Skip to content

go(deps): Bump the go-dependencies group across 1 directory with 8 updates - #13

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-dependencies-c05d803956
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-dependencies-c05d803956

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown

Bumps the go-dependencies group with 8 updates in the / directory:

Package From To
github.com/ProtonMail/go-crypto 1.4.1 1.5.1
github.com/gowebpki/jcs 1.0.1 1.0.2
github.com/klauspost/compress 1.18.7 1.20.1
github.com/knadh/koanf/v2 2.3.6 2.3.7
github.com/mattn/go-isatty 0.0.20 0.0.24
github.com/vbauerster/mpb/v8 8.16.1 8.16.2
golang.org/x/sync 0.22.0 0.23.0
golang.org/x/term 0.45.0 0.46.0

Updates github.com/ProtonMail/go-crypto from 1.4.1 to 1.5.1

Release notes

Sourced from github.com/ProtonMail/go-crypto's releases.

Release v1.5.1

What's Changed

Full Changelog: ProtonMail/go-crypto@v1.5.0...v1.5.1

Release v1.5.1-proton

This release is v1.5.1 with support for the following non-standardized features:

Release v1.5.0

What's Changed

Full Changelog: ProtonMail/go-crypto@v1.4.1...v1.5.0

Commits
  • b3ee477 test: Ensure rsa key gen test works with go 1.27 (#334)
  • 361d29a Harden handling of malformed OpenPGP input (#332)
  • 9f896c8 fix: Reduce risk of invalid slice access (#331)
  • 1252688 fix: Do not accept malformed ecdh input (#329)
  • ac21ec5 fix: PKESK empty message decryption (#330)
  • d697e70 Reject embedded signatures in primary key binding signatures (#325)
  • d1dc24f Don't panic on unknown AEAD mode in v5/v6 SKESK packets (#322)
  • f7bfe56 Guard against nil issuer key ID on v2 message read path (#319)
  • 4fa2a8d Guard against nil issuer key ID when checking trailing signature (#320)
  • 0c1128b Implement ML-KEM, ML-DSA, and SLH-DSA (#316)
  • Additional commits viewable in compare view

Updates github.com/gowebpki/jcs from 1.0.1 to 1.0.2

Release notes

Sourced from github.com/gowebpki/jcs's releases.

Version 1.0.2

A fully implemented version of RFC 8785 for Golang with fixes for various bugs.

Commits

Updates github.com/klauspost/compress from 1.18.7 to 1.20.1

Release notes

Sourced from github.com/klauspost/compress's releases.

v1.20.1

What's Changed

New Contributors

Full Changelog: klauspost/compress@v1.20.0...v1.20.1

v1.20.0

What's Changed

New Contributors

Full Changelog: klauspost/compress@v1.19.2...v1.20.0

v1.19.2

What's Changed

... (truncated)

Commits
  • 5d880f2 tests: Pre-release cleanups (#1231)
  • 5ed8a01 Report unexpected EOF for truncated Huffman extra bits (#1229)
  • 0bed724 flate: avoid FMA in EstimatedBits for portable rounding (#1224)
  • 147b531 zstd: apply reset options to reused frame decoders (#1226)
  • 58dac78 gzhttp: only decompress a request when gzip is the outermost coding (#1223)
  • 9b00a55 gzhttp: preserve caller request headers in Transport (#1225)
  • de8f55d ossfuzz: include zstd seqdec path tests (#1222)
  • a1c49c6 flate: precompute literal costs for findMatch (#1217)
  • ebd8190 flate: avoid the hand-rolled sorts when generating Huffman codes (#1214)
  • 4dc0d32 flate: use separate tables in histogramSplit (#1215)
  • Additional commits viewable in compare view

Updates github.com/knadh/koanf/v2 from 2.3.6 to 2.3.7

Release notes

Sourced from github.com/knadh/koanf/v2's releases.

v2.3.7

What's Changed

New Contributors

Full Changelog: knadh/koanf@v2.3.6...v2.3.7

Commits
  • f3b40fa Fix typed map getter funcs returning empty results (#450)
  • c69572c Fix Slices silently dropping a natively-typed []map[string]any (#448)
  • 83a6751 Bump google.golang.org/grpc from 1.82.1 to 1.83.1 in /examples (#446)
  • c316bd1 Fix empty slices resulting in removed keys in StringsMap() (#449)
  • 6ad56fe Fix key collission on 'Unflatten' by making insertions deterministic. Closes ...
  • eb15bf7 fix: panic when Config.Transport is not supplied (#439)
  • defde9b Fix azurevault throwing 403 incorrectly fetching disabled keys. Closes #436.
  • fb45026 Skip env entries without '=' in env provider avoid panicking.
  • See full diff in compare view

Updates github.com/mattn/go-isatty from 0.0.20 to 0.0.24

Commits
  • c44dc0b Use TIOCGWINSZ instead of TCGETS to detect terminals (#97)
  • 4bc9b75 Lower go directive to 1.20 for Windows 7 users (#94)
  • 4e061da add stub for haiku os (#93)
  • 9a68506 Fix isCygwinPipeName to accept Windows 7 trailing suffix (#90)
  • 4237fb1 Update Go test matrix to current versions (1.24-1.26)
  • 433c12b Update GitHub Actions to latest versions
  • 1cf5589 Add wasip1 and wasip2 to build constraints in isatty_others.go
  • 1237245 Update dependencies: go 1.15 -> 1.21, golang.org/x/sys v0.6.0 -> v0.28.0
  • ac9c88d Fix typo in comment: undocomented -> undocumented
  • 8b7124e Add availability check for NtQueryObject in init
  • Additional commits viewable in compare view

Updates github.com/vbauerster/mpb/v8 from 8.16.1 to 8.16.2

Release notes

Sourced from github.com/vbauerster/mpb/v8's releases.

v8.16.2

Full Changelog: vbauerster/mpb@v8.16.1...v8.16.2

Commits

Updates golang.org/x/sync from 0.22.0 to 0.23.0

Commits
  • f75267d semaphore: panic on negative capacity
  • 3ffd83c all: upgrade go directive to at least 1.26.0 [generated]
  • See full diff in compare view

Updates golang.org/x/term from 0.45.0 to 0.46.0

Commits
  • 6226200 go.mod: update golang.org/x dependencies
  • 7c2fb74 term: process bytes returned with a read error
  • 3963fce all: upgrade go directive to at least 1.26.0 [generated]
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…dates

Bumps the go-dependencies group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/ProtonMail/go-crypto](https://github.com/ProtonMail/go-crypto) | `1.4.1` | `1.5.1` |
| [github.com/gowebpki/jcs](https://github.com/gowebpki/jcs) | `1.0.1` | `1.0.2` |
| [github.com/klauspost/compress](https://github.com/klauspost/compress) | `1.18.7` | `1.20.1` |
| [github.com/knadh/koanf/v2](https://github.com/knadh/koanf) | `2.3.6` | `2.3.7` |
| [github.com/mattn/go-isatty](https://github.com/mattn/go-isatty) | `0.0.20` | `0.0.24` |
| [github.com/vbauerster/mpb/v8](https://github.com/vbauerster/mpb) | `8.16.1` | `8.16.2` |
| [golang.org/x/sync](https://github.com/golang/sync) | `0.22.0` | `0.23.0` |
| [golang.org/x/term](https://github.com/golang/term) | `0.45.0` | `0.46.0` |



Updates `github.com/ProtonMail/go-crypto` from 1.4.1 to 1.5.1
- [Release notes](https://github.com/ProtonMail/go-crypto/releases)
- [Commits](ProtonMail/go-crypto@v1.4.1...v1.5.1)

Updates `github.com/gowebpki/jcs` from 1.0.1 to 1.0.2
- [Release notes](https://github.com/gowebpki/jcs/releases)
- [Commits](gowebpki/jcs@v1.0.1...v1.0.2)

Updates `github.com/klauspost/compress` from 1.18.7 to 1.20.1
- [Release notes](https://github.com/klauspost/compress/releases)
- [Commits](klauspost/compress@v1.18.7...v1.20.1)

Updates `github.com/knadh/koanf/v2` from 2.3.6 to 2.3.7
- [Release notes](https://github.com/knadh/koanf/releases)
- [Commits](knadh/koanf@v2.3.6...v2.3.7)

Updates `github.com/mattn/go-isatty` from 0.0.20 to 0.0.24
- [Commits](mattn/go-isatty@v0.0.20...v0.0.24)

Updates `github.com/vbauerster/mpb/v8` from 8.16.1 to 8.16.2
- [Release notes](https://github.com/vbauerster/mpb/releases)
- [Commits](vbauerster/mpb@v8.16.1...v8.16.2)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](golang/sync@v0.22.0...v0.23.0)

Updates `golang.org/x/term` from 0.45.0 to 0.46.0
- [Commits](golang/term@v0.45.0...v0.46.0)

---
updated-dependencies:
- dependency-name: github.com/ProtonMail/go-crypto
  dependency-version: 1.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: github.com/gowebpki/jcs
  dependency-version: 1.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/klauspost/compress
  dependency-version: 1.20.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: github.com/knadh/koanf/v2
  dependency-version: 2.3.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/mattn/go-isatty
  dependency-version: 0.0.24
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/vbauerster/mpb/v8
  dependency-version: 8.16.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: golang.org/x/term
  dependency-version: 0.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies, go. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants