Skip to content

chore(deps): bump the all group with 8 updates - #1909

Merged
tekton-robot merged 1 commit into
release-v0.29.xfrom
dependabot/go_modules/release-v0.29.x/all-c62e75ecdb
Aug 25, 2026
Merged

chore(deps): bump the all group with 8 updates#1909
tekton-robot merged 1 commit into
release-v0.29.xfrom
dependabot/go_modules/release-v0.29.x/all-c62e75ecdb

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Bumps the all group with 8 updates:

Package From To
github.com/secure-systems-lab/go-securesystemslib 0.11.0 0.11.1
github.com/sigstore/rekor 1.5.3 1.5.4
github.com/stretchr/testify 1.11.1 1.12.0
golang.org/x/crypto 0.54.0 0.55.0
k8s.io/api 0.36.3 0.36.4
k8s.io/apimachinery 0.36.3 0.36.4
k8s.io/client-go 0.36.3 0.36.4
k8s.io/code-generator 0.36.3 0.36.4

Updates github.com/secure-systems-lab/go-securesystemslib from 0.11.0 to 0.11.1

Commits
  • 662f0f7 Merge pull request #165 from secure-systems-lab/dependabot/go_modules/github....
  • 0b40db0 chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0
  • e330185 Merge pull request #166 from secure-systems-lab/dependabot/go_modules/golang....
  • 1778905 chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0
  • 4d3d2c7 Merge pull request #164 from secure-systems-lab/dependabot/github_actions/act...
  • 379ec0d chore(deps): bump actions/checkout from 7.0.0 to 7.0.1
  • efcd6cb Merge pull request #163 from secure-systems-lab/dependabot/github_actions/act...
  • cd018df chore(deps): bump actions/setup-go from 6.5.0 to 7.0.0
  • 5cd75e5 Merge pull request #162 from secure-systems-lab/dependabot/go_modules/golang....
  • 4a8f3f8 chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0
  • Additional commits viewable in compare view

Updates github.com/sigstore/rekor from 1.5.3 to 1.5.4

Release notes

Sourced from github.com/sigstore/rekor's releases.

v1.5.4

Changelog

  • a36bd716fd0d81c314092718f37b53dc26b2af38 add changelog for v1.5.4 release (#2944)
  • 705fc05d8397407872ebce83598c6ab27ef2a13b Apply proactive hardening against malformed requests (GHSA-843x-px86-vq42) (#2945)
  • 5789c38f5cb272e7e41309d44985ce77cf01e56d build(deps): Bump github.com/go-swagger/go-swagger from 0.33.2 to 0.36.4 in /hack/tools in the all group across 1 directory (#2840)
  • 7dd85d3abf008c7d11e1721fc95c6f4f91e5c6a0 better handle connection issues (#2931)
  • a8544a8e30ac73774b52f573c05d8e31844d26dd build(deps): Bump github.com/tink-crypto/tink-go-gcpkms/v2 from 2.2.0 to 2.4.0 (#2939)
  • ee19b41b56d15ac955e2a6fa5d059270d69bd8e6 remove repetitive viper lookups from api endpoints (#2922)
  • f3441b54a6969017e2a4cb111eecca9bf35385a2 move CI containers to GHCR (#2943)
  • d53aa51f4c3960d3b448cac308dc4e416e15671a build(deps): Bump the all group across 1 directory with 3 updates (#2942)
  • 7af1d7c47fb9e893a3295b4a72553d2e9918dda3 build(deps): Bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#2938)
  • ed250aa4865cf653e537fd84d8acc828a3889159 build(deps): Bump cloud.google.com/go/iam from 1.11.0 to 1.13.0 (#2937)
  • 78ba595f16b0bfda5f1e5d7c76c93c260c4d9eef build(deps): Bump gocloud.dev from 0.45.0 to 0.46.0 (#2940)
  • 6a6443e5230980a25a887a861f5c455eac46bf35 build(deps): Bump the all group with 4 updates (#2941)
  • a64a34535a43229d9b18d001f072a64b53a21004 build(deps): Bump google.com/cloudsdktool/google-cloud-cli (#2935)
  • f6fa665db64145e254fb8b6ea2605074e96f946e build(deps): Bump golang from 1.26.5 to 1.26.6 in the all group (#2934)
  • 2309dab576448029c276730735ccb76e5de52036 fix pprof arg (#2932)
  • 5a1909af34d1f25c569d127b9b05530b54f02a05 build(deps): Bump the all group across 1 directory with 6 updates (#2925)
  • d9790726d5be07f40c3e1aa01f7f842b43976a6c build(deps): Bump golang from 3aff665 to 2005724 (#2924)
  • e1564dc41944a9653b79bf98e00b4ddd46919d45 build(deps): Bump github.com/prometheus/client_golang (#2928)
  • a497c02c0a0db1817cdb5d865f84576cca3723b6 build(deps): Bump the all group with 4 updates (#2930)
  • aea3064bdb4fcaa3ec06ee1c66e885fe5dc9073d build(deps): Bump github.com/go-sql-driver/mysql from 1.9.3 to 1.10.0 (#2926)
  • 5486ddaa6db154049646f2cbf4d327145d85eee3 build(deps): Bump go.step.sm/crypto from 0.85.0 to 0.87.0 (#2927)
  • ebd7339c38c08f3ea865f63bc611b84d6d72f1df build(deps): Bump github.com/redis/go-redis/v9 from 9.20.1 to 9.22.0 (#2929)
  • d543a4a664465d8b99507fcd720af86539d5b817 build(deps): Bump google.com/cloudsdktool/google-cloud-cli (#2923)
  • eaa6d5b3d22096c9bfd7458ca66032df4354aee7 build(deps): upgrade grpc-ecosystem/go-grpc-middleware to v2 (#2921)
  • 1665651737fdea7d588a8bd71a2e5577abd2a928 build(deps): Migrate gopkg.in/yaml.v2 to sigs.k8s.io/yaml (#2919)
  • 24394e3bb6cceed5f17fa93972aba21b3e26d0f7 remove unused semver type version map (#2918)
  • 3a9dba1565ad62d20004b6edd62c2997b8c71f5e build(deps): Bump github.com/in-toto/in-toto-golang from 0.9.0 to 0.11.0 (#2823)
  • c4d4150e7fbdd45536cb79b32ced752a0c4a59c8 separate read/write sql traffic for indexservice into separate pools (#2914)
  • 99f7844c567c7f37440882414c30970242f9ecf2 test against valkey (#2916)
  • aef6385ce5132a39b8f9dfe0210e5f2599fef5e9 Change default CLI upload type to hashedrekord (#2885)
  • 1be154f685d656971fe80369cbb4e84ff3233886 fix shadowed err, wrong err label (#2907)
  • 2cdf437463fbfdd0e638c7965b5ca2dcf315f4c5 build(deps): Bump github.com/go-openapi/swag/conv from 0.27.3 to 0.28.0 (#2910)
  • e7730e022c63ac15673d9138059127bb1ff20c23 build(deps): Bump golang.org/x/mod from 0.37.0 to 0.38.0 (#2911)
  • df58502b6ba2e74d9687638ee8094ffd3a908a9d build(deps): Bump google.com/cloudsdktool/google-cloud-cli (#2909)
  • 730fa3757b2bb19efa4967c079a12dd1d2fc1581 build(deps): Bump github.com/go-chi/chi/v5 from 5.2.5 to 5.3.1 (#2912)
  • ace88208974be7481e44f6e849133a3b74e6e4d4 build(deps): Bump the all group with 4 updates (#2913)
  • dfe5a1c485c83b265696c1c9ea4399924d9af154 alpine: hash only the bytes read when computing the control.tar.gz digest (#2908)
  • a8f4a17c5628e2ccca90688086aef6ed87cbb38a Remove unmaintained scripts/createdb.sh dev helper (#2905)
  • 9573f1b131eb20b000f4752233ca63538429c600 test mysql with production dsn strings (#2906)
  • f3299aac1ff4e1c7278bbbde80cde66f279203bc build(deps): Bump golang.org/x/crypto in /hack/tools (#2882)
  • cc5737ee991c30c4b300f464f00a74beb4e18acb build(deps): Bump the all group across 1 directory with 6 updates (#2898)
  • 8485b5d69e1976880d0e6d05765e4489888228d4 build(deps): Bump cloud.google.com/go/pubsub from 1.50.2 to 1.51.0 (#2899)
  • 3d80df7ee97108beb93477477ff0a2411528db79 build(deps): Bump google.com/cloudsdktool/google-cloud-cli (#2897)
  • 09bf9caea7ee3874ac651f3b11375fd8c181b748 create interface for TrillianClient (#2896)
  • 671e78b6fc294999761fbd155e56ae54d1d23b93 build(deps): Bump the all group with 5 updates (#2900)
  • a00d60ef97b6016afe498c430bbd35a62f9b7fab build(deps): Bump go.step.sm/crypto from 0.77.7 to 0.85.0 (#2901)
  • ea4ed74526ad20b1a05e89fa387d03c123beafe1 build(deps): Bump actions/setup-go from 6.5.0 to 7.0.0 (#2902)
  • bde4e86e1e85cfb7ee4d48a7f98c9533051bac22 use more efficient table schema for indexes (#2903)

... (truncated)

Changelog

Sourced from github.com/sigstore/rekor's changelog.

v1.5.4

Features

  • search: add subject field for SAN-based lookup (#2850)
  • Change default CLI upload type to hashedrekord (#2885)
  • separate read/write sql traffic for indexservice into separate pools (#2914)

Bug Fixes

  • better handle connection issues (#2931)
  • fix pprof arg (#2932)
  • fix shadowed err, wrong err label (#2907)
  • alpine: hash only the bytes read when computing the control.tar.gz digest (#2908)
  • return a 400 error for invalid TreeID (#2895)
  • Return the file error instead of the URL error for a missing artifact path (#2872)
  • Apply proactive hardening against malformed requests (#2945)

Improvements

  • remove repetitive viper lookups from api endpoints (#2922)
  • move CI containers to GHCR (#2943)
  • remove unused semver type version map (#2918)
  • test against valkey (#2916)
  • Remove unmaintained scripts/createdb.sh dev helper (#2905)
  • test mysql with production dsn strings (#2906)
  • create interface for TrillianClient (#2896)
  • use more efficient table schema for indexes (#2903)
  • Migrate off deprecated golang.org/x/crypto/openpgp (#2883)
  • minimize duplicative JSON parsing while handling entries (#2880)
  • remove duplicative log entry (#2881)
  • optimize DSSE memory and cpu while parsing and verifying envs (#2879)
  • update builder to use go1.26.4 (#2873)
  • upgrade grpc-ecosystem/go-grpc-middleware to v2 (#2921)
  • Migrate gopkg.in/yaml.v2 to sigs.k8s.io/yaml (#2919)
  • numerous upgraded dependencies

Documentation

  • docs(cli): add usage examples to rekor-cli commands (#2851)

Contributors

  • ahmagdyfb
  • Bob Callaway
  • Carlos Tadeu Panato Junior
  • Chiman Jain
  • Hayden
  • Jason Hall
  • Nikhil J

... (truncated)

Commits
  • a36bd71 add changelog for v1.5.4 release (#2944)
  • 705fc05 Apply proactive hardening against malformed requests (GHSA-843x-px86-vq42) (#...
  • 5789c38 build(deps): Bump github.com/go-swagger/go-swagger from 0.33.2 to 0.36.4 in /...
  • 7dd85d3 better handle connection issues (#2931)
  • a8544a8 build(deps): Bump github.com/tink-crypto/tink-go-gcpkms/v2 from 2.2.0 to 2.4....
  • ee19b41 remove repetitive viper lookups from api endpoints (#2922)
  • f3441b5 move CI containers to GHCR (#2943)
  • d53aa51 build(deps): Bump the all group across 1 directory with 3 updates (#2942)
  • 7af1d7c build(deps): Bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#2938)
  • ed250aa build(deps): Bump cloud.google.com/go/iam from 1.11.0 to 1.13.0 (#2937)
  • Additional commits viewable in compare view

Updates github.com/stretchr/testify from 1.11.1 to 1.12.0

Release notes

Sourced from github.com/stretchr/testify's releases.

v1.12.0

What's Changed

Functional Changes

Fixes

Documentation, Build & CI

New Contributors

... (truncated)

Commits
  • 001eb79 Merge pull request #1905 from Kentzo/patch-1
  • ad40f38 Merge pull request #1906 from stretchr/dependabot/github_actions/actions/chec...
  • 3bae017 build(deps): bump actions/checkout from 6.0.2 to 6.0.3
  • f8c01f3 mock: Mock.Return does not exist anymore
  • 12f8b56 Merge pull request #1563 from stretchr/make-AssertionFunc-types-aliases
  • a11649e assert: make *AssertionFunc type just aliases
  • dc20f41 Merge pull request #1890 from stretchr/dolmen/codegen-modernize
  • 098f8d7 _codegen: use strings.Builder
  • d2699be _codegen: modernize
  • a463c8c Merge pull request #1885 from stretchr/dolmen/ci-check-ghactions-hashes
  • Additional commits viewable in compare view

Updates golang.org/x/crypto from 0.54.0 to 0.55.0

Commits
  • f44d03d go.mod: update golang.org/x dependencies
  • 5ed4944 crypto/internal/poly1305: provide optimised assembly for riscv64
  • b07833c ssh: return window credit for discarded extended data
  • d701c51 acme: fix nil pointer dereference in pebble test error reporting
  • 999d053 ssh: fix parsing of GSSAPI payloads offering multiple mechanisms
  • 90f76b8 ssh: reject certificate signature keys before recursing
  • b53964a ssh: permit empty but non-nil HostKeyAlgorithms, KeyExchanges, Ciphers, MACs
  • 626e40f ssh: drain stderr on forwarded TCP and Unix channels
  • 31914c6 x509roots/fallback: update bundle
  • f2135b8 all: clean up minor issues found by staticcheck
  • Additional commits viewable in compare view

Updates k8s.io/api from 0.36.3 to 0.36.4

Commits

Updates k8s.io/apimachinery from 0.36.3 to 0.36.4

Commits

Updates k8s.io/client-go from 0.36.3 to 0.36.4

Commits

Updates k8s.io/code-generator from 0.36.3 to 0.36.4

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all group with 8 updates:

| Package | From | To |
| --- | --- | --- |
| [github.com/secure-systems-lab/go-securesystemslib](https://github.com/secure-systems-lab/go-securesystemslib) | `0.11.0` | `0.11.1` |
| [github.com/sigstore/rekor](https://github.com/sigstore/rekor) | `1.5.3` | `1.5.4` |
| [github.com/stretchr/testify](https://github.com/stretchr/testify) | `1.11.1` | `1.12.0` |
| [golang.org/x/crypto](https://github.com/golang/crypto) | `0.54.0` | `0.55.0` |
| [k8s.io/api](https://github.com/kubernetes/api) | `0.36.3` | `0.36.4` |
| [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) | `0.36.3` | `0.36.4` |
| [k8s.io/client-go](https://github.com/kubernetes/client-go) | `0.36.3` | `0.36.4` |
| [k8s.io/code-generator](https://github.com/kubernetes/code-generator) | `0.36.3` | `0.36.4` |


Updates `github.com/secure-systems-lab/go-securesystemslib` from 0.11.0 to 0.11.1
- [Release notes](https://github.com/secure-systems-lab/go-securesystemslib/releases)
- [Commits](secure-systems-lab/go-securesystemslib@v0.11.0...v0.11.1)

Updates `github.com/sigstore/rekor` from 1.5.3 to 1.5.4
- [Release notes](https://github.com/sigstore/rekor/releases)
- [Changelog](https://github.com/sigstore/rekor/blob/main/CHANGELOG.md)
- [Commits](sigstore/rekor@v1.5.3...v1.5.4)

Updates `github.com/stretchr/testify` from 1.11.1 to 1.12.0
- [Release notes](https://github.com/stretchr/testify/releases)
- [Commits](stretchr/testify@v1.11.1...v1.12.0)

Updates `golang.org/x/crypto` from 0.54.0 to 0.55.0
- [Commits](golang/crypto@v0.54.0...v0.55.0)

Updates `k8s.io/api` from 0.36.3 to 0.36.4
- [Commits](kubernetes/api@v0.36.3...v0.36.4)

Updates `k8s.io/apimachinery` from 0.36.3 to 0.36.4
- [Commits](kubernetes/apimachinery@v0.36.3...v0.36.4)

Updates `k8s.io/client-go` from 0.36.3 to 0.36.4
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](kubernetes/client-go@v0.36.3...v0.36.4)

Updates `k8s.io/code-generator` from 0.36.3 to 0.36.4
- [Commits](kubernetes/code-generator@v0.36.3...v0.36.4)

---
updated-dependencies:
- dependency-name: github.com/secure-systems-lab/go-securesystemslib
  dependency-version: 0.11.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github.com/sigstore/rekor
  dependency-version: 1.5.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github.com/stretchr/testify
  dependency-version: 1.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: golang.org/x/crypto
  dependency-version: 0.55.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: k8s.io/api
  dependency-version: 0.36.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.36.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: k8s.io/client-go
  dependency-version: 0.36.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: k8s.io/code-generator
  dependency-version: 0.36.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. labels Aug 24, 2026
@tekton-robot tekton-robot added the size/L Denotes a PR that changes 100-499 lines, ignoring generated files. label Aug 24, 2026

@infernus01 infernus01 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@tekton-robot tekton-robot added the lgtm Indicates that a PR is ready to be merged. label Aug 25, 2026
@tekton-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: infernus01

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@tekton-robot tekton-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 25, 2026
@tekton-robot
tekton-robot merged commit d4dd349 into release-v0.29.x Aug 25, 2026
18 checks passed
@dependabot
dependabot Bot deleted the dependabot/go_modules/release-v0.29.x/all-c62e75ecdb branch August 25, 2026 08:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. lgtm Indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants