Skip to content

Update Go Dependencies - #420

Open
red-hat-konflux[bot] wants to merge 1 commit into
release-1.4from
konflux/mintmaker/release-1.4/go-deps
Open

Update Go Dependencies#420
red-hat-konflux[bot] wants to merge 1 commit into
release-1.4from
konflux/mintmaker/release-1.4/go-deps

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Jul 17, 2026

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Pending
chainguard.dev/go-grpc-kit require minor v0.17.17v0.18.0
chainguard.dev/sdk require patch v0.1.54v0.1.164 v0.1.170 (+5)
cloud.google.com/go/auth indirect minor v0.20.0v0.22.0
cloud.google.com/go/kms indirect minor v1.31.0v1.33.0
cloud.google.com/go/longrunning indirect minor v1.0.0v1.2.0
github.com/AzureAD/microsoft-authentication-library-for-go indirect minor v1.7.2v1.8.0
github.com/Masterminds/semver/v3 indirect minor v3.3.1v3.5.0
github.com/ThalesGroup/crypto11 require patch v1.6.2v1.6.8
github.com/aws/aws-sdk-go indirect patch v1.55.7v1.55.8
github.com/aws/aws-sdk-go-v2/config indirect patch v1.32.30v1.32.34
github.com/aws/aws-sdk-go-v2/credentials indirect patch v1.19.29v1.19.33
github.com/aws/aws-sdk-go-v2/feature/ec2/imds indirect patch v1.18.30v1.18.34
github.com/aws/aws-sdk-go-v2/internal/configsources indirect patch v1.4.30v1.4.34
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 indirect patch v2.7.30v2.7.34
github.com/aws/aws-sdk-go-v2/internal/v4a indirect patch v1.4.31v1.4.35
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding indirect patch v1.13.13v1.13.15
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url indirect patch v1.13.30v1.13.34
github.com/aws/aws-sdk-go-v2/service/kms indirect minor v1.54.1v1.55.3
github.com/aws/aws-sdk-go-v2/service/signin indirect minor v1.4.1v1.5.3
github.com/aws/aws-sdk-go-v2/service/sso indirect minor v1.32.1v1.33.3
github.com/aws/aws-sdk-go-v2/service/ssooidc indirect minor v1.37.1v1.38.3
github.com/aws/smithy-go indirect patch v1.27.3v1.27.6
github.com/bmatcuk/doublestar/v4 indirect minor v4.9.1v4.10.0
github.com/cenkalti/backoff/v4 indirect major v4.3.0v7.0.0
github.com/cenkalti/backoff/v5 indirect major v5.0.3v7.0.0
github.com/chainguard-dev/clog indirect patch v1.8.0v1.8.1
github.com/clipperhouse/displaywidth indirect minor v0.10.0v0.11.0
github.com/clipperhouse/uax29/v2 indirect minor v2.6.0v2.7.0
github.com/fatih/color indirect minor v1.18.0v1.19.0
github.com/go-jose/go-jose/v3 indirect major v3.0.5v4.1.4
github.com/go-logr/logr indirect patch v1.4.3v1.4.4
github.com/go-viper/mapstructure/v2 indirect minor v2.4.0v2.5.0
github.com/google/go-containerregistry indirect patch v0.21.5v0.21.8
github.com/googleapis/api-linter/v2 indirect minor v2.0.0v2.3.1
github.com/googleapis/enterprise-certificate-proxy indirect patch v0.3.18v0.3.19 v0.3.20
github.com/grpc-ecosystem/go-grpc-middleware require major v1.4.0v2.3.3
github.com/grpc-ecosystem/grpc-gateway/v2 indirect minor v2.27.3v2.29.0
github.com/hashicorp/hcl indirect major v1.0.1-vault-7v2.24.0
github.com/jellydator/ttlcache/v3 indirect patch v3.4.0v3.4.1
github.com/letsencrypt/boulder indirect minor v0.20260420.0v0.20260729.0
github.com/magiconair/properties require minor v1.8.10v1.18.11
github.com/mattn/go-colorable indirect patch v0.1.14v0.1.15
github.com/mattn/go-isatty indirect patch v0.0.20v0.0.24
github.com/mattn/go-runewidth indirect patch v0.0.23v0.0.27
github.com/olekukonko/errors indirect minor v1.2.0v1.3.0
github.com/olekukonko/ll indirect patch v0.1.6v0.1.8
github.com/pelletier/go-toml/v2 indirect minor v2.2.4v2.4.3
github.com/prometheus/client_golang require minor v1.23.2v1.24.1
github.com/prometheus/common require patch v0.70.0v0.70.1
github.com/rogpeppe/go-internal indirect minor v1.14.1v1.15.0
github.com/sigstore/sigstore require patch v1.10.8v1.10.9
github.com/sigstore/sigstore/pkg/signature/kms/aws require patch v1.10.8v1.10.9
github.com/sigstore/sigstore/pkg/signature/kms/azure require patch v1.10.8v1.10.9
github.com/sigstore/sigstore/pkg/signature/kms/gcp require patch v1.10.8v1.10.9
github.com/sigstore/sigstore/pkg/signature/kms/hashivault require patch v1.10.8v1.10.9
github.com/spiffe/go-spiffe/v2 require minor v2.6.0v2.8.1
github.com/tink-crypto/tink-go-awskms/v2 require major v2.1.0v3.0.0
github.com/tink-crypto/tink-go-gcpkms/v2 require minor v2.2.0v2.3.0
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc indirect minor v0.68.0v0.69.0
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp indirect minor v0.68.0v0.69.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace indirect minor v1.42.0v1.44.0 v1.45.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc indirect minor v1.42.0v1.44.0 v1.45.0
go.opentelemetry.io/proto/otlp indirect minor v1.10.0v1.11.0
go.step.sm/crypto require minor v0.85.0v0.87.0
go.yaml.in/yaml/v3 indirect patch v3.0.4v3.0.5
go.yaml.in/yaml/v3 require patch v3.0.4v3.0.5
goa.design/goa/v3 require minor v3.23.4v3.28.0
golang.org/x/net indirect minor v0.53.0v0.57.0
golang.org/x/sync indirect minor v0.20.0v0.22.0
golang.org/x/sys indirect minor v0.43.0v0.47.0
golang.org/x/text indirect minor v0.36.0v0.40.0
google.golang.org/api require minor v0.289.0v0.291.0
google.golang.org/grpc indirect minor v1.80.0v1.83.0
google.golang.org/grpc require minor v1.82.1v1.83.0
google.golang.org/grpc/cmd/protoc-gen-go-grpc indirect patch v1.6.1v1.6.2

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

chainguard-dev/go-grpc-kit (chainguard.dev/go-grpc-kit)

v0.18.0

Compare Source

What's Changed

New Contributors

Full Changelog: chainguard-dev/go-grpc-kit@v0.17.17...v0.18.0

chainguard-dev/sdk (chainguard.dev/sdk)

v0.1.164

Compare Source

  • Add auth.ExtractAudiences and token.ListAudiences helpers
  • GetEffectiveEntitlements now returns swap_refill_time: when the organization's next catalog-image swap becomes available (set only when no swaps are currently available).

v0.1.163

Compare Source

  • ArgosDocuments: ArgosDocument gains output-only per-file bindings (filename, analysis status, CGP IDs), derived by the platform from the submission archive.

v0.1.162

Compare Source

  • Add the Charts.FindChart RPC and ChartCatalog enum to chainguard.platform.registry.v1 for server-side chart name resolution.

v0.1.161

Compare Source

  • Add the libraries/v1 ResolutionCache service (Zap, SetOptOut, Status, List) and the CAP_LIBRARIES_CACHE_LIST capability for managing the Libraries resolution cache.

v0.1.160

Compare Source

  • chore(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.1

v0.1.159

Compare Source

  • feat(skills): public Skills catalog API — ListSkills/GetSkill (ACID-363) (#​47844)

v0.1.158

Compare Source

  • add image-to-chart lookup to api (#​48009)

v0.1.157

Compare Source

  • docs(iter): fix SDK-3 violation in doc.go integration example [skillup] (#​48063)

v0.1.156

Compare Source

  • oidc: enable public OIDC clients (client id + PKCE) (#​47654)

v0.1.155

Compare Source

  • feat(sdk): add SCIM token lifecycle surface to v1 IdentityProviders (#​47753)

v0.1.154

Compare Source

  • refactor(policies): policies declare a single supported_resource_type (#​47245)

v0.1.153

Compare Source

  • fix(public/sdk/hack): add doc.go and example_test.go [skillup] (#​47670)

v0.1.152

Compare Source

  • fix(iter): use cmp.Or for page size default [skillup] (#​47682)

v0.1.151

Compare Source

  • fix(scim): decouple token lifecycle from provisioning enablement (#​47522)

v0.1.150

Compare Source

  • feat(registry): enforce catalog-image swap quota and expose it in GetEffectiveEntitlements (#​47230)
  • fix(sdk/sts): send HTTP/1 downgrade STS requests form-encoded (#​47475)

v0.1.149

Compare Source

  • feat(private-osv): add OSV-spec withdrawn field (#​47542)

v0.1.148

Compare Source

  • test(capabilities): bit-space hygiene invariants via descriptor reflection (CUS-849) (#​46213)

v0.1.147

Compare Source

  • feat(capabilities): StringifyAllContext, Parse error propagation, Set.String placeholders (CUS-849) (#​46212)

v0.1.146

Compare Source

  • fix(libraries): partial package search on malware blocklist (#​45938)

v0.1.145

Compare Source

  • fix(iam): add description to hidden MCP annotations [skillup] (#​47353)

v0.1.144

Compare Source

  • feat(scim): implement token lifecycle service (#​47071)

v0.1.143

Compare Source

  • fix(sdk/sts): honor HTTP(S)_PROXY in HTTP/1 downgrade exchanger CUS-1012 (#​46170)

v0.1.142

Compare Source

  • test(registry): pin PathMutation uid/gid presence semantics (CON-1931 follow-up) (#​47018)

v0.1.141

Compare Source

  • chore(deps): bump chainguard.dev/apko to v1.2.23 (CON-1931) (#​46716)
  • fix(sdk): add missing example_test.go and doc.go files [skillup] (#​47151)

v0.1.140

Compare Source

  • fix(ping): add mcp description to Ping RPC annotation [skillup] (#​47141)

v0.1.139

Compare Source

  • fix: add missing doc.go and example_test.go files [skillup] (#​47136)

v0.1.138

Compare Source

  • fix(advisory): rename reports field to resolved_vulns_reports [skillup] (#​47040)
  • feat(scim): define token lifecycle API and permissions (#​46676)

v0.1.137

Compare Source

  • feat(advisory): migrate SecurityAdvisory endpoints to v2beta1 (#​45820)

v0.1.136

Compare Source

  • feat(iam): add a guardener service principal (#​46988)

v0.1.135

Compare Source

  • feat(chainctl): add hidden policies validate subcommand (#​45586)

v0.1.134

Compare Source

  • feat(capabilities): mark all rebuilder-api capabilities internal_only

v0.1.133

Compare Source

  • feat(osv-dump)[ARG-201] Add OSV Dump and wire up staging to build the tarball manually (#​45694)

v0.1.132

Compare Source

  • feat(roles): adds custom policies capabilities (#​46535)

v0.1.131

Compare Source

  • feat(registry): add CreateTag, promote DeleteTag to v2beta1, remove v2alpha1 (#​45208)

v0.1.130

Compare Source

  • oidc: Add backend support for custom IDPs to enable PKCE (#​44767)

v0.1.129

Compare Source

  • docs(sdk): add doc.go and example tests for githubflow, uploads, uidp [skillup] (#​46514)

v0.1.128

Compare Source

  • feat(rexie): the split rexie protocol packages + class capabilities (#​46559)

v0.1.127

Compare Source

  • feat(guardener): on-demand actions migration API with long-running operations (#​45466)

v0.1.126

Compare Source

  • fix(iam/v2beta1): add field_behavior to oidc oneof field [skillup] (#​46469)

v0.1.125

Compare Source

  • fix(iter): add maxPages ceiling and fix test UIDs [skillup] (#​46063)

v0.1.124

Compare Source

  • feat(libraries): cache source_type/malware, default to Chainguard-built with upstream opt-in (#​45337)

v0.1.123

Compare Source

  • feat(libraries): reject inert allow entries; warn on block/allow overlap (#​45684)

v0.1.122

Compare Source

  • feat(registry): add custom APK keyring proto fields (CON-1873, PR 1/6) (#​43731)

v0.1.121

Compare Source

  • feat(chainctl): filter required/optional helm refs (#​44641)

v0.1.120

Compare Source

  • Elastic Build: the event producer for the build index (#​45935)

v0.1.119

Compare Source

  • fix(iam/v2beta1): add CloudEvents annotations and event.go for roles [skillup] (#​45982)

v0.1.118

Compare Source

  • aws-marketplace: move LIST cap to viewer role (#​45964)

v0.1.117

Compare Source

  • feat(rebuilder-api) add untrusted to libraries.rebuilder.admin, sa-signer, sa-publish, sa-build for updating status with minted JWT (#​45858)

v0.1.116

Compare Source

  • feat(libraries): surface Athena entitlement tiers in public APIs (#​45765)

v0.1.115

Compare Source

  • feat(registry): promote RepoReadme endpoints to v2beta1 (#​45740)

v0.1.114

Compare Source

  • feat(guardener): add support-only entitlement service (#​45525)

v0.1.113

Compare Source

  • feat(iam): add v1 ExternalGroupRoleMappings BatchDelete (#​45725)

v0.1.112

Compare Source

  • feat(rexie): the deployed edge — REv2 surface over an in-process scheduler (#​45292)
  • fix(api-impl/registry): resolve UpdateRepoReadme authz scope and honor update_mask (#​45530)

v0.1.111

Compare Source

  • fix #​45468: auth/aws.VerifyToken: canonicalize audience/identity header values to match SigV4 (whitespace hygiene) (#​45470)

v0.1.110

Compare Source

  • feat(policies-proto): allow ValidatePolicy to accept parameter_schemas (#​45492)

v0.1.109

Compare Source

  • feat(api-impl/registry): error on managed repo field changes for synced repos (#​45363)

v0.1.108

Compare Source

  • feat(libraries): persist LibraryPolicy blocked_licenses end to end (#​45373)

v0.1.107

Compare Source

  • fix(sdk/auth/aws): require binding headers, host, and date to be signed in VerifyToken (#​45286)

v0.1.106

Compare Source

  • feat(chainctl): add guardener github status to list linked GitHub orgs (#​45328)

v0.1.105

Compare Source

  • Policies/add validate policy rpc (#​44846)
  • feat(dfc): add a server-built build report with base image changes (#​45187)

v0.1.104

Compare Source

  • feat(iam): grant guardener admin capabilities to the Owner role (#​45194)

v0.1.103

Compare Source

  • feat(api-impl/registry): implement v2beta1 CreateRepo (#​44895)

v0.1.102

Compare Source

  • feat(api-impl/libraries): add before upper-bound filter to malware blocklist API (#​44694)

v0.1.101

Compare Source

  • feat(loggie): add live build-log streaming across the buildie services

v0.1.100

Compare Source

v0.1.99

Compare Source

  • feat(capabilities): add staff-only CVE remediation caps; make rebuilder admin internal

v0.1.98

Compare Source

  • feat(registry): expose chart CHANGELOG.md via GetChart (#​42852)

v0.1.97

Compare Source

  • fix: add missing iam_scope annotation to UpdateAWSMarketplaceSubscriptionRequest.subscription (#​44607)

v0.1.96

Compare Source

v0.1.95

Compare Source

  • feat(api-impl): admin override for policies (#​44387)

v0.1.94

Compare Source

  • feat(advisories): include severity information in advisory API (#​42513)

v0.1.93

Compare Source

v0.1.92

Compare Source

  • feat(cassie): split action-cache capabilities from CAS (#​44174)

v0.1.91

Compare Source

  • feat(guardener): self-service GitHub org↔group linking (API + chainctl + KMS-signed state) (#​43173)

v0.1.90

Compare Source

  • fix #​44025: ValidateHelmRepoURL accepts file://, ftp:// and empty-host URLs (#​44038)

v0.1.89

Compare Source

  • feat(datastore/iam): add BatchDelete to ExternalGroupRoleMappings (#​43816)

v0.1.88

Compare Source

  • fix(iam): wire GroupsClaim through v2beta1 IdP converter (#​43959)

v0.1.87

Compare Source

  • expose chart image requirement in API (#​43909)

v0.1.86

Compare Source

  • feat(registry): add RemoveEntitlementImages with soft delete (#​42334)
  • feat(api-impl/registry): implement v2alpha1 Repo README APIs (#​43928)

v0.1.85

Compare Source

  • chore(registry): remove dead image Diff API remnants (#​43536)

v0.1.84

Compare Source

  • aws-marketplace: add subscription reconciler (#​43795)

v0.1.83

Compare Source

  • Updates go.opentelemetry.io/otel from 1.43 to 1.44 (#​43876)
  • fix(deps): update chainguard (#​43806)

v0.1.82

Compare Source

  • registry: rename CAP_REPO_SYNC_ADMIN to CAP_REPO_INTERNAL_ADMIN and tidy repo v2 field semantics (#​43778)

v0.1.81

Compare Source

  • feat(iam): BatchCreateRoleBindings cache, AIP-233 role_uid, and event docs (#​43370)

v0.1.80

Compare Source

  • Add emeritoss to bundle allowlist (#​43725)

v0.1.79

Compare Source

  • feat(iam): promote Terms endpoints to v2beta1 and remove v2alpha1 (#​43364)

v0.1.78

Compare Source

  • sdk: propose v2beta1 Repos CRUD, readme singleton, and admin API (#​42682)

v0.1.77

Compare Source

  • registry: add v2 GetArchitectures and GetSize endpoints (#​41969)

v0.1.76

Compare Source

  • feat(bots/microflow): GitHub PR reconciler that runs microflows (#​42726)

v0.1.75

Compare Source

  • feat(rebuilder): grant prod-eco-python build SA malware-status access

v0.1.74

Compare Source

  • feat(argos): ArgosVulns query API — org-scoped CGP metadata (BatchGet, ListForOrg) (#​41760)

v0.1.73

Compare Source

  • feat(advisories): record grype DB provenance on detection and fixed events (#​43211)

v0.1.72

Compare Source

  • feat(libraries): migrate Artifacts service to v2beta1 (#​42526)

v0.1.71

Compare Source

  • feat(iam): migrate ExternalGroupRoleMapping to v2beta1 (#​43160)

v0.1.70

Compare Source

  • registry: emit subdomain on pull/push events for skills attribution (#​43168)

v0.1.69

Compare Source

  • graphql: add update for AWS subscriptions (#​43165)

v0.1.68

Compare Source

  • policies: audit events on policy mutations (#​43083)

v0.1.67

Compare Source

  • feat(iam): enrich group-mapping audit events (IdP + capabilities) (#​43035)

v0.1.66

Compare Source

  • api: add Update RPC for aws marketplace subscriptions (#​43141)

v0.1.65

Compare Source

  • fix(chainctl,sdk/sts): bound, retry, and fail-fast the refresh-token exchange instead of hanging or going interactive (CUS-839) (#​42233)

v0.1.64

Compare Source

  • feat(AddChart): allow users to specify a tag (#​42952)
  • sdk: rename AWS marketplace subscription caps and add to owner (#​43008)

v0.1.63

[Compare Source](https://redirect.github.c

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux

red-hat-konflux Bot commented Jul 17, 2026

Copy link
Copy Markdown
Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: go.sum
Command failed: go get -t ./...
go: github.com/ThalesGroup/crypto11@v1.6.8: parsing go.mod:
	module declares its path as: github.com/eclipse-keypont/crypto11
	        but was required as: github.com/ThalesGroup/crypto11

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/release-1.4/go-deps branch 28 times, most recently from c6e64ab to e19642c Compare July 22, 2026 21:56
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/release-1.4/go-deps branch 29 times, most recently from 52d2a9a to 413b79d Compare July 30, 2026 06:12
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants