Skip to content

build(deps): bump github.com/Glyndor/authcore from 1.11.3 to 1.11.5 in /examples/username - #244

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/go_modules/examples/username/develop/github.com/Glyndor/authcore-1.11.5
Closed

build(deps): bump github.com/Glyndor/authcore from 1.11.3 to 1.11.5 in /examples/username#244
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/go_modules/examples/username/develop/github.com/Glyndor/authcore-1.11.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/Glyndor/authcore from 1.11.3 to 1.11.5.

Release notes

Sourced from github.com/Glyndor/authcore's releases.

v1.11.5

What's Changed

Full Changelog: v1.11.4...v1.11.5

v1.11.4

What's Changed

Full Changelog: v1.11.3...v1.11.4

Commits
  • 30f019a release: v1.11.5 (#224)
  • 979e240 feat(keymanager): record the on-disk key layout version (#221)
  • 81718cc fix(keymanager): tighten the key directory, never loosen it (#223)
  • a3d2108 release: v1.11.4 (#217)
  • 21b899a fix(deps): require go 1.26.5 to close the crypto/tls ECH leak (#216)
  • 3a83205 build(deps): bump golang.org/x/net from 0.56.0 to 0.57.0 (#212)
  • 1e3c3de ci(examples): resolve the examples through a Go workspace (#214)
  • e485cc8 build(deps): bump github.com/gofiber/fiber/v3 from 3.3.0 to 3.4.0 in /example...
  • 1cbd4d0 ci(deps): bump actions/setup-go from 6.5.0 to 7.0.0 (#205)
  • 63d6c00 ci(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#207)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/Glyndor/authcore](https://github.com/Glyndor/authcore) from 1.11.3 to 1.11.5.
- [Release notes](https://github.com/Glyndor/authcore/releases)
- [Commits](v1.11.3...v1.11.5)

---
updated-dependencies:
- dependency-name: github.com/Glyndor/authcore
  dependency-version: 1.11.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the type:deps Dependency update label Jul 27, 2026
@dependabot
dependabot Bot requested a review from Jaro-c as a code owner July 27, 2026 07:16
@dependabot dependabot Bot added the type:deps Dependency update label Jul 27, 2026
Jaro-c added a commit that referenced this pull request Jul 28, 2026
v1.11.6 produced **ten** pull requests that all said the same thing —
#235 through #244, each bumping `github.com/Glyndor/authcore` in one
example module, all of them already stale by one patch before anyone
looked at them.

That cost is mine. Dropping the `replace` in #213 was right — it stopped
the examples claiming versions that never applied (v1.1.1, v1.2.2,
v1.9.0, v1.10.6, all masked by the replace) and gave anyone copying a
directory out of the tree a `require` that means something. But it also
made authcore a tracked dependency of all nine example modules, so every
release drifts them in lockstep.

A group is what they were all along: they move together by construction.
One group, one review, and the versions stay honest.

The root module keeps its own ungrouped entry. A bump there changes what
a consumer actually resolves and deserves to be looked at on its own —
which is exactly what happened with `x/crypto` 0.54.0 this week.

Validated the file parses and carries the group. The existing ten will
close themselves once Dependabot regroups on its next daily run; I would
rather let it do that than merge ten stale pull requests by hand.

Signed-off-by: Jaro-c <75870284+Jaro-c@users.noreply.github.com>
@Jaro-c

Jaro-c commented Jul 28, 2026

Copy link
Copy Markdown
Member

Superseded by the grouping in #247 — these nine move together by construction, so Dependabot will propose them as one pull request on its next run, against the current release rather than v1.11.5.

@Jaro-c Jaro-c closed this Jul 28, 2026
@Jaro-c
Jaro-c deleted the dependabot/go_modules/examples/username/develop/github.com/Glyndor/authcore-1.11.5 branch July 28, 2026 02:35
@dependabot @github

dependabot Bot commented on behalf of github Jul 28, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:deps Dependency update

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant