build(deps): Bump the go group with 11 updates#2092
Open
dependabot[bot] wants to merge 1 commit intomainfrom
Open
build(deps): Bump the go group with 11 updates#2092dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the go group with 11 updates: | Package | From | To | | --- | --- | --- | | [github.com/ProtonMail/go-crypto](https://github.com/ProtonMail/go-crypto) | `1.3.0` | `1.4.0` | | [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.41.1` | `1.41.2` | | [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.32.9` | `1.32.10` | | [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2) | `1.19.9` | `1.19.10` | | [github.com/aws/aws-sdk-go-v2/feature/s3/manager](https://github.com/aws/aws-sdk-go-v2) | `1.22.2` | `1.22.4` | | [github.com/aws/aws-sdk-go-v2/service/kms](https://github.com/aws/aws-sdk-go-v2) | `1.50.0` | `1.50.1` | | [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2) | `1.96.0` | `1.96.2` | | [github.com/aws/aws-sdk-go-v2/service/sts](https://github.com/aws/aws-sdk-go-v2) | `1.41.6` | `1.41.7` | | [golang.org/x/net](https://github.com/golang/net) | `0.50.0` | `0.51.0` | | [google.golang.org/api](https://github.com/googleapis/google-api-go-client) | `0.267.0` | `0.269.0` | | [google.golang.org/genproto/googleapis/rpc](https://github.com/googleapis/go-genproto) | `0.0.0-20260203192932-546029d2fa20` | `0.0.0-20260217215200-42d3e9bedb6d` | Updates `github.com/ProtonMail/go-crypto` from 1.3.0 to 1.4.0 - [Release notes](https://github.com/ProtonMail/go-crypto/releases) - [Commits](ProtonMail/go-crypto@v1.3.0...v1.4.0) Updates `github.com/aws/aws-sdk-go-v2` from 1.41.1 to 1.41.2 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@v1.41.1...v1.41.2) Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.9 to 1.32.10 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@config/v1.32.9...config/v1.32.10) Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.19.9 to 1.19.10 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/m2/v1.19.9...service/iam/v1.19.10) Updates `github.com/aws/aws-sdk-go-v2/feature/s3/manager` from 1.22.2 to 1.22.4 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@v1.22.2...service/mq/v1.22.4) Updates `github.com/aws/aws-sdk-go-v2/service/kms` from 1.50.0 to 1.50.1 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/s3/v1.50.0...service/s3/v1.50.1) Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.96.0 to 1.96.2 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/s3/v1.96.0...service/s3/v1.96.2) Updates `github.com/aws/aws-sdk-go-v2/service/sts` from 1.41.6 to 1.41.7 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/sts/v1.41.6...service/sts/v1.41.7) Updates `golang.org/x/net` from 0.50.0 to 0.51.0 - [Commits](golang/net@v0.50.0...v0.51.0) Updates `google.golang.org/api` from 0.267.0 to 0.269.0 - [Release notes](https://github.com/googleapis/google-api-go-client/releases) - [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md) - [Commits](googleapis/google-api-go-client@v0.267.0...v0.269.0) Updates `google.golang.org/genproto/googleapis/rpc` from 0.0.0-20260203192932-546029d2fa20 to 0.0.0-20260217215200-42d3e9bedb6d - [Commits](https://github.com/googleapis/go-genproto/commits) --- updated-dependencies: - dependency-name: github.com/ProtonMail/go-crypto dependency-version: 1.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go - dependency-name: github.com/aws/aws-sdk-go-v2 dependency-version: 1.41.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go - dependency-name: github.com/aws/aws-sdk-go-v2/config dependency-version: 1.32.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go - dependency-name: github.com/aws/aws-sdk-go-v2/credentials dependency-version: 1.19.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go - dependency-name: github.com/aws/aws-sdk-go-v2/feature/s3/manager dependency-version: 1.22.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go - dependency-name: github.com/aws/aws-sdk-go-v2/service/kms dependency-version: 1.50.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go - dependency-name: github.com/aws/aws-sdk-go-v2/service/s3 dependency-version: 1.96.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go - dependency-name: github.com/aws/aws-sdk-go-v2/service/sts dependency-version: 1.41.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go - dependency-name: golang.org/x/net dependency-version: 0.51.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go - dependency-name: google.golang.org/api dependency-version: 0.269.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go - dependency-name: google.golang.org/genproto/googleapis/rpc dependency-version: 0.0.0-20260217215200-42d3e9bedb6d dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go ... Signed-off-by: dependabot[bot] <support@github.com>
b70b75c to
4364a97
Compare
felixfontein
requested changes
Mar 2, 2026
| module github.com/getsops/sops/v3 | ||
|
|
||
| go 1.24.0 | ||
| go 1.25.0 |
Contributor
There was a problem hiding this comment.
It looks like this update would bump the minimum Go version to 1.25. I don't think that's acceptable as a Dependabot update.
I'm wondering why on earth Dependabot tries to bump the minimum supported Go version. That's really nothing Dependabot should do IMO.
There was a problem hiding this comment.
The "net" package updated the minimum go version, and dependabot is trying to update that package.
golang/net@8109305
Contributor
There was a problem hiding this comment.
Yes, but why does it do that? It could also stick to a version of that package that still works with 1.24.0. IMO this behavior should be configurable at least, but I couldn't find any way to control it.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the go group with 11 updates:
1.3.01.4.01.41.11.41.21.32.91.32.101.19.91.19.101.22.21.22.41.50.01.50.11.96.01.96.21.41.61.41.70.50.00.51.00.267.00.269.00.0.0-20260203192932-546029d2fa200.0.0-20260217215200-42d3e9bedb6dUpdates
github.com/ProtonMail/go-cryptofrom 1.3.0 to 1.4.0Release notes
Sourced from github.com/ProtonMail/go-crypto's releases.
Commits
a8cc4f0Merge pull request #298 from ProtonMail/feat/cleartext-hash-header57f891bMerge branch 'main' into feat/cleartext-hash-headerda5c190Merge pull request #299 from ProtonMail/fix/ecdh-low-order-curve-points3cc59b0Merge branch 'main' into feat/cleartext-hash-headerb11bd23fix(ecdh): Do not allow low order public key pointsb6bdd12Merge pull request #294 from ProtonMail/chore/bump-go-and-circlb1ff3d5Bump crypto dependencies and min go version to 1.23cfb2af9fix(cleartext): Check hashes in headersde87788Add InsecureGenerateNonCriticalSignatureCreationTime option to generate non-c...0906643Add InsecureGenerateNonCriticalKeyFlags option to generate non-critical key f...Updates
github.com/aws/aws-sdk-go-v2from 1.41.1 to 1.41.2Commits
238dde7Release 2026-02-233a957b9Regenerated Clients2972c7dUpdate endpoints modelaa03794Update API model7712be7Feature add new eventstream implementation to support bedrockruntime#InvokeMo...da36a98Release 2026-02-209d7b59cRegenerated Clientse75eb3fUpdate endpoints model2c987cdUpdate API model766b176parameterize generate-dev (#3329)Updates
github.com/aws/aws-sdk-go-v2/configfrom 1.32.9 to 1.32.10Commits
238dde7Release 2026-02-233a957b9Regenerated Clients2972c7dUpdate endpoints modelaa03794Update API model7712be7Feature add new eventstream implementation to support bedrockruntime#InvokeMo...da36a98Release 2026-02-209d7b59cRegenerated Clientse75eb3fUpdate endpoints model2c987cdUpdate API model766b176parameterize generate-dev (#3329)Updates
github.com/aws/aws-sdk-go-v2/credentialsfrom 1.19.9 to 1.19.10Commits
fcc0f5dRelease 2023-04-10cd750e0Regenerated Clients1bc2f05Update endpoints modelb964f5cUpdate API modelfd69015fix APIGW exports nullability exceptionsfae239aMerge pull request #2089 from aws/auditAccessibilityacf33a2Update aws-sdk-go-v2's comment codegened from Smithy Go's updated document sm...27360c1fix APIGW exports nullability exceptions30383d5Release 2023-04-07352f89cRegenerated ClientsUpdates
github.com/aws/aws-sdk-go-v2/feature/s3/managerfrom 1.22.2 to 1.22.4Commits
0fde27cRelease 2024-03-2957e0d95Regenerated Clientse114db5Update SDK's smithy-go dependency to v1.20.2f456f07Update endpoints model96b431aUpdate API model6a694c7dep: upgrade to smithy 1.47.0 (#2587)973665bRelease 2024-03-288b24e40Regenerated Clients8788e04Update endpoints model0480396Update API modelUpdates
github.com/aws/aws-sdk-go-v2/service/kmsfrom 1.50.0 to 1.50.1Commits
7cb105fRelease 2024-02-197f9c4d2Regenerated Clientsa60d4b2Update API modelbe0accdfix: panic due to potentially uncomparable wrapped fn in express_resolve (#2500)Updates
github.com/aws/aws-sdk-go-v2/service/s3from 1.96.0 to 1.96.2Commits
dfcf25bRelease 2026-02-26981d0b4Regenerated Clients60d901eUpdate API model51e7bd8Fix: support arbitrary pre-calculated checksum values on s3 (#3332)2b53e5bRelease 2026-02-25ebfd72dRegenerated Clients87640ceUpdate endpoints modelba64e1bUpdate API modelf3f1e54Release 2026-02-24c4df0e1Regenerated ClientsUpdates
github.com/aws/aws-sdk-go-v2/service/stsfrom 1.41.6 to 1.41.7Commits
238dde7Release 2026-02-233a957b9Regenerated Clients2972c7dUpdate endpoints modelaa03794Update API model7712be7Feature add new eventstream implementation to support bedrockruntime#InvokeMo...da36a98Release 2026-02-209d7b59cRegenerated Clientse75eb3fUpdate endpoints model2c987cdUpdate API model766b176parameterize generate-dev (#3329)Updates
golang.org/x/netfrom 0.50.0 to 0.51.0Commits
60b3f6finternal/http3: prevent Server handler from writing longer body than declaredb0ca456internal/http3: fix Write in Server Handler returning the wrong value1558ba7publicsuffix: update to 2026-02-064e1c745internal/http3: make Server response include headers that can be inferred19f580fhttp2: fix nil panic in typeFrameParser for unassigned frame types818aad7internal/http3: add server to client trailer header supportc1bbe1ainternal/http3: add client to server trailer header support29181b8all: remove go1.25 and older build constraints8109305all: upgrade go directive to at least 1.25.0 [generated]0b37bdfquic: don't run TestStreamsCreateConcurrency in synctest bubbleUpdates
google.golang.org/apifrom 0.267.0 to 0.269.0Release notes
Sourced from google.golang.org/api's releases.
Changelog
Sourced from google.golang.org/api's changelog.
Commits
312ac01chore(main): release 0.268.1 (#3513)7565f1cfeat(all): auto-regenerate discovery clients (#3512)2a249cefix(generator): handle preview version pkg name (#3511)26ea889chore(all): update all (#3498)5b078d9chore(main): release 0.268.0 (#3503)20c1e0ffeat(all): auto-regenerate discovery clients (#3509)20fbcc1feat(all): auto-regenerate discovery clients (#3508)e9015ccfeat(all): auto-regenerate discovery clients (#3507)cc5baecfeat: update to go 1.26 (#3504)cda923afeat(all): auto-regenerate discovery clients (#3506)Updates
google.golang.org/genproto/googleapis/rpcfrom 0.0.0-20260203192932-546029d2fa20 to 0.0.0-20260217215200-42d3e9bedb6dCommits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions