build(deps): bump the go-dependencies group across 1 directory with 14 updates - #2692
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
…4 updates Bumps the go-dependencies group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github.com/chainguard-dev/kaniko](https://github.com/chainguard-dev/kaniko) | `1.25.16` | `1.25.19` | | [github.com/docker/cli](https://github.com/docker/cli) | `29.4.3+incompatible` | `29.8.0+incompatible` | | [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry) | `0.21.5` | `0.22.1` | | [github.com/moby/go-archive](https://github.com/moby/go-archive) | `0.2.0` | `0.3.3` | | [github.com/onsi/gomega](https://github.com/onsi/gomega) | `1.42.1` | `1.43.0` | | [golang.org/x/crypto](https://github.com/golang/crypto) | `0.54.0` | `0.57.0` | | [golang.org/x/oauth2](https://github.com/golang/oauth2) | `0.36.0` | `0.37.0` | Updates `github.com/chainguard-dev/kaniko` from 1.25.16 to 1.25.19 - [Release notes](https://github.com/chainguard-dev/kaniko/releases) - [Changelog](https://github.com/chainguard-forks/kaniko/blob/main/CHANGELOG.md) - [Commits](chainguard-forks/kaniko@v1.25.16...v1.25.19) Updates `github.com/docker/cli` from 29.4.3+incompatible to 29.8.0+incompatible - [Commits](docker/cli@v29.4.3...v29.8.0) Updates `github.com/google/go-containerregistry` from 0.21.5 to 0.22.1 - [Release notes](https://github.com/google/go-containerregistry/releases) - [Commits](google/go-containerregistry@v0.21.5...v0.22.1) Updates `github.com/moby/go-archive` from 0.2.0 to 0.3.3 - [Release notes](https://github.com/moby/go-archive/releases) - [Changelog](https://github.com/moby/go-archive/blob/main/changes_test.go) - [Commits](moby/go-archive@v0.2.0...v0.3.3) Updates `github.com/moby/moby/api` from 1.54.2 to 1.55.0 - [Release notes](https://github.com/moby/moby/releases) - [Commits](moby/moby@api/v1.54.2...api/v1.55.0) Updates `github.com/moby/moby/client` from 0.4.1 to 0.5.1 - [Release notes](https://github.com/moby/moby/releases) - [Changelog](https://github.com/moby/moby/blob/v0.5.1/CHANGELOG.md) - [Commits](moby/moby@v0.4.1...v0.5.1) Updates `github.com/onsi/gomega` from 1.42.1 to 1.43.0 - [Release notes](https://github.com/onsi/gomega/releases) - [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md) - [Commits](onsi/gomega@v1.42.1...v1.43.0) Updates `golang.org/x/crypto` from 0.54.0 to 0.57.0 - [Commits](golang/crypto@v0.54.0...v0.57.0) Updates `golang.org/x/mod` from 0.38.0 to 0.41.0 - [Commits](golang/mod@v0.38.0...v0.41.0) Updates `golang.org/x/oauth2` from 0.36.0 to 0.37.0 - [Commits](golang/oauth2@v0.36.0...v0.37.0) Updates `golang.org/x/sync` from 0.22.0 to 0.23.0 - [Commits](golang/sync@v0.22.0...v0.23.0) Updates `golang.org/x/sys` from 0.47.0 to 0.48.0 - [Commits](golang/sys@v0.47.0...v0.48.0) Updates `golang.org/x/term` from 0.45.0 to 0.46.0 - [Commits](golang/term@v0.45.0...v0.46.0) Updates `golang.org/x/text` from 0.40.0 to 0.42.0 - [Release notes](https://github.com/golang/text/releases) - [Commits](golang/text@v0.40.0...v0.42.0) --- updated-dependencies: - dependency-name: github.com/chainguard-dev/kaniko dependency-version: 1.25.19 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: github.com/docker/cli dependency-version: 29.8.0+incompatible dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/google/go-containerregistry dependency-version: 0.22.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/moby/go-archive dependency-version: 0.3.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/moby/moby/api dependency-version: 1.55.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/moby/moby/client dependency-version: 0.5.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/onsi/gomega dependency-version: 1.43.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/crypto dependency-version: 0.57.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/mod dependency-version: 0.41.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/oauth2 dependency-version: 0.37.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/sync dependency-version: 0.23.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/sys dependency-version: 0.48.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/term dependency-version: 0.46.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/text dependency-version: 0.42.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
dependabot
Bot
deleted the
dependabot/go_modules/go-dependencies-b2ceb678f8
branch
September 21, 2026 22:13
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the go-dependencies group with 7 updates in the / directory:
1.25.161.25.1929.4.3+incompatible29.8.0+incompatible0.21.50.22.10.2.00.3.31.42.11.43.00.54.00.57.00.36.00.37.0Updates
github.com/chainguard-dev/kanikofrom 1.25.16 to 1.25.19Release notes
Sourced from github.com/chainguard-dev/kaniko's releases.
Commits
848c402fix(util): close each layer reader before opening the next (#477)0e01843test(integration): move the issue-1039 fixture off end-of-life UBI 7 (#478)570480cchore(deps): bump github.com/go-git/go-git/v5 from 5.19.1 to 5.19.2 (#467)c96cc53chore(deps): bump golang from3aff665to2005724in /deploy (#469)dfbdb7dchore(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.1 (#468)c8370a1chore(deps): bump debian from7b140f3toabd67ffin /deploy (#465)852c0e9chore(deps): bump step-security/harden-runner in the actions group (#466)2363af0chore(deps): bump zizmorcore/zizmor-action in the actions group (#462)973b3d1chore(deps): bump actions/setup-go from 6.5.0 to 7.0.0 (#463)7e42229chore(deps): bump github.com/aws/aws-sdk-go-v2 from 1.41.7 to 1.43.2 (#447)Updates
github.com/docker/clifrom 29.4.3+incompatible to 29.8.0+incompatibleCommits
88096efMerge pull request #7288 from thaJeztah/bump_josec50ce17vendor: github.com/go-jose/go-jose/v4 v4.1.5cec24c7Merge pull request #7285 from vvoland/update-dockerd5ea3bdvendor: github.com/moby/moby/client v0.6.07cf09bavendor: github.com/moby/moby/api v1.56.06239084Merge pull request #7108 from zhangyoufu/umask45a3e0be2e/container: Skip umask test until engine support79dd1f4Merge pull request #7284 from thaJeztah/trust_bump32bfe54cmd/docker-trust: update dependenciesd703697cmd/docker-trust: fix testsUpdates
github.com/google/go-containerregistryfrom 0.21.5 to 0.22.1Release notes
Sourced from github.com/google/go-containerregistry's releases.
... (truncated)
Commits
8a72a42remote: copy manifest annotations to referrers fallback tag descriptors (#2441)5765c35build(deps): bump the go-deps group across 2 directories with 3 updates (#2439)969402ffix(mutate): make Time layer updates lazy (#2429)25c682eflatten: preserve config and layer media types when flattening (#2438)79af990remote: add SSRF redirect protection to writer-side HTTP clients (#2432)4b9b3c7fix(release): honor declared Go toolchain (#2435)e033b9cfix(build): install binaries to /ko-app and add to PATH (#2424) (#2436)8bd7902name: return a helpful error when a reference contains a URL scheme (#2431)163134dvalidate: support index attestation manifests and empty configs (#2414)44f7ea3fix(build): Use dependencies.gitSource in cloudbuild_v2.yaml (#2434)Updates
github.com/moby/go-archivefrom 0.2.0 to 0.3.3Release notes
Sourced from github.com/moby/go-archive's releases.
... (truncated)
Commits
ae9e219Merge pull request #104 from thaJeztah/use_O_CLOEXEC98ff1daarchive: set close-on-exec for chmod fallback descriptors1e8dfbcMerge pull request #103 from thaJeztah/fix_chmod_fallbacke738eedarchive: keep procfs file alive during fchmodat2d863f5archive: preserve procfs access during chroot extraction89653edarchive: fix chmod fallback for device nodes on nodev mountsf37d413Merge pull request #106 from thaJeztah/fallback_no_read4ffc915archive: test chmod fallback without read permission9af1c40Merge pull request #105 from thaJeztah/test_chrooted_chmod_fallback3daca2aarchive: test chmod fallback without procfs in chrootUpdates
github.com/moby/moby/apifrom 1.54.2 to 1.55.0Release notes
Sourced from github.com/moby/moby/api's releases.
Commits
b6c53c2Merge pull request #52773 from vvoland/c8d-amd64-variants01115e8Merge pull request #52906 from vvoland/fix-TestContainerWithConflictingNoneNe...b36296fMerge pull request #52913 from thaJeztah/windows_does_statsa81aa78TestContainerWithConflictingNoneNetwork: Extend Windows timeout908a35aMerge pull request #52914 from thaJeztah/no_stderr04d33b5Merge pull request #52912 from thaJeztah/cleanup_GenerateRandomAlphaOnlyString3b2f557Merge pull request #52722 from notandruu/integration/migrate-TestInspectAPIIm...62b3aaeMerge pull request #52901 from vvoland/c8d-imageusage11d3342integration-cli: un-skip stats tests on Windowsa47b1b2Merge pull request #52891 from smerkviladze/attestations-clearer-blob-missing...Updates
github.com/moby/moby/clientfrom 0.4.1 to 0.5.1Release notes
Sourced from github.com/moby/moby/client's releases.
Changelog
Sourced from github.com/moby/moby/client's changelog.
... (truncated)
Commits
3b89d13Bump to v0.5.116225c4Merge pull request #1291 from dotcloud/ensure_mount_commitdd2f0d8Merge pull request #1238 from dotcloud/1237-improve_docker_top-feature0b57e44Merge branch 'master' into 1237-improve_docker_top-featuref2dc492Merge pull request #1342 from dsissitka/patch-4a7ace53Merge pull request #1339 from dhrp/docker-run-d-descriptionc99e8deMerge branch 'cleanup_signal_handling' of https://github.com/calavera/docker ...c06aa62Merge pull request #1306 from dotcloud/1294_fix_wrong_untag_using_id_rmi9ba9983Fixed a couple of minor syntax errors.7d68afbMerge pull request #1209 from zimbatm/upstart-improvementsUpdates
github.com/onsi/gomegafrom 1.42.1 to 1.43.0Release notes
Sourced from github.com/onsi/gomega's releases.
Changelog
Sourced from github.com/onsi/gomega's changelog.
Commits
bc1f21ev1.43.0c814c0ev1.43.0 (full)a89f25dAdd gomock adaptor extension for using Gomega matchers with gomockUpdates
golang.org/x/cryptofrom 0.54.0 to 0.57.0Commits
3f62bf1go.mod: update golang.org/x dependencies86efde5ssh: reject unexpected message types on established channelsa6cdac6ssh: drop traffic on undecided channels39dc44essh: don't skip the source-address critical option in CheckCertafebf4cx509roots/fallback/bundle: make subjectsEqual stricter on Go 1.27+89f4e9bx509roots/fallback: update bundle71488c4ssh/knownhosts: compare only public key portions for revocation82adefassh: synchronize unexpected response testc757c98all: upgrade go directive to at least 1.26.0 [generated]593c81assh: correctly ignore pre-banner linesUpdates
golang.org/x/modfrom 0.38.0 to 0.41.0Commits
d0a27b2modfile: fix Cleanup and DropTool documentationd12008call: upgrade go directive to at least 1.26.0 [generated]d3398d0go.mod: update golang.org/x dependencies57549bfsumdb: ignore unrelated hashes in Lookup96f62aesumdb/tlog: fix TileHashReader authentication bypass13be902go.mod: update golang.org/x dependenciesUpdates
golang.org/x/oauth2from 0.36.0 to 0.37.0Commits
c624b89google: change the snake case endpoint to kebab-case09a82f6all: upgrade go directive to at least 1.26.0 [generated]Updates
golang.org/x/syncfrom 0.22.0 to 0.23.0Commits
f75267dsemaphore: panic on negative capacity3ffd83call: upgrade go directive to at least 1.26.0 [generated]Updates
golang.org/x/sysfrom 0.47.0 to 0.48.0Commits
613e257cpu: add riscv64 hwprobe drift test6f7b10funix: add MLOCK_ONFAULT constant663e7c8cpu: add basic support for GOARCH=sparc64de5f12fcpu: add ppc64le POWER10 detection80e8acfunix: run go fix1e3c182unix: add IPMI interfaced429e20unix: stop generating sparc termbits from the generic headerbd3bddfunix: add missing HWTSTAMP_* constantse812f53windows: add SO_SNDTIMEO constant for socket optionsf6989c5unix: align Ifreq so its union accessors cannot faultUpdates
golang.org/x/termfrom 0.45.0 to 0.46.0Commits
6226200go.mod: update golang.org/x dependencies7c2fb74term: process bytes returned with a read error3963fceall: upgrade go directive to at least 1.26.0 [generated]Updates
golang.org/x/textfrom 0.40.0 to 0.42.0Commits
fafe4a0go.mod: update golang.org/x dependenciesf53c316unicode/norm: don't truncate runes in the recomposition map key37867f6unicode/norm: let any starter block composition in compose0dd525funicode/norm: compose non-Hangul runes after a Hangul syllablebac26e5unicode/norm: avoid improper ErrShortDst return in Form.transform4f55186unicode/norm: simplify short source detection in Form.transforma1b6c10unicode/norm: prevent decomposeSegment from moving backwardscd1cbc9unicode/bidi: panic rather than log.Panicfa459614internal/export/idna: fix conformance with optional validation disabledbe70a61internal/export/idna: drop trie field from ProfilesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions