Skip to content

build(deps): bump the all-go-deps group across 1 directory with 4 updates - #7

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/all-go-deps-d8de029cd5
Open

build(deps): bump the all-go-deps group across 1 directory with 4 updates#7
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/all-go-deps-d8de029cd5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 19, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-go-deps group with 4 updates in the / directory: github.com/google/go-containerregistry, github.com/pb33f/libopenapi, github.com/pb33f/libopenapi-validator and github.com/urfave/cli/v3.

Updates github.com/google/go-containerregistry from 0.21.7 to 0.22.0

Release notes

Sourced from github.com/google/go-containerregistry's releases.

v0.22.0

What's Changed

New Contributors

Full Changelog: google/go-containerregistry@v0.21.9...v0.21.10

v0.21.9

What's Changed

Full Changelog: google/go-containerregistry@v0.21.8...v0.21.9

v0.21.8

The artifacts attached to this release are missing SLSA provenance, see #2390.

What's Changed

... (truncated)

Commits
  • 3f4ff3c fix(build): unify new build flow into cloudbuild_v2.yaml (#2419)
  • c6b5acd fix(build): correct Cloud Build schema options and source provenance hash (#2...
  • 8f4a85d go.mod: bump Go version + add toolchain directive to replace .go-version file...
  • 5481560 build(deps): bump the go-deps group across 1 directory with 3 updates (#2415)
  • 5b5c272 build(deps): bump the actions group across 1 directory with 8 updates (#2405)
  • 66dd454 remote: retry failed Puller and Pusher initialization (#2406)
  • 3f47f91 fix: add missing substitutions and workspace cleanup to new build files (#2413)
  • 4cb3583 Allow single-character repository paths (#2407)
  • 82cc428 remote: resolve push-check credentials against the repository (#2411)
  • 97815aa build: add multi-architecture Cloud Build configurations for crane, gcrane, a...
  • Additional commits viewable in compare view

Updates github.com/pb33f/libopenapi from 0.38.3 to 0.38.7

Release notes

Sourced from github.com/pb33f/libopenapi's releases.

v0.38.7 improves composed bundling by correctly lifting external Security Scheme references—including bare-file and component-fragment refs—into components.securitySchemes, with safeguards against misclassifying wrapper maps or complete OpenAPI documents. Arazzo engines can now inject a context-aware SleepFunc through EngineConfig, enabling replay-safe retry delays in durable workflow runtimes and deterministic tests while preserving existing behavior by default. This release also adds regression coverage for empty Security Requirement objects and updates golang.org/x/sync to v0.22.0.

@​kriptoburak @​khalidDaoud

v0.38.6

Fixes daveshanley/vacuum#928

v0.38.5

Fixes #597

v0.38.4

Just an internal refactor and deduplication of code, and build speed upgrades. No fixes, no features, no breaking changes,

Commits
  • 0837c9b coverage
  • 1338994 coverage
  • dd2a700 fix: compose external security scheme refs during bundling (#932)
  • a1e9b6a Bump golang.org/x/sync from 0.21.0 to 0.22.0
  • 01d2e4d arazzo: make the retry sleeper injectable via EngineConfig.SleepFunc
  • af8d024 test: cover empty security requirements
  • f078cc8 tuneups
  • 87a6330 fix: rebase external circular refs during inline bundling (vacuum #928)
  • 2abedeb Address #597
  • d4c45ce tune up build
  • Additional commits viewable in compare view

Updates github.com/pb33f/libopenapi-validator from 0.13.13 to 0.14.0

Release notes

Sourced from github.com/pb33f/libopenapi-validator's releases.

v0.14.0

Add kin-openapi parity features: router, content validation, and OpenAPI 3.2 support

Port key kin-openapi capabilities into libopenapi-validator:

  • New router package with route resolution and server matching
  • New content package for content-type negotiation and body decoding
  • Content-based parameter validation (parameters/content_parameter.go)
  • Internal bodycodec and requeststate packages for body/route caching
  • Request defaults application (request_defaults.go)
  • Validated OpenAPI 3.2 document validation support with new test specs
  • Kin parity test suites across paths, requests, responses, and root
  • Extended config options and updates across parameters, request,
  • response, and schema validation paths.
Commits
  • f309f59 fixed coverage
  • e4c1877 bump deps
  • c7963cf Add kin-openapi parity features: router, content validation, and OpenAPI 3.2 ...
  • e8302f2 Bump github.com/pb33f/libopenapi from 0.38.3 to 0.38.4
  • e8915d7 Bump github.com/go-openapi/jsonpointer from 0.23.1 to 0.23.2
  • See full diff in compare view

Updates github.com/urfave/cli/v3 from 3.10.1 to 3.11.0

Release notes

Sourced from github.com/urfave/cli/v3's releases.

v3.11.0

What's Changed

New Contributors

Full Changelog: urfave/cli@v3.10.1...v3.11.0

Commits
  • 138d3b3 Merge pull request #2410 from dearchap/issue_2404
  • 1bee208 test: fix ineffective mutex error-string assertion and add mirror cases
  • 5ec7335 Merge pull request #2408 from urfave/issue_2405
  • cccd133 Merge branch 'main' into issue_2405
  • 493a0d3 test: add shell-completion case for hidden BoolWithInverseFlag
  • 141d89c Merge pull request #2407 from dearchap/issue_2406
  • 9eee563 test: cover Run with no args, empty name, and shell completion
  • 79f8fc7 Merge pull request #2395 from utkarshalpha/fix/hide-help-command-inheritance
  • 8f56e7f Merge branch 'main' into fix/hide-help-command-inheritance
  • 339a375 Merge pull request #2386 from BrandonIrizarry/bci
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 19, 2026
…ates

Bumps the all-go-deps group with 4 updates in the / directory: [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry), [github.com/pb33f/libopenapi](https://github.com/pb33f/libopenapi), [github.com/pb33f/libopenapi-validator](https://github.com/pb33f/libopenapi-validator) and [github.com/urfave/cli/v3](https://github.com/urfave/cli).


Updates `github.com/google/go-containerregistry` from 0.21.7 to 0.22.0
- [Release notes](https://github.com/google/go-containerregistry/releases)
- [Commits](google/go-containerregistry@v0.21.7...v0.22.0)

Updates `github.com/pb33f/libopenapi` from 0.38.3 to 0.38.7
- [Release notes](https://github.com/pb33f/libopenapi/releases)
- [Commits](pb33f/libopenapi@v0.38.3...v0.38.7)

Updates `github.com/pb33f/libopenapi-validator` from 0.13.13 to 0.14.0
- [Release notes](https://github.com/pb33f/libopenapi-validator/releases)
- [Commits](pb33f/libopenapi-validator@v0.13.13...v0.14.0)

Updates `github.com/urfave/cli/v3` from 3.10.1 to 3.11.0
- [Release notes](https://github.com/urfave/cli/releases)
- [Changelog](https://github.com/urfave/cli/blob/main/docs/CHANGELOG.md)
- [Commits](urfave/cli@v3.10.1...v3.11.0)

---
updated-dependencies:
- dependency-name: github.com/google/go-containerregistry
  dependency-version: 0.21.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-go-deps
- dependency-name: github.com/pb33f/libopenapi
  dependency-version: 0.38.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-go-deps
- dependency-name: github.com/pb33f/libopenapi-validator
  dependency-version: 0.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-go-deps
- dependency-name: github.com/urfave/cli/v3
  dependency-version: 3.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-go-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/all-go-deps-d8de029cd5 branch from d109eb5 to 303fb6d Compare August 26, 2026 22:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants