Skip to content

deps(deps): bump the gomod-minor-and-patch group across 1 directory with 31 updates#275

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/gomod-minor-and-patch-159eea7d7c
Closed

deps(deps): bump the gomod-minor-and-patch group across 1 directory with 31 updates#275
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/gomod-minor-and-patch-159eea7d7c

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 19, 2026

Bumps the gomod-minor-and-patch group with 24 updates in the / directory:

Package From To
cloud.google.com/go/storage 1.49.0 1.62.2
github.com/MShekow/directory-checksum 1.4.9 1.4.18
github.com/atombender/go-jsonschema 0.23.0 0.23.1
github.com/aws/aws-lambda-go 1.47.0 1.54.0
github.com/aws/aws-sdk-go-v2/config 1.29.7 1.32.17
github.com/cloudflare/cloudflare-go 0.104.0 0.116.0
github.com/disgoorg/disgo 0.18.5 0.19.3
github.com/fatih/color 1.18.0 1.19.0
github.com/go-git/go-git/v5 5.19.0 5.19.1
github.com/onsi/gomega 1.38.2 1.41.0
github.com/otiai10/copy 1.14.0 1.14.1
github.com/pulumi/pulumi-aws/sdk/v6 6.83.0 6.83.3
github.com/pulumi/pulumi-cloudflare/sdk/v6 6.2.0 6.15.0
github.com/pulumi/pulumi-docker/sdk/v4 4.5.8 4.11.2
github.com/pulumi/pulumi-gcp/sdk/v8 8.0.0 8.41.1
github.com/pulumi/pulumi-kubernetes/sdk/v4 4.18.1 4.31.0
github.com/pulumi/pulumi-mongodbatlas/sdk/v3 3.30.0 3.38.0
github.com/pulumi/pulumi-random/sdk/v4 4.17.0 4.20.0
github.com/pulumi/pulumi/pkg/v3 3.184.0 3.241.0
github.com/samber/lo 1.38.1 1.53.0
github.com/tmc/langchaingo 0.1.13 0.1.14
go.mongodb.org/mongo-driver 1.16.1 1.17.9
k8s.io/apimachinery 0.35.0 0.36.1
k8s.io/client-go 0.35.0 0.36.1

Updates cloud.google.com/go/storage from 1.49.0 to 1.62.2

Release notes

Sourced from cloud.google.com/go/storage's releases.

storage: v1.62.2

v1.62.2 (2026-05-18)

Features

Bug Fixes

  • restore metadata operations timeout in gRPC (#14575) (275ff562)

  • Set default chunkRetryDeadline to 32s in NewWriterFromAppendableObject (#14458) (ec7c7d66)

  • refactor userProject metadata propagation in ListObjects (#14533) (fbb543e3)

storage: v1.59.3

v1.59.3 (2026-05-05)

Bug Fixes

container: v1.52.0

v1.52.0 (2026-05-14)

Features

Commits
  • 50a5755 chore: librarian release pull request: 20260518T161338Z (#14610)
  • 585840f spanner: skip flaky TestIntegration_DbRemovalRecovery (#14607)
  • f8bf88f test(spanner): retry query after database recreation in integration test (#14...
  • 9168ab8 chore(librariangen): tweak release preview test (#14599)
  • f8b9a93 fix(spanner/spannertest): Support UUID as a base data type (#14117)
  • a42fd83 fix(internal/librariange): release preview support (#14588)
  • d944830 fix(datastore): add retries to emulator (#14591)
  • c5aaedc chore: migrate Go configuration in librarian.yaml (#14587)
  • 8a0e849 doc(agentplatform): Add notes and quick examples to the README
  • 033f4fe chore: librarian release pull request: 20260514T191310Z (#14589)
  • Additional commits viewable in compare view

Updates github.com/MShekow/directory-checksum from 1.4.9 to 1.4.18

Release notes

Sourced from github.com/MShekow/directory-checksum's releases.

v1.4.18

Changelog

  • 4ce00c57b5c7d95d5341b2af5d33a125f1559b0b chore(deps): update goreleaser/goreleaser-action action to v7.2.1 (#122)
  • 238103b19a4526004e8be9eaf8853668ab7fd9fd chore(deps): update go toolchain directive to v1.26.3 (#121)
  • c4d0ac4ccbf366b722c91ad3b00febec87166f27 chore(deps): update robinraju/release-downloader action to v1.13 (#120)
  • 7cc7f005a503338f9980203ed35572d4f4d0d446 chore(deps): update goreleaser/goreleaser-action action to v7.1.0 (#119)

v1.4.17

Changelog

  • b5ec9cb649e9298e020b860d44de3655d8dc99db chore(deps): pin GitHub Actions digests (#117)
  • 9e14614cba7ea4d2e45bff7d898976b472033023 chore: configure Renovate to pin GitHub Action digests
  • d0db2cce14af7ef180eab64db0a8f413a1b0a2bf chore(deps): update dependency go to v1.26.2 (#116)
  • e7b210875c142a2858cccb0988451491413f064e chore(deps): update anchore/scan-action action to v7.4.0 (#115)
  • ebcb84ba64784235854e0e9aeed2270a8af825ad chore(deps): update anchore/sbom-action action to v0.24.0 (#114)
  • db43f1ecb8acf2c8cf9fa982f75aa762503a563b chore(deps): update actions/setup-go action to v6.4.0 (#113)
  • a3f08e15d4a61e1c01cd0fb911db75b13cf66145 chore(deps): update anchore/sbom-action action to v0.23.1 (#112)
  • 3dac27826410e350598c6aa2176dbaa05f6310f6 chore(deps): update dominikh/staticcheck-action action to v1.4.1 (#111)
  • 1c6495a73c454eac1d963a6d8c4e3eda0fb04ec6 chore(deps): update actions/attest-build-provenance action to v4.1.0 (#110)
  • b51cc5cb9a579d6c7ba0d18da8d3ce983e46cfba chore(deps): update actions/attest-build-provenance action to v4 (#109)
  • 6c3b5f1771cf4d51dc2ed21e63a8f480b7a7d728 chore(deps): update actions/setup-go action to v6.3.0 (#108)

v1.4.16

Changelog

  • 17f5c9e9ca5e402a02dddc513b235dbb27eac6c6 chore(deps): update anchore/sbom-action action to v0.23.0 (#107)
  • 05a7b47be8bcdaaf7107212e8304adae17cf9675 chore(deps): update dependency go to v1.26.1 (#106)
  • 1138ae7b4da6bea17e4c4cf98cf44f88de52f26b chore(deps): update goreleaser/goreleaser-action action to v7 (#105)

v1.4.15

Changelog

  • d3231e88115606eff0747a131104d3405d941633 chore(renovate): remove digest pinning from GHA
  • f821a8b45ec07ed8545950646f4bd61115595e00 chore: delete accidentally-committed file
  • 068c44d880c0d8638e88d6f2a829f1fe0e20f159 ci: update GitHub action versions from digest to concrete semantic version
  • afc8dbe2c5780828c308a177d2db27bd44c90022 chore(deps): update dependency go to v1.26.0 (#99)
  • 0f4f17bdc2cf7aa323ba33c43bdf5506f594afd2 chore(deps): update anchore/sbom-action digest to deef08a (#89)
  • 72ecf231f53888d31e777f32feeceb9f5b83543b chore(deps): update anchore/scan-action digest to 8d2fce0 (#90)
  • e65eaab36e0cbbdc3f2018c39695cd63be4d4fac chore(deps): update actions/setup-go digest to 7a3fe6c (#91)

v1.4.14

Changelog

  • 835dc1df98d09ea8dcb689bf7ec52255722d5118 chore(deps): update dependency go to v1.25.6 (#95)
  • 1f0a046b816e12c7d68aeb5b4e22d48de5f8d784 chore(deps): update dependency go to v1.25.6 (#94)
  • 1be2511f81925c1af8724c79af0791e39e24b228 chore(deps): update actions/checkout action to v6 (#93)

v1.4.13

Changelog

  • f138506bd6dac9fd15ba9aa284ac96e1f0087f21 chore(deps): update dependency go to v1.25.5 (#92)
  • bca7d0f7ddedd418cd3ce2cd34795a1e6eab7478 chore(deps): update dependency go (#87)
  • 8626fc7cf66f87d73abdf757cf0ee18155dac816 chore(deps): update actions/checkout digest to 93cb6ef (#88)
  • a82ae184c179610d72dda62204e0065c391232b9 chore(deps): update dependency go to v1.25.4 (#86)

... (truncated)

Commits
  • 4ce00c5 chore(deps): update goreleaser/goreleaser-action action to v7.2.1 (#122)
  • 238103b chore(deps): update go toolchain directive to v1.26.3 (#121)
  • c4d0ac4 chore(deps): update robinraju/release-downloader action to v1.13 (#120)
  • 7cc7f00 chore(deps): update goreleaser/goreleaser-action action to v7.1.0 (#119)
  • b5ec9cb chore(deps): pin GitHub Actions digests (#117)
  • 9e14614 chore: configure Renovate to pin GitHub Action digests
  • d0db2cc chore(deps): update dependency go to v1.26.2 (#116)
  • e7b2108 chore(deps): update anchore/scan-action action to v7.4.0 (#115)
  • ebcb84b chore(deps): update anchore/sbom-action action to v0.24.0 (#114)
  • db43f1e chore(deps): update actions/setup-go action to v6.4.0 (#113)
  • Additional commits viewable in compare view

Updates github.com/atombender/go-jsonschema from 0.23.0 to 0.23.1

Release notes

Sourced from github.com/atombender/go-jsonschema's releases.

v0.23.1

What's Changed

New Contributors

Full Changelog: omissis/go-jsonschema@v0.23.0...v0.23.1

Commits
  • 5c08d7e fix: replace deprecated goreleaser --debug flag with --verbose
  • 9050015 fix: introduce specialized docker-container builder for buildx to make the sb...
  • 07df3da fix: introduce containerd as driver to work with sbom attestation
  • 22aebde Fix bugs in codegen when the struct has additional fields and constraints at ...
  • 0827449 feat/update-deps-2026-05-09 (#558)
  • d7e5ed1 chore(deps): update dependency markdownlint-cli2 to v0.22.1 (#543)
  • 74f12af chore(deps): update dependency shfmt to v3.13.1 (#539)
  • See full diff in compare view

Updates github.com/aws/aws-lambda-go from 1.47.0 to 1.54.0

Release notes

Sourced from github.com/aws/aws-lambda-go's releases.

v1.54.0

What's Changed

New Contributors

Full Changelog: aws/aws-lambda-go@v1.54.0...v1.53.0

v1.53.0

What's Changed

New Contributors

Full Changelog: aws/aws-lambda-go@v1.53.0...v1.52.0

v1.52.0

What's Changed

New Contributors

Full Changelog: aws/aws-lambda-go@v1.51.2...v1.52.0

v1.51.2

What's Changed

New Contributors

Full Changelog: aws/aws-lambda-go@v1.51.1...v1.51.2

v1.51.1

What's Changed

Full Changelog: aws/aws-lambda-go@v1.51.0...v1.51.1

v1.51.0

What's Changed

... (truncated)

Commits
  • ca19f6f Allow ClientContext.Custom unmarshaling for non-string (JSON) values (#620)
  • 9c32960 Merge pull request #619 from maximrub/inbound-federation
  • ebe38d9 add support for Cognito Inbound federation Lambda trigger
  • 71624ac Fix spelling typos (#616)
  • 33e4dc3 Update workflows for go 1.26 (#617)
  • e1cb461 Merge pull request #612 from yhamano0312/feat/add-s3-event-fields
  • a66ce2d Merge branch 'main' into feat/add-s3-event-fields
  • 9dac8a5 Add structured logging helper (#614)
  • 6252f73 fix: always return PhysicalResourceID for CFn CustomResources (#613)
  • be52e48 feat: add lifecycle event data structure and corresponding test for S3 events
  • Additional commits viewable in compare view

Updates github.com/aws/aws-sdk-go-v2/config from 1.29.7 to 1.32.17

Commits

Updates github.com/aws/aws-sdk-go-v2/credentials from 1.17.60 to 1.19.16

Commits

Updates github.com/cloudflare/cloudflare-go from 0.104.0 to 0.116.0

Release notes

Sourced from github.com/cloudflare/cloudflare-go's releases.

v0.116.0

ENHANCEMENTS:

  • access_service_tokens: Added graceful rotation support for client secrets (#4189)

v0.115.0

ENHANCEMENTS:

  • access_service_token: add last_seen_at field (#3838)
  • dns: Add settings to DNSRecord (#3670)
  • teams_rules: add support for biso admin controls v2 (#3848)

DEPENDENCIES:

  • deps: bumps dependabot/fetch-metadata from 2.2.0 to 2.3.0 (#3865)
  • deps: bumps github.com/go-git/go-git/v5 from 5.11.0 to 5.13.0 (#3869)
  • deps: bumps github.com/goccy/go-json from 0.10.4 to 0.10.5 (#3870)
  • deps: bumps golang.org/x/net from 0.25.0 to 0.33.0 (#3868)

v0.114.0

NOTES:

  • rulesets: remove http_request_sbfm phase (#3824)
  • workers: The placement_mode attribute in script upload responses has been deprecated. The new attribute placement.mode should be used instead. (#3825)

ENHANCEMENTS:

  • access_application: added more fields to private destinations (#3829)
  • teams_rules: add support for resolve_dns_internally settings on dns_resolver rules (#3779)
  • waiting_room: add waiting room turnstile integration fields (#3764)
  • workers: Add new placement attribute object in script upload responses. It contains the mode and status attributes. (#3825)

DEPENDENCIES:

  • deps: bumps golang.org/x/net from 0.33.0 to 0.34.0 (#3796)
  • deps: bumps golang.org/x/time from 0.8.0 to 0.9.0 (#3783)

v0.113.0

ENHANCEMENTS:

  • teams_location: make location parameters optional (#3758)

DEPENDENCIES:

  • deps: bumps golang.org/x/net from 0.32.0 to 0.33.0 (#3756)

v0.112.0

ENHANCEMENTS:

  • access_application: support Access service token + multi-valued authentication for SCIM provisioning (#3708)

... (truncated)

Changelog

Sourced from github.com/cloudflare/cloudflare-go's changelog.

0.116.0 (September 5th, 2025)

ENHANCEMENTS:

  • access_service_tokens: Added graceful rotation support for client secrets (#4189)

0.115.0 (January 29th, 2025)

ENHANCEMENTS:

  • access_service_token: add last_seen_at field (#3838)
  • dns: Add settings to DNSRecord (#3670)
  • teams_rules: add support for biso admin controls v2 (#3848)

DEPENDENCIES:

  • deps: bumps dependabot/fetch-metadata from 2.2.0 to 2.3.0 (#3865)
  • deps: bumps github.com/go-git/go-git/v5 from 5.11.0 to 5.13.0 (#3869)
  • deps: bumps github.com/goccy/go-json from 0.10.4 to 0.10.5 (#3870)
  • deps: bumps golang.org/x/net from 0.25.0 to 0.33.0 (#3868)

0.114.0 (January 15th, 2025)

NOTES:

  • rulesets: remove http_request_sbfm phase (#3824)
  • workers: The placement_mode attribute in script upload responses has been deprecated. The new attribute placement.mode should be used instead. (#3825)

ENHANCEMENTS:

  • access_application: added more fields to private destinations (#3829)
  • teams_rules: add support for resolve_dns_internally settings on dns_resolver rules (#3779)
  • waiting_room: add waiting room turnstile integration fields (#3764)
  • workers: Add new placement attribute object in script upload responses. It contains the mode and status attributes. (#3825)

DEPENDENCIES:

  • deps: bumps golang.org/x/net from 0.33.0 to 0.34.0 (#3796)
  • deps: bumps golang.org/x/time from 0.8.0 to 0.9.0 (#3783)

0.113.0 (January 1st, 2025)

ENHANCEMENTS:

  • teams_location: make location parameters optional (#3758)

DEPENDENCIES:

  • deps: bumps golang.org/x/net from 0.32.0 to 0.33.0 (#3756)

... (truncated)

Commits
  • 1eda786 Update CHANGELOG.md
  • 1317436 Update CHANGELOG.md for #4189
  • fd41d6b Merge pull request #4189 from GreenStage/aholland/client_secret_version
  • 8f93e33 Bump golangci/golangci-lint-action to fix CI errors
  • d5bd4b9 Add graceful rotation support for client secrets
  • 57714bf Update CHANGELOG.md
  • b063df7 generate changelog
  • 46140a1 Merge pull request #3870 from cloudflare/dependabot/go_modules/github.com/goc...
  • 3abb34b add CHANGELOG for #3870
  • c726fce Bump github.com/goccy/go-json from 0.10.4 to 0.10.5
  • Additional commits viewable in compare view

Updates github.com/disgoorg/disgo from 0.18.5 to 0.19.3

Release notes

Sourced from github.com/disgoorg/disgo's releases.

v0.19.3

What's Changed

New Contributors

Full Changelog: disgoorg/disgo@v0.19.2...v0.19.3

v0.19.2

What's Changed

Full Changelog: disgoorg/disgo@v0.19.1...v0.19.2

v0.19.1

What's Changed

Full Changelog: disgoorg/disgo@v0.19.0...v0.19.1

v0.19.0

What's Changed

[!NOTE] This release includes support DAVE (E2EE voice) which will be required for all voice connections starting on March 1st 2026. If you need help or found issues with our implementation please reach out to us via GitHub issues/discussions or our support server (see README.md for invite link). For a basic example see: https://github.com/disgoorg/disgo/blob/v0.19.0/_examples/voice/main.go

[!WARNING] This release includes breaking changes. Please review the Breaking Changes section below for details. If you need help migrating please reach out to us via GitHub discussions or our support server (see README.md for invite link).

Added

... (truncated)

Commits

Updates github.com/fatih/color from 1.18.0 to 1.19.0

Release notes

Sourced from github.com/fatih/color's releases.

v1.19.0

What's Changed

New Contributors

Full Changelog: fatih/color@v1.18.0...v1.19.0

Commits
  • ca25f6e Merge pull request #266 from fatih/dependabot/github_actions/actions/setup-go-6
  • 1205984 Bump actions/setup-go from 5 to 6
  • 5715c20 Merge pull request #269 from UnSubble/main
  • 2f6e200 Merge branch 'main' into main
  • f72ec94 Merge pull request #273 from fatih/dependabot/github_actions/actions/checkout-6
  • 848e633 Merge branch 'main' into main
  • 4c2cd34 Add tests
  • 7f812f0 Bump actions/checkout from 4 to 6
  • b7fc9f9 Merge pull request #259 from fatih/dependabot/github_actions/dominikh/staticc...
  • 239a88f Bump dominikh/staticcheck-action from 1.3.1 to 1.4.0
  • Additional commits viewable in compare view

Updates github.com/go-git/go-git/v5 from 5.19.0 to 5.19.1

Release notes

Sourced from github.com/go-git/go-git/v5's releases.

v5.19.1

What's Changed

Full Changelog: go-git/go-git@v5.19.0...v5.19.1

Commits
  • 3c3be60 Merge pull request #2137 from go-git/validate-v5
  • 3fba897 plumbing: format/packfile, cap delta chain depth in parser
  • a97d660 Merge pull request #2125 from hiddeco/v5/format-input-bounds
  • aeaa125 plumbing: format/objfile, require Header before Read
  • 1f38e17 plumbing: format/packfile, bound inflate size
  • f7545a0 plumbing: format/idxfile, bound nr by file size
  • 170b881 Merge pull request #2116 from pjbgf/symlink-v5
  • 7b6d994 Merge pull request #2117 from hiddeco/v5/worktree-fs-mkdirall-root-noop
  • f0709b3 git: Stop validating symlink target paths
  • 776d00f git: Allow MkdirAll on worktree-root paths
  • Additional commits viewable in compare view

Updates github.com/onsi/gomega from 1.38.2 to 1.41.0

Release notes

Sourced from github.com/onsi/gomega's releases.

v1.41.0

No release notes provided.

v1.40.0

1.40.0

We're adopting a new release strategy to minimize dependency bloat in projects that consume Gomega. It is a limitation of the go mod toolchain that test subdependencies of your project's direct dependencies get pulled in as indirect dependencies. In the case of Gomega, this ends up pulling in all of Ginkgo into your go.mod even if you are only using Gomega (Gomega uses Ginkgo for its own tests).

Going forward, releases will strip out all tests, tidy up the go.mod and then push this stripped down version to a new master-lite branch. These stripped-down versions will receive the vx.y.z git tag and will be picked up by the go toolchain.

Please open an issue if this new release process causes unexpected changes for your projects.

v1.39.1

1.39.1

Update all dependencies. This auto-updated the required version of Go to 1.24, consistent with the fact that Go 1.23 has been out of support for almost six months.

v1.39.0

1.39.0

Features

Add MatchErrorStrictly which only passes if errors.Is(actual, expected) returns true. MatchError, by contrast, will fallback to string comparison.

v1.38.3

1.38.3

Fixes

make string formatitng more consistent for users who use format.Object directly

Changelog

Sourced from github.com/onsi/gomega's changelog.

1.41.0

Features

Add BeASlice and BeAnArray matchers

Fixes

Object formatting now detects pointer cycles to avoid runaway formatting output.

1.40.0

We're adopting a new release strategy to minimize dependency bloat in projects that consume Gomega. It is a limitation of the go mod toolchain that test subdependencies of your project's direct dependencies get pulled in as indirect dependencies. In the case of Gomega, this ends up pulling in all of Ginkgo into your go.mod even if you are only using Gomega (Gomega uses Ginkgo for its own tests).

Going forward, releases will strip out all tests, tidy up the go.mod and then push this stripped down version to a new master-lite branch. These stripped-down versions will receive the vx.y.z git tag and will be picked up by the go toolchain.

Please open an issue if this new release process causes unexpected changes for your projects.

1.39.1

Update all dependencies. This auto-updated the required version of Go to 1.24, consistent with the fact that Go 1.23 has been out of support for almost six months.

1.39.0

Features

Add MatchErrorStrictly which only passes if errors.Is(actual, expected) returns true. MatchError, by contrast, will fallback to string comparison.

1.38.3

Fixes

make string formatitng more consistent for users who use format.Object directly

Commits

…ith 31 updates

Bumps the gomod-minor-and-patch group with 24 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [cloud.google.com/go/storage](https://github.com/googleapis/google-cloud-go) | `1.49.0` | `1.62.2` |
| [github.com/MShekow/directory-checksum](https://github.com/MShekow/directory-checksum) | `1.4.9` | `1.4.18` |
| [github.com/atombender/go-jsonschema](https://github.com/atombender/go-jsonschema) | `0.23.0` | `0.23.1` |
| [github.com/aws/aws-lambda-go](https://github.com/aws/aws-lambda-go) | `1.47.0` | `1.54.0` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.29.7` | `1.32.17` |
| [github.com/cloudflare/cloudflare-go](https://github.com/cloudflare/cloudflare-go) | `0.104.0` | `0.116.0` |
| [github.com/disgoorg/disgo](https://github.com/disgoorg/disgo) | `0.18.5` | `0.19.3` |
| [github.com/fatih/color](https://github.com/fatih/color) | `1.18.0` | `1.19.0` |
| [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) | `5.19.0` | `5.19.1` |
| [github.com/onsi/gomega](https://github.com/onsi/gomega) | `1.38.2` | `1.41.0` |
| [github.com/otiai10/copy](https://github.com/otiai10/copy) | `1.14.0` | `1.14.1` |
| [github.com/pulumi/pulumi-aws/sdk/v6](https://github.com/pulumi/pulumi-aws) | `6.83.0` | `6.83.3` |
| [github.com/pulumi/pulumi-cloudflare/sdk/v6](https://github.com/pulumi/pulumi-cloudflare) | `6.2.0` | `6.15.0` |
| [github.com/pulumi/pulumi-docker/sdk/v4](https://github.com/pulumi/pulumi-docker) | `4.5.8` | `4.11.2` |
| [github.com/pulumi/pulumi-gcp/sdk/v8](https://github.com/pulumi/pulumi-gcp) | `8.0.0` | `8.41.1` |
| [github.com/pulumi/pulumi-kubernetes/sdk/v4](https://github.com/pulumi/pulumi-kubernetes) | `4.18.1` | `4.31.0` |
| [github.com/pulumi/pulumi-mongodbatlas/sdk/v3](https://github.com/pulumi/pulumi-mongodbatlas) | `3.30.0` | `3.38.0` |
| [github.com/pulumi/pulumi-random/sdk/v4](https://github.com/pulumi/pulumi-random) | `4.17.0` | `4.20.0` |
| [github.com/pulumi/pulumi/pkg/v3](https://github.com/pulumi/pulumi) | `3.184.0` | `3.241.0` |
| [github.com/samber/lo](https://github.com/samber/lo) | `1.38.1` | `1.53.0` |
| [github.com/tmc/langchaingo](https://github.com/tmc/langchaingo) | `0.1.13` | `0.1.14` |
| [go.mongodb.org/mongo-driver](https://github.com/mongodb/mongo-go-driver) | `1.16.1` | `1.17.9` |
| [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) | `0.35.0` | `0.36.1` |
| [k8s.io/client-go](https://github.com/kubernetes/client-go) | `0.35.0` | `0.36.1` |



Updates `cloud.google.com/go/storage` from 1.49.0 to 1.62.2
- [Release notes](https://github.com/googleapis/google-cloud-go/releases)
- [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/CHANGES.md)
- [Commits](googleapis/google-cloud-go@pubsub/v1.49.0...storage/v1.62.2)

Updates `github.com/MShekow/directory-checksum` from 1.4.9 to 1.4.18
- [Release notes](https://github.com/MShekow/directory-checksum/releases)
- [Commits](MShekow/directory-checksum@v1.4.9...v1.4.18)

Updates `github.com/atombender/go-jsonschema` from 0.23.0 to 0.23.1
- [Release notes](https://github.com/atombender/go-jsonschema/releases)
- [Commits](omissis/go-jsonschema@v0.23.0...v0.23.1)

Updates `github.com/aws/aws-lambda-go` from 1.47.0 to 1.54.0
- [Release notes](https://github.com/aws/aws-lambda-go/releases)
- [Commits](aws/aws-lambda-go@v1.47.0...v1.54.0)

Updates `github.com/aws/aws-sdk-go-v2/config` from 1.29.7 to 1.32.17
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@config/v1.29.7...config/v1.32.17)

Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.17.60 to 1.19.16
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@credentials/v1.17.60...credentials/v1.19.16)

Updates `github.com/cloudflare/cloudflare-go` from 0.104.0 to 0.116.0
- [Release notes](https://github.com/cloudflare/cloudflare-go/releases)
- [Changelog](https://github.com/cloudflare/cloudflare-go/blob/v0.116.0/CHANGELOG.md)
- [Commits](cloudflare/cloudflare-go@v0.104.0...v0.116.0)

Updates `github.com/disgoorg/disgo` from 0.18.5 to 0.19.3
- [Release notes](https://github.com/disgoorg/disgo/releases)
- [Commits](disgoorg/disgo@v0.18.5...v0.19.3)

Updates `github.com/fatih/color` from 1.18.0 to 1.19.0
- [Release notes](https://github.com/fatih/color/releases)
- [Commits](fatih/color@v1.18.0...v1.19.0)

Updates `github.com/go-git/go-git/v5` from 5.19.0 to 5.19.1
- [Release notes](https://github.com/go-git/go-git/releases)
- [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md)
- [Commits](go-git/go-git@v5.19.0...v5.19.1)

Updates `github.com/onsi/gomega` from 1.38.2 to 1.41.0
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](onsi/gomega@v1.38.2...v1.41.0)

Updates `github.com/otiai10/copy` from 1.14.0 to 1.14.1
- [Release notes](https://github.com/otiai10/copy/releases)
- [Commits](otiai10/copy@v1.14.0...v1.14.1)

Updates `github.com/pulumi/pulumi-aws/sdk/v6` from 6.83.0 to 6.83.3
- [Release notes](https://github.com/pulumi/pulumi-aws/releases)
- [Changelog](https://github.com/pulumi/pulumi-aws/blob/master/CHANGELOG_OLD.md)
- [Commits](pulumi/pulumi-aws@v6.83.0...v6.83.3)

Updates `github.com/pulumi/pulumi-cloudflare/sdk/v6` from 6.2.0 to 6.15.0
- [Release notes](https://github.com/pulumi/pulumi-cloudflare/releases)
- [Changelog](https://github.com/pulumi/pulumi-cloudflare/blob/master/CHANGELOG_OLD.md)
- [Commits](pulumi/pulumi-cloudflare@v6.2.0...v6.15.0)

Updates `github.com/pulumi/pulumi-docker/sdk/v4` from 4.5.8 to 4.11.2
- [Release notes](https://github.com/pulumi/pulumi-docker/releases)
- [Changelog](https://github.com/pulumi/pulumi-docker/blob/master/CHANGELOG_OLD.md)
- [Commits](pulumi/pulumi-docker@v4.5.8...v4.11.2)

Updates `github.com/pulumi/pulumi-gcp/sdk/v8` from 8.0.0 to 8.41.1
- [Release notes](https://github.com/pulumi/pulumi-gcp/releases)
- [Changelog](https://github.com/pulumi/pulumi-gcp/blob/master/CHANGELOG_OLD.md)
- [Commits](pulumi/pulumi-gcp@v8.0.0...v8.41.1)

Updates `github.com/pulumi/pulumi-kubernetes/sdk/v4` from 4.18.1 to 4.31.0
- [Release notes](https://github.com/pulumi/pulumi-kubernetes/releases)
- [Changelog](https://github.com/pulumi/pulumi-kubernetes/blob/master/CHANGELOG.md)
- [Commits](pulumi/pulumi-kubernetes@v4.18.1...v4.31.0)

Updates `github.com/pulumi/pulumi-mongodbatlas/sdk/v3` from 3.30.0 to 3.38.0
- [Release notes](https://github.com/pulumi/pulumi-mongodbatlas/releases)
- [Changelog](https://github.com/pulumi/pulumi-mongodbatlas/blob/master/CHANGELOG_OLD.md)
- [Commits](pulumi/pulumi-mongodbatlas@v3.30.0...v3.38.0)

Updates `github.com/pulumi/pulumi-random/sdk/v4` from 4.17.0 to 4.20.0
- [Release notes](https://github.com/pulumi/pulumi-random/releases)
- [Changelog](https://github.com/pulumi/pulumi-random/blob/master/CHANGELOG_OLD.md)
- [Commits](pulumi/pulumi-random@v4.17.0...v4.20.0)

Updates `github.com/pulumi/pulumi/pkg/v3` from 3.184.0 to 3.241.0
- [Release notes](https://github.com/pulumi/pulumi/releases)
- [Changelog](https://github.com/pulumi/pulumi/blob/master/CHANGELOG.md)
- [Commits](pulumi/pulumi@v3.184.0...v3.241.0)

Updates `github.com/pulumi/pulumi/sdk/v3` from 3.184.0 to 3.241.0
- [Release notes](https://github.com/pulumi/pulumi/releases)
- [Changelog](https://github.com/pulumi/pulumi/blob/master/CHANGELOG.md)
- [Commits](pulumi/pulumi@v3.184.0...v3.241.0)

Updates `github.com/samber/lo` from 1.38.1 to 1.53.0
- [Release notes](https://github.com/samber/lo/releases)
- [Commits](samber/lo@v1.38.1...v1.53.0)

Updates `github.com/tmc/langchaingo` from 0.1.13 to 0.1.14
- [Release notes](https://github.com/tmc/langchaingo/releases)
- [Commits](tmc/langchaingo@v0.1.13...v0.1.14)

Updates `go.mongodb.org/mongo-driver` from 1.16.1 to 1.17.9
- [Release notes](https://github.com/mongodb/mongo-go-driver/releases)
- [Commits](mongodb/mongo-go-driver@v1.16.1...v1.17.9)

Updates `golang.org/x/crypto` from 0.50.0 to 0.51.0
- [Commits](golang/crypto@v0.50.0...v0.51.0)

Updates `golang.org/x/oauth2` from 0.35.0 to 0.36.0
- [Commits](golang/oauth2@v0.35.0...v0.36.0)

Updates `golang.org/x/term` from 0.42.0 to 0.43.0
- [Commits](golang/term@v0.42.0...v0.43.0)

Updates `golang.org/x/text` from 0.36.0 to 0.37.0
- [Release notes](https://github.com/golang/text/releases)
- [Commits](golang/text@v0.36.0...v0.37.0)

Updates `google.golang.org/api` from 0.223.0 to 0.274.0
- [Release notes](https://github.com/googleapis/google-api-go-client/releases)
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md)
- [Commits](googleapis/google-api-go-client@v0.223.0...v0.274.0)

Updates `k8s.io/apimachinery` from 0.35.0 to 0.36.1
- [Commits](kubernetes/apimachinery@v0.35.0...v0.36.1)

Updates `k8s.io/client-go` from 0.35.0 to 0.36.1
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](kubernetes/client-go@v0.35.0...v0.36.1)

---
updated-dependencies:
- dependency-name: cloud.google.com/go/storage
  dependency-version: 1.62.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/MShekow/directory-checksum
  dependency-version: 1.4.18
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/atombender/go-jsonschema
  dependency-version: 0.23.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/aws/aws-lambda-go
  dependency-version: 1.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.32.17
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
  dependency-version: 1.19.16
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/cloudflare/cloudflare-go
  dependency-version: 0.116.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/disgoorg/disgo
  dependency-version: 0.19.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/fatih/color
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/go-git/go-git/v5
  dependency-version: 5.19.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.41.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/otiai10/copy
  dependency-version: 1.14.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/pulumi/pulumi-aws/sdk/v6
  dependency-version: 6.83.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/pulumi/pulumi-cloudflare/sdk/v6
  dependency-version: 6.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/pulumi/pulumi-docker/sdk/v4
  dependency-version: 4.11.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/pulumi/pulumi-gcp/sdk/v8
  dependency-version: 8.41.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/pulumi/pulumi-kubernetes/sdk/v4
  dependency-version: 4.31.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/pulumi/pulumi-mongodbatlas/sdk/v3
  dependency-version: 3.38.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/pulumi/pulumi-random/sdk/v4
  dependency-version: 4.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/pulumi/pulumi/pkg/v3
  dependency-version: 3.241.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/pulumi/pulumi/sdk/v3
  dependency-version: 3.241.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/samber/lo
  dependency-version: 1.53.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: github.com/tmc/langchaingo
  dependency-version: 0.1.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod-minor-and-patch
- dependency-name: go.mongodb.org/mongo-driver
  dependency-version: 1.17.9
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: golang.org/x/crypto
  dependency-version: 0.51.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: golang.org/x/oauth2
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: golang.org/x/term
  dependency-version: 0.43.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: golang.org/x/text
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: google.golang.org/api
  dependency-version: 0.274.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.36.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
- dependency-name: k8s.io/client-go
  dependency-version: 0.36.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels May 19, 2026
@dependabot dependabot Bot requested review from Cre-eD and smecsia as code owners May 19, 2026 02:41
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels May 19, 2026
@github-actions
Copy link
Copy Markdown

Semgrep Scan Results

Repository: api | Commit: cf2e75a

Check Status Details
⚠️ Semgrep Warning 10 warning(s), 10 total

Scanned at 2026-05-19 02:42 UTC

@github-actions
Copy link
Copy Markdown

Security Scan Results

Repository: api | Commit: cf2e75a

Check Status Details
🚨 Secret Scan SECRETS FOUND 1 potential secret(s) detected
✅ Dependencies (Trivy) Pass 0 total (no critical/high)
✅ Dependencies (Grype) Pass 0 total (no critical/high)
📦 SBOM Generated 527 components (CycloneDX)

Scanned at 2026-05-19 02:42 UTC

Cre-eD added a commit that referenced this pull request May 20, 2026
…robes

Two Scorecard warnings on PR #279 left after the deps consolidation:

1. **Pinned-Dependencies**: the sole `goCommand not pinned by hash`
   was `go install golang.org/x/vuln/cmd/govulncheck@latest` in
   govulncheck.yml. SHA-pin to v1.3.0:
   0782b76014f15f24e22a438f30f308df42899ba1. Bumps will be 1-line PRs
   going forward.

2. **Signed-Releases / releasesHaveProvenance**: the 5 most recent
   releases each carry a `.sigstore.json` SLSA build-provenance bundle
   (from actions/attest-build-provenance@v4) which Scorecard
   recognises as a *signature*, but its provenance-probe matches
   specifically on `.intoto.jsonl`. Dual-publish each `.sigstore.json`
   as a `.intoto.jsonl` alias from create-github-release.sh — same
   bytes, second name, so cosign/sigstore consumers keep the
   canonical name and Scorecard sees provenance on every future
   release. (Scorecard#3699 tracks the upstream rule extension.)

Other Scorecard warnings already handled in earlier commits of #279:

  - GHSA-crhj-59gh-8x96 / GHSA-m7cr-m3pv-hgrp (go-git ≤5.19.0) —
    bumped to v5.19.1 in the gomod-minor-and-patch group (#275).
  - GO-2022-0635 / GO-2022-0646 (aws-sdk-go v1 s3crypto) — transitive
    via Pulumi, no reachable call, already in vex/openvex.json.
  - PYSEC-2026-89 (Python markdown) — OSV record is incomplete
    (missing fixed-event); we already pin `markdown==3.9` which is
    past the 3.8.1 fix referenced in the advisory body.

Out-of-scope follow-ups (require repo-admin action, not file edits):

  - Branch protection: require ≥2 approving reviews + codeowners
    review + apply settings to admins on `main`.
  - SAST coverage 19/30 commits: historical, no retroactive fix.

Signed-off-by: Dmitrii Creed <creeed22@gmail.com>
@Cre-eD Cre-eD closed this in e3d0e73 May 20, 2026
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 20, 2026

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot dependabot Bot deleted the dependabot/go_modules/gomod-minor-and-patch-159eea7d7c branch May 20, 2026 14:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants