Skip to content

build(deps): bump the minor-and-patch group across 1 directory with 18 updates - #13079

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/minor-and-patch-21fb060dbf
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/minor-and-patch-21fb060dbf

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 18 updates in the / directory:

Package From To
github.com/blevesearch/bleve/v2 2.6.0 2.6.1
github.com/davidbyttow/govips/v2 2.18.0 2.19.0
github.com/grpc-ecosystem/grpc-gateway/v2 2.30.0 2.31.0
github.com/libregraph/lico 0.67.0 0.68.0
github.com/olekukonko/tablewriter 1.1.4 1.1.5
github.com/open-policy-agent/opa 1.19.0 1.21.1
github.com/sirupsen/logrus 1.10.0 1.10.2
github.com/tidwall/gjson 1.19.0 1.19.1
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc 0.71.0 0.72.0
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp 0.70.0 0.71.0
go.opentelemetry.io/contrib/zpages 0.70.0 0.72.0
go.opentelemetry.io/otel 1.46.0 1.47.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc 1.46.0 1.47.0
go.opentelemetry.io/otel/sdk 1.46.0 1.47.0
go.opentelemetry.io/otel/trace 1.46.0 1.47.0
golang.org/x/exp 0.0.0-20260611194520-c48552f49976 0.0.0-20260908205506-85c1c2202aba
golang.org/x/image 0.45.0 0.46.0
google.golang.org/genproto/googleapis/api 0.0.0-20260819154853-08b0e4226688 0.0.0-20260928230214-8a89bd6388cc

Updates github.com/blevesearch/bleve/v2 from 2.6.0 to 2.6.1

Release notes

Sourced from github.com/blevesearch/bleve/v2's releases.

v2.6.1

What's Changed

New Contributors

Full Changelog: blevesearch/bleve@v2.6.0...v2.6.1

Commits

Updates github.com/davidbyttow/govips/v2 from 2.18.0 to 2.19.0

Release notes

Sourced from github.com/davidbyttow/govips/v2's releases.

v2.19.0

Highlights

  • Streaming I/O: new LoadImageFromReader, SaveToWriter, and TranscodeStream for working with io.Reader/io.Writer instead of whole buffers (#539). Stream loads sniff the file signature, so sub-formats like AVIF vs HEIF are still reported correctly (#540)
  • NewImageFromMemory: build an ImageRef from a raw pixel buffer (#528)
  • WebP TargetSize: new option on WebpExportParams, requires libvips 8.17.4+ (#535)
  • Kill flag: SetKill exposes libvips' image evaluation kill flag, for cancelling long-running work (#537)
  • BigTIFF image type detection (#527)

Fixes

Several of these are memory-safety bugs that could crash a process. Upgrading is recommended.

  • Fix SIGSEGV after a failed DrawRect: the error path unref'd the caller's image, so the later Close() or GC finalizer was a double-unref. Reachable from truncated JPEGs (#547, #549)
  • Fix input double-unref in Join, which caused intermittent use-after-free crashes at unrelated call sites (#531)
  • Fix SetBlob: it passed the slice header to C instead of the backing array and panicked under cgocheck on any non-empty input (#545, #549)
  • Fix a C string leak on every ExportMagick call (#546, #549)
  • Keep ImageRef arguments alive across cgo calls in two-image ops (Composite, Insert, Join, ArrayJoin, BandJoin, Mapim, Maplut, Add, Subtract, Multiply, Divide), closing a GC finalization hazard (#543)
  • Fix background colors on 1 and 2-band greyscale images for Embed and friends (#534, #538)

Housekeeping

  • Add AGENTS.md with contributor and agent guidance: cgo/memory rules, testing conventions, known local quirks (#541, #542)
  • CI installs the libheif HEVC plugin so HEIC fixtures run (#529)
  • Bump golang.org/x/image to 0.41.0 and golang.org/x/net to 0.55.0 (#533, #532)
  • Bump sharp in examples/tiff (#536, #548)

Thanks to @​antst, @​alon-ne, @​goodmartian, and @​joecorall for patches, and to @​svkoskin and @​OvOhao for detailed bug reports.

Commits
  • f1d8d53 Fix three cgo memory bugs: DrawRect double-unref, SetBlob pointer, magick for...
  • f005cdb Bump sharp from 0.35.0 to 0.35.4 in /examples/tiff (#548)
  • ea03fac Add runtime.KeepAlive for ImageRef arguments in two-image ops (#543)
  • 1159365 Correct AGENTS.md on ImageRef locking (#542)
  • 67c3214 Add AGENTS.md with agent/contributor guidance (#541)
  • 33bd986 Sniff stream signature to preserve sub-format detection (#540)
  • 78f9044 Add streaming I/O: LoadImageFromReader, SaveToWriter, TranscodeStream (#539)
  • 6a7b264 Bump golang.org/x/image from 0.38.0 to 0.41.0 (#533)
  • ef9141c Fix background colors for 1/2-band greyscale images (#538)
  • f181186 Bump golang.org/x/net from 0.52.0 to 0.55.0 (#532)
  • Additional commits viewable in compare view

Updates github.com/grpc-ecosystem/grpc-gateway/v2 from 2.30.0 to 2.31.0

Release notes

Sourced from github.com/grpc-ecosystem/grpc-gateway/v2's releases.

v2.31.0

What's Changed

New Contributors

Full Changelog: grpc-ecosystem/grpc-gateway@v2.30.0...v2.31.0

Commits
  • 1dbf071 runtime: deep wildcard (**) must not match zero segments after a preceding li...
  • 53e28c4 chore(deps): update google/oss-fuzz digest to bd2ce21 (#7413)
  • 84afe50 chore(deps): update googleapis digest to 665784f (#7411)
  • dc62ab3 chore(deps): update google/oss-fuzz digest to bee2a55 (#7410)
  • 87fcd67 protoc-gen-openapiv2: allow proto files without a go_package option (#7409)
  • e534705 fix(deps): update module github.com/go-openapi/errors to v0.22.9 (#7408)
  • 5fc39f4 chore(deps): update googleapis digest to cdf35e7 (#7407)
  • a2e3b17 chore(deps): update dependency com_github_bazelbuild_buildtools to v10.1.0 (#...
  • 296885a chore(deps): update googleapis digest to d22e357 (#7406)
  • ca06c22 parse integer and enum path params as base 10 in convert.go (#7405)
  • Additional commits viewable in compare view

Updates github.com/libregraph/lico from 0.67.0 to 0.68.0

Changelog

Sourced from github.com/libregraph/lico's changelog.

v0.68.0 (2026-09-01)

  • Limit decompressed size of SAML logout messages
  • Fix the action logger running in production
  • Bump github.com/sirupsen/logrus from 1.9.3 to 1.9.4
  • Bump golang.org/x/crypto from 0.51.0 to 0.52.0
  • Bump github.com/go-ldap/ldap/v3 from 3.4.11 to 3.4.13
  • Bump golang.org/x/net from 0.47.0 to 0.55.0
  • Bump golang.org/x/oauth2 from 0.31.0 to 0.35.0
  • Bump github.com/go-jose/go-jose/v3 from 3.0.4 to 3.0.5
  • Bump github.com/Azure/go-ntlmssp
Commits
  • f60e071 Add v0.68.0 to changelog
  • cc2cb24 Limit decompressed size of SAML logout messages
  • a09a858 Fix the action logger running in production
  • 9283212 Bump github.com/sirupsen/logrus from 1.9.3 to 1.9.4
  • 873feda Bump golang.org/x/crypto from 0.51.0 to 0.52.0
  • 439f03d Bump github.com/go-ldap/ldap/v3 from 3.4.11 to 3.4.13
  • fb2dae7 Bump golang.org/x/net from 0.47.0 to 0.55.0
  • 0f56768 Bump golang.org/x/oauth2 from 0.31.0 to 0.35.0
  • 53e778a Bump github.com/go-jose/go-jose/v3 from 3.0.4 to 3.0.5
  • 586747e Bump github.com/Azure/go-ntlmssp
  • See full diff in compare view

Updates github.com/olekukonko/tablewriter from 1.1.4 to 1.1.5

Commits
  • 5f0c87a change readme to v1.1.5
  • 8535cd2 Merge pull request #331 from olekukonko/makawhy
  • 8db545f markdown game
  • 569d938 Merge pull request #330 from olekukonko/makawhy
  • ce371fa Merge pull request #326 from olekukonko/makawhy
  • e1d22bb Merge pull request #329 from team-humaki/fix/global-width-wrap-split
  • c9a710f Merge pull request #327 from youdie006/wrapwords-last-word-hang
  • cbd4eb4 wrap: split Widths.Global across columns
  • 2a7896c Broaden the WrapWords table to the shapes around the last-word case
  • cb595f4 Terminate WrapWords when the last word is wider than the limit
  • Additional commits viewable in compare view

Updates github.com/open-policy-agent/opa from 1.19.0 to 1.21.1

Release notes

Sourced from github.com/open-policy-agent/opa's releases.

v1.21.1

This release fixes a compiler regression introduced in OPA v1.21.0.

Fix some … in/every in comprehensions nested in object and set literals (#9280)

A comprehension using some … in or every in its body, nested inside an object or set literal, was wrongly treated as ground, so the compiler skipped rewriting it. some … in then failed with rego_unsafe_var_error; every caused a compiler panic:

package example
p := {"k": [r.a | some r in input.xs]}           # rego_unsafe_var_error: var r is unsafe
q := {[1 | every x in input.xs { x > 0 }]}       # panic

Array literals weren't affected, and neither were literals that contain some other non-ground term.

authored by @​srenatus, reported by @​tun0

v1.21.0

This release contains a mix of new features and bug fixes. Notably:

  • Improved rule indexing
  • Improved rule recursion check
  • YAML is parsed against the 1.2 core schema (breaking change)

Rules with general refs no longer collide in the recursion check (#6813)

Before, this was a recursion error:

package play
p[x].foo.bar if {
x := "a"
not p[x].foo.baz
}
p[x].foo.baz if {
x := "a"
false
}

Rules with a variable in their head are all stored at the ground prefix of their ref, so p[x].foo.bar and p[x].foo.baz looked like dependencies of each other. The compiler is now less conservative and compares the ref parts past the prefix. Genuine cycles are still reported.

... (truncated)

Changelog

Sourced from github.com/open-policy-agent/opa's changelog.

1.21.1

This release fixes a compiler regression introduced in OPA v1.21.0.

Fix some … in/every in comprehensions nested in object and set literals (#9280)

A comprehension using some … in or every in its body, nested inside an object or set literal, was wrongly treated as ground, so the compiler skipped rewriting it. some … in then failed with rego_unsafe_var_error; every caused a compiler panic:

package example
p := {"k": [r.a | some r in input.xs]}           # rego_unsafe_var_error: var r is unsafe
q := {[1 | every x in input.xs { x > 0 }]}       # panic

Array literals weren't affected, and neither were literals that contain some other non-ground term.

authored by @​srenatus, reported by @​tun0

1.21.0

This release contains a mix of new features and bug fixes. Notably:

  • Improved rule indexing
  • Improved rule recursion check
  • YAML is parsed against the 1.2 core schema (breaking change)

Rules with general refs no longer collide in the recursion check (#6813)

Before, this was a recursion error:

package play
p[x].foo.bar if {
x := "a"
not p[x].foo.baz
}
p[x].foo.baz if {
x := "a"
false
}

Rules with a variable in their head are all stored at the ground prefix of their ref, so p[x].foo.bar and p[x].foo.baz looked like dependencies of each other. The compiler is now less conservative and compares the ref parts past the prefix. Genuine cycles are still reported.

... (truncated)

Commits
  • 2a109e5 Prepare v1.21.1 release
  • 9057ccb ast: treat SomeDecl/Every exprs as non-ground in Expr.IsGround
  • dc6269f Release v1.21.0 (#9258)
  • f6aa85f ast: count a ref once when an index entry replaces its var entry
  • b7a4a42 build(deps): bump the dependencies group across 2 directories with 11 updates
  • 3f11d3a docs: update Agent Evidence Admission repo links (#9255)
  • 2dcd8ab topdown: fix flaky TestRegexBuiltinCache (#9254)
  • c327a14 docs: ecosystem entry for Agent Evidence Admission (#9213)
  • a83674f docs: Address incorrect package name in example (#9250)
  • 620b7a5 website: Implement local search based on Pagefind (#9249)
  • Additional commits viewable in compare view

Updates github.com/sirupsen/logrus from 1.10.0 to 1.10.2

Release notes

Sourced from github.com/sirupsen/logrus's releases.

v1.10.2

Logrus v1.10.2

This is a small maintenance release that updates github.com/stretchr/testify to v1.12.1, removing the legacy gopkg.in/yaml.v3 dependency from Logrus' dependency graph. There are no functional changes in this release.

Dependency Changes

  • update github.com/stretchr/testify to v1.12.1

Full Changelog: sirupsen/logrus@v1.10.1...v1.10.2

v1.10.1

Logrus v1.10.1

This patch release fixes two issues in field formatting and handling:

  • Fix a regression introduced in v1.10.0 where TextFormatter could panic when formatting nil or panicking error and fmt.Stringer values.
  • Allow function-backed values implementing error to be used with WithError, WithField, and WithFields.

Dependency Changes

  • update github.com/stretchr/testify to v1.12.0

Full Changelog: sirupsen/logrus@v1.10.0...v1.10.1

Changelog

Sourced from github.com/sirupsen/logrus's changelog.

1.10.2

Changed:

  • Update github.com/stretchr/testify to v1.12.1, removing the legacy gopkg.in/yaml.v3 dependency.

1.10.1

Fixes:

  • Fix a regression introduced in v1.10.0 where TextFormatter could panic when formatting nil or panicking error and fmt.Stringer values.
  • Allow function-backed implementations of error as field values.
Commits
  • 6d6a132 Merge pull request #1586 from thaJeztah/prepare_v1.10.2
  • 4f94653 update changelog for v1.10.2
  • 87434bb Merge pull request #1585 from thaJeztah/bump_testify
  • e7d2120 chore(deps): bump github.com/stretchr/testify v1.12.1
  • 8b673a9 Merge pull request #1583 from thaJeztah/release_1.10.1
  • 0b920ad Merge pull request #1584 from thaJeztah/more_coverage
  • 5e20694 TextFormatter: cover nil pointer method receivers
  • 8312732 update changelog for v1.10.1
  • e987a40 Merge pull request #1582 from thaJeztah/panic_handler
  • 17d574b TextFormatter: recover panics from Error and String methods
  • Additional commits viewable in compare view

Updates github.com/tidwall/gjson from 1.19.0 to 1.19.1

Commits

Updates go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc from 0.71.0 to 0.72.0

Changelog

Sourced from go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc's changelog.

[1.47.0/2.6.0/0.72.0/0.38.0/0.27.0/0.21.0/0.17.0/0.19.0] - 2026-10-03

Added

  • Add NewResourceDetectorWithOptions and the WithAWSLogger option to go.opentelemetry.io/contrib/detectors/aws/ec2/v2, allowing a custom AWS SDK logging.Logger to be supplied to the EC2 resource detector. (#9132)
  • Add go.opentelemetry.io/contrib/detectors/openshift, a new resource detector for OpenShift 4 clusters, ported from processor/resourcedetectionprocessor/internal/openshift in opentelemetry-collector-contrib. Detects k8s.cluster.name, and cloud.provider, cloud.platform and cloud.region for clusters running on AWS, Google Cloud and IBM Cloud; Azure clusters report cloud.provider and cloud.platform only. (#9499)
  • Add go.opentelemetry.io/contrib/detectors/kubeadm, a new resource detector for kubeadm-provisioned Kubernetes clusters, ported from processor/resourcedetectionprocessor/internal/kubeadm in opentelemetry-collector-contrib. Detects k8s.cluster.name from the ClusterConfiguration document in the kube-system/kubeadm-config ConfigMap and k8s.cluster.uid from the kube-system namespace UID. (#9500)

Changed

  • Client metrics in go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp no longer include attributes from the server-side Labeler, preventing attributes such as http.route from leaking into outbound requests. This is a breaking change for applications that use ContextWithLabeler to add custom client metric attributes: use ContextWithClientLabeler / ClientLabelerFromContext or the WithMetricAttributesFn option instead. Server-side use of ContextWithLabeler / LabelerFromContext is unchanged. (#8924)
  • Stop emitting the legacy http.read_bytes and http.wrote_bytes attributes on the per-operation span events enabled by WithMessageEvents in go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp. The read and write events remain, while total body sizes continue to be recorded on the server span as http.request.body.size and http.response.body.size according to HTTP semantic conventions. (#9624)

Deprecated

  • Deprecate go.opentelemetry.io/contrib/instrumentation/github.com/aws/aws-sdk-go-v2/otelaws. (#9707)
  • Deprecate go.opentelemetry.io/contrib/propagators/aws. (#9706)
  • Deprecate go.opentelemetry.io/contrib/samplers/probability/consistent. (#9633)
  • Deprecate ReadBytesKey, ReadErrorKey, WroteBytesKey, and WriteErrorKey in go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp. The identifiers remain available and their values are unchanged, but WithMessageEvents no longer emits http.read_bytes or http.wrote_bytes. There is no semantic-convention replacement for per-read or per-write byte counts or the human-readable error fields. Use HTTPRequestBodySizeKey and HTTPResponseBodySizeKey from go.opentelemetry.io/otel/semconv/v1.43.0 to record total body sizes on the span. If an error causes the HTTP request to fail, set the span status to Error and record ErrorType(err) from go.opentelemetry.io/otel/semconv/v1.43.0 on the span. (#9624)

Fixed

  • Treat empty Prometheus exporter environment variable values as unset in go.opentelemetry.io/contrib/exporters/autoexport, restoring the documented defaults. (#9636)
  • Bound converter-owned recursive map, slice, array, and pointer traversal in go.opentelemetry.io/contrib/bridges/otellogr, go.opentelemetry.io/contrib/bridges/otellogrus, go.opentelemetry.io/contrib/bridges/otelslog, and go.opentelemetry.io/contrib/bridges/otelzap. A field requiring more than 100 such levels is replaced with <max-depth-exceeded> and the record continues to be emitted. Existing fmt and user-method behavior remains unchanged. (#9691)
  • Format span attributes in go.opentelemetry.io/contrib/zpages using attribute.Value.String instead of the deprecated attribute.Value.Emit, following the OpenTelemetry AnyValue representation for non-OTLP protocols. (#9453)
  • Set error.type on the span and on the request-duration, request-body-size, and response-body-size metrics when a client disconnects mid-request in go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin, using the request context's cancellation error as the classification source when the handler has not already recorded an error via c.Error. Previously a disconnect was recorded with span status Error and no error.type, indistinguishable from a genuine server fault. (#9394)
  • Report Prometheus metrics HTTP server errors in go.opentelemetry.io/contrib/otelconf when using the v0.2.0 configuration schema. The error check was inverted, so a clean shutdown (http.ErrServerClosed) was reported as unexpected while real Serve errors were ignored. (#9653)
  • Fix temporary file cleanup for multipart requests in go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp by copying the parsed multipart form back to the original request during deferred cleanup, preserving net/http cleanup during panic unwinding for HTTP/2 panic handling and outer recovery middleware paths. Unrecovered HTTP/1 handler panics remain uncleaned because net/http skips finishRequest in that path. (#9685)
  • Fix http.client.request.body.size recording for streaming request bodies in go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp. (#8684)
  • Bound Kubernetes ConfigMap requests in go.opentelemetry.io/contrib/detectors/aws/eks with a 10-second timeout so Detect cannot hang indefinitely when the caller-provided context has no deadline. (#9419)

Removed

  • Drop support for [Go 1.25]. (#9584)
  • Remove go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho. Use github.com/labstack/echo-opentelemetry instead. (#9613)
Commits
  • 0c76f61 Release v1.47.0/v2.6.0/v0.72.0/v0.38.0/v0.27.0/v0.21.0/v0.17.0/v0.19.0 (#9802)
  • 318f5f9 Add timeout on Kubernetes API calls for EKS detector (#9419)
  • f848a15 test(detector/ecs): increase unit test coverage (#9774)
  • c0d84de Restore gofumpt clothe-returns and balance-calls (#9793)
  • 6215054 fix(deps): update aws-sdk-go-v2 monorepo (#9785)
  • 9a2e8ea fix(deps): update kubernetes monorepo to v0.37.1
  • 3d8e338 chore(deps): update sigs.k8s.io/json digest to 11ed52e
  • be5b688 chore(deps): update go-openapi packages
  • e382b4d chore(deps): update module github.com/fxamacker/cbor/v2 to v2.9.4
  • 97f9e88 fix(deps): update module github.com/moby/moby/client to v0.6.1
  • Additional commits viewable in compare view

Updates go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp from 0.70.0 to 0.71.0

Changelog

Sourced from go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp's changelog.

[1.46.0/2.5.3/0.71.0/0.37.3/0.26.0/0.20.1/0.16.3/0.18.0] - 2026-08-25

This release is the last to support [Go 1.25]. The next release will require at least [Go 1.26].

Added

  • Add support for the aws.ec2 resource detector in go.opentelemetry.io/contrib/otelconf/x. (#9139)
  • Support testing of [Go 1.27]. (#9524)
  • Add go.opentelemetry.io/contrib/detectors/docker, a resource detector for Docker, ported from processor/resourcedetectionprocessor/internal/docker in opentelemetry-collector-contrib. (#9001)
  • Add S3AttributeBuilder to go.opentelemetry.io/contrib/instrumentation/github.com/aws/aws-sdk-go-v2/otelaws that sets S3-specific span attributes following the OpenTelemetry S3 semantic conventions. (#9292)

Deprecated

  • Deprecate go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho. Use github.com/labstack/echo-opentelemetry instead. (#9136)

Fixed

  • Record error.type attribute on server spans in go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful when a request is cancelled or ends in a 5xx error. (#9387)
  • Report ot-baggage-* extraction errors from go.opentelemetry.io/contrib/propagators/ot to otel.Handle instead of silently discarding them, while still attaching the successfully parsed baggage members to the context. (

…8 updates

Bumps the minor-and-patch group with 18 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/blevesearch/bleve/v2](https://github.com/blevesearch/bleve) | `2.6.0` | `2.6.1` |
| [github.com/davidbyttow/govips/v2](https://github.com/davidbyttow/govips) | `2.18.0` | `2.19.0` |
| [github.com/grpc-ecosystem/grpc-gateway/v2](https://github.com/grpc-ecosystem/grpc-gateway) | `2.30.0` | `2.31.0` |
| [github.com/libregraph/lico](https://github.com/libregraph/lico) | `0.67.0` | `0.68.0` |
| [github.com/olekukonko/tablewriter](https://github.com/olekukonko/tablewriter) | `1.1.4` | `1.1.5` |
| [github.com/open-policy-agent/opa](https://github.com/open-policy-agent/opa) | `1.19.0` | `1.21.1` |
| [github.com/sirupsen/logrus](https://github.com/sirupsen/logrus) | `1.10.0` | `1.10.2` |
| [github.com/tidwall/gjson](https://github.com/tidwall/gjson) | `1.19.0` | `1.19.1` |
| [go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc](https://github.com/open-telemetry/opentelemetry-go-contrib) | `0.71.0` | `0.72.0` |
| [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp](https://github.com/open-telemetry/opentelemetry-go-contrib) | `0.70.0` | `0.71.0` |
| [go.opentelemetry.io/contrib/zpages](https://github.com/open-telemetry/opentelemetry-go-contrib) | `0.70.0` | `0.72.0` |
| [go.opentelemetry.io/otel](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [go.opentelemetry.io/otel/trace](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [golang.org/x/exp](https://github.com/golang/exp) | `0.0.0-20260611194520-c48552f49976` | `0.0.0-20260908205506-85c1c2202aba` |
| [golang.org/x/image](https://github.com/golang/image) | `0.45.0` | `0.46.0` |
| [google.golang.org/genproto/googleapis/api](https://github.com/googleapis/go-genproto) | `0.0.0-20260819154853-08b0e4226688` | `0.0.0-20260928230214-8a89bd6388cc` |



Updates `github.com/blevesearch/bleve/v2` from 2.6.0 to 2.6.1
- [Release notes](https://github.com/blevesearch/bleve/releases)
- [Commits](blevesearch/bleve@v2.6.0...v2.6.1)

Updates `github.com/davidbyttow/govips/v2` from 2.18.0 to 2.19.0
- [Release notes](https://github.com/davidbyttow/govips/releases)
- [Commits](davidbyttow/govips@v2.18.0...v2.19.0)

Updates `github.com/grpc-ecosystem/grpc-gateway/v2` from 2.30.0 to 2.31.0
- [Release notes](https://github.com/grpc-ecosystem/grpc-gateway/releases)
- [Commits](grpc-ecosystem/grpc-gateway@v2.30.0...v2.31.0)

Updates `github.com/libregraph/lico` from 0.67.0 to 0.68.0
- [Changelog](https://github.com/libregraph/lico/blob/master/CHANGELOG.md)
- [Commits](libregraph/lico@v0.67.0...v0.68.0)

Updates `github.com/olekukonko/tablewriter` from 1.1.4 to 1.1.5
- [Release notes](https://github.com/olekukonko/tablewriter/releases)
- [Commits](olekukonko/tablewriter@v1.1.4...v1.1.5)

Updates `github.com/open-policy-agent/opa` from 1.19.0 to 1.21.1
- [Release notes](https://github.com/open-policy-agent/opa/releases)
- [Changelog](https://github.com/open-policy-agent/opa/blob/main/CHANGELOG.md)
- [Commits](open-policy-agent/opa@v1.19.0...v1.21.1)

Updates `github.com/sirupsen/logrus` from 1.10.0 to 1.10.2
- [Release notes](https://github.com/sirupsen/logrus/releases)
- [Changelog](https://github.com/sirupsen/logrus/blob/master/CHANGELOG.md)
- [Commits](sirupsen/logrus@v1.10.0...v1.10.2)

Updates `github.com/tidwall/gjson` from 1.19.0 to 1.19.1
- [Commits](tidwall/gjson@v1.19.0...v1.19.1)

Updates `go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc` from 0.71.0 to 0.72.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go-contrib@zpages/v0.71.0...zpages/v0.72.0)

Updates `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` from 0.70.0 to 0.71.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go-contrib@zpages/v0.70.0...zpages/v0.71.0)

Updates `go.opentelemetry.io/contrib/zpages` from 0.70.0 to 0.72.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go-contrib@zpages/v0.70.0...zpages/v0.72.0)

Updates `go.opentelemetry.io/otel` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `go.opentelemetry.io/otel/sdk` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `go.opentelemetry.io/otel/trace` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `golang.org/x/exp` from 0.0.0-20260611194520-c48552f49976 to 0.0.0-20260908205506-85c1c2202aba
- [Commits](https://github.com/golang/exp/commits)

Updates `golang.org/x/image` from 0.45.0 to 0.46.0
- [Commits](golang/image@v0.45.0...v0.46.0)

Updates `google.golang.org/genproto/googleapis/api` from 0.0.0-20260819154853-08b0e4226688 to 0.0.0-20260928230214-8a89bd6388cc
- [Commits](https://github.com/googleapis/go-genproto/commits)

---
updated-dependencies:
- dependency-name: github.com/blevesearch/bleve/v2
  dependency-version: 2.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: github.com/davidbyttow/govips/v2
  dependency-version: 2.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/grpc-ecosystem/grpc-gateway/v2
  dependency-version: 2.31.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/libregraph/lico
  dependency-version: 0.68.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/olekukonko/tablewriter
  dependency-version: 1.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: github.com/open-policy-agent/opa
  dependency-version: 1.21.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/sirupsen/logrus
  dependency-version: 1.10.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: github.com/tidwall/gjson
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc
  dependency-version: 0.72.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp
  dependency-version: 0.71.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: go.opentelemetry.io/contrib/zpages
  dependency-version: 0.72.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: go.opentelemetry.io/otel
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: go.opentelemetry.io/otel/sdk
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: go.opentelemetry.io/otel/trace
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: golang.org/x/exp
  dependency-version: 0.0.0-20260908205506-85c1c2202aba
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: golang.org/x/image
  dependency-version: 0.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: google.golang.org/genproto/googleapis/api
  dependency-version: 0.0.0-20260928230214-8a89bd6388cc
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner October 6, 2026 15:26
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 6, 2026
@update-docs

update-docs Bot commented Oct 6, 2026

Copy link
Copy Markdown

Thanks for opening this pull request! The maintainers of this repository would appreciate it if you would create a changelog item based on your changes.

@kw-security

kw-security commented Oct 6, 2026 •

Copy link
Copy Markdown

⚠️ Snyk checks are incomplete.

Status Scan Engine Critical High Medium Low Total (0)
⚠️ Open Source Security 0 0 0 0 See details
⚠️ Licenses 0 0 0 0 See details
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

2403905 pushed a commit that referenced this pull request Oct 7, 2026
* chore(deps): consolidate dependency and security bumps

Dependabot PRs applied:
- #12878 qs 6.15.2 -> 6.16.0 (web/web-runtime)
- #13013 alpine 3.24.1 -> 3.24.2
- #13061 actions/checkout -> v7.0.1 (missed instance in k8s.yml)
- #13062 actions/setup-node -> v7.0.0 (missed instance in k8s.yml)
- #13075 simple-git 3.36.0 -> 4.0.1 (security)
- #13076 katex 0.16.45 -> 0.18.2+ (security)
- #13077 dompurify 3.4.13 -> 3.4.16 (security)
- #13079 go deps minor-and-patch group, 18 updates (opa 1.19.0 -> 1.21.1, otel 1.46 -> 1.47, bleve, govips, grpc-gateway, lico, tablewriter, logrus, gjson, x/exp, x/image, genproto, etc.)

Skipped (already satisfied on master): #12513, #12624, #12625, #12633

Manual security bumps via pnpm.overrides (no dependabot PR existed):
- axios -> 1.20.0
- smol-toml -> 1.9.0
- postcss -> 8.5.23
- postcss-selector-parser -> 7.1.6
- colord -> 2.9.4
- unhead -> 2.1.13
- markdown-it -> 14.3.1
- esbuild -> 0.28.1
- brace-expansion 5.0.11 -> 5.0.12

Not fixable: sprintf-js and elliptic have no patched version released upstream yet; left as-is.

go build and pnpm install verified clean.

* chore(deps): fix residual transitive vulns found by trivy

trivy flagged duplicate/stale resolutions that survived the earlier
override pass: dompurify (3.4.12 -> 3.4.16), qs (6.14.2 -> 6.16.0),
and fast-uri (3.1.7 -> 3.1.8, CVE-2026-86472). Added/bumped pnpm.overrides
accordingly. trivy fs scan of web/pnpm-lock.yaml now clean.

* chore(deps): bump reva to bac0e1ee144ab853a81c6b02142032f102dd245a

Pins github.com/owncloud/reva/v2 to bac0e1ee144ab853a81c6b02142032f102dd245a,
pulling in its go-playground/locales and huandu/xstrings version bumps.
Appends this PR to changelog/unreleased/bump-reva.md.

go build ./... verified clean after go mod vendor resync.

* fix(ci): revert unhead override, breaks web build

* revert: keep k8s.yml actions/checkout and setup-node pinned
@dependabot @github

dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 7, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/minor-and-patch-21fb060dbf branch October 7, 2026 06:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant