Skip to content

gomod(deps): Bump the go-deps group across 1 directory with 8 updates - #2917

Closed
dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/go_modules/staging/go-deps-c74c402d04
Closed

dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/go_modules/staging/go-deps-c74c402d04

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the go-deps group with 7 updates in the / directory:

Package From To
github.com/anchore/stereoscope 0.3.0 0.3.1
github.com/cli/cli/v2 2.98.0 2.99.0
github.com/cli/go-gh/v2 2.13.0 2.15.0
github.com/compose-spec/compose-go/v2 2.14.0 2.15.0
github.com/gobwas/glob 0.2.3 1.0.0
github.com/moby/buildkit 0.32.2 0.33.0
github.com/onsi/gomega 1.42.1 1.43.0

Updates github.com/anchore/stereoscope from 0.3.0 to 0.3.1

Release notes

Sourced from github.com/anchore/stereoscope's releases.

v0.3.1

Bug Fixes

Dependencies

21 dependency changes (17 updated, 1 added, 3 removed). 2 vulnerabilities remediated.

🟢 Remediated (2)

  • github.com/containerd/containerd/v2 v2.3.3 → v2.3.4
  • github.com/containerd/platforms v1.0.0-rc.4 → v1.0.0-rc.5
  • github.com/docker/cli v29.6.1+incompatible → v29.7.2+incompatible
  • github.com/docker/go-connections v0.7.0 → v0.8.1
  • github.com/gabriel-vasile/mimetype v1.4.13 → v1.4.15
  • github.com/google/go-containerregistry v0.21.7 → v0.21.9
  • github.com/klauspost/compress v1.18.6 → v1.19.1 (🟢 remediated GO-2026-5841)
  • github.com/moby/moby/client v0.5.0 → v0.5.1
  • github.com/stretchr/objx v0.5.2 → v0.5.3
  • github.com/stretchr/testify v1.11.1 → v1.12.1
  • golang.org/x/crypto v0.54.0 → v0.55.0
  • golang.org/x/mod v0.38.0 → v0.39.0
  • golang.org/x/net v0.57.0 → v0.58.0
  • golang.org/x/text v0.40.0 → v0.41.0
  • golang.org/x/tools v0.48.0 → v0.49.0
  • google.golang.org/genproto/googleapis/rpc v0.0.0-6f92a3b → v0.0.0-afd174a
  • google.golang.org/grpc v1.80.0 → v1.82.1 (🟢 remediated GHSA-hrxh-6v49-42gf)
  • go.yaml.in/yaml/v3 v3.0.5
  • github.com/davecgh/go-spew v1.1.2-0.d8f796a
  • gopkg.in/check.v1 v1.0.0-10cb982
  • gopkg.in/yaml.v3 v3.0.1

... (truncated)

Commits
  • 85f62fd chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.1 (#672)
  • 02c3bdc chore(deps): bump golang.org/x/tools from 0.48.0 to 0.49.0 (#674)
  • 85798ef chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#673)
  • 467c2d3 chore(deps): bump github.com/containerd/containerd/v2 (#671)
  • 5052829 chore(deps): bump github.com/containerd/platforms from 1.0.0-rc.4 to 1.0.0-rc...
  • 3cd14ec fix(image): bind hardlinks to the file they name when indexing a layer (#670)
  • f70c7c3 chore(deps): bump github.com/google/go-containerregistry (#668)
  • c5d5b94 chore(deps): bump github.com/docker/cli (#669)
  • 09c972e chore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 (#667)
  • 4d73b65 chore(deps): bump github.com/docker/go-connections from 0.8.0 to 0.8.1 (#663)
  • Additional commits viewable in compare view

Updates github.com/cli/cli/v2 from 2.98.0 to 2.99.0

Release notes

Sourced from github.com/cli/cli/v2's releases.

GitHub CLI 2.99.0

Attach images and videos to issues and pull requests

The repeatable --attach flag uploads local images and videos and adds them to issue, pull request, or comment bodies. If a body already references the local path, gh replaces it with the uploaded URL; otherwise it appends the attachment:

# Attach files when creating or editing an issue
gh issue create --attach './repro.png#The error state'
gh issue edit 123 --attach ./walkthrough.mp4
Attach files when creating or editing a pull request
gh pr create --attach ./before.png
gh pr edit 456 --attach ./after.png
Attach files to comments
gh issue comment 123 --attach ./repro.png
gh pr comment 456 --attach ./result.mp4

Repeat the flag to attach multiple files in a single invocation. Attachments are available on GitHub.com and GitHub Enterprise Cloud.

For more information see https://gh.io/gh-attach and https://github.blog/changelog/2026-09-01-github-cli-media-in-issues-pull-requests-and-comments/

Worktree support extended to gh issue develop

gh issue develop can now create a linked branch and check it out in a new Git worktree, leaving your current working copy unchanged:

# Create a linked branch for an issue and check it out in a worktree
gh issue develop 123 --checkout --worktree /path/to/wt-feature

What's Changed

✨ Features

🐛 Fixes

... (truncated)

Commits
  • d528f20 Merge pull request #14260 from cli/tommaso-moro-support-pi-agent-directory
  • e909b95 Merge pull request #14154 from scarletkc/scarletkc/fix-codex-user-skill-path
  • a8460b5 Merge pull request #14300 from cli/dependabot/github_actions/codeql-actions-6...
  • 35f596d Merge pull request #14301 from cli/dependabot/github_actions/azure/login-3.0.2
  • 0574bc5 Merge pull request #14299 from cli/dependabot/go_modules/google.golang.org/gr...
  • 5d0f7d7 chore(deps): bump azure/login from 3.0.1 to 3.0.2
  • 78aaae9 chore(deps): bump the codeql-actions group with 3 updates
  • 367d30a chore(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2
  • 40b742f Merge pull request #14289 from cli/bagtoad/limit-attachment-batches
  • f2bf7c3 Limit attachment batches to 50 files
  • Additional commits viewable in compare view

Updates github.com/cli/go-gh/v2 from 2.13.0 to 2.15.0

Release notes

Sourced from github.com/cli/go-gh/v2's releases.

v2.15.0

What's Changed

Full Changelog: cli/go-gh@v2.14.0...v2.15.0

v2.14.0

What's Changed

🐛 Fixes

📚 Docs & Chores

:dependabot: Dependencies

  • Update Go module and GitHub Actions dependencies

Full Changelog: cli/go-gh@v2.13.0...v2.14.0

Commits
  • 1b0b67c Merge pull request #275 from cli/williammartin-implement-per-host-api-host
  • 96a581e Add guarded release workflow (#288)
  • de1d657 Clarify API host authentication behavior
  • 50ccff8 Apply paired review changes
  • bafadb3 Merge pull request #273 from cli/dependabot/go_modules/github.com/henvic/http...
  • b3bff58 Merge pull request #282 from cli/dependabot/go_modules/golang.org/x/text-0.41.0
  • 57c79e4 Merge pull request #284 from cli/dependabot/github_actions/codeql-actions-a10...
  • 92f04e6 Merge pull request #285 from cli/dependabot/go_modules/github.com/stretchr/te...
  • 7f9c85c chore(deps): Bump golang.org/x/text from 0.40.0 to 0.41.0
  • 49d277b chore(deps): Bump github.com/stretchr/testify from 1.11.1 to 1.12.1
  • Additional commits viewable in compare view

Updates github.com/compose-spec/compose-go/v2 from 2.14.0 to 2.15.0

Release notes

Sourced from github.com/compose-spec/compose-go/v2's releases.

v2.15.0

What's Changed

New Contributors

Full Changelog: compose-spec/compose-go@v2.14.0...v2.15.0

Commits
  • 4ddbf11 cli: validate COMPOSE_FILE entries point to actual compose files
  • 500d50c fix: merge attributes of repeated variable occurrences in ExtractVariables
  • 57f6c16 tests: run named table cases as subtests
  • 261851b loader/tests: completeness test keeps the conformance matrix exhaustive
  • 3843a20 loader/tests: link every attribute file to the spec section it locks
  • 728b3f2 loader/tests: loadsAs expresses expectations as canonical YAML
  • f8211c4 docs: TESTING.md codifies the testing contract
  • 95dbfdf test: cover short/long ulimit syntax combinations in override merge
  • 5a10b5a fix: ignore default .env probe on permission denied
  • f0442ff fix(types): reject unrecognized pull_policy values instead of defaulting
  • Additional commits viewable in compare view

Updates github.com/gobwas/glob from 0.2.3 to 1.0.0

Release notes

Sourced from github.com/gobwas/glob's releases.

v1.0.0

What's Changed

New Contributors

Full Changelog: gobwas/glob@v0.2.3...v1.0.0

Commits
  • 80c58b0 bench.sh: fix the assignment and the benchstat args, ignore *.bench
  • 60a7c15 readme: clarify ** and escaping, make the regexp comparison exact
  • c45ce1c remove parked files (but keep them in git history)
  • dab909e all: split parse.go into parse.go/match.go, polish docs, fix U+FFFD
  • 12d7a23 globtest: print out matchers tree and pretty syntax errors
  • ae63730 shape matchers: switch from <> to () and quote literals
  • a82038c pattern: String() and Separators() impl
  • e9b2193 ci: migrate to github actions
  • c0ec127 glob/v1: rewrite the matching engine
  • e7a84e9 Fix speed results table formatting.
  • Additional commits viewable in compare view

Updates github.com/moby/buildkit from 0.32.2 to 0.33.0

Release notes

Sourced from github.com/moby/buildkit's releases.

v0.33.0

Welcome to the v0.33.0 release of buildkit!

Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.

Contributors

  • CrazyMax
  • Tõnis Tiigi
  • Sebastiaan van Stijn
  • Matthieu MOREL
  • eliuriegas
  • Daniel Nephin
  • Dawei Wei
  • Guthrie McAfee Armstrong
  • Jiří Moravčík
  • Leo Li
  • Ravi Arnan
  • Shurong Cao
  • Spencer G. Jones
  • Vedant Madane

Notable Changes

  • Built-in Dockerfile frontend has been updated to v1.27.0 changelog
  • Builds using proxy-based network tracking/monitoring for exec steps now support fallback to the daemon's proxy settings when the BuildKit daemon is running behind a proxy. #7074
  • The maximum attestation size for exporters has been raised to 80 MiB. #7104
  • Content produced by Rootless versions of BuildKit has been updated to be compatible with Rootful versions of BuildKit for result reproducibility. #7039
  • Buildctl now supports passing valueless build-args read from the environment. #7030
  • Sanitize platform IDs returned by frontend to ensure tar exports can't end up with invalid paths for Windows. #7022
  • Suppress bogus git advice messages on progress output from the way BuildKit checks out git repositories. #6998
  • Build history can now be disabled from daemon configuration #7040
  • Redact more possible inline credentials in progress output or HTTP source and Git bundle steps. This didn't include builds that used build secrets to pass credentials. #7068
  • MaxRegistryConcurrency now also applies to remote cache requests. #7049
  • Windows containers now support RUN --mount=type=secret build secrets. #6944
  • Fix possible "no active session for" error when running concurrent builds with remote cache #7047
  • Fix possible "failed to apply diffs: snapshot does not exist" error #7035
  • Fix possible context upload errors when context directory contains foreign characters. #6989
  • Fix possible silently dropped cache link in remote cache exporter. #7053
  • Fix xz archive unpacking silently skipping when xz binary was missing in environment. #7071
  • Fix possible incorrect platform validation warnings caused by mismatched Windows OS versions #7072
  • Fix QEMU emulator arguments being persisted on an exec operation when a canceled operation is executed again. #7092

Dependency Changes

  • cyphar.com/go-pathrs v0.2.1 -> v0.2.5

... (truncated)

Commits
  • dddd562 Merge pull request #7105 from crazy-max/v0.33_picks_v0.33.0-rc2
  • 3c05040 vendor: update moby/policy-helpers to dd6c5499c491
  • ae09dd0 solver: avoid mutating exec args for QEMU
  • bd1ac13 exporter: raise max attestation size to 80 MiB
  • ccfc875 dockerfile: update version to 1.27
  • eece108 Merge pull request #7080 from tonistiigi/dockerd-test-fix-v0.33
  • d3f86c1 test: fix dockerd integration coverage
  • b09f8f1 Merge pull request #6944 from rzlink/wcow-secret-mount
  • bb80b2a Merge pull request #7078 from thaJeztah/bump_grpc
  • 964cf3d vendor: google.golang.org/grpc v1.83.2
  • Additional commits viewable in compare view

Updates github.com/onsi/gomega from 1.42.1 to 1.43.0

Release notes

Sourced from github.com/onsi/gomega's releases.

v1.43.0

1.43.0

Features

Add gomock adaptor extension for using Gomega matchers with gomock

Changelog

Sourced from github.com/onsi/gomega's changelog.

1.43.0

Features

Add gomock adaptor extension for using Gomega matchers with gomock

Commits

Updates github.com/tonistiigi/fsutil from 0.0.0-20260717003753-6d9dc2ebad62 to 0.0.0-20260819142231-83cac42c1c52

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-deps group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/anchore/stereoscope](https://github.com/anchore/stereoscope) | `0.3.0` | `0.3.1` |
| [github.com/cli/cli/v2](https://github.com/cli/cli) | `2.98.0` | `2.99.0` |
| [github.com/cli/go-gh/v2](https://github.com/cli/go-gh) | `2.13.0` | `2.15.0` |
| [github.com/compose-spec/compose-go/v2](https://github.com/compose-spec/compose-go) | `2.14.0` | `2.15.0` |
| [github.com/gobwas/glob](https://github.com/gobwas/glob) | `0.2.3` | `1.0.0` |
| [github.com/moby/buildkit](https://github.com/moby/buildkit) | `0.32.2` | `0.33.0` |
| [github.com/onsi/gomega](https://github.com/onsi/gomega) | `1.42.1` | `1.43.0` |



Updates `github.com/anchore/stereoscope` from 0.3.0 to 0.3.1
- [Release notes](https://github.com/anchore/stereoscope/releases)
- [Changelog](https://github.com/anchore/stereoscope/blob/main/RELEASE.md)
- [Commits](anchore/stereoscope@v0.3.0...v0.3.1)

Updates `github.com/cli/cli/v2` from 2.98.0 to 2.99.0
- [Release notes](https://github.com/cli/cli/releases)
- [Changelog](https://github.com/cli/cli/blob/trunk/docs/release-process-deep-dive.md)
- [Commits](cli/cli@v2.98.0...v2.99.0)

Updates `github.com/cli/go-gh/v2` from 2.13.0 to 2.15.0
- [Release notes](https://github.com/cli/go-gh/releases)
- [Commits](cli/go-gh@v2.13.0...v2.15.0)

Updates `github.com/compose-spec/compose-go/v2` from 2.14.0 to 2.15.0
- [Release notes](https://github.com/compose-spec/compose-go/releases)
- [Commits](compose-spec/compose-go@v2.14.0...v2.15.0)

Updates `github.com/gobwas/glob` from 0.2.3 to 1.0.0
- [Release notes](https://github.com/gobwas/glob/releases)
- [Commits](gobwas/glob@v0.2.3...v1.0.0)

Updates `github.com/moby/buildkit` from 0.32.2 to 0.33.0
- [Release notes](https://github.com/moby/buildkit/releases)
- [Commits](moby/buildkit@v0.32.2...v0.33.0)

Updates `github.com/onsi/gomega` from 1.42.1 to 1.43.0
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](onsi/gomega@v1.42.1...v1.43.0)

Updates `github.com/tonistiigi/fsutil` from 0.0.0-20260717003753-6d9dc2ebad62 to 0.0.0-20260819142231-83cac42c1c52
- [Commits](https://github.com/tonistiigi/fsutil/commits)

---
updated-dependencies:
- dependency-name: github.com/anchore/stereoscope
  dependency-version: 0.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/cli/cli/v2
  dependency-version: 2.99.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/cli/go-gh/v2
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/compose-spec/compose-go/v2
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/gobwas/glob
  dependency-version: 1.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: go-deps
- dependency-name: github.com/moby/buildkit
  dependency-version: 0.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.43.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/tonistiigi/fsutil
  dependency-version: 0.0.0-20260819142231-83cac42c1c52
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 6, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 6, 2026
@github-project-automation github-project-automation Bot moved this to 🧊 Icebox in KraftKit Roadmap Sep 6, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 20, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/staging/go-deps-c74c402d04 branch September 20, 2026 09:04
@github-project-automation github-project-automation Bot moved this from 🧊 Icebox to 🚀 Done in KraftKit Roadmap Sep 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

Status: 🚀 Done

Development

Successfully merging this pull request may close these issues.

0 participants