An open index of dependabot pull requests across open source projects.

chore(deps): bump the go-modules group across 1 directory with 84 updates

Open
Number: #23
Type: Pull Request
State: Open
Author: dependabot[bot] dependabot[bot]
Association: None
Comments: 0
Created: August 07, 2025 at 11:31 PM UTC
(10 months ago)
Updated: August 07, 2025 at 11:31 PM UTC
(10 months ago)
Labels:
dependencies go
Description:

Bumps the go-modules group with 4 updates in the / directory: github.com/onsi/gomega, github.com/paketo-buildpacks/occam, github.com/Microsoft/hcsshim and github.com/docker/go-connections.

Updates github.com/onsi/gomega from 1.37.0 to 1.38.0

Release notes

Sourced from github.com/onsi/gomega's releases.

v1.38.0

1.38.0

Features

  • gstruct handles extra unexported fields [4ee7ed0]

Fixes

  • support [] in IgnoringTopFunction function signatures (#851) [36bbf72]

Maintenance

  • Bump golang.org/x/net from 0.40.0 to 0.41.0 (#846) [529d408]
  • Fix typo [acd1f55]
  • Bump google.golang.org/protobuf from 1.36.5 to 1.36.6 (#835) [bae65a0]
  • Bump nokogiri from 1.18.4 to 1.18.8 in /docs (#842) [8dda91f]
  • Bump golang.org/x/net from 0.39.0 to 0.40.0 (#843) [212d812]
  • Bump github.com/onsi/ginkgo/v2 from 2.23.3 to 2.23.4 (#839) [59bd7f9]
  • Bump nokogiri from 1.18.1 to 1.18.4 in /docs (#834) [328c729]
  • Bump uri from 1.0.2 to 1.0.3 in /docs (#826) [9a798a1]
  • Bump golang.org/x/net from 0.37.0 to 0.39.0 (#841) [04a72c6]
Changelog

Sourced from github.com/onsi/gomega's changelog.

1.38.0

Features

  • gstruct handles extra unexported fields [4ee7ed0]

Fixes

  • support [] in IgnoringTopFunction function signatures (#851) [36bbf72]

Maintenance

  • Bump golang.org/x/net from 0.40.0 to 0.41.0 (#846) [529d408]
  • Fix typo [acd1f55]
  • Bump google.golang.org/protobuf from 1.36.5 to 1.36.6 (#835) [bae65a0]
  • Bump nokogiri from 1.18.4 to 1.18.8 in /docs (#842) [8dda91f]
  • Bump golang.org/x/net from 0.39.0 to 0.40.0 (#843) [212d812]
  • Bump github.com/onsi/ginkgo/v2 from 2.23.3 to 2.23.4 (#839) [59bd7f9]
  • Bump nokogiri from 1.18.1 to 1.18.4 in /docs (#834) [328c729]
  • Bump uri from 1.0.2 to 1.0.3 in /docs (#826) [9a798a1]
  • Bump golang.org/x/net from 0.37.0 to 0.39.0 (#841) [04a72c6]
Commits
  • c1237df v1.38.0
  • 36bbf72 support [] in IgnoringTopFunction function signatures (#851)
  • 4ee7ed0 gstruct handles extra unexported fields
  • 529d408 Bump golang.org/x/net from 0.40.0 to 0.41.0 (#846)
  • acd1f55 Fix typo
  • bae65a0 Bump google.golang.org/protobuf from 1.36.5 to 1.36.6 (#835)
  • 8dda91f Bump nokogiri from 1.18.4 to 1.18.8 in /docs (#842)
  • 212d812 Bump golang.org/x/net from 0.39.0 to 0.40.0 (#843)
  • 59bd7f9 Bump github.com/onsi/ginkgo/v2 from 2.23.3 to 2.23.4 (#839)
  • 328c729 Bump nokogiri from 1.18.1 to 1.18.4 in /docs (#834)
  • Additional commits viewable in compare view

Updates github.com/paketo-buildpacks/occam from 0.25.0 to 0.28.1

Release notes

Sourced from github.com/paketo-buildpacks/occam's releases.

v0.28.1

What's Changed

Full Changelog: https://github.com/paketo-buildpacks/occam/compare/v0.28.0...v0.28.1

v0.28.0

What's Changed

Full Changelog: https://github.com/paketo-buildpacks/occam/compare/v0.27.0...v0.28.0

v0.27.0

What's Changed

New Contributors

Full Changelog: https://github.com/paketo-buildpacks/occam/compare/v0.26.0...v0.27.0

v0.26.0

What's Changed

... (truncated)

Commits
  • bf909c9 chore(deps): updated module github.com/docker/docker from v28.3.2+incompatibl...
  • 5c2a89c chore(deps): updated module github.com/paketo-buildpacks/freezer from v0.2.0 ...
  • 7892a15 chore(deps): updated module github.com/paketo-buildpacks/packit/v2 from v2.22...
  • 655432e Delete dependabot.yml (#416)
  • 21c9dcc Bump github.com/onsi/gomega from 1.37.0 to 1.38.0
  • 2b069f7 Bump github.com/paketo-buildpacks/packit/v2 from 2.21.0 to 2.22.0
  • e4537da Updating github-config
  • 6738ffd Bump github.com/testcontainers/testcontainers-go from 0.37.0 to 0.38.0
  • 6ab6ac5 Updating github-config
  • f695f8a Updating github-config
  • Additional commits viewable in compare view

Updates github.com/paketo-buildpacks/packit/v2 from 2.17.0 to 2.23.0

Release notes

Sourced from github.com/paketo-buildpacks/packit/v2's releases.

v2.23.0

What's Changed

Full Changelog: https://github.com/paketo-buildpacks/packit/compare/v2.22.0...v2.23.0

v2.22.0

What's Changed

New Contributors

Full Changelog: https://github.com/paketo-buildpacks/packit/compare/v2.21.0...v2.22.0

v2.21.0

What's Changed

New Contributors

Full Changelog: https://github.com/paketo-buildpacks/packit/compare/v2.20.0...v2.21.0

v2.20.0

What's Changed

Full Changelog: https://github.com/paketo-buildpacks/packit/compare/v2.19.0...v2.20.0

v2.19.0

What's Changed

... (truncated)

Commits
  • 4101df4 Only enforce strict arch checking when dependency specifies arch (#671)
  • f5dd316 Bump github.com/onsi/gomega from 1.37.0 to 1.38.0
  • 3c276b8 Bump github.com/anchore/syft from 1.28.0 to 1.29.0
  • 677efd0 skip-path feature added for dependency mirrors
  • ec1ecc5 Updates go mod version to 1.24.5
  • 62193ff Bump github.com/anchore/syft from 1.27.1 to 1.28.0
  • c7ebb14 Bump github.com/Masterminds/semver/v3 from 3.3.1 to 3.4.0 (#663)
  • bf6b5f7 Updating github-config
  • 2b214bf Updating github-config
  • 592b39d Updating github-config
  • Additional commits viewable in compare view

Updates dario.cat/mergo from 1.0.0 to 1.0.2

Release notes

Sourced from dario.cat/mergo's releases.

v1.0.2

What's Changed

  • Drops gopkg.in/yaml.v3, only used for loading fixtures. Thanks @​trim21 for bringing to my attention (#262) that this library is no longer maintained.

Full Changelog: https://github.com/darccio/mergo/compare/v1.0.1...v1.0.2

v1.0.1

What's Changed

New Contributors

Full Changelog: https://github.com/darccio/mergo/compare/v1.0.0...v1.0.1

Commits
  • 7b33b2b refactor: migrate from YAML to JSON for test data and update related functions
  • 229a214 chore(.well-known): add funding manifest URLs file
  • 6be20c6 chore(SECURITY.md): update supported versions to reflect current versioning
  • 9007623 chore(README) : remove kubernetes from the list of users
  • 2b1eb9c Update FUNDING.yml
  • 2ceb994 Create FUNDING.json
  • 59ea6a9 Merge pull request #251 from joshkaplinsky/joshkaplinsky/without-dereference-...
  • 96f24af Merge pull request #253 from vsemichev/master
  • 2f1a615 fixes issue #187. adds test to verify the fix.
  • 4da170b fixes issue #187. attempt #3
  • Additional commits viewable in compare view

Updates github.com/Azure/go-ansiterm from 0.0.0-20210617225240-d185dfc1b5a1 to 0.0.0-20250102033503-faa5f7b0171c

Commits

Updates github.com/CycloneDX/cyclonedx-go from 0.7.1 to 0.9.2

Release notes

Sourced from github.com/CycloneDX/cyclonedx-go's releases.

v0.9.2

Changelog

Features

  • 39ede217f126cfbc80eabf880f6643be3d392a4f: feat: add MarshalXML and UnmarshalXML (@​DmitriyLewen)
  • e9191ed11a269fcb6b3fb54e000ed6d81b5bf9db: feat: add UnmarshalJSON (@​DmitriyLewen)

Fixes

  • 80fede1f13a956d35eb14696cd2ca9d2d943f809: fix: add json tag for Identity (@​DmitriyLewen)
  • 24e9503293f0837e6e7ea3ff670ef958e6075b87: fix: tests (@​DmitriyLewen)
  • d68a199bc1747e5d6a7d4196c2f270535bbf6e3e: fix: use identity as array in valid-evidence.json (@​DmitriyLewen)
  • ff9cc28f9c9554328bd6c1ad56098be5a692d5e9: fix: use componentEvidence array for Evidence.Identity field (@​DmitriyLewen)

Building and Packaging

  • 016ee293d464d6383be3a714f7fb0debebef8ad5: build(deps): bump actions/checkout from 4.1.7 to 4.2.0 (@​dependabot[bot])
  • 77153ab5fe005f6484ac1e1225e7152df00db3f1: build(deps): bump actions/checkout from 4.2.0 to 4.2.1 (@​dependabot[bot])
  • 4f50d02c1282ac1d0d7448502b231a0e84a1e529: build(deps): bump actions/checkout from 4.2.1 to 4.2.2 (@​dependabot[bot])
  • b84451219e77e0fbbe7d5ba054bcf25dbc7aaea4: build(deps): bump actions/setup-go from 5.0.2 to 5.1.0 (@​dependabot[bot])
  • 238cbea3479fed9fdfcbfa5f1751828390a05211: build(deps): bump actions/setup-go from 5.1.0 to 5.2.0 (@​dependabot[bot])
  • bbe8f3c2c7c4567514ae966c69bf93fc1b3dba2a: build(deps): bump github.com/stretchr/testify from 1.9.0 to 1.10.0 (@​dependabot[bot])
  • 05f8930fe918a31941ebf90eec627e5e6e908d1c: build(deps): bump github.com/terminalstatic/go-xsd-validate (@​dependabot[bot])
  • 082f87791a5e290c9d4c6e8126dc0cc987028a60: build(deps): bump gitpod/workspace-go from 2a9e01c to 9c95281 (@​dependabot[bot])
  • 093b1c15164dad5d46768db0e3f6ee43eb60ca20: build(deps): bump gitpod/workspace-go from 9c95281 to 6932342 (@​dependabot[bot])
  • 47b7e01ce8f8209894065e9656217b8c00a3c8ea: build(deps): bump golangci/golangci-lint-action from 6.1.0 to 6.1.1 (@​dependabot[bot])
  • ce6eb841cb1e21aa28efbccd9eb8fe5eea0555c9: build(deps): bump goreleaser/goreleaser-action from 6.0.0 to 6.1.0 (@​dependabot[bot])

Others

  • 4d3aff9fab9ae78bd6fbbc9fd0912fab14c8fb64: UPDATE_SNAPSHOTS=true make test (@​DmitriyLewen)
  • 31d954443e6563aeee69d82bdfb82aee83e07df1: refactor (@​DmitriyLewen)
  • 0170729e313a681fc8659643601410ae10ffe803: refactor: update convert package (@​DmitriyLewen)

v0.9.1

Changelog

Fixes

  • 6f0e0cf025dd99ab903e33f8e043d92b28dab4f6: fix: nil pointer dereference during evidence conversion (@​nscuro)
  • ce43b6f4cb5707d3ef2db1af1d597f5b23bf0e15: fix: make linter happy (@​nscuro)
  • 5d799e634b9bed9c86621048544737b210e433e8: fix: remove deprecated goreleaser flag (@​nscuro)

Building and Packaging

  • 6d5bcb0e277207551dbc728eb29959f1d3cbd685: build(deps): bump actions/checkout from 4.1.6 to 4.1.7 (@​dependabot[bot])
  • f34fc0c413da74d20d1cc240863aaf2eb6b274f7: build(deps): bump actions/setup-go from 5.0.1 to 5.0.2 (@​dependabot[bot])
  • 71cff221b8dbbc1d50f839fa76ecea4e42d83a2b: build(deps): bump gitpod/workspace-go from 8d15123 to 2a9e01c (@​dependabot[bot])
  • ea693550558d230b3fbba810b6e75ac2eb0b55c8: build(deps): bump golangci/golangci-lint-action from 6.0.1 to 6.1.0 (@​dependabot[bot])
  • d5cbdad49dfbf54f2dab4ad95bd1a47c710a526c: build(deps): bump goreleaser/goreleaser-action from 5.1.0 to 6.0.0 (@​dependabot[bot])

v0.9.0

Changelog

Features

  • 729c284798ebe341ced210b661362f77d68cd655: feat: Add CycloneDX 1.6 fields swhid and omniborId (@​snyk-tim)
  • b5d35959767efce95f50e96bf752c47fbe374496: feat: add manufacturer and authors (@​snyk-tim)
  • c52e698d2fe3fbd60df6ff397f44e7b0ea15a4bc: feat: raise baseline go version to 1.20 (@​nscuro)

Fixes

  • 9166e10fdecaadd8a97ceed9636261d351d90a65: fix: ioutil -> io (@​nscuro)
  • 349fc8cd072e90d81c0328f1d9dab16aa30fcf60: fix: add bom-ref to OrganizationalEntity/Contact (@​snyk-tim)
  • c97da90e259e0051e02e07300c75ad5e37a0311b: fix: handle breaking changes in skywalking-eyes (@​nscuro)

... (truncated)

Commits
  • cba06ff Merge pull request #205 from CycloneDX/dependabot/go_modules/github.com/termi...
  • 5c81749 Merge pull request #211 from CycloneDX/dependabot/github_actions/actions/setu...
  • 753526c Merge pull request #204 from DmitriyLewen/fix/componentEvidence-as-array
  • 4d3aff9 UPDATE_SNAPSHOTS=true make test
  • d68a199 fix: use identity as array in valid-evidence.json
  • 24e9503 fix: tests
  • 238cbea build(deps): bump actions/setup-go from 5.1.0 to 5.2.0
  • a7f7415 Merge branch 'master' of github.com:DmitriyLewen/cyclonedx-go into fix/compon...
  • 05f8930 build(deps): bump github.com/terminalstatic/go-xsd-validate
  • 464d426 Merge pull request #202 from CycloneDX/dependabot/github_actions/actions/chec...
  • Additional commits viewable in compare view

Updates github.com/DataDog/zstd from 1.4.5 to 1.5.5

Release notes

Sourced from github.com/DataDog/zstd's releases.

zstd 1.5.5

What's Changed

  • Update vendored zstd to 1.5.5 (#125)
  • [circleci] Update to non-deprecated images (#124)

https://github.com/DataDog/zstd/compare/v1.5.2...v1.5.5

zstd 1.5.5 - wrapper patches 1

What's Changed

New Contributors

Full Changelog: https://github.com/DataDog/zstd/compare/v1.5.5...v1.5.5+patch1

zstd 1.5.2

This release updates the upstream zstd version to 1.5.2 (DataDog/zstd#116)

The update 1.5.0 -> 1.5.2 overall has a similar performance profile. Please note that depending on the workload, performance could vary by -10% / +10%

zstd 1.5.2 - wrapper patches 1

What's Changed

New Contributors

Full Changelog: https://github.com/DataDog/zstd/compare/v1.5.2...v1.5.2+patch1

zstd 1.5.0

This release updates the upstream zstd version to 1.5.0 (#106) (thanks @​SirSniper!) which sports some major performance improvements!

It comes with additional changes to the Go wrapper:

  • Allow building against zstd dynamic library instead of static by @​dopuskh3 (#109)
  • Don't block the stream reader when a block is available by @​delthas (#96)

zstd 1.5.0 - wrapper patches 1

What's Changed

Full Changelog: https://github.com/DataDog/zstd/compare/v1.5.0...v1.5.0+patch1

zstd 1.5.0 - wrapper patches 2

... (truncated)

Commits
  • 5f14d6a Merge pull request #125 from DataDog/viq111/1.5.5
  • ca4d3c7 Update vendored zstd to 1.5.5
  • 03725e7 Merge pull request #126 from DataDog/viq111/circleci
  • 1b4c894 [circle] Remove latest as cimg/go does not have the tag
  • ff5a3bb [circleci] Update tested Go versions to 1.19 & 1.20
  • 6e5a54b [circleci] Switch to newer images
  • fd035e5 Merge pull request #117 from bsergean/patch-1
  • c798238 Merge branch '1.x' into patch-1
  • 13d5b10 update documentation
  • d64f463 Merge pull request #120 from DataDog/viq111/fix-min-size
  • Additional commits viewable in compare view

Updates github.com/Masterminds/semver/v3 from 3.3.1 to 3.4.0

Release notes

Sourced from github.com/Masterminds/semver/v3's releases.

v3.4.0

There are a few changes in this release to highlight:

  1. Constraints now has a property IncludePrerelease. When set to true the Check and Validate methods will include prereleases.
  2. When an AND group has one constraint with a prerelease but more than one constraint then prereleases will be included. For example, >1.0.0-beta.1 < 2. In the past this would not have included prereleases because each constraint needed to have a prerelease. Now, only one constraint needs to have a prerelease. This is considered a long standing bug fix. Note, this does not carry across OR groups. For example, >1.0.0-beta.1 < 2 || > 3. In this case, prereleases will not be included when evaluating against >3.
  3. NewVersion coercion with leading "0"'s is restored. This can be disabled by setting the package level property CoerceNewVersion to false.

What's Changed

New Contributors

Full Changelog: https://github.com/Masterminds/semver/compare/v3.3.1...v3.4.0

Changelog

Sourced from github.com/Masterminds/semver/v3's changelog.

3.4.0 (2025-06-27)

Added

  • #268: Added property to Constraints to include prereleases for Check and Validate

Changed

  • #263: Updated Go testing for 1.24, 1.23, and 1.22
  • #269: Updated the error message handling for message case and wrapping errors
  • #266: Restore the ability to have leading 0's when parsing with NewVersion. Opt-out of this by setting CoerceNewVersion to false.

Fixed

  • #257: Fixed the CodeQL link (thanks @​dmitris)
  • #262: Restored detailed errors when failed to parse with NewVersion. Opt-out of this by setting DetailedNewVersionErrors to false for faster performance.
  • #267: Handle pre-releases for an "and" group if one constraint includes them
Commits
  • 61fc460 Merge pull request #270 from mattfarina/relnotes-3.4.0
  • 69a63e7 Update the release notes and readme for new version
  • dc05094 Merge pull request #269 from mattfarina/lowercase-error-strings
  • a2cd9c2 Updating the error message handling
  • 9760c47 Merge pull request #268 from mattfarina/include-prerelease
  • c374751 Add property to include prereleases
  • 057c901 Merge pull request #267 from mattfarina/fix-259
  • abab1c2 Handle pre-releases on all in an and group
  • ebda872 Merge pull request #266 from mattfarina/restore-calver
  • 4ed619e Restore the ability to have leading 0's with NewVersion
  • Additional commits viewable in compare view

Updates github.com/Masterminds/sprig/v3 from 3.2.3 to 3.3.0

Release notes

Sourced from github.com/Masterminds/sprig/v3's releases.

v3.3.0

What's Changed

New Contributors

Full Changelog: https://github.com/Masterminds/sprig/compare/v3.2.3...v3.3.0

Changelog

Sourced from github.com/Masterminds/sprig/v3's changelog.

Release 3.3.0 (2024-08-29)

Added

Changed

  • #407: Removed duplicate documentation (functions were documentated in 2 places)
  • #290: Corrected copy/paster oops in math documentation (thanks @​zzhu41)
  • #369: Corrected template reference in docs (thanks @​chey)
  • #375: Added link to URL documenation (thanks @​carlpett)
  • #406: Updated the mergo dependency which had a breaking change (which was accounted for)
  • #376: Fixed documentation error (thanks @​jheyduk)
  • #404: Updated dependency tree
  • #391: Fixed misspelling (thanks @​chrishalbert)
  • #405: Updated Go versions used in testing
Commits
  • e708470 Merge pull request #408 from mattfarina/update-changelog-3.3
  • 8fc4354 Updating the changelog for the 3.3.0 release
  • cb81a32 Merge pull request #407 from mattfarina/remove-dup-math-functions
  • 2637693 Removing duplicate documentation
  • 06b9a87 Merge pull request #290 from zzhu41/patch-1
  • e663ec6 Merge pull request #369 from chey/patch-1
  • bb2f73f Merge pull request #375 from carlpett/patch-1
  • f07659e Merge pull request #400 from itzik-elayev/master
  • 98b35c1 Add closing bracket
  • 7a88928 Merge pull request #406 from mattfarina/update-mergo
  • Additional commits viewable in compare view

Updates github.com/Microsoft/hcsshim from 0.11.7 to 0.13.0

Release notes

Sourced from github.com/Microsoft/hcsshim's releases.

v0.13.0

What's Changed

Pull Request Statistics
Commits:
1
Files Changed:
2
Additions:
+1529
Deletions:
-338
Package Dependencies
Ecosystem:
go
Version Change:
3.3.1 → 3.4.0
Update Type:
Minor
Ecosystem:
go
Version Change:
1.37.0 → 1.38.0
Update Type:
Minor
Ecosystem:
go
Version Change:
0.25.0 → 0.28.1
Update Type:
Minor
Ecosystem:
go
Version Change:
1.4.5 → 1.5.5
Update Type:
Minor
Ecosystem:
go
Version Change:
0.11.7 → 0.13.0
Update Type:
Minor
Ecosystem:
go
Version Change:
1.0.0 → 1.0.2
Update Type:
Patch
Ecosystem:
go
Version Change:
2.17.0 → 2.23.0
Update Type:
Minor
Ecosystem:
go
Version Change:
3.2.3 → 3.3.0
Update Type:
Minor
Ecosystem:
go
Version Change:
0.7.1 → 0.9.2
Update Type:
Minor
Ecosystem:
go
Version Change:
0.0.0-20210617225240-d185dfc1b5a1 → 0.0.0-20250102033503-faa5f7b0171c
Technical Details
ID: 4768021
UUID: 2729204832
Node ID: PR_kwDOOfq5fc6irFxg
Host: GitHub
Repository: idiap/python-packagers
Mergeable: Yes
Merge State: Clean
Rebaseable: Yes