build(deps): bump the all-updates group with 12 updates#7456
Open
dependabot[bot] wants to merge 1 commit intomasterfrom
Open
build(deps): bump the all-updates group with 12 updates#7456dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps the all-updates group with 12 updates: | Package | From | To | | --- | --- | --- | | [github.com/alecthomas/chroma/v2](https://github.com/alecthomas/chroma) | `2.21.1` | `2.23.1` | | [github.com/cloudflare/circl](https://github.com/cloudflare/circl) | `1.6.2` | `1.6.3` | | [github.com/go-chi/chi/v5](https://github.com/go-chi/chi) | `5.2.3` | `5.2.4` | | [github.com/google/cel-go](https://github.com/google/cel-go) | `0.26.1` | `0.27.0` | | [github.com/klauspost/compress](https://github.com/klauspost/compress) | `1.18.2` | `1.18.3` | | [github.com/yuin/goldmark](https://github.com/yuin/goldmark) | `1.7.15` | `1.7.16` | | [go.step.sm/crypto](https://github.com/smallstep/crypto) | `0.75.0` | `0.76.0` | | [golang.org/x/crypto](https://github.com/golang/crypto) | `0.46.0` | `0.47.0` | | [golang.org/x/net](https://github.com/golang/net) | `0.48.0` | `0.49.0` | | [golang.org/x/term](https://github.com/golang/term) | `0.38.0` | `0.39.0` | | [github.com/pires/go-proxyproto](https://github.com/pires/go-proxyproto) | `0.8.1` | `0.9.2` | | [golang.org/x/sys](https://github.com/golang/sys) | `0.39.0` | `0.40.0` | Updates `github.com/alecthomas/chroma/v2` from 2.21.1 to 2.23.1 - [Release notes](https://github.com/alecthomas/chroma/releases) - [Commits](alecthomas/chroma@v2.21.1...v2.23.1) Updates `github.com/cloudflare/circl` from 1.6.2 to 1.6.3 - [Release notes](https://github.com/cloudflare/circl/releases) - [Commits](cloudflare/circl@v1.6.2...v1.6.3) Updates `github.com/go-chi/chi/v5` from 5.2.3 to 5.2.4 - [Release notes](https://github.com/go-chi/chi/releases) - [Changelog](https://github.com/go-chi/chi/blob/master/CHANGELOG.md) - [Commits](go-chi/chi@v5.2.3...v5.2.4) Updates `github.com/google/cel-go` from 0.26.1 to 0.27.0 - [Release notes](https://github.com/google/cel-go/releases) - [Commits](google/cel-go@v0.26.1...v0.27.0) Updates `github.com/klauspost/compress` from 1.18.2 to 1.18.3 - [Release notes](https://github.com/klauspost/compress/releases) - [Commits](klauspost/compress@v1.18.2...v1.18.3) Updates `github.com/yuin/goldmark` from 1.7.15 to 1.7.16 - [Release notes](https://github.com/yuin/goldmark/releases) - [Commits](yuin/goldmark@v1.7.15...v1.7.16) Updates `go.step.sm/crypto` from 0.75.0 to 0.76.0 - [Release notes](https://github.com/smallstep/crypto/releases) - [Commits](smallstep/crypto@v0.75.0...v0.76.0) Updates `golang.org/x/crypto` from 0.46.0 to 0.47.0 - [Commits](golang/crypto@v0.46.0...v0.47.0) Updates `golang.org/x/net` from 0.48.0 to 0.49.0 - [Commits](golang/net@v0.48.0...v0.49.0) Updates `golang.org/x/term` from 0.38.0 to 0.39.0 - [Commits](golang/term@v0.38.0...v0.39.0) Updates `github.com/pires/go-proxyproto` from 0.8.1 to 0.9.2 - [Release notes](https://github.com/pires/go-proxyproto/releases) - [Commits](pires/go-proxyproto@v0.8.1...v0.9.2) Updates `golang.org/x/sys` from 0.39.0 to 0.40.0 - [Commits](golang/sys@v0.39.0...v0.40.0) --- updated-dependencies: - dependency-name: github.com/alecthomas/chroma/v2 dependency-version: 2.23.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-updates - dependency-name: github.com/cloudflare/circl dependency-version: 1.6.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-updates - dependency-name: github.com/go-chi/chi/v5 dependency-version: 5.2.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-updates - dependency-name: github.com/google/cel-go dependency-version: 0.27.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-updates - dependency-name: github.com/klauspost/compress dependency-version: 1.18.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-updates - dependency-name: github.com/yuin/goldmark dependency-version: 1.7.16 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-updates - dependency-name: go.step.sm/crypto dependency-version: 0.76.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-updates - dependency-name: golang.org/x/crypto dependency-version: 0.47.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-updates - dependency-name: golang.org/x/net dependency-version: 0.49.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-updates - dependency-name: golang.org/x/term dependency-version: 0.39.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-updates - dependency-name: github.com/pires/go-proxyproto dependency-version: 0.9.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-updates - dependency-name: golang.org/x/sys dependency-version: 0.40.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-updates ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the all-updates group with 12 updates:
2.21.12.23.11.6.21.6.35.2.35.2.40.26.10.27.01.18.21.18.31.7.151.7.160.75.00.76.00.46.00.47.00.48.00.49.00.38.00.39.00.8.10.9.20.39.00.40.0Updates
github.com/alecthomas/chroma/v2from 2.21.1 to 2.23.1Release notes
Sourced from github.com/alecthomas/chroma/v2's releases.
Commits
5b4188bfix: remove AGPL licensed testdatab9b4edcAdd.env.*pattern to bash lexer (#1197)f163adcdocs: add AGENTS.mdfe6f0f3fix: title link to Chroma610afd8feat: add light/dark mode toggle1b5aad9fix: make just commands faster84583c6fix: wait for WASM runtime to become ready at startup1b6f6e7fix: need relative import for wasm_exec.js2a78195fix: wasm builds got broken by the last changef8a34ecfeat: fix local dev so it falls back to serverUpdates
github.com/cloudflare/circlfrom 1.6.2 to 1.6.3Release notes
Sourced from github.com/cloudflare/circl's releases.
Commits
24ae53cRelease CIRCL v1.6.3581020bRename method to oddMultiplesProjective.12209a4Removing unused cmov for jacobian points.fcba359ecc/p384: use of complete projective formulas for scalar multiplication.5e1bae8ecc/p384: handle point doubling in point addition with Jacobian coordinates.3416046Check opts for nil value.Updates
github.com/go-chi/chi/v5from 5.2.3 to 5.2.4Commits
6eb3588middleware: harden RedirectSlashes handler (#1044)de0d16eUpdate comment about min Go version (#1023)9fb4a15update reverseMethodMap in RegisterMethod (#1022)51c977cRefactor to use atomic type (#1019)563ab11Refactor graceful shutdown example (#994)a52c582Bump minimum Go and use new features (#1017)Updates
github.com/google/cel-gofrom 0.26.1 to 0.27.0Release notes
Sourced from github.com/google/cel-go's releases.
... (truncated)
Commits
450089bPreserve source information during CEL policy composition. (#1253)c66b313Remove types as variables to allow user-defined variables to shadow type decl...bff3a72Expose the CEL JSON types to assist with conversion to native values (#1261)559cbc9Remove errant diff checked into a prior PR (#1260)fe26efaSimplify the disambiguation logic to a single boolean (#1263)52280baClean up unused source info after checker rewrites the AST. (#1258)3cb5705Namespace resolution fix (#1256)409bcbeRefactor match output compiling to accept user-defined logic. (#1246)e9f15eaEnable two var comprehension conformance tests. (#1255)057fa1aAdd parse only evaluation to REPL (#1254)Updates
github.com/klauspost/compressfrom 1.18.2 to 1.18.3Release notes
Sourced from github.com/klauspost/compress's releases.
Commits
1d6cf28Downstream CVE-2025-61728Updates
github.com/yuin/goldmarkfrom 1.7.15 to 1.7.16Commits
246a6f1fix: #542Updates
go.step.sm/cryptofrom 0.75.0 to 0.76.0Commits
be45bd7Merge pull request #939 from smallstep/mariano/cavium-root06d0890Merge pull request #927 from smallstep/mariano/tpmkms-searchkeys3c1bf7aUpdate Marvell (Cavium) HSM root certificate3aec72dMerge pull request #936 from smallstep/dependabot/go_modules/modernc.org/sqli...65f3d89Fix SearchKeys docs and typo3fdb5b8chore(deps): Bump modernc.org/sqlite from 1.44.0 to 1.44.2975c521Merge pull request #938 from smallstep/herman/bump-cavium-test-skip-date79419cbSkip the Cavium root validity test until March 19th, 20268e41a47Merge pull request #934 from smallstep/dependabot/go_modules/github.com/Azure...b1e977dchore(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcoreUpdates
golang.org/x/cryptofrom 0.46.0 to 0.47.0Commits
506e022go.mod: update golang.org/x dependencies7dacc38chacha20poly1305: error out in fips140=only modeUpdates
golang.org/x/netfrom 0.48.0 to 0.49.0Commits
d977772go.mod: update golang.org/x dependencieseea413einternal/http3: use go1.25 synctest.Test instead of go1.24 synctest.Run9ace223websocket: add missing call to resp.Body.Close7d3dbb0http2: buffer the most recently received PRIORITY_UPDATE frameUpdates
golang.org/x/termfrom 0.38.0 to 0.39.0Commits
a7e5b04go.mod: update golang.org/x dependencies943f25dx/term: handle transpose9b991ddx/term: handle delete keyUpdates
github.com/pires/go-proxyprotofrom 0.8.1 to 0.9.2Release notes
Sourced from github.com/pires/go-proxyproto's releases.
Commits
f6b536fhttp2: net/http panics if ConnContext returns nil96b9868http2: avoid empty ALPN on TLS connections9cd9cbdhttp2: respect http.Server.BaseContextaaf9a7ehelper/http2: use http.Server.ConnContext for HTTP/2 if set5b1be82tlvparse: move comments before PP2SSL fieldse5f7f96tlvparse: format azure.gof000eedAdd SSL client certificate TLV1542a61policy: PolicyFunc is deprecated in favor of ConnPolicyFunc6dc9050ci: bump to Go 1.244165843Add TrustProxyHeaderFrom policy functionUpdates
golang.org/x/sysfrom 0.39.0 to 0.40.0Commits
2f44229sys/cpu: add symbolic constants for remaining cpuid bitse5770d2sys/cpu: use symbolic names for masks714a44csys/cpu: modify x86 port to match what internal/cpu doesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions