Skip to content

gomod(deps): Bump the go-deps group across 1 directory with 24 updates - #2939

Closed
dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/go_modules/staging/go-deps-71bed0f744
Closed

dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/go_modules/staging/go-deps-71bed0f744

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the go-deps group with 24 updates in the / directory:

Package From To
github.com/anchore/stereoscope 0.3.0 0.3.2
github.com/cli/cli/v2 2.98.0 2.102.0
github.com/cli/go-gh/v2 2.13.0 2.16.1
github.com/compose-spec/compose-go/v2 2.14.0 2.16.1
github.com/containerd/containerd/v2 2.3.4 2.3.5
github.com/containerd/log 0.1.0 0.2.0
github.com/containerd/nerdctl/v2 2.3.5 2.4.0
github.com/docker/cli 29.7.2+incompatible 29.8.1+incompatible
github.com/dustin/go-humanize 1.0.1 1.1.0
github.com/gobwas/glob 0.2.3 1.0.0
github.com/google/go-containerregistry 0.22.0 0.22.1
github.com/mattn/go-shellwords 1.0.14 1.0.15
github.com/moby/buildkit 0.32.2 0.33.1
github.com/moby/moby/api 1.55.0 1.56.0
github.com/moby/moby/client 0.5.1 0.6.0
github.com/onsi/ginkgo/v2 2.32.1 2.33.0
github.com/onsi/gomega 1.42.1 1.44.0
github.com/tonistiigi/fsutil 0.0.0-20260717003753-6d9dc2ebad62 0.0.0-20260819142231-83cac42c1c52
golang.org/x/oauth2 0.36.0 0.37.0
golang.org/x/sync 0.22.0 0.23.0
golang.org/x/sys 0.47.0 0.48.0
golang.org/x/term 0.45.0 0.46.0
google.golang.org/grpc 1.83.2 1.84.0
sigs.k8s.io/kustomize/kyaml 0.21.1 0.21.2

Updates github.com/anchore/stereoscope from 0.3.0 to 0.3.2

Release notes

Sourced from github.com/anchore/stereoscope's releases.

v0.3.2

Bug Fixes

Performance

  • overlap layer fetch and indexing in Image.Read [PR #681 @​asomya]
  • keep one open descriptor per layer tar and read entries positionally [PR #679 @​asomya]
  • take layer diff IDs from the image config instead of recomputing [PR #680 @​asomya]

Dependencies

15 dependency changes (14 updated, 1 added). 7 vulnerabilities remediated.

🟢 Remediated (7)

  • github.com/containerd/containerd/v2 v2.3.4 → v2.3.5 (🟢 remediated GHSA-7jxh-36q5-gcqv)
  • github.com/docker/cli v29.7.2+incompatible → v29.8.0+incompatible
  • github.com/google/go-containerregistry v0.21.9 → v0.22.1
  • github.com/klauspost/compress v1.19.1 → v1.19.2
  • github.com/moby/moby/api v1.55.0 → v1.56.0
  • github.com/moby/moby/client v0.5.1 → v0.6.0
  • go.opentelemetry.io/otel v1.43.0 → v1.44.0 (🟢 remediated GO-2026-5158)
  • go.opentelemetry.io/otel/metric v1.43.0 → v1.44.0
  • go.opentelemetry.io/otel/sdk v1.43.0 → v1.44.0
  • go.opentelemetry.io/otel/sdk/metric v1.43.0 → v1.44.0
  • go.opentelemetry.io/otel/trace v1.43.0 → v1.44.0
  • golang.org/x/crypto v0.55.0 → v0.56.0 (🟢 remediated GO-2026-6354, GO-2026-6355)
  • google.golang.org/genproto/googleapis/rpc v0.0.0-afd174a → v0.0.0-3dc84a4
  • google.golang.org/grpc v1.82.1 → v1.83.2 (🟢 remediated GHSA-2v4p-qf9q-27wj, GHSA-qc2q-p7wx-3px3, GHSA-vp52-pcj8-j9qc)

... (truncated)

Commits
  • cb6de87 Fix: whiteout marker correctness (#696)
  • db5362a Fix: read cancellation should wait for workers (#693)
  • 1f355bd Fix: clear opaque whiteouts by real path, not through symlinks (#694)
  • a22e5ae fix: populate OCI platform metadata & do not ignore platform option for singl...
  • 7d54621 fix: continue file tree searches after link cycles (#666)
  • ef9a9a3 perf: overlap layer fetch and indexing in Image.Read (#681)
  • 4e5b774 chore(deps): update tool versions (#692)
  • 4f188af chore(deps): bump github.com/moby/moby/client from 0.5.1 to 0.6.0 (#688)
  • 52cbac6 chore(deps): bump golang.org/x/crypto from 0.55.0 to 0.56.0 (#691)
  • e7889db chore(deps): bump github.com/docker/cli (#690)
  • Additional commits viewable in compare view

Updates github.com/cli/cli/v2 from 2.98.0 to 2.102.0

Release notes

Sourced from github.com/cli/cli/v2's releases.

GitHub CLI 2.102.0

Security

Four security vulnerabilities have been identified, and fixed, in this release. Users are advised to update gh to version v2.102.0 as soon as possible.

gh release download, gh run download, gh repo read-file --output, and gh attestation download could write remote content to an unintended local file when the destination contained symbolic links.

See GHSA-39wj-f2f4-978v for more information.

gh attestation verify compared the --source-ref value case-insensitively, so an attestation built from a branch whose name differs only in case could satisfy a policy that named a different branch.

See GHSA-4mq3-hpgx-9cx8 for more information.

Interactive gh skill search passed repository paths from search results to gh skill install without an option separator, so a search result could inject installer options and change where skill files were written.

See GHSA-qcwj-mr2r-2cx7 for more information.

gh attestation verify matched the --signer-workflow value against only the start of the signing certificate's identity, so an attestation signed by a different workflow in the pinned repository could pass verification when its path began with the pinned value.

See GHSA-wjmr-j3rp-mh2g for more information.

What's Changed

🐛 Fixes

📚 Docs & Chores

:dependabot: Dependencies

Full Changelog: cli/cli@v2.101.0...v2.102.0

GitHub CLI 2.101.0

Linux package repository signing key rotation

... (truncated)

Commits
  • fc4b137 Merge commit from fork
  • c601748 Merge commit from fork
  • 5092057 Merge commit from fork
  • 9ee0afb Merge commit from fork
  • 1863cb7 Merge pull request #14553 from cli/bagtoad/remove-host-versions-from-help
  • b628904 Remove extra blank line in search issues help
  • 3bc352e Remove host versions from project item-list help
  • 0706fa4 Merge pull request #14519 from waldyrious/document-search-operator-support
  • 8b97df3 Close the destination root in the archive download test
  • b473ca8 Anchor exactly when --signer-workflow pins a ref of its own
  • Additional commits viewable in compare view

Updates github.com/cli/go-gh/v2 from 2.13.0 to 2.16.1

Release notes

Sourced from github.com/cli/go-gh/v2's releases.

v2.16.1

What's Changed

New Contributors

Full Changelog: cli/go-gh@v2.16.0...v2.16.1

v2.16.0

What's Changed

Full Changelog: cli/go-gh@v2.15.0...v2.16.0

v2.15.0

What's Changed

Full Changelog: cli/go-gh@v2.14.0...v2.15.0

v2.14.0

What's Changed

🐛 Fixes

📚 Docs & Chores

:dependabot: Dependencies

  • Update Go module and GitHub Actions dependencies

Full Changelog: cli/go-gh@v2.13.0...v2.14.0

Commits
  • 37aa5bb fix(repository): honor resolved remote (#290)
  • 01be116 Merge pull request #263 from baiyuxi930826/fix/atomic-api-cache-store
  • 3707f4d harden cache publication across platforms
  • d8f2f73 fix(api): make HTTP response cache writes atomic
  • c9808f2 Merge pull request #289 from cli/williammartin-relax-api-host-auth
  • d53df0d Merge pull request #287 from cli/dependabot/github_actions/codeql-actions-f1b...
  • 494d231 chore(deps): Bump the codeql-actions group across 1 directory with 2 updates
  • fbd0ed5 Trust canonical host alongside API host
  • 1b0b67c Merge pull request #275 from cli/williammartin-implement-per-host-api-host
  • 96a581e Add guarded release workflow (#288)
  • Additional commits viewable in compare view

Updates github.com/compose-spec/compose-go/v2 from 2.14.0 to 2.16.1

Release notes

Sourced from github.com/compose-spec/compose-go/v2's releases.

v2.16.1

What's Changed

Full Changelog: compose-spec/compose-go@v2.16.0...v2.16.1

v2.16.0

⚠️ Breaking change (Go API)

types.ServiceConfig now embeds types.ContainerSpec and types.WorkloadSpec, shared with the new jobs element and pre_start init containers. Field access is unchanged (svc.Image), but struct literals must now set moved fields through the embedded structs, and code walking ServiceConfig with reflection will see these two embedded structs instead of a flat list of fields:

types.ServiceConfig{Name: "web", ContainerSpec: types.ContainerSpec{Image: "nginx"}}

ServiceConfig.PreStart is now a []types.PreStartHook (was []types.ServiceHook), which embeds a full ContainerSpec; Image and PerReplica are no longer fields of ServiceHook.

The order of keys in the YAML and JSON produced for a service also changes (service-level keys first, then container-level, then workload-level ones). The content is the same, but expected files compared as text need to be regenerated.

What's Changed

New Contributors

Full Changelog: compose-spec/compose-go@v2.15.0...v2.16.0

v2.15.0

What's Changed

... (truncated)

Commits
  • 32d8d5d override: share the by-key compaction and reject null ipam config items
  • 7ed4d72 override: pin the merge of KEY=VALUE entries that are not interpolated
  • be0aa2f override: compact repeated keys and keep empty lists in KEY=VALUE merge
  • 398bcb3 override: merge KEY=VALUE lists by key so the last entry wins
  • 832c7b5 override: accept a null value when merging a list or mapping attribute
  • 6ec8efb lint: fix gocritic, gofumpt and govet issues
  • 98fd653 loader: reuse deepClone instead of duplicating it as cloneYaml
  • e93a134 loader: merge an extension into the attribute it stands for
  • f33989c loader: pin promotion of extensions before extends merges services
  • 732bdd9 loader: apply !reset and !override to the attribute an extension stands for
  • Additional commits viewable in compare view

Updates github.com/containerd/containerd/v2 from 2.3.4 to 2.3.5

Release notes

Sourced from github.com/containerd/containerd/v2's releases.

containerd 2.3.5

Welcome to the v2.3.5 release of containerd!

The fifth patch release for containerd 2.3 contains various fixes and updates including security patches.

Security Updates

Highlights

Image Distribution

  • Apply hardening to strip sensitive authentication headers when fetching descriptor URLs (#14030)

Runtime

  • Avoid hangs and data races when streaming container standard I/O in CRI (#14094)
  • Fix missing error messages in OpenTelemetry trace attributes (#14049)
  • Fix user and group lookup failures in container rootfs containing symlinked /etc/passwd or /etc/group (#13999)
  • Fix configuration loading error when drop-in configuration files have a higher version than the root configuration (#13995)
  • Avoid containerd startup hangs when loading shims (#13983)
  • Add context to error when shim delete times out (#13921)
  • Fix Windows Server 2022 container compatibility on host builds newer than the latest LTSC (containerd/platforms#34)

Snapshotters

  • Fix unpack failure for EROFS images containing the erofs OS feature (#14062)

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors

  • Phil Estes
  • Samuel Karp
  • Derek McGowan
  • Sebastiaan van Stijn
  • Akhil Mohan
  • Maksym Pavlenko
  • Wei Fu
  • Oleh Konko
  • Austin Vazquez
  • Jing Chen
  • Martín Fernández
  • Paco Xu
  • XlabAI

... (truncated)

Commits
  • 1294c24 Merge pull request #14092 from samuelkarp/prepare-release-2.3.5
  • db68d72 Prepare release notes for v2.3.5
  • be419b0 Merge commit from fork
  • 84ea25b Merge commit from fork
  • 5db0399 Merge pull request #14094 from k8s-infra-cherrypick-robot/cherry-pick-14085-t...
  • 9f6be86 Fix data races and a deadlock in the byte stream helpers
  • 9ec55f0 cri: cancel ExecSync IO drain on context cancellation
  • c535779 archive: skip redundant opaque whiteout walks
  • 3684f86 Merge pull request #14063 from k8s-infra-cherrypick-robot/cherry-pick-14057-t...
  • 7459b1f Merge pull request #14062 from k8s-infra-cherrypick-robot/cherry-pick-14012-t...
  • Additional commits viewable in compare view

Updates github.com/containerd/log from 0.1.0 to 0.2.0

Release notes

Sourced from github.com/containerd/log's releases.

v0.2.0

What's Changed

New Contributors

Full Changelog: containerd/log@v0.1.0...v0.2.0

Commits
  • 8b5d653 Merge pull request #25 from thaJeztah/integrate_tracing_improve
  • 65e60ca otel: add option to set span error status
  • 9c0b6a4 otel: add option to configure log level
  • 6fcf9c1 Merge pull request #28 from thaJeztah/handle_nil_contexts
  • 2b5e7c3 otel: avoid span lookup for entries without context
  • 4ec26d0 Merge pull request #24 from thaJeztah/integrate_tracing
  • dd120bd Merge pull request #21 from thaJeztah/rewrite_slog
  • dd21ae6 Merge pull request #27 from thaJeztah/bump_logrus
  • 18f2de6 log: accept slog-compatible levels in SetLevel
  • c474254 slog: improve bridge test coverage
  • Additional commits viewable in compare view

Updates github.com/containerd/nerdctl/v2 from 2.3.5 to 2.4.0

Release notes

Sourced from github.com/containerd/nerdctl/v2's releases.

v2.4.0

This release improves compatibility with Docker v29.

Changes

Major changes (💡 for highlights):

  • nerdctl image:

    • 💡Adopted Docker v29 default nerdctl images output (IMAGE, ID, DISK USAGE, CONTENT SIZE, EXTRA) (#5093, thanks to @​ekalinin)
    • Added nerdctl images --tree to show a row per platform an image declares, like docker image ls --tree (#5092, thanks to @​ekalinin)
    • Added nerdctl push --all-tags (-a) to push every local tag of a repository (#5133, thanks to @​ekalinin)
    • Added nerdctl image convert --erofs {raw|zstd} and aligned EROFS pull/push with containerd (#4927, thanks to @​ChengyuZhu6)
    • Added nerdctl save --quiet (-q) to suppress progress output (#5064, thanks to @​s3onghyun)
    • Fixed nerdctl image ls <repo> to list all tags of a bare repository name (#5115, thanks to @​ankit090701)
    • Added snapshot info to native nerdctl image inspect (#5114, thanks to @​ningmingxiao)
    • Pinned the image a container runs to its digest (#5125, thanks to @​ekalinin)
    • Truncated the output file of nerdctl save and nerdctl image export (#5160, thanks to @​ekalinin)
    • Preserved equals signs in image label filter values (#5163, thanks to @​immanuwell)
  • nerdctl container:

    • 💡Added --mount type=image (read-only) (#4990, thanks to @​mayur-tolexo)
    • Added image-subpath to --mount type=image to mount a relative path inside the image rootfs instead of the whole rootfs (#4993, thanks to @​mayur-tolexo)
    • Added --expose and --publish-all (-P) (#5036, thanks to @​Mujib-Ahasan)
    • 💡Added support for the Docker v25 recursive read-only (RRO) mount form (#5043)
    • Allocated a free host port from a published port range for a single container port (#4988, thanks to @​s3onghyun)
    • Added the volume-nocopy mount option, so existing data in the container is not copied into the volume (#5129, thanks to @​jiwahn)
    • Fixed --cpus writing cpuset instead of CFS quota/period (#5067, thanks to @​kmaris)
    • Fixed nerdctl run/exec -i hanging when stdin reaches EOF during task creation (#5042)
    • Fixed a foreground stdio deadlock when the internal logging process stops consuming (#5151, thanks to @​gsaddict91)
    • Added snapshot info to native nerdctl container inspect (#5118, thanks to @​ningmingxiao)
    • Suppressed a spurious hostsstore NotFound warning on container removal (#5098, thanks to @​pujitha24)
    • Allowed removing containers that have no network annotations (#5211, thanks to @​Arman16-1998)
    • Matched nerdctl ps --filter keys exactly instead of by prefix (#5197, thanks to @​immanuwell)
  • nerdctl system:

    • 💡 Added nerdctl system df, with --verbose (-v) and --format (#5130, thanks to @​ekalinin)
  • nerdctl build:

    • Printed the image ID with --quiet when using the containerd worker (#5170, thanks to @​locker95)
  • nerdctl network:

  • nerdctl events:

... (truncated)

Commits
  • bbc533c Merge pull request #5224 from AkihiroSuda/dev
  • 08ed575 Merge pull request #5223 from immanuwell/fix/top-container-states
  • 4504226 update RootlessKit (3.2.0)
  • 34a85c2 go.mod: github.com/rootless-containers/rootlesskit/v3 v3.2.0
  • 8d7f340 fix(top): handle stopped and paused containers
  • df23ce0 Merge pull request #5221 from containerd/dependabot/github_actions/docker/set...
  • 279d929 Merge pull request #5219 from containerd/dependabot/github_actions/docker/bui...
  • 9508dce Merge pull request #5220 from containerd/dependabot/github_actions/docker/set...
  • 1e7cfd9 Merge pull request #5222 from containerd/dependabot/go_modules/docker-cea57ad793
  • a7e1d20 build(deps): bump the docker group with 2 updates
  • Additional commits viewable in compare view

Updates github.com/docker/cli from 29.7.2+incompatible to 29.8.1+incompatible

Commits
  • 4a63305 Merge pull request #7297 from docker/dependabot/github_actions/docker-actions...
  • 87ff477 Merge pull request #7307 from thaJeztah/ci_ubuntu_2604
  • 101ffc0 ci: update to Ubuntu 26.04 runners
  • 32ff1e7 build(deps): bump docker/docker-agent-action/.github/workflows/review-pr.yml
  • d146e67 Merge pull request #7290 from vvoland/port-template
  • ac976d9 Merge pull request #7296 from keeltrace/keeltrace/history-timezone-test
  • 48baf6c Merge pull request #7306 from thaJeztah/bump_x_deps
  • 47a06aa Merge pull request #7293 from thaJeztah/bump_uax29
  • 1bf3eb6 Merge pull request #7295 from thaJeztah/bump_userns
  • 60dffc9 vendor: golang.org/x/net v0.59.0
  • Additional commits viewable in compare view

Updates github.com/dustin/go-humanize from 1.0.1 to 1.1.0

Commits

Updates github.com/gobwas/glob from 0.2.3 to 1.0.0

Release notes

Sourced from github.com/gobwas/glob's releases.

v1.0.0

What's Changed

New Contributors

Full Changelog: https://github.com/gobwas/glob/compare/v0.2.3...v1.0.0Description has been truncated

Bumps the go-deps group with 24 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/anchore/stereoscope](https://github.com/anchore/stereoscope) | `0.3.0` | `0.3.2` |
| [github.com/cli/cli/v2](https://github.com/cli/cli) | `2.98.0` | `2.102.0` |
| [github.com/cli/go-gh/v2](https://github.com/cli/go-gh) | `2.13.0` | `2.16.1` |
| [github.com/compose-spec/compose-go/v2](https://github.com/compose-spec/compose-go) | `2.14.0` | `2.16.1` |
| [github.com/containerd/containerd/v2](https://github.com/containerd/containerd) | `2.3.4` | `2.3.5` |
| [github.com/containerd/log](https://github.com/containerd/log) | `0.1.0` | `0.2.0` |
| [github.com/containerd/nerdctl/v2](https://github.com/containerd/nerdctl) | `2.3.5` | `2.4.0` |
| [github.com/docker/cli](https://github.com/docker/cli) | `29.7.2+incompatible` | `29.8.1+incompatible` |
| [github.com/dustin/go-humanize](https://github.com/dustin/go-humanize) | `1.0.1` | `1.1.0` |
| [github.com/gobwas/glob](https://github.com/gobwas/glob) | `0.2.3` | `1.0.0` |
| [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry) | `0.22.0` | `0.22.1` |
| [github.com/mattn/go-shellwords](https://github.com/mattn/go-shellwords) | `1.0.14` | `1.0.15` |
| [github.com/moby/buildkit](https://github.com/moby/buildkit) | `0.32.2` | `0.33.1` |
| [github.com/moby/moby/api](https://github.com/moby/moby) | `1.55.0` | `1.56.0` |
| [github.com/moby/moby/client](https://github.com/moby/moby) | `0.5.1` | `0.6.0` |
| [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) | `2.32.1` | `2.33.0` |
| [github.com/onsi/gomega](https://github.com/onsi/gomega) | `1.42.1` | `1.44.0` |
| [github.com/tonistiigi/fsutil](https://github.com/tonistiigi/fsutil) | `0.0.0-20260717003753-6d9dc2ebad62` | `0.0.0-20260819142231-83cac42c1c52` |
| [golang.org/x/oauth2](https://github.com/golang/oauth2) | `0.36.0` | `0.37.0` |
| [golang.org/x/sync](https://github.com/golang/sync) | `0.22.0` | `0.23.0` |
| [golang.org/x/sys](https://github.com/golang/sys) | `0.47.0` | `0.48.0` |
| [golang.org/x/term](https://github.com/golang/term) | `0.45.0` | `0.46.0` |
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.83.2` | `1.84.0` |
| [sigs.k8s.io/kustomize/kyaml](https://github.com/kubernetes-sigs/kustomize) | `0.21.1` | `0.21.2` |



Updates `github.com/anchore/stereoscope` from 0.3.0 to 0.3.2
- [Release notes](https://github.com/anchore/stereoscope/releases)
- [Changelog](https://github.com/anchore/stereoscope/blob/main/RELEASE.md)
- [Commits](anchore/stereoscope@v0.3.0...v0.3.2)

Updates `github.com/cli/cli/v2` from 2.98.0 to 2.102.0
- [Release notes](https://github.com/cli/cli/releases)
- [Changelog](https://github.com/cli/cli/blob/trunk/docs/release-process-deep-dive.md)
- [Commits](cli/cli@v2.98.0...v2.102.0)

Updates `github.com/cli/go-gh/v2` from 2.13.0 to 2.16.1
- [Release notes](https://github.com/cli/go-gh/releases)
- [Commits](cli/go-gh@v2.13.0...v2.16.1)

Updates `github.com/compose-spec/compose-go/v2` from 2.14.0 to 2.16.1
- [Release notes](https://github.com/compose-spec/compose-go/releases)
- [Commits](compose-spec/compose-go@v2.14.0...v2.16.1)

Updates `github.com/containerd/containerd/v2` from 2.3.4 to 2.3.5
- [Release notes](https://github.com/containerd/containerd/releases)
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)
- [Commits](containerd/containerd@v2.3.4...v2.3.5)

Updates `github.com/containerd/log` from 0.1.0 to 0.2.0
- [Release notes](https://github.com/containerd/log/releases)
- [Commits](containerd/log@v0.1.0...v0.2.0)

Updates `github.com/containerd/nerdctl/v2` from 2.3.5 to 2.4.0
- [Release notes](https://github.com/containerd/nerdctl/releases)
- [Commits](containerd/nerdctl@v2.3.5...v2.4.0)

Updates `github.com/docker/cli` from 29.7.2+incompatible to 29.8.1+incompatible
- [Commits](docker/cli@v29.7.2...v29.8.1)

Updates `github.com/dustin/go-humanize` from 1.0.1 to 1.1.0
- [Commits](dustin/go-humanize@v1.0.1...v1.1.0)

Updates `github.com/gobwas/glob` from 0.2.3 to 1.0.0
- [Release notes](https://github.com/gobwas/glob/releases)
- [Commits](gobwas/glob@v0.2.3...v1.0.0)

Updates `github.com/google/go-containerregistry` from 0.22.0 to 0.22.1
- [Release notes](https://github.com/google/go-containerregistry/releases)
- [Commits](google/go-containerregistry@v0.22.0...v0.22.1)

Updates `github.com/mattn/go-shellwords` from 1.0.14 to 1.0.15
- [Release notes](https://github.com/mattn/go-shellwords/releases)
- [Commits](mattn/go-shellwords@v1.0.14...v1.0.15)

Updates `github.com/moby/buildkit` from 0.32.2 to 0.33.1
- [Release notes](https://github.com/moby/buildkit/releases)
- [Commits](moby/buildkit@v0.32.2...v0.33.1)

Updates `github.com/moby/moby/api` from 1.55.0 to 1.56.0
- [Release notes](https://github.com/moby/moby/releases)
- [Commits](moby/moby@api/v1.55.0...api/v1.56.0)

Updates `github.com/moby/moby/client` from 0.5.1 to 0.6.0
- [Release notes](https://github.com/moby/moby/releases)
- [Changelog](https://github.com/moby/moby/blob/v0.6.0/CHANGELOG.md)
- [Commits](moby/moby@v0.5.1...v0.6.0)

Updates `github.com/onsi/ginkgo/v2` from 2.32.1 to 2.33.0
- [Release notes](https://github.com/onsi/ginkgo/releases)
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md)
- [Commits](onsi/ginkgo@v2.32.1...v2.33.0)

Updates `github.com/onsi/gomega` from 1.42.1 to 1.44.0
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](onsi/gomega@v1.42.1...v1.44.0)

Updates `github.com/tonistiigi/fsutil` from 0.0.0-20260717003753-6d9dc2ebad62 to 0.0.0-20260819142231-83cac42c1c52
- [Commits](https://github.com/tonistiigi/fsutil/commits)

Updates `golang.org/x/oauth2` from 0.36.0 to 0.37.0
- [Commits](golang/oauth2@v0.36.0...v0.37.0)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](golang/sync@v0.22.0...v0.23.0)

Updates `golang.org/x/sys` from 0.47.0 to 0.48.0
- [Commits](golang/sys@v0.47.0...v0.48.0)

Updates `golang.org/x/term` from 0.45.0 to 0.46.0
- [Commits](golang/term@v0.45.0...v0.46.0)

Updates `google.golang.org/grpc` from 1.83.2 to 1.84.0
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.83.2...v1.84.0)

Updates `sigs.k8s.io/kustomize/kyaml` from 0.21.1 to 0.21.2
- [Release notes](https://github.com/kubernetes-sigs/kustomize/releases)
- [Commits](kubernetes-sigs/kustomize@api/v0.21.1...api/v0.21.2)

---
updated-dependencies:
- dependency-name: github.com/anchore/stereoscope
  dependency-version: 0.3.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/cli/cli/v2
  dependency-version: 2.102.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/cli/go-gh/v2
  dependency-version: 2.16.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/compose-spec/compose-go/v2
  dependency-version: 2.16.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/containerd/containerd/v2
  dependency-version: 2.3.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/containerd/log
  dependency-version: 0.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/containerd/nerdctl/v2
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/docker/cli
  dependency-version: 29.8.1+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/dustin/go-humanize
  dependency-version: 1.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/gobwas/glob
  dependency-version: 1.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: go-deps
- dependency-name: github.com/google/go-containerregistry
  dependency-version: 0.22.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/mattn/go-shellwords
  dependency-version: 1.0.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/moby/buildkit
  dependency-version: 0.33.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/moby/moby/api
  dependency-version: 1.56.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/moby/moby/client
  dependency-version: 0.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/onsi/ginkgo/v2
  dependency-version: 2.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/tonistiigi/fsutil
  dependency-version: 0.0.0-20260819142231-83cac42c1c52
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: golang.org/x/oauth2
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: golang.org/x/sys
  dependency-version: 0.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: golang.org/x/term
  dependency-version: 0.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: google.golang.org/grpc
  dependency-version: 1.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: sigs.k8s.io/kustomize/kyaml
  dependency-version: 0.21.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Oct 4, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 11, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 11, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/staging/go-deps-71bed0f744 branch October 11, 2026 09:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

Status: 🚀 Done

Development

Successfully merging this pull request may close these issues.

0 participants