Bump the gomod group across 1 directory with 10 updates#784
Merged
adityasaky merged 1 commit intomainfrom Apr 8, 2026
Merged
Conversation
Bumps the gomod group with 4 updates in the / directory: [github.com/go-git/go-git/v5](https://github.com/go-git/go-git), [github.com/go-openapi/runtime](https://github.com/go-openapi/runtime), [github.com/sigstore/cosign/v3](https://github.com/sigstore/cosign) and [github.com/sigstore/protobuf-specs](https://github.com/sigstore/protobuf-specs). Updates `github.com/go-git/go-git/v5` from 5.17.1 to 5.17.2 - [Release notes](https://github.com/go-git/go-git/releases) - [Commits](go-git/go-git@v5.17.1...v5.17.2) Updates `github.com/go-openapi/runtime` from 0.29.2 to 0.29.3 - [Release notes](https://github.com/go-openapi/runtime/releases) - [Commits](go-openapi/runtime@v0.29.2...v0.29.3) Updates `github.com/go-openapi/strfmt` from 0.25.0 to 0.26.0 - [Release notes](https://github.com/go-openapi/strfmt/releases) - [Commits](go-openapi/strfmt@v0.25.0...v0.26.0) Updates `github.com/go-openapi/swag/conv` from 0.25.4 to 0.25.5 - [Release notes](https://github.com/go-openapi/swag/releases) - [Commits](go-openapi/swag@v0.25.4...v0.25.5) Updates `github.com/sigstore/cosign/v3` from 3.0.4 to 3.0.6 - [Release notes](https://github.com/sigstore/cosign/releases) - [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md) - [Commits](sigstore/cosign@v3.0.4...v3.0.6) Updates `github.com/sigstore/protobuf-specs` from 0.5.0 to 0.5.1 - [Release notes](https://github.com/sigstore/protobuf-specs/releases) - [Changelog](https://github.com/sigstore/protobuf-specs/blob/main/CHANGELOG.md) - [Commits](sigstore/protobuf-specs@v0.5.0...v0.5.1) Updates `github.com/sigstore/rekor` from 1.5.0 to 1.5.1 - [Release notes](https://github.com/sigstore/rekor/releases) - [Changelog](https://github.com/sigstore/rekor/blob/main/CHANGELOG.md) - [Commits](sigstore/rekor@v1.5.0...v1.5.1) Updates `github.com/sigstore/sigstore` from 1.10.4 to 1.10.5 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.4...v1.10.5) Updates `golang.org/x/crypto` from 0.47.0 to 0.49.0 - [Commits](golang/crypto@v0.47.0...v0.49.0) Updates `golang.org/x/oauth2` from 0.35.0 to 0.36.0 - [Commits](golang/oauth2@v0.35.0...v0.36.0) --- updated-dependencies: - dependency-name: github.com/go-git/go-git/v5 dependency-version: 5.17.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: github.com/go-openapi/runtime dependency-version: 0.29.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: github.com/go-openapi/strfmt dependency-version: 0.26.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gomod - dependency-name: github.com/go-openapi/swag/conv dependency-version: 0.25.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: github.com/sigstore/cosign/v3 dependency-version: 3.0.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: github.com/sigstore/protobuf-specs dependency-version: 0.5.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: github.com/sigstore/rekor dependency-version: 1.5.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: github.com/sigstore/sigstore dependency-version: 1.10.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: golang.org/x/crypto dependency-version: 0.49.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gomod - dependency-name: golang.org/x/oauth2 dependency-version: 0.36.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gomod ... Signed-off-by: dependabot[bot] <support@github.com>
adityasaky
approved these changes
Apr 8, 2026
|
Observed review from adityasaky+8928778 (@adityasaky) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the gomod group with 4 updates in the / directory: github.com/go-git/go-git/v5, github.com/go-openapi/runtime, github.com/sigstore/cosign/v3 and github.com/sigstore/protobuf-specs.
Updates
github.com/go-git/go-git/v5from 5.17.1 to 5.17.2Release notes
Sourced from github.com/go-git/go-git/v5's releases.
Commits
45ae193Merge pull request #1944 from go-git/fix-permsfda4f74storage: filesystem/dotgit, Skip writing pack files that already exist on disk2212dc7Merge pull request #1941 from go-git/renovate/releases/v5.x-go-github.qkg1.top-go-...ebb2d7dbuild: Update module github.com/go-git/go-git/v5 to v5.17.1 [SECURITY]Updates
github.com/go-openapi/runtimefrom 0.29.2 to 0.29.3Release notes
Sourced from github.com/go-openapi/runtime's releases.
... (truncated)
Commits
b00b2f1chore: prepare release v0.29.3b5088b8ci: fixed dropped trivy release - updated shared workflowc9809a6docs: add FAQ from resolved GitHub issues (#403)3d599d6build(deps): bump the development-dependencies group across 2 directories wit...3b063c0chore: updated dependencies (removed mongodb indirect dependency) (#399)f9c40d3build(deps): bump the other-dependencies group with 3 updatesadabde2build(deps): bump the go-openapi-dependencies group with 6 updates2e68776build(deps): bump the go-openapi-dependencies group with 2 updatesbb7e2f0build(deps): bump the go-openapi-dependencies group with 2 updatesb3119aebuild(deps): bump the go-openapi-dependencies group with 2 updatesUpdates
github.com/go-openapi/strfmtfrom 0.25.0 to 0.26.0Release notes
Sourced from github.com/go-openapi/strfmt's releases.
... (truncated)
Commits
189f0ccchore: prepare release v0.26.08d2d66ctest: updated testify/v2 (#226)397a475build(deps): bump filippo.io/edwards25519 in /internal/testintegration (#221)56a7663ci: fix coverage reporting for integration tests (#225)f309793build(deps): bump the development-dependencies group across 2 directories wit...435a1e4refactor: decouple mongodb driver from root module (#222)7304ce1Test/integration mariadb (#220)8b27f48chore: reverted go requirement back to go1.24 (#219)6a4afe0chore: doc, lint, test (#218)cd99722doc: updated contributors fileUpdates
github.com/go-openapi/swag/convfrom 0.25.4 to 0.25.5Release notes
Sourced from github.com/go-openapi/swag/conv's releases.
... (truncated)
Commits
86905ccchore: prepare release v0.25.5345f85bdoc: updated docs, links (#180)01b074bci: updated ci workflows (#179)607decdbuild(deps): bump the go-openapi-dependencies group across 15 directories wit...4924f95doc: updated contributors file281942dtest: upgraded tests to use generics (#176)b9f9e45test: upgraded to go-openapi/testify@v2.3.0 (#175)b7e96e1ci: upgraded shared workflows (fixed secret propagation, fuzz matrix) (#174)236d975ci: upgraded shared workflows (fixes mono-repo releases) (#173)fd4d373build(deps): bump the development-dependencies group across 2 directories wit...Updates
github.com/sigstore/cosign/v3from 3.0.4 to 3.0.6Release notes
Sourced from github.com/sigstore/cosign/v3's releases.
... (truncated)
Changelog
Sourced from github.com/sigstore/cosign/v3's changelog.
Commits
f1ad3eeFix DSSE predicate check (GHSA-w6c6-c85g-mmv6) (#4801)2b396bdchore(deps): bump gitlab.com/gitlab-org/api/client-go (#4757)eb5b147chore(deps): bump the gomod group across 1 directory with 18 updates (#4789)fb66c28fix(deps): CVE-2026-2303 / CVE-2026-2303 (#4764)f3d74d4Fix 'the' typo in copyright name (#4788)f4766a9chore(deps): bump the actions group across 1 directory with 5 updates (#4784)4c9ba21chore(deps): bump chainguard-dev/actions in the actions group (#4772)af30fe6chore(deps): bump github.com/awslabs/amazon-ecr-credential-helper/ecr-login92084d8chore(deps): bump cuelang.org/go from 0.15.4 to 0.16.043a9682chore(deps): bump github.com/open-policy-agent/opa from 1.13.2 to 1.14.1Updates
github.com/sigstore/protobuf-specsfrom 0.5.0 to 0.5.1Changelog
Sourced from github.com/sigstore/protobuf-specs's changelog.
Commits
3001afeBump ts to v0.5.1 for new release (#874)f68ef15build(deps): bump the actions-deps group with 2 updates (#873)9859358build(deps): bump gradle-wrapper in /java in the java-deps group (#866)51546adbuild(deps): bump ts-proto from 2.11.2 to 2.11.5 in /protoc-builder/hack in t...8bb3cb3build(deps): bump the docker-refs group (#867)9dfb871Update GRPC_GATEWAY_COMMIT in versions.mk (#864)80abc3fbuild(deps): bump the rust-deps group across 1 directory with 3 updates (#869)c24db24build(deps): bump homebrew/core/protobuf from 33.4 to 34.1 in /protoc-builder...6a50d86Update GOOGLEAPIS_COMMIT in versions.mk (#863)a2cbebdBump packages for 0.5.1, bump deps (#862)Updates
github.com/sigstore/rekorfrom 1.5.0 to 1.5.1Release notes
Sourced from github.com/sigstore/rekor's releases.
Changelog
Sourced from github.com/sigstore/rekor's changelog.
Commits
bb573aabuild(deps): Bump actions/upload-artifact from 6.0.0 to 7.0.0 (#2773)6188957build(deps): Bump google.golang.org/api from 0.264.0 to 0.269.0 (#2770)f76fb2abuild(deps): Bump github/codeql-action in the all group (#2772)ae85b80build(deps): Bump github.com/redis/go-redis/v9 from 9.17.3 to 9.18.0 (#2769)9836e32build(deps): Bump the all group with 11 updates (#2768)b81ecd3build(deps): Bump gocloud.dev from 0.40.0 to 0.44.0 (#2757)2d46808optimize memory for DSSE v0.0.1 processing (#2766)bd11cb9build(deps): Bump go.step.sm/crypto from 0.74.0 to 0.76.2 (#2760)c302fdbbuild(deps): Bump github.com/secure-systems-lab/go-securesystemslib (#2758)3444350build(deps): Bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 (#2763)Updates
github.com/sigstore/sigstorefrom 1.10.4 to 1.10.5Release notes
Sourced from github.com/sigstore/sigstore's releases.
Commits
c90de3echore: mention openbao being supported as well (#2313) (#2313)b377f8fchore: Project-wide linting (#2310)295d656build(deps): Bump the all group across 1 directory with 3 updates (#2296)c731032(kms/hashivault): add openbao support (#2303)b56c866fix: eliminate usage of text/template (#2288)1d8faffbuild(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2286)4ac5776build(deps): Bump github.com/letsencrypt/boulder (#2282)36276e8build(deps): Bump golang.org/x/crypto from 0.44.0 to 0.47.0 (#2258)59887c9build(deps): Bump the all group across 1 directory with 2 updates (#2278)1e85403build(deps): Bump dexidp/dex in /test/e2e in the all group (#2279)Updates
golang.org/x/cryptofrom 0.47.0 to 0.49.0Commits
982eaa6go.mod: update golang.org/x dependencies159944fssh,acme: clean up tautological/impossible nil conditionsa408498acme: only require prompt if server has terms of servicecab0f71all: upgrade go directive to at least 1.25.0 [generated]2f26647x509roots/fallback: update bundlee08b067go.mod: update golang.org/x dependencies7d0074cscrypt: fix panic on parameters <= 0Updates
golang.org/x/oauth2from 0.35.0 to 0.36.0Commits
4d954e6all: upgrade go directive to at least 1.25.0 [generated]Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions