chore: Bump github.com/ratify-project/ratify from 1.4.0 to 1.4.3 - #2810
Closed
dependabot[bot] wants to merge 1 commit into
Closed
chore: Bump github.com/ratify-project/ratify from 1.4.0 to 1.4.3#2810dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
dependabot
Bot
requested review from
binbin-li,
fseldow,
jimmyraywv,
luisdlp,
susanshi and
toddysm
as code owners
July 23, 2026 05:46
Contributor
There was a problem hiding this comment.
Pull request overview
Note
Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.
Updates Go module dependencies to newer versions, including Kubernetes and OPA ecosystem libraries, and refreshes module checksums accordingly.
Changes:
- Bumped several direct dependencies (AWS ECR SDK, fsnotify, Ginkgo/Gomega, OPA, Kubernetes libs, controller-runtime).
- Updated
go.modindirect dependency set to reflect the new dependency graph. - Regenerated
go.sumto match the updated module versions.
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| go.mod | Upgrades direct deps (notably k8s, OPA, test libs) and updates indirect requirements to match. |
| go.sum | Updates checksum entries to align with the new resolved module graph. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| gopkg.in/ini.v1 v1.67.3 // indirect | ||
| gopkg.in/yaml.v3 v3.0.1 // indirect | ||
| k8s.io/apiextensions-apiserver v0.33.1 // indirect | ||
| k8s.io/apiextensions-apiserver v0.35.3 // indirect |
dependabot
Bot
force-pushed
the
dependabot/go_modules/github.com/ratify-project/ratify-1.4.3
branch
from
July 23, 2026 06:09
5a117f6 to
9ece79e
Compare
Bumps [github.com/ratify-project/ratify](https://github.com/ratify-project/ratify) from 1.4.0 to 1.4.3. - [Release notes](https://github.com/ratify-project/ratify/releases) - [Changelog](https://github.com/notaryproject/ratify/blob/main/RELEASES.md) - [Commits](v1.4.0...v1.4.3) --- updated-dependencies: - dependency-name: github.com/ratify-project/ratify dependency-version: 1.4.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/go_modules/github.com/ratify-project/ratify-1.4.3
branch
from
July 24, 2026 00:43
9ece79e to
55b6817
Compare
Contributor
Author
|
Superseded by #2859. |
dependabot
Bot
deleted the
dependabot/go_modules/github.com/ratify-project/ratify-1.4.3
branch
July 30, 2026 05:47
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps github.com/ratify-project/ratify from 1.4.0 to 1.4.3.
Release notes
Sourced from github.com/ratify-project/ratify's releases.
Commits
a26203fchore: upgrade chart version to 1.15.4 to fix incorrect repo (#2728)885927dchore: update release charts for v1.4.3 (#2690)99929b7chore: update Go builder to 1.26.5 (#2722)8ef995echore: Bump oras.land/oras-go/v2 from v2.6.1 to v2.6.2 (#2721)03d4c30Revert "ci: temp migrate publish package ci to use azure-test (#2689)" (#2715)3fab5bcchore: Bump anchore/sbom-action/download-syft from 0.17.9 to 0.24.0 (#2656)926561echore: Bump github.com/google/go-containerregistry from 0.21.5 to 0.21.7 (#2708)23de033chore: Bump github.com/aws/aws-sdk-go-v2/credentials from 1.19.16 to 1.19.28 ...9ff2a67ci: temp migrate publish package ci to use azure-test (#2689)544cdf4chore: update signature verify values (#2687)