Skip to content

Bump the go_modules group across 1 directory with 13 updates - #116

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go_modules-7ffa907336
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go_modules-7ffa907336

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the go_modules group with 13 updates in the / directory:

Package From To
github.com/hjson/hjson-go/v4 4.4.0 4.5.0
github.com/ClickHouse/ch-go 0.61.5 0.65.0
github.com/compose-spec/compose-go/v2 2.1.1 2.4.1
github.com/containerd/containerd 1.7.17 1.7.36
github.com/gorilla/websocket 1.5.0 1.5.3
github.com/in-toto/in-toto-golang 0.5.0 0.11.0
github.com/moby/spdystream 0.2.0 0.5.1
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp 1.21.0 1.43.0
go.opentelemetry.io/otel/sdk 1.24.0 1.46.0
golang.org/x/crypto 0.33.0 0.55.0
golang.org/x/net 0.35.0 0.58.0
golang.org/x/oauth2 0.15.0 0.36.0
google.golang.org/grpc 1.59.0 1.83.1

Updates github.com/hjson/hjson-go/v4 from 4.4.0 to 4.5.0

Release notes

Sourced from github.com/hjson/hjson-go/v4's releases.

v4.5.0

In order to avoid stack overflows now throws an error if input Hjson contains a tree deeper than 10000 levels

The file go.mod now specifies go 1.12 instead of go 1.11

Tested on Go 1.12 and 1.24

Commits

Updates github.com/ClickHouse/ch-go from 0.61.5 to 0.65.0

Release notes

Sourced from github.com/ClickHouse/ch-go's releases.

v0.65.0

What's Changed

Breaking change if you were manually using the Writer from the compress package.

New Contributors

Full Changelog: ClickHouse/ch-go@v0.64.1...v0.65.0

v0.64.1

What's Changed

Full Changelog: ClickHouse/ch-go@v0.64.0...v0.64.1

v0.64.0

What's Changed

New Contributors

Full Changelog: ClickHouse/ch-go@v0.63.1...v0.64.0

v0.63.1

What's Changed

Full Changelog: ClickHouse/ch-go@v0.63.0...v0.63.1

... (truncated)

Commits
  • 0e83566 Merge pull request #1041 from ClickHouse/fix_potential_overflow
  • b64209f refactor: simplify overflow check
  • 05fba0a fix(security): overflow that could smuggle query
  • aadb7ee Merge pull request #1040 from ClickHouse/compressor_etc
  • 65a3012 perf(compressor): use new compression code, refactor/optimize
  • 4cdb83a Merge pull request #1039 from pablomatiasgomez/allow-creating-compressor-with...
  • b9258c0 perf(compress.writer): revert back to ifs in NewWriterWithMethods
  • 743c9d7 perf(compress.writer): use %s instead of %v
  • b26ebf4 perf(compress.writer): revert nil check and use fixed length array
  • 1d4ba47 perf(compress.writer): remove methods map and instaed do nil check
  • Additional commits viewable in compare view

Updates github.com/compose-spec/compose-go/v2 from 2.1.1 to 2.4.1

Release notes

Sourced from github.com/compose-spec/compose-go/v2's releases.

v2.4.1

What's Changed

Full Changelog: compose-spec/compose-go@v2.4.0...v2.4.1

v2.4.0

What's Changed

Full Changelog: compose-spec/compose-go@v2.3.0...v2.4.0

v2.3.0

What's Changed

New Contributors

Full Changelog: compose-spec/compose-go@v2.2.0...v2.3.0

v2.2.0

What's Changed

... (truncated)

Commits
  • 222d93c fix reset.go
  • 88ca71b fix(reset): Add cycle detector in reset.go
  • 156e22d introduce OmitEmpty in yaml processing pipeline
  • 74c1d59 always test to load config with localFileLoader
  • c558adc ingest config files with ResourceLoader
  • bff5006 detect project dir is a symlink and warn user
  • 35c9659 add support for bind mount recursive
  • 97c49fc normalize volume.target to drop trailing slash
  • fb8e04d seiralise NanoCPUs as string
  • 7218685 introduce service.gpus
  • Additional commits viewable in compare view

Updates github.com/containerd/containerd from 1.7.17 to 1.7.36

Release notes

Sourced from github.com/containerd/containerd's releases.

containerd 1.7.36

Welcome to the v1.7.36 release of containerd!

The thirty-sixth patch release for containerd 1.7 contains various fixes and updates including a security patch.

Security Updates

Highlights

Image Storage

  • Ensure all layers are fetched when multiple manifests in an index share a config descriptor (#14142)

Runtime

  • Mask /proc/interrupts and CPU thermal throttle sysfs paths in Linux containers by default (#14184)

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors

  • Samuel Karp
  • Chris Henzie
  • Derek McGowan

Changes

  • b0ab39c205 Prepare release notes for v1.7.36
  • 670a5de22f Merge commit from fork
  • a3a39e5873 Bound Walk references
  • ffc673f859 Bound Dispatch concurrency and references
  • pkg/oci: mask thermal interrupt info (#14184)
  • core/unpack: fetch layers of every config-sharing manifest (#14142)
    • 4684c683c2 core/unpack: fetch layers of every config-sharing manifest
    • 7fba9f7c3c Create new imagetest package

Dependency Changes

This release has no dependency changes

... (truncated)

Commits
  • 2892c20 Merge pull request #14229 from samuelkarp/prepare-release-1.7.36
  • cac5660 Prepare release notes for v1.7.36
  • 670a5de Merge commit from fork
  • a3a39e5 Bound Walk references
  • ffc673f Bound Dispatch concurrency and references
  • e594492 Merge pull request #14184 from samuelkarp/cherry-pick-c176f-to-release/1.7
  • 19334a4 pkg/oci: mask thermal interrupt info
  • a81ea12 Merge pull request #14142 from chrishenzie/unpack-shared-config-1.7
  • 4684c68 core/unpack: fetch layers of every config-sharing manifest
  • 7fba9f7 Create new imagetest package
  • Additional commits viewable in compare view

Updates github.com/gorilla/websocket from 1.5.0 to 1.5.3

Release notes

Sourced from github.com/gorilla/websocket's releases.

v1.5.3

Important change

This reverts the websockets package back to gorilla/websocket@931041c

What's Changed

New Contributors

Full Changelog: gorilla/websocket@v1.5.1...v1.5.3

v1.5.2

What's Changed

... (truncated)

Commits
  • ce903f6 Reverts to v1.5.0
  • 9ec25ca fixes broken random value generation
  • 1bddf2e bumps go version & removes deprecated module usage
  • 750bf92 adds GHA & Makefile configs
  • b2c246b Revert " Update go version & add verification/testing tools (#840)"
  • 09a6bab removing error handling while closing connections
  • 58af150 return errors instead of printing to logs
  • e5f1a0a excludes errchecks linter
  • b2a86a1 Do not timeout when WriteControl deadline is zero
  • 695e909 Remove hideTempErr to allow downstream users to check for errors like net.Err...
  • Additional commits viewable in compare view

Updates github.com/in-toto/in-toto-golang from 0.5.0 to 0.11.0

Release notes

Sourced from github.com/in-toto/in-toto-golang's releases.

v0.11.0

What's Changed

Full Changelog: in-toto/in-toto-golang@v0.10.0...v0.11.0

v0.10.0

What's Changed

... (truncated)

Commits
  • 36d782f Merge pull request #462 from in-toto/fix-negation-character
  • 4a09e3b match: Replace ^ with ! for negation in character classes
  • c3302e8 Merge pull request #459 from in-toto/dependabot/go_modules/github.com/go-jose...
  • 016e87e chore(deps): bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4
  • 5b9df76 Merge pull request #457 from in-toto/dependabot/go_modules/google.golang.org/...
  • 595b3fe chore(deps): bump google.golang.org/grpc from 1.79.1 to 1.79.3
  • e396d24 Merge pull request #452 from in-toto/dependabot/github_actions/all-502588e1ca
  • 142b779 Merge pull request #453 from in-toto/dependabot/go_modules/all-d8ef5820aa
  • f741bcc chore(deps): bump the all group with 2 updates
  • c374dc9 chore(deps): bump the all group across 1 directory with 2 updates
  • Additional commits viewable in compare view

Updates github.com/moby/spdystream from 0.2.0 to 0.5.1

Release notes

Sourced from github.com/moby/spdystream's releases.

v0.5.1

What's Changed

Security

Fix memory amplification in SPDY frame parsing leads to denial of service (CVE-2026-35469 / GHSA-pc3f-x583-g7j2)

Changes

Full Changelog: moby/spdystream@v0.5.0...v0.5.1

[v0.5.0] Avoid leaking timeout timer channels and update github actions

What's Changed

Full Changelog: moby/spdystream@v0.4.0...v0.5.0

[v0.4.0] fix goroutine leak and remove unused code

What's Changed

New Contributors

Full Changelog: moby/spdystream@v0.3.0...v0.4.0

[v0.3.0] Release with fixes for a race condition

What's Changed

New Contributors

Full Changelog: moby/spdystream@v0.2.0...v0.3.0

Commits
  • c59e5d7 Merge pull request #109 from thaJeztah/use_ioutil
  • 2fd0155 use ioutil.Discard for go1.13 compatibility
  • ef6121f Merge commit from fork
  • 241cec9 compare with signed Int for 32-bit Arm
  • 21c3864 Add options to customize limits
  • acf9b45 spdy: update godoc for MaxDataLength
  • eb63605 spdy: limit header-size and header-count
  • 2f21da4 spdy: fix header block byte accounting
  • 5976b66 spdy: enforce 24-bit frame length limits
  • cf0ec5d Guard against oversized SPDY frames
  • Additional commits viewable in compare view

Updates go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp from 1.21.0 to 1.43.0

Release notes

Sourced from go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp's releases.

v1.43.0/v0.65.0/v0.19.0

Added

  • Add IsRandom and WithRandom on TraceFlags, and IsRandom on SpanContext in go.opentelemetry.io/otel/trace for W3C Trace Context Level 2 Random Trace ID Flag support. (#8012)
  • Add service detection with WithService in go.opentelemetry.io/otel/sdk/resource. (#7642)
  • Add DefaultWithContext and EnvironmentWithContext in go.opentelemetry.io/otel/sdk/resource to support plumbing context.Context through default and environment detectors. (#8051)
  • Support attributes with empty value (attribute.EMPTY) in go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc. (#8038)
  • Support attributes with empty value (attribute.EMPTY) in go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc. (#8038)
  • Support attributes with empty value (attribute.EMPTY) in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc. (#8038)
  • Support attributes with empty value (attribute.EMPTY) in go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp. (#8038)
  • Support attributes with empty value (attribute.EMPTY) in go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp. (#8038)
  • Support attributes with empty value (attribute.EMPTY) in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp. (#8038)
  • Support attributes with empty value (attribute.EMPTY) in go.opentelemetry.io/otel/sdk/metric/metricdata/metricdatatest. (#8038)
  • Add support for per-series start time tracking for cumulative metrics in go.opentelemetry.io/otel/sdk/metric. Set OTEL_GO_X_PER_SERIES_START_TIMESTAMPS=true to enable. (#8060)
  • Add WithCardinalityLimitSelector for metric reader for configuring cardinality limits specific to the instrument kind. (#7855)

Changed

  • Introduce the EMPTY Type in go.opentelemetry.io/otel/attribute to reflect that an empty value is now a valid value, with INVALID remaining as a deprecated alias of EMPTY. (#8038)
  • Refactor slice handling in go.opentelemetry.io/otel/attribute to optimize short slice values with fixed-size fast paths. (#8039)
  • Improve performance of span metric recording in go.opentelemetry.io/otel/sdk/trace by returning early if self-observability is not enabled. (#8067)
  • Improve formatting of metric data diffs in go.opentelemetry.io/otel/sdk/metric/metricdata/metricdatatest. (#8073)

Deprecated

  • Deprecate INVALID in go.opentelemetry.io/otel/attribute. Use EMPTY instead. (#8038)

Fixed

  • Return spec-compliant TraceIdRatioBased description. This is a breaking behavioral change, but it is necessary to make the implementation spec-compliant. (#8027)
  • Fix a race condition in go.opentelemetry.io/otel/sdk/metric where the lastvalue aggregation could collect the value 0 even when no zero-value measurements were recorded. (#8056)
  • Limit HTTP response body to 4 MiB in go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp to mitigate excessive memory usage caused by a misconfigured or malicious server. Responses exceeding the limit are treated as non-retryable errors. (#8108)
  • Limit HTTP response body to 4 MiB in go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp to mitigate excessive memory usage caused by a misconfigured or malicious server. Responses exceeding the limit are treated as non-retryable errors. (#8108)
  • Limit HTTP response body to 4 MiB in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp to mitigate excessive memory usage caused by a misconfigured or malicious server. Responses exceeding the limit are treated as non-retryable errors. (#8108)
  • WithHostID detector in go.opentelemetry.io/otel/sdk/resource to use full path for kenv command on BSD. (#8113)
  • Fix missing request.GetBody in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp to correctly handle HTTP2 GOAWAY frame. (#8096)

What's Changed

Bumps the go_modules group with 13 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/hjson/hjson-go/v4](https://github.com/hjson/hjson-go) | `4.4.0` | `4.5.0` |
| [github.com/ClickHouse/ch-go](https://github.com/ClickHouse/ch-go) | `0.61.5` | `0.65.0` |
| [github.com/compose-spec/compose-go/v2](https://github.com/compose-spec/compose-go) | `2.1.1` | `2.4.1` |
| [github.com/containerd/containerd](https://github.com/containerd/containerd) | `1.7.17` | `1.7.36` |
| [github.com/gorilla/websocket](https://github.com/gorilla/websocket) | `1.5.0` | `1.5.3` |
| [github.com/in-toto/in-toto-golang](https://github.com/in-toto/in-toto-golang) | `0.5.0` | `0.11.0` |
| [github.com/moby/spdystream](https://github.com/moby/spdystream) | `0.2.0` | `0.5.1` |
| [go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp](https://github.com/open-telemetry/opentelemetry-go) | `1.21.0` | `1.43.0` |
| [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) | `1.24.0` | `1.46.0` |
| [golang.org/x/crypto](https://github.com/golang/crypto) | `0.33.0` | `0.55.0` |
| [golang.org/x/net](https://github.com/golang/net) | `0.35.0` | `0.58.0` |
| [golang.org/x/oauth2](https://github.com/golang/oauth2) | `0.15.0` | `0.36.0` |
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.59.0` | `1.83.1` |



Updates `github.com/hjson/hjson-go/v4` from 4.4.0 to 4.5.0
- [Release notes](https://github.com/hjson/hjson-go/releases)
- [Commits](hjson/hjson-go@v4.4.0...v4.5.0)

Updates `github.com/ClickHouse/ch-go` from 0.61.5 to 0.65.0
- [Release notes](https://github.com/ClickHouse/ch-go/releases)
- [Commits](ClickHouse/ch-go@v0.61.5...v0.65.0)

Updates `github.com/compose-spec/compose-go/v2` from 2.1.1 to 2.4.1
- [Release notes](https://github.com/compose-spec/compose-go/releases)
- [Commits](compose-spec/compose-go@v2.1.1...v2.4.1)

Updates `github.com/containerd/containerd` from 1.7.17 to 1.7.36
- [Release notes](https://github.com/containerd/containerd/releases)
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)
- [Commits](containerd/containerd@v1.7.17...v1.7.36)

Updates `github.com/gorilla/websocket` from 1.5.0 to 1.5.3
- [Release notes](https://github.com/gorilla/websocket/releases)
- [Commits](gorilla/websocket@v1.5.0...v1.5.3)

Updates `github.com/in-toto/in-toto-golang` from 0.5.0 to 0.11.0
- [Release notes](https://github.com/in-toto/in-toto-golang/releases)
- [Changelog](https://github.com/in-toto/in-toto-golang/blob/master/CHANGELOG.md)
- [Commits](in-toto/in-toto-golang@v0.5.0...v0.11.0)

Updates `github.com/moby/spdystream` from 0.2.0 to 0.5.1
- [Release notes](https://github.com/moby/spdystream/releases)
- [Commits](moby/spdystream@v0.2.0...v0.5.1)

Updates `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp` from 1.21.0 to 1.43.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.21.0...v1.43.0)

Updates `go.opentelemetry.io/otel/sdk` from 1.24.0 to 1.46.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.24.0...v1.46.0)

Updates `golang.org/x/crypto` from 0.33.0 to 0.55.0
- [Commits](golang/crypto@v0.33.0...v0.55.0)

Updates `golang.org/x/net` from 0.35.0 to 0.58.0
- [Commits](golang/net@v0.35.0...v0.58.0)

Updates `golang.org/x/oauth2` from 0.15.0 to 0.36.0
- [Commits](golang/oauth2@v0.15.0...v0.36.0)

Updates `google.golang.org/grpc` from 1.59.0 to 1.83.1
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.59.0...v1.83.1)

---
updated-dependencies:
- dependency-name: github.com/hjson/hjson-go/v4
  dependency-version: 4.5.0
  dependency-type: direct:production
  dependency-group: go_modules
- dependency-name: github.com/ClickHouse/ch-go
  dependency-version: 0.65.0
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: github.com/compose-spec/compose-go/v2
  dependency-version: 2.4.1
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: github.com/containerd/containerd
  dependency-version: 1.7.36
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: github.com/gorilla/websocket
  dependency-version: 1.5.3
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: github.com/in-toto/in-toto-golang
  dependency-version: 0.11.0
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: github.com/moby/spdystream
  dependency-version: 0.5.1
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp
  dependency-version: 1.43.0
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: go.opentelemetry.io/otel/sdk
  dependency-version: 1.46.0
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/crypto
  dependency-version: 0.55.0
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-version: 0.58.0
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/oauth2
  dependency-version: 0.36.0
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: google.golang.org/grpc
  dependency-version: 1.83.1
  dependency-type: indirect
  dependency-group: go_modules
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 29, 2026
@lisaSW lisaSW closed this Sep 30, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@lisaSW
lisaSW deleted the dependabot/go_modules/go_modules-7ffa907336 branch September 30, 2026 20:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant