Skip to content

chore(deps): bump the go group with 11 updates - #2118

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-57c62750ac
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-57c62750ac

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 20, 2026

Copy link
Copy Markdown
Contributor

Bumps the go group with 11 updates:

Package From To
github.com/aws/aws-sdk-go-v2/config 1.33.4 1.33.5
github.com/aws/aws-sdk-go-v2/credentials 1.20.4 1.20.5
github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager 0.4.5 0.4.7
github.com/aws/aws-sdk-go-v2/service/ecr 1.65.0 1.66.0
github.com/aws/aws-sdk-go-v2/service/s3 1.113.0 1.113.1
github.com/containerd/containerd/v2 2.3.5 2.4.0
github.com/docker/cli 29.8.0+incompatible 29.8.1+incompatible
github.com/fluxcd/pkg/ssa 0.77.0 0.78.0
github.com/sigstore/sigstore 1.10.9 1.10.10
go.podman.io/image/v5 5.41.1 5.41.2
sigs.k8s.io/controller-runtime 0.25.0 0.25.1

Updates github.com/aws/aws-sdk-go-v2/config from 1.33.4 to 1.33.5

Commits

Updates github.com/aws/aws-sdk-go-v2/credentials from 1.20.4 to 1.20.5

Commits
  • f2706c8 Release 2023-12-08
  • 1dac0c9 Regenerated Clients
  • cbd9216 Update API model
  • c7357bb fix: reinstate presence of retryer when functional opts run but still respect...
  • c5c34b3 fix: translation of ini service sections into shared config (#2416)
  • b3c7fbf update express cache key (#2414)
  • 9b90af4 fix: add non-vhostable buckets to path when using legacy endpoint resolver (#...
  • See full diff in compare view

Updates github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager from 0.4.5 to 0.4.7

Commits

Updates github.com/aws/aws-sdk-go-v2/service/ecr from 1.65.0 to 1.66.0

Commits

Updates github.com/aws/aws-sdk-go-v2/service/s3 from 1.113.0 to 1.113.1

Commits

Updates github.com/containerd/containerd/v2 from 2.3.5 to 2.4.0

Release notes

Sourced from github.com/containerd/containerd/v2's releases.

containerd 2.4.0

Welcome to the v2.4.0 release of containerd!

containerd 2.4 is a regular (non-LTS) release with a shorter support window, intended for users who want to adopt new features sooner. As the release following the 2.3 LTS, it is the point in the release cycle where previously deprecated features may be removed, so this release may include breaking changes; check the notes below and clear any deprecation warnings from your current version before upgrading.

Users prioritizing stability and a longer support lifecycle should stay on the 2.3 LTS release.

Highlights

Container Runtime Interface (CRI)

  • Enable mount manager for image mounts in CRI (#13542)
  • Export sandbox image and CNI directory configuration in CRI plugin info (#13940)
  • Set default runtimeFeatures.UserNamespacesHostNetwork to true (#13162)
  • Support OCI runtime feature introspection for non-runc runtimes (#13504)

Image Distribution

  • Apply hardening to strip sensitive authentication headers when fetching descriptor URLs (#12889)
  • Support propagating HTTP 299 warning headers from registries to the resolver (#12698)
  • Use klauspost/compress for gzip layer decompression (#13560)

Image Storage

  • Add client options to fetch all layer content during unpack even when snapshots exist (#14126)
  • Include media type in content create events (#13833)
  • Add forward References to the GC collection context (#13634)

Node Resource Interface (NRI)

  • Expose container image name, digest, and config digest to NRI plugins (#13960)
  • Emit deprecation warnings for plugins using deprecated NRI interfaces (#13916)

Runtime

  • Mask /proc/interrupts and CPU thermal throttle sysfs paths in Linux containers by default (#14090)
  • Add UpdateSandbox RPC to propagate sandbox controller updates to the shim (#14105)
  • Avoid immediately restarting containers with restart=always policy after they are explicitly stopped (#13993)
  • Pass tracing context from shim to runc and hooks (#14036)
  • Fix user and group lookup failures in container rootfs containing symlinked /etc/passwd or /etc/group (#13818)
  • Implement Windows named-pipe server and log streaming support in pkg/shim (#13948)
  • Enable log scrubbing by default on Windows (#13837)
  • Allow specifying parent checkpoint directory when checkpointing with runc (#13699)

... (truncated)

Changelog

Sourced from github.com/containerd/containerd/v2's changelog.

Versioning and Release

This document details the versioning and release plan for containerd. Stability is a top goal for this project, and we hope that this document and the processes it entails will help to achieve that. It covers the release process, versioning numbering, backporting, API stability and support horizons.

If you rely on containerd, it would be good to spend time understanding the areas of the API that are and are not supported and how they impact your project in the future.

This document will be considered a living document. Supported timelines, backport targets and API stability guarantees will be updated here as they change.

If there is something that you require or this document leaves out, please reach out by filing an issue.

Releases

Releases of containerd will be versioned using dotted triples, similar to Semantic Version. For the purposes of this document, we will refer to the respective components of this triple as <major>.<minor>.<patch>. The version number may have additional information, such as alpha, beta and release candidate qualifications. Such releases will be considered "pre-releases".

Major and Minor Releases

Major and minor releases of containerd will be made from main. Releases of containerd will be marked with GPG signed tags and announced at https://github.com/containerd/containerd/releases. The tag will be of the format v<major>.<minor>.<patch> and should be made with the command git tag -s v<major>.<minor>.<patch>.

After a minor release, a branch will be created, with the format release/<major>.<minor> from the minor tag. All further patch releases will be done from that branch. For example, once we release v1.0.0, a branch release/1.0 will be created from that tag. All future patch releases will be done against that branch.

Release Cadence

Since containerd v2.3 in April 2026, minor releases are provided on a time basis with a cadence of 4 months. New minor releases are scheduled for April, August, and December of each year. This cadence is synchronized with the Kubernetes release schedule to ensure that new features in containerd can be smoothly adopted by new Kubernetes releases.

The maintainers will maintain a roadmap and milestones for each release, however,

... (truncated)

Commits
  • a7fe631 Merge pull request #14169 from samuelkarp/prepare-release-2.4.0
  • 647fafa Prepare release notes for v2.4.0
  • c6d0192 Merge pull request #14170 from samuelkarp/prepare-api-v1.12.0
  • 5c4ea21 Prepare release notes for api/v1.12.0
  • 610d8d8 Merge pull request #14166 from samuelkarp/deprecations-and-removals-for-2.4
  • 531b3a3 tracing: remove deprecated tracing config options
  • ca8579a tracing: add tests for otlp exporter and env vars
  • ee024b7 tracing: remove deprecated otlp configs
  • f7c654f cri: remove deprecated cni bin_dir
  • 4f7de25 cri: remove enable_cdi config option
  • Additional commits viewable in compare view

Updates github.com/docker/cli from 29.8.0+incompatible to 29.8.1+incompatible

Commits
  • 4a63305 Merge pull request #7297 from docker/dependabot/github_actions/docker-actions...
  • 87ff477 Merge pull request #7307 from thaJeztah/ci_ubuntu_2604
  • 101ffc0 ci: update to Ubuntu 26.04 runners
  • 32ff1e7 build(deps): bump docker/docker-agent-action/.github/workflows/review-pr.yml
  • d146e67 Merge pull request #7290 from vvoland/port-template
  • ac976d9 Merge pull request #7296 from keeltrace/keeltrace/history-timezone-test
  • 48baf6c Merge pull request #7306 from thaJeztah/bump_x_deps
  • 47a06aa Merge pull request #7293 from thaJeztah/bump_uax29
  • 1bf3eb6 Merge pull request #7295 from thaJeztah/bump_userns
  • 60dffc9 vendor: golang.org/x/net v0.59.0
  • Additional commits viewable in compare view

Updates github.com/fluxcd/pkg/ssa from 0.77.0 to 0.78.0

Commits
  • fc29ca0 Merge pull request #1293 from fluxcd/release-main
  • 98725a2 Prepare for release
  • 1e50081 Merge pull request #1144 from adri1197/event-api
  • 46f413f Migrate event recorder to events/v1 API
  • 46433b8 Merge pull request #1298 from dipti-pai/kustomize-substitute-with-vars
  • 56fb7e5 kustomize: add ContextWithSecretVarsCollector for LoadVariables
  • 6d8d5d9 Merge pull request #1292 from fluxcd/k8s-1.37.0
  • a532207 auth: Update cloud SDKs
  • bc7fd2f Update to Kubernetes 1.37.0
  • c437e4f Merge pull request #1290 from fluxcd/comment-migrate-api-version
  • Additional commits viewable in compare view

Updates github.com/sigstore/sigstore from 1.10.9 to 1.10.10

Release notes

Sourced from github.com/sigstore/sigstore's releases.

v1.10.10

What's Changed

New Contributors

Full Changelog: sigstore/sigstore@v1.10.9...v1.10.10

Commits
  • 49e21e5 build(deps): Bump github.com/google/go-containerregistry from 0.21.9 to 0.22....
  • eda3b60 build(deps): Bump the gomod group across 4 directories with 4 updates (#2413)
  • b3e2728 Adjust mldsa error handling (#2417)
  • bfbf63e Support for ML-DSA keys (#2416)
  • 538e3fa Bump go to 1.27 and fix linter and api issues (#2415)
  • e8841f5 build(deps): Bump hashicorp/vault in /test/e2e in the all group (#2412)
  • 5b3d739 Fix Azure KMS ECDSA signature verification (r||s ordering + padding) (#2410)
  • ba4de68 build(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2406)
  • 1abcedd build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#2407)
  • d579148 build(deps): Bump github.com/aws/aws-sdk-go-v2/service/kms (#2404)
  • Additional commits viewable in compare view

Updates go.podman.io/image/v5 from 5.41.1 to 5.41.2

Commits
  • b5becb3 bump image to 5.41.2
  • 32b2c7e go.mod: require go.podman.io/storage v1.64.1
  • 6eac452 bump storage to 1.64.1
  • 3b75133 Merge commit from fork
  • 8049716 Merge branch 'LOCAL-oci-archive-6.1' into LOCAL-changes-security-6.1
  • b3122a5 Merge branch 'LOCAL-storage-extract-archive-6.1' into LOCAL-changes-security-6.1
  • 5ec1386 Merge branch 'LOCAL-storage-create-archive-6.1' into LOCAL-changes-security-6.1
  • 2de0f0b Merge branch 'LOCAL-storage-tests-6.1' into LOCAL-changes-security-6.1
  • dc134cb Prevent symbolic link escapes when consuming oci-archive: archives
  • d06a599 Turn tempDirOCIRef into stateful unpackedArchive
  • Additional commits viewable in compare view

Updates sigs.k8s.io/controller-runtime from 0.25.0 to 0.25.1

Release notes

Sourced from sigs.k8s.io/controller-runtime's releases.

v0.25.1

What's Changed

Full Changelog: kubernetes-sigs/controller-runtime@v0.25.0...v0.25.1

Commits
  • 67b72c2 [release-0.25] 🐛 client: fix subresource create RV parse error under read-you...
  • f997220 [release-0.25] 🐛 priorityqueue: fix data race on []*item in logState (#3593)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go group with 11 updates:

| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.33.4` | `1.33.5` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2) | `1.20.4` | `1.20.5` |
| [github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager](https://github.com/aws/aws-sdk-go-v2) | `0.4.5` | `0.4.7` |
| [github.com/aws/aws-sdk-go-v2/service/ecr](https://github.com/aws/aws-sdk-go-v2) | `1.65.0` | `1.66.0` |
| [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2) | `1.113.0` | `1.113.1` |
| [github.com/containerd/containerd/v2](https://github.com/containerd/containerd) | `2.3.5` | `2.4.0` |
| [github.com/docker/cli](https://github.com/docker/cli) | `29.8.0+incompatible` | `29.8.1+incompatible` |
| [github.com/fluxcd/pkg/ssa](https://github.com/fluxcd/pkg) | `0.77.0` | `0.78.0` |
| [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) | `1.10.9` | `1.10.10` |
| [go.podman.io/image/v5](https://github.com/podman-container-tools/container-libs) | `5.41.1` | `5.41.2` |
| [sigs.k8s.io/controller-runtime](https://github.com/kubernetes-sigs/controller-runtime) | `0.25.0` | `0.25.1` |


Updates `github.com/aws/aws-sdk-go-v2/config` from 1.33.4 to 1.33.5
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@config/v1.33.4...config/v1.33.5)

Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.20.4 to 1.20.5
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/mq/v1.20.4...service/mq/v1.20.5)

Updates `github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager` from 0.4.5 to 0.4.7
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@feature/s3/transfermanager/v0.4.5...feature/s3/transfermanager/v0.4.7)

Updates `github.com/aws/aws-sdk-go-v2/service/ecr` from 1.65.0 to 1.66.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.65.0...service/s3/v1.66.0)

Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.113.0 to 1.113.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.113.0...service/s3/v1.113.1)

Updates `github.com/containerd/containerd/v2` from 2.3.5 to 2.4.0
- [Release notes](https://github.com/containerd/containerd/releases)
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)
- [Commits](containerd/containerd@v2.3.5...v2.4.0)

Updates `github.com/docker/cli` from 29.8.0+incompatible to 29.8.1+incompatible
- [Commits](docker/cli@v29.8.0...v29.8.1)

Updates `github.com/fluxcd/pkg/ssa` from 0.77.0 to 0.78.0
- [Commits](fluxcd/pkg@ssa/v0.77.0...ssa/v0.78.0)

Updates `github.com/sigstore/sigstore` from 1.10.9 to 1.10.10
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.10.9...v1.10.10)

Updates `go.podman.io/image/v5` from 5.41.1 to 5.41.2
- [Release notes](https://github.com/podman-container-tools/container-libs/releases)
- [Commits](podman-container-tools/container-libs@image/v5.41.1...image/v5.41.2)

Updates `sigs.k8s.io/controller-runtime` from 0.25.0 to 0.25.1
- [Release notes](https://github.com/kubernetes-sigs/controller-runtime/releases)
- [Changelog](https://github.com/kubernetes-sigs/controller-runtime/blob/main/RELEASE.md)
- [Commits](kubernetes-sigs/controller-runtime@v0.25.0...v0.25.1)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.33.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
  dependency-version: 1.20.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager
  dependency-version: 0.4.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/ecr
  dependency-version: 1.66.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
  dependency-version: 1.113.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/containerd/containerd/v2
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/docker/cli
  dependency-version: 29.8.1+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/fluxcd/pkg/ssa
  dependency-version: 0.78.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/sigstore/sigstore
  dependency-version: 1.10.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: go.podman.io/image/v5
  dependency-version: 5.41.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: sigs.k8s.io/controller-runtime
  dependency-version: 0.25.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. labels Sep 20, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 20, 2026 08:28
@dependabot dependabot Bot added kind/dependency dependency update, etc. kind/chore chore, maintenance, etc. labels Sep 20, 2026
@github-actions github-actions Bot added the size/m Medium label Sep 20, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 22, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/go_modules/go-57c62750ac branch September 22, 2026 05:45
pull Bot pushed a commit to Skarlso/ocm that referenced this pull request Sep 22, 2026
…del#2118) (open-component-model#2120)

open-component-model#2118 upgrades go to `1.27` because of the `sigstore` bump. However, the
new go version fails on different CI pipelines which might be connected
to golang/go#81089. Hence, we skip the go
upgrade until the fix is backported.

Fixes open-component-model#2118

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Frederic Wilhelm <frederic.wilhelm@sap.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. size/m Medium

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants