Skip to content

chore(deps): bump github.com/oapi-codegen/runtime from 1.4.2 to 1.6.0#296

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/oapi-codegen/runtime-1.6.0
Open

chore(deps): bump github.com/oapi-codegen/runtime from 1.4.2 to 1.6.0#296
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/oapi-codegen/runtime-1.6.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 23, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/oapi-codegen/runtime from 1.4.2 to 1.6.0.

Release notes

Sourced from github.com/oapi-codegen/runtime's releases.

Allow customization of parameter encoding

This is a small release which adds a global encoding setting on the runtime, to allow users to customize how to handle spaces in query arguments. This is a new minor release, since we're adding new API, even though this is a very minor feature. I imagine that in the future, we will add more settings, rather than making behavior assumptions.

🚀 New features and improvements

📦 Dependency updates

  • chore(deps): update module github.com/golangci/golangci-lint to v2.12.2 (#112) @renovate[bot]

Sponsors

We would like to thank our sponsors for their support during this release.

Sponsors

We would like to thank our sponsors for their support during this release.

v1.5.0: RFC3339 durations, and bug fixes

This is mainly a bugfix release, but we're bumping the minor version since we also introduce a new type, Duration into our types/ package, which allows for parsing and emitting RFC3339 durations. Rather than trying to parse a duration string into a time.Duration, which requires assumptions that may not be right for everyone, we decided not to make those decisions and just store all possible fields as provided. Users can convert this to Go Duration as they see fit.

🚀 New features and improvements

🐛 Bug fixes

📝 Documentation updates

... (truncated)

Commits
  • 01be2fa chore(deps): update module github.com/golangci/golangci-lint to v2.12.2 (#112)
  • 1463938 Allow customizing default query encoder (#145)
  • 540d34a fix(deps): update module github.com/labstack/echo/v5 to v5.3.0 (#142)
  • e89dbb8 Add types.Duration for the RFC 3339 duration format (#144)
  • 324e57f Let generated code declare whether styled parameter values are escaped (#143)
  • 95c13c0 Explain how to send nested objects when style serialization fails (#141)
  • 7c889f3 Prefer the form struct tag over json for form encoding (#140)
  • d0d5c3a chore(deps): update golang/govulncheck-action action to v1.1.0 (#137)
  • 67e86fd chore(deps): update oapi-codegen/actions action to v0.8.0 (#130)
  • df140cb fix(deps): update module github.com/labstack/echo/v5 to v5.2.1 (#126)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/oapi-codegen/runtime](https://github.com/oapi-codegen/runtime) from 1.4.2 to 1.6.0.
- [Release notes](https://github.com/oapi-codegen/runtime/releases)
- [Commits](oapi-codegen/runtime@v1.4.2...v1.6.0)

---
updated-dependencies:
- dependency-name: github.com/oapi-codegen/runtime
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jul 23, 2026
@github-actions

Copy link
Copy Markdown

MegaLinter analysis: Error

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 4 0 0 0.07s
✅ API spectral 2 0 0 2.53s
✅ COPYPASTE jscpd yes no no 2.16s
✅ DOCKERFILE hadolint 1 0 0 0.14s
✅ GO golangci-lint yes yes no no 59.47s
✅ GO revive yes no no 2.16s
✅ MARKDOWN markdownlint 2 0 0 0 0.71s
✅ MARKDOWN markdown-table-formatter 2 0 0 0 0.33s
✅ REPOSITORY checkov yes no no 43.84s
✅ REPOSITORY gitleaks yes no no 0.38s
✅ REPOSITORY git_diff yes no no 0.0s
✅ REPOSITORY grype yes no no 88.57s
✅ REPOSITORY secretlint yes no no 0.7s
✅ REPOSITORY syft yes no no 3.93s
❌ REPOSITORY trivy yes 1 no 24.27s
✅ REPOSITORY trivy-sbom yes no no 3.39s
✅ REPOSITORY trufflehog yes no no 5.23s
✅ SPELL lychee 14 0 0 0.13s
✅ YAML prettier 12 0 0 0 0.91s
✅ YAML v8r 12 0 0 16.99s
✅ YAML yamllint 12 0 0 0.95s

Detailed Issues

❌ REPOSITORY / trivy - 1 error
2026-07-23T00:24:41Z	INFO	[vulndb] Need to update DB
2026-07-23T00:24:41Z	INFO	[vulndb] Downloading vulnerability DB...
2026-07-23T00:24:41Z	INFO	[vulndb] Downloading artifact...	repo="mirror.gcr.io/aquasec/trivy-db:2"
24.88 MiB / 101.38 MiB [-------------->_____________________________________________] 24.54% ? p/s ?55.46 MiB / 101.38 MiB [-------------------------------->___________________________] 54.71% ? p/s ?79.52 MiB / 101.38 MiB [----------------------------------------------->____________] 78.44% ? p/s ?101.38 MiB / 101.38 MiB [------------------------------------------->] 100.00% 127.11 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [------------------------------------------->] 100.00% 127.11 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [------------------------------------------->] 100.00% 127.11 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [------------------------------------------->] 100.00% 118.91 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [------------------------------------------->] 100.00% 118.91 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [------------------------------------------->] 100.00% 118.91 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [------------------------------------------->] 100.00% 111.24 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [------------------------------------------->] 100.00% 111.24 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [------------------------------------------->] 100.00% 111.24 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [------------------------------------------->] 100.00% 104.06 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [------------------------------------------->] 100.00% 104.06 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [------------------------------------------->] 100.00% 104.06 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 97.35 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 97.35 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 97.35 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 91.07 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 91.07 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 91.07 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 85.19 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 85.19 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 85.19 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 79.69 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 79.69 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 79.69 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 74.55 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 74.55 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 74.55 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 69.74 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 69.74 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 69.74 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 65.24 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 65.24 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 65.24 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 61.03 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 61.03 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 61.03 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 57.10 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 57.10 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 57.10 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 53.41 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 53.41 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 53.41 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 49.97 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 49.97 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 49.97 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 46.74 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 46.74 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 46.74 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 43.73 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 43.73 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 43.73 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 40.91 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 40.91 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 40.91 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 38.27 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 38.27 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 38.27 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 35.80 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 35.80 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 35.80 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------->] 100.00% 33.49 MiB p/s ETA 0s101.38 MiB / 101.38 MiB [-------------------------------------------------] 100.00% 8.03 MiB p/s 13s2026-07-23T00:24:55Z	INFO	[vulndb] Artifact successfully downloaded	repo="mirror.gcr.io/aquasec/trivy-db:2"
2026-07-23T00:24:55Z	INFO	[vuln] Vulnerability scanning is enabled
2026-07-23T00:24:55Z	INFO	[misconfig] Misconfiguration scanning is enabled
2026-07-23T00:24:55Z	INFO	[checks-client] Need to update the checks bundle
2026-07-23T00:24:55Z	INFO	[checks-client] Downloading the checks bundle...
234.65 KiB / 234.65 KiB [--------------------------------------------------------->] 100.00% ? p/s ?234.65 KiB / 234.65 KiB [-----------------------------------------------] 100.00% 2.09 MiB p/s 300ms2026-07-23T00:25:04Z	INFO	Number of language-specific files	num=1
2026-07-23T00:25:04Z	INFO	[gomod] Detecting vulnerabilities...
2026-07-23T00:25:04Z	INFO	Detected config files	num=2
2026-07-23T00:25:04Z	WARN	Using severities from other vendors for some vulnerabilities. Read https://trivy.dev/docs/v0.69/guide/scanner/vulnerability#severity-selection for details.

Report Summary

┌──────────────────┬────────────┬─────────────────┬───────────────────┐
│      Target      │    Type    │ Vulnerabilities │ Misconfigurations │
├──────────────────┼────────────┼─────────────────┼───────────────────┤
│ go.mod           │   gomod    │        3        │         -         │
├──────────────────┼────────────┼─────────────────┼───────────────────┤
│ Dockerfile       │ dockerfile │        -        │         0         │
├──────────────────┼────────────┼─────────────────┼───────────────────┤
│ Dockerfile.local │ dockerfile │        -        │         0         │
└──────────────────┴────────────┴─────────────────┴───────────────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement.
VEX allows you to communicate the actual status of vulnerabilities in your project, improving security transparency and reducing false positives for your users.
Learn more and start using VEX: https://trivy.dev/docs/v0.69/guide/supply-chain/vex/repo#publishing-vex-documents

To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable.


go.mod (gomod)
==============
Total: 3 (UNKNOWN: 2, LOW: 1, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

┌─────────────────────────────────────────┬─────────────────────┬──────────┬──────────┬───────────────────┬───────────────┬────────────────────────────────────────────────────────────┐
│                 Library                 │    Vulnerability    │ Severity │  Status  │ Installed Version │ Fixed Version │                           Title                            │
├─────────────────────────────────────────┼─────────────────────┼──────────┼──────────┼───────────────────┼───────────────┼────────────────────────────────────────────────────────────┤
│ github.com/oapi-codegen/oapi-codegen/v2 │ GHSA-rjwr-m7qx-3fjr │ LOW      │ fixed    │ v2.5.0            │ 2.7.1         │ oapi-codegen: OpenAPI Server Description Escapes Generated │
│                                         │                     │          │          │                   │               │ Go Comment and Injects Executable Code...                  │
│                                         │                     │          │          │                   │               │ https://github.com/advisories/GHSA-rjwr-m7qx-3fjr          │
├─────────────────────────────────────────┼─────────────────────┼──────────┼──────────┼───────────────────┼───────────────┼────────────────────────────────────────────────────────────┤
│ golang.org/x/crypto                     │ GO-2026-5932        │ UNKNOWN  │ affected │ v0.53.0           │               │ The golang.org/x/crypto/openpgp package is unmaintained,   │
│                                         │                     │          │          │                   │               │ unsafe by design, and has known security...                │
├─────────────────────────────────────────┼─────────────────────┤          ├──────────┼───────────────────┼───────────────┼────────────────────────────────────────────────────────────┤
│ golang.org/x/text                       │ CVE-2026-56852      │          │ fixed    │ v0.38.0           │ 0.39.0        │ Infinite loop on invalid input in golang.org/x/text        │
│                                         │                     │          │          │                   │               │ https://avd.aquasec.com/nvd/cve-2026-56852                 │
└─────────────────────────────────────────┴─────────────────────┴──────────┴──────────┴───────────────────┴───────────────┴────────────────────────────────────────────────────────────┘

📣 Notices:
  - Version 0.72.0 of Trivy is now available, current version is 0.69.1

To suppress version checks, run Trivy scans with the --skip-version-check flag

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.4.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,API_SPECTRAL,COPYPASTE_JSCPD,DOCKERFILE_HADOLINT,GO_GOLANGCI_LINT,GO_REVIVE,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_GRYPE,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant