chore(deps): Bump the minor-patch group across 1 directory with 22 updates#1962
Closed
dependabot[bot] wants to merge 1 commit into
Closed
chore(deps): Bump the minor-patch group across 1 directory with 22 updates#1962dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
…dates Bumps the minor-patch group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.41.2` | `1.41.5` | | [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry) | `0.21.3` | `0.21.5` | | [github.com/letsencrypt/boulder](https://github.com/letsencrypt/boulder) | `0.20251110.0` | `0.20260406.0` | | [github.com/sigstore/cosign/v3](https://github.com/sigstore/cosign) | `3.0.5` | `3.0.6` | | [github.com/hashicorp/vault/api](https://github.com/hashicorp/vault) | `1.22.0` | `1.23.0` | | [github.com/sigstore/protobuf-specs](https://github.com/sigstore/protobuf-specs) | `0.5.0` | `0.5.1` | | [github.com/sigstore/scaffolding](https://github.com/sigstore/scaffolding) | `0.7.22` | `0.7.33` | Updates `github.com/aws/aws-sdk-go-v2` from 1.41.2 to 1.41.5 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@v1.41.2...v1.41.5) Updates `github.com/google/go-containerregistry` from 0.21.3 to 0.21.5 - [Release notes](https://github.com/google/go-containerregistry/releases) - [Commits](google/go-containerregistry@v0.21.3...v0.21.5) Updates `github.com/letsencrypt/boulder` from 0.20251110.0 to 0.20260406.0 - [Release notes](https://github.com/letsencrypt/boulder/releases) - [Changelog](https://github.com/letsencrypt/boulder/blob/main/docs/release.md) - [Commits](letsencrypt/boulder@v0.20251110.0...v0.20260406.0) Updates `github.com/sigstore/cosign/v3` from 3.0.5 to 3.0.6 - [Release notes](https://github.com/sigstore/cosign/releases) - [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md) - [Commits](sigstore/cosign@v3.0.5...v3.0.6) Updates `github.com/sigstore/rekor` from 1.5.0 to 1.5.1 - [Release notes](https://github.com/sigstore/rekor/releases) - [Changelog](https://github.com/sigstore/rekor/blob/main/CHANGELOG.md) - [Commits](sigstore/rekor@v1.5.0...v1.5.1) Updates `github.com/sigstore/sigstore` from 1.10.4 to 1.10.5 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.4...v1.10.5) Updates `golang.org/x/crypto` from 0.49.0 to 0.50.0 - [Commits](golang/crypto@v0.49.0...v0.50.0) Updates `golang.org/x/net` from 0.52.0 to 0.53.0 - [Commits](golang/net@v0.52.0...v0.53.0) Updates `golang.org/x/time` from 0.14.0 to 0.15.0 - [Commits](golang/time@v0.14.0...v0.15.0) Updates `google.golang.org/grpc` from 1.79.3 to 1.80.0 - [Release notes](https://github.com/grpc/grpc-go/releases) - [Commits](grpc/grpc-go@v1.79.3...v1.80.0) Updates `k8s.io/api` from 0.35.2 to 0.35.3 - [Commits](kubernetes/api@v0.35.2...v0.35.3) Updates `k8s.io/apimachinery` from 0.35.2 to 0.35.3 - [Commits](kubernetes/apimachinery@v0.35.2...v0.35.3) Updates `k8s.io/client-go` from 0.35.2 to 0.35.3 - [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md) - [Commits](kubernetes/client-go@v0.35.2...v0.35.3) Updates `sigs.k8s.io/release-utils` from 0.12.3 to 0.12.4 - [Release notes](https://github.com/kubernetes-sigs/release-utils/releases) - [Commits](kubernetes-sigs/release-utils@v0.12.3...v0.12.4) Updates `github.com/go-jose/go-jose/v4` from 4.1.3 to 4.1.4 - [Release notes](https://github.com/go-jose/go-jose/releases) - [Commits](go-jose/go-jose@v4.1.3...v4.1.4) Updates `github.com/hashicorp/vault/api` from 1.22.0 to 1.23.0 - [Release notes](https://github.com/hashicorp/vault/releases) - [Changelog](https://github.com/hashicorp/vault/blob/main/CHANGELOG-v1.10-v1.15.md) - [Commits](hashicorp/vault@api/v1.22.0...api/v1.23.0) Updates `github.com/sigstore/protobuf-specs` from 0.5.0 to 0.5.1 - [Release notes](https://github.com/sigstore/protobuf-specs/releases) - [Changelog](https://github.com/sigstore/protobuf-specs/blob/main/CHANGELOG.md) - [Commits](sigstore/protobuf-specs@v0.5.0...v0.5.1) Updates `github.com/sigstore/scaffolding` from 0.7.22 to 0.7.33 - [Release notes](https://github.com/sigstore/scaffolding/releases) - [Changelog](https://github.com/sigstore/scaffolding/blob/main/release.md) - [Commits](sigstore/scaffolding@v0.7.22...v0.7.33) Updates `github.com/sigstore/sigstore/pkg/signature/kms/aws` from 1.10.4 to 1.10.5 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.4...v1.10.5) Updates `github.com/sigstore/sigstore/pkg/signature/kms/azure` from 1.10.4 to 1.10.5 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.4...v1.10.5) Updates `github.com/sigstore/sigstore/pkg/signature/kms/gcp` from 1.10.4 to 1.10.5 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.4...v1.10.5) Updates `github.com/sigstore/sigstore/pkg/signature/kms/hashivault` from 1.10.4 to 1.10.5 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.4...v1.10.5) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go-v2 dependency-version: 1.41.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/google/go-containerregistry dependency-version: 0.21.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/letsencrypt/boulder dependency-version: 0.20260406.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: github.com/sigstore/cosign/v3 dependency-version: 3.0.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/rekor dependency-version: 1.5.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/sigstore dependency-version: 1.10.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: golang.org/x/crypto dependency-version: 0.50.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: golang.org/x/net dependency-version: 0.53.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: golang.org/x/time dependency-version: 0.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: google.golang.org/grpc dependency-version: 1.80.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: k8s.io/api dependency-version: 0.35.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: k8s.io/apimachinery dependency-version: 0.35.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: k8s.io/client-go dependency-version: 0.35.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: sigs.k8s.io/release-utils dependency-version: 0.12.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/go-jose/go-jose/v4 dependency-version: 4.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/hashicorp/vault/api dependency-version: 1.23.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: github.com/sigstore/protobuf-specs dependency-version: 0.5.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/scaffolding dependency-version: 0.7.33 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/aws dependency-version: 1.10.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/azure dependency-version: 1.10.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/gcp dependency-version: 1.10.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/hashivault dependency-version: 1.10.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch ... Signed-off-by: dependabot[bot] <[email protected]>
Contributor
Author
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the minor-patch group with 7 updates in the / directory:
1.41.21.41.50.21.30.21.50.20251110.00.20260406.03.0.53.0.61.22.01.23.00.5.00.5.10.7.220.7.33Updates
github.com/aws/aws-sdk-go-v2from 1.41.2 to 1.41.5Commits
90650ddRelease 2026-03-26dd88818Regenerated Clientsb662c50Update endpoints model500a9cbUpdate API model6221102fix stale skew and delayed skew healing (#3359)0a39373fix order of generated event header handlers (#3361)098f389Only generate resolveAccountID when it's required (#3360)6ebab66Release 2026-03-25b2ec3beRegenerated Clientsabc126fUpdate API modelUpdates
github.com/google/go-containerregistryfrom 0.21.3 to 0.21.5Release notes
Sourced from github.com/google/go-containerregistry's releases.
Commits
5b80281build(deps): bump golang.org/x/tools from 0.43.0 to 0.44.0 in the go-deps gro...b99bca2build(deps): bump aws-actions/configure-aws-credentials (#2257)f8be1d4update to Go 1.26.2 (#2255)87ad88bBump docker/cli v29.4.0, moby/api v1.54.1, moby/client v0.4.0 (#2254)e8813ddgoreleaser: Update goreleaser config and GH action for releases (#2253)e90447dreplace gcloud in binary calls in pkg/v1/google tests (#2085)0d0368crevert path traversal and symlink escape changes (#2250)a2f47d4transport: validate Bearer realm URL to prevent SSRF (#2243)19a36cdfork distribution client v3 auth-challenge as an internal package (squashed) ...c612a9bBump codecov/codecov-action from 5.5.2 to 5.5.3 in the actions group (#2240)Updates
github.com/letsencrypt/boulderfrom 0.20251110.0 to 0.20260406.0Release notes
Sourced from github.com/letsencrypt/boulder's releases.
... (truncated)
Commits
e139723build(deps): bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#8699)4065776deps: update pkcs11 and pkcs11key (#8692)dd8ce81bad-key-revoker: Require maxExpectedReplicationLag (#8693)daf80eeRemove registrations.LockCol (#8698)1958cc9test: Upgrade consul to 1.22.6 (#8696)3495c8bgrpc: Advertise h2 support in ALPN (#8697)5af6580ra: remove MaxNames config field (#8691)d51bd6ava: Add experimental VA for testing Hickory (#8688)9872323test: make nonce-srv-v2 / noncev2 the default (#8689)329e63dRemove deprecated flags (#8684)Updates
github.com/sigstore/cosign/v3from 3.0.5 to 3.0.6Release notes
Sourced from github.com/sigstore/cosign/v3's releases.
Commits
f1ad3eeFix DSSE predicate check (GHSA-w6c6-c85g-mmv6) (#4801)2b396bdchore(deps): bump gitlab.com/gitlab-org/api/client-go (#4757)eb5b147chore(deps): bump the gomod group across 1 directory with 18 updates (#4789)fb66c28fix(deps): CVE-2026-2303 / CVE-2026-2303 (#4764)f3d74d4Fix 'the' typo in copyright name (#4788)f4766a9chore(deps): bump the actions group across 1 directory with 5 updates (#4784)4c9ba21chore(deps): bump chainguard-dev/actions in the actions group (#4772)af30fe6chore(deps): bump github.com/awslabs/amazon-ecr-credential-helper/ecr-login92084d8chore(deps): bump cuelang.org/go from 0.15.4 to 0.16.043a9682chore(deps): bump github.com/open-policy-agent/opa from 1.13.2 to 1.14.1Updates
github.com/sigstore/rekorfrom 1.5.0 to 1.5.1Release notes
Sourced from github.com/sigstore/rekor's releases.
Changelog
Sourced from github.com/sigstore/rekor's changelog.
Commits
bb573aabuild(deps): Bump actions/upload-artifact from 6.0.0 to 7.0.0 (#2773)6188957build(deps): Bump google.golang.org/api from 0.264.0 to 0.269.0 (#2770)f76fb2abuild(deps): Bump github/codeql-action in the all group (#2772)ae85b80build(deps): Bump github.com/redis/go-redis/v9 from 9.17.3 to 9.18.0 (#2769)9836e32build(deps): Bump the all group with 11 updates (#2768)b81ecd3build(deps): Bump gocloud.dev from 0.40.0 to 0.44.0 (#2757)2d46808optimize memory for DSSE v0.0.1 processing (#2766)bd11cb9build(deps): Bump go.step.sm/crypto from 0.74.0 to 0.76.2 (#2760)c302fdbbuild(deps): Bump github.com/secure-systems-lab/go-securesystemslib (#2758)3444350build(deps): Bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 (#2763)Updates
github.com/sigstore/sigstorefrom 1.10.4 to 1.10.5Release notes
Sourced from github.com/sigstore/sigstore's releases.
Commits
c90de3echore: mention openbao being supported as well (#2313) (#2313)b377f8fchore: Project-wide linting (#2310)295d656build(deps): Bump the all group across 1 directory with 3 updates (#2296)c731032(kms/hashivault): add openbao support (#2303)b56c866fix: eliminate usage of text/template (#2288)1d8faffbuild(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2286)4ac5776build(deps): Bump github.com/letsencrypt/boulder (#2282)36276e8build(deps): Bump golang.org/x/crypto from 0.44.0 to 0.47.0 (#2258)59887c9build(deps): Bump the all group across 1 directory with 2 updates (#2278)1e85403build(deps): Bump dexidp/dex in /test/e2e in the all group (#2279)Updates
golang.org/x/cryptofrom 0.49.0 to 0.50.0Commits
03ca0dcgo.mod: update golang.org/x dependencies8400f4assh: respect signer's algorithm preference in pickSignatureAlgorithm81c6cb3ssh: swap cbcMinPaddingSize to cbcMinPacketSize to get encLengthUpdates
golang.org/x/netfrom 0.52.0 to 0.53.0Commits
a8d1fc1go.mod: update golang.org/x dependencies056ac74quic: avoid depending on golang.org/x/sys/unixc85f611http3: add http3 package for testing in std805fc81http2: add transport API testse63b894http2: support testing via net/http.Transport.RoundTrip9ee1e48http2/hpack: prevent HeaderField from escaping during encoding1e71bd8http2: prevent hanging Transport due to bad SETTINGS frame7bca150internal/http3: respect net/http Server Shutdown context when shutting down44c41beinternal/http3: prevent server from holding mutex when sleeping during shutdown228a67ainternal/http3: add CloseIdleConnections support in transportUpdates
golang.org/x/timefrom 0.14.0 to 0.15.0Commits
812b343all: upgrade go directive to at least 1.25.0 [generated]Updates
google.golang.org/grpcfrom 1.79.3 to 1.80.0Release notes
Sourced from google.golang.org/grpc's releases.
Commits
397e45eChange version to 1.80.0 (#8948)64ebf0aCherry-pick #8997 to v1.80.x (#9027)e45ed24xds/rbac: add additional handling for addresses with ports (#8990) (#9022)c78d26eCherry-pick #8957 to v1.80.x (#9007)bd7cd3cgrpc: enforce strict path checking for incoming requests on the server (#8987)b6597b3xds/clusterimpl: use xdsConfig for updates and remove redundant fields from L...1d4fa8axds: change cdsbalancer to use update from dependency manager (#8907)8f47d36attributes: Replace internal map with linked list (#8933)22e1ee8xds: add panic recovery in xdsclient resource unmarshalling. (#8895)7136e99credentials/alts: Pool write buffers (#8919)Updates
k8s.io/apifrom 0.35.2 to 0.35.3Commits
3897036Update dependencies to v0.35.3 tagUpdates
k8s.io/apimachineryfrom 0.35.2 to 0.35.3Commits
Updates
k8s.io/client-gofrom 0.35.2 to 0.35.3Commits
4f1f0a2Update dependencies to v0.35.3 tagf80003cMerge pull request #136903pohly/automated-cherry-pick-of-#1364558b41556fake client-go: un-deprecate NewSimpleClientsetUpdates
sigs.k8s.io/release-utilsfrom 0.12.3 to 0.12.4Release notes
Sourced from sigs.k8s.io/release-utils's releases.
Commits
c5ec679Merge pull request #182 from saschagrunert/fix/agent-shared-optionse3734a4Fix shared default options mutation across agents96f97baMerge pull request #181 from kubernetes-sigs/dependabot/github_actions/action...6f678e3build(deps): bump the actions group with 2 updatesc2cdc95Merge pull request #179 from cpanato/updatesd5a73e4fix lintsa4f2787bump cosign and golangci-lintd1b29d9Merge pull request #177 from kubernetes-sigs/dependabot/docker/all-9adf8b7ea7ffec3c4build(deps): bump golang from 1.26.0 to 1.26.1 in the all groupae59572Merge pull request #178 from kubernetes-sigs/dependabot/go_modules/all-c0a0eb...Updates
github.com/go-jose/go-jose/v4from 4.1.3 to 4.1.4Release notes
Sourced from github.com/go-jose/go-jose/v4's releases.
Commits
0e59876Merge commit from forkddffdbcBump actions/checkout from 5 to 6 (#213)Updates
github.com/hashicorp/vault/apifrom 1.22.0 to 1.23.0Commits
d430306Merge remote-tracking branch 'remotes/from/ce/main'a3bc0a3(enos): Add LDAP secrets engine blackbox tests to Plugin Scenario (#13072) (#...f8df539Merge remote-tracking branch 'remotes/from/ce/main'2b0ec25VAULT-43444 Addressed races in tests (#13278) (#13285)a097d1fMerge remote-tracking branch 'remotes/from/ce/main'7e587fdUpdate vault-plugin-auth-kubernetes to v0.24.1 (#13259) (#13287)1331818UI: Fix namespace search showing empty state when namespaces exist (#13257) (...7b12febMerge remote-tracking branch 'remotes/from/ce/main'7d4395cUpdate vault-plugin-auth-jwt to v0.26.1 (#13242) (#13283)6d4b615adds flag to fix chrome in ci (#13279) (#13282)Updates
github.com/sigstore/protobuf-specsfrom 0.5.0 to 0.5.1Changelog
Sourced from github.com/sigstore/protobuf-specs's changelog.
Commits
3001afeBump ts to v0.5.1 for new release (#874)f68ef15build(deps): bump the actions-deps group with 2 updates (#873)9859358build(deps): bump gradle-wrapper in /java in the java-deps group (#866)51546adbuild(deps): bump ts-proto from 2.11.2 to 2.11.5 in /protoc-builder/hack in t...8bb3cb3build(deps): bump the docker-refs group (#867)9dfb871Update GRPC_GATEWAY_COMMIT in versions.mk (#864)80abc3fbuild(deps): bump the rust-deps group across 1 directory with 3 updates (#869)c24db24build(deps): bump homebrew/core/protobuf from 33.4 to 34.1 in /protoc-builder...6a50d86Update GOOGLEAPIS_COMMIT in versions.mk (#863)a2cbebdBump packages for 0.5.1, bump deps (#862)Updates
github.com/sigstore/scaffoldingfrom 0.7.22 to 0.7.33Release notes
Sourced from github.com/sigstore/scaffolding's releases.
... (truncated)
Commits
8bd6867Fix TUF workflow file (#1842)62e684cFix goreleaser hook (#1841)6c76ec3Bump tesseract (#1835)28cccdeMove commands to separate modules (#1814)9d6e1a3Bump the docker-deps group across 3 directories with 3 updates (#1832)4fb9911Bump github.com/sigstore/timestamp-authority/v2 in the go-deps group (#1831)08da4a8Bump github.com/sigstore/fulcio from 1.8.2 to 1.8.3 (#1830)f3ca261Bump the go-deps group across 1 directory with 2 updates (#1828)5f2eae0Bump sigstore deps (#1826)cb48a63Add unit test job (#1823)Updates
github.com/sigstore/sigstore/pkg/signature/kms/awsfrom 1.10.4 to 1.10.5Release notes
Sourced from github.com/sigstore/sigstore/pkg/signature/kms/aws's releases.