Skip to content

Update Go Dependencies - #420

Open
red-hat-konflux[bot] wants to merge 1 commit into
release-1.4from
konflux/mintmaker/release-1.4/go-deps
Open

Update Go Dependencies#420
red-hat-konflux[bot] wants to merge 1 commit into
release-1.4from
konflux/mintmaker/release-1.4/go-deps

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Jul 17, 2026

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Pending
chainguard.dev/go-grpc-kit require minor v0.17.17v0.18.0
chainguard.dev/sdk require patch v0.1.54v0.1.224 v0.1.228 (+3)
cloud.google.com/go/auth indirect minor v0.20.0v0.23.2
cloud.google.com/go/iam indirect minor v1.11.0v1.13.0
cloud.google.com/go/kms indirect minor v1.31.0v1.33.0
cloud.google.com/go/longrunning indirect minor v1.0.0v1.2.0
cloud.google.com/go/security require minor v1.26.0v1.27.0
github.com/Azure/azure-sdk-for-go/sdk/azcore indirect minor v1.22.0v1.23.1
github.com/Azure/azure-sdk-for-go/sdk/azidentity indirect patch v1.14.0v1.14.1
github.com/AzureAD/microsoft-authentication-library-for-go indirect minor v1.7.2v1.9.0
github.com/Masterminds/semver/v3 indirect minor v3.3.1v3.5.0
github.com/ThalesGroup/crypto11 require patch v1.6.2v1.6.8
github.com/aws/aws-sdk-go indirect patch v1.55.7v1.55.8
github.com/aws/aws-sdk-go-v2 indirect minor v1.42.1v1.45.1
github.com/aws/aws-sdk-go-v2/config indirect minor v1.32.30v1.33.1 v1.33.2
github.com/aws/aws-sdk-go-v2/credentials indirect minor v1.19.29v1.20.1 v1.20.2
github.com/aws/aws-sdk-go-v2/feature/ec2/imds indirect minor v1.18.30v1.19.1
github.com/aws/aws-sdk-go-v2/internal/configsources indirect minor v1.4.30v1.5.1
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 indirect minor v2.7.30v2.8.1
github.com/aws/aws-sdk-go-v2/internal/v4a indirect minor v1.4.31v1.5.1
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding indirect patch v1.13.13v1.13.19
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url indirect minor v1.13.30v1.14.1
github.com/aws/aws-sdk-go-v2/service/kms indirect minor v1.54.1v1.57.1 v1.58.0
github.com/aws/aws-sdk-go-v2/service/signin indirect minor v1.4.1v1.7.1 v1.8.0
github.com/aws/aws-sdk-go-v2/service/sso indirect minor v1.32.1v1.35.1 v1.36.0
github.com/aws/aws-sdk-go-v2/service/ssooidc indirect minor v1.37.1v1.40.1 v1.41.0
github.com/aws/aws-sdk-go-v2/service/sts indirect minor v1.44.1v1.47.1 v1.48.0
github.com/aws/smithy-go indirect minor v1.27.3v1.28.1
github.com/bmatcuk/doublestar/v4 indirect minor v4.9.1v4.10.0
github.com/cenkalti/backoff/v4 indirect major v4.3.0v7.0.0
github.com/cenkalti/backoff/v5 indirect major v5.0.3v7.0.0
github.com/chainguard-dev/clog indirect patch v1.8.0v1.8.1
github.com/clipperhouse/displaywidth indirect minor v0.10.0v0.11.0
github.com/clipperhouse/uax29/v2 indirect minor v2.6.0v2.7.0
github.com/fatih/color indirect minor v1.18.0v1.19.0
github.com/go-jose/go-jose/v3 indirect major v3.0.5v4.1.4
github.com/go-logr/logr indirect patch v1.4.3v1.4.4
github.com/go-viper/mapstructure/v2 indirect minor v2.4.0v2.5.0
github.com/google/go-containerregistry indirect minor v0.21.5v0.22.0
github.com/googleapis/api-linter/v2 indirect minor v2.0.0v2.3.1
github.com/googleapis/enterprise-certificate-proxy indirect patch v0.3.18v0.3.20
github.com/googleapis/gax-go/v2 indirect minor v2.23.0v2.24.0
github.com/grpc-ecosystem/go-grpc-middleware require major v1.4.0v2.3.4
github.com/grpc-ecosystem/go-grpc-middleware/v2 indirect patch v2.3.3v2.3.4
github.com/grpc-ecosystem/grpc-gateway/v2 indirect minor v2.27.3v2.30.0
github.com/grpc-ecosystem/grpc-gateway/v2 require minor v2.29.0v2.30.0
github.com/hashicorp/hcl indirect major v1.0.1-vault-7v2.24.0
github.com/jellydator/ttlcache/v3 indirect patch v3.4.0v3.4.1
github.com/letsencrypt/boulder indirect minor v0.20260420.0v0.20260825.0
github.com/magiconair/properties require minor v1.8.10v1.18.11
github.com/mattn/go-colorable indirect patch v0.1.14v0.1.15
github.com/mattn/go-isatty indirect patch v0.0.20v0.0.24
github.com/mattn/go-runewidth indirect patch v0.0.23v0.0.28
github.com/olekukonko/errors indirect minor v1.2.0v1.3.0
github.com/olekukonko/ll indirect patch v0.1.6v0.1.8
github.com/pelletier/go-toml/v2 indirect minor v2.2.4v2.4.3
github.com/prometheus/client_golang require minor v1.23.2v1.24.1
github.com/prometheus/common require patch v0.70.0v0.70.1 v0.71.0
github.com/prometheus/procfs indirect minor v0.21.1v0.22.0
github.com/rogpeppe/go-internal indirect minor v1.14.1v1.16.0
github.com/secure-systems-lab/go-securesystemslib indirect patch v0.11.0v0.11.1
github.com/sigstore/protobuf-specs require patch v0.5.1v0.5.2
github.com/sigstore/sigstore require patch v1.10.8v1.10.9
github.com/sigstore/sigstore/pkg/signature/kms/aws require patch v1.10.8v1.10.9
github.com/sigstore/sigstore/pkg/signature/kms/azure require patch v1.10.8v1.10.9
github.com/sigstore/sigstore/pkg/signature/kms/gcp require patch v1.10.8v1.10.9
github.com/sigstore/sigstore/pkg/signature/kms/hashivault require patch v1.10.8v1.10.9
github.com/spiffe/go-spiffe/v2 require minor v2.6.0v2.8.1
github.com/stretchr/testify require minor v1.11.1v1.12.1
github.com/tink-crypto/tink-go-awskms/v2 require major v2.1.0v3.0.0
github.com/tink-crypto/tink-go-gcpkms/v2 require minor v2.2.0v2.4.0
github.com/tink-crypto/tink-go/v2 require minor v2.7.0v2.8.0
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc indirect minor v0.68.0v0.71.0
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp indirect minor v0.68.0v0.71.0
go.opentelemetry.io/otel indirect minor v1.44.0v1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace indirect minor v1.42.0v1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc indirect minor v1.42.0v1.46.0
go.opentelemetry.io/otel/metric indirect minor v1.44.0v1.46.0
go.opentelemetry.io/otel/sdk indirect minor v1.44.0v1.46.0
go.opentelemetry.io/otel/trace indirect minor v1.44.0v1.46.0
go.opentelemetry.io/proto/otlp indirect minor v1.10.0v1.11.0
go.step.sm/crypto require minor v0.85.0v0.89.0
go.yaml.in/yaml/v3 indirect patch v3.0.4v3.0.5
go.yaml.in/yaml/v3 require patch v3.0.4v3.0.5
goa.design/goa/v3 require minor v3.23.4v3.30.0
golang.org/x/crypto indirect minor v0.54.0v0.55.0
golang.org/x/net indirect minor v0.53.0v0.58.0
golang.org/x/net indirect minor v0.57.0v0.58.0
golang.org/x/sync indirect minor v0.20.0v0.22.0
golang.org/x/sys indirect minor v0.43.0v0.47.0
golang.org/x/text indirect minor v0.36.0v0.41.0
golang.org/x/text indirect minor v0.40.0v0.41.0
google.golang.org/api require minor v0.289.0v0.295.0 v0.296.0
google.golang.org/grpc indirect minor v1.80.0v1.83.2
google.golang.org/grpc require minor v1.82.1v1.83.2
google.golang.org/grpc/cmd/protoc-gen-go-grpc indirect patch v1.6.1v1.6.2
google.golang.org/protobuf indirect patch v1.36.11v1.36.12
google.golang.org/protobuf require patch v1.36.11v1.36.12

Release Notes

chainguard-dev/go-grpc-kit (chainguard.dev/go-grpc-kit)

v0.18.0

Compare Source

What's Changed

New Contributors

Full Changelog: chainguard-dev/go-grpc-kit@v0.17.17...v0.18.0

chainguard-dev/sdk (chainguard.dev/sdk)

v0.1.224

Compare Source

  • Add the chainguard.platform.actions.v1alpha2 Actions service, exposing the GitHub Actions dependency graph: SetDependencies, SetHardenedRevision, ListDependents and ListRevisions. Reads are scoped per group; both capabilities are internal only.

v0.1.223

Compare Source

  • Update MockRegistryClient, move MockChartsClient and MockPoliciesClient.
  • Renames PackageLicense to PackageInfo since the name is misleading, this message can carry additional APK identity fields.

v0.1.222

Compare Source

  • Add the SANDBOX service principal for the ACID sandbox Runs control plane

v0.1.221

Compare Source

  • Add ListChartImageBindings batch RPC and ChartImageBinding.image_repo field; ChartImageBinding.chart_repo values are now chainguard-private chart repo UIDPs instead of bare names (wire type unchanged).
  • Add new capability and role for being able to access Athena documentation without having any further capabilities.
  • Add updated_since timestamps to ListOrgVulnsRequest and ArgosDocumentFilter

v0.1.220

Compare Source

  • Add ComponentLocationChanged advisory event to advisory v2 api

v0.1.219

Compare Source

  • Extends FetchPolicyInputResponse and PolicyInput to carry the license of the package(s) in an image.

v0.1.218

Compare Source

  • Update MockRegistryClient

v0.1.217

Compare Source

  • Add artifact_id to policy Override, identifying the waived artifact by image digest or package URL. The digest field is deprecated and now mirrors artifact_id.

v0.1.216

Compare Source

  • Add ListCatalogImages to the v2 registry API for browsing the published Chainguard Images catalog

v0.1.215

Compare Source

  • Add database_specific.chainguard.fixed_artifacts to the Athena OSV record, naming the exact published Chainguard rebuilds that contain a fix and the upstream version each was built from

v0.1.214

Compare Source

  • Add source_types filter to the Libraries v1 Artifacts List and ListVersions APIs

v0.1.213

Compare Source

  • Regenerate protobuf code with Go 1.27.0 (comment formatting only, no functional changes)

v0.1.212

Compare Source

  • Retry the HTTP/1-downgrade STS exchange on 5xx responses, matching the gRPC path

v0.1.211

Compare Source

  • Add libraries.remote_registries.{create,list,delete} capabilities for the upcoming RemoteRegistry resource

v0.1.210

Compare Source

Automated release.

v0.1.209

Compare Source

  • Update chainguard.dev/apko to v1.2.36, chainguard.dev/melange to v0.58.0, github.com/chainguard-dev/terraform-provider-cosign to v0.4.14

v0.1.208

Compare Source

  • iam: mark the OIDC client_secret and the one-time SCIM bearer token (GenerateScimTokenResponse/RegenerateScimTokenResponse) as debug_redact so redaction-aware log formatting omits these credentials.

v0.1.207

Compare Source

  • Expose chainctl errors when fetching token

v0.1.206

Compare Source

  • Add receiver.NewHTTPHandler for serving verified Chainguard webhooks, and return an error instead of panicking when request data is absent

v0.1.205

Compare Source

  • guardener: add Guardener.ListScans and Guardener.GetScan with the guardener.scan.list and guardener.scan.get capabilities (granted to viewers) — list summaries of a group's repository dependency scans (newest per repository) and fetch one scan by id (artifact purls, declaring file paths, and artifact relationships).
  • Add OverlayBindingCreatedEventType and OverlayBindingDeletedEventType CloudEvents constants

v0.1.204

Compare Source

  • Clarify the LibrariesRebuilderSourceResolverCaps capability-bundle documentation

v0.1.203

Compare Source

  • BREAKING (registry v2beta1): Overlay.packages is replaced by Overlay.config, a CustomOverlay message matching Repo.custom_overlay. Send config: {contents: {packages: [...]}}; only config.contents.packages is accepted and any other field fails with InvalidArgument.

v0.1.202

Compare Source

  • Add the libraries v2beta1 RequestGroups service for requesting Chainguard-built library versions and tracking them per library

v0.1.201

Compare Source

  • Add hardened and keywords fields to the Skills catalog Skill (ListSkills/GetSkill/UpdateSkill)

v0.1.200

Compare Source

  • Remove the referenced_by field from the v2beta1 Overlay payload. Find an overlay's attachments via ListOverlayBindings filtered to the overlay.

v0.1.199

Compare Source

  • Update MockEntitlementsClient
  • Add Registry.GetRepoTagsSummary

v0.1.198

Compare Source

  • Add the registry v2beta1 Overlays services for tag-scoped Custom Assembly: create, get, list, and delete reusable packages-only overlays, and attach or detach them to repos under exact-tag selectors via overlay bindings, with paginated lists and CloudEvents on mutations. New capabilities registry.overlays.list and registry.overlays.edit.

v0.1.197

Compare Source

  • Add the dev.chainguard.entitlement.changed.v1 CloudEvent type (public/sdk/events/entitlements)

v0.1.196

Compare Source

  • : Add swap capability to owners

v0.1.195

Compare Source

  • Add the correlation_rule field and CorrelationRule enum to the v1 IdentityProviders OIDC config

v0.1.194

Compare Source

  • Add deduplicate_results to MalwareBlockListFilter to collapse block list entries flagged by multiple advisories

v0.1.193

Compare Source

  • Add ParseChartLockAttestationFromPayload for parsing chart-lock predicates from unwrapped in-toto statements

v0.1.192

Compare Source

  • Add GO and GO_ATHENA Libraries ecosystem enum values and libraries.go.list/create capabilities

v0.1.191

Compare Source

  • Add clients/v2 aggregator for the v2 (GA) API surface.

v0.1.190

Compare Source

  • Add database_specific.patch_status to Athena OSV records where applicable. Patch status currently indicates the status of the reported version's patch, not all potentially affected versions. To see if the version you are interested in has been patched, look at the affected[].ranges[].events[].fixed to see what has been patched, or verify your version doesn't show up in the affected[].versions array.

v0.1.189

Compare Source

  • Add iam v2 (GA) API surface — identical copy of v2beta1 (9 services) served at /iam/v2/ paths; activates ping and events v2 registration.

v0.1.188

Compare Source

  • Add built-in rebuilder IAM roles libraries.rebuilder.source-resolver (source-coordinate write) and libraries.rebuilder.resolve (enqueue-only on-demand resolution).

v0.1.187

Compare Source

  • Add the SkillsHarden API (POST /skills/v1alpha1/harden) for submitting uploaded skill artifacts to be hardened, plus a deterministic harden job-id helper.

v0.1.186

Compare Source

  • Add events v2 (GA) API surface — identical copy of v2beta1 Subscriptions, served at /events/v2/ paths once registered.

v0.1.185

Compare Source

  • Add Entitlements.SwapEntitlementImages: atomically remove and add catalog images on an organization's entitlements in one call, gated on the new registry.entitlements.images.swap capability and charged against the rolling 30-day swap quota.

v0.1.184

Compare Source

  • Add ping v2 (GA) API surface — identical copy of v2beta1, served at /ping/v2/ paths once registered.

v0.1.183

Compare Source

  • Add registry v2 (GA) API surface — identical copy of v2beta1 Repos/Tags/Images served at /registry/v2/ paths.

v0.1.182

Compare Source

  • Add the internal-only libraries.rebuilder.source_coordinates.resolve capability.
  • libraries: corrected stale LibraryPolicyBindings ecosystem doc-strings (JAVA is accepted alongside JAVASCRIPT and PYTHON). Comment-only; no API or behavior change.

v0.1.181

Compare Source

  • Add advisory v2 (GA) API surface — identical copy of v2beta1 served at /advisory/v2/ paths.

v0.1.180

Compare Source

  • Add the internal-only libraries.rebuilder.source_coordinates.write capability.

v0.1.179

Compare Source

Automated release.

v0.1.178

Compare Source

  • Add the correlation_rule field and CorrelationRule enum to the v2beta1 IdentityProviders OIDC config
  • Preserve correlation_rule in v2beta1 IdentityProvider audit-event payloads

v0.1.177

Compare Source

  • Add vulnerabilities v2 (GA) API surface — identical copy of v2beta1 served at /vulnerabilities/v2/ paths.

v0.1.176

Compare Source

  • Create a MICROVM service principal

v0.1.175

Compare Source

  • Add libraries v2 (GA) API surface — identical copy of v2beta1 served at /libraries/v2/ paths.

v0.1.174

Compare Source

  • Update dependencies: google.golang.org/grpc v1.83.0, cloud.google.com/go/longrunning v1.2.0, and golang.org/x/exp.

v0.1.173

Compare Source

  • Update dependencies: apko v1.2.33, go-grpc-kit v0.18.0, aws-sdk-go-v2 v1.43.3, go-oidc/v3 v3.20.0, google.golang.org/api v0.291.0, and k8s.io/apimachinery v0.36.3.
  • Add the skills.harden capability (CAP_SKILLS_HARDEN) gating access to the Skills harden API.

v0.1.172

Compare Source

  • argos OSV records now carry a repeated sink_locator (multiple confirmed sinks per vulnerability) instead of a single sink.

v0.1.171

Compare Source

  • Add ArgosOSVDumperCaps and CAP_ARGOS_OSV_DUMP capability, which are required for the OSV Dump API

v0.1.170

Compare Source

  • libraries: add DOTNET and DOTNET_ATHENA to the Ecosystem enum and the libraries.dotnet.list / libraries.dotnet.create capabilities. Gated off by default per environment; inert until enabled.

v0.1.169

Compare Source

  • WhoAmI capability entries resolve group-mapped roles to one entry per role and carry the raw capabilities.

v0.1.168

Compare Source

  • Annotate Roles.{Create,Update,Delete} RPCs with audit event annotations (audience: CUSTOMER)

v0.1.167

Compare Source

  • Preserve pkce_enabled in v1 and v2beta1 IdentityProvider audit-event payloads

v0.1.166

Compare Source

  • Add skills.{list,write,delete} capabilities (writes internal-only)
  • Skills catalog API: ListSkills takes a UIDP filter (org-agnostic); add UpdateSkill (AIP-134 create-or-update) and DeleteSkill

v0.1.165

Compare Source

  • Refactors octosts credential helpers to use consistent TokenSource setup for all funcs.

v0.1.164

Compare Source

  • Add auth.ExtractAudiences and token.ListAudiences helpers
  • GetEffectiveEntitlements now returns swap_refill_time: when the organization's next catalog-image swap becomes available (set only when no swaps are currently available).

v0.1.163

Compare Source

  • ArgosDocuments: ArgosDocument gains output-only per-file bindings (filename, analysis status, CGP IDs), derived by the platform from the submission archive.

v0.1.162

Compare Source

  • Add the Charts.FindChart RPC and ChartCatalog enum to chainguard.platform.registry.v1 for server-side chart name resolution.

v0.1.161

Compare Source

  • Add the libraries/v1 ResolutionCache service (Zap, SetOptOut, Status, List) and the CAP_LIBRARIES_CACHE_LIST capability for managing the Libraries resolution cache.

v0.1.160

Compare Source

  • chore(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.1

v0.1.159

Compare Source

  • feat(skills): public Skills catalog API — ListSkills/GetSkill (ACID-363) (#​47844)

v0.1.158

Compare Source

  • add image-to-chart lookup to api (#​48009)

v0.1.157

Compare Source

  • docs(iter): fix SDK-3 violation in doc.go integration example [skillup] (#​48063)

v0.1.156

Compare Source

  • oidc: enable public OIDC clients (client id + PKCE) (#​47654)

v0.1.155

Compare Source

  • feat(sdk): add SCIM token lifecycle surface to v1 IdentityProviders (#​47753)

v0.1.154

Compare Source

  • refactor(policies): policies declare a single supported_resource_type (#​47245)

v0.1.153

Compare Source

  • fix(public/sdk/hack): add doc.go and example_test.go [skillup] (#​47670)

v0.1.152

Compare Source

  • fix(iter): use cmp.Or for page size default [skillup] (#​47682)

v0.1.151

Compare Source

  • fix(scim): decouple token lifecycle from provisioning enablement (#​47522)

v0.1.150

Compare Source

  • feat(registry): enforce catalog-image swap quota and expose it in GetEffectiveEntitlements (#​47230)
  • fix(sdk/sts): send HTTP/1 downgrade STS requests form-encoded (#​47475)

v0.1.149

Compare Source

  • feat(private-osv): add OSV-spec withdrawn field (#​47542)

v0.1.148

Compare Source

  • test(capabilities): bit-space hygiene invariants via descriptor reflection (CUS-849) (#​46213)

v0.1.147

Compare Source

  • feat(capabilities): StringifyAllContext, Parse error propagation, Set.String placeholders (CUS-849) (#​46212)

v0.1.146

Compare Source

  • fix(libraries): partial package search on malware blocklist (#​45938)

v0.1.145

Compare Source

  • fix(iam): add description to hidden MCP annotations [skillup] (#​47353)

v0.1.144

Compare Source

  • feat(scim): implement token lifecycle service (#​47071)

v0.1.143

Compare Source

  • fix(sdk/sts): honor HTTP(S)_PROXY in HTTP/1 downgrade exchanger CUS-1012 (#​46170)

v0.1.142

Compare Source

  • test(registry): pin PathMutation uid/gid presence semantics (CON-1931 follow-up) (#​47018)

v0.1.141

Compare Source

  • chore(deps): bump chainguard.dev/apko to v1.2.23 (CON-1931) (#​46716)
  • fix(sdk): add missing example_test.go and doc.go files [skillup] (#​47151)

v0.1.140

Compare Source

  • fix(ping): add mcp description to Ping RPC annotation [skillup] (#​47141)

v0.1.139

Compare Source

  • fix: add missing doc.go and example_test.go files [skillup] (#​47136)

v0.1.138

Compare Source

  • fix(advisory): rename reports field to resolved_vulns_reports [skillup] (#​47040)
  • feat(scim): define token lifecycle API and permissions (#​46676)

v0.1.137

Compare Source

  • feat(advisory): migrate SecurityAdvisory endpoints to v2beta1 (#​45820)

v0.1.136

Compare Source

  • feat(iam): add a guardener service principal (#​46988)

v0.1.135

Compare Source

  • feat(chainctl): add hidden policies validate subcommand (#​45586)

v0.1.134

Compare Source

  • feat(capabilities): mark all rebuilder-api capabilities internal_only

v0.1.133

Compare Source

  • feat(osv-dump)[ARG-201] Add OSV Dump and wire up staging to build the tarball manually (#​45694)

v0.1.132

Compare Source

  • feat(roles): adds custom policies capabilities (#​46535)

v0.1.131

Compare Source

  • feat(registry): add CreateTag, promote DeleteTag to v2beta1, remove v2alpha1 (#​45208)

v0.1.130

Compare Source

  • oidc: Add backend support for custom IDPs to enable PKCE (#​44767)

[v0.1.129](https://redirect.github

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux

red-hat-konflux Bot commented Jul 17, 2026

Copy link
Copy Markdown
Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: go.sum
Command failed: go get -t ./...
go: github.com/ThalesGroup/crypto11@v1.6.8: parsing go.mod:
	module declares its path as: github.com/eclipse-keypont/crypto11
	        but was required as: github.com/ThalesGroup/crypto11

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/release-1.4/go-deps branch 28 times, most recently from c6e64ab to e19642c Compare July 22, 2026 21:56
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/release-1.4/go-deps branch 29 times, most recently from 52d2a9a to 413b79d Compare July 30, 2026 06:12
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants