Skip to content

Bump the all group across 1 directory with 4 updates#125

Closed
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/go_modules/all-a723cc51e2
Closed

Bump the all group across 1 directory with 4 updates#125
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/go_modules/all-a723cc51e2

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 3, 2026

Bumps the all group with 3 updates in the / directory: github.com/google/go-containerregistry, github.com/maxbrunsfeld/counterfeiter/v6 and github.com/openvex/go-vex.

Updates github.com/google/go-containerregistry from 0.21.0 to 0.21.3

Release notes

Sourced from github.com/google/go-containerregistry's releases.

v0.21.3

What's Changed

New Contributors

Full Changelog: google/go-containerregistry@v0.21.2...v0.21.3

v0.21.2

What's Changed

Full Changelog: google/go-containerregistry@v0.21.1...v0.21.2

v0.21.1

This release fixes a regression in crane introduced in the previous release.

What's Changed

New Contributors

Full Changelog: google/go-containerregistry@v0.21.0...v0.21.1

Commits
  • 3888fb8 bump golang to 1.25.7 (#2236)
  • f439624 tarball: detect symlink cycles in extractFileFromTar (#2232)
  • 400c263 mutate: reject path traversal and symlink escape in Extract (#2227)
  • 47eedc9 Bump goreleaser/goreleaser-action in the actions group (#2220)
  • be0a845 Bump the go-deps group across 4 directories with 7 updates (#2233)
  • e916301 migrate to github.com/moby/moby modules (#2228)
  • 8b2478e Adds local file support to the crane index subcommand (#2223)
  • 9e0ccb0 Better handle redirects to https in ping (#2225)
  • 85f2bf5 crane: fix case in auth response json (#2218)
  • e971d63 Add WithFileBufferedOpener for file-backed daemon image buffering (#2214)
  • See full diff in compare view

Updates github.com/maxbrunsfeld/counterfeiter/v6 from 6.12.1 to 6.12.2

Release notes

Sourced from github.com/maxbrunsfeld/counterfeiter/v6's releases.

v6.12.2

What's Changed

Full Changelog: maxbrunsfeld/counterfeiter@v6.12.1...v6.12.2

Commits
  • 4fbda3b Merge pull request #358 from maxbrunsfeld/dependabot/go_modules/golang.org/x/...
  • 49c41c0 Bump golang.org/x/tools from 0.42.0 to 0.43.0
  • 266628f Merge pull request #357 from maxbrunsfeld/dependabot/go_modules/golang.org/x/...
  • e19e05e Bump golang.org/x/text from 0.34.0 to 0.35.0
  • 46bc143 Merge pull request #355 from maxbrunsfeld/dependabot/go_modules/golang.org/x/...
  • 2fa471e Bump golang.org/x/tools from 0.41.0 to 0.42.0
  • 0f165c0 Merge pull request #356 from maxbrunsfeld/dependabot/go_modules/golang.org/x/...
  • 807573e Bump golang.org/x/text from 0.33.0 to 0.34.0
  • 7c40434 Merge pull request #354 from maxbrunsfeld/dependabot/go_modules/github.com/on...
  • 92c75ca Bump github.com/onsi/gomega from 1.39.0 to 1.39.1
  • Additional commits viewable in compare view

Updates github.com/openvex/go-vex from 0.2.7 to 0.2.8

Release notes

Sourced from github.com/openvex/go-vex's releases.

v0.2.8

No release notes provided.

Commits
  • a340b5d Merge pull request #201 from openvex/dependabot/go_modules/all-218c634111
  • 214cbfc Bump github.com/package-url/packageurl-go
  • 6fb153b Merge pull request #200 from puerco/intoto-attestation
  • acc5892 Wrap tests to satisfy branch protection
  • 973475b Update boilerplates
  • 077b3f7 Add matrix testing
  • 76f3595 Fix linter nits. bump to golangcilint 2.11
  • ced2cc0 Add marshaling tests for predicate and statement
  • 84208d5 go mod tidy
  • 40b92ff Update predicate for new intoto and predicate
  • Additional commits viewable in compare view

Updates github.com/package-url/packageurl-go from 0.1.3 to 0.1.5

Release notes

Sourced from github.com/package-url/packageurl-go's releases.

v0.1.5

What's Changed

New Contributors

Full Changelog: package-url/packageurl-go@v0.1.4...v0.1.5

v0.1.4

What's Changed

New Contributors

Full Changelog: package-url/packageurl-go@v0.1.3...v0.1.4

Commits
  • 53d197f TestRoundtrip: complements parsing/toString tests in purl-spec
  • b33c146 parsing should support slashes in version names
  • 2c7e350 Merge pull request #90 from Talgarr/master
  • ccaaf70 Remove version requirement for TypeSwift
  • 384a9f2 update purl-spec tests
  • 8382d52 update submodule
  • 41187c2 add vscode-extension purl
  • 8cc1ea4 update purl-spec submodule
  • 77b148e add support for pkg:otp
  • c721992 add go.sum (good practice)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all group with 3 updates in the / directory: [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry), [github.com/maxbrunsfeld/counterfeiter/v6](https://github.com/maxbrunsfeld/counterfeiter) and [github.com/openvex/go-vex](https://github.com/openvex/go-vex).


Updates `github.com/google/go-containerregistry` from 0.21.0 to 0.21.3
- [Release notes](https://github.com/google/go-containerregistry/releases)
- [Commits](google/go-containerregistry@v0.21.0...v0.21.3)

Updates `github.com/maxbrunsfeld/counterfeiter/v6` from 6.12.1 to 6.12.2
- [Release notes](https://github.com/maxbrunsfeld/counterfeiter/releases)
- [Commits](maxbrunsfeld/counterfeiter@v6.12.1...v6.12.2)

Updates `github.com/openvex/go-vex` from 0.2.7 to 0.2.8
- [Release notes](https://github.com/openvex/go-vex/releases)
- [Commits](openvex/go-vex@v0.2.7...v0.2.8)

Updates `github.com/package-url/packageurl-go` from 0.1.3 to 0.1.5
- [Release notes](https://github.com/package-url/packageurl-go/releases)
- [Commits](package-url/packageurl-go@v0.1.3...v0.1.5)

---
updated-dependencies:
- dependency-name: github.com/google/go-containerregistry
  dependency-version: 0.21.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github.com/maxbrunsfeld/counterfeiter/v6
  dependency-version: 6.12.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github.com/openvex/go-vex
  dependency-version: 0.2.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github.com/package-url/packageurl-go
  dependency-version: 0.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Apr 3, 2026
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 7, 2026

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Apr 7, 2026
@dependabot dependabot Bot deleted the dependabot/go_modules/all-a723cc51e2 branch April 7, 2026 10:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants