Bump the go-dependencies group across 1 directory with 22 updates#752
Bump the go-dependencies group across 1 directory with 22 updates#752dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
|
Claude finished @dependabot[bot]'s task in 2m 53s —— View job Dependency Update Review
SummaryThis PR bumps 22 Go dependencies (16 direct, 6 indirect). The changes are net-negative on lines (179 added / 856 deleted in Dependency-by-Dependency AnalysisLow Risk (routine patch/minor updates)
Medium Risk — Worth Verifying
Higher Risk — Needs Attention
Action Items
Overall AssessmentApprove with testing. The dependency updates are well-scoped and include important security fixes (go-jira JWT CVE, go-git bugfix). The main risk is the |
Bumps the go-dependencies group with 16 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github.com/Azure/azure-sdk-for-go/sdk/azcore](https://github.com/Azure/azure-sdk-for-go) | `1.18.0` | `1.21.0` | | [github.com/Azure/azure-sdk-for-go/sdk/containers/azcontainerregistry](https://github.com/Azure/azure-sdk-for-go) | `0.2.2` | `0.2.3` | | [github.com/andygrunwald/go-jira](https://github.com/andygrunwald/go-jira) | `1.16.0` | `1.17.0` | | [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.36.3` | `1.41.5` | | [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.29.14` | `1.32.13` | | [github.com/aws/aws-sdk-go-v2/feature/s3/manager](https://github.com/aws/aws-sdk-go-v2) | `1.17.72` | `1.22.10` | | [github.com/aws/aws-sdk-go-v2/service/ecs](https://github.com/aws/aws-sdk-go-v2) | `1.54.6` | `1.75.0` | | [github.com/aws/aws-sdk-go-v2/service/lambda](https://github.com/aws/aws-sdk-go-v2) | `1.71.2` | `1.88.5` | | [github.com/containers/image/v5](https://github.com/containers/image) | `5.34.3` | `5.36.2` | | [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) | `5.17.1` | `5.17.2` | | [github.com/go-playground/validator/v10](https://github.com/go-playground/validator) | `10.26.0` | `10.30.2` | | [github.com/open-policy-agent/opa](https://github.com/open-policy-agent/opa) | `1.13.2` | `1.15.1` | | [github.com/zalando/go-keyring](https://github.com/zalando/go-keyring) | `0.2.6` | `0.2.8` | | [golang.org/x/oauth2](https://github.com/golang/oauth2) | `0.34.0` | `0.36.0` | | [k8s.io/kubernetes](https://github.com/kubernetes/kubernetes) | `1.35.0` | `1.35.3` | | [sigs.k8s.io/kind](https://github.com/kubernetes-sigs/kind) | `0.11.1` | `0.31.0` | Updates `github.com/Azure/azure-sdk-for-go/sdk/azcore` from 1.18.0 to 1.21.0 - [Release notes](https://github.com/Azure/azure-sdk-for-go/releases) - [Commits](Azure/azure-sdk-for-go@sdk/azcore/v1.18.0...sdk/azcore/v1.21.0) Updates `github.com/Azure/azure-sdk-for-go/sdk/azidentity` from 1.9.0 to 1.10.1 - [Release notes](https://github.com/Azure/azure-sdk-for-go/releases) - [Commits](Azure/azure-sdk-for-go@sdk/azcore/v1.9.0...sdk/azidentity/v1.10.1) Updates `github.com/Azure/azure-sdk-for-go/sdk/containers/azcontainerregistry` from 0.2.2 to 0.2.3 - [Release notes](https://github.com/Azure/azure-sdk-for-go/releases) - [Commits](Azure/azure-sdk-for-go@sdk/internal/v0.2.2...sdk/internal/v0.2.3) Updates `github.com/andygrunwald/go-jira` from 1.16.0 to 1.17.0 - [Release notes](https://github.com/andygrunwald/go-jira/releases) - [Changelog](https://github.com/andygrunwald/go-jira/blob/main/CHANGELOG.md) - [Commits](andygrunwald/go-jira@v1.16.0...v1.17.0) Updates `github.com/aws/aws-sdk-go-v2` from 1.36.3 to 1.41.5 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@v1.36.3...v1.41.5) Updates `github.com/aws/aws-sdk-go-v2/config` from 1.29.14 to 1.32.13 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@config/v1.29.14...config/v1.32.13) Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.17.67 to 1.19.13 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@credentials/v1.17.67...credentials/v1.19.13) Updates `github.com/aws/aws-sdk-go-v2/feature/s3/manager` from 1.17.72 to 1.22.10 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@feature/s3/manager/v1.17.72...service/mq/v1.22.10) Updates `github.com/aws/aws-sdk-go-v2/service/ecs` from 1.54.6 to 1.75.0 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/ecs/v1.54.6...service/s3/v1.75.0) Updates `github.com/aws/aws-sdk-go-v2/service/lambda` from 1.71.2 to 1.88.5 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/rds/v1.71.2...service/s3/v1.88.5) Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.79.2 to 1.97.3 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/s3/v1.79.2...service/s3/v1.97.3) Updates `github.com/aws/smithy-go` from 1.22.3 to 1.24.2 - [Release notes](https://github.com/aws/smithy-go/releases) - [Changelog](https://github.com/aws/smithy-go/blob/main/CHANGELOG.md) - [Commits](aws/smithy-go@v1.22.3...v1.24.2) Updates `github.com/containers/image/v5` from 5.34.3 to 5.36.2 - [Release notes](https://github.com/containers/image/releases) - [Commits](containers/image@v5.34.3...v5.36.2) Updates `github.com/docker/docker` from 28.0.4+incompatible to 28.3.2+incompatible - [Release notes](https://github.com/docker/docker/releases) - [Commits](moby/moby@v28.0.4...v28.3.2) Updates `github.com/go-git/go-git/v5` from 5.17.1 to 5.17.2 - [Release notes](https://github.com/go-git/go-git/releases) - [Commits](go-git/go-git@v5.17.1...v5.17.2) Updates `github.com/go-playground/validator/v10` from 10.26.0 to 10.30.2 - [Release notes](https://github.com/go-playground/validator/releases) - [Commits](go-playground/validator@v10.26.0...v10.30.2) Updates `github.com/hashicorp/go-retryablehttp` from 0.7.7 to 0.7.8 - [Changelog](https://github.com/hashicorp/go-retryablehttp/blob/main/CHANGELOG.md) - [Commits](hashicorp/go-retryablehttp@v0.7.7...v0.7.8) Updates `github.com/open-policy-agent/opa` from 1.13.2 to 1.15.1 - [Release notes](https://github.com/open-policy-agent/opa/releases) - [Changelog](https://github.com/open-policy-agent/opa/blob/main/CHANGELOG.md) - [Commits](open-policy-agent/opa@v1.13.2...v1.15.1) Updates `github.com/zalando/go-keyring` from 0.2.6 to 0.2.8 - [Release notes](https://github.com/zalando/go-keyring/releases) - [Commits](zalando/go-keyring@v0.2.6...v0.2.8) Updates `golang.org/x/oauth2` from 0.34.0 to 0.36.0 - [Commits](golang/oauth2@v0.34.0...v0.36.0) Updates `k8s.io/kubernetes` from 1.35.0 to 1.35.3 - [Release notes](https://github.com/kubernetes/kubernetes/releases) - [Commits](kubernetes/kubernetes@v1.35.0...v1.35.3) Updates `sigs.k8s.io/kind` from 0.11.1 to 0.31.0 - [Release notes](https://github.com/kubernetes-sigs/kind/releases) - [Commits](kubernetes-sigs/kind@v0.11.1...v0.31.0) --- updated-dependencies: - dependency-name: github.com/Azure/azure-sdk-for-go/sdk/azcore dependency-version: 1.21.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/Azure/azure-sdk-for-go/sdk/azidentity dependency-version: 1.10.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/Azure/azure-sdk-for-go/sdk/containers/azcontainerregistry dependency-version: 0.2.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: github.com/andygrunwald/go-jira dependency-version: 1.17.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/aws/aws-sdk-go-v2 dependency-version: 1.41.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/aws/aws-sdk-go-v2/config dependency-version: 1.32.13 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/aws/aws-sdk-go-v2/credentials dependency-version: 1.19.13 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/aws/aws-sdk-go-v2/feature/s3/manager dependency-version: 1.22.10 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/aws/aws-sdk-go-v2/service/ecs dependency-version: 1.75.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/aws/aws-sdk-go-v2/service/lambda dependency-version: 1.88.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/aws/aws-sdk-go-v2/service/s3 dependency-version: 1.97.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/aws/smithy-go dependency-version: 1.24.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/containers/image/v5 dependency-version: 5.36.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/docker/docker dependency-version: 28.3.2+incompatible dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/go-git/go-git/v5 dependency-version: 5.17.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: github.com/go-playground/validator/v10 dependency-version: 10.30.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/hashicorp/go-retryablehttp dependency-version: 0.7.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: github.com/open-policy-agent/opa dependency-version: 1.15.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/zalando/go-keyring dependency-version: 0.2.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: golang.org/x/oauth2 dependency-version: 0.36.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: k8s.io/kubernetes dependency-version: 1.35.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: sigs.k8s.io/kind dependency-version: 0.31.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
e726ba5 to
17b88b7
Compare
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the go-dependencies group with 16 updates in the / directory:
1.18.01.21.00.2.20.2.31.16.01.17.01.36.31.41.51.29.141.32.131.17.721.22.101.54.61.75.01.71.21.88.55.34.35.36.25.17.15.17.210.26.010.30.21.13.21.15.10.2.60.2.80.34.00.36.01.35.01.35.30.11.10.31.0Updates
github.com/Azure/azure-sdk-for-go/sdk/azcorefrom 1.18.0 to 1.21.0Release notes
Sourced from github.com/Azure/azure-sdk-for-go/sdk/azcore's releases.
Commits
f6309d4Prep azcore@v1.21.0 for release (#25864)d0a9819Update SDK generation as completed when SDK pull request is linked to release...aba8672Configurations: 'specification/resourceconnector/resource-manager/Microsoft....481e4abAdd some missing methods to the types in datetime (#25826)35d6071Skip unsafeptr check for storage SDKs (#25856)5d68f66add code (#25837)944cd8dadd code (#25836)1191825[Regeneration]sdk/resourcemanager/quota/armquota (#25835)e1a9bfdadd code (#25838)1de7ac7[Automation] Regenerate SDK based on typespec-go branch main (#25729)Updates
github.com/Azure/azure-sdk-for-go/sdk/azidentityfrom 1.9.0 to 1.10.1Commits
a98a0dbPrepare azidentity v1.10.1 for release (#24746)8aa9f8b[Release] sdk/resourcemanager/avs/armavs/2.1.0 (#24709)01782abFix typo in azidentity troubleshooting guide (#24748)6ba8640remove reprecated service (#24744)18ff882[keyvault] upgrade to 7.6 (#24733)214f119Add in a simple service bus troubleshooting guide. (#24741)bb804de[Release] sdk/resourcemanager/containerservice/armcontainerservice/7.0.0-beta...542616aSupport 1es canary template validation for unified pipeline (#24731)6d7f1b2[Release] sdk/resourcemanager/mongodbatlas/armmongodbatlas/0.1.0 (#24590)466a17bupgrade dependency (#24736)Updates
github.com/Azure/azure-sdk-for-go/sdk/containers/azcontainerregistryfrom 0.2.2 to 0.2.3Commits
338d220Added mock.WithPredicate ResponseOption (#11959)3ff8aceOmit read-only content from request payloads (#11928)30a759dremove legacy ci.yml file (#11930)165ddcbMinor release v44.2.0 (#11841)c446bd0add ci.yml for azidentity (#11855)9ab3f58Adding azidentity package (#11845)Updates
github.com/andygrunwald/go-jirafrom 1.16.0 to 1.17.0Release notes
Sourced from github.com/andygrunwald/go-jira's releases.
Changelog
Sourced from github.com/andygrunwald/go-jira's changelog.
Commits
93f28ddMerge pull request #735 from andygrunwald/v1.17.0-dev-upgrade-dependencies00778a6Replaceioutil.Discardwithio.Discard44e617eReplaceioutil.ReadFilewithos.ReadFile546b61fReplaceioutil.ReadAllwithio.ReadAll79978f0upgraded static v2022.1 => v2023.1463a8a0go fmt sprint.goe0ea06fgo fmt metaissue.go2095c75go fmt issue.go3d9306eGithub Actions: Upgrade dominikh/staticcheck-action from v1.2 to v1.4ead0c0cGithub Actions: Upgrade actions/setup-go from v3 to v6Updates
github.com/aws/aws-sdk-go-v2from 1.36.3 to 1.41.5Commits
90650ddRelease 2026-03-26dd88818Regenerated Clientsb662c50Update endpoints model500a9cbUpdate API model6221102fix stale skew and delayed skew healing (#3359)0a39373fix order of generated event header handlers (#3361)098f389Only generate resolveAccountID when it's required (#3360)6ebab66Release 2026-03-25b2ec3beRegenerated Clientsabc126fUpdate API modelUpdates
github.com/aws/aws-sdk-go-v2/configfrom 1.29.14 to 1.32.13Commits
90650ddRelease 2026-03-26dd88818Regenerated Clientsb662c50Update endpoints model500a9cbUpdate API model6221102fix stale skew and delayed skew healing (#3359)0a39373fix order of generated event header handlers (#3361)098f389Only generate resolveAccountID when it's required (#3360)6ebab66Release 2026-03-25b2ec3beRegenerated Clientsabc126fUpdate API modelUpdates
github.com/aws/aws-sdk-go-v2/credentialsfrom 1.17.67 to 1.19.13Commits
90650ddRelease 2026-03-26dd88818Regenerated Clientsb662c50Update endpoints model500a9cbUpdate API model6221102fix stale skew and delayed skew healing (#3359)0a39373fix order of generated event header handlers (#3361)098f389Only generate resolveAccountID when it's required (#3360)6ebab66Release 2026-03-25b2ec3beRegenerated Clientsabc126fUpdate API modelUpdates
github.com/aws/aws-sdk-go-v2/feature/s3/managerfrom 1.17.72 to 1.22.10Commits
d872461Release 2024-06-07dd82156Regenerated Clients85ebac0Update endpoints model490e6cbUpdate API model4892b05Merge pull request #2668 from aws/feature-clock-skew8bdbe6aMerge branch 'main' into feature-clock-skewc4f8ba3run goimports2474a05update snapshot tests9fa716bregen clients6d365fbaddress feedback from pr, mostly moving things aroundUpdates
github.com/aws/aws-sdk-go-v2/service/ecsfrom 1.54.6 to 1.75.0Commits
b820c57Release 2025-01-2940ddb76Regenerated Clients2b4adaeUpdate API model78c2be4Revert "beta: feature/s3/transfermanager (S3 transfer manager v2) (#2988)"5c9d67cbeta: feature/s3/transfermanager (S3 transfer manager v2) (#2988)571aa56Release 2025-01-28783ff00Regenerated Clientsfcdc1bbUpdate API modeldf279dbRelease 2025-01-27912497bRegenerated ClientsUpdates
github.com/aws/aws-sdk-go-v2/service/lambdafrom 1.71.2 to 1.88.5Commits
b9b0c65Release 2025-10-16e2bc8a0Regenerated Clients8691ee3Update API model51e8a3fbump to go1.23 (#3211)ad2d36cRelease 2025-10-1519a35d6Regenerated Clients35cb02fUpdate endpoints modelf673a1bUpdate API model48421fdRelease 2025-10-14fedcba7Regenerated ClientsUpdates
github.com/aws/aws-sdk-go-v2/service/s3from 1.79.2 to 1.97.3Commits
90650ddRelease 2026-03-26dd88818Regenerated Clientsb662c50Update endpoints model500a9cbUpdate API model6221102fix stale skew and delayed skew healing (#3359)0a39373fix order of generated event header handlers (#3361)098f389Only generate resolveAccountID when it's required (#3360)6ebab66Release 2026-03-25b2ec3beRegenerated Clientsabc126fUpdate API modelUpdates
github.com/aws/smithy-gofrom 1.22.3 to 1.24.2Release notes
Sourced from github.com/aws/smithy-go's releases.
Commits
b860661Release 2026-02-27567846bBump minimun Go version to 1.24 (#629)8c63558Release 2026-02-20c6d1144Create new event stream generator (#626)f82babdupdate Smithy version to 1.67.0 (#627)708bee3move writable and chainwritable up (#622)7bfe108Add support for OrExpression JMESPath (#620)9dbc5b2bump smithy to v1.64.071f5bffRelease 2025-12-01c94c177changelogUpdates
github.com/containers/image/v5from 5.34.3 to 5.36.2Release notes
Sourced from github.com/containers/image/v5's releases.
... (truncated)
Commits
d464a25Bump to v5.36.250a6b67Merge pull request #2943 from TomSweeneyRedHat/dev/tsweeney/backport_2938d3eb538[release-5.36] rekor: do not cancel http context6ed8326Merge pull request #2920 from TomSweeneyRedHat/dev/tsweeney/v5.36.1f6ca2da[release-5.36] Bump to c/image v5.36.1d18da19[release-5.36] Bump c/storage to v1.59.1ae0c9f3Merge pull request #2913 from TomSweeneyRedHat/dev/tsweeney/cherrypick290740d1027[release-5.36] Update the CI image, to match Skopeo's updated test code08ce6b4Bump to c/image v5.36.0b5e2b66Bump to c/storage v1.59.0Updates
github.com/docker/dockerfrom 28.0.4+incompatible to 28.3.2+incompatibleRelease notes
Sourced from github.com/docker/docker's releases.
... (truncated)
Commits
e77ff99Merge pull request #50354 from vvoland/50353-28.x6e3cf7fMerge pull request #50351 from vvoland/50179-28.x38c0abfupdate to go1.24.53b7d703Merge pull request #50352 from vvoland/50347-28.xd14a60fMerge pull request #50348 from vvoland/50314-28.xda65c86Merge pull request #50350 from vvoland/50333-28.x76fbfe9Merge pull request #50349 from vvoland/50255-28.xbfade89integration/networking: increase context timeout for attacha818cfdgha: run windows 2025 on PRs, 2022 scheduled653777agha: update to windows 2022 / 2025Updates
github.com/go-git/go-git/v5from 5.17.1 to 5.17.2Release notes
Sourced from github.com/go-git/go-git/v5's releases.
Commits
45ae193Merge pull request #1944 from go-git/fix-permsfda4f74storage: filesystem/dotgit, Skip writing pack files that already exist on disk2212dc7Merge pull request #1941 from go-git/renovate/releases/v5.x-go-github.com-go-...ebb2d7dbuild: Update module github.com/go-git/go-git/v5 to v5.17.1 [SECURITY]Updates
github.com/go-playground/validator/v10from 10.26.0 to 10.30.2Release notes
Sourced from github.com/go-playground/validator/v10's releases.
... (truncated)
Commits
b9258bdfix(fqdn): allow hyphens in last domain label (#1548)b9f1d79feat: add postcode patterns for Colombia (CO) and British Virgin Islands (VG)...7fa9599chore(deps): bump golang.org/x/crypto from 0.48.0 to 0.49.0 (#1546)8ca29ecchore(deps): bump golang.org/x/text from 0.34.0 to 0.35.0 (#1545)5e1bedfdocs: add Valuer interface documentation and example (#1540)42927a0feat: implement ValidatorValuer interface feature (#1416<...Description has been truncated