Skip to content

gomod(deps): Bump the go-deps group across 2 directories with 28 updates - #2904

Closed
dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/go_modules/staging/go-deps-4b2dcc1505
Closed

dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/go_modules/staging/go-deps-4b2dcc1505

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 11, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the go-deps group with 16 updates in the / directory:

Package From To
github.com/LastPossum/kamino 0.0.3 0.0.5
github.com/anchore/stereoscope 0.1.23 0.3.0
github.com/cli/cli/v2 2.93.0 2.97.0
github.com/compose-spec/compose-go/v2 2.10.2 2.14.0
github.com/containerd/nerdctl/v2 2.3.0 2.3.5
github.com/erikgeiser/promptkit 0.11.0 0.12.0
github.com/getsentry/sentry-go 0.46.2 0.48.0
github.com/henvic/httpretty 0.1.4 0.2.0
github.com/klauspost/cpuid/v2 2.3.0 2.4.0
github.com/kubescape/go-git-url 0.0.31 0.0.32
github.com/mattn/go-shellwords 1.0.13 1.0.14
github.com/moby/buildkit 0.29.0 0.32.2
github.com/onsi/ginkgo/v2 2.28.3 2.32.1
github.com/onsi/gomega 1.40.0 1.42.1
github.com/testcontainers/testcontainers-go 0.41.0 0.44.0
google.golang.org/grpc 1.82.1 1.83.0

Bumps the go-deps group with 2 updates in the /tools/go-generate-qemu-devices directory: kraftkit.sh and mvdan.cc/gofumpt.

Updates github.com/LastPossum/kamino from 0.0.3 to 0.0.5

Release notes

Sourced from github.com/LastPossum/kamino's releases.

Speadup release

Reducs allocs and speedup in special cases

Bugfix release

  • Fix map value not deep-copied under zero key
Commits
  • 8514345 Merge pull request #8 from LastPossum/perf/array-clone-and-robustness
  • b6f738b Speed up array cloning and harden edge cases
  • 8c1423b Merge pull request #7 from LastPossum/fix/map-value-clone-zero-key
  • c1738a6 Fix map value not deep-copied under zero key
  • See full diff in compare view

Updates github.com/anchore/stereoscope from 0.1.23 to 0.3.0

Release notes

Sourced from github.com/anchore/stereoscope's releases.

v0.3.0

Added Features

Bug Fixes

Dependencies

14 dependency changes (14 updated).

  • github.com/containerd/containerd/v2 v2.3.2 → v2.3.3
  • github.com/docker/cli v29.5.3+incompatible → v29.6.1+incompatible
  • github.com/gkampitakis/go-snaps v0.5.22 → v0.5.23
  • github.com/moby/moby/api v1.54.2 → v1.55.0
  • github.com/moby/moby/client v0.4.1 → v0.5.0
  • github.com/pelletier/go-toml/v2 v2.3.1 → v2.4.3
  • golang.org/x/crypto v0.53.0 → v0.54.0
  • golang.org/x/mod v0.37.0 → v0.38.0
  • golang.org/x/net v0.56.0 → v0.57.0
  • golang.org/x/sync v0.21.0 → v0.22.0
  • golang.org/x/sys v0.46.0 → v0.47.0
  • golang.org/x/term v0.44.0 → v0.45.0
  • golang.org/x/text v0.38.0 → v0.40.0
  • golang.org/x/tools v0.46.0 → v0.48.0

(Full Changelog)

v0.2.2

Dependencies

28 dependency changes (26 updated, 2 removed). 6 vulnerabilities remediated.

🟢 Remediated (6)

... (truncated)

Commits
  • e46db95 fix: preserve effective URL after HTTP redirects in registry client (#461)
  • 3d1c7c6 Skip comment and blank lines when parsing known_hosts (#634)
  • 1e33344 chore(deps): bump anchore/workflows/.github/workflows/check-gate.yaml (#640)
  • 119305b Remove references to make bootstrap (#646)
  • c49e20f file: do not treat a bare .wh. as a whiteout marker (#647)
  • e314419 feat: add multi-platform OCI image support (#548)
  • 4afcb22 chore(deps): bump github.com/pelletier/go-toml/v2 from 2.4.2 to 2.4.3 (#651)
  • b2b9dc0 chore(deps): bump golang.org/x/tools from 0.47.0 to 0.48.0 (#650)
  • 68b171c chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.22 to 0.5.23 (#652)
  • 9aa4855 chore(deps): bump github.com/containerd/containerd/v2 (#648)
  • Additional commits viewable in compare view

Updates github.com/cli/cli/v2 from 2.93.0 to 2.97.0

Release notes

Sourced from github.com/cli/cli/v2's releases.

GitHub CLI 2.97.0

Security

Four security vulnerabilities have been identified, and fixed, in this release. Users are advised to update gh to version v2.97.0 as soon as possible.

Several commands (including gh gist view, gh api, gh pr diff, gh release download --output -, gh codespace logs, gh skills preview, and gh agent-task view/create) printed externally controlled content without neutralizing terminal escape sequences, allowing escape sequence injection into a user's terminal.

See GHSA-3m3g-3wcr-px46 for more information.

Some request URLs were built without escaping their variable path components, so a value containing URL path metacharacters could alter the request path and cause gh to address a different resource than intended.

See GHSA-4fjg-2h4q-fwg3 for more information.

gh auth status (without --show-token) could print a portion of the authentication token in plaintext for token types whose format contains an underscore after the prefix, such as github_pat_*, ghs_*, and ghu_*.

See GHSA-cg6r-mpgc-h9mm for more information.

gh attestation verify built the certificate matcher from --signer-repo and --signer-workflow without escaping regex metacharacters, so a lookalike repository or workflow name could satisfy a matcher intended for a trusted signer and bypass attestation verification.

See GHSA-mm27-mwq9-fr5g for more information.

Address project fields and items by name in gh project

gh project item-edit and gh project item-list can now reference project fields and single-select options by name:

# Set an item's field by name
gh project item-edit 1 --owner monalisa --url <url> --field "Status" --value "In Progress"
Show named fields as extra columns
gh project item-list 1 --owner "@​me" --field "Status" --field "Priority"

What's Changed

✨ Features

🐛 Fixes

  • Gracefully handle failed GitHub verifier initialization caused by a missing trusted root by @​malancas in #13624
  • Bump keyring operation timeout from 3s to 60s so interactive unlock prompts have time to complete by @​kofuk in #13787
  • Fix skill picker label wrapping by @​tommaso-moro in #13967

📚 Docs & Chores

... (truncated)

Commits
  • 55dbb4d Merge commit from fork
  • 3f6a16a Merge commit from fork
  • 0c2eea6 Merge commit from fork
  • 2a1409f Merge commit from fork
  • ba0b7d9 Add a code review agent skill (#14003)
  • c6aa327 Merge pull request #14018 from cli/dependabot/github_actions/github/gh-aw-act...
  • 45db9b2 chore(deps): bump github/gh-aw-actions/setup-cli from 0.83.3 to 0.83.4
  • c2ad3b0 Fix skill picker label wrapping (#13967)
  • 11a5ef8 Merge pull request #13985 from cli/williammartin-dependabot-triage-dry-run
  • b1c84bb Merge pull request #14004 from cli/bagtoad/pr-template-anti-slop
  • Additional commits viewable in compare view

Updates github.com/compose-spec/compose-go/v2 from 2.10.2 to 2.14.0

Release notes

Sourced from github.com/compose-spec/compose-go/v2's releases.

v2.14.0

What's Changed

Full Changelog: compose-spec/compose-go@v2.13.0...v2.14.0

v2.13.0

What's Changed

Full Changelog: compose-spec/compose-go@v2.12.1...v2.13.0

v2.12.1

What's Changed

Full Changelog: compose-spec/compose-go@v2.11.0...v2.12.1

v2.11.0

What's Changed

New Contributors

Full Changelog: compose-spec/compose-go@v2.10.2...v2.11.0

Commits
  • d70c053 Memoize include and extends.file loads within a single Load call
  • b3992fc fix(interpolation): sort collected errors by config path
  • 42e84bc fix(interpolation): report all errors in a deterministic order
  • a3e1b4b Add SkipResolveLabels option to skip label_file resolution
  • ace34eb Bump actions/checkout from 7.0.0 to 7.0.1
  • e70e961 Memoize image digest resolution across a WithImagesResolved call
  • 587a6bd Resolve type: image volume sources in WithImagesResolved
  • 9f39d6f Resolve pre_start hook images in WithImagesResolved
  • 5a265f5 Bump actions/stale from 10.3.0 to 10.4.0
  • 23a07bc Bump actions/setup-go from 6.5.0 to 7.0.0
  • Additional commits viewable in compare view

Updates github.com/containerd/containerd/v2 from 2.3.0 to 2.3.3

Release notes

Sourced from github.com/containerd/containerd/v2's releases.

containerd 2.3.3

Welcome to the v2.3.3 release of containerd!

The third patch release for containerd 2.3 contains various fixes and updates.

Highlights

  • Set SystemTemp environment variable on Windows so temp directory overrides work for SYSTEM services (#13694)

Container Runtime Interface (CRI)

  • Fix nil pointer dereference in NRI GetIPs during pod sandbox teardown or container exit (#13697)
  • Reject CreateContainer calls when the target sandbox is not running (#13668)
  • Ensure sandbox shutdown on RunPodSandbox hook failures to avoid mount leaks (#13645)

Image Distribution

  • Surface OCI error bodies in registry 403 responses by falling back to GET requests (#13738)

Snapshotters

  • Align default 4K mkfs block size for EROFS across all platforms (#13632)

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors

  • Maksym Pavlenko
  • Samuel Karp
  • Chris Henzie
  • Phil Estes
  • Sebastiaan van Stijn
  • Akihiro Suda
  • Austin Vazquez
  • Chris Crone
  • Derek McGowan
  • Maksim An
  • crawfordxx
  • cshung
  • lauralorenz

Changes

  • Prepare release notes for v2.3.3 (#13750)
  • CI: migrate Vagrant to Lima (#13744)

... (truncated)

Commits
  • aad1100 Merge pull request #13750 from chrishenzie/prepare-v2.3.3
  • 7f6cee0 Prepare release notes for v2.3.3
  • bc63467 Merge pull request #13744 from AkihiroSuda/cherrypick-13728-2.3
  • 7316210 CI: migrate Vagrant to Lima
  • dc84019 Merge pull request #13738 from k8s-infra-cherrypick-robot/cherry-pick-13547-t...
  • 457fba3 remotes: surface OCI error body on HEAD 403 via GET fallback
  • 5e5581f Merge pull request #13732 from k8s-infra-cherrypick-robot/cherry-pick-13725-t...
  • dc2df93 Update go to 1.26.5
  • e2240ef Merge pull request #13711 from k8s-infra-cherrypick-robot/cherry-pick-13707-t...
  • 5be0495 ci: pin fog-json to resolve gem conflict
  • Additional commits viewable in compare view

Updates github.com/containerd/nerdctl/v2 from 2.3.0 to 2.3.5

Release notes

Sourced from github.com/containerd/nerdctl/v2's releases.

v2.3.5

Changes

  • Cherry-picks from main to release/2.3 containerd/nerdctl#5082
    • nerdctl-full: Update containerd (2.3.3), RootlessKit (3.0.2), BuildKit (0.31.2), runc (1.5.1)

Full changes: https://github.com/containerd/nerdctl/milestone/67?closed=1

Compatible containerd versions

This release of nerdctl is expected to be used with containerd v1.7, v2.0, v2.1, v2.2, or v2.3. Some features may not work with other releases of containerd.

About the binaries

  • Minimal (nerdctl-2.3.5-linux-amd64.tar.gz): nerdctl only
  • Full (nerdctl-full-2.3.5-linux-amd64.tar.gz): Includes dependencies such as containerd, runc, and CNI

Minimal

Extract the archive to a path like /usr/local/bin or ~/bin .

-rwxr-xr-x root/root  31334562 2026-07-20 07:58 nerdctl
-rwxr-xr-x root/root     23381 2026-07-20 07:57 containerd-rootless-setuptool.sh
-rwxr-xr-x root/root      8639 2026-07-20 07:57 containerd-rootless.sh

Full

Extract the archive to a path like /usr/local or ~/.local .

drwxr-xr-x 0/0               0 2026-07-20 08:07 bin/
-rwxr-xr-x 0/0        34352159 2026-07-16 13:59 bin/buildctl
-rwxr-xr-x 0/0        29909144 2025-05-12 13:10 bin/buildg
lrwxrwxrwx 0/0               0 2026-07-20 08:06 bin/buildkit-cni-bandwidth -> ../libexec/cni/bandwidth
lrwxrwxrwx 0/0               0 2026-07-20 08:06 bin/buildkit-cni-bridge -> ../libexec/cni/bridge
lrwxrwxrwx 0/0               0 2026-07-20 08:06 bin/buildkit-cni-dhcp -> ../libexec/cni/dhcp
lrwxrwxrwx 0/0               0 2026-07-20 08:06 bin/buildkit-cni-dummy -> ../libexec/cni/dummy
lrwxrwxrwx 0/0               0 2026-07-20 08:06 bin/buildkit-cni-firewall -> ../libexec/cni/firewall
lrwxrwxrwx 0/0               0 2026-07-20 08:06 bin/buildkit-cni-host-device -> ../libexec/cni/host-device
lrwxrwxrwx 0/0               0 2026-07-20 08:06 bin/buildkit-cni-host-local -> ../libexec/cni/host-local
lrwxrwxrwx 0/0               0 2026-07-20 08:06 bin/buildkit-cni-ipvlan -> ../libexec/cni/ipvlan
lrwxrwxrwx 0/0               0 2026-07-20 08:06 bin/buildkit-cni-loopback -> ../libexec/cni/loopback
lrwxrwxrwx 0/0               0 2026-07-20 08:06 bin/buildkit-cni-macvlan -> ../libexec/cni/macvlan
lrwxrwxrwx 0/0               0 2026-07-20 08:06 bin/buildkit-cni-portmap -> ../libexec/cni/portmap
lrwxrwxrwx 0/0               0 2026-07-20 08:06 bin/buildkit-cni-ptp -> ../libexec/cni/ptp
</tr></table> 

... (truncated)

Commits
  • 347782c Merge pull request #5082 from AkihiroSuda/dev-2.3
  • 8995778 update runc (1.5.1)
  • dc4740d update BuildKit (0.31.2)
  • 93662a8 update RootlessKit (3.0.2)
  • 3032d8e update containerd (2.3.3)
  • f6c523e tigron: hide env from logs by default
  • 0ce88b9 Merge pull request #5010 from mayur-tolexo/fix/network-dual-stack-gateway
  • 9152506 Merge pull request #5019 from immanuwell/fix-inspect-format-errors
  • 97ad253 fix: return inspect format errors
  • c913e9a Merge pull request #5017 from containerd/dependabot/go_modules/docker-a2be455989
  • Additional commits viewable in compare view

Updates github.com/cyphar/filepath-securejoin from 0.6.1 to 0.7.0

Release notes

Sourced from github.com/cyphar/filepath-securejoin's releases.

v0.7.0 -- "You talk of times of peace for all, and then prepare for war."

Changed

  • Update to cyphar.com/go-pathrs@0.2.5, which included a build-time API breakage that we needed to work around. The API of this library is unchanged by this, but users should make sure to update to v0.7.0 of filepath-securejoin if they use the libpathrs built tag and have update to libpathrs v0.2.5.

Signed-off-by: Aleksa Sarai cyphar@cyphar.com

Changelog

Sourced from github.com/cyphar/filepath-securejoin's changelog.

[0.7.0] - 2025-06-17

You talk of times of peace for all, and then prepare for war.

Changed

  • Update to cyphar.com/go-pathrs@0.2.5, which included a build-time API breakage that we needed to work around. The API of this library is unchanged by this, but users should make sure to update to v0.7.0 of filepath-securejoin if they use the libpathrs built tag and have update to libpathrs v0.2.5.
Commits
  • 8096a95 VERSION: release v0.7.0
  • 1324ccb merge #101 into cyphar/filepath-securejoin:main
  • dd8f0bb deps: bump to cyphar.com/go-pathrs@v0.2.5
  • c9a7725 gha: bump golangci-lint to v2.12
  • 2e968bd Merge pull request #91 from cyphar/dependabot/github_actions/actions/download...
  • 2879148 Merge pull request #90 from cyphar/dependabot/github_actions/actions/upload-a...
  • 07b805b build(deps): bump actions/download-artifact from 6 to 7
  • 8507844 build(deps): bump actions/upload-artifact from 5 to 6
  • daef0cf Merge pull request #89 from cyphar/dependabot/github_actions/actions/checkout-6
  • 95f8ea4 build(deps): bump actions/checkout from 5 to 6
  • Additional commits viewable in compare view

Updates github.com/docker/cli from 29.4.3+incompatible to 29.6.1+incompatible

Commits
  • 8900f1d Merge pull request #7074 from thaJeztah/version
  • 22b8f13 Merge pull request #7069 from docker-agent/auto/migrate-to-docker-agent-action
  • d9c59c9 version 29.6.1
  • 6430751 Merge pull request #7073 from thaJeztah/bump_moby_user
  • 8fda97b vendor: github.com/moby/sys/user v0.4.1
  • f9dc4e4 chore: bump docker-agent-action to v2.0.1
  • f8a2d2b Merge pull request #7070 from docker/dependabot/github_actions/actions/checko...
  • 7eb15d3 build(deps): bump actions/checkout from 6.0.3 to 7.0.0
  • 033b0ff Merge pull request #7063 from docker/dependabot/github_actions/crazy-max/dot-...
  • 317bfd1 Merge pull request #7067 from docker/dependabot/github_actions/docker/cagent-...
  • Additional commits viewable in compare view

Updates github.com/erikgeiser/promptkit from 0.11.0 to 0.12.0

Release notes

Sourced from github.com/erikgeiser/promptkit's releases.

v0.12.0

Changelog:

  • New multi selection prompt with optional pre-selection
  • New text area prompt
  • Improved auto-completion for text input that allows browsing suggestions
Commits

Updates github.com/getsentry/sentry-go from 0.46.2 to 0.48.0

Release notes

Sourced from github.com/getsentry/sentry-go's releases.

0.48.0

Breaking Changes 🛠

New Features ✨

  • Add ClientOptions.DataCollection for granular control over data collected by automatic instrumentation, replacing the broad SendDefaultPII switch. DataCollection can independently configure automatic user.* population, cookies, request/response headers, HTTP bodies, and query parameters. When configured, it is the source of truth and SendDefaultPII is ignored. by @​giortzisg in #1339
    • For backwards compatibility, clients that do not configure DataCollection keep a best-effort mapping of the previous SendDefaultPII behavior. To opt in to the new defaults, pass an empty DataCollection and then restrict individual categories as needed.
    sentry.Init(sentry.ClientOptions{
        Dsn: "https://public@example.com/1",
    // Opt in to the new data collection defaults. Omitted fields use their
    // defaults: user info, cookies, headers, query params, and supported HTTP
    // bodies are collected, with sensitive values filtered.
    DataCollection: &amp;sentry.DataCollection{},
    
    })

    • To opt in while disabling automatic user info and HTTP bodies, configure those fields explicitly:
    sentry.Init(sentry.ClientOptions{
        Dsn: "https://public@example.com/1",
        DataCollection: &sentry.DataCollection{
            UserInfo:   sentry.Set(false),
            HTTPBodies: []sentry.BodyType{},
        },
    })
  • PushScope shorthand now returns the new scope reference by @​DoctorJohn in #1335

Bug Fixes 🐛

Internal Changes 🔧

Deps

... (truncated)

Changelog

Sourced from github.com/getsentry/sentry-go's changelog.

0.48.0

Breaking Changes 🛠

New Features ✨

  • Add ClientOptions.DataCollection for granular control over data collected by automatic instrumentation, replacing the broad SendDefaultPII switch. DataCollection can independently configure automatic user.* population, cookies, request/response headers, HTTP bodies, and query parameters. When configured, it is the source of truth and SendDefaultPII is ignored. by @​giortzisg in #1339
    • For backwards compatibility, clients that do not configure DataCollection keep a best-effort mapping of the previous SendDefaultPII behavior. To opt in to the new defaults, pass an empty DataCollection and then restrict individual categories as needed.
    sentry.Init(sentry.ClientOptions{
        Dsn: "https://public@example.com/1",
    // Opt in to the new data collection defaults. Omitted fields use their
    // defaults: user info, cookies, headers, query params, and supported HTTP
    // bodies are collected, with sensitive values filtered.
    DataCollection: &amp;sentry.DataCollection{},
    
    })

    • To opt in while disabling automatic user info and HTTP bodies, configure those fields explicitly:
    sentry.Init(sentry.ClientOptions{
        Dsn: "https://public@example.com/1",
        DataCollection: &sentry.DataCollection{
            UserInfo:   sentry.Set(false),
            HTTPBodies: []sentry.BodyType{},
        },
    })
  • PushScope shorthand now returns the new scope reference by @​DoctorJohn in #1335

Bug Fixes 🐛

Internal Changes 🔧

Deps

... (truncated)

Commits
  • d02f9ba release: 0.48.0
  • 99c424f feat!: remove issue creation from logging integrations (#1340)
  • d1c1d3f feat: parse request body for outgoing http (#1339)
  • 9b5cab2 fix: fix fiber route name when using middlewares (#1363)
  • 07a7975 fix: omit empty event id for standalone client reports (#1362)
  • c255382 build(deps): bump fiber/v2 to 2.52.14 (#1359)
  • 06c58dc ci: remove changelog-preview and codecov actions (#1357)
  • a99e044 fix: preserve '%' literal in log messages (#1358)
  • 8aaf1d4 feat: apply sensitive data filters to grpc & sql (#1333)
  • 4347773 feat: apply sensitive data filters to http (#1332)
  • Additional commits viewable in compare view

Updates github.com/google/go-containerregistry from 0.21.6 to 0.21.7

Release notes

Sourced from github.com/google/go-containerregistry's releases.

v0.21.7

What's Changed

New Contributors

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Aug 11, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Aug 11, 2026
@github-project-automation github-project-automation Bot moved this to 🧊 Icebox in KraftKit Roadmap Aug 11, 2026
@ijaidev ijaidev mentioned this pull request Aug 12, 2026
2 tasks done
Bumps the go-deps group with 16 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/LastPossum/kamino](https://github.com/LastPossum/kamino) | `0.0.3` | `0.0.5` |
| [github.com/anchore/stereoscope](https://github.com/anchore/stereoscope) | `0.1.23` | `0.3.0` |
| [github.com/cli/cli/v2](https://github.com/cli/cli) | `2.93.0` | `2.97.0` |
| [github.com/compose-spec/compose-go/v2](https://github.com/compose-spec/compose-go) | `2.10.2` | `2.14.0` |
| [github.com/containerd/nerdctl/v2](https://github.com/containerd/nerdctl) | `2.3.0` | `2.3.5` |
| [github.com/erikgeiser/promptkit](https://github.com/erikgeiser/promptkit) | `0.11.0` | `0.12.0` |
| [github.com/getsentry/sentry-go](https://github.com/getsentry/sentry-go) | `0.46.2` | `0.48.0` |
| [github.com/henvic/httpretty](https://github.com/henvic/httpretty) | `0.1.4` | `0.2.0` |
| [github.com/klauspost/cpuid/v2](https://github.com/klauspost/cpuid) | `2.3.0` | `2.4.0` |
| [github.com/kubescape/go-git-url](https://github.com/kubescape/go-git-url) | `0.0.31` | `0.0.32` |
| [github.com/mattn/go-shellwords](https://github.com/mattn/go-shellwords) | `1.0.13` | `1.0.14` |
| [github.com/moby/buildkit](https://github.com/moby/buildkit) | `0.29.0` | `0.32.2` |
| [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) | `2.28.3` | `2.32.1` |
| [github.com/onsi/gomega](https://github.com/onsi/gomega) | `1.40.0` | `1.42.1` |
| [github.com/testcontainers/testcontainers-go](https://github.com/testcontainers/testcontainers-go) | `0.41.0` | `0.44.0` |
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.82.1` | `1.83.0` |

Bumps the go-deps group with 2 updates in the /tools/go-generate-qemu-devices directory: [kraftkit.sh](https://github.com/unikraft/kraftkit) and [mvdan.cc/gofumpt](https://github.com/mvdan/gofumpt).


Updates `github.com/LastPossum/kamino` from 0.0.3 to 0.0.5
- [Release notes](https://github.com/LastPossum/kamino/releases)
- [Changelog](https://github.com/LastPossum/kamino/blob/master/CHANGELOG.md)
- [Commits](LastPossum/kamino@v0.0.3...v0.0.5)

Updates `github.com/anchore/stereoscope` from 0.1.23 to 0.3.0
- [Release notes](https://github.com/anchore/stereoscope/releases)
- [Changelog](https://github.com/anchore/stereoscope/blob/main/RELEASE.md)
- [Commits](anchore/stereoscope@v0.1.23...v0.3.0)

Updates `github.com/cli/cli/v2` from 2.93.0 to 2.97.0
- [Release notes](https://github.com/cli/cli/releases)
- [Changelog](https://github.com/cli/cli/blob/trunk/docs/release-process-deep-dive.md)
- [Commits](cli/cli@v2.93.0...v2.97.0)

Updates `github.com/compose-spec/compose-go/v2` from 2.10.2 to 2.14.0
- [Release notes](https://github.com/compose-spec/compose-go/releases)
- [Commits](compose-spec/compose-go@v2.10.2...v2.14.0)

Updates `github.com/containerd/containerd/v2` from 2.3.0 to 2.3.3
- [Release notes](https://github.com/containerd/containerd/releases)
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)
- [Commits](containerd/containerd@v2.3.0...v2.3.3)

Updates `github.com/containerd/nerdctl/v2` from 2.3.0 to 2.3.5
- [Release notes](https://github.com/containerd/nerdctl/releases)
- [Commits](containerd/nerdctl@v2.3.0...v2.3.5)

Updates `github.com/cyphar/filepath-securejoin` from 0.6.1 to 0.7.0
- [Release notes](https://github.com/cyphar/filepath-securejoin/releases)
- [Changelog](https://github.com/cyphar/filepath-securejoin/blob/main/CHANGELOG.md)
- [Commits](cyphar/filepath-securejoin@v0.6.1...v0.7.0)

Updates `github.com/docker/cli` from 29.4.3+incompatible to 29.6.1+incompatible
- [Commits](docker/cli@v29.4.3...v29.6.1)

Updates `github.com/erikgeiser/promptkit` from 0.11.0 to 0.12.0
- [Release notes](https://github.com/erikgeiser/promptkit/releases)
- [Commits](erikgeiser/promptkit@v0.11.0...v0.12.0)

Updates `github.com/getsentry/sentry-go` from 0.46.2 to 0.48.0
- [Release notes](https://github.com/getsentry/sentry-go/releases)
- [Changelog](https://github.com/getsentry/sentry-go/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-go@v0.46.2...v0.48.0)

Updates `github.com/google/go-containerregistry` from 0.21.6 to 0.21.7
- [Release notes](https://github.com/google/go-containerregistry/releases)
- [Commits](google/go-containerregistry@v0.21.6...v0.21.7)

Updates `github.com/henvic/httpretty` from 0.1.4 to 0.2.0
- [Release notes](https://github.com/henvic/httpretty/releases)
- [Commits](henvic/httpretty@v0.1.4...v0.2.0)

Updates `github.com/klauspost/cpuid/v2` from 2.3.0 to 2.4.0
- [Release notes](https://github.com/klauspost/cpuid/releases)
- [Commits](klauspost/cpuid@v2.3.0...v2.4.0)

Updates `github.com/kubescape/go-git-url` from 0.0.31 to 0.0.32
- [Release notes](https://github.com/kubescape/go-git-url/releases)
- [Commits](kubescape/go-git-url@v0.0.31...v0.0.32)

Updates `github.com/mattn/go-colorable` from 0.1.14 to 0.1.15
- [Commits](mattn/go-colorable@v0.1.14...v0.1.15)

Updates `github.com/mattn/go-isatty` from 0.0.22 to 0.0.24
- [Commits](mattn/go-isatty@v0.0.22...v0.0.24)

Updates `github.com/mattn/go-shellwords` from 1.0.13 to 1.0.14
- [Commits](mattn/go-shellwords@v1.0.13...v1.0.14)

Updates `github.com/moby/buildkit` from 0.29.0 to 0.32.2
- [Release notes](https://github.com/moby/buildkit/releases)
- [Commits](moby/buildkit@v0.29.0...v0.32.2)

Updates `github.com/moby/moby/client` from 0.4.1 to 0.5.0
- [Release notes](https://github.com/moby/moby/releases)
- [Changelog](https://github.com/moby/moby/blob/v0.5.0/CHANGELOG.md)
- [Commits](moby/moby@v0.4.1...v0.5.0)

Updates `github.com/onsi/ginkgo/v2` from 2.28.3 to 2.32.1
- [Release notes](https://github.com/onsi/ginkgo/releases)
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md)
- [Commits](onsi/ginkgo@v2.28.3...v2.32.1)

Updates `github.com/onsi/gomega` from 1.40.0 to 1.42.1
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](onsi/gomega@v1.40.0...v1.42.1)

Updates `github.com/opencontainers/selinux` from 1.14.0 to 1.15.1
- [Release notes](https://github.com/opencontainers/selinux/releases)
- [Commits](opencontainers/selinux@v1.14.0...v1.15.1)

Updates `github.com/testcontainers/testcontainers-go` from 0.41.0 to 0.44.0
- [Release notes](https://github.com/testcontainers/testcontainers-go/releases)
- [Commits](testcontainers/testcontainers-go@v0.41.0...v0.44.0)

Updates `golang.org/x/sys` from 0.46.0 to 0.47.0
- [Commits](golang/sys@v0.46.0...v0.47.0)

Updates `golang.org/x/term` from 0.44.0 to 0.45.0
- [Commits](golang/term@v0.44.0...v0.45.0)

Updates `google.golang.org/grpc` from 1.82.1 to 1.83.0
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.82.1...v1.83.0)

Updates `kraftkit.sh` from 0.12.11 to 0.12.15
- [Release notes](https://github.com/unikraft/kraftkit/releases)
- [Commits](v0.12.11...v0.12.15)

Updates `mvdan.cc/gofumpt` from 0.10.0 to 0.11.0
- [Release notes](https://github.com/mvdan/gofumpt/releases)
- [Changelog](https://github.com/mvdan/gofumpt/blob/master/CHANGELOG.md)
- [Commits](mvdan/gofumpt@v0.10.0...v0.11.0)

---
updated-dependencies:
- dependency-name: github.com/anchore/stereoscope
  dependency-version: 0.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/cli/cli/v2
  dependency-version: 2.97.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/compose-spec/compose-go/v2
  dependency-version: 2.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/containerd/containerd/v2
  dependency-version: 2.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/containerd/nerdctl/v2
  dependency-version: 2.3.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/cyphar/filepath-securejoin
  dependency-version: 0.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/docker/cli
  dependency-version: 29.6.1+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/erikgeiser/promptkit
  dependency-version: 0.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/getsentry/sentry-go
  dependency-version: 0.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/google/go-containerregistry
  dependency-version: 0.21.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/henvic/httpretty
  dependency-version: 0.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/klauspost/cpuid/v2
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/kubescape/go-git-url
  dependency-version: 0.0.32
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/LastPossum/kamino
  dependency-version: 0.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/mattn/go-colorable
  dependency-version: 0.1.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/mattn/go-isatty
  dependency-version: 0.0.24
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/mattn/go-shellwords
  dependency-version: 1.0.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/moby/buildkit
  dependency-version: 0.32.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/moby/moby/client
  dependency-version: 0.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/onsi/ginkgo/v2
  dependency-version: 2.32.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.42.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/opencontainers/selinux
  dependency-version: 1.15.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/testcontainers/testcontainers-go
  dependency-version: 0.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: golang.org/x/sys
  dependency-version: 0.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: golang.org/x/term
  dependency-version: 0.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: google.golang.org/grpc
  dependency-version: 1.83.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: kraftkit.sh
  dependency-version: 0.12.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: mvdan.cc/gofumpt
  dependency-version: 0.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/staging/go-deps-4b2dcc1505 branch from 6aae5b1 to 0f26201 Compare August 16, 2026 09:06
@github-project-automation github-project-automation Bot moved this from 🧊 Icebox to 🚀 Done in KraftKit Roadmap Aug 17, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/go_modules/staging/go-deps-4b2dcc1505 branch August 17, 2026 08:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

Status: 🚀 Done

Development

Successfully merging this pull request may close these issues.

0 participants