From 4a04028172e7c26de45901e2d2bb3ecd77ec3ea0 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 9 Sep 2026 23:12:40 +0000 Subject: [PATCH 1/3] Bump the go group across 1 directory with 2 updates Bumps the go group with 2 updates in the / directory: [github.com/beevik/etree](https://github.com/beevik/etree) and [golang.org/x/crypto](https://github.com/golang/crypto). Updates `github.com/beevik/etree` from 1.7.1 to 1.8.0 - [Release notes](https://github.com/beevik/etree/releases) - [Changelog](https://github.com/beevik/etree/blob/main/RELEASE_NOTES.md) - [Commits](https://github.com/beevik/etree/compare/v1.7.1...v1.8.0) Updates `golang.org/x/crypto` from 0.55.0 to 0.56.0 - [Commits](https://github.com/golang/crypto/compare/v0.55.0...v0.56.0) --- updated-dependencies: - dependency-name: github.com/beevik/etree dependency-version: 1.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go - dependency-name: golang.org/x/crypto dependency-version: 0.56.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go ... Signed-off-by: dependabot[bot] --- go.mod | 6 +++--- go.sum | 8 ++++---- 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/go.mod b/go.mod index db59a84..8da8c6e 100644 --- a/go.mod +++ b/go.mod @@ -1,15 +1,15 @@ module github.com/mdeous/plasmid -go 1.25.0 +go 1.26.0 require ( - github.com/beevik/etree v1.7.1 + github.com/beevik/etree v1.8.0 github.com/crewjam/saml v0.5.1 github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c github.com/spf13/cobra v1.10.2 github.com/spf13/pflag v1.0.10 github.com/spf13/viper v1.21.0 - golang.org/x/crypto v0.55.0 + golang.org/x/crypto v0.56.0 ) require ( diff --git a/go.sum b/go.sum index e77c154..44d951d 100644 --- a/go.sum +++ b/go.sum @@ -1,5 +1,5 @@ -github.com/beevik/etree v1.7.1 h1:xBlSFAjlMfZkrCNKCEdZ2MSN9pfQYeRBaISDnAVi4Ek= -github.com/beevik/etree v1.7.1/go.mod h1:bh4zJxiIr62SOf9pRzN7UUYaEDa9HEKafK25+sLc0Gc= +github.com/beevik/etree v1.8.0 h1:TOfpQtMZ3ZuG9f2ZnLvsbOOVxrjTvE0qbYb5D0p44j0= +github.com/beevik/etree v1.8.0/go.mod h1:bh4zJxiIr62SOf9pRzN7UUYaEDa9HEKafK25+sLc0Gc= github.com/cpuguy83/go-md2man/v2 v2.0.6/go.mod h1:oOW0eioCTA6cOiMLiUPZOpcVxMig6NIQQ7OS05n1F4g= github.com/crewjam/saml v0.5.1 h1:g+mfp0CrLuLRZCK793PgJcZeg5dS/0CDwoeAX2zcwNI= github.com/crewjam/saml v0.5.1/go.mod h1:r0fDkmFe5URDgPrmtH0IYokva6fac3AUdstiPhyEolQ= @@ -60,8 +60,8 @@ github.com/subosito/gotenv v1.6.0 h1:9NlTDc1FTs4qu0DDq7AEtTPNw6SVm7uBMsUCUjABIf8 github.com/subosito/gotenv v1.6.0/go.mod h1:Dk4QP5c2W3ibzajGcXpNraDfq2IrhjMIvMSWPKKo0FU= go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc= go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg= -golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M= -golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis= +golang.org/x/crypto v0.56.0 h1:GUh5Ii4J5jtcseSMiRqr1jXCNHoxjeV9Fmekc2oLy6Y= +golang.org/x/crypto v0.56.0/go.mod h1:OMW5y6CY9l38uPLmxU6l6pwcXp1obtLo3e6gT7gQR2I= golang.org/x/sys v0.1.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs= golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= From 7a097b8f11b358ee94ab712550cd3a483798c29c Mon Sep 17 00:00:00 2001 From: Mathieu Deous Date: Sun, 27 Sep 2026 12:07:49 +0200 Subject: [PATCH 2/3] Bump Docker builder image to golang:1.27-alpine golang.org/x/crypto 0.56.0 declares go 1.26.0, which raised the go.mod directive above the 1.25 builder image pin and broke the image build: go: go.mod requires go >= 1.26.0 (running go 1.25.14; GOTOOLCHAIN=local) Pin 1.27 to match the go-version: stable used by the Build workflow. --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 8403562..e715552 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM golang:1.25-alpine AS base +FROM golang:1.27-alpine AS base ARG VERSION=devel WORKDIR /plasmid COPY . . From 3b1132f67660a1992b11ba530d909631c775c2e1 Mon Sep 17 00:00:00 2001 From: Mathieu Deous Date: Sun, 27 Sep 2026 12:07:52 +0200 Subject: [PATCH 3/3] Disambiguate the required Build status check The Docker Image workflow's build job was also named "Build", so it published a check run with the same name as the Build workflow's job. Required status checks match on check-run name only, making the branch ruleset's required "Build" context ambiguous: the PR check list showed Build:FAILURE next to Build:SUCCESS. Rename the Docker job to "Docker Build" (the job key stays 'build', so the publish job's needs: build is unaffected), and widen build.yml's pull_request path filter to Dockerfile and .github/workflows/** so the required check still reports on PRs that touch only those files instead of sitting pending forever. --- .github/workflows/build.yml | 2 ++ .github/workflows/docker.yml | 2 +- 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 4b6702e..c752465 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -16,6 +16,8 @@ on: - '**.go' - 'go.mod' - 'go.sum' + - 'Dockerfile' + - '.github/workflows/**' permissions: contents: read diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index c052ab4..3508458 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -27,7 +27,7 @@ env: jobs: build: - name: Build + name: Docker Build runs-on: ubuntu-latest permissions: