Skip to content

deps: bump the go-minor-patch group across 1 directory with 10 updates - #831

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/go_modules/go-minor-patch-fe66c56cd4
Closed

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/go_modules/go-minor-patch-fe66c56cd4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the go-minor-patch group with 10 updates in the / directory:

Package From To
github.com/aws/aws-sdk-go-v2 1.47.0 1.47.1
github.com/aws/aws-sdk-go-v2/config 1.33.4 1.33.6
github.com/aws/aws-sdk-go-v2/credentials 1.20.4 1.20.6
github.com/aws/aws-sdk-go-v2/service/s3 1.113.0 1.113.4
github.com/hashicorp/consul/api 1.34.4 1.34.5
github.com/mattn/go-shellwords 1.0.14 1.0.15
github.com/onsi/ginkgo/v2 2.32.2 2.33.0
github.com/onsi/gomega 1.43.0 1.44.0
go.etcd.io/etcd/client/v3 3.7.1 3.7.2
google.golang.org/api 0.297.0 0.299.0

Updates github.com/aws/aws-sdk-go-v2 from 1.47.0 to 1.47.1

Commits

Updates github.com/aws/aws-sdk-go-v2/config from 1.33.4 to 1.33.6

Commits

Updates github.com/aws/aws-sdk-go-v2/credentials from 1.20.4 to 1.20.6

Commits

Updates github.com/aws/aws-sdk-go-v2/service/s3 from 1.113.0 to 1.113.4

Commits

Updates github.com/hashicorp/consul/api from 1.34.4 to 1.34.5

Commits
  • 0548ce8 sub module release
  • c115f1d fix: upgrade golang.org/x/mod and golang.org/x/crypto to address CVEs (#23913)
  • 78ab247 fix: update debian docker images from bullseye to bookworm (#23909)
  • 132d262 api-gateway: fix cold-start Envoy crash from aggregate clusters missing EDS ...
  • c04f913 security: escape regex metacharacters in SPIFFE RBAC patterns (#23900)
  • 13cdc76 security: bound RPC header size to prevent pre-auth memory exhaustion (#23898)
  • 645a489 security: gate Lua/Wasm extensions and bootstrap escape-hatch keys behind mes...
  • 4fefef9 security: reject non-default PeerName in Catalog.Deregister (#23897)
  • 281d039 security: fix catalog node-ID ACL bypass allowing cross-node takeover (#23899)
  • cdf07d5 fix sec vuln for qs, xmldom and fast-uri (#23895)
  • Additional commits viewable in compare view

Updates github.com/mattn/go-shellwords from 1.0.14 to 1.0.15

Release notes

Sourced from github.com/mattn/go-shellwords's releases.

v1.0.15

What's Changed

New Contributors

Full Changelog: mattn/go-shellwords@v1.0.14...v1.0.15

Commits
  • f40666a Merge pull request #77 from vitalivo/fix/comments-after-empty-quotes
  • f7c60ee Keep hash characters following empty quotes as word content
  • See full diff in compare view

Updates github.com/onsi/ginkgo/v2 from 2.32.2 to 2.33.0

Release notes

Sourced from github.com/onsi/ginkgo/v2's releases.

v2.33.0

Features

  • The JUnit reporter now records each spec's ReportEntrys as <properties> on its <testcase> element, with the entry's name and its JSON-encoded value. Thanks @​pohly! [23db51a]

Maintenance

  • Releases are now cut by a GitHub Actions workflow (Actions -> Release -> Run workflow) rather than by hand, with changelog entries collected under ## Unreleased as the work happens. See RELEASING.md. [8616ecb]
Changelog

Sourced from github.com/onsi/ginkgo/v2's changelog.

2.33.0

Features

  • The JUnit reporter now records each spec's ReportEntrys as <properties> on its <testcase> element, with the entry's name and its JSON-encoded value. Thanks @​pohly! [23db51a]

Maintenance

  • Releases are now cut by a GitHub Actions workflow (Actions -> Release -> Run workflow) rather than by hand, with changelog entries collected under ## Unreleased as the work happens. See RELEASING.md. [8616ecb]
Commits
  • 9f94149 v2.33.0
  • db78e1b changelog: entries for the JUnit ReportEntry support and the release flow
  • 8616ecb ci: release from a single workflow_dispatch button
  • d8d9cdd README: add a sponsor badge
  • ac70da6 README: dark-mode logo and a docs badge
  • 23db51a junit: support ReportEntry
  • See full diff in compare view

Updates github.com/onsi/gomega from 1.43.0 to 1.44.0

Release notes

Sourced from github.com/onsi/gomega's releases.

v1.44.0

Fixes

  • BeNumerically compares signed and unsigned integers by value: -1 no longer equals uint64(math.MaxUint64) and uint(5) is now greater than -3 (#925) [26e3c6b]
  • BeNumerically("~") no longer overflows when computing the distance between extreme integers (#928) [1955764]
  • BeNumerically("==", x, threshold) now honors the threshold for floats, as it already did for integers (#927) [10e2aca]
  • HaveKeyWithValue succeeds if any key accepted by the key matcher has a matching value, rather than depending on map iteration order (#929) [ffc577a]
  • HaveKey and HaveKeyWithValue treat key and value matcher errors like ContainElement does: a match wins, and an error is only reported when nothing matches (#926) [dc91598]
  • MatchJSON no longer treats numbers too large for a float64 as equal to one another (#930) [9d619a5]
  • MatchJSON compares integers beyond ±2^53 exactly, so neighboring large integers (e.g. IDs) no longer match; all other numbers are still compared as float64s (#931) [8ef1aa7, 630fe12]
  • HaveExactElements reports missing or extra elements that start at index 0, and reports the first extra element's index rather than the last (#934) [af1b777]
  • MatchYAML compares every document in a multi-document stream rather than only the first; empty documents (e.g. a leading or trailing ---) are ignored (#933) [2773796]
  • MatchXML ignores namespace prefixes: elements and attributes are compared by namespace URI, and the URIs declared on each element must match whatever prefix they are bound to (#932) [c0dbd89, 2565350]

v1.43.1

Maintenance

  • Update go.yaml.in/yaml/v3 to v3.0.5 [d547015]
  • Releases are now cut by a GitHub Actions workflow (Actions -> Release -> Run workflow) rather than by hand, with changelog entries collected under ## Unreleased as the work happens. Releases still ship the stripped-down tree on master-lite - tests removed and Ginkgo dropped from go.mod - and the workflow now builds it and checks it on every push. See RELEASING.md. [e9dc84d]
Changelog

Sourced from github.com/onsi/gomega's changelog.

1.44.0

Fixes

  • BeNumerically compares signed and unsigned integers by value: -1 no longer equals uint64(math.MaxUint64) and uint(5) is now greater than -3 (#925) [26e3c6b]
  • BeNumerically("~") no longer overflows when computing the distance between extreme integers (#928) [1955764]
  • BeNumerically("==", x, threshold) now honors the threshold for floats, as it already did for integers (#927) [10e2aca]
  • HaveKeyWithValue succeeds if any key accepted by the key matcher has a matching value, rather than depending on map iteration order (#929) [ffc577a]
  • HaveKey and HaveKeyWithValue treat key and value matcher errors like ContainElement does: a match wins, and an error is only reported when nothing matches (#926) [dc91598]
  • MatchJSON no longer treats numbers too large for a float64 as equal to one another (#930) [9d619a5]
  • MatchJSON compares integers beyond ±2^53 exactly, so neighboring large integers (e.g. IDs) no longer match; all other numbers are still compared as float64s (#931) [8ef1aa7, 630fe12]
  • HaveExactElements reports missing or extra elements that start at index 0, and reports the first extra element's index rather than the last (#934) [af1b777]
  • MatchYAML compares every document in a multi-document stream rather than only the first; empty documents (e.g. a leading or trailing ---) are ignored (#933) [2773796]
  • MatchXML ignores namespace prefixes: elements and attributes are compared by namespace URI, and the URIs declared on each element must match whatever prefix they are bound to (#932) [c0dbd89, 2565350]

1.43.1

Maintenance

  • Update go.yaml.in/yaml/v3 to v3.0.5 [d547015]
  • Releases are now cut by a GitHub Actions workflow (Actions -> Release -> Run workflow) rather than by hand, with changelog entries collected under ## Unreleased as the work happens. Releases still ship the stripped-down tree on master-lite - tests removed and Ginkgo dropped from go.mod - and the workflow now builds it and checks it on every push. See RELEASING.md. [e9dc84d]
Commits
  • c933817 v1.44.0
  • 37fa900 v1.44.0 (full)
  • 509f2b0 changelog: entries for #925-#934
  • 2565350 fix: MatchXML compares namespace declarations by URI, ignoring the prefix
  • 630fe12 fix: MatchJSON only compares integers beyond 2^53 exactly
  • c0dbd89 fix: MatchXML ignores namespace prefixes and declarations
  • 2773796 fix: MatchYAML compares every document in a multi-document stream
  • af1b777 fix: HaveExactElements reports missing/extra elements starting at index 0
  • 8ef1aa7 fix: MatchJSON compares numbers exactly
  • 9d619a5 fix: MatchJSON reports numbers that do not fit in a float64
  • Additional commits viewable in compare view

Updates go.etcd.io/etcd/client/v3 from 3.7.1 to 3.7.2

Release notes

Sourced from go.etcd.io/etcd/client/v3's releases.

v3.7.2

Please check out CHANGELOG for a full list of changes. And make sure to read upgrade guide before upgrading etcd (there may be breaking changes).

For installation guides, please check out play.etcd.io and operating etcd. Latest support status for common architectures and operating systems can be found at supported platforms.

Linux
ETCD_VER=v3.7.2
choose either URL
GOOGLE_URL=https://storage.googleapis.com/etcd
GITHUB_URL=https://github.com/etcd-io/etcd/releases/download
DOWNLOAD_URL=${GOOGLE_URL}
rm -f /tmp/etcd-${ETCD_VER}-linux-amd64.tar.gz
rm -rf /tmp/etcd-download-test && mkdir -p /tmp/etcd-download-test
curl -L ${DOWNLOAD_URL}/${ETCD_VER}/etcd-${ETCD_VER}-linux-amd64.tar.gz -o /tmp/etcd-${ETCD_VER}-linux-amd64.tar.gz
tar xzvf /tmp/etcd-${ETCD_VER}-linux-amd64.tar.gz -C /tmp/etcd-download-test --strip-components=1 --no-same-owner
rm -f /tmp/etcd-${ETCD_VER}-linux-amd64.tar.gz
/tmp/etcd-download-test/etcd --version
/tmp/etcd-download-test/etcdctl version
/tmp/etcd-download-test/etcdutl version
start a local etcd server
/tmp/etcd-download-test/etcd
write,read to etcd
/tmp/etcd-download-test/etcdctl --endpoints=localhost:2379 put foo bar
/tmp/etcd-download-test/etcdctl --endpoints=localhost:2379 get foo

macOS (Darwin)
ETCD_VER=v3.7.2
choose either URL
GOOGLE_URL=https://storage.googleapis.com/etcd
GITHUB_URL=https://github.com/etcd-io/etcd/releases/download
DOWNLOAD_URL=${GOOGLE_URL}
rm -f /tmp/etcd-${ETCD_VER}-darwin-amd64.zip
rm -rf /tmp/etcd-download-test && mkdir -p /tmp/etcd-download-test
curl -L ${DOWNLOAD_URL}/${ETCD_VER}/etcd-${ETCD_VER}-darwin-amd64.zip -o /tmp/etcd-${ETCD_VER}-darwin-amd64.zip
unzip /tmp/etcd-${ETCD_VER}-darwin-amd64.zip -d /tmp && rm -f /tmp/etcd-${ETCD_VER}-darwin-amd64.zip
mv /tmp/etcd-${ETCD_VER}-darwin-amd64/* /tmp/etcd-download-test && rm -rf mv /tmp/etcd-${ETCD_VER}-darwin-amd64
</tr></table>

... (truncated)

Commits
  • 68c065e version: bump up to 3.7.2
  • b85cf4b dependency: bump google.golang.org/grpc to v1.83.2
  • 9e41c76 fileutil: close locked files when purging fails
  • c1c6e17 Delete bump-devcontainer-version GitHub action
  • ca26c7e Merge pull request #22413 from ivanvc/release-3.7-go-1.26.8
  • 9d58213 fix: deflake TestIssue20271
  • adb3646 Bump go to 1.26.8
  • 2632b79 Merge pull request #22404 from k8s-infra-cherrypick-robot/cherry-pick-22173-t...
  • 0c06cc3 Merge pull request #22378 from k8s-infra-cherrypick-robot/cherry-pick-22314-t...
  • 3d67b05 Deflake TestEtcdGrpcResolverRoundRobin: sleep 1s to allow all grpc sub channe...
  • Additional commits viewable in compare view

Updates google.golang.org/api from 0.297.0 to 0.299.0

Release notes

Sourced from google.golang.org/api's releases.

v0.299.0

0.299.0 (2026-09-21)

Features

v0.298.0

0.298.0 (2026-09-14)

Features

Changelog

Sourced from google.golang.org/api's changelog.

0.299.0 (2026-09-21)

Features

0.298.0 (2026-09-14)

Features

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-minor-patch group with 10 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.47.0` | `1.47.1` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.33.4` | `1.33.6` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2) | `1.20.4` | `1.20.6` |
| [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2) | `1.113.0` | `1.113.4` |
| [github.com/hashicorp/consul/api](https://github.com/hashicorp/consul) | `1.34.4` | `1.34.5` |
| [github.com/mattn/go-shellwords](https://github.com/mattn/go-shellwords) | `1.0.14` | `1.0.15` |
| [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) | `2.32.2` | `2.33.0` |
| [github.com/onsi/gomega](https://github.com/onsi/gomega) | `1.43.0` | `1.44.0` |
| [go.etcd.io/etcd/client/v3](https://github.com/etcd-io/etcd) | `3.7.1` | `3.7.2` |
| [google.golang.org/api](https://github.com/googleapis/google-api-go-client) | `0.297.0` | `0.299.0` |



Updates `github.com/aws/aws-sdk-go-v2` from 1.47.0 to 1.47.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@v1.47.0...v1.47.1)

Updates `github.com/aws/aws-sdk-go-v2/config` from 1.33.4 to 1.33.6
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@config/v1.33.4...config/v1.33.6)

Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.20.4 to 1.20.6
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/mq/v1.20.4...service/mq/v1.20.6)

Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.113.0 to 1.113.4
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.113.0...service/s3/v1.113.4)

Updates `github.com/hashicorp/consul/api` from 1.34.4 to 1.34.5
- [Release notes](https://github.com/hashicorp/consul/releases)
- [Changelog](https://github.com/hashicorp/consul/blob/main/CHANGELOG.md)
- [Commits](hashicorp/consul@api/v1.34.4...api/v1.34.5)

Updates `github.com/mattn/go-shellwords` from 1.0.14 to 1.0.15
- [Release notes](https://github.com/mattn/go-shellwords/releases)
- [Commits](mattn/go-shellwords@v1.0.14...v1.0.15)

Updates `github.com/onsi/ginkgo/v2` from 2.32.2 to 2.33.0
- [Release notes](https://github.com/onsi/ginkgo/releases)
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md)
- [Commits](onsi/ginkgo@v2.32.2...v2.33.0)

Updates `github.com/onsi/gomega` from 1.43.0 to 1.44.0
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](onsi/gomega@v1.43.0...v1.44.0)

Updates `go.etcd.io/etcd/client/v3` from 3.7.1 to 3.7.2
- [Release notes](https://github.com/etcd-io/etcd/releases)
- [Commits](etcd-io/etcd@v3.7.1...v3.7.2)

Updates `google.golang.org/api` from 0.297.0 to 0.299.0
- [Release notes](https://github.com/googleapis/google-api-go-client/releases)
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md)
- [Commits](googleapis/google-api-go-client@v0.297.0...v0.299.0)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
  dependency-version: 1.47.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-patch
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.33.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-patch
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
  dependency-version: 1.20.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-patch
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
  dependency-version: 1.113.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-patch
- dependency-name: github.com/hashicorp/consul/api
  dependency-version: 1.34.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-patch
- dependency-name: github.com/mattn/go-shellwords
  dependency-version: 1.0.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-patch
- dependency-name: github.com/onsi/ginkgo/v2
  dependency-version: 2.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-patch
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-patch
- dependency-name: go.etcd.io/etcd/client/v3
  dependency-version: 3.7.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-patch
- dependency-name: google.golang.org/api
  dependency-version: 0.299.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 28, 2026
wayneeseguin added a commit that referenced this pull request Oct 1, 2026
* Update vendored dependencies to latest

Every module moves to its newest release within its current major
version. The AWS SDK, gRPC, ginkgo, gomega and the Google API
packages carry the bulk of the change.

Supersedes the go-minor-patch Dependabot group in #831, which
cannot merge: its required concourse-ci/status check comes from
the retired Concourse pipeline and will never report.

* Move the consul plugin to consul/api v2

Every symbol the plugin uses is unchanged in v2: KV, KVPair,
Client, DefaultConfig, HttpBasicAuth, NewClient and
HTTPSSLVerifyEnvName all keep their signatures, so this is the
import path and nothing else.

* Move the swift plugin to ncw/swift v2

v2 takes a context on every call that reaches the network, so
Connect, Authenticate, ObjectPutBytes, ObjectGetBytes and
ObjectDelete all gain one. The plugin interface hands us no
context, so Store, Retrieve and Purge each start from
context.Background(), which leaves the current behaviour of
waiting indefinitely unchanged.

* Move the Okta provider to the v2 token verifier

The fields we set, Issuer and ClaimsToValidate, and the Jwt.Claims
map we read back are all unchanged. The one difference is that
New() now returns an error alongside the verifier, so verifyToken
reports a verifier it could not build rather than carrying on with
a nil one.

This also takes the lestrrat-go/jwx dependency from v1, which
upstream no longer maintains, to v2.

* Move the GitHub auth provider to go-github v92

v92 replaced the NewClient(nil).WithAuthToken(token) pair with a
single variadic constructor that returns an error, so the token
becomes a WithAuthToken option and a configured enterprise API
address becomes a WithURLs option.

WithURLs does the url.Parse the old code did by hand, which is why
net/url is no longer imported. It also appends the trailing slash
that go-github has always needed on a base URL, so an enterprise
address configured without one now reaches the right endpoint
instead of silently losing its last path segment.

* Record the stale dependencies we decided to keep

Six direct dependencies have not been pushed in over two years.
Each one is already on the newest version published, so there is
nothing to upgrade to, and the file says why we are leaving each
one alone so the next pass does not re-open the question.
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 1, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/go-minor-patch-fe66c56cd4 branch October 1, 2026 00:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Development

Successfully merging this pull request may close these issues.

0 participants