Skip to content

chore(deps): bump the go-dependencies group with 2 updates#76

Merged
trly merged 1 commit intomainfrom
dependabot/go_modules/go-dependencies-e9748f08ea
Apr 13, 2026
Merged

chore(deps): bump the go-dependencies group with 2 updates#76
trly merged 1 commit intomainfrom
dependabot/go_modules/go-dependencies-e9748f08ea

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Apr 10, 2026

Bumps the go-dependencies group with 2 updates: github.com/compose-spec/compose-go/v2 and github.com/google/go-containerregistry.

Updates github.com/compose-spec/compose-go/v2 from 2.10.1 to 2.10.2

Release notes

Sourced from github.com/compose-spec/compose-go/v2's releases.

v2.10.2

What's Changed

New Contributors

Full Changelog: compose-spec/compose-go@v2.10.1...v2.10.2

Commits
  • 65af4e5 Fix: Process includes before extends for proper attribute inheritance
  • d8a259c Bump actions/setup-go from 6.3.0 to 6.4.0
  • b9f4c49 Bump upload-artifact to v7 and download-artifact to v8
  • a5376f9 Pin GitHub Actions to commit SHA
  • 9e540fd migrate tests to attribute-specific test files
  • df29b8a replace tests based on a huge "full" example and use tests dedicated to each ...
  • 9dee8f4 Bump yaml/v4 v4.0.0-rc.4
  • See full diff in compare view

Updates github.com/google/go-containerregistry from 0.21.3 to 0.21.4

Release notes

Sourced from github.com/google/go-containerregistry's releases.

v0.21.4

What's Changed

New Contributors

Full Changelog: google/go-containerregistry@v0.21.3...v0.21.4

Commits
  • e8813dd goreleaser: Update goreleaser config and GH action for releases (#2253)
  • e90447d replace gcloud in binary calls in pkg/v1/google tests (#2085)
  • 0d0368c revert path traversal and symlink escape changes (#2250)
  • a2f47d4 transport: validate Bearer realm URL to prevent SSRF (#2243)
  • 19a36cd fork distribution client v3 auth-challenge as an internal package (squashed) ...
  • c612a9b Bump codecov/codecov-action from 5.5.2 to 5.5.3 in the actions group (#2240)
  • 8f92f59 Bump CI go version to 1.26.1 (#2242)
  • c99e7cf fix: update to go1.25.8, and use separate .go-version file (#2246)
  • 0794660 Bump the go-deps group across 3 directories with 5 updates (#2245)
  • 4cb93ae Undo pruning absolute links from extracted and flattened images (#2241)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-dependencies group with 2 updates: [github.com/compose-spec/compose-go/v2](https://github.com/compose-spec/compose-go) and [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry).


Updates `github.com/compose-spec/compose-go/v2` from 2.10.1 to 2.10.2
- [Release notes](https://github.com/compose-spec/compose-go/releases)
- [Commits](compose-spec/compose-go@v2.10.1...v2.10.2)

Updates `github.com/google/go-containerregistry` from 0.21.3 to 0.21.4
- [Release notes](https://github.com/google/go-containerregistry/releases)
- [Commits](google/go-containerregistry@v0.21.3...v0.21.4)

---
updated-dependencies:
- dependency-name: github.com/compose-spec/compose-go/v2
  dependency-version: 2.10.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/google/go-containerregistry
  dependency-version: 0.21.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Apr 10, 2026
@codecov
Copy link
Copy Markdown

codecov bot commented Apr 10, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@trly trly merged commit 1a4d79d into main Apr 13, 2026
10 of 11 checks passed
@dependabot dependabot bot deleted the dependabot/go_modules/go-dependencies-e9748f08ea branch April 13, 2026 04:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant