver) | `3.4.0` | `3.5.0` | | [github.com/anchore/clio](https://github.com/anchore/clio) | `0.0.0-20250715152405-a0fa658e5084` | `0.1.0` | | [github.com/anchore/grype](https://github.com/anchore/grype) | `0.110.0` | `0.112.0` | | [github.com/anthropics/anthropic-sdk-go](https://github.com/anthropics/anthropic-sdk-go) | `1.30.0` | `1.42.0` | | [github.com/aws/aws-sdk-go-v2/feature/s3/manager](https://github.com/aws/aws-sdk-go-v2) | `1.22.12` | `1.22.18` | | [github.com/aws/aws-sdk-go-v2/service/ecr](https://github.com/aws/aws-sdk-go-v2) | `1.56.2` | `1.57.2` | | [github.com/go-openapi/strfmt](https://github.com/go-openapi/strfmt) | `0.26.1` | `0.26.2` | | [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) | `2.6.2` | `2.6.3` | | [github.com/testcontainers/testcontainers-go](https://github.com/testcontainers/testcontainers-go) | `0.41.0` | `0.42.0` | | [github.com/testcontainers/testcontainers-go/modules/minio](https://github.com/testcontainers/testcontainers-go) | `0.41.0` | `0.42.0` | | [github.com/testcontainers/testcontainers-go/modules/postgres](https://github.com/testcontainers/testcontainers-go) | `0.41.0` | `0.42.0` | | [go.uber.org/zap](https://github.com/uber-go/zap) | `1.27.1` | `1.28.0` | | [golang.org/x/crypto](https://github.com/golang/crypto) | `0.50.0` | `0.51.0` | Updates `chainguard.dev/apko` from 1.2.7 to 1.2.12 - [Release notes](https://github.com/chainguard-dev/apko/releases) - [Changelog](https://github.com/chainguard-dev/apko/blob/main/NEWS.md) - [Commits](chainguard-dev/apko@v1.2.7...v1.2.12) Updates `chainguard.dev/melange` from 0.48.2 to 0.50.6 - [Release notes](https://github.com/chainguard-dev/melange/releases) - [Changelog](https://github.com/chainguard-dev/melange/blob/main/NEWS.md) - [Commits](chainguard-dev/melange@v0.48.2...v0.50.6) Updates `cloud.google.com/go/iam` from 1.7.0 to 1.11.0 - [Release notes](https://github.com/googleapis/google-cloud-go/releases) - [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/documentai/CHANGES.md) - [Commits](googleapis/google-cloud-go@iam/v1.7.0...dlp/v1.11.0) Updates `github.com/Masterminds/semver/v3` from 3.4.0 to 3.5.0 - [Release notes](https://github.com/Masterminds/semver/releases) - [Changelog](https://github.com/Masterminds/semver/blob/master/CHANGELOG.md) - [Commits](Masterminds/semver@v3.4.0...v3.5.0) Updates `github.com/anchore/clio` from 0.0.0-20250715152405-a0fa658e5084 to 0.1.0 - [Release notes](https://github.com/anchore/clio/releases) - [Commits](https://github.com/anchore/clio/commits/v0.1.0) Updates `github.com/anchore/grype` from 0.110.0 to 0.112.0 - [Release notes](https://github.com/anchore/grype/releases) - [Changelog](https://github.com/anchore/grype/blob/main/RELEASE.md) - [Commits](anchore/grype@v0.110.0...v0.112.0) Updates `github.com/anchore/stereoscope` from 0.1.22 to 0.1.23 - [Release notes](https://github.com/anchore/stereoscope/releases) - [Changelog](https://github.com/anchore/stereoscope/blob/main/RELEASE.md) - [Commits](anchore/stereoscope@v0.1.22...v0.1.23) Updates `github.com/anchore/syft` from 1.42.3 to 1.44.0 - [Release notes](https://github.com/anchore/syft/releases) - [Changelog](https://github.com/anchore/syft/blob/main/RELEASE.md) - [Commits](anchore/syft@v1.42.3...v1.44.0) Updates `github.com/anthropics/anthropic-sdk-go` from 1.30.0 to 1.42.0 - [Release notes](https://github.com/anthropics/anthropic-sdk-go/releases) - [Changelog](https://github.com/anthropics/anthropic-sdk-go/blob/main/CHANGELOG.md) - [Commits](anthropics/anthropic-sdk-go@v1.30.0...v1.42.0) Updates `github.com/aws/aws-sdk-go-v2` from 1.41.5 to 1.41.6 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@v1.41.5...v1.41.6) Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.14 to 1.32.16 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@config/v1.32.14...config/v1.32.16) Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.19.14 to 1.19.15 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@credentials/v1.19.14...credentials/v1.19.15) Updates `github.com/aws/aws-sdk-go-v2/feature/s3/manager` from 1.22.12 to 1.22.18 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/mq/v1.22.12...feature/s3/manager/v1.22.18) Updates `github.com/aws/aws-sdk-go-v2/service/ecr` from 1.56.2 to 1.57.2 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/ssm/v1.56.2...service/ssm/v1.57.2) Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.98.0 to 1.101.0 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/s3/v1.98.0...service/s3/v1.101.0) Updates `github.com/go-openapi/strfmt` from 0.26.1 to 0.26.2 - [Release notes](https://github.com/go-openapi/strfmt/releases) - [Commits](go-openapi/strfmt@v0.26.1...v0.26.2) Updates `github.com/sigstore/cosign/v2` from 2.6.2 to 2.6.3 - [Release notes](https://github.com/sigstore/cosign/releases) - [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md) - [Commits](sigstore/cosign@v2.6.2...v2.6.3) Updates `github.com/testcontainers/testcontainers-go` from 0.41.0 to 0.42.0 - [Release notes](https://github.com/testcontainers/testcontainers-go/releases) - [Commits](testcontainers/testcontainers-go@v0.41.0...v0.42.0) Updates `github.com/testcontainers/testcontainers-go/modules/minio` from 0.41.0 to 0.42.0 - [Release notes](https://github.com/testcontainers/testcontainers-go/releases) - [Commits](testcontainers/testcontainers-go@v0.41.0...v0.42.0) Updates `github.com/testcontainers/testcontainers-go/modules/postgres` from 0.41.0 to 0.42.0 - [Release notes](https://github.com/testcontainers/testcontainers-go/releases) - [Commits](testcontainers/testcontainers-go@v0.41.0...v0.42.0) Updates `go.uber.org/zap` from 1.27.1 to 1.28.0 - [Release notes](https://github.com/uber-go/zap/releases) - [Changelog](https://github.com/uber-go/zap/blob/master/CHANGELOG.md) - [Commits](uber-go/zap@v1.27.1...v1.28.0) Updates `golang.org/x/crypto` from 0.50.0 to 0.51.0 - [Commits](golang/crypto@v0.50.0...v0.51.0) Updates `google.golang.org/api` from 0.276.0 to 0.277.0 - [Release notes](https://github.com/googleapis/google-api-go-client/releases) - [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md) - [Commits](googleapis/google-api-go-client@v0.276.0...v0.277.0) Updates `google.golang.org/protobuf` from 1.36.11 to 1.36.12-0.20260120151049-f2248ac996af --- updated-dependencies: - dependency-name: chainguard.dev/apko dependency-version: 1.2.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-minor-patch - dependency-name: chainguard.dev/melange dependency-version: 0.50.6 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: cloud.google.com/go/iam dependency-version: 1.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: github.com/anchore/clio dependency-version: 0.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: github.com/anchore/grype dependency-version: 0.112.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: github.com/anchore/stereoscope dependency-version: 0.1.23 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-minor-patch - dependency-name: github.com/anchore/syft dependency-version: 1.44.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: github.com/anthropics/anthropic-sdk-go dependency-version: 1.42.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: github.com/aws/aws-sdk-go-v2 dependency-version: 1.41.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-minor-patch - dependency-name: github.com/aws/aws-sdk-go-v2/config dependency-version: 1.32.16 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-minor-patch - dependency-name: github.com/aws/aws-sdk-go-v2/credentials dependency-version: 1.19.15 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-minor-patch - dependency-name: github.com/aws/aws-sdk-go-v2/feature/s3/manager dependency-version: 1.22.18 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-minor-patch - dependency-name: github.com/aws/aws-sdk-go-v2/service/ecr dependency-version: 1.57.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: github.com/aws/aws-sdk-go-v2/service/s3 dependency-version: 1.101.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: github.com/go-openapi/strfmt dependency-version: 0.26.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-minor-patch - dependency-name: github.com/Masterminds/semver/v3 dependency-version: 3.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: github.com/sigstore/cosign/v2 dependency-version: 2.6.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-minor-patch - dependency-name: github.com/testcontainers/testcontainers-go dependency-version: 0.42.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: github.com/testcontainers/testcontainers-go/modules/minio dependency-version: 0.42.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: github.com/testcontainers/testcontainers-go/modules/postgres dependency-version: 0.42.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: go.uber.org/zap dependency-version: 1.28.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: golang.org/x/crypto dependency-version: 0.51.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: google.golang.org/api dependency-version: 0.277.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: google.golang.org/protobuf dependency-version: 1.36.12-0.20260120151049-f2248ac996af dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
167fd18 to
4678d0a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the go-minor-patch group with 16 updates in the / directory:
1.2.71.2.120.48.20.50.61.7.01.11.03.4.03.5.00.0.0-20250715152405-a0fa658e50840.1.00.110.00.112.01.30.01.42.01.22.121.22.181.56.21.57.20.26.10.26.22.6.22.6.30.41.00.42.00.41.00.42.00.41.00.42.01.27.11.28.00.50.00.51.0Updates
chainguard.dev/apkofrom 1.2.7 to 1.2.12Release notes
Sourced from chainguard.dev/apko's releases.
Commits
b7931babuild(deps): bump chainguard-dev/actions from 1.6.17 to 1.6.19 (#2219)34a7530fix(ci): harden against template injection and credential exposure (#2217)bfd6776Tweak solver's same-origin heuristic (#2208)0e4728dbuild(deps): bump k8s.io/apimachinery from 0.35.4 to 0.36.0 (#2189)9157b1abuild(deps): bump google.golang.org/api from 0.276.0 to 0.277.0 (#2212)4700edfbuild(deps): bump github.com/klauspost/compress from 1.18.5 to 1.18.6 (#2211)b593d2cbuild(deps): bump github/codeql-action from 4.35.2 to 4.35.3 (#2213)d81a5d4build(deps): bump step-security/harden-runner from 2.19.0 to 2.19.1 (#2214)1564c07build(deps): bump chainguard-dev/actions from 1.6.15 to 1.6.17 (#2215)5644a41retry package fetch+expand on transient errors (#2210)Updates
chainguard.dev/melangefrom 0.48.2 to 0.50.6Release notes
Sourced from chainguard.dev/melange's releases.
... (truncated)
Commits
02f6591Add linter to complain about shipping libtool linker files. (#2520)d3ba2e5build(deps): bump github.com/chainguard-dev/yam from 0.2.57 to 0.2.58 in the ...2f47547linter: validate cfg.Package.Version against path traversal in saveLintResult...04312ddfix(ci): harden against template injection and credential exposure (#2514)e04248bbuild(deps): bump the gomod group with 3 updates (#2510)ec29706chore(workflows): add tcp.dl.google.com allowed endpoint (#2509)2582b68build(deps): bump the actions group across 1 directory with 2 updates (#2505)d892f07build(deps): bump the gomod group across 1 directory with 4 updates (#2507)9852e87Bump apko to v1.2.9 (#2506)79c8d06Update apko to 1.2.7 to pick up bug fixes (#2499)Updates
cloud.google.com/go/iamfrom 1.7.0 to 1.11.0Release notes
Sourced from cloud.google.com/go/iam's releases.
Changelog
Sourced from cloud.google.com/go/iam's changelog.
... (truncated)
Commits
6e77611chore: release main (#8936)34103cbfeat(redis): new client(s) (#8948)4d40180docs(batch): update default max parallel tasks per job (#8940)1a2f20cchore(redis/cluster): add config to generate apiv1 (#8947)43bc0f7chore(main): release storage 1.34.0 (#8620)21ec815fix(pubsub): set x-goog-request-params for streaming pull request (#8753)fe1e195feat(storage): support autoclass v2.1 (#8721)3053c79build(ai/generativelanguage): include gRPC service config in BUILD.bazel file...6e20312chore(profiler): upgrade go version used in kokoro integration test to fix bu...ffb0ddafeat(spanner): add PG.OID type cod annotation (#8749)Updates
github.com/Masterminds/semver/v3from 3.4.0 to 3.5.0Release notes
Sourced from github.com/Masterminds/semver/v3's releases.
Changelog
Sourced from github.com/Masterminds/semver/v3's changelog.
Commits
8b89c86Merge pull request #287 from mattfarina/fix-da-issues29d51d0Fixing some quality issues87f651dMerge pull request #286 from mattfarina/update-devcontainer158a685Updating gitignore for devcontainers7e83c08Merge pull request #284 from Masterminds/dependabot/github_actions/golangci/g...697e27fMerge pull request #283 from Masterminds/dependabot/github_actions/actions/ca...1591f8eMerge pull request #282 from Masterminds/dependabot/github_actions/github/cod...3f5ff17Bump golangci/golangci-lint-action from 7.0.1 to 9.2.004baa33Bump actions/cache from 4.2.3 to 5.0.545939feBump github/codeql-action from 4.35.1 to 4.35.2Updates
github.com/anchore/cliofrom 0.0.0-20250715152405-a0fa658e5084 to 0.1.0Release notes
Sourced from github.com/anchore/clio's releases.
Commits
Updates
github.com/anchore/grypefrom 0.110.0 to 0.112.0Release notes
Sourced from github.com/anchore/grype's releases.
Commits
244f2a1chore(deps): update anchore dependencies (#3391)d646a93feat: ignore known not-vulnerable records across related packages (#3326)d11ee91chore(units): use in-process CDX and Sarif validation (#3402)6d0b66cAdd DB test harness (#3284)8981927chore(deps): update anchore dependencies (#3387)1d73349restore go version to 1.25.8 (#3386)d47248bchore(deps): update anchore dependencies (#3383)8f43856chore(deps): update quality gate database (#3338)6a2eebechore(deps): update anchore dependencies (#3381)7f42c1echore(deps): update Go version (#3382)Updates
github.com/anchore/stereoscopefrom 0.1.22 to 0.1.23Release notes
Sourced from github.com/anchore/stereoscope's releases.
Commits
c6e16e2chore(internal/podman): migrate to github.com/pelletier/go-toml/v2 (#574)1430c6achore(deps): bump github.com/google/go-containerregistry (#558)d32601dchore(deps): update anchore dependencies (#562)689583echore(deps): bump actions/cache from 5.0.3 to 5.0.4 (#568)1f61e88chore(deps): bump github.com/containerd/platforms (#571)03ea466chore(deps): bump actions/cache in /.github/actions/bootstrap (#555)664d199chore(deps): bump actions/setup-go in /.github/actions/bootstrap (#563)965f4cachore(deps): bump github.com/gkampitakis/go-snaps from 0.5.20 to 0.5.21 (#559)339b8cachore(deps): bump actions/cache in /.github/workflows (#556)684f9f6chore(deps): bump slackapi/slack-github-action in /.github/workflows (#551)Updates
github.com/anchore/syftfrom 1.42.3 to 1.44.0Release notes
Sourced from github.com/anchore/syft's releases.
... (truncated)
Commits
8cb78cefix: resolve yarn lock aliases to source package (#4836)3b046b3chore: move snippet files from test-fixtures to testdata (#4830)05cc8eeAdd support for linux-riscv64 (#4757)3562dabfix(lua-rockspec): handle empty and whitespace-only rockspec files gracefully...014a4c9chore: tidy go.mod (#4823)3cb838efixed pe dotnet wrong ver , fixed #4813 (#4814)758324bfix: propagate non-EOF errors out of safeCopy (#4807)390cf6cchore(deps): update anchore dependencies (#4797)4393654Chore fix sync bump (#4809)d179724fix: improve redhat-release parsing fallback for RHEL clones (#4808)Updates
github.com/anthropics/anthropic-sdk-gofrom 1.30.0 to 1.42.0Release notes
Sourced from github.com/anthropics/anthropic-sdk-go's releases.
... (truncated)
Changelog
Sourced from github.com/anthropics/anthropic-sdk-go's changelog.