Skip to content

chore: bump the go-minor-patch group across 1 directory with 3 updates#11

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-minor-patch-e545ac659e
Open

chore: bump the go-minor-patch group across 1 directory with 3 updates#11
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-minor-patch-e545ac659e

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github May 22, 2026

Bumps the go-minor-patch group with 3 updates in the / directory: github.com/gechr/clib, github.com/gechr/clog and github.com/slack-go/slack.

Updates github.com/gechr/clib from 0.4.4 to 0.4.6

Commits
  • 055517f help/cobra: Don't extract backticked flag refs as placeholders
  • a39e938 cobra/urfave: lowercase placeholders by default
  • See full diff in compare view

Updates github.com/gechr/clog from 0.9.3 to 0.9.8

Release notes

Sourced from github.com/gechr/clog's releases.

v0.9.8

Changes

  • 7c63b76 group: Preserve ready task errors

v0.9.7

Changes

  • b40635f group: Cap aligned bars to terminal width

v0.9.6

Changes

  • 433bb0a group: Suppress bottom viewport frames

v0.9.5

Changes

  • b706db1 group: Add transient status controls

v0.9.4

Changes

  • 68cf9eb group: Fix wrapped repaint rows
  • 72ffd48 build(deps): bump github.com/pelletier/go-toml/v2 from 2.3.0 to 2.3.1 in the go-modules group (#7)
  • 54ea31c build(deps): bump zizmorcore/zizmor-action from 0.5.2 to 0.5.3 in the github-actions group (#6)
Commits
  • 7c63b76 group: Preserve ready task errors
  • b40635f group: Cap aligned bars to terminal width
  • 433bb0a group: Suppress bottom viewport frames
  • b706db1 group: Add transient status controls
  • 68cf9eb group: Fix wrapped repaint rows
  • 72ffd48 build(deps): bump github.com/pelletier/go-toml/v2 from 2.3.0 to 2.3.1 in the ...
  • 54ea31c build(deps): bump zizmorcore/zizmor-action from 0.5.2 to 0.5.3 in the github-...
  • See full diff in compare view

Updates github.com/slack-go/slack from 0.23.0 to 0.23.1

Release notes

Sourced from github.com/slack-go/slack's releases.

v0.23.1

[!IMPORTANT] Even though this is a [security] patch release, if you were using an empty secret, this is a breaking change due to a change in behaviour. That's on purpose, to ensure you fix your approach so that there are no footguns.

Fixed

  • NewSecretsVerifier now rejects empty signing secrets to avoid accepting forged request signatures when applications are misconfigured.

Full Changelog: slack-go/slack@v0.23.0...v0.23.1

Changelog

Sourced from github.com/slack-go/slack's changelog.

[0.23.1] - 2026-05-10

Fixed

  • NewSecretsVerifier now rejects empty signing secrets to avoid accepting forged request signatures when applications are misconfigured.
Commits
  • 34ad5c0 security: reject empty signing secret for NewSecretsVerifier
  • c6edc27 chore: bump go to 1.25.9
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-minor-patch group with 3 updates in the / directory: [github.com/gechr/clib](https://github.com/gechr/clib), [github.com/gechr/clog](https://github.com/gechr/clog) and [github.com/slack-go/slack](https://github.com/slack-go/slack).


Updates `github.com/gechr/clib` from 0.4.4 to 0.4.6
- [Commits](gechr/clib@v0.4.4...v0.4.6)

Updates `github.com/gechr/clog` from 0.9.3 to 0.9.8
- [Release notes](https://github.com/gechr/clog/releases)
- [Commits](gechr/clog@v0.9.3...v0.9.8)

Updates `github.com/slack-go/slack` from 0.23.0 to 0.23.1
- [Release notes](https://github.com/slack-go/slack/releases)
- [Changelog](https://github.com/slack-go/slack/blob/master/CHANGELOG.md)
- [Commits](slack-go/slack@v0.23.0...v0.23.1)

---
updated-dependencies:
- dependency-name: github.com/gechr/clib
  dependency-version: 0.4.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-patch
- dependency-name: github.com/gechr/clog
  dependency-version: 0.9.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-patch
- dependency-name: github.com/slack-go/slack
  dependency-version: 0.23.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency label May 22, 2026
@dependabot dependabot Bot requested a review from matcra587 as a code owner May 22, 2026 14:17
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency label May 22, 2026
@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgithub.com/​slack-go/​slack@​v0.23.0 ⏵ v0.23.173 +1100 +2100100100
Updatedgithub.com/​gechr/​clog@​v0.9.3 ⏵ v0.9.899 +1100100100100
Updatedgithub.com/​gechr/​clib@​v0.4.4 ⏵ v0.4.6100 +1100100100100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants