generated from sigstore/sigstore-project-template
    
        
        - 
                Notifications
    You must be signed in to change notification settings 
- Fork 67
chore(deps): Bump the minor-patch group across 1 directory with 19 updates #1850
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
          
     Closed
      
      
    Conversation
  
    
      This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
      Learn more about bidirectional Unicode characters
    
  
  
    
    …dates Bumps the minor-patch group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go) | `1.55.6` | `1.55.7` | | [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry) | `0.20.3` | `0.20.6` | | [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) | `2.5.0` | `2.5.1` | | [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) | `1.9.4` | `1.9.5` | | [golang.org/x/time](https://github.com/golang/time) | `0.11.0` | `0.12.0` | | [github.com/sigstore/scaffolding](https://github.com/sigstore/scaffolding) | `0.7.22` | `0.7.23` | | [github.com/sigstore/sigstore/pkg/signature/kms/aws](https://github.com/sigstore/sigstore) | `1.9.4` | `1.9.5` | | [github.com/sigstore/sigstore/pkg/signature/kms/azure](https://github.com/sigstore/sigstore) | `1.9.4` | `1.9.5` | | [github.com/sigstore/sigstore/pkg/signature/kms/gcp](https://github.com/sigstore/sigstore) | `1.9.4` | `1.9.5` | | [github.com/sigstore/sigstore/pkg/signature/kms/hashivault](https://github.com/sigstore/sigstore) | `1.9.4` | `1.9.5` | Updates `github.com/aws/aws-sdk-go` from 1.55.6 to 1.55.7 - [Release notes](https://github.com/aws/aws-sdk-go/releases) - [Changelog](https://github.com/aws/aws-sdk-go/blob/main/CHANGELOG_PENDING.md) - [Commits](aws/aws-sdk-go@v1.55.6...v1.55.7) Updates `github.com/google/go-containerregistry` from 0.20.3 to 0.20.6 - [Release notes](https://github.com/google/go-containerregistry/releases) - [Changelog](https://github.com/google/go-containerregistry/blob/main/.goreleaser.yml) - [Commits](google/go-containerregistry@v0.20.3...v0.20.6) Updates `github.com/sigstore/cosign/v2` from 2.5.0 to 2.5.1 - [Release notes](https://github.com/sigstore/cosign/releases) - [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md) - [Commits](sigstore/cosign@v2.5.0...v2.5.1) Updates `github.com/sigstore/sigstore` from 1.9.4 to 1.9.5 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.9.4...v1.9.5) Updates `golang.org/x/crypto` from 0.37.0 to 0.39.0 - [Commits](golang/crypto@v0.37.0...v0.39.0) Updates `golang.org/x/net` from 0.39.0 to 0.41.0 - [Commits](golang/net@v0.39.0...v0.41.0) Updates `golang.org/x/time` from 0.11.0 to 0.12.0 - [Commits](golang/time@v0.11.0...v0.12.0) Updates `k8s.io/api` from 0.32.3 to 0.33.1 - [Commits](kubernetes/api@v0.32.3...v0.33.1) Updates `k8s.io/apimachinery` from 0.32.3 to 0.33.1 - [Commits](kubernetes/apimachinery@v0.32.3...v0.33.1) Updates `k8s.io/client-go` from 0.32.3 to 0.33.1 - [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md) - [Commits](kubernetes/client-go@v0.32.3...v0.33.1) Updates `github.com/Azure/azure-sdk-for-go/sdk/azidentity` from 1.9.0 to 1.10.0 - [Release notes](https://github.com/Azure/azure-sdk-for-go/releases) - [Changelog](https://github.com/Azure/azure-sdk-for-go/blob/main/documentation/go-mgmt-sdk-release-guideline.md) - [Commits](Azure/azure-sdk-for-go@sdk/azcore/v1.9.0...sdk/azcore/v1.10.0) Updates `github.com/docker/docker` from 28.1.1+incompatible to 28.2.2+incompatible - [Release notes](https://github.com/docker/docker/releases) - [Commits](moby/moby@v28.1.1...v28.2.2) Updates `github.com/sigstore/protobuf-specs` from 0.4.1 to 0.4.2 - [Release notes](https://github.com/sigstore/protobuf-specs/releases) - [Changelog](https://github.com/sigstore/protobuf-specs/blob/main/CHANGELOG.md) - [Commits](sigstore/protobuf-specs@v0.4.1...v0.4.2) Updates `github.com/sigstore/scaffolding` from 0.7.22 to 0.7.23 - [Release notes](https://github.com/sigstore/scaffolding/releases) - [Changelog](https://github.com/sigstore/scaffolding/blob/main/release.md) - [Commits](sigstore/scaffolding@v0.7.22...v0.7.23) Updates `github.com/sigstore/sigstore-go` from 0.7.2 to 1.0.0 - [Release notes](https://github.com/sigstore/sigstore-go/releases) - [Commits](sigstore/sigstore-go@v0.7.2...v1.0.0) Updates `github.com/sigstore/sigstore/pkg/signature/kms/aws` from 1.9.4 to 1.9.5 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.9.4...v1.9.5) Updates `github.com/sigstore/sigstore/pkg/signature/kms/azure` from 1.9.4 to 1.9.5 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.9.4...v1.9.5) Updates `github.com/sigstore/sigstore/pkg/signature/kms/gcp` from 1.9.4 to 1.9.5 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.9.4...v1.9.5) Updates `github.com/sigstore/sigstore/pkg/signature/kms/hashivault` from 1.9.4 to 1.9.5 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.9.4...v1.9.5) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go dependency-version: 1.55.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/google/go-containerregistry dependency-version: 0.20.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/cosign/v2 dependency-version: 2.5.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/sigstore dependency-version: 1.9.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: golang.org/x/crypto dependency-version: 0.39.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: golang.org/x/net dependency-version: 0.41.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: golang.org/x/time dependency-version: 0.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: k8s.io/api dependency-version: 0.33.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: k8s.io/apimachinery dependency-version: 0.33.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: k8s.io/client-go dependency-version: 0.33.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: github.com/Azure/azure-sdk-for-go/sdk/azidentity dependency-version: 1.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: github.com/docker/docker dependency-version: 28.2.2+incompatible dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: github.com/sigstore/protobuf-specs dependency-version: 0.4.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/scaffolding dependency-version: 0.7.23 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/sigstore-go dependency-version: 1.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: minor-patch - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/aws dependency-version: 1.9.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/azure dependency-version: 1.9.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/gcp dependency-version: 1.9.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/hashivault dependency-version: 1.9.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch ... Signed-off-by: dependabot[bot] <[email protected]>
| Looks like these dependencies are updatable in another way, so this is no longer needed. | 
  
    Sign up for free
    to join this conversation on GitHub.
    Already have an account?
    Sign in to comment
  
      Labels
  Add this suggestion to a batch that can be applied as a single commit.
  This suggestion is invalid because no changes were made to the code.
  Suggestions cannot be applied while the pull request is closed.
  Suggestions cannot be applied while viewing a subset of changes.
  Only one suggestion per line can be applied in a batch.
  Add this suggestion to a batch that can be applied as a single commit.
  Applying suggestions on deleted lines is not supported.
  You must change the existing code in this line in order to create a valid suggestion.
  Outdated suggestions cannot be applied.
  This suggestion has been applied or marked resolved.
  Suggestions cannot be applied from pending reviews.
  Suggestions cannot be applied on multi-line comments.
  Suggestions cannot be applied while the pull request is queued to merge.
  Suggestion cannot be applied right now. Please check back later.
  
    
  
    
Bumps the minor-patch group with 10 updates in the / directory:
1.55.61.55.70.20.30.20.62.5.02.5.11.9.41.9.50.11.00.12.00.7.220.7.231.9.41.9.51.9.41.9.51.9.41.9.51.9.41.9.5Updates
github.com/aws/aws-sdk-gofrom 1.55.6 to 1.55.7Release notes
Sourced from github.com/aws/aws-sdk-go's releases.
Commits
163aadarelease v1.55.7 (2025-04-22) (#5346)9eb2bfdAbort multi part download if the object is modified during download8d203ccUpdate bug-report.ymlUpdates
github.com/google/go-containerregistryfrom 0.20.3 to 0.20.6Release notes
Sourced from github.com/google/go-containerregistry's releases.
Commits
59a4b85Bump some deps (#2110)5b10395Ensure that tag name is not empty if name contains colon (#2094)4eb8c4dUpdate validator action (#2106)78d4a6eUpdate provenance action (#2105)33840ffUpdate goreleaser permissions (#2104)8d47c37Update CodeQL permissions (#2103)a61de15implement TextMarshaler/JSONMarshaler more consistently (#2097)1d5b256bump go version + bump deps (#2093)ccaa0d6Migrate linter to v2 (#2096)098045dbuild(deps): bump docker/docker to v28.0.0+incompatible (#2071)Updates
github.com/sigstore/cosign/v2from 2.5.0 to 2.5.1Commits
a7345fbAdd Rekor v2 support for trusted-root create (#4242)3df894eAdd baseUrl and Uri to trusted-root create commandfb26ffdupdate builder to use go1.24.4 (#4241)5b82c30Bump to sigstore-go v1.0, fix lint errors (#4240)a8fb9eechore(deps): bump github.com/open-policy-agent/opa from 1.4.2 to 1.5.1 (#4233)8bbd493chore(deps): bump k8s.io/client-go from 0.28.3 to 0.33.1 (#4235)32a2d62Upgrade to TUF v2 client with trusted root95bec1aRun reusable dependency review workflow from main (#4239)9b508f5chore(deps): bump google.golang.org/api from 0.234.0 to 0.236.0 (#4236)08c0240chore(deps): bump gitlab.com/gitlab-org/api/client-go (#4231)Updates
github.com/sigstore/sigstorefrom 1.9.4 to 1.9.5Release notes
Sourced from github.com/sigstore/sigstore's releases.
Commits
75efc00build(deps): Bump localstack/localstack in /test/e2e in the all group (#2092)32d462fbuild(deps): Bump the all group in /test/e2e with 3 updates (#2091)007cd79build(deps): Bump the all group in /test/e2e with 3 updates (#2074)bbd546bbuild(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (#2087)540126bbuild(deps): Bump google.golang.org/api in /pkg/signature/kms/gcp (#2088)0996ba4build(deps): Bump actions/dependency-review-action in the all group (#2085)7eafe24build(deps): Bump golang.org/x/oauth2 from 0.29.0 to 0.30.0 (#2081)d771343build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2082)1b0bd69build(deps): Bump the all group with 2 updates (#2078)e2f3b71build(deps): Bump google.golang.org/api in /pkg/signature/kms/gcp (#2084)Updates
golang.org/x/cryptofrom 0.37.0 to 0.39.0Commits
3bf9d2assh/test: skip KEX test if unsupported by system SSH client9bab967go.mod: update golang.org/x dependencies4f9f0cax509roots/fallback: add init time benchmarkeac7cf0x509roots/fallback: move parsing code to a non-generated file18228cdacme: return err from deprecated TLS-SNI-[01|02] functions73f6362acme: remove dead codeebc8e46ssh: add server side support for Diffie Hellman Group Exchangee944286ssh: expose negotiated algorithms78a1fd7ssh: automatically add [email protected] KEX aliasac58737ssh: export supported algorithmsUpdates
golang.org/x/netfrom 0.39.0 to 0.41.0Commits
6e41caego.mod: update golang.org/x dependencies15f7d40http2: correctly wrap ErrFrameTooLarge in Framer.ReadFrameef33bc0internal/http3: use bubbled context in synctest tests919c6bchttp2: use an array instead of a map in typeFrameParserbae01a7trace: add missing td tag7d6e62ago.mod: update golang.org/x dependenciesea0c1d9internal/timeseries: use built-in max/min to simplify the code3e7a445quic: skip packet numbers for optimistic ack defense3f563d3quic: use an enum for sentPacket statea3b6e77quic: don't re-lose packets when discarding keysUpdates
golang.org/x/timefrom 0.11.0 to 0.12.0Commits
1616a7frate: skip time.Now call in Sometimes.Do unless necessaryUpdates
k8s.io/apifrom 0.32.3 to 0.33.1Commits
04f698eUpdate dependencies to v0.33.1 tag16cedc7Merge pull request #131088 from atiratree/rename-terminating-replicas-fgdc88679Merge pull request #131103 from ahrtr/etcd_sdk_202503284a456a2bump etcd 3.5.21 sdk96e38c9rename DeploymentPodReplacementPolicy FG to DeploymentReplicaSetTerminatingRe...c21a017Merge pull request #129970 from mortent/AddResourceV1beta2APId0673dbRun make update118546dMerge pull request #130556 from sreeram-venkitesh/kep-4960-container-stop-sig...f9401a3Merge pull request #130797 from jm-franc/configurable-tolerance9b3e544Generated UPDATE_COMPATIBILITY_FIXTURE_DATAUpdates
k8s.io/apimachineryfrom 0.32.3 to 0.33.1Commits
173776aMerge pull request #131708tigrato/automated-cherry-pick-of-#131702a3d1fdefix: fixes a possible panic inNewYAMLToJSONDecoder955939fbump etcd 3.5.21 sdke8a77bdMerge pull request #130910 from googs1025/fix/datarace7e8c77eMerge pull request #130906 from serathius/streaming-validation27fd396flake: fix data race for func TestBackoff_Step8bcc6f1Update kube-openapi and integrate streaming tags validation6ce776cMerge pull request #130857 from thockin/kk_small_vg_diffsf2c94d6Comment on origin and JSON schemab63ba07Use origin in validateFalse's own testUpdates
k8s.io/client-gofrom 0.32.3 to 0.33.1Commits
e7397e5Update dependencies to v0.33.1 tagecbbb06bump etcd 3.5.21 sdk2086688Merge pull request #129970 from mortent/AddResourceV1beta2APIdba34c7Run make updatee359642Merge pull request #130556 from sreeram-venkitesh/kep-4960-container-stop-sig...3bf0a05Merge pull request #130797 from jm-franc/configurable-tolerance7a03a3bGenerated files1676bebRefresh autogenerated files following the configurable tolerance updates.387edb8Merge pull request #130967 from aojea/listers21dc3b4benchmark to show inefficient linear search lookupUpdates
github.com/Azure/azure-sdk-for-go/sdk/azidentityfrom 1.9.0 to 1.10.0Release notes
Sourced from github.com/Azure/azure-sdk-for-go/sdk/azidentity's releases.
Commits
91de7c6Prep azcore for release (#22481)6e61c5eUpdating changelog for v1.1.1 release (#22479)f1530dcUpdates for aztables metadata (#22472)fa064d6Updating changelog for v1.2.1 release (#22478)d742ee8Add MatchConditions to azcore (#22476)da33ad0azfile, azdatalake: Updating the type of number of chunks to uint64 (#22468)2b23e14[aznamespaces] Moving to new folder site, updating readme and autorest (#22441)367d699Update azappconfig with latest code generator (#22473)4769244NewListEntitiesPager fix (#22469)4718139Increment package version after release of storage/azblob (#22471)Updates
github.com/docker/dockerfrom 28.1.1+incompatible to 28.2.2+incompatibleRelease notes
Sourced from github.com/docker/docker's releases.
... (truncated)
Commits
45873beMerge pull request #50105 from jsternberg/revert-build-dangling7994426Revert "containerd: images overridden by a build are kept dangling"f144264Merge pull request #50090 from corhere/libn/overlay-netip768cfaeMerge pull request #50050 from robmry/nftables_internal_dnsd3289ddAdd nftables NAT rules for internal DNS resolver7a0bf74Merge pull request #50038 from ctalledo/fix-for-50037b43afbfMerge pull request #50098 from robmry/remove_docker-user_return_rulec299ba3Update worker.Platforms() in builder-next worker.0e2cc22Merge pull request #50049 from robmry/nftables_env_var_enablee37efd4Merge pull request #50068 from mmorel-35/github.com/containerd/errdefsUpdates
github.com/sigstore/protobuf-specsfrom 0.4.1 to 0.4.2Changelog
Sourced from github.com/sigstore/protobuf-specs's changelog.
Commits
011f5a0Add CHANGELOG, bump releases for v0.4.2 (#637)8beee48build(deps): bump ruby/setup-ruby from 1.238.0 to 1.239.0 (#636)966b43dadd: ML-DSA to algorithm registry (#616)a4c70feAdd operator for SigningConfig services, log and TSA roots (#634)ef40dfbbuild(deps): bump ruby/setup-ruby from 1.237.0 to 1.238.0 (#635)8b886ffRevise checkpoint key ID comment, deprecate log ID (#629)8e998cebuild(deps): bump prost-reflect-build in /gen/pb-rust (#623)1124687build(deps): bump distroless/nodejs22-debian12 in /protoc-builder (#622)33a35ccUpdate GOOGLEAPIS_COMMIT in versions.mk (#617)bda1b2cbuild(deps): bump distroless/base-debian12 in /protoc-builder (#621)Updates
github.com/sigstore/scaffoldingfrom 0.7.22 to 0.7.23Release notes
Sourced from github.com/sigstore/scaffolding's releases.
Commits
57c1c47Bump golangci/golangci-lint-action from 7.0.0 to 8.0.0 (#1574)6524e0cBump go.step.sm/crypto from 0.61.0 to 0.63.0 (#1570)49e68a5Bump github.com/go-jose/go-jose/v4 from 4.0.5 to 4.1.0 (#1571)aa457faBump github.com/sigstore/timestamp-authority from 1.2.5 to 1.2.6 (#1569)ee6e244Bump github.com/golang/glog from 1.2.4 to 1.2.5 (#1572)d4d6d74Bump github.com/go-sql-driver/mysql from 1.9.1 to 1.9.2 (#1573)f13df2bBump github/codeql-action from 3.28.16 to 3.28.17 (#1575)832418bbump cloud-sql-proxy to v2.16.0 (#1568)fd22420Bump k8s.io/code-generator from 0.32.2 to 0.33.0 (#1565)ea1250fadd support for testing on k8s 1.33 (#1567)Updates
github.com/sigstore/sigstore-gofrom 0.7.2 to 1.0.0Release notes
Sourced from github.com/sigstore/sigstore-go's releases.
Commits
cedac1bUpdate README for 1.0.0 release. (#480)48df3a9Bump the minor-patch group across 2 directories with 3 updates (#479)fed666aBump actions/setup-go from 5.4.0 to 5.5.0 (#478)6392d0eDeprecate and rename VerifyTimestampAuthority/VerifyArtifactTransparencyLog (...b47323bRename and deprecate SignedEntityVerifier in favor of Verifier (#476)d1f9d7fUse repository.Type from go-tuf in tests (#475)94bb81bAdd verification errors to output of VerifyTimestampAuthority (#473)2bb86a1Update theupdateframework/go-tuf to v2.1.0 and copy in unexported repo type f...6207d62Prevent duplicate timestamps from same TSA (#472)8dff965Disable TUF timestamping when TUF cache disabled (#470)Updates
github.com/sigstore/sigstore/pkg/signature/kms/awsfrom 1.9.4 to 1.9.5Release notes
Sourced from github.com/sigstore/sigstore/pkg/signature/kms/aws's releases.
Commits
75efc00build(deps): Bump localstack/localstack in /test/e2e in the all group (#2092)32d462fbuild(deps): Bump the all group in /test/e2e with 3 updates (#2091)007cd79build(deps): Bump the all group in /test/e2e with 3 updates (#2074)bbd546bbuild(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (#2087)540126bbuild(deps): Bump google.go...Description has been truncated