Skip to content

Bump the gomod-minor-updates group across 1 directory with 9 updates#1143

Merged
calebbrown merged 1 commit into
mainfrom
dependabot/go_modules/gomod-minor-updates-767ca06d86
May 15, 2026
Merged

Bump the gomod-minor-updates group across 1 directory with 9 updates#1143
calebbrown merged 1 commit into
mainfrom
dependabot/go_modules/gomod-minor-updates-767ca06d86

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 15, 2026

Bumps the gomod-minor-updates group with 7 updates in the / directory:

Package From To
cloud.google.com/go/pubsub 1.45.3 1.50.2
github.com/gopacket/gopacket 1.3.1 1.5.0
github.com/package-url/packageurl-go 0.1.3 0.1.6
go.uber.org/zap 1.27.0 1.28.0
gocloud.dev 0.40.0 0.45.0
gocloud.dev/pubsub/kafkapubsub 0.40.0 0.45.0
google.golang.org/grpc 1.79.3 1.81.1

Updates cloud.google.com/go/pubsub from 1.45.3 to 1.50.2

Commits
  • e2bbf19 chore: librarian release pull request: 20260331T202405Z (#14314)
  • 4e6350f chore: librarian release pull request: 20260331T201226Z (#14312)
  • 7c26e42 chore(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 in /interna...
  • e5b2057 chore(deps): bump google.golang.org/grpc from 1.79.2 to 1.79.3 in /internal/g...
  • 97d824d feat(firestore): add WithAlwaysUseImplicitOrderBy option (#14260)
  • eb1fe4c chore: librarian release pull request: 20260331T193117Z (#14310)
  • 8a34364 feat(bigtable): check alts if we return permission denied for pingandwarm (#...
  • 98a546d chore: update version.go template (#14307)
  • efb8c17 chore: add biglake and hive (#14306)
  • 4c0232a fix(pubsub): check for nil concurrency control span (#14303)
  • Additional commits viewable in compare view

Updates github.com/gopacket/gopacket from 1.3.1 to 1.5.0

Release notes

Sourced from github.com/gopacket/gopacket's releases.

v1.5.0

What's Changed

New Contributors

Full Changelog: gopacket/gopacket@v1.4.0...v1.5.0

v1.4.0

What's Changed

New Contributors

... (truncated)

Commits
  • ac0316a feat: support to parse enip and cip protocols for industrial automation (#137)
  • c656f7a fix: prevent panic when creating flows from malformed linux sll packets (#139)
  • 34a6022 afpacket: add vnet_hdr_size option that can be passed to NewTPacket (#136)
  • f251eb3 fix: Update MAC prefixes and generation logic (#138)
  • e229ad0 afpacket: add protocol option that can be passed to NewTPacket (#135)
  • f972276 gtp: assign value to data[0] after PrependBytes (#130)
  • 1365ed5 Bump actions/setup-go from 5 to 6 (#131)
  • 3df4fdc added apsp (from Google's repo) (#129)
  • cabc5c7 added ague (from google's repo) (#128)
  • fa445ca Fix Dot11InformationElement parsing panic (#124)
  • Additional commits viewable in compare view

Updates github.com/package-url/packageurl-go from 0.1.3 to 0.1.6

Release notes

Sourced from github.com/package-url/packageurl-go's releases.

v0.1.5

What's Changed

New Contributors

Full Changelog: package-url/packageurl-go@v0.1.4...v0.1.5

v0.1.4

What's Changed

New Contributors

Full Changelog: package-url/packageurl-go@v0.1.3...v0.1.4

Commits
  • a74324e Optimize parsing and serialization performance (#86)
  • b41f387 Address review feedback and add chrome-extension validation
  • a546cc5 Optimize parsing and serialization performance
  • 53d197f TestRoundtrip: complements parsing/toString tests in purl-spec
  • b33c146 parsing should support slashes in version names
  • 2c7e350 Merge pull request #90 from Talgarr/master
  • ccaaf70 Remove version requirement for TypeSwift
  • 384a9f2 update purl-spec tests
  • 8382d52 update submodule
  • 41187c2 add vscode-extension purl
  • Additional commits viewable in compare view

Updates go.uber.org/zap from 1.27.0 to 1.28.0

Release notes

Sourced from go.uber.org/zap's releases.

v1.28.0

Enhancements:

  • #1534[]: Add zapcore.CheckPreWriteHook and CheckedEntry.Before method for transforming entries before they are written to any Cores.

#1534: uber-go/zap#1534

v1.27.1

Enhancements:

  • #1501[]: prevent Object from panicking on nils
  • #1511[]: Fix a race condition in WithLazy.

Thanks to @​rabbbit, @​alshopov, @​jquirke, @​arukiidou for their contributions to this release.

#1501: uber-go/zap#1501 #1511: uber-go/zap#1511

Changelog

Sourced from go.uber.org/zap's changelog.

1.28.0 (27 Apr 2026)

Enhancements:

  • #1534[]: Add zapcore.CheckPreWriteHook and CheckedEntry.Before method for transforming entries before they are written to any Cores.

1.27.1 (19 Nov 2025)

Enhancements:

  • #1501[]: prevent Object from panicking on nils
  • #1511[]: Fix a race condition in WithLazy.

Thanks to @​rabbbit, @​alshopov, @​jquirke, @​arukiidou for their contributions to this release.

#1501: uber-go/zap#1501 #1511: uber-go/zap#1511

Commits

Updates gocloud.dev from 0.40.0 to 0.45.0

Release notes

Sourced from gocloud.dev's releases.

v0.45.0

What's Changed

New Contributors

Full Changelog: google/go-cloud@v0.44.0...v0.45.0

v0.44.0

What's Changed

blob

pubsub

docstore

mysql

New Contributors

... (truncated)

Commits
  • 7cc909b all: prerelease (#3664)
  • 31e3651 blob/s3blob: map S3 403 errors to PermissionDenied code (#3663)
  • c8f1226 all: update NATS dependency (#3662)
  • ac4bb89 all: Upgrade GitHub Actions for Node 24 compatibility (#3660)
  • 1497536 secrets/gcpkms: Add support for Additional Authenticated Data (AAD) (#3659)
  • 113974a all: Upgrade go.opentelemetry.io/otel/sdk to v1.40.0 (#3657)
  • 0b41d48 build(deps): bump the go_modules group across 2 directories with 1 update (#3...
  • 4c421d0 all: Update to go 1.26 (#3653)
  • b84d07f all: run go 1.26's go fix (#3654)
  • ae3c665 blob/gcsblob: derive universe domain from credentials (#3652)
  • Additional commits viewable in compare view

Updates gocloud.dev/pubsub/kafkapubsub from 0.40.0 to 0.45.0

Release notes

Sourced from gocloud.dev/pubsub/kafkapubsub's releases.

v0.45.0

What's Changed

New Contributors

Full Changelog: google/go-cloud@v0.44.0...v0.45.0

v0.44.0

What's Changed

blob

pubsub

docstore

mysql

New Contributors

... (truncated)

Commits
  • 7cc909b all: prerelease (#3664)
  • 31e3651 blob/s3blob: map S3 403 errors to PermissionDenied code (#3663)
  • c8f1226 all: update NATS dependency (#3662)
  • ac4bb89 all: Upgrade GitHub Actions for Node 24 compatibility (#3660)
  • 1497536 secrets/gcpkms: Add support for Additional Authenticated Data (AAD) (#3659)
  • 113974a all: Upgrade go.opentelemetry.io/otel/sdk to v1.40.0 (#3657)
  • 0b41d48 build(deps): bump the go_modules group across 2 directories with 1 update (#3...
  • 4c421d0 all: Update to go 1.26 (#3653)
  • b84d07f all: run go 1.26's go fix (#3654)
  • ae3c665 blob/gcsblob: derive universe domain from credentials (#3652)
  • Additional commits viewable in compare view

Updates google.golang.org/api from 0.216.0 to 0.272.0

Release notes

Sourced from google.golang.org/api's releases.

v0.272.0

0.272.0 (2026-03-16)

Features

v0.271.0

0.271.0 (2026-03-10)

Features

v0.270.0

0.270.0 (2026-03-08)

Features

v0.269.0

0.269.0 (2026-02-24)

Features

... (truncated)

Changelog

Sourced from google.golang.org/api's changelog.

0.272.0 (2026-03-16)

Features

0.271.0 (2026-03-10)

Features

0.270.0 (2026-03-08)

Features

0.269.0 (2026-02-24)

Features

Bug Fixes

  • generator: Handle preview version pkg name (#3511) (2a249ce)

... (truncated)

Commits

Updates google.golang.org/grpc from 1.79.3 to 1.81.1

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.81.1

Security

  • xds/rbac: Fix a potential authorization bypass caused by incorrectly falling through URI/DNS SANs to Subject Distinguished Name (DN) when matching the authenticated principal name. With this fix, only the first non-empty identity source will be used, as per gRFC A41. (#9111)

Bug Fixes

  • otel: Segregate client and server RPC information used for metrics and traces, to avoid one overwriting the other. (#9081)

Release 1.81.0

Behavior Changes

  • balancer/rls: Switch gauge metrics to asynchronous emission (once per collection cycle) to reduce telemetry noise and align with other gRPC language implementations. (#8808)

Dependencies

  • Minimum supported Go version is now 1.25. (#8969)

Bug Fixes

  • xds: Use the leaf cluster's security config for the TLS handshake instead of the aggregate cluster's config. (#8956)
  • transport: Send a RST_STREAM when receiving an END_STREAM when the stream is not already half-closed. (#8832)
  • xds: Fix ADS resource name validation to prevent a panic. (#8970)

...

Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels May 15, 2026
@dependabot dependabot Bot force-pushed the dependabot/go_modules/gomod-minor-updates-767ca06d86 branch from fd28436 to ae914fa Compare May 15, 2026 00:45
@kusari-inspector
Copy link
Copy Markdown

kusari-inspector Bot commented May 15, 2026

Kusari Inspector

Kusari Analysis Results:

Proceed with these changes

✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.

Both dependency and code security analyses independently recommend proceeding. The net security posture of this PR is positive: the removal of github.com/aws/aws-sdk-go eliminates two known CVEs (CVE-2020-8912 and CVE-2020-8911) related to S3 Crypto SDK weaknesses, and no new CVEs are introduced by any added or updated packages. No secrets, malicious code patterns, or workflow security issues were detected in the code changes. Two non-blocking items require follow-up but are not security blockers: (1) the transitive dependency github.com/rcrowley/go-metrics carries a BSD-2-Clause-Views license that should be reviewed and confirmed acceptable by your legal team before merging; (2) cloud.google.com/go/pubsub v1 should be fully removed from go.mod once the in-progress migration to cloud.google.com/go/pubsub/v2 v2.4.0 is complete. Neither item presents a security risk that would justify blocking this PR.

Note

View full detailed analysis result for more information on the output and the checks that were run.


@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: c6100a4, performed at: 2026-05-15T02:01:54Z

Found this helpful? Give it a 👍 or 👎 reaction!

@kusari-inspector
Copy link
Copy Markdown

Kusari PR Analysis rerun based on - ae914fa performed at: 2026-05-15T00:46:59Z - link to updated analysis

@calebbrown
Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps the gomod-minor-updates group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [cloud.google.com/go/pubsub](https://github.com/googleapis/google-cloud-go) | `1.45.3` | `1.50.2` |
| [github.com/gopacket/gopacket](https://github.com/gopacket/gopacket) | `1.3.1` | `1.5.0` |
| [github.com/package-url/packageurl-go](https://github.com/package-url/packageurl-go) | `0.1.3` | `0.1.6` |
| [go.uber.org/zap](https://github.com/uber-go/zap) | `1.27.0` | `1.28.0` |
| [gocloud.dev](https://github.com/google/go-cloud) | `0.40.0` | `0.45.0` |
| [gocloud.dev/pubsub/kafkapubsub](https://github.com/google/go-cloud) | `0.40.0` | `0.45.0` |
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.79.3` | `1.81.1` |



Updates `cloud.google.com/go/pubsub` from 1.45.3 to 1.50.2
- [Release notes](https://github.com/googleapis/google-cloud-go/releases)
- [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/CHANGES.md)
- [Commits](googleapis/google-cloud-go@pubsub/v1.45.3...pubsub/v1.50.2)

Updates `github.com/gopacket/gopacket` from 1.3.1 to 1.5.0
- [Release notes](https://github.com/gopacket/gopacket/releases)
- [Commits](gopacket/gopacket@v1.3.1...v1.5.0)

Updates `github.com/package-url/packageurl-go` from 0.1.3 to 0.1.6
- [Release notes](https://github.com/package-url/packageurl-go/releases)
- [Commits](package-url/packageurl-go@v0.1.3...v0.1.6)

Updates `go.uber.org/zap` from 1.27.0 to 1.28.0
- [Release notes](https://github.com/uber-go/zap/releases)
- [Changelog](https://github.com/uber-go/zap/blob/master/CHANGELOG.md)
- [Commits](uber-go/zap@v1.27.0...v1.28.0)

Updates `gocloud.dev` from 0.40.0 to 0.45.0
- [Release notes](https://github.com/google/go-cloud/releases)
- [Commits](google/go-cloud@v0.40.0...v0.45.0)

Updates `gocloud.dev/pubsub/kafkapubsub` from 0.40.0 to 0.45.0
- [Release notes](https://github.com/google/go-cloud/releases)
- [Commits](google/go-cloud@v0.40.0...v0.45.0)

Updates `google.golang.org/api` from 0.216.0 to 0.272.0
- [Release notes](https://github.com/googleapis/google-api-go-client/releases)
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md)
- [Commits](googleapis/google-api-go-client@v0.216.0...v0.272.0)

Updates `google.golang.org/grpc` from 1.79.3 to 1.81.1
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.79.3...v1.81.1)

Updates `google.golang.org/protobuf` from 1.36.10 to 1.36.11

---
updated-dependencies:
- dependency-name: cloud.google.com/go/pubsub
  dependency-version: 1.50.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-updates
- dependency-name: github.com/gopacket/gopacket
  dependency-version: 1.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-updates
- dependency-name: github.com/package-url/packageurl-go
  dependency-version: 0.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod-minor-updates
- dependency-name: go.uber.org/zap
  dependency-version: 1.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-updates
- dependency-name: gocloud.dev
  dependency-version: 0.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-updates
- dependency-name: gocloud.dev/pubsub/kafkapubsub
  dependency-version: 0.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-updates
- dependency-name: google.golang.org/api
  dependency-version: 0.272.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-updates
- dependency-name: google.golang.org/grpc
  dependency-version: 1.81.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-updates
- dependency-name: google.golang.org/protobuf
  dependency-version: 1.36.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod-minor-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/go_modules/gomod-minor-updates-767ca06d86 branch from ae914fa to c6100a4 Compare May 15, 2026 00:59
@kusari-inspector
Copy link
Copy Markdown

Kusari PR Analysis rerun based on - c6100a4 performed at: 2026-05-15T01:03:25Z - link to updated analysis

@calebbrown calebbrown enabled auto-merge (squash) May 15, 2026 01:04
@calebbrown calebbrown merged commit ade3224 into main May 15, 2026
10 of 12 checks passed
@calebbrown calebbrown deleted the dependabot/go_modules/gomod-minor-updates-767ca06d86 branch May 15, 2026 01:05
@kusari-inspector
Copy link
Copy Markdown

Kusari PR Analysis rerun based on - c6100a4 performed at: 2026-05-15T01:18:58Z - link to updated analysis

@kusari-inspector
Copy link
Copy Markdown

Kusari PR Analysis rerun based on - c6100a4 performed at: 2026-05-15T02:02:22Z - link to updated analysis

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant