Skip to content

chore(deps): bump github.com/spf13/cobra from 1.8.1 to 1.10.2#23

Merged
aksOps merged 1 commit intomainfrom
dependabot/go_modules/github.com/spf13/cobra-1.10.2
Apr 23, 2026
Merged

chore(deps): bump github.com/spf13/cobra from 1.8.1 to 1.10.2#23
aksOps merged 1 commit intomainfrom
dependabot/go_modules/github.com/spf13/cobra-1.10.2

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 23, 2026

Bumps github.com/spf13/cobra from 1.8.1 to 1.10.2.

Release notes

Sourced from github.com/spf13/cobra's releases.

v1.10.2

🔧 Dependencies

  • chore: Migrate from gopkg.in/yaml.v3 to go.yaml.in/yaml/v3 by @​dims in spf13/cobra#2336 - the gopkg.in/yaml.v3 package has been deprecated for some time: this should significantly cleanup dependency/supply-chains for consumers of spf13/cobra

📈 CI/CD

🔥✍🏼 Docs

🍂 Refactors

🤗 New Contributors

Full Changelog: spf13/cobra@v1.10.1...v1.10.2

Thank you to our amazing contributors!!!!! 🐍 🚀

v1.10.1

🐛 Fix

v1.0.9 of pflags brought back ParseErrorsWhitelist and marked it as deprecated

Full Changelog: spf13/cobra@v1.10.0...v1.10.1

v1.10.0

What's Changed

🚨 Attention!

This version of pflag carried a breaking change: it renamed ParseErrorsWhitelist to ParseErrorsAllowlist which can break builds if both pflag and cobra are dependencies in your project.

  • If you use both pflag and cobra, upgrade pflagto 1.0.8 andcobrato1.10.0`
  • or use the newer, fixed version of pflag v1.0.9 which keeps the deprecated ParseErrorsWhitelist

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Apr 23, 2026
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Apr 23, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgolang/​github.com/​spf13/​cobra@​v1.8.1 ⏵ v1.10.295100100100100

View full report

@aksOps aksOps enabled auto-merge (squash) April 23, 2026 00:47
@aksOps
Copy link
Copy Markdown
Contributor

aksOps commented Apr 23, 2026

@dependabot rebase

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 23, 2026

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@aksOps
Copy link
Copy Markdown
Contributor

aksOps commented Apr 23, 2026

@dependabot rebase

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 23, 2026

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@aksOps
Copy link
Copy Markdown
Contributor

aksOps commented Apr 23, 2026

@dependabot rebase

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 23, 2026

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@aksOps
Copy link
Copy Markdown
Contributor

aksOps commented Apr 23, 2026

@dependabot recreate

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/spf13/cobra-1.10.2 branch from a5a2a8f to bfdc969 Compare April 23, 2026 10:18
@dependabot dependabot Bot requested a review from aksOps as a code owner April 23, 2026 10:18
@aksOps
Copy link
Copy Markdown
Contributor

aksOps commented Apr 23, 2026

@dependabot recreate

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/spf13/cobra-1.10.2 branch from bfdc969 to a55b5e4 Compare April 23, 2026 10:31
auto-merge was automatically disabled April 23, 2026 10:37

Pull Request is not mergeable

@aksOps
Copy link
Copy Markdown
Contributor

aksOps commented Apr 23, 2026

@dependabot recreate

Bumps [github.com/spf13/cobra](https://github.com/spf13/cobra) from 1.8.1 to 1.10.2.
- [Release notes](https://github.com/spf13/cobra/releases)
- [Commits](spf13/cobra@v1.8.1...v1.10.2)

---
updated-dependencies:
- dependency-name: github.com/spf13/cobra
  dependency-version: 1.10.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/spf13/cobra-1.10.2 branch from a55b5e4 to 3fcbd3e Compare April 23, 2026 10:38
@aksOps aksOps merged commit 90a2ef6 into main Apr 23, 2026
9 checks passed
@aksOps aksOps deleted the dependabot/go_modules/github.com/spf13/cobra-1.10.2 branch April 23, 2026 10:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant