-
Notifications
You must be signed in to change notification settings - Fork 9
build(deps): bump the security group across 1 directory with 17 updates #3387
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
dependabot
wants to merge
1
commit into
main
Choose a base branch
from
dependabot/go_modules/security-3d9ba9736e
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the security group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.41.0` | `1.41.1` | | [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.32.6` | `1.32.7` | | [github.com/aws/aws-sdk-go-v2/feature/s3/manager](https://github.com/aws/aws-sdk-go-v2) | `1.20.18` | `1.20.19` | | [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) | `2.27.3` | `2.27.5` | | [github.com/replicatedhq/troubleshoot](https://github.com/replicatedhq/troubleshoot) | `0.123.16` | `0.123.17` | | [github.com/vmware-tanzu/velero](https://github.com/vmware-tanzu/velero) | `1.17.1` | `1.17.2` | | [helm.sh/helm/v3](https://github.com/helm/helm) | `3.19.4` | `3.19.5` | Updates `github.com/aws/aws-sdk-go-v2` from 1.41.0 to 1.41.1 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json) - [Commits](aws/aws-sdk-go-v2@v1.41.0...v1.41.1) Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.6 to 1.32.7 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json) - [Commits](aws/aws-sdk-go-v2@v1.32.6...v1.32.7) Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.19.6 to 1.19.7 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json) - [Commits](aws/aws-sdk-go-v2@service/m2/v1.19.6...service/m2/v1.19.7) Updates `github.com/aws/aws-sdk-go-v2/feature/s3/manager` from 1.20.18 to 1.20.19 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json) - [Commits](aws/aws-sdk-go-v2@service/emr/v1.20.18...feature/s3/manager/v1.20.19) Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.95.0 to 1.95.1 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json) - [Commits](aws/aws-sdk-go-v2@service/s3/v1.95.0...service/s3/v1.95.1) Updates `github.com/onsi/ginkgo/v2` from 2.27.3 to 2.27.5 - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](onsi/ginkgo@v2.27.3...v2.27.5) Updates `github.com/replicatedhq/troubleshoot` from 0.123.16 to 0.123.17 - [Release notes](https://github.com/replicatedhq/troubleshoot/releases) - [Commits](replicatedhq/troubleshoot@v0.123.16...v0.123.17) Updates `github.com/sirupsen/logrus` from 1.9.3 to 1.9.4-0.20251023124752-b61f268f75b6 - [Release notes](https://github.com/sirupsen/logrus/releases) - [Changelog](https://github.com/sirupsen/logrus/blob/master/CHANGELOG.md) - [Commits](https://github.com/sirupsen/logrus/commits) Updates `github.com/vmware-tanzu/velero` from 1.17.1 to 1.17.2 - [Release notes](https://github.com/vmware-tanzu/velero/releases) - [Changelog](https://github.com/vmware-tanzu/velero/blob/main/CHANGELOG.md) - [Commits](vmware-tanzu/velero@v1.17.1...v1.17.2) Updates `golang.org/x/crypto` from 0.46.0 to 0.47.0 - [Commits](golang/crypto@v0.46.0...v0.47.0) Updates `golang.org/x/term` from 0.38.0 to 0.39.0 - [Commits](golang/term@v0.38.0...v0.39.0) Updates `helm.sh/helm/v3` from 3.19.4 to 3.19.5 - [Release notes](https://github.com/helm/helm/releases) - [Commits](helm/helm@v3.19.4...v3.19.5) Updates `k8s.io/api` from 0.34.3 to 0.35.0 - [Commits](kubernetes/api@v0.34.3...v0.35.0) Updates `k8s.io/apiextensions-apiserver` from 0.34.3 to 0.35.0 - [Release notes](https://github.com/kubernetes/apiextensions-apiserver/releases) - [Commits](kubernetes/apiextensions-apiserver@v0.34.3...v0.35.0) Updates `k8s.io/apimachinery` from 0.34.3 to 0.35.0 - [Commits](kubernetes/apimachinery@v0.34.3...v0.35.0) Updates `k8s.io/cli-runtime` from 0.34.3 to 0.35.0 - [Commits](kubernetes/cli-runtime@v0.34.3...v0.35.0) Updates `k8s.io/client-go` from 0.34.3 to 0.35.0 - [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md) - [Commits](kubernetes/client-go@v0.34.3...v0.35.0) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go-v2 dependency-version: 1.41.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: github.com/aws/aws-sdk-go-v2/config dependency-version: 1.32.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: github.com/aws/aws-sdk-go-v2/credentials dependency-version: 1.19.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: github.com/aws/aws-sdk-go-v2/feature/s3/manager dependency-version: 1.20.19 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: github.com/aws/aws-sdk-go-v2/service/s3 dependency-version: 1.95.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.27.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: github.com/replicatedhq/troubleshoot dependency-version: 0.123.17 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: github.com/sirupsen/logrus dependency-version: 1.9.4-0.20251023124752-b61f268f75b6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: github.com/vmware-tanzu/velero dependency-version: 1.17.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: golang.org/x/crypto dependency-version: 0.47.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security - dependency-name: golang.org/x/term dependency-version: 0.39.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security - dependency-name: helm.sh/helm/v3 dependency-version: 3.19.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: k8s.io/api dependency-version: 0.35.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security - dependency-name: k8s.io/apiextensions-apiserver dependency-version: 0.35.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security - dependency-name: k8s.io/apimachinery dependency-version: 0.35.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security - dependency-name: k8s.io/cli-runtime dependency-version: 0.35.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security - dependency-name: k8s.io/client-go dependency-version: 0.35.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security ... Signed-off-by: dependabot[bot] <support@github.com>
This was referenced Jan 17, 2026
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the security group with 7 updates in the / directory:
1.41.01.41.11.32.61.32.71.20.181.20.192.27.32.27.50.123.160.123.171.17.11.17.23.19.43.19.5Updates
github.com/aws/aws-sdk-go-v2from 1.41.0 to 1.41.1Commits
dcbed91Release 2026-01-0908120e8Regenerated Clients1d7a925Update endpoints model482067dUpdate API model4662404remove example (#3282)c28a6f4Release 2026-01-072fa7a72Regenerated Clients077cbaaUpdate endpoints model3282dbcUpdate API model3daa74aRelease 2026-01-06Updates
github.com/aws/aws-sdk-go-v2/configfrom 1.32.6 to 1.32.7Commits
5a96470Release 2024-12-19653aa80Regenerated Clientsd02b239Update endpoints model698d709Update API model885de40Fix improper use of Printf-style functions (#2934)858298aRelease 2024-12-18f58264aRegenerated Clientsdf31082Update endpoints model346690eUpdate API model4515454Release 2024-12-17Updates
github.com/aws/aws-sdk-go-v2/credentialsfrom 1.19.6 to 1.19.7Commits
e2e9697Release 2025-01-316576a09Regenerated Clientsf762573Update API modelc94df29add transfer manager doc header (#2990)880543crevert the revert on the transfer manager beta (#2993)8da49e5switch to code-generated waiters for remaining services (#2994)Updates
github.com/aws/aws-sdk-go-v2/feature/s3/managerfrom 1.20.18 to 1.20.19Commits
dcbed91Release 2026-01-0908120e8Regenerated Clients1d7a925Update endpoints model482067dUpdate API model4662404remove example (#3282)c28a6f4Release 2026-01-072fa7a72Regenerated Clients077cbaaUpdate endpoints model3282dbcUpdate API model3daa74aRelease 2026-01-06Updates
github.com/aws/aws-sdk-go-v2/service/s3from 1.95.0 to 1.95.1Commits
dcbed91Release 2026-01-0908120e8Regenerated Clients1d7a925Update endpoints model482067dUpdate API model4662404remove example (#3282)c28a6f4Release 2026-01-072fa7a72Regenerated Clients077cbaaUpdate endpoints model3282dbcUpdate API model3daa74aRelease 2026-01-06Updates
github.com/onsi/ginkgo/v2from 2.27.3 to 2.27.5Release notes
Sourced from github.com/onsi/ginkgo/v2's releases.
Changelog
Sourced from github.com/onsi/ginkgo/v2's changelog.
Commits
a928307v2.27.50d0e96ddon't make a new formatter for each GinkgoT(); that's just silly and uses pre...867ce95v2.27.459bc751CurrentTreeConstructionNodeReport: fix for nested container nodesUpdates
github.com/replicatedhq/troubleshootfrom 0.123.16 to 0.123.17Release notes
Sourced from github.com/replicatedhq/troubleshoot's releases.
Commits
06a8692chore(deps): bump helm.sh/helm/v3 from 3.19.2 to 3.19.4 in /examples/sdk/helm...a50bd61use oras.land/oras-go/v2 (#1957)d5b591dchore(deps): bump the security group across 1 directory with 3 updates (#1960)ad8ad1bchore(deps): bump actions/download-artifact from 5 to 7 (#1950)083ec78chore(deps): bump actions/upload-artifact from 5 to 6 (#1949)bd10262Update modules (#1959)985416fCopy TaintExists to pkg/k8sutil and stop importing k8s.io/kubernetes (#1952)128f931move to go.podman.io dependencies (#1956)Updates
github.com/sirupsen/logrusfrom 1.9.3 to 1.9.4-0.20251023124752-b61f268f75b6Commits
Updates
github.com/vmware-tanzu/velerofrom 1.17.1 to 1.17.2Release notes
Sourced from github.com/vmware-tanzu/velero's releases.
... (truncated)
Commits
7013a40Merge pull request #9479 from blackpiglet/add_role_rolebinding_in_resotre_seq...b188701Add Role, RoleBinding, ClusterRole, and ClusterRoleBinding in restore sequence.9d79e48Merge pull request #9458 from Lyndon-Li/release-1.171e350c0Merge branch 'release-1.17' into release-1.17339dee0Merge pull request #9459 from blackpiglet/bump_golang_and_ubuntu77b6812Replace golang.org/x/net/context with context package to fix linter issues.8e35a19Bump Golang to v1.24.11 and go/x/crypto to v0.45.0 to fix CVEs.69f29651.17.2 changelogdf05057Fix managed fields patch for resources using GenerateName (#9408)cad0169Merge pull request #9409 from shubham-pampattiwar/fix-volume-info-generatenam...Updates
golang.org/x/cryptofrom 0.46.0 to 0.47.0Commits
506e022go.mod: update golang.org/x dependencies7dacc38chacha20poly1305: error out in fips140=only modeUpdates
golang.org/x/termfrom 0.38.0 to 0.39.0Commits
a7e5b04go.mod: update golang.org/x dependencies943f25dx/term: handle transpose9b991ddx/term: handle delete keyUpdates
helm.sh/helm/v3from 3.19.4 to 3.19.5Release notes
Sourced from helm.sh/helm/v3's releases.
Commits
4a19a5bfix(rollback):errors.Isinstead of string comp7a00235fix(uninstall): supersede deployed releases578564efix null mergeUpdates
k8s.io/apifrom 0.34.3 to 0.35.0Commits
9afe7deUpdate dependencies to v0.35.0 tagbbcbaa8Merge remote-tracking branch 'origin/master' into release-1.355bced61Bump golang.org/x/crypto to v0.45.039e2e26Merge pull request #135131 from Dev1622/sig-storage/mock-expand-flake-fixc22b4a1vendor: update vendor and license metadata after replacing BeTrue usage in cs...e3b1f3dResolve lint restriction on BeTrue by introducing Succeed() with contextual e...3da327cUpdate vendored dependenciesc764b44Merge pull request #132919 from ndixita/pod-level-in-place-pod-resizeaced136Generated files from API changes02d790dAdding Resources and AllocatedResoures fields to the list of expected fields ...Updates
k8s.io/apiextensions-apiserverfrom 0.34.3 to 0.35.0Commits
a8d2a03Update dependencies to v0.35.0 tagb9eb912Merge remote-tracking branch 'origin/master' into release-1.35e526698Bump golang.org/x/crypto to v0.45.0fd7881dMerge pull request #135278 from aman4433/KUBE-1344688db5ab6Merge pull request #135131 from Dev1622/sig-storage/mock-expand-flake-fix4ed5bd4vendor: update vendor and license metadata after replacing BeTrue usage in cs...704bc3dResolve lint restriction on BeTrue by introducing Succeed() with contextual e...7d598d7Refactor: Contextualize CRDFinalizer to fix goroutine leak27e5803Update vendored dependenciesc4e434cMerge pull request #134216 from Goend/masterUpdates
k8s.io/apimachineryfrom 0.34.3 to 0.35.0Commits
72d71eaMerge remote-tracking branch 'origin/master' into release-1.35e2a2dbcBump golang.org/x/crypto to v0.45.02e9c228Merge pull request #135131 from Dev1622/sig-storage/mock-expand-flake-fixf274aacvendor: update vendor and license metadata after replacing BeTrue usage in cs...9445443Resolve lint restriction on BeTrue by introducing Succeed() with contextual e...52154f7Update vendored dependencies5a348c5KEP-5471: Extend tolerations operators (#134665)6f89492Merge pull request #133648 from richabanker/merged-discoveryc77dde2util/sort: Add MergePreservingRelativeOrder for topological sorting729c13dMerge pull request #134624 from yt2985/podcertificates-betaUpdates
k8s.io/cli-runtimefrom 0.34.3 to 0.35.0Commits
d9055a8Update dependencies to v0.35.0 tagb1c72f6Merge remote-tracking branch 'origin/master' into release-1.358b2d026Bump golang.org/x/crypto to v0.45.0dd906d1Merge pull request #135131 from Dev1622/sig-storage/mock-expand-flake-fixbf2e5e5vendor: update vendor and license metadata after replacing BeTrue usage in cs...6796641Resolve lint restriction on BeTrue by introducing Succeed() with contextual e...fb22739Update vendored dependenciesaaf392aMerge pull request #134870 from pmengelbert/pmengelbert/kuberc/45410342Add client-go credential plugin to kubercbd08406Introduce --as-user-extra persistent flag in kubectl (#134378)Updates
k8s.io/client-gofrom 0.34.3 to 0.35.0Commits
9bcb694Update dependencies to v0.35.0 tag2d83546Merge remote-tracking branch 'origin/master' into release-1.3556b4af2Merge pull request #135591 from p0lyn0mial/upstream-watchlist-reflector-log-f...891f94cMerge remote-tracking branch 'origin/master' into release-1.3565ffe04Merge pull request #135580 from serathius/client-go-transformer2fe4ac2downgrade reflector watchlist fallback log to V(4)97256a6Bump golang.org/x/crypto to v0.45.046360b5Merge pull request #135131 from Dev1622/sig-storage/mock-expand-flake-fix171ef8cUse transformer in consistency checker3878a64vendor: update vendor and license metadata after replacing BeTrue usage in cs...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions