Skip to content

chore(deps): bump github.com/kubescape/opa-utils from 0.0.308 to 0.0.312 - #6861

Merged
devantler merged 2 commits into
mainfrom
dependabot/go_modules/github.com/kubescape/opa-utils-0.0.312
Sep 3, 2026
Merged

devantler merged 2 commits into
mainfrom
dependabot/go_modules/github.com/kubescape/opa-utils-0.0.312

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/kubescape/opa-utils from 0.0.308 to 0.0.312.

Commits
  • a39e2ee Merge pull request #191 from dakshhhhh16/scan-contract-provenance-types
  • f61eafd feat(report): add scan contract provenance types
  • d93b556 Merge pull request #190 from yugal07/lfx-alertonly-exception-semantics
  • 5dfcd5b fix(results): keep alertOnly exceptions failing instead of suppressing the fi...
  • 13c546f Merge pull request #189 from doraem-on/fix-3368
  • 49eb257 fix: an exception with no Resources matches everywhere, not nowhere
  • 097201d Merge pull request #188 from Namanbhatt-01/fix/framework-scoped-exceptions
  • b8930c3 fix: preserve framework-scoped exception status
  • 01d62a8 fix: scope exceptions by framework
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/kubescape/opa-utils](https://github.com/kubescape/opa-utils) from 0.0.308 to 0.0.312.
- [Release notes](https://github.com/kubescape/opa-utils/releases)
- [Commits](kubescape/opa-utils@v0.0.308...v0.0.312)

---
updated-dependencies:
- dependency-name: github.com/kubescape/opa-utils
  dependency-version: 0.0.312
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@ksail-bot
ksail-bot Bot enabled auto-merge (squash) September 3, 2026 17:16
@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

MegaLinter analysis: Success

✅ Linters with no issues

actionlint, bash-exec, git_diff, hadolint, jscpd, jsonlint, lychee, markdown-table-formatter, markdownlint, prettier, prettier, shellcheck, shfmt, stylelint, syft, trivy-sbom, trufflehog, v8r, v8r, yamllint

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: REPOSITORY_GITLEAKS. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@devantler
devantler marked this pull request as draft September 3, 2026 18:04
auto-merge was automatically disabled September 3, 2026 18:04

Pull request was converted to draft

The desktop module mirrors the root graph through its indirect pins, so the
root bump leaves it stale and the required Test job fails on
TestClaircoreLinkedPackagesStayInert/desktop (ksail#6862).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Adaptation commit pushed: 217ad20033c0a370c5f944e539dc059eb67cda1b — the desktop module tidied for opa-utils 0.0.312.

At Dependabot's head bba957fb the required 🧪 Test job failed on TestClaircoreLinkedPackagesStayInert/desktop (go: updates to go.mod needed), and the 🧩 Desktop App builds failed the same way: desktop/go.mod still pinned opa-utils v0.0.308 // indirect. CI detected the drift (desktop-tidy-patch uploaded) but, since #6851, no longer pushes it onto Dependabot branches — so nothing could finish this head. The systemic side is tracked in #6862.

The commit is one pin line plus its two go.sum entries. Converted to draft and auto-merge disabled before the push, per the dependency-PR adaptation rule; the adapted head now takes the ordinary current-head review gate before promotion and re-arming. Dependabot can no longer rebase this branch (#6832), so it is merged promptly rather than left to age.

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 3, 2026

Copy link
Copy Markdown

@devantler I will review the current pull request head.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Sep 3, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Team

Run ID: bc769598-950a-4102-9a46-90768870023a

📥 Commits

Reviewing files that changed from the base of the PR and between 0a382f9 and 217ad20.

⛔ Files ignored due to path filters (2)
  • desktop/go.sum is excluded by !**/*.sum
  • go.sum is excluded by !**/*.sum
📒 Files selected for processing (2)
  • desktop/go.mod
  • go.mod

Included review availability: Your plan provides up to 2 included reviews per hour; 1 remains after this review.

📜 Recent review details
🔇 Additional comments (2)
go.mod (1)

88-88: LGTM!

desktop/go.mod (1)

474-474: LGTM!


📝 Walkthrough

Walkthrough

The pull request updates github.com/kubescape/opa-utils from v0.0.308 to v0.0.312 in the root go.mod and desktop/go.mod files.

Merge Risk: ⚪ Minimal · up to 217ad

Both root and desktop modules now use the updated opa-utils version with matching dependency checksums. No current merge-blocking risk is identified.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the dependency update from github.com/kubescape/opa-utils v0.0.308 to v0.0.312.
Description check ✅ Passed The description accurately describes the dependency update and lists the included upstream fixes and features.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (2 skipped: 2 unsupported.)

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Ready at 217ad200 — the adapted head satisfies all three readiness conditions:

  1. Programmatically tested: CI green (77 checks, mergeStateStatus: CLEAN), 0 review threads, no body findings, no conflict with main.
  2. Reviewed: finding-free CodeRabbit review at 217ad20033c0a370c5f944e539dc059eb67cda1b — auto-generated summary "No actionable comments" naming the head (19:15:39Z) and status Review completed (19:15:41Z), both after the 19:10Z request. green_review=cr@217ad200.
  3. Tried as a user: the adaptation is the desktop-module tidy the bump needed; its effect is observed directly on this head's runs — the 🧪 Test job (including TestClaircoreLinkedPackagesStayInert/desktop) and both 🧩 Desktop App builds that failed at bba957fb with go: updates to go.mod needed now pass, and the tidy itself was run locally with the same result CI's 🧩 Verify Desktop Module Tidy job reports (no further drift).

Promoting and merging with --match-head-commit 217ad20033c0a370c5f944e539dc059eb67cda1b.

@devantler
devantler marked this pull request as ready for review September 3, 2026 19:16
@devantler
devantler merged commit 7c8c85b into main Sep 3, 2026
89 of 90 checks passed
@devantler
devantler deleted the dependabot/go_modules/github.com/kubescape/opa-utils-0.0.312 branch September 3, 2026 19:17
@github-project-automation github-project-automation Bot moved this from 🫴 Ready to ✅ Done in 🌊 Project Board Sep 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

1 participant