This repository was archived by the owner on May 9, 2025. It is now read-only.
chore(deps): bump the go_modules group with 8 updates #186
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the go_modules group with 8 updates:
5.29.25.29.35.11.05.13.024.0.9+incompatible25.0.6+incompatible4.5.04.5.10.7.50.7.72.2.32.2.40.19.00.31.00.20.00.33.0Updates
github.com/containers/image/v5from 5.29.2 to 5.29.3Release notes
Sourced from github.com/containers/image/v5's releases.
Commits
3e684b1[release-5.29] Bump to v5.29.3e894804Merge pull request #2418 from mtrmac/digest-unmarshal-5.296e25805Validate the tags returned by a registry086c760Call .Validate() before digest.Digest.String() if necessary0860c58Refactor the error handling further7b58b43Refactor the error handling path of saveStreamaf94ba1Call .Validate() before digest.Hex() / digest.Encoded()9c49ca1Validate digests before using them534068fMerge pull request #2270 from TomSweeneyRedHat/dev/tsweeney/ddaemon0111e79[release-5.29] Bump to v5.29.3-devUpdates
github.com/go-git/go-git/v5from 5.11.0 to 5.13.0Release notes
Sourced from github.com/go-git/go-git/v5's releases.
... (truncated)
Commits
94bd4afMerge pull request #1261 from BeChris/issue6808b7f5baMerge pull request #1262 from go-git/dependabot/go_modules/github.com/elazarl...41d80a0build: bump github.com/elazarl/goproxy4998140git: worktree_commit, sanitize author and commiter name and email before crea...9049625Merge pull request #1260 from go-git/dependabot/github_actions/github/codeql-...dae48b4build: bump github/codeql-action from 3.27.9 to 3.28.07d6fbc2Merge pull request #1220 from BeChris/accept_uppercase_hexa_in_pktline_length62a77b7plumbing: Fix invalid reference name error while cloning branches containing ...5e11196plumbing: format/pktline, accept upercase hexadecimal value as pktline length...65f5e1aMerge pull request #1256 from go-git/dependabot/go_modules/golang-org-232a611e2dUpdates
github.com/docker/dockerfrom 24.0.9+incompatible to 25.0.6+incompatibleRelease notes
Sourced from github.com/docker/docker's releases.
... (truncated)
Commits
b08a51fMerge pull request #48231 from austinvazquez/backport-vendor-otel-v0.46.1-to-...d151b0fvendor: OTEL v0.46.1 / v1.21.0c6ba9a5Merge pull request #48225 from austinvazquez/backport-workflow-artifact-reten...4673a3cMerge pull request #48227 from austinvazquez/backport-backport-branch-check-t...30f8908github/ci: Check if backport is opened against the expected branch7454d6aci: update workflow artifacts retention65cc597Merge commit from forkb722836Merge pull request #48199 from austinvazquez/update-containerd-binary-to-1.7.20e8ecb9cupdate containerd binary to v1.7.20e6cae1fupdate containerd binary to v1.7.19Updates
github.com/golang-jwt/jwt/v4from 4.5.0 to 4.5.1Release notes
Sourced from github.com/golang-jwt/jwt/v4's releases.
Commits
7b1c1c0Merge commit from forkUpdates
github.com/hashicorp/go-retryablehttpfrom 0.7.5 to 0.7.7Changelog
Sourced from github.com/hashicorp/go-retryablehttp's changelog.
Commits
1542b31v0.7.7defb9f4v0.7.7a99f07bMerge pull request #158 from dany74q/danny/redacted-url-in-logs8a28c57Merge branch 'main' into danny/redacted-url-in-logs86e852dMerge pull request #227 from hashicorp/dependabot/github_actions/actions/chec...47fe99eBump actions/checkout from 4.1.5 to 4.1.6490fc06Merge pull request #226 from testwill/ioutilf3e9417chore: remove refs to deprecated io/ioutild969eaaMerge pull request #225 from hashicorp/manicminer-patch-22ad8ed4v0.7.6Updates
github.com/sigstore/cosign/v2from 2.2.3 to 2.2.4Release notes
Sourced from github.com/sigstore/cosign/v2's releases.
Changelog
Sourced from github.com/sigstore/cosign/v2's changelog.
Commits
fb651b4Add v2.2.4 changelog (#3662)629f5f8Fixes for GHSA-88jx-383q-w4qc and GHSA-95pr-fxf5-86gv (#3661)302aee6Refactor e2e-tests.yml workflow (#3627)d0b9861chore(deps): bump golang.org/x/crypto from 0.21.0 to 0.22.0 (#3649)c95439bchore(deps): bump github.com/spiffe/go-spiffe/v2 from 2.1.7 to 2.2.0 (#3653)430c985chore(deps): bump golang.org/x/sync from 0.6.0 to 0.7.0 (#3655)48858a2chore(deps): bump github.com/xanzy/go-gitlab from 0.101.0 to 0.102.0 (#3652)eba7c59chore(deps): bump golang.org/x/term from 0.18.0 to 0.19.0 (#3651)2d13b65chore(deps): bump golang.org/x/oauth2 from 0.18.0 to 0.19.0 (#3650)d56c9e8chore(deps): bump the gomod group with 3 updates (#3648)Updates
golang.org/x/cryptofrom 0.19.0 to 0.31.0Commits
b4f1988ssh: make the public key cache a 1-entry FIFO cache7042ebcopenpgp/clearsign: just use rand.Reader in tests3e90321go.mod: update golang.org/x dependencies8c4e668x509roots/fallback: update bundle6018723go.mod: update golang.org/x dependencies71ed71bREADME: don't recommend go get750a45fsha3: add MarshalBinary, AppendBinary, and UnmarshalBinary36b1725sha3: avoid trailing permutation80ea76esha3: fix padding for long cSHAKE parametersc17aa50sha3: avoid buffer copyUpdates
golang.org/x/netfrom 0.20.0 to 0.33.0Commits
dfc720dgo.mod: update golang.org/x dependencies8e66b04html: use strings.EqualFold instead of lowering ourselvesb935f7bhtml: avoid endless loop on error token9af49efroute: remove unused sizeof* consts6705db9quic: clean up crypto streams when dropping packet protection keys4ef7588quic: handle ACK frame in packet which drops number space552d8acRevert "route: change from syscall to x/sys/unix"13a7c01Revert "route: remove unused sizeof* consts on freebsd"285e1cfgo.mod: update golang.org/x dependenciesd0a1049route: remove unused sizeof* consts on freebsdDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.