chore(deps): bump github.com/mattn/go-colorable from 0.1.14 to 0.1.15 - #13572
Merged
BagToad merged 1 commit intoJun 5, 2026
Merged
Conversation
Bumps [github.com/mattn/go-colorable](https://github.com/mattn/go-colorable) from 0.1.14 to 0.1.15. - [Commits](mattn/go-colorable@v0.1.14...v0.1.15) --- updated-dependencies: - dependency-name: github.com/mattn/go-colorable dependency-version: 0.1.15 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
BagToad
approved these changes
Jun 5, 2026
BagToad
left a comment
Member
There was a problem hiding this comment.
Audit summary (generated)
Reviewed how we use github.com/mattn/go-colorable and the actual v0.1.14 → v0.1.15 source diff.
Our usage:
- Direct import in
pkg/iostreams/iostreams.go:colorable.NewColorable(os.Stdout)andcolorable.NewColorable(os.Stderr), used for Windows ANSI translation when VT processing isn't available. - Indirect consumers in our module graph:
cli/go-gh,fatih/color,survey,spinner,certificate-transparency-go.
What changed v0.1.14 → v0.1.15:
colorable_windows.gois the only file with real logic changes:- Adds a
curattrfield cached on the writer to avoid re-querying console state on every attribute change. - Plaintext fast path: if there's no pending state and no
0x1bescape byte in the input, write straight through and skip ANSI parsing entirely. - Uses cached
w.curattrinstead of refetchingcsbi.attributes; only callsprocSetConsoleTextAttributewhen the attribute actually changes.
- Adds a
- Other diffs: typo fix in a test, new benchmarks, CI workflow tweak.
go.sumdiff is limited togo-colorableitself; no transitive bumps.
Impact on us:
- Non-Windows: no runtime change.
- Modern Windows with VT enabled:
NewColorablereturns the original file unchanged, so no effect. - Legacy Windows console: this is our path via
IOStreams.System(), but the changes are strict perf improvements. Two tiny theoretical risks worth naming: the plaintext fast path ignores partial-write errors onw.out.Write(negligible for interactive stdout/stderr), and cachedcurattrcould go stale if an external writer mutates console attributes (not a concern for normalghoutput).
LGTM.
BagToad
deleted the
dependabot/go_modules/github.com/mattn/go-colorable-0.1.15
branch
June 5, 2026 15:55
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps github.com/mattn/go-colorable from 0.1.14 to 0.1.15.
Commits
8bf39a2Merge pull request #78 from mattn/windows-write-fastpathd7a88e0Bump checkout to v4 and setup-go to v54dd1c6dUpdate CI matrix to Go 1.24-1.2609158f8Fast path for plaintext writes and cache text attribute on Windows171d5b4Add Windows writer benchmarks74f8ed1Merge pull request #72 from alexandear/fix-test-typo50c5b53Fix typo in TestNonColorableNilDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)