Skip to content

Bump grafana/xk6/.github/workflows/extension-validate.yml from 1.3.0 to 1.3.5#31

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/grafana/xk6/dot-github/workflows/extension-validate.yml-1.3.5
Open

Bump grafana/xk6/.github/workflows/extension-validate.yml from 1.3.0 to 1.3.5#31
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/grafana/xk6/dot-github/workflows/extension-validate.yml-1.3.5

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Feb 23, 2026

Bumps grafana/xk6/.github/workflows/extension-validate.yml from 1.3.0 to 1.3.5.

Release notes

Sourced from grafana/xk6/.github/workflows/extension-validate.yml's releases.

v1.3.5

Grafana xk6 v1.3.5 is here! 🎉

This release introduces subcommand extension support for greater extensibility and includes a critical security update that addresses multiple CVEs by updating to Go 1.25.7.

New Features

  • Add support for subcommand extensions (#417) - Implements native support for k6 subcommand extensions in xk6, enabling developers to build and run subcommand extensions more efficiently.

Security

Bug Fixes

  • Fix missing .exe extension when cross-compiling to Windows from other platforms (#429, fixes #427)

Docker

  • Update Go version to 1.25.7-alpine3.23 in Dockerfiles (#431)

Dependencies

  • Update github.com/lmittmann/tint to v1.1.3 (#422)

Maintenance

  • Update GitHub Actions workflows:
    • Update bats-core/bats-action action to v4 (#426)
    • Update actions/checkout digest (#421)
  • Update gosec to v2.23.0 (#425)

v1.3.4

Grafana xk6 v1.3.4 is here! 🎉

This is a patch release that addresses a critical security vulnerability.

Security

... (truncated)

Commits
  • 15b66b6 Update Go to 1.25.7 to fix security vulnerabilities (#431)
  • 8da6c57 Fix: append .exe extension to default output filename on Windows (#429)
  • 001ca29 chore(deps): update bats-core/bats-action action to v4 (#426)
  • 9e8f6b6 chore(deps): update dependency securego/gosec to v2.23.0 (#425)
  • e1bd4d9 fix(deps): update module github.com/go-git/go-git/v5 to v5.16.5 [security] (#...
  • e78fef8 build(deps): bump github.com/go-git/go-git/v5 from 5.16.4 to 5.16.5 in the go...
  • 700329f fix(deps): update module github.com/lmittmann/tint to v1.1.3 (#422)
  • b29b2a5 chore(deps): update actions/checkout digest to de0fac2 (#421)
  • 386567b Add support for subcommand extensions (#417)
  • 6bf2772 ci: update go to 1.25.6 in release pipeline (#420)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [grafana/xk6/.github/workflows/extension-validate.yml](https://github.com/grafana/xk6) from 1.3.0 to 1.3.5.
- [Release notes](https://github.com/grafana/xk6/releases)
- [Commits](grafana/xk6@1dbaf89...15b66b6)

---
updated-dependencies:
- dependency-name: grafana/xk6/.github/workflows/extension-validate.yml
  dependency-version: 1.3.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Feb 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants