build(deps): Bump the go_modules group with 8 updates#658
Closed
dependabot[bot] wants to merge 1 commit intomainfrom
Closed
build(deps): Bump the go_modules group with 8 updates#658dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Contributor
|
@dependabot rebase |
11e815a to
17e3b7f
Compare
Contributor
|
@dependabot rebase |
Bumps the go_modules group with 8 updates: | Package | From | To | | --- | --- | --- | | [github.com/containers/image/v5](https://github.com/containers/image) | `5.24.2` | `5.29.3` | | [github.com/moby/buildkit](https://github.com/moby/buildkit) | `0.11.4` | `0.12.5` | | [github.com/anchore/stereoscope](https://github.com/anchore/stereoscope) | `0.0.0-20230925132944-bf05af58eb44` | `0.0.1` | | [github.com/cloudflare/circl](https://github.com/cloudflare/circl) | `1.3.3` | `1.3.7` | | [github.com/containerd/containerd](https://github.com/containerd/containerd) | `1.7.0` | `1.7.11` | | [github.com/docker/docker](https://github.com/docker/docker) | `24.0.6+incompatible` | `24.0.7+incompatible` | | [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) | `5.11.0` | `5.13.0` | | [github.com/sigstore/rekor](https://github.com/sigstore/rekor) | `1.0.1` | `1.2.2` | Updates `github.com/containers/image/v5` from 5.24.2 to 5.29.3 - [Release notes](https://github.com/containers/image/releases) - [Commits](containers/image@v5.24.2...v5.29.3) Updates `github.com/moby/buildkit` from 0.11.4 to 0.12.5 - [Release notes](https://github.com/moby/buildkit/releases) - [Commits](moby/buildkit@v0.11.4...v0.12.5) Updates `github.com/anchore/stereoscope` from 0.0.0-20230925132944-bf05af58eb44 to 0.0.1 - [Release notes](https://github.com/anchore/stereoscope/releases) - [Changelog](https://github.com/anchore/stereoscope/blob/main/RELEASE.md) - [Commits](https://github.com/anchore/stereoscope/commits/v0.0.1) Updates `github.com/cloudflare/circl` from 1.3.3 to 1.3.7 - [Release notes](https://github.com/cloudflare/circl/releases) - [Commits](cloudflare/circl@v1.3.3...v1.3.7) Updates `github.com/containerd/containerd` from 1.7.0 to 1.7.11 - [Release notes](https://github.com/containerd/containerd/releases) - [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md) - [Commits](containerd/containerd@v1.7.0...v1.7.11) Updates `github.com/docker/docker` from 24.0.6+incompatible to 24.0.7+incompatible - [Release notes](https://github.com/docker/docker/releases) - [Commits](moby/moby@v24.0.6...v24.0.7) Updates `github.com/go-git/go-git/v5` from 5.11.0 to 5.13.0 - [Release notes](https://github.com/go-git/go-git/releases) - [Commits](go-git/go-git@v5.11.0...v5.13.0) Updates `github.com/sigstore/rekor` from 1.0.1 to 1.2.2 - [Release notes](https://github.com/sigstore/rekor/releases) - [Changelog](https://github.com/sigstore/rekor/blob/main/CHANGELOG.md) - [Commits](sigstore/rekor@v1.0.1...v1.2.2) --- updated-dependencies: - dependency-name: github.com/containers/image/v5 dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/moby/buildkit dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/anchore/stereoscope dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/cloudflare/circl dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/containerd/containerd dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/docker/docker dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/go-git/go-git/v5 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/sigstore/rekor dependency-type: indirect dependency-group: go_modules ... Signed-off-by: dependabot[bot] <support@github.com>
17e3b7f to
4119d81
Compare
hallyn
approved these changes
Jul 5, 2025
Contributor
|
@dependabot recreate |
Contributor
Author
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the go_modules group with 8 updates:
5.24.25.29.30.11.40.12.50.0.0-20230925132944-bf05af58eb440.0.11.3.31.3.71.7.01.7.1124.0.6+incompatible24.0.7+incompatible5.11.05.13.01.0.11.2.2Updates
github.com/containers/image/v5from 5.24.2 to 5.29.3Release notes
Sourced from github.com/containers/image/v5's releases.
... (truncated)
Commits
3e684b1[release-5.29] Bump to v5.29.3e894804Merge pull request #2418 from mtrmac/digest-unmarshal-5.296e25805Validate the tags returned by a registry086c760Call .Validate() before digest.Digest.String() if necessary0860c58Refactor the error handling further7b58b43Refactor the error handling path of saveStreamaf94ba1Call .Validate() before digest.Hex() / digest.Encoded()9c49ca1Validate digests before using them534068fMerge pull request #2270 from TomSweeneyRedHat/dev/tsweeney/ddaemon0111e79[release-5.29] Bump to v5.29.3-devUpdates
github.com/moby/buildkitfrom 0.11.4 to 0.12.5Release notes
Sourced from github.com/moby/buildkit's releases.
... (truncated)
Commits
bac3f2bupdate runc to v1.1.12f781267exec: add extra validation for submount sourcesd089e0boci: fix error handling on submount calls00fe637executor: recheck mount stub path within root after container run92cc595llbsolver: make sure interactive container API validates entitlements5026d95gateway: pass executor with build and not access worker directly7718bd5pb: add extra validation to protobuf typese1924dcsourcepolicy: add validations for nil values96663ddexporter: add validation for platforms key value481d9c4exporter: add validation for invalid platormUpdates
github.com/anchore/stereoscopefrom 0.0.0-20230925132944-bf05af58eb44 to 0.0.1Release notes
Sourced from github.com/anchore/stereoscope's releases.
Commits
Updates
github.com/cloudflare/circlfrom 1.3.3 to 1.3.7Release notes
Sourced from github.com/cloudflare/circl's releases.
Commits
c48866bReleasing CIRCL v1.3.775ef91ekyber: remove division by q in ciphertext compression899732abuild(deps): bump golang.org/x/crypto99f0f71Releasing CIRCL v1.3.6e728d0dApply thibmeu code review suggestionsceb2d90Updating blindrsa to be compliant with RFC9474.44133f7spelling: trippedc2076d6spelling: transposesdad2166spelling: title171c418spelling: thresholdUpdates
github.com/containerd/containerdfrom 1.7.0 to 1.7.11Release notes
Sourced from github.com/containerd/containerd's releases.
... (truncated)
Changelog
Sourced from github.com/containerd/containerd's changelog.
... (truncated)
Commits
64b8a81Merge pull request #9491 from dmcgowan/prepare-1.7.11ea5a477Merge pull request #9352 from thaJeztah/1.7_update_golang_1.20.1167d356cMerge pull request from GHSA-7ww5-4wqc-m92cdfae68bPrepare release notes for v1.7.11de6d8a8Merge pull request #9482 from ambarve/sn_cleanup_1.7ed7c689Don't block snapshot garbage collection on Remove failures467de56Merge pull request #9481 from ruiwen-zhao/cri-ud94f8ffMerge pull request #9483 from dmcgowan/backport-1.7-fix-otel-http1fdefddAdd warning for CRIU config usage8e06899Merge pull request #9479 from ruiwen-zhao/cri-api-warningUpdates
github.com/docker/dockerfrom 24.0.6+incompatible to 24.0.7+incompatibleRelease notes
Sourced from github.com/docker/docker's releases.
Commits
311b9ffMerge pull request #46697 from thaJeztah/24.0_backport_restart_nocancelaf60804Merge pull request from GHSA-jq35-85cj-fj4p3cf363eMerge pull request #46709 from thaJeztah/24.0_backport_bump_compress05d7386daemon: daemon.containerRestart: don't cancel restart on context cancel649c944Merge pull request #46703 from thaJeztah/24.0_backport_atomic-layer-data-write9b20b1aMerge pull request #46702 from thaJeztah/24.0_backport_releaseNetwork_Network...dd37b0bvendor: github.com/klauspost/compress v1.17.27058c0dvendor: github.com/klauspost/compress v1.16.557bd388daemon: overlay2: Write layer metadata atomically05d95fddaemon: release sandbox even when NetworkDisabledUpdates
github.com/go-git/go-git/v5from 5.11.0 to 5.13.0Release notes
Sourced from github.com/go-git/go-git/v5's releases.
... (truncated)
Commits
94bd4afMerge pull request #1261 from BeChris/issue6808b7f5baMerge pull request #1262 from go-git/dependabot/go_modules/github.com/elazarl...41d80a0build: bump github.com/elazarl/goproxy4998140git: worktree_commit, sanitize author and commiter name and email before crea...9049625Merge pull request #1260 from go-git/dependabot/github_actions/github/codeql-...dae48b4build: bump github/codeql-action from 3.27.9 to 3.28.07d6fbc2Merge pull request #1220 from BeChris/accept_uppercase_hexa_in_pktline_length62a77b7plumbing: Fix invalid reference name error while cloning branches containing ...5e11196plumbing: format/pktline, accept upercase hexadecimal value as pktline length...65f5e1aMerge pull request #1256 from go-git/dependabot/go_modules/golang-org-232a611e2dUpdates
github.com/sigstore/rekorfrom 1.0.1 to 1.2.2Release notes
Sourced from github.com/sigstore/rekor's releases.
... (truncated)
Changelog
Sourced from github.com/sigstore/rekor's changelog.
... (truncated)
Commits
9c13e97changelog for v1.2.2 (#1570)aacc6aefuzz: Add utility to create structured jar bytes (#1548)beae36fbuild(deps): bump sigstore/cosign-installer from 3.1.0 to 3.1.1 (#1567)67b37f1build(deps): bump go.step.sm/crypto from 0.32.1 to 0.32.2 (#1568)a1349daswap killswitch for 'docker-compose restart' (#1562)a9f13f6build(deps): bump sigstore/cosign-installer from 3.0.5 to 3.1.0 (#1564)3c405d3build(deps): bump golang from8f958bfto344193a(#1563)0ac9ff7build(deps): bump google.golang.org/protobuf from 1.30.0 to 1.31.0 (#1565)c17612echore: replacegithub.com/ghodss/yamlwithsigs.k8s.io/yaml(#1558)c2e3149pass down error with message instead of nil (#1560Description has been truncated