Skip to content

chore(deps): bump github.com/oapi-codegen/runtime from 1.4.2 to 1.6.0 - #296

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/oapi-codegen/runtime-1.6.0
Open

chore(deps): bump github.com/oapi-codegen/runtime from 1.4.2 to 1.6.0#296
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/oapi-codegen/runtime-1.6.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 23, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/oapi-codegen/runtime from 1.4.2 to 1.6.0.

Release notes

Sourced from github.com/oapi-codegen/runtime's releases.

Allow customization of parameter encoding

This is a small release which adds a global encoding setting on the runtime, to allow users to customize how to handle spaces in query arguments. This is a new minor release, since we're adding new API, even though this is a very minor feature. I imagine that in the future, we will add more settings, rather than making behavior assumptions.

🚀 New features and improvements

📦 Dependency updates

  • chore(deps): update module github.com/golangci/golangci-lint to v2.12.2 (#112) @renovate[bot]

Sponsors

We would like to thank our sponsors for their support during this release.

Sponsors

We would like to thank our sponsors for their support during this release.

v1.5.0: RFC3339 durations, and bug fixes

This is mainly a bugfix release, but we're bumping the minor version since we also introduce a new type, Duration into our types/ package, which allows for parsing and emitting RFC3339 durations. Rather than trying to parse a duration string into a time.Duration, which requires assumptions that may not be right for everyone, we decided not to make those decisions and just store all possible fields as provided. Users can convert this to Go Duration as they see fit.

🚀 New features and improvements

🐛 Bug fixes

📝 Documentation updates

... (truncated)

Commits
  • 01be2fa chore(deps): update module github.com/golangci/golangci-lint to v2.12.2 (#112)
  • 1463938 Allow customizing default query encoder (#145)
  • 540d34a fix(deps): update module github.com/labstack/echo/v5 to v5.3.0 (#142)
  • e89dbb8 Add types.Duration for the RFC 3339 duration format (#144)
  • 324e57f Let generated code declare whether styled parameter values are escaped (#143)
  • 95c13c0 Explain how to send nested objects when style serialization fails (#141)
  • 7c889f3 Prefer the form struct tag over json for form encoding (#140)
  • d0d5c3a chore(deps): update golang/govulncheck-action action to v1.1.0 (#137)
  • 67e86fd chore(deps): update oapi-codegen/actions action to v0.8.0 (#130)
  • df140cb fix(deps): update module github.com/labstack/echo/v5 to v5.2.1 (#126)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jul 23, 2026
@github-actions

github-actions Bot commented Jul 23, 2026

Copy link
Copy Markdown

MegaLinter analysis: Error

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 4 0 0 0.07s
✅ API spectral 2 0 0 2.57s
✅ COPYPASTE jscpd yes no no 2.05s
✅ DOCKERFILE hadolint 1 0 0 0.18s
✅ GO golangci-lint yes yes no no 57.53s
✅ GO revive yes no no 1.67s
✅ MARKDOWN markdownlint 2 0 0 0 0.62s
✅ MARKDOWN markdown-table-formatter 2 0 0 0 0.32s
✅ REPOSITORY checkov yes no no 41.88s
✅ REPOSITORY gitleaks yes no no 0.43s
✅ REPOSITORY git_diff yes no no 0.01s
⚠️ REPOSITORY grype yes 3 no 87.24s
✅ REPOSITORY secretlint yes no no 0.76s
✅ REPOSITORY syft yes no no 3.34s
❌ REPOSITORY trivy yes 1 no 24.76s
✅ REPOSITORY trivy-sbom yes no no 2.94s
✅ REPOSITORY trufflehog yes no no 4.7s
✅ SPELL lychee 14 0 0 0.11s
✅ YAML prettier 12 0 0 0 0.75s
✅ YAML v8r 12 0 0 14.84s
✅ YAML yamllint 12 0 0 0.73s

Detailed Issues

❌ REPOSITORY / trivy - 1 error
2026-08-04T21:21:23Z	INFO	[vulndb] Need to update DB
2026-08-04T21:21:23Z	INFO	[vulndb] Downloading vulnerability DB...
2026-08-04T21:21:23Z	INFO	[vulndb] Downloading artifact...	repo="mirror.gcr.io/aquasec/trivy-db:2"
15.98 MiB / 103.45 MiB [--------->__________________________________________________] 15.45% ? p/s ?38.11 MiB / 103.45 MiB [---------------------->_____________________________________] 36.84% ? p/s ?59.98 MiB / 103.45 MiB [---------------------------------->_________________________] 57.98% ? p/s ?82.48 MiB / 103.45 MiB [------------------------------------>_________] 79.73% 111.22 MiB p/s ETA 0s99.11 MiB / 103.45 MiB [-------------------------------------------->_] 95.80% 111.22 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [------------------------------------------->] 100.00% 111.22 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [------------------------------------------->] 100.00% 106.27 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [------------------------------------------->] 100.00% 106.27 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [------------------------------------------->] 100.00% 106.27 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 99.42 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 99.42 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 99.42 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 93.00 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 93.00 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 93.00 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 87.00 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 87.00 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 87.00 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 81.39 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 81.39 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 81.39 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 76.14 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 76.14 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 76.14 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 71.23 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 71.23 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 71.23 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 66.63 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 66.63 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 66.63 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 62.33 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 62.33 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 62.33 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 58.31 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 58.31 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 58.31 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 54.55 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 54.55 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 54.55 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 51.03 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 51.03 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 51.03 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 47.74 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 47.74 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 47.74 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 44.66 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 44.66 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 44.66 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 41.78 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 41.78 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 41.78 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 39.08 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 39.08 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 39.08 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 36.56 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 36.56 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 36.56 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 34.20 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 34.20 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 34.20 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 32.00 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 32.00 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 32.00 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 29.93 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------->] 100.00% 29.93 MiB p/s ETA 0s103.45 MiB / 103.45 MiB [-------------------------------------------------] 100.00% 7.97 MiB p/s 13s2026-08-04T21:21:38Z	INFO	[vulndb] Artifact successfully downloaded	repo="mirror.gcr.io/aquasec/trivy-db:2"
2026-08-04T21:21:38Z	INFO	[vuln] Vulnerability scanning is enabled
2026-08-04T21:21:38Z	INFO	[misconfig] Misconfiguration scanning is enabled
2026-08-04T21:21:38Z	INFO	[checks-client] Need to update the checks bundle
2026-08-04T21:21:38Z	INFO	[checks-client] Downloading the checks bundle...
234.65 KiB / 234.65 KiB [--------------------------------------------------------->] 100.00% ? p/s ?234.65 KiB / 234.65 KiB [----------------------------------------------] 100.00% 15.06 MiB p/s 200ms2026-08-04T21:21:47Z	INFO	Number of language-specific files	num=1
2026-08-04T21:21:47Z	INFO	[gomod] Detecting vulnerabilities...
2026-08-04T21:21:47Z	INFO	Detected config files	num=2
2026-08-04T21:21:47Z	WARN	Using severities from other vendors for some vulnerabilities. Read https://trivy.dev/docs/v0.69/guide/scanner/vulnerability#severity-selection for details.

Report Summary

┌──────────────────┬────────────┬─────────────────┬───────────────────┐
│      Target      │    Type    │ Vulnerabilities │ Misconfigurations │
├──────────────────┼────────────┼─────────────────┼───────────────────┤
│ go.mod           │   gomod    │        4        │         -         │
├──────────────────┼────────────┼─────────────────┼───────────────────┤
│ Dockerfile       │ dockerfile │        -        │         0         │
├──────────────────┼────────────┼─────────────────┼───────────────────┤
│ Dockerfile.local │ dockerfile │        -        │         0         │
└──────────────────┴────────────┴─────────────────┴───────────────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement.
VEX allows you to communicate the actual status of vulnerabilities in your project, improving security transparency and reducing false positives for your users.
Learn more and start using VEX: https://trivy.dev/docs/v0.69/guide/supply-chain/vex/repo#publishing-vex-documents

To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable.


go.mod (gomod)
==============
Total: 4 (UNKNOWN: 1, LOW: 0, MEDIUM: 1, HIGH: 1, CRITICAL: 1)

┌───────────────────────────────┬─────────────────────┬──────────┬──────────┬───────────────────┬───────────────┬────────────────────────────────────────────────────────────┐
│            Library            │    Vulnerability    │ Severity │  Status  │ Installed Version │ Fixed Version │                           Title                            │
├───────────────────────────────┼─────────────────────┼──────────┼──────────┼───────────────────┼───────────────┼────────────────────────────────────────────────────────────┤
│ github.com/getkin/kin-openapi │ GHSA-r277-6w6q-xmqw │ CRITICAL │ fixed    │ v0.140.0          │ 0.144.0       │ kin-openapi: ValidationHandler.Load() Fail-Open            │
│                               │                     │          │          │                   │               │ Authentication Bypass via NoopAuthenticationFunc Default   │
│                               │                     │          │          │                   │               │ https://github.com/advisories/GHSA-r277-6w6q-xmqw          │
│                               ├─────────────────────┼──────────┤          │                   │               ├────────────────────────────────────────────────────────────┤
│                               │ GHSA-jpcw-4wr7-c3vq │ MEDIUM   │          │                   │               │ kin-openapi openapi3filter: unauthenticated nil-pointer    │
│                               │                     │          │          │                   │               │ panic when validating a request against a `content`...     │
│                               │                     │          │          │                   │               │ https://github.com/advisories/GHSA-jpcw-4wr7-c3vq          │
├───────────────────────────────┼─────────────────────┼──────────┼──────────┼───────────────────┼───────────────┼────────────────────────────────────────────────────────────┤
│ golang.org/x/crypto           │ GO-2026-5932        │ UNKNOWN  │ affected │ v0.53.0           │               │ The golang.org/x/crypto/openpgp package is unmaintained,   │
│                               │                     │          │          │                   │               │ unsafe by design, and has known security...                │
├───────────────────────────────┼─────────────────────┼──────────┼──────────┼───────────────────┼───────────────┼────────────────────────────────────────────────────────────┤
│ golang.org/x/text             │ CVE-2026-56852      │ HIGH     │ fixed    │ v0.38.0           │ 0.39.0        │ A norm.Iter can enter an infinite loop when handling input │
│                               │                     │          │          │                   │               │ containing ...                                             │
│                               │                     │          │          │                   │               │ https://avd.aquasec.com/nvd/cve-2026-56852                 │
└───────────────────────────────┴─────────────────────┴──────────┴──────────┴───────────────────┴───────────────┴────────────────────────────────────────────────────────────┘

📣 Notices:
  - Version 0.73.0 of Trivy is now available, current version is 0.69.1

To suppress version checks, run Trivy scans with the --skip-version-check flag
⚠️ REPOSITORY / grype - 3 errors
[0000]  WARN no explicit name and version provided for directory source, deriving artifact ID from the given path (which is not ideal) from=syft
NAME                           INSTALLED  FIXED IN  TYPE       VULNERABILITY        SEVERITY  EPSS         RISK  
golang.org/x/text              v0.38.0    0.39.0    go-module  GO-2026-5970         High      0.4% (36th)  0.3   
github.com/getkin/kin-openapi  v0.140.0   0.144.0   go-module  GHSA-r277-6w6q-xmqw  Critical  N/A          N/A   
github.com/getkin/kin-openapi  v0.140.0   0.144.0   go-module  GHSA-jpcw-4wr7-c3vq  Medium    N/A          N/A   
github.com/klauspost/compress  v1.18.0    1.18.7    go-module  GO-2026-5841         Unknown   N/A          N/A   
golang.org/x/crypto            v0.53.0              go-module  GO-2026-5932         Unknown   N/A          N/A
[0087] ERROR discovered vulnerabilities at or above the severity threshold

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.4.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,API_SPECTRAL,COPYPASTE_JSCPD,DOCKERFILE_HADOLINT,GO_GOLANGCI_LINT,GO_REVIVE,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_GRYPE,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

Bumps [github.com/oapi-codegen/runtime](https://github.com/oapi-codegen/runtime) from 1.4.2 to 1.6.0.
- [Release notes](https://github.com/oapi-codegen/runtime/releases)
- [Commits](oapi-codegen/runtime@v1.4.2...v1.6.0)

---
updated-dependencies:
- dependency-name: github.com/oapi-codegen/runtime
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/github.com/oapi-codegen/runtime-1.6.0 branch from 8ec2fd8 to 0c740e2 Compare August 4, 2026 21:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant