Repository navigation
Bump the minor-patch group across 2 directories with 7 updates - #651
Merged
kommendorkapten merged 1 commit intoJun 30, 2026
Merged
Conversation
Bumps the minor-patch group with 4 updates in the / directory: [github.com/go-openapi/runtime](https://github.com/go-openapi/runtime), [github.com/go-openapi/strfmt](https://github.com/go-openapi/strfmt), [github.com/sigstore/rekor-tiles/v2](https://github.com/sigstore/rekor-tiles) and [golang.org/x/mod](https://github.com/golang/mod). Bumps the minor-patch group with 1 update in the /examples/oci-image-verification directory: [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry). Updates `github.com/go-openapi/runtime` from 0.32.3 to 0.32.4 - [Release notes](https://github.com/go-openapi/runtime/releases) - [Commits](go-openapi/runtime@v0.32.3...v0.32.4) Updates `github.com/go-openapi/strfmt` from 0.26.3 to 0.26.4 - [Release notes](https://github.com/go-openapi/strfmt/releases) - [Commits](go-openapi/strfmt@v0.26.3...v0.26.4) Updates `github.com/go-openapi/swag/conv` from 0.26.0 to 0.26.1 - [Release notes](https://github.com/go-openapi/swag/releases) - [Commits](go-openapi/swag@v0.26.0...v0.26.1) Updates `github.com/sigstore/rekor-tiles/v2` from 2.2.2-0.20260601073857-5d098a2b6443 to 2.3.0 - [Release notes](https://github.com/sigstore/rekor-tiles/releases) - [Changelog](https://github.com/sigstore/rekor-tiles/blob/main/RELEASE.md) - [Commits](https://github.com/sigstore/rekor-tiles/commits/v2.3.0) Updates `golang.org/x/crypto` from 0.52.0 to 0.53.0 - [Commits](golang/crypto@v0.52.0...v0.53.0) Updates `golang.org/x/mod` from 0.36.0 to 0.37.0 - [Commits](golang/mod@v0.36.0...v0.37.0) Updates `github.com/google/go-containerregistry` from 0.21.6 to 0.21.7 - [Release notes](https://github.com/google/go-containerregistry/releases) - [Commits](google/go-containerregistry@v0.21.6...v0.21.7) --- updated-dependencies: - dependency-name: github.com/go-openapi/runtime dependency-version: 0.32.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/go-openapi/strfmt dependency-version: 0.26.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/go-openapi/swag/conv dependency-version: 0.26.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/rekor-tiles/v2 dependency-version: 2.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: golang.org/x/crypto dependency-version: 0.53.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: golang.org/x/mod dependency-version: 0.37.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: github.com/google/go-containerregistry dependency-version: 0.21.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Hayden-IO
enabled auto-merge (squash)
June 30, 2026 01:48
Hayden-IO
disabled auto-merge
June 30, 2026 01:48
Hayden-IO
reviewed
Jun 30, 2026
| module github.com/sigstore/sigstore-go | ||
|
|
||
| go 1.25.0 | ||
| go 1.25.8 |
Contributor
There was a problem hiding this comment.
I can't keep up the fight with keeping this as .0. sigstore/rekor-tiles#820 caused this. The best thing we can do is continue to shed dependencies.
Member
There was a problem hiding this comment.
Keeping the dependencies set small is admirable for sure!
Hayden-IO
approved these changes
Jun 30, 2026
kommendorkapten
approved these changes
Jun 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the minor-patch group with 4 updates in the / directory: github.com/go-openapi/runtime, github.com/go-openapi/strfmt, github.com/sigstore/rekor-tiles/v2 and golang.org/x/mod.
Bumps the minor-patch group with 1 update in the /examples/oci-image-verification directory: github.com/google/go-containerregistry.
Updates
github.com/go-openapi/runtimefrom 0.32.3 to 0.32.4Release notes
Sourced from github.com/go-openapi/runtime's releases.
... (truncated)
Commits
908a0ffchore: prepare release v0.32.45a6fbeebuild(deps): bump github.com/go-openapi/specb63b221build(deps): bump the development-dependencies group with 2 updatesd3cd4f6fix(middleware): nil-guard param.Schema in UntypedRequestBinder map path (#488)760cc62build(deps): bump the go-openapi-dependencies group across 2 directories with...6c5385ebuild(deps): bump golang.org/x/sync1045e1cbuild(deps): bump the development-dependencies group with 9 updates9b01ff4build(deps): bump the go-openapi-dependencies group across 2 directories with...deed159doc: updated contributors file2dc38aebuild(deps): bump the development-dependencies group with 10 updatesUpdates
github.com/go-openapi/strfmtfrom 0.26.3 to 0.26.4Release notes
Sourced from github.com/go-openapi/strfmt's releases.
... (truncated)
Commits
09a3881chore: prepare release v0.26.47dcda43build(deps): bump the other-dependencies group across 3 directories with 1 up...5b746cbbuild(deps): bump the go-openapi-dependencies group across 2 directories with...708588cci: post README announcements to discord + bump ci-workflows to v0.4.0 (#272)06b6bb0fix: validate "uri" format for absolute URIs with a fragment (#131) (#269)64c4277chore: disabled goconst linter (#271)a8a2d74chore(ci): run contributors workflow monthly instead of weekly (#270)00af19ebuild(deps): bump the development-dependencies group with 2 updatesa3d472abuild(deps): bump golang.org/x/net1928b1dbuild(deps): bump the development-dependencies group with 9 updatesUpdates
github.com/go-openapi/swag/convfrom 0.26.0 to 0.26.1Release notes
Sourced from github.com/go-openapi/swag/conv's releases.
... (truncated)
Commits
85923a5chore: prepare release v0.26.1336c586doc(loading): document security implications of using the loader (#207)92ec622doc: updated contributors file3f77c79doc: aligned with org docs (#205)40578b5build(deps): bump the development-dependencies group with 8 updateseefaba1feat(loading): sandbox local loading with WithRoot (GHSA-v2xp-g8xf-22pf) (#203)2e99502feat(ci): added shared workflow for bot-pr monitoringcafd10fbuild(deps): bump the go-openapi-dependencies group across 15 directories wit...660dd54build(deps): bump the development-dependencies group with 7 updatese089511build(deps): bump the go-openapi-dependencies group across 15 directories wit...Updates
github.com/sigstore/rekor-tiles/v2from 2.2.2-0.20260601073857-5d098a2b6443 to 2.3.0Release notes
Sourced from github.com/sigstore/rekor-tiles/v2's releases.
Commits
Updates
golang.org/x/cryptofrom 0.52.0 to 0.53.0Commits
45460e0go.mod: update golang.org/x dependenciesd37c95epkcs12: limit PBKDF iteration count to prevent CPU exhaustione2ffffessh: reject incomplete gssapi-with-mic configurations60e158assh/test: isolate CLI tests from user SSH config and agent1b77d23ssh/knownhosts: reject lines with multiple or unknown markers3872a2bssh/knownhosts: verify declared key type matches decoded key9f72eccssh/knownhosts: treat only ASCII space and tab as whitespace8f405a4ssh: validate ECDSA curve matches expected algorithmbb41b3dssh: improve DH GEX group selection using PreferredBitse04e721ssh/agent: validate ed25519 private key length in AddUpdates
golang.org/x/modfrom 0.36.0 to 0.37.0Commits
deb1dfcgo.mod: update golang.org/x dependencies087f651modfile: use slices.Backward343ee60x/mod: allow for aggressively conslidating requiresUpdates
github.com/google/go-containerregistryfrom 0.21.6 to 0.21.7Release notes
Sourced from github.com/google/go-containerregistry's releases.
Commits
c68d899Bump go version to 1.26.4 (#2350)da61d86transport: do not re-attach bearer token after cross-host redirect (#2349)09fe1e5fix(tarball): normalize paths when matching files (#2334)5baa399build(deps): bump the go-deps group across 3 directories with 4 updates (#2348)97a8a17fix(transport): apply refreshed bearer token after cross-host redirect (#2337)e963497internal/gzip: fix goroutine leak in ReadCloserLevel (#2347)02649eafix: prevent SSRF in google.List() pagination (#2332)7204b40build(deps): bump the actions group across 1 directory with 2 updates (#2344)4cfaa93build(deps): bump the go-deps group across 1 directory with 2 updates (#2343)6849394pkg/registry: export RedirectError (#2177)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions