Skip to content

Bump the go-modules group across 1 directory with 2 updates - #30

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-modules-71394dc419
Closed

Bump the go-modules group across 1 directory with 2 updates#30
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-modules-71394dc419

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 16, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-modules group with 2 updates in the / directory: github.com/securego/gosec/v2 and golang.org/x/vuln.

Updates github.com/securego/gosec/v2 from 2.27.1 to 2.28.0

Release notes

Sourced from github.com/securego/gosec/v2's releases.

v2.28.0

Changelog

  • 9e75c0576c9878035d4221392108d458abe10fc3 feat(G101): detect AWS temporary access keys (#1702)
  • 14f493ab92f212e1f3d69aeaa561989e5baf9d6f Update to go version 1.26.5 and 1.25.12 (#1704)
  • ffd5ba1d3354928fae89ac31912bd1d730798799 Update all dependencies (#1703)
  • 849570622f56a251c015c0e2417aebafc0216e17 Update all dependencies (#1699)
  • 11023e51e1f46c4ea63315bdb7670f073442168f Update all dependencies (#1698)
  • f88a0781159d73052ba792962e624749904783d6 fix: min+max G115 false positives (#1697)
  • 6a008f60b8f7f3d7fae8f126984a9df5d4b7e0cf Update all dependencies (#1696)
  • caf8857bbd3276599d0176b0528e9712bb0b5bec fix(G404): flag missing math/rand weak-random functions (#1694)
  • cbef395cb1e2e3a35f6223f5b97f1657f7144797 Update all dependencies (#1695)
  • f1c81de5fcdf7b466b229fb24ca02d1a8406dd09 Update all dependencies (#1693)
  • 9addc97cefc9460a114e3c36f536b935da3b98c9 Update to go version 1.26.4 and 1.25.11 (#1690)
  • 92ed8df32846e85d4e81b0b62012567afddfdc95 Update the gosec in the Github action to v2.27.1 (#1688)
Commits

Updates golang.org/x/vuln from 1.4.0 to 1.6.0

Commits
  • 19b0bb6 go.mod: update golang.org/x dependencies
  • 3e6f44f go.mod: update golang.org/x dependencies
  • c3d51cb all: update to x/tools@0602b30930e3
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-modules group with 2 updates in the / directory: [github.com/securego/gosec/v2](https://github.com/securego/gosec) and [golang.org/x/vuln](https://github.com/golang/vuln).


Updates `github.com/securego/gosec/v2` from 2.27.1 to 2.28.0
- [Release notes](https://github.com/securego/gosec/releases)
- [Commits](securego/gosec@v2.27.1...v2.28.0)

Updates `golang.org/x/vuln` from 1.4.0 to 1.6.0
- [Release notes](https://github.com/golang/vuln/releases)
- [Commits](golang/vuln@v1.4.0...v1.6.0)

---
updated-dependencies:
- dependency-name: github.com/securego/gosec/v2
  dependency-version: 2.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules
- dependency-name: golang.org/x/vuln
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Dependabot update go Pull requests that update go code minor Minor-level Semver Bump labels Jul 16, 2026
@ben-vaughan-nttd

Copy link
Copy Markdown
Contributor

Superseded by #33, which rolls up all open dependabot updates and configures batching for future GitHub Actions updates.

@dependabot @github

dependabot Bot commented on behalf of github Aug 13, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/go_modules/go-modules-71394dc419 branch August 13, 2026 13:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependabot update go Pull requests that update go code minor Minor-level Semver Bump

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant