Skip to content

chore(deps): bump the go group across 1 directory with 17 updates - #2129

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-9d5796b529
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-9d5796b529

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps the go group with 17 updates in the / directory:

Package From To
github.com/aws/aws-sdk-go-v2 1.47.0 1.47.1
github.com/aws/aws-sdk-go-v2/config 1.33.5 1.33.6
github.com/aws/aws-sdk-go-v2/credentials 1.20.5 1.20.6
github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager 0.4.7 0.4.10
github.com/aws/aws-sdk-go-v2/service/ecr 1.66.0 1.66.1
github.com/aws/aws-sdk-go-v2/service/s3 1.113.1 1.113.4
github.com/aws/smithy-go 1.28.1 1.28.2
github.com/klauspost/compress 1.20.0 1.20.1
github.com/onsi/ginkgo/v2 2.32.2 2.33.0
github.com/onsi/gomega 1.43.0 1.44.0
github.com/sigstore/sigstore 1.10.9 1.11.0
github.com/ulikunitz/xz 0.5.16 0.5.17
k8s.io/api 0.37.0 0.37.1
k8s.io/apiextensions-apiserver 0.37.0 0.37.1
k8s.io/apimachinery 0.37.0 0.37.1
k8s.io/cli-runtime 0.37.0 0.37.1
k8s.io/client-go 0.37.0 0.37.1

Updates github.com/aws/aws-sdk-go-v2 from 1.47.0 to 1.47.1

Commits

Updates github.com/aws/aws-sdk-go-v2/config from 1.33.5 to 1.33.6

Commits

Updates github.com/aws/aws-sdk-go-v2/credentials from 1.20.5 to 1.20.6

Commits

Updates github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager from 0.4.7 to 0.4.10

Commits

Updates github.com/aws/aws-sdk-go-v2/service/ecr from 1.66.0 to 1.66.1

Commits

Updates github.com/aws/aws-sdk-go-v2/service/s3 from 1.113.1 to 1.113.4

Commits

Updates github.com/aws/smithy-go from 1.28.1 to 1.28.2

Changelog

Sourced from github.com/aws/smithy-go's changelog.

Release (2026-09-18)

General Highlights

  • Dependency Update: Updated to the latest SDK module versions

Module Highlights

  • github.com/aws/smithy-go: v1.28.2
    • Bug Fix: Avoid allocating a slice in ValidateEndpointHost by indexing into the hostname instead of using strings.Split.
    • Bug Fix: Fix event stream decode panic on unknown header value type.
    • Bug Fix: Fix schema-serde CBOR decode panic on malformed string/blob length.
    • Bug Fix: JoinPath keeps a trailing slash when the added path is a slash.

Release (2026-08-26)

General Highlights

  • Dependency Update: Updated to the latest SDK module versions

Module Highlights

  • github.com/aws/smithy-go: v1.28.1
    • Bug Fix: Fix broken AddLogger middleware since its insert point was removed.

Release (2026-08-25.2)

General Highlights

  • Dependency Update: Updated to the latest SDK module versions

Module Highlights

  • github.com/aws/smithy-go: v1.28.0
    • Feature: Set Content-Length inline when the request body is set via SetStream. The ComputeContentLength middleware is now deprecated.

Release (2026-08-25)

General Highlights

  • Dependency Update: Updated to the latest SDK module versions

Module Highlights

  • github.com/aws/smithy-go: v1.27.10
    • Bug Fix: Fix a data race on the underlying writer when an event stream is closed while an event write is in flight.
    • Bug Fix: Restore draining the HTTP response body in CloseResponseBody to avoid issues with TCP connection reuse.

Release (2026-08-21)

General Highlights

  • Dependency Update: Updated to the latest SDK module versions

Module Highlights

  • github.com/aws/smithy-go: v1.27.9
    • Bug Fix: Fix a generic event stream exception not carrying the error code and message from its payload.
    • Bug Fix: Fix an event stream not being closed when its connection is lost, which would cause a caller writing to the stream to block indefinitely.
    • Bug Fix: Fix deserialization of an empty list producing a nil slice instead of an empty one.

... (truncated)

Commits
  • 9b28af0 Release 2026-09-18
  • f59df88 Avoid slice allocation in ValidateEndpointHost (#705)
  • 7c16d7f fix decode panic on event stream header type and bad cbor string/blob len (#713)
  • c60819a fix initial-message race (#712)
  • d05a672 fix v2 event streams orphaning the result channel on error paths in schema-se...
  • fe95176 Revert "fix v2 event streams orphaning the result channel on error paths in s...
  • 9847245 fix v2 event streams orphaning the result channel on error paths in schema-serde
  • 9eba49f Print stacktrace when smithy-build fails (#708)
  • 959c6ab Keep a trailing slash when JoinPath right operand is a slash. (#698)
  • d253285 update README
  • See full diff in compare view

Updates github.com/klauspost/compress from 1.20.0 to 1.20.1

Release notes

Sourced from github.com/klauspost/compress's releases.

v1.20.1

What's Changed

New Contributors

Full Changelog: klauspost/compress@v1.20.0...v1.20.1

Commits
  • 5d880f2 tests: Pre-release cleanups (#1231)
  • 5ed8a01 Report unexpected EOF for truncated Huffman extra bits (#1229)
  • 0bed724 flate: avoid FMA in EstimatedBits for portable rounding (#1224)
  • 147b531 zstd: apply reset options to reused frame decoders (#1226)
  • 58dac78 gzhttp: only decompress a request when gzip is the outermost coding (#1223)
  • 9b00a55 gzhttp: preserve caller request headers in Transport (#1225)
  • de8f55d ossfuzz: include zstd seqdec path tests (#1222)
  • a1c49c6 flate: precompute literal costs for findMatch (#1217)
  • ebd8190 flate: avoid the hand-rolled sorts when generating Huffman codes (#1214)
  • 4dc0d32 flate: use separate tables in histogramSplit (#1215)
  • Additional commits viewable in compare view

Updates github.com/onsi/ginkgo/v2 from 2.32.2 to 2.33.0

Release notes

Sourced from github.com/onsi/ginkgo/v2's releases.

v2.33.0

Features

  • The JUnit reporter now records each spec's ReportEntrys as <properties> on its <testcase> element, with the entry's name and its JSON-encoded value. Thanks @​pohly! [23db51a]

Maintenance

  • Releases are now cut by a GitHub Actions workflow (Actions -> Release -> Run workflow) rather than by hand, with changelog entries collected under ## Unreleased as the work happens. See RELEASING.md. [8616ecb]
Changelog

Sourced from github.com/onsi/ginkgo/v2's changelog.

2.33.0

Features

  • The JUnit reporter now records each spec's ReportEntrys as <properties> on its <testcase> element, with the entry's name and its JSON-encoded value. Thanks @​pohly! [23db51a]

Maintenance

  • Releases are now cut by a GitHub Actions workflow (Actions -> Release -> Run workflow) rather than by hand, with changelog entries collected under ## Unreleased as the work happens. See RELEASING.md. [8616ecb]
Commits
  • 9f94149 v2.33.0
  • db78e1b changelog: entries for the JUnit ReportEntry support and the release flow
  • 8616ecb ci: release from a single workflow_dispatch button
  • d8d9cdd README: add a sponsor badge
  • ac70da6 README: dark-mode logo and a docs badge
  • 23db51a junit: support ReportEntry
  • See full diff in compare view

Updates github.com/onsi/gomega from 1.43.0 to 1.44.0

Release notes

Sourced from github.com/onsi/gomega's releases.

v1.44.0

Fixes

  • BeNumerically compares signed and unsigned integers by value: -1 no longer equals uint64(math.MaxUint64) and uint(5) is now greater than -3 (#925) [26e3c6b]
  • BeNumerically("~") no longer overflows when computing the distance between extreme integers (#928) [1955764]
  • BeNumerically("==", x, threshold) now honors the threshold for floats, as it already did for integers (#927) [10e2aca]
  • HaveKeyWithValue succeeds if any key accepted by the key matcher has a matching value, rather than depending on map iteration order (#929) [ffc577a]
  • HaveKey and HaveKeyWithValue treat key and value matcher errors like ContainElement does: a match wins, and an error is only reported when nothing matches (#926) [dc91598]
  • MatchJSON no longer treats numbers too large for a float64 as equal to one another (#930) [9d619a5]
  • MatchJSON compares integers beyond ±2^53 exactly, so neighboring large integers (e.g. IDs) no longer match; all other numbers are still compared as float64s (#931) [8ef1aa7, 630fe12]
  • HaveExactElements reports missing or extra elements that start at index 0, and reports the first extra element's index rather than the last (#934) [af1b777]
  • MatchYAML compares every document in a multi-document stream rather than only the first; empty documents (e.g. a leading or trailing ---) are ignored (#933) [2773796]
  • MatchXML ignores namespace prefixes: elements and attributes are compared by namespace URI, and the URIs declared on each element must match whatever prefix they are bound to (#932) [c0dbd89, 2565350]

v1.43.1

Maintenance

  • Update go.yaml.in/yaml/v3 to v3.0.5 [d547015]
  • Releases are now cut by a GitHub Actions workflow (Actions -> Release -> Run workflow) rather than by hand, with changelog entries collected under ## Unreleased as the work happens. Releases still ship the stripped-down tree on master-lite - tests removed and Ginkgo dropped from go.mod - and the workflow now builds it and checks it on every push. See RELEASING.md. [e9dc84d]
Changelog

Sourced from github.com/onsi/gomega's changelog.

1.44.0

Fixes

  • BeNumerically compares signed and unsigned integers by value: -1 no longer equals uint64(math.MaxUint64) and uint(5) is now greater than -3 (#925) [26e3c6b]
  • BeNumerically("~") no longer overflows when computing the distance between extreme integers (#928) [1955764]
  • BeNumerically("==", x, threshold) now honors the threshold for floats, as it already did for integers (#927) [10e2aca]
  • HaveKeyWithValue succeeds if any key accepted by the key matcher has a matching value, rather than depending on map iteration order (#929) [ffc577a]
  • HaveKey and HaveKeyWithValue treat key and value matcher errors like ContainElement does: a match wins, and an error is only reported when nothing matches (#926) [dc91598]
  • MatchJSON no longer treats numbers too large for a float64 as equal to one another (#930) [9d619a5]
  • MatchJSON compares integers beyond ±2^53 exactly, so neighboring large integers (e.g. IDs) no longer match; all other numbers are still compared as float64s (#931) [8ef1aa7, 630fe12]
  • HaveExactElements reports missing or extra elements that start at index 0, and reports the first extra element's index rather than the last (#934) [af1b777]
  • MatchYAML compares every document in a multi-document stream rather than only the first; empty documents (e.g. a leading or trailing ---) are ignored (#933) [2773796]
  • MatchXML ignores namespace prefixes: elements and attributes are compared by namespace URI, and the URIs declared on each element must match whatever prefix they are bound to (#932) [c0dbd89, 2565350]

1.43.1

Maintenance

  • Update go.yaml.in/yaml/v3 to v3.0.5 [d547015]
  • Releases are now cut by a GitHub Actions workflow (Actions -> Release -> Run workflow) rather than by hand, with changelog entries collected under ## Unreleased as the work happens. Releases still ship the stripped-down tree on master-lite - tests removed and Ginkgo dropped from go.mod - and the workflow now builds it and checks it on every push. See RELEASING.md. [e9dc84d]
Commits
  • c933817 v1.44.0
  • 37fa900 v1.44.0 (full)
  • 509f2b0 changelog: entries for Bump the go group with 13 updates #925-#934
  • 2565350 fix: MatchXML compares namespace declarations by URI, ignoring the prefix
  • 630fe12 fix: MatchJSON only compares integers beyond 2^53 exactly
  • c0dbd89 fix: MatchXML ignores namespace prefixes and declarations
  • 2773796 fix: MatchYAML compares every document in a multi-document stream
  • af1b777 fix: HaveExactElements reports missing/extra elements starting at index 0
  • 8ef1aa7 fix: MatchJSON compares numbers exactly
  • 9d619a5 fix: MatchJSON reports numbers that do not fit in a float64
  • Additional commits viewable in compare view

Updates github.com/sigstore/sigstore from 1.10.9 to 1.11.0

Release notes

Sourced from github.com/sigstore/sigstore's releases.

v1.11.0

What's Changed

v1.11.0 and v1.10.10 are identical releases tagged for the same commit. Since the minimum Go version has been bumped to 1.27.0, we are releasing this change as a minor version bump. Dependencies that do not want to update to 1.27 yet can use v1.10.11, and we'll backport any security fixes to v1.10.x for the next 6 months while Go 1.26 is still supported.

Full Changelog: sigstore/sigstore@v1.10.9...v1.11.0

v1.10.11 rolls back the release to a previous commit where the minimum Go version is 1.25.0. An upcoming v1.11.0 will require 1.27.0.

v1.10.10

What's Changed

New Contributors

Full Changelog: sigstore/sigstore@v1.10.9...v1.10.10

Commits
  • 4f4c3f8 Add release instructions (#2418)
  • 49e21e5 build(deps): Bump github.com/google/go-containerregistry from 0.21.9 to 0.22....
  • eda3b60 build(deps): Bump the gomod group across 4 directories with 4 updates (#2413)
  • b3e2728 Adjust mldsa error handling (#2417)
  • bfbf63e Support for ML-DSA keys (#2416)
  • 538e3fa Bump go to 1.27 and fix linter and api issues (#2415)
  • e8841f5 build(deps): Bump hashicorp/vault in /test/e2e in the all group (#2412)
  • 5b3d739 Fix Azure KMS ECDSA signature verification (r||s ordering + padding) (#2410)
  • ba4de68 build(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2406)
  • 1abcedd build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#2407)
  • Additional commits viewable in compare view

Updates github.com/ulikunitz/xz from 0.5.16 to 0.5.17

Commits

Updates k8s.io/api from 0.37.0 to 0.37.1

Commits

Updates k8s.io/apiextensions-apiserver from 0.37.0 to 0.37.1

Commits

Updates k8s.io/apimachinery from 0.37.0 to 0.37.1

Commits

Updates k8s.io/cli-runtime from 0.37.0 to 0.37.1

Commits

Updates k8s.io/client-go from 0.37.0 to 0.37.1

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go group with 17 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.47.0` | `1.47.1` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.33.5` | `1.33.6` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2) | `1.20.5` | `1.20.6` |
| [github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager](https://github.com/aws/aws-sdk-go-v2) | `0.4.7` | `0.4.10` |
| [github.com/aws/aws-sdk-go-v2/service/ecr](https://github.com/aws/aws-sdk-go-v2) | `1.66.0` | `1.66.1` |
| [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2) | `1.113.1` | `1.113.4` |
| [github.com/aws/smithy-go](https://github.com/aws/smithy-go) | `1.28.1` | `1.28.2` |
| [github.com/klauspost/compress](https://github.com/klauspost/compress) | `1.20.0` | `1.20.1` |
| [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) | `2.32.2` | `2.33.0` |
| [github.com/onsi/gomega](https://github.com/onsi/gomega) | `1.43.0` | `1.44.0` |
| [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) | `1.10.9` | `1.11.0` |
| [github.com/ulikunitz/xz](https://github.com/ulikunitz/xz) | `0.5.16` | `0.5.17` |
| [k8s.io/api](https://github.com/kubernetes/api) | `0.37.0` | `0.37.1` |
| [k8s.io/apiextensions-apiserver](https://github.com/kubernetes/apiextensions-apiserver) | `0.37.0` | `0.37.1` |
| [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) | `0.37.0` | `0.37.1` |
| [k8s.io/cli-runtime](https://github.com/kubernetes/cli-runtime) | `0.37.0` | `0.37.1` |
| [k8s.io/client-go](https://github.com/kubernetes/client-go) | `0.37.0` | `0.37.1` |



Updates `github.com/aws/aws-sdk-go-v2` from 1.47.0 to 1.47.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@v1.47.0...v1.47.1)

Updates `github.com/aws/aws-sdk-go-v2/config` from 1.33.5 to 1.33.6
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@config/v1.33.5...config/v1.33.6)

Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.20.5 to 1.20.6
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/mq/v1.20.5...service/mq/v1.20.6)

Updates `github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager` from 0.4.7 to 0.4.10
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@feature/s3/transfermanager/v0.4.7...feature/s3/transfermanager/v0.4.10)

Updates `github.com/aws/aws-sdk-go-v2/service/ecr` from 1.66.0 to 1.66.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.66.0...service/s3/v1.66.1)

Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.113.1 to 1.113.4
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.113.1...service/s3/v1.113.4)

Updates `github.com/aws/smithy-go` from 1.28.1 to 1.28.2
- [Release notes](https://github.com/aws/smithy-go/releases)
- [Changelog](https://github.com/aws/smithy-go/blob/main/CHANGELOG.md)
- [Commits](aws/smithy-go@v1.28.1...v1.28.2)

Updates `github.com/klauspost/compress` from 1.20.0 to 1.20.1
- [Release notes](https://github.com/klauspost/compress/releases)
- [Commits](klauspost/compress@v1.20.0...v1.20.1)

Updates `github.com/onsi/ginkgo/v2` from 2.32.2 to 2.33.0
- [Release notes](https://github.com/onsi/ginkgo/releases)
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md)
- [Commits](onsi/ginkgo@v2.32.2...v2.33.0)

Updates `github.com/onsi/gomega` from 1.43.0 to 1.44.0
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](onsi/gomega@v1.43.0...v1.44.0)

Updates `github.com/sigstore/sigstore` from 1.10.9 to 1.11.0
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.10.9...v1.11.0)

Updates `github.com/ulikunitz/xz` from 0.5.16 to 0.5.17
- [Commits](ulikunitz/xz@v0.5.16...v0.5.17)

Updates `k8s.io/api` from 0.37.0 to 0.37.1
- [Commits](kubernetes/api@v0.37.0...v0.37.1)

Updates `k8s.io/apiextensions-apiserver` from 0.37.0 to 0.37.1
- [Release notes](https://github.com/kubernetes/apiextensions-apiserver/releases)
- [Commits](kubernetes/apiextensions-apiserver@v0.37.0...v0.37.1)

Updates `k8s.io/apimachinery` from 0.37.0 to 0.37.1
- [Commits](kubernetes/apimachinery@v0.37.0...v0.37.1)

Updates `k8s.io/cli-runtime` from 0.37.0 to 0.37.1
- [Commits](kubernetes/cli-runtime@v0.37.0...v0.37.1)

Updates `k8s.io/client-go` from 0.37.0 to 0.37.1
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](kubernetes/client-go@v0.37.0...v0.37.1)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
  dependency-version: 1.47.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.33.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
  dependency-version: 1.20.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager
  dependency-version: 0.4.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/ecr
  dependency-version: 1.66.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
  dependency-version: 1.113.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/aws/smithy-go
  dependency-version: 1.28.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/klauspost/compress
  dependency-version: 1.20.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/onsi/ginkgo/v2
  dependency-version: 2.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/sigstore/sigstore
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/ulikunitz/xz
  dependency-version: 0.5.17
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: k8s.io/api
  dependency-version: 0.37.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: k8s.io/apiextensions-apiserver
  dependency-version: 0.37.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.37.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: k8s.io/cli-runtime
  dependency-version: 0.37.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: k8s.io/client-go
  dependency-version: 0.37.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. labels Sep 30, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 30, 2026 06:47
@dependabot dependabot Bot added kind/dependency dependency update, etc. kind/chore chore, maintenance, etc. labels Sep 30, 2026
@github-actions github-actions Bot added the size/m Medium label Sep 30, 2026

@frewilhelm frewilhelm left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we cannot bump go to 1.27 as there is a regression, see #2120 for more details. I will prepare another fix for this bump

@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/go_modules/go-9d5796b529 branch October 2, 2026 06:28
frewilhelm added a commit to frewilhelm/ocm that referenced this pull request Oct 2, 2026
…x 2129) (open-component-model#2130)

Fixes open-component-model#2129 by reverting sigstore and go version bump

> the new go version fails on different CI pipelines which might be
connected to golang/go#81089. Hence, we skip
the go upgrade until the fix is backported. (from
open-component-model#2120)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Frederic Wilhelm <frederic.wilhelm@sap.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. size/m Medium

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant