Skip to content

Bump the gomod group with 2 updates#144

Merged
miniprow[bot] merged 1 commit into
mainfrom
dependabot/go_modules/gomod-a4e47bd3bd
Jun 10, 2026
Merged

Bump the gomod group with 2 updates#144
miniprow[bot] merged 1 commit into
mainfrom
dependabot/go_modules/gomod-a4e47bd3bd

Bump the gomod group with 2 updates

88b247a
Select commit
Loading
Failed to load commit list.
Kusari Inspector / Kusari Inspector succeeded Jun 10, 2026 in 1m 59s

Security Analysis Passed

No security issues found

Details

Kusari Inspector

Kusari Analysis Results:

Proceed with these changes

✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.

Both independent analyses return clean results with no security concerns. The dependency analysis confirms that the two updated packages (github.com/sigstore/sigstore-go v1.2.0 to v1.2.1 and github.com/carabiner-dev/signer v0.5.1 to v0.5.2) carry zero risk scores, no known vulnerabilities or advisories, are not deprecated or end-of-life, hold permissive Apache-2.0 licenses, and score 10/10 on maintenance and code review. The code analysis of the modified files (go.mod and go.sum) found zero issues across all categories — no code vulnerabilities, no exposed secrets, and no workflow concerns. The combined risk profile remains low, and no action items are required before merging.

Note

View full detailed analysis result for more information on the output and the checks that were run.


@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: 88b247a, performed at: 2026-06-10T04:45:13Z