Skip to content

chore(deps): update go dependencies - #269

Open
red-hat-konflux[bot] wants to merge 1 commit into
release-1.0from
konflux/mintmaker/release-1.0/go-deps
Open

chore(deps): update go dependencies#269
red-hat-konflux[bot] wants to merge 1 commit into
release-1.0from
konflux/mintmaker/release-1.0/go-deps

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Aug 21, 2026

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Pending
cloud.google.com/go/auth indirect patch v0.23.1v0.23.2
github.com/AzureAD/microsoft-authentication-library-for-go indirect minor v1.8.0v1.9.0
github.com/ThalesIgnite/crypto11 indirect minor v1.2.5v1.6.8
github.com/alibabacloud-go/cr-20160607 indirect major v1.0.1v2.0.0
github.com/alibabacloud-go/cr-20181201 indirect major v1.0.10v3.2.2
github.com/alibabacloud-go/darabonba-openapi indirect major v0.2.1v2.2.4
github.com/alibabacloud-go/tea-utils indirect major v1.4.5v2.0.9
github.com/aliyun/credentials-go indirect patch v1.4.12v1.4.13
github.com/aws/aws-sdk-go-v2 require patch v1.43.6v1.43.7 v1.43.8
github.com/aws/aws-sdk-go-v2/config indirect patch v1.32.37v1.32.38 v1.32.39
github.com/aws/aws-sdk-go-v2/credentials indirect patch v1.19.36v1.19.37 v1.19.38
github.com/aws/aws-sdk-go-v2/feature/ec2/imds indirect patch v1.18.37v1.18.38 v1.18.39
github.com/aws/aws-sdk-go-v2/internal/configsources indirect patch v1.4.37v1.4.38 v1.4.39
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 indirect patch v2.7.37v2.7.38 v2.7.39
github.com/aws/aws-sdk-go-v2/internal/v4a indirect patch v1.4.38v1.4.39 v1.4.40
github.com/aws/aws-sdk-go-v2/service/ecr indirect patch v1.60.6v1.60.7 v1.60.8
github.com/aws/aws-sdk-go-v2/service/ecrpublic indirect patch v1.41.6v1.41.7 v1.41.8
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url indirect patch v1.13.37v1.13.38 v1.13.39
github.com/aws/aws-sdk-go-v2/service/kms indirect patch v1.55.6v1.55.7 v1.55.8
github.com/cenkalti/backoff/v5 indirect major v5.0.3v7.0.0
github.com/digitorus/pkcs7 indirect digest ffadbf305f7944
github.com/fxamacker/cbor/v2 indirect patch v2.9.2v2.9.3
github.com/gaganhr94/docker-credential-acr indirect patch v1.0.2v1.0.3
github.com/go-chi/chi/v5 indirect patch v5.3.1v5.3.2
github.com/go-openapi/runtime indirect patch v0.33.0v0.33.1
github.com/go-openapi/runtime/server-middleware indirect patch v0.33.0v0.33.1
github.com/go-openapi/swag indirect minor v0.28.0v0.29.1
github.com/go-openapi/swag/cmdutils indirect minor v0.28.0v0.29.1
github.com/go-openapi/swag/conv indirect minor v0.28.0v0.29.1
github.com/go-openapi/swag/fileutils indirect minor v0.28.0v0.29.1
github.com/go-openapi/swag/jsonutils indirect minor v0.28.0v0.29.1
github.com/go-openapi/swag/loading indirect minor v0.28.0v0.29.1
github.com/go-openapi/swag/mangling indirect minor v0.28.0v0.29.1
github.com/go-openapi/swag/netutils indirect minor v0.28.0v0.29.1
github.com/go-openapi/swag/pools indirect minor v0.28.0v0.29.1
github.com/go-openapi/swag/stringutils indirect minor v0.28.0v0.29.1
github.com/go-openapi/swag/typeutils indirect minor v0.28.0v0.29.1
github.com/go-openapi/swag/yamlutils indirect minor v0.28.0v0.29.1
github.com/golang-jwt/jwt/v4 indirect major v4.5.2v5.3.1
github.com/google/go-containerregistry require minor v0.21.5v0.22.0
github.com/google/go-containerregistry/pkg/authn/k8schain require digest e8b2b9e3f4ff3c
github.com/google/go-containerregistry/pkg/authn/kubernetes require digest e8b2b9e3f4ff3c
github.com/google/go-github/v73 indirect major v73.0.0v90.0.0
github.com/googleapis/gax-go/v2 indirect minor v2.23.0v2.24.0
github.com/hashicorp/golang-lru require major v1.0.2v2.0.7
github.com/hashicorp/hcl require major v1.0.1-vault-7v2.24.0
github.com/lestrrat-go/dsig indirect minor v1.3.0v1.4.0
github.com/lestrrat-go/jwx/v3 indirect major v3.1.1v4.4.0
github.com/letsencrypt/boulder require minor v0.20260811.0v0.20260825.0
github.com/open-policy-agent/opa indirect patch v1.19.0v1.19.1
github.com/secure-systems-lab/go-securesystemslib indirect patch v0.11.0v0.11.1
github.com/sigstore/cosign/v3 require minor v3.0.5v3.1.3
github.com/sigstore/protobuf-specs require patch v0.5.1v0.5.2
github.com/sigstore/rekor require patch v1.5.3v1.5.4
github.com/sigstore/rekor-tiles/v2 indirect minor v2.2.1v2.3.0
github.com/sigstore/scaffolding require patch v0.7.22v0.7.37
github.com/sigstore/sigstore require patch v1.10.8v1.10.9
github.com/sigstore/sigstore-go require minor v1.1.4v1.3.0
github.com/sigstore/sigstore/pkg/signature/kms/aws require patch v1.10.8v1.10.9
github.com/sigstore/sigstore/pkg/signature/kms/azure require patch v1.10.8v1.10.9
github.com/sigstore/sigstore/pkg/signature/kms/gcp require patch v1.10.8v1.10.9
github.com/sigstore/sigstore/pkg/signature/kms/hashivault require patch v1.10.8v1.10.9
github.com/sigstore/timestamp-authority/v2 indirect patch v2.1.2v2.1.3
github.com/sirupsen/logrus indirect patch v1.10.0v1.10.1 v1.10.2
github.com/stretchr/testify require patch v1.12.0v1.12.1
github.com/theupdateframework/go-tuf require major v0.7.0v2.4.2
github.com/tjfoc/gmsm indirect major v1.4.1v2.0.0
gitlab.com/gitlab-org/api/client-go indirect major v1.25.0v2.58.2 v2.59.1 (+1)
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc replace minor v0.68.0v0.70.0
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp replace minor v0.69.0v0.70.0
go.opentelemetry.io/contrib/instrumentation/runtime replace minor v0.69.0v0.70.0
go.opentelemetry.io/otel replace minor v1.44.0v1.45.0 v1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc indirect minor v1.44.0v1.45.0 v1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp indirect minor v1.44.0v1.45.0 v1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace indirect minor v1.44.0v1.45.0 v1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc indirect minor v1.44.0v1.45.0 v1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp indirect minor v1.44.0v1.45.0 v1.46.0
go.opentelemetry.io/otel/exporters/prometheus indirect minor v0.66.0v0.67.0 v0.68.0
go.opentelemetry.io/otel/exporters/stdout/stdouttrace replace minor v1.44.0v1.45.0 v1.46.0
go.opentelemetry.io/otel/metric replace minor v1.44.0v1.45.0 v1.46.0
go.opentelemetry.io/otel/sdk replace minor v1.44.0v1.45.0 v1.46.0
go.opentelemetry.io/otel/sdk/metric replace minor v1.44.0v1.45.0 v1.46.0
go.opentelemetry.io/otel/trace replace minor v1.44.0v1.45.0 v1.46.0
go.step.sm/crypto indirect minor v0.88.0v0.89.0
go.yaml.in/yaml/v2 indirect major v2.4.4v3.0.5
gomodules.xyz/jsonpatch/v2 indirect major v2.5.0v3.0.1
google.golang.org/grpc require patch v1.83.0v1.83.1 v1.83.2
gopkg.in/evanphx/json-patch.v4 indirect major v4.13.0v5.9.11
k8s.io/api require patch v0.36.3v0.36.4
k8s.io/apiextensions-apiserver indirect patch v0.36.3v0.36.4
k8s.io/apimachinery require patch v0.36.3v0.36.4
k8s.io/client-go require patch v0.36.3v0.36.4
k8s.io/code-generator replace patch v0.36.3v0.36.4
k8s.io/code-generator require patch v0.36.3v0.36.4
k8s.io/kube-openapi replace digest d427ff9be32def
k8s.io/kube-openapi require digest d427ff9be32def

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

AzureAD/microsoft-authentication-library-for-go (github.com/AzureAD/microsoft-authentication-library-for-go)

v1.9.0

Compare Source

What's Changed

Full Changelog: AzureAD/microsoft-authentication-library-for-go@v1.8.0...v1.9.0

ThalesIgnite/crypto11 (github.com/ThalesIgnite/crypto11)

v1.6.8

Compare Source

What's Changed

  • downgrade the go version to 1.25.0 and add go toolchain by @​Nicolas-Peiffer in eclipse-keypont#139
  • fix: restore eclipse-keypont module path; refresh README install command, Go Reference badge and documentation links

Full Changelog: eclipse-keypont/crypto11@v1.6.5...v1.6.8

Module path restored — github.com/eclipse-keypont/crypto11

This release restores the correct module path following the repository move from
github.com/ThalesGroup/crypto11 to github.com/eclipse-keypont/crypto11.

Migrating
go get github.com/eclipse-keypont/crypto11@​v1.6.8
-import "github.com/ThalesGroup/crypto11"
+import "github.com/eclipse-keypont/crypto11"

The old path is deprecated and frozen at
ThalesGroup/crypto11@​v1.6.7.
It will receive no further updates, including security fixes. GitHub still redirects the old
repository URL, but the Go module path must be updated by hand — go get cannot follow it for you.

If you are already on this path: upgrade v1.6.5 → v1.6.8

v1.6.6 and v1.6.7 declare the old module path and exist only to publish the deprecation
notice for github.com/ThalesGroup/crypto11. They are not usable as
github.com/eclipse-keypont/crypto11 and will fail with:

module declares its path as: github.com/ThalesGroup/crypto11
        but was required as: github.com/eclipse-keypont/crypto11

v1.6.8 fixes this, so github.com/eclipse-keypont/crypto11@​latest resolves correctly again.

Go version policy

go.mod targets go 1.25.0 with toolchain go1.25.8. The go directive is kept conservative
so this library does not raise the minimum Go version for projects that import it, while
maintainers build and test with the latest patch toolchain. See #​137 and #​139.

The v1.6.x series is the current stable line. v2.x.y on github.com/eclipse-keypont/crypto11/v2 is in
development (v2.0.0-rc3), which is why pkg.go.dev reports a higher tagged major version.

v1.6.7

Compare Source

v1.6.6

Compare Source

v1.6.5

Compare Source

Full Changelog: eclipse-keypont/crypto11@v1.6.3...v1.6.5

v1.6.4

Compare Source

v1.6.3

Compare Source

v1.6.2

Compare Source

Full Changelog: eclipse-keypont/crypto11@v1.6.0...v1.6.2

v1.6.1

Compare Source

v1.6.0

Compare Source

What's Changed

Full Changelog: eclipse-keypont/crypto11@v1.5.0...v1.6.0

v1.5.0

Compare Source

What's Changed

Full Changelog: eclipse-keypont/crypto11@v1.4.1...v1.5.0

v1.4.1

Compare Source

What's Changed

New Contributors

Full Changelog: eclipse-keypont/crypto11@v1.4.0...v1.4.1

v1.4.0

Compare Source

What's Changed

New Contributors

Full Changelog: eclipse-keypont/crypto11@v1.3.0...v1.4.0

v1.3.0

Compare Source

What's Changed

New Contributors

Full Changelog: eclipse-keypont/crypto11@v1.2.1...v1.3.0

alibabacloud-go/cr-20160607 (github.com/alibabacloud-go/cr-20160607)

v2.0.0

Compare Source

  • Generated 2016-06-07 for cr.
alibabacloud-go/cr-20181201 (github.com/alibabacloud-go/cr-20181201)

v3.2.2

Compare Source

  • Generated 2018-12-01 for cr.

v3.2.1

Compare Source

  • Generated 2018-12-01 for cr.

v3.2.0

Compare Source

  • Support API CreateInstanceCustomizedDomain.
  • Support API DeleteInstanceCustomizedDomain.
  • Support API GetInstanceCustomizedDomain.
  • Support API UpdateInstanceCustomizedDomain.

v3.1.3

Compare Source

  • Update API CreateInstanceEndpointAclPolicy: add request parameters Entries.
  • Update API DeleteInstanceEndpointAclPolicy: add request parameters Entries.

v3.1.2

Compare Source

  • Update API CreateRepoSyncRule: add request parameters LinkId.
  • Update API ListRepoSyncRule: add response parameters Body.SyncRules.$.LinkId.
  • Update API ListRepoSyncTask: add response parameters Body.SyncTasks.$.LinkId.
  • Update API ListRepoSyncTask: add response parameters Body.SyncTasks.$.ModifiedTime.

v3.1.1

Compare Source

  • Update API ListRepoBuildRule: add response parameters Body.BuildRules.$.DestArtifactType.

v3.1.0

Compare Source

  • Support API CreateScanRule.
  • Support API CreateStorageDomainRoutingRule.
  • Support API DeleteScanRule.
  • Support API DeleteStorageDomainRoutingRule.
  • Support API GetScanRule.
  • Support API GetStorageDomainRoutingRule.
  • Support API ListScanRule.
  • Support API UpdateScanRule.
  • Support API UpdateStorageDomainRoutingRule.

v3.0.6

Compare Source

  • Update API GetArtifactSubscriptionRule: add response parameters Body.SourceDomain.
  • Update API ListArtifactSubscriptionRule: add response parameters Body.Rules.$.SourceDomain.

v3.0.5

Compare Source

  • Update API GetInstanceVpcEndpoint: add response parameters Body.LinkedVpcs.$.Issue.

v3.0.4

Compare Source

  • Update API GetArtifactLifecycleRule: add response parameters Body.Policies.
  • Update API ListArtifactLifecycleRule: add response parameters Body.Rules.$.Policies.

v3.0.3

Compare Source

  • Generated 2018-12-01 for cr.

v3.0.2

Compare Source

  • Update API CreateNamespace: add request parameters DefaultRepoConfiguration.
  • Update API GetNamespace: add response parameters Body.DefaultRepoConfiguration.
  • Update API ListNamespace: add response parameters Body.Namespaces.$.DefaultRepoConfiguration.
  • Update API UpdateNamespace: add request parameters DefaultRepoConfiguration.

v3.0.1

Compare Source

  • Update API CreateRepoTagScanTask: add request parameters ScanType.
  • Update API GetRepoTagScanStatus: add request parameters ScanType.

v3.0.0

Compare Source

  • Support API CancelRepoSyncTask.
  • Support API CreateArtifactSubscriptionRule.
  • Support API CreateArtifactSubscriptionTask.
  • Support API DeleteArtifactSubscriptionRule.
  • Support API GetArtifactSubscriptionRule.
  • Support API GetArtifactSubscriptionTask.
  • Support API GetArtifactSubscriptionTaskResult.
  • Support API ListArtifactSubscriptionRule.
  • Support API ListArtifactSubscriptionTask.
  • Support API UpdateArtifactSubscriptionRule.
  • Delete API GetRepoTagLayers.
  • Delete API GetRepoTagManifest.
  • Update API CreateRepoSyncRule: add request parameters RepoNameFilter.
  • Update API GetArtifactBuildRule: add response parameters Body.Parameters.PriorityFile.
  • Update API GetInstanceUsage: add response parameters Body.VpcQuota.
  • Update API GetInstanceUsage: add response parameters Body.VpcUsage.
  • Update API GetRepoSyncTask: add response parameters Body.TaskIssue.
  • Update API ListRepoSyncRule: add response parameters Body.SyncRules.$.RepoNameFilter.
  • Update API ListRepoSyncTask: add response parameters Body.SyncTasks.$.TaskIssue.

v2.5.0

Compare Source

  • Support API CreateArtifactLifecycleRule.
  • Support API DeleteArtifactLifecycleRule.
  • Support API GetArtifactLifecycleRule.
  • Support API ListArtifactLifecycleRule.
  • Support API UpdateArtifactLifecycleRule.

v2.4.0

Compare Source

  • Support API ListScanBaselineByTask.
  • Support API ListScanMaliciousFileByTask.
  • Update API GetArtifactBuildRule: update response param.
  • Update API ListRepository: update param RepoStatus.

v2.3.2

Compare Source

  • Generated 2018-12-01 for cr.

v2.3.1

Compare Source

  • Generated 2018-12-01 for cr.

v2.3.0

Compare Source

  • Generated 2018-12-01 for cr.

v2.2.2

Compare Source

  • Generated 2018-12-01 for cr.

v2.2.1

Compare Source

  • Generated 2018-12-01 for cr.

v2.2.0

Compare Source

  • Generated 2018-12-01 for cr.

v2.1.0

Compare Source

  • Generated 2018-12-01 for cr.

v2.0.1

Compare Source

  • Chain api.

v2.0.0

Compare Source

  • Generated 2018-12-01 for cr.
alibabacloud-go/darabonba-openapi (github.com/alibabacloud-go/darabonba-openapi)

v2.2.4

Compare Source

Sync WebSocket OpenAPI support from aliyun/darabonba-openapi master (#​280).

v2.2.3

Compare Source

v2.2.2

Compare Source

v2.2.1

Compare Source

v2.2.0

Compare Source

v2.1.16

Compare Source

v2.1.15

Compare Source

v2.1.14

Compare Source

v2.1.13

Compare Source

v2.1.12: Realase v2.1.12

Compare Source

v2.1.11

Compare Source

v2.1.10

Compare Source

Full Changelog: alibabacloud-go/darabonba-openapi@v2.1.9...v2.1.10

v2.1.9

Compare Source

v2.1.8

Compare Source

v2.1.7

Compare Source

v2.1.6

Compare Source

v2.1.5

Compare Source

  • update tea core

v2.1.4

Compare Source

v2.1.3

Compare Source

  • Add ToArray in utils

v2.1.2

Compare Source

  • Solve the Token judge error

v2.1.1

Compare Source

  • add GetRules in utils

v2.1.0

Compare Source

  • Upgrade By Darabonba V2

v2.0.12

Compare Source

Full Changelog: alibabacloud-go/darabonba-openapi@v2.0.11...v2.0.12

v2.0.11

Compare Source

Full Changelog: alibabacloud-go/darabonba-openapi@v2.0.10...v2.0.11

v2.0.10

Compare Source

Full Changelog: alibabacloud-go/darabonba-openapi@v2.0.9...v2.0.10

v2.0.9

Compare Source

v2.0.8

Compare Source

Support bearer token credentials request.

v2.0.7

Compare Source

Support extends parameters.

v2.0.6

Compare Source

feat: support extends parameters

v2.0.5

Compare Source

v2.0.4: Release version v2.0.4

v2.0.2

Compare Source

Add gateway client setter.

v2.0.1

Compare Source

Return description and accessDeniedDetail in error info.

v2.0.0

Compare Source

Update with tea-utils.

alibabacloud-go/tea-utils (github.com/alibabacloud-go/tea-utils)

v2.0.9

Compare Source

v2.0.8

Compare Source

v2.0.7

Compare Source

v2.0.6

Compare Source

Support extends query parameters.

v2.0.5

Compare Source

feat: support extends parameters

v2.0.4

Compare Source

Refactor: improve design of nonce

v2.0.3

Compare Source

Support static method AssertAsInteger().

v2.0.2

Compare Source

Fix stringify map value.

v2.0.1

Compare Source

Support ca params for server and client.

v2.0.0

Compare Source

Remove function panic.

aliyun/credentials-go (github.com/aliyun/credentials-go)

v1.4.13

Compare Source

What's Changed

Full Changelog: aliyun/credentials-go@v1.4.12...v1.4.13

aws/aws-sdk-go-v2 (github.com/aws/aws-sdk-go-v2)

v1.43.7

Compare Source

General Highlights

  • Dependency Update: Updated to the latest SDK module versions

Module Highlights

  • github.com/aws/aws-sdk-go-v2: v1.43.7
    • Bug Fix: Make x-amz-checksum-* headers on presigner always show up as headers
  • github.com/aws/aws-sdk-go-v2/feature/s3/manager: v1.22.44
    • Bug Fix: Fix flaky test from feature/s3/manager upload retry
  • github.com/aws/aws-sdk-go-v2/service/amplify: v1.42.0
    • Feature: Increased the maximum allowed length from 255 to 4,096 characters to support longer access tokens.
  • github.com/aws/aws-sdk-go-v2/service/arcregionswitch: v1.14.0
    • Feature: Adds support for Rds switchover read replica for Oracle databases in Region switch plans
  • github.com/aws/aws-sdk-go-v2/service/batch: v1.70.0
    • Feature: AWS Batch now supports a new compute environment type that provides fully managed EC2 capacity with broader compute flexibility than Fargate, including GPU instances, bare metal, and specific instance type selection, without infrastructure management overhead.
  • github.com/aws/aws-sdk-go-v2/service/cloudfront: v1.68.0
    • Feature: Added SigV4a as a supported signing protocol for Origin Access Control (OAC), enabling CloudFront to sign requests to Amazon S3 Multi-Region Access Point (S3-MRAP) origins.
  • github.com/aws/aws-sdk-go-v2/service/directconnect: v1.45.0
    • Feature: This release adds custom route prefix pool allocations for Direct Connect. You can set IPv4 and IPv6 route prefix counts on private and transit virtual interfaces, and view pool size and unallocated counts on connections and LAGs, plus direct connect gateway attachment prefix allocation totals.
  • github.com/aws/aws-sdk-go-v2/service/ec2: v1.322.0
    • Feature: EC2 marks UEFI instance metadata field as sensitive.
  • github.com/aws/aws-sdk-go-v2/service/lambda: v1.102.0
    • Feature: Adds support for full JSON resource-based policies, enabling customers to create, retrieve, update, and delete function resource policies as complete JSON documents.
  • github.com/aws/aws-sdk-go-v2/service/pricingplanmanager: v1.0.5
    • Documentation: Documentation update for the CreateSubscription API to correct the default value of the approval mode parameter. The default value for paid subscriptions is MANUAL, not IMMEDIATE as previously documented. The default value remains IMMEDIATE for FREE tier subscriptions.
  • github.com/aws/aws-sdk-go-v2/service/s3: v1.107.3
    • Bug Fix: Expand S3 operations that check for an error inside an HTTP 200 response (wave 2/4)
    • Bug Fix: Forward the original response body's Closer in S3 200-error handling instead of wrapping it in io.NopCloser, to avoid issues with TCP connection reuse (observed on CompleteMultipartUpload).
  • github.com/aws/aws-sdk-go-v2/service/sagemaker: v1.268.0
    • Feature: Added IAM Identity Center (IdC) support to CreatePartnerApp and UpdatePartnerApp APIs. Added Customer Managed Key (CMK) support to CreateMlflowApp and DescribeMlflowApp.
  • github.com/aws/aws-sdk-go-v2/service/sesv2: v1.67.0
    • Feature: Amazon SES now supports per-message tracking overrides. You can use the new ConfigurationOverrides parameter in SendEmail and SendBulkEmail to enable or disable open and click tracking for individual messages without changing your account-level or configuration set settings.
cenkalti/backoff (github.com/cenkalti/backoff/v5)

v7.0.0

Compare Source

v6.0.1

Compare Source

v6.0.0

Compare Source

fxamacker/cbor (github.com/fxamacker/cbor/v2)

v2.9.3

Compare Source

This release fixes a potential panic when decoding into a time.Time from a CBOR byte string, map, or array under certain conditions.

Not affected: standard CBOR time data (RFC 8949 tag 0 or tag 1), and decoders configured with timeTag = DecTagRequired.

Upgrading to v2.9.3 is recommended.

The panic stack trace was publicly reported on 2026-08-17, and the fix was released the same day. Fuzz testing was extended to cover this class of bug, and fuzzing of v2.9.3 is ongoing.

What's Changed
  • Skip data item when decoding to time.Time fails under certain conditions by @​fxamacker in #​803

Full Changelog: fxamacker/cbor@v2.9.2...v2.9.3

gaganhr94/docker-credential-acr (github.com/gaganhr94/docker-credential-acr)

v1.0.3

Compare Source

v1.0.3 — Stable Release with vulnerability fixes

Changelog

  • bda0c14 Anchor the ACR host regex to reject lookalike hostnames (#​6)
  • d467cd8 Rename project in README (#​2)
  • 1ed482e chore(deps): Bump golang.org/x/crypto from 0.47.0 to 0.52.0 (#​5)
  • 4137665 chore(deps): Bump golang.org/x/net from 0.54.0 to 0.55.0 (#​4)
go-chi/chi (github.com/go-chi/chi/v5)

v5.3.2

Compare Source

What's Changed

  • feat(middleware): add text/markdown, text/csv, text/vtt to default compressible types by @​VojtechVitek in #​1151
  • docs: deployment recipe for middleware.ClientIPFromXFFTrustedProxies() by @​VojtechVitek in #​1111
  • fix: don't drop handlers that collide with a Mount()/Route() pattern by @​VojtechVitek in #​1148
  • Don't duplicate methods in Allow: header for 405 responses by @​flimzy in #​1029
  • fix(middleware): reject catch-all compress wildcards by @​VojtechVitek in #​1156
    • middleware.NewCompressor(level, "/*") never worked and silently compressed nothing. Instead of turning it into a compress-everything catch-all (as proposed in #​868 and #​1121), we decided to reject both "/" and "/*" at construction and panic. Compressing every response wastes CPU on already-compressed types (zip, jpeg, png), which is why the middleware keeps a curated default list. Users should pass explicit content types.

Full Changelog: go-chi/chi@v5.3.1...v5.3.2

go-openapi/runtime (github.com/go-openapi/runtime)

v0.33.1

Compare Source

0.33.1 - 2026-08-21

Full Changelog: go-openapi/runtime@v0.33.0...v0.33.1

15 commits in this release.


Fixed bugs
Documentation
Code quality
Testing
Miscellaneous tasks

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux

Copy link
Copy Markdown
Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: go.sum
Command failed: go get -t ./...
go: github.com/ThalesIgnite/crypto11@v1.6.8: parsing go.mod:
	module declares its path as: github.com/eclipse-keypont/crypto11
	        but was required as: github.com/ThalesIgnite/crypto11

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/release-1.0/go-deps branch 8 times, most recently from ee30507 to 22689f0 Compare August 26, 2026 03:19
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/release-1.0/go-deps branch from 22689f0 to c07bc0c Compare August 26, 2026 07:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants