build(deps): bump the go-deps group across 1 directory with 10 updates #1804
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the go-deps group with 9 updates in the / directory:
3.3.03.3.17.0.917.0.921.2.01.3.01.3.01.3.23.11.03.12.01.8.151.9.40.37.00.38.00.29.00.30.02.5.02.6.0Updates
github.com/Masterminds/semver/v3from 3.3.0 to 3.3.1Release notes
Sourced from github.com/Masterminds/semver/v3's releases.
Changelog
Sourced from github.com/Masterminds/semver/v3's changelog.
Commits
1558ca3Merge pull request #253 from mattfarina/fix-bad-versions252dd61Fix for allowing some version that were invalidUpdates
github.com/minio/minio-go/v7from 7.0.91 to 7.0.92Release notes
Sourced from github.com/minio/minio-go/v7's releases.
Commits
4f25bfcAdd msgpack serializers to stringset (#2107)6651105add support for automatic region extraction for S3 Express (#2104)6b0f80fAdd MakeBucket forceCreate option a MinIO specific extension (#2108)5d96728support aws s3 express zone behavior (#2103)3dbe5a3Add API for bucket resync cancellation (#2101)e994501implement Go native iterator style ListObjects() (#2099)dc867a5feat: make JSON lib configurable (#2088)832e1d3Add copy destination fields (#2095)3e647ddUpdate version to next releaseUpdates
github.com/notaryproject/notation-core-gofrom 1.2.0 to 1.3.0Release notes
Sourced from github.com/notaryproject/notation-core-go's releases.
Commits
ef87896fix: error message ofSignatureAuthenticityError(#269)46726d8build(deps): bump golang.org/x/crypto from 0.36.0 to 0.37.0 (#267)b85e8f7build(deps): bump github.com/fxamacker/cbor/v2 from 2.7.0 to 2.8.0 (#265)4d73532build(deps): bump github.com/golang-jwt/jwt/v4 from 4.5.1 to 4.5.2 (#263)6a378d5build(deps): bump golang.org/x/crypto from 0.35.0 to 0.36.0 (#262)ea37e4efix: use iterator instead of looping through multiple slices (#259)fcf4512build(deps): bump apache/skywalking-eyes from 0.6.0 to 0.7.0 (#258)9c4662fbuild(deps): bump golang.org/x/crypto from 0.32.0 to 0.35.0 (#261)441bbe8bump: update go v1.23 (#260)7510083feat: delta CRL (#247)Updates
github.com/notaryproject/notation-gofrom 1.3.0 to 1.3.2Release notes
Sourced from github.com/notaryproject/notation-go's releases.
Commits
34a1ababump: release v1.3.2c447774backport: from main to release-1.3 branch (#536)727046dMerge pull request #517 from Two-Hearts/release-1.3961cef1bump: release v1.3.1f171fb0bump: bump up dependencies for release-1.3 branch (#516)540cc34fix: remove signing time check during authenticTimestamp (#514)1864576Merge pull request #507 from Two-Hearts/release-1.3Updates
github.com/ory/dockertest/v3from 3.11.0 to 3.12.0Release notes
Sourced from github.com/ory/dockertest/v3's releases.
Commits
8a76ff0chore: update repository templates to ory/meta@bc60...207b20achore: update repository templates to ory/meta@83e7...fabf563autogen: update license overview4b1e539chore: update repository templates to ory/meta@44ef...46d1a7bchore: update repository templates to ory/meta@c091...13e6e33chore(deps): bump actions/stale from 4 to 9 (#554)91b7d0bchore(deps): bump actions/setup-node from 2.pre.beta to 4.1.0 (#539)28c8c5bchore(deps): bump github.com/containerd/continuity from 0.4.3 to 0.4.5 (#545)eec3a4ffeat: add support for BuildKit when building images (#416)f6e65bachore(deps): bump github.com/stretchr/testify from 1.9.0 to 1.10.0 (#547)Updates
github.com/sigstore/sigstorefrom 1.8.15 to 1.9.4Release notes
Sourced from github.com/sigstore/sigstore's releases.
Commits
0c2ec3aUpdate to use Tink v2.3.0 API (#2069)8f79f87Add a Name field to the TargetFile struct (#2068)0923918Update signing algorithm policy (#2066)d49b18cbuild(deps): Bump cloud.google.com/go/kms (#2067)844f42dbuild(deps): Bump golang.org/x/net in /pkg/signature/kms/hashivault (#2064)2f15489build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (#2057)6e3c093build(deps): Bump golang.org/x/oauth2 from 0.28.0 to 0.29.0 (#2052)20f1b38build(deps): Bump github.com/tink-crypto/tink-go/v2 from 2.3.0 to 2.4.0 (#2053)ca90b6dbuild(deps): Bump github.com/coreos/go-oidc/v3 from 3.13.0 to 3.14.1 (#2055)fcf4f5dbuild(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#2059)Updates
golang.org/x/cryptofrom 0.37.0 to 0.38.0Commits
aae6e61go.mod: update golang.org/x dependencies9c1aa6assh/test: reset the random source before capturing a recording8819902ssh/test: enable Diffie-Hellman key exchange algorithms3f311e4acme: return error from pre-authorization when unsupported1f7c62cssh/test: skip unsupported tests on js/wasma5f8048acme/autocert: use standard functions to pick the cache directory958cde8Revert "chacha20: add loong64 SIMD implementation"51f005cRevert "salsa20: add loong64 SIMD implementation"7c35866Revert "argon2: add loong64 SIMD implementation"0091fc8Revert "blake2s: add loong64 SIMD implementation"Updates
golang.org/x/oauth2from 0.29.0 to 0.30.0Commits
cf14319oauth2: fix expiration time window check32d34efinternal: include clientID in auth style cache key2d34e30oauth2: replace a magic number with AuthStyleUnknown696f7b3all: modernize with doc links and any471209boauth2: drop dependency on go-cmp6968da2oauth2: sync Token.ExpiresIn from internal Tokend2c4e0aoauth2: context instead of golang.org/x/net/context in doc883dc3cendpoints: add various endpoints from stale CLs1c06e87all: make use of oauth.Token.ExpiresInUpdates
golang.org/x/syncfrom 0.13.0 to 0.14.0Commits
506c70ferrgroup: propagate panic and Goexit through WaitUpdates
oras.land/oras-go/v2from 2.5.0 to 2.6.0Release notes
Sourced from oras.land/oras-go/v2's releases.
... (truncated)
Commits
05a2b09build(deps): bump golang.org/x/sync from 0.13.0 to 0.14.0 (#955)753f8a8docs: improve README.md (#950)5043a7bdocs: updated broken links (#951)17e7d15docs: add quick start for oras-go (#939)34a87eftest: add unit tests for validateMediaType (#946)f7a6126docs: add more practical examples (#940)0c12035docs: improve docs for OCI store (#941)7963626feat: introduceCopyErrorto identify error source in copy operations (#933)6dd6913build(deps): bump golang.org/x/sync from 0.12.0 to 0.13.0 (#937)d0ac8e4docs: update example tests (#932)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions