chore(deps): bump the all group across 1 directory with 13 updates#1696
Open
dependabot[bot] wants to merge 1 commit into
Open
chore(deps): bump the all group across 1 directory with 13 updates#1696dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the all group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [cloud.google.com/go/storage](https://github.com/googleapis/google-cloud-go) | `1.62.1` | `1.62.2` | | [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry) | `0.21.5` | `0.21.6` | | [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) | `1.10.6` | `1.10.8` | | [github.com/sigstore/sigstore/pkg/signature/kms/aws](https://github.com/sigstore/sigstore) | `1.10.6` | `1.10.8` | | [github.com/sigstore/sigstore/pkg/signature/kms/azure](https://github.com/sigstore/sigstore) | `1.10.6` | `1.10.8` | | [github.com/sigstore/sigstore/pkg/signature/kms/gcp](https://github.com/sigstore/sigstore) | `1.10.6` | `1.10.8` | | [github.com/sigstore/sigstore/pkg/signature/kms/hashivault](https://github.com/sigstore/sigstore) | `1.10.6` | `1.10.8` | | [github.com/spiffe/go-spiffe/v2](https://github.com/spiffe/go-spiffe) | `2.6.0` | `2.7.0` | | [github.com/tektoncd/pipeline](https://github.com/tektoncd/pipeline) | `1.12.0` | `1.13.0` | | [go.opentelemetry.io/otel/sdk/metric](https://github.com/open-telemetry/opentelemetry-go) | `1.43.0` | `1.44.0` | Updates `cloud.google.com/go/storage` from 1.62.1 to 1.62.2 - [Release notes](https://github.com/googleapis/google-cloud-go/releases) - [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/CHANGES.md) - [Commits](googleapis/google-cloud-go@storage/v1.62.1...storage/v1.62.2) Updates `github.com/google/go-containerregistry` from 0.21.5 to 0.21.6 - [Release notes](https://github.com/google/go-containerregistry/releases) - [Commits](google/go-containerregistry@v0.21.5...v0.21.6) Updates `github.com/sigstore/sigstore` from 1.10.6 to 1.10.8 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.6...v1.10.8) Updates `github.com/sigstore/sigstore/pkg/signature/kms/aws` from 1.10.6 to 1.10.8 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.6...v1.10.8) Updates `github.com/sigstore/sigstore/pkg/signature/kms/azure` from 1.10.6 to 1.10.8 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.6...v1.10.8) Updates `github.com/sigstore/sigstore/pkg/signature/kms/gcp` from 1.10.6 to 1.10.8 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.6...v1.10.8) Updates `github.com/sigstore/sigstore/pkg/signature/kms/hashivault` from 1.10.6 to 1.10.8 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.6...v1.10.8) Updates `github.com/spiffe/go-spiffe/v2` from 2.6.0 to 2.7.0 - [Release notes](https://github.com/spiffe/go-spiffe/releases) - [Changelog](https://github.com/spiffe/go-spiffe/blob/main/CHANGELOG.md) - [Commits](spiffe/go-spiffe@v2.6.0...v2.7.0) Updates `github.com/tektoncd/pipeline` from 1.12.0 to 1.13.0 - [Release notes](https://github.com/tektoncd/pipeline/releases) - [Changelog](https://github.com/tektoncd/pipeline/blob/main/releases.md) - [Commits](tektoncd/pipeline@v1.12.0...v1.13.0) Updates `go.opentelemetry.io/otel` from 1.43.0 to 1.44.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.43.0...v1.44.0) Updates `go.opentelemetry.io/otel/metric` from 1.43.0 to 1.44.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.43.0...v1.44.0) Updates `go.opentelemetry.io/otel/sdk/metric` from 1.43.0 to 1.44.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.43.0...v1.44.0) Updates `golang.org/x/crypto` from 0.51.0 to 0.52.0 - [Commits](golang/crypto@v0.51.0...v0.52.0) --- updated-dependencies: - dependency-name: cloud.google.com/go/storage dependency-version: 1.62.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/google/go-containerregistry dependency-version: 0.21.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/sigstore/sigstore dependency-version: 1.10.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/aws dependency-version: 1.10.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/azure dependency-version: 1.10.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/gcp dependency-version: 1.10.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/hashivault dependency-version: 1.10.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/spiffe/go-spiffe/v2 dependency-version: 2.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: github.com/tektoncd/pipeline dependency-version: 1.13.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: go.opentelemetry.io/otel dependency-version: 1.44.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: go.opentelemetry.io/otel/metric dependency-version: 1.44.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: go.opentelemetry.io/otel/sdk/metric dependency-version: 1.44.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: golang.org/x/crypto dependency-version: 0.52.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all ... Signed-off-by: dependabot[bot] <support@github.com>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the all group with 10 updates in the / directory:
1.62.11.62.20.21.50.21.61.10.61.10.81.10.61.10.81.10.61.10.81.10.61.10.81.10.61.10.82.6.02.7.01.12.01.13.01.43.01.44.0Updates
cloud.google.com/go/storagefrom 1.62.1 to 1.62.2Release notes
Sourced from cloud.google.com/go/storage's releases.
Commits
50a5755chore: librarian release pull request: 20260518T161338Z (#14610)585840fspanner: skip flaky TestIntegration_DbRemovalRecovery (#14607)f8bf88ftest(spanner): retry query after database recreation in integration test (#14...9168ab8chore(librariangen): tweak release preview test (#14599)f8b9a93fix(spanner/spannertest): Support UUID as a base data type (#14117)a42fd83fix(internal/librariange): release preview support (#14588)d944830fix(datastore): add retries to emulator (#14591)c5aaedcchore: migrate Go configuration in librarian.yaml (#14587)8a0e849doc(agentplatform): Add notes and quick examples to the README033f4fechore: librarian release pull request: 20260514T191310Z (#14589)Updates
github.com/google/go-containerregistryfrom 0.21.5 to 0.21.6Release notes
Sourced from github.com/google/go-containerregistry's releases.
Commits
53f7e39Update go version to 1.26.3 (#2300)bf87c3btransport: allow bearer realm at same host:port as registry (#2302)c55facdtransport: retry HTTP 429 (Too Many Requests) (#2301)68a569efix: preserve per-occurrence layer identity in Layers() (#2299)35b354bfix(mutate): preserve config blob and layers for non-Docker OCI artifacts (#2...e5983f2remote: block SSRF via private-IP Location headers in blob uploads (#2295)6dad820remote: validate foreign layer URLs to prevent SSRF (fixes #2259) (#2293)78bdf1bvalidate: skip non-layer layers (#2298)c29d91cpkg/v1/mutate: preserve relative symlinks that stay within rootfs in Extract ...a70d75atransport: block redirects from token server to private/link-local addresses ...Updates
github.com/sigstore/sigstorefrom 1.10.6 to 1.10.8Release notes
Sourced from github.com/sigstore/sigstore's releases.
Commits
c761681Support standard PKCS#8 encrypted private key decryption (#2333)005faf9Extend PEM private key unmarshalling to support legacy format (#2332)e70e4edadd functional options to DSSE to improve memory usage, validation (#2326)899684dbuild(deps): Bump github.com/letsencrypt/boulder (#2307)181dc40build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2308)2c141a7build(deps): Bump golangci/golangci-lint-action in the all group (#2328)b6c0214build(deps): Bump actions/upload-artifact from 6.0.0 to 7.0.1 (#2329)2ff50c9build(deps): Bump actions/dependency-review-action from 4.8.3 to 5.0.0 (#2330)d0204c3build(deps): Bump hashicorp/vault from 1.21.4 to 2.0.1 in /test/e2e (#2331)afdf897build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp (#2312)Updates
github.com/sigstore/sigstore/pkg/signature/kms/awsfrom 1.10.6 to 1.10.8Release notes
Sourced from github.com/sigstore/sigstore/pkg/signature/kms/aws's releases.
Commits
c761681Support standard PKCS#8 encrypted private key decryption (#2333)005faf9Extend PEM private key unmarshalling to support legacy format (#2332)e70e4edadd functional options to DSSE to improve memory usage, validation (#2326)899684dbuild(deps): Bump github.com/letsencrypt/boulder (#2307)181dc40build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2308)2c141a7build(deps): Bump golangci/golangci-lint-action in the all group (#2328)b6c0214build(deps): Bump actions/upload-artifact from 6.0.0 to 7.0.1 (#2329)2ff50c9build(deps): Bump actions/dependency-review-action from 4.8.3 to 5.0.0 (#2330)d0204c3build(deps): Bump hashicorp/vault from 1.21.4 to 2.0.1 in /test/e2e (#2331)afdf897build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp (#2312)Updates
github.com/sigstore/sigstore/pkg/signature/kms/azurefrom 1.10.6 to 1.10.8Release notes
Sourced from github.com/sigstore/sigstore/pkg/signature/kms/azure's releases.
Commits
c761681Support standard PKCS#8 encrypted private key decryption (#2333)005faf9Extend PEM private key unmarshalling to support legacy format (#2332)e70e4edadd functional options to DSSE to improve memory usage, validation (#2326)899684dbuild(deps): Bump github.com/letsencrypt/boulder (#2307)181dc40build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2308)2c141a7build(deps): Bump golangci/golangci-lint-action in the all group (#2328)b6c0214build(deps): Bump actions/upload-artifact from 6.0.0 to 7.0.1 (#2329)2ff50c9build(deps): Bump actions/dependency-review-action from 4.8.3 to 5.0.0 (#2330)d0204c3build(deps): Bump hashicorp/vault from 1.21.4 to 2.0.1 in /test/e2e (#2331)afdf897build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp (#2312)Updates
github.com/sigstore/sigstore/pkg/signature/kms/gcpfrom 1.10.6 to 1.10.8Release notes
Sourced from github.com/sigstore/sigstore/pkg/signature/kms/gcp's releases.
Commits
c761681Support standard PKCS#8 encrypted private key decryption (#2333)005faf9Extend PEM private key unmarshalling to support legacy format (#2332)e70e4edadd functional options to DSSE to improve memory usage, validation (#2326)899684dbuild(deps): Bump github.com/letsencrypt/boulder (#2307)181dc40build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2308)2c141a7build(deps): Bump golangci/golangci-lint-action in the all group (#2328)b6c0214build(deps): Bump actions/upload-artifact from 6.0.0 to 7.0.1 (#2329)2ff50c9build(deps): Bump actions/dependency-review-action from 4.8.3 to 5.0.0 (#2330)d0204c3build(deps): Bump hashicorp/vault from 1.21.4 to 2.0.1 in /test/e2e (#2331)afdf897build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp (#2312)Updates
github.com/sigstore/sigstore/pkg/signature/kms/hashivaultfrom 1.10.6 to 1.10.8Release notes
Sourced from github.com/sigstore/sigstore/pkg/signature/kms/hashivault's releases.
Commits
c761681Support standard PKCS#8 encrypted private key decryption (#2333)005faf9Extend PEM private key unmarshalling to support legacy format (#2332)e70e4edadd functional options to DSSE to improve memory usage, validation (#2326)899684dbuild(deps): Bump github.com/letsencrypt/boulder (#2307)181dc40build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2308)2c141a7build(deps): Bump golangci/golangci-lint-action in the all group (#2328)b6c0214build(deps): Bump actions/upload-artifact from 6.0.0 to 7.0.1 (#2329)2ff50c9build(deps): Bump actions/dependency-review-action from 4.8.3 to 5.0.0 (#2330)d0204c3build(deps): Bump hashicorp/vault from 1.21.4 to 2.0.1 in /test/e2e (#2331)afdf897build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp (#2312)Updates
github.com/spiffe/go-spiffe/v2from 2.6.0 to 2.7.0Release notes
Sourced from github.com/spiffe/go-spiffe/v2's releases.
Changelog
Sourced from github.com/spiffe/go-spiffe/v2's changelog.
Commits
76b14bdv2.7.0 changelog (#392)8580a01Add missing witbundle APIs for parity with jwtbundle (#391)280d52efix(x509svid): reject leaf SPIFFE IDs with root path (#375)c7f2701Add WIT-SVID (#385)af3667aBump google.golang.org/grpc from 1.75.0 to 1.79.3 (#380)c925be7Bump christophebedard/dco-check from 0.5.0 to 0.5.1 (#390)1d02ca5Bump google.golang.org/protobuf from 1.36.8 to 1.36.11 (#371)9e0f387Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#381)9e644d8Add Marcos as maintainer (#387)c010fdcFix current build break (#379)Updates
github.com/tektoncd/pipelinefrom 1.12.0 to 1.13.0Release notes
Sourced from github.com/tektoncd/pipeline's releases.
... (truncated)
Changelog
Sourced from github.com/tektoncd/pipeline's changelog.
... (truncated)
Commits
31e7226fix: allow finally tasks to run when tasks timeout is exceeded (#6794)e7c660ebuild: bump go directive to 1.26e0ed3ffci: fix setup-go version comment in codeql-analysis.yml285339dfix: truncate affinity assistant volume names to 63 characters9a18647fix: avoid throttling script init containerd230bd5fix: update taskrun reconciler tests for default resource requirements5a78afffix: set default resource requirements on internal containers171cfb3fix: gofmt formatting in taskrun_test.god5a575bfix: preserve previous condition context when TaskRun is cancelled or times out1900840fix: downgrade tracing logs to debug and update security docsUpdates
go.opentelemetry.io/otelfrom 1.43.0 to 1.44.0Changelog
Sourced from go.opentelemetry.io/otel's changelog.
... (truncated)
Commits
b62d928Release 1.44.0 (#8376)94132a0chore(deps): update golang.org/x/telemetry digest to 5997936 (#8379)6fdcf82feat: add self-observability metrics to otlpmetricgrpc metric exporters (#8192)761bbfcfix(deps): update golang.org/x (#8377)3a91dc6fix(deps): update googleapis to 3dc84a4 (#8375)f593185exporters/otlp: default max request size to 64 MiB (#8365)f02feacMerge commit from fork36c2f1bsemconvkit: add invariant test for histogram-exclusion rule (#8370)d0b6cbdsdk/metric: document unit-sensitivity of DefaultAggregationSelector (#8224)9a68034add self observability for stdout exporter (#8263)Updates
go.opentelemetry.io/otel/metricfrom 1.43.0 to 1.44.0Changelog
Sourced from go.opentelemetry.io/otel/metric's changelog.