Skip to content

fix(deps): update github actions - #397

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence Type Update Pending
github.com/cli/go-gh/v2 v2.16.0 → v2.16.1 age adoption passing confidence require patch
github.com/digitorus/pkcs7 ffadbf3 → d678ea5 age adoption passing confidence require digest
github.com/digitorus/timestamp c455327 → b4b58b9 age adoption passing confidence require digest
github.com/go-git/go-billy/v5 → 19ea4dd require pinDigest
github.com/go-git/go-git/v5 → 3eeb238 require pinDigest
github.com/go-openapi/strfmt → 49f0562 require pinDigest
github.com/google/go-github/v91 → a13dc0f require pinDigest
github.com/opencontainers/image-spec → 147f9c1 require pinDigest
github.com/sigstore/cosign/v3 → 11926fa require pinDigest
github.com/sigstore/protobuf-specs → 0342fe5 require pinDigest
github.com/sigstore/rekor → a36bd71 require pinDigest
github.com/sigstore/sigstore v1.10.9 → v1.10.10 age adoption passing confidence require patch v1.11.0 (+1)
github.com/sigstore/sigstore-go → 22d3691 require pinDigest
github.com/spf13/cobra → 88b30ab require pinDigest
github.com/spf13/pflag → 0491e57 require pinDigest
github.com/spf13/viper → 394040c require pinDigest
github.com/stretchr/testify → 959dbda require pinDigest
github.com/xeipuuv/gojsonschema → 82fcdeb require pinDigest
google.golang.org/protobuf → cdd4c5f require pinDigest
gopkg.in/yaml.v3 → f6f7691 require pinDigest

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

cli/go-gh (github.com/cli/go-gh/v2)

v2.16.1

Compare Source

What's Changed

New Contributors

Full Changelog: cli/go-gh@v2.16.0...v2.16.1

sigstore/sigstore (github.com/sigstore/sigstore)

v1.10.10

Compare Source

What's Changed

  • Validate ed25519 public key length in verifier constructors by @​sueun-dev in #​2378
  • build(deps): Bump google.golang.org/api from 0.287.1 to 0.291.0 in /pkg/signature/kms/gcp by @​dependabot[bot] in #​2389
  • build(deps): Bump the gomod group across 3 directories with 4 updates by @​dependabot[bot] in #​2393
  • build(deps): Bump hashicorp/vault from 2.0.3 to 2.0.4 in /test/e2e in the all group by @​dependabot[bot] in #​2391
  • build(deps): Bump github.com/sigstore/sigstore from 1.10.8 to 1.10.9 in /test/fuzz in the tools group across 1 directory by @​dependabot[bot] in #​2392
  • build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azidentity from 1.13.1 to 1.14.0 in /pkg/signature/kms/azure by @​dependabot[bot] in #​2388
  • build(deps): Bump github.com/aws/aws-sdk-go-v2/service/kms from 1.54.0 to 1.55.6 in /pkg/signature/kms/aws by @​dependabot[bot] in #​2387
  • build(deps): Bump google.golang.org/api from 0.291.0 to 0.293.0 in /pkg/signature/kms/gcp by @​dependabot[bot] in #​2401
  • build(deps): Bump github.com/tink-crypto/tink-go/v2 from 2.7.0 to 2.8.0 by @​dependabot[bot] in #​2399
  • build(deps): Bump github.com/secure-systems-lab/go-securesystemslib from 0.11.0 to 0.11.1 in /test/fuzz in the tools group across 1 directory by @​dependabot[bot] in #​2397
  • build(deps): Bump the gomod group across 2 directories with 7 updates by @​dependabot[bot] in #​2398
  • build(deps): Bump google.golang.org/grpc from 1.83.0 to 1.83.1 in /pkg/signature/kms/gcp by @​dependabot[bot] in #​2411
  • Add retryable HTTP transport by @​crazy-max in #​2396
  • build(deps): Bump google.golang.org/api from 0.293.0 to 0.295.0 in /pkg/signature/kms/gcp by @​dependabot[bot] in #​2408
  • build(deps): Bump github.com/aws/aws-sdk-go-v2/service/kms from 1.55.7 to 1.57.1 in /pkg/signature/kms/aws by @​dependabot[bot] in #​2404
  • build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore from 1.22.0 to 1.23.1 in /pkg/signature/kms/azure by @​dependabot[bot] in #​2407
  • build(deps): Bump github.com/aws/aws-sdk-go-v2/config from 1.32.38 to 1.33.2 in /pkg/signature/kms/aws by @​dependabot[bot] in #​2406
  • Fix Azure KMS ECDSA signature verification (r||s ordering + padding) by @​hugolevino in #​2410
  • build(deps): Bump hashicorp/vault from 2.0.4 to 2.1.0 in /test/e2e in the all group by @​dependabot[bot] in #​2412
  • Bump go to 1.27 and fix linter and api issues by @​loosebazooka in #​2415
  • Support for ML-DSA keys by @​loosebazooka in #​2416
  • adjust mldsa error handling by @​loosebazooka in #​2417
  • build(deps): Bump the gomod group across 4 directories with 4 updates by @​dependabot[bot] in #​2413
  • build(deps): Bump github.com/google/go-containerregistry from 0.21.9 to 0.22.1 by @​dependabot[bot] in #​2403

New Contributors

Full Changelog: sigstore/sigstore@v1.10.9...v1.10.10


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 5am every weekday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner September 29, 2026 02:50
@renovate renovate Bot added dependencies Pull requests that update a dependency file renovate labels Sep 29, 2026
@renovate

renovate Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 4 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=14 days

Details:

Package Change
go 1.26.6 -> 1.27.0
github.com/go-jose/go-jose/v4 v4.1.4 -> v4.1.5
github.com/google/go-containerregistry v0.21.7 -> v0.22.1
github.com/klauspost/compress v1.19.1 -> v1.19.2
github.com/secure-systems-lab/go-securesystemslib v0.11.0 -> v0.11.1

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: liatrio/autogov/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: b8a86e0e-f19d-4713-8689-d87c209020f0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 7bfd68d to f298436 Compare September 29, 2026 12:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file renovate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants