Skip to content

chore(deps): bump the go-dependencies group across 1 directory with 3 updates#42

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/go_modules/go-dependencies-9b0d88e04a
Open

chore(deps): bump the go-dependencies group across 1 directory with 3 updates#42
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/go_modules/go-dependencies-9b0d88e04a

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 9, 2026

Bumps the go-dependencies group with 3 updates in the / directory: github.com/coredns/coredns, go.pixelfactory.io/pkg/observability/log and go.pixelfactory.io/pkg/server.

Updates github.com/coredns/coredns from 1.14.1 to 1.14.2

Release notes

Sourced from github.com/coredns/coredns's releases.

v1.14.2

This release adds the new proxyproto plugin to support Proxy Protocol and preserve client IPs behind load balancers. It also includes enhancements such as improved DNS logging metadata and stronger randomness for loop detection (CVE-2026-26018), along with several bug fixes including TLS+IPv6 forwarding, improved CNAME handling and rewriting, allowing jitter disabling, prevention of an ACL bypass (CVE-2026-26017), and a Kubernetes plugin crash fix. In addition, the release updates the build to Go 1.26.1, which include security fixes addressing CVE-2026-27137, CVE-2026-27138, CVE-2026-27139, CVE-2026-25679, and CVE-2026-27142.

Brought to You By

Adphi Henrik Gerdes hide Kelly Kane Shiv Tyagi vflaux Ville Vesilehto yangsenzk Yong Tang YOUNEVSKY

Noteworthy Changes

Commits
  • dd1df4f Update release note for upcoming 1.14.2 (#7897)
  • 8c271b8 Bump golang to 1.26.1 (#7902)
  • 51a11b3 plugin/reload: Allow disabling jitter with 0s (#7896)
  • 5d97c15 Bump version to 1.14.2 (#7895)
  • ba3b6ce build(deps): bump github.com/aws/aws-sdk-go-v2/service/route53 (#7893)
  • b760b24 build(deps): bump google.golang.org/api from 0.267.0 to 0.269.0 (#7890)
  • a012d9e build(deps): bump github.com/aws/aws-sdk-go-v2/service/secretsmanager (#7892)
  • 465d75b build(deps): bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 (#7885)
  • 86d9bc7 build: add grpcnotrace tag to exclude x/net/trace (#7884)
  • 442f106 build(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 (#7886)
  • Additional commits viewable in compare view

Updates go.pixelfactory.io/pkg/observability/log from 1.4.3 to 1.5.0

Release notes

Sourced from go.pixelfactory.io/pkg/observability/log's releases.

v1.5.0

1.5.0 (2026-01-29)

Features

  • enhance SECURITY.md with comprehensive vulnerability disclosure policy (#27) (83866f1)
Changelog

Sourced from go.pixelfactory.io/pkg/observability/log's changelog.

1.5.0 (2026-01-29)

Features

  • enhance SECURITY.md with comprehensive vulnerability disclosure policy (#27) (83866f1)
Commits
  • 4e6f65d chore(main): release 1.5.0 (#28)
  • a87ff21 chore(deps): bump actions/checkout from 4.3.1 to 6.0.2 (#30)
  • fb46b84 chore(deps): bump the github-actions group with 2 updates (#29)
  • 1b4f865 ci: Add Lint PR workflow to validate pull request titles (#31)
  • 83866f1 feat: enhance SECURITY.md with comprehensive vulnerability disclosure policy ...
  • See full diff in compare view

Updates go.pixelfactory.io/pkg/server from 0.5.1 to 0.7.1

Release notes

Sourced from go.pixelfactory.io/pkg/server's releases.

v0.7.1

0.7.1 (2026-01-30)

Bug Fixes

  • prevent fuzz test timeout by reusing a shared logger (#32) (09e8fda)

v0.7.0

Features

  • add PR title validation workflow (ef9a412)

v0.6.0

0.6.0 (2026-01-23)

Features

  • Add workflow_dispatch trigger to release-please workflow (#18) (7cf6bb2)
Changelog

Sourced from go.pixelfactory.io/pkg/server's changelog.

0.7.1 (2026-01-30)

Bug Fixes

  • prevent fuzz test timeout by reusing a shared logger (#32) (09e8fda)

0.7.0 (2026-01-26)

Features

  • add PR title validation workflow (ef9a412)

0.6.0 (2026-01-23)

Features

  • Add workflow_dispatch trigger to release-please workflow (#18) (7cf6bb2)
Commits
  • 679ce7f chore(main): release 0.7.1 (#33)
  • 09e8fda fix: prevent fuzz test timeout by reusing a shared logger (#32)
  • ec8cfe9 [StepSecurity] Apply security best practices (#31)
  • dc65b42 chore(deps): bump go.pixelfactory.io/pkg/observability/log (#27)
  • 699cda7 chore(deps): bump the github-actions group with 2 updates (#28)
  • dd3c80e chore(deps): bump amannn/action-semantic-pull-request (#29)
  • 1dac161 chore(deps): bump actions/checkout from 4.3.1 to 6.0.2 (#30)
  • 9d0e789 chore(main): release 0.7.0 (#25)
  • ef9a412 feat: add PR title validation workflow
  • e1e4ee7 chore(main): release 0.6.0 (#19)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

… updates

Bumps the go-dependencies group with 3 updates in the / directory: [github.com/coredns/coredns](https://github.com/coredns/coredns), [go.pixelfactory.io/pkg/observability/log](https://github.com/pixelfactory-go/observability-log) and [go.pixelfactory.io/pkg/server](https://github.com/pixelfactory-go/server).


Updates `github.com/coredns/coredns` from 1.14.1 to 1.14.2
- [Release notes](https://github.com/coredns/coredns/releases)
- [Commits](coredns/coredns@v1.14.1...v1.14.2)

Updates `go.pixelfactory.io/pkg/observability/log` from 1.4.3 to 1.5.0
- [Release notes](https://github.com/pixelfactory-go/observability-log/releases)
- [Changelog](https://github.com/pixelfactory-go/observability-log/blob/main/CHANGELOG.md)
- [Commits](pixelfactory-go/observability-log@v1.4.3...v1.5.0)

Updates `go.pixelfactory.io/pkg/server` from 0.5.1 to 0.7.1
- [Release notes](https://github.com/pixelfactory-go/server/releases)
- [Changelog](https://github.com/pixelfactory-go/server/blob/main/CHANGELOG.md)
- [Commits](pixelfactory-go/server@v0.5.1...v0.7.1)

---
updated-dependencies:
- dependency-name: github.com/coredns/coredns
  dependency-version: 1.14.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: go.pixelfactory.io/pkg/observability/log
  dependency-version: 1.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: go.pixelfactory.io/pkg/server
  dependency-version: 0.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Mar 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants