Skip to content

Update go modules (main) (minor) - #3131

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/main-go-modules
Open

Update go modules (main) (minor)#3131
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/main-go-modules

Conversation

@renovate

@renovate renovate Bot commented Feb 27, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Adoption Passing Confidence Type Update Pending
cuelang.org/go v0.16.0v0.17.1 age adoption passing confidence require minor
github.com/CycloneDX/cyclonedx-go v0.10.0v0.12.0 age adoption passing confidence require minor
github.com/cucumber/godog v0.15.0v0.16.0 age adoption passing confidence require minor
github.com/daixiang0/gci v0.13.7v0.14.0 age adoption passing confidence require minor
github.com/go-openapi/runtime v0.32.4v0.33.2 age adoption passing confidence require minor
github.com/go-openapi/strfmt v0.26.4v0.27.2 age adoption passing confidence require minor
github.com/golangci/golangci-lint/v2 v2.11.4v2.13.2 age adoption passing confidence require minor
github.com/google/go-containerregistry v0.21.7v0.22.1 age adoption passing confidence require minor
github.com/konflux-ci/application-api e7eb2ec2999a91 age adoption passing confidence require digest
github.com/open-policy-agent/conftest v0.68.2v0.69.0 age adoption passing confidence require minor
github.com/open-policy-agent/opa v1.15.2v1.20.2 age adoption passing confidence require minor
github.com/pkg/diff 20ebb0f4e6772a age adoption passing confidence require digest
github.com/sigstore/cosign/v3 v3.0.4v3.1.3 age adoption passing confidence require minor
github.com/sigstore/sigstore-go v1.2.2v1.3.0 age adoption passing confidence require minor
github.com/tektoncd/chains v0.26.2v0.29.3 age adoption passing confidence require minor v0.29.4
github.com/tektoncd/cli v0.44.1v0.46.0 age adoption passing confidence require minor
github.com/testcontainers/testcontainers-go v0.34.0v0.44.0 age adoption passing confidence require minor
github.com/testcontainers/testcontainers-go/modules/registry v0.34.0v0.44.0 age adoption passing confidence require minor
github.com/wiremock/go-wiremock v1.11.0v1.16.0 age adoption passing confidence require minor
gocloud.dev v0.43.0v0.46.0 age adoption passing confidence replace minor
gotest.tools/gotestsum v1.12.1v1.13.0 age adoption passing confidence require minor
helm.sh/helm/v3 v3.20.2v3.21.4 age adoption passing confidence require minor v3.22.0
k8s.io/api v0.36.3v0.37.0 age adoption passing confidence require minor
k8s.io/api v0.36.0v0.37.0 age adoption passing confidence require minor
k8s.io/apiextensions-apiserver v0.36.0v0.37.0 age adoption passing confidence require minor
k8s.io/apimachinery v0.36.3v0.37.0 age adoption passing confidence require minor
k8s.io/apimachinery v0.36.0v0.37.0 age adoption passing confidence require minor
k8s.io/client-go v0.36.3v0.37.0 age adoption passing confidence require minor
k8s.io/client-go v0.36.0v0.37.0 age adoption passing confidence require minor
k8s.io/kubernetes v1.34.2v1.37.0 age adoption passing confidence require minor
sigs.k8s.io/kind v0.26.0v0.33.0 age adoption passing confidence require minor
sigs.k8s.io/kustomize/api v0.20.1v0.21.1 age adoption passing confidence require minor
sigs.k8s.io/kustomize/kyaml v0.20.1v0.21.1 age adoption passing confidence require minor

Release Notes

cue-lang/cue (cuelang.org/go)

v0.17.1

Compare Source

Evaluator

Fix several regressions introduced in v0.17.0: a panic when evaluating some disjunctions (#​4419), and spurious invalid interpolation (#​4420), field not allowed (#​4423), and structural cycle (#​4430) errors involving comprehensions or self references.

Fix two regressions introduced in v0.17.0 where evaluation could hang (#​4421, #​4422), as well as two long-standing hangs on self-referencing configurations (#​2766, #​4231).

cmd/cue

Fix a panic in cue exp gengotypes, a regression introduced in v0.17.0, when a definition references a definition from another package via embedding (#​4436).

Module replacements are now subject to minimum-version selection like any other dependency. cue mod tidy now normalizes a fully-pinned replacement to its major version and records the target as a regular dependency.

Full list of changes since v0.17.0
  • internal/cueversion: bump for v0.17.1 by @​mvdan in fc6c0b2
  • internal/ci: bump pinnedReleaseGo for v0.17.1 by @​mvdan in 9c720d0
  • [release-branch.v0.17] internal/core: resolve import instances back to their build instance by @​mvdan in 8ead2d9
  • [release-branch.v0.17] internal/core/adt: allow chained re-instantiation of inline conjunctions by @​mvdan in f81f772
  • [release-branch.v0.17] cue/testdata/cycle: add regression test for spurious inline cycle by @​mvdan in 993c44e
  • [release-branch.v0.17] internal/core/adt: fix hang on let binding a self-referencing struct by @​mvdan in 1cd5e1f
  • [release-branch.v0.17] internal/core/adt: fix hang on self-feeding cycle advancing depth by @​mvdan in ed51952
  • [release-branch.v0.17] internal/core/adt: defer field-set freeze for a running resolver by @​mvdan in e69e621
  • [release-branch.v0.17] internal/core/adt: defer fieldSetKnown for a running field-adding conjunct by @​mvdan in 459016a
  • [release-branch.v0.17] internal/core/adt: do not defer resolvers during comprehension clauses by @​mvdan in f89ebec
  • [release-branch.v0.17] cue/testdata/comprehensions: test guard-driven premature finalization by @​mvdan in 6176fb5
  • [release-branch.v0.17] internal/core/adt,pkg: bound string, bytes, and list repeat counts by @​mvdan in 3017156
  • [release-branch.v0.17] cue/parser: limit expression nesting depth during parsing by @​mvdan in f6f05bb
  • [release-branch.v0.17] internal/encoding/yaml: limit the size of YAML alias expansion by @​mvdan in 04d57ab
  • [release-branch.v0.17] internal/core/adt: treat cyclic under-resolved values as incomplete scalars by @​mvdan in 63994d5
  • [release-branch.v0.17] cue/testdata/references: test a comprehension dynamic field under a let self by @​mvdan in 0ba71ca
  • [release-branch.v0.17] internal/core/adt: do not reclaim disjunct arc states before merging by @​mvdan in b72d5b4
  • [release-branch.v0.17] internal/core/adt: do not discard recomputed let cycle placeholders by @​mvdan in f82d498
  • [release-branch.v0.17] internal/core/adt: fix hang on dynamic field whose key is under evaluation by @​mvdan in e0b974d
  • [release-branch.v0.17] all: re-run tests with CUE_UPDATE=1 by @​mvdan in 7d5a557
  • [release-branch.v0.17] encoding/jsonschema: avoid panic on non-string element in "required" by @​mvdan in f6bc350

v0.17.0

Compare Source

Changes which may break some users are marked below with: ⚠️

Language

The active try experiment renames the new fallback keyword, used with for comprehensions, to otherwise. fallback continues to be accepted for now, but is rewritten to the new form.

The active aliasv2 experiment now allows ~(X) as an alternative to ~X for the single postfix alias form. ~X is also rewritten as ~(X) for the sake of consistency and clarity.

Language versions v0.17.0 and later allow omitting commas in multi-line lists. Just like a newline after a struct field implies a comma, a newline after a list element now implies a comma as well.

Language versions v0.17.0 and later allow a newline or a comma before the closing bracket of an index expression, matching how lists and func arguments allow omitting trailing commas.

The language spec is tweaked to make $ a valid identifier, which was already allowed by the parser and evaluator.

⚠️ Support for the infix div, mod, quo, and rem operators has been removed. Since late 2020, these infix forms have been undocumented and rewritten by cue fix to the new function calls.

The new shortcircuit experiment

This release introduces the shortcircuit experiment, which changes the && and || operators to not evaluate the right operand if the left operand alone determines the result.

This matches the behavior already documented in the CUE spec and is consistent with most mainstream languages, but for the sake of a smooth transition for end users, we are rolling out this change via an experiment.

You can try this experiment via the @experiment(shortcircuit) file attribute. To mimic the old behavior with the experiment, you can use a hidden field:

_y: Y
if X && _y {}

Evaluator

Comprehensions

The comprehension algorithm now waits to run a comprehension's body until the fields it reads have a concrete value, rather than trying to produce its fields up front. This resolves a number of long-standing bugs, most notably the last known regressions from evalv2, where a comprehension that should have resolved instead failed as an incomplete value or a cycle.

This design also greatly simplifies upcoming evaluator work, such as introducing new builtins to replace comparing values to bottom, as well as the design of evalv4.

Other changes

The evaluator no longer deduplicates errors just by position, which was causing some useful errors from disjunctions or standard library calls to be dropped incorrectly.

Several long-standing cycle-detection bugs have been fixed, such as self-referential uses of matchN and matchIf, self-feeding disjunctions, and comprehensions that read a let binding which refers back to the comprehension's own fields.

Fixed a bug where the same package imported via different qualified import paths (e.g. foo.com/bar@v0 or foo.com/bar:baz) did not share the same hidden field namespace.

Resolving an unversioned import from a dependency module now respects that module's own default major version, instead of always using the main module's default.

Fix a number of issues where cue def could produce invalid CUE output, such as due to name conflicts.

Fix an evaluator regression where embedded disjunctions across packages may not correctly apply closedness.

Fix an evaluator bug where cue.Context.BuildExpr of close({}) did not actually result in a closed struct.

Fix a bug where some calls to standard library functions or validators did not include the "error in call to pkg.Func" error context, or included it twice.

A few changes to the evaluator should reduce allocated objects by up to 16%, reducing GC overhead and memory usage.

To ease the transition into the new formatter we plan to release with v0.18, CUE_EXPERIMENT=formatv2=0 is now allowed as a no-op.

A number of other bugs, panics, and hangs have been resolved as well.

cmd/cue

Module replaces

CUE now supports substituting a module dependency with a local directory or a different remote module during development - for example while testing a fix to a dependency before it is published, or to replace a dependency with a fork including improvements.

This configuration lives in cue.mod/local-module.cue, which is excluded when publishing to registries. cue mod edit and cue mod tidy gain support for maintaining this file.

We have also published a how-to guide on replacing a dependency with a local module.

Read the full design doc in the proposal, or read the cue.mod/local-module.cue reference docs.

Other changes

The new global -C or --chdir flag runs cue from the given working directory.

Command input parsing is improved so that CUE packages can come after data files, such as cue vet -c data.yaml ./schema.

cue import --with-context now ensures that data represents the original raw input data, and not its interpretation like JSON Schema.
cue import --path now skips over null values in an input stream, such as empty documents in a YAML file.

Fix a bug where the flag cue export --path was ignored when the inputs were pure CUE.

The new cue exp gengotypes --outfile flag controls the output file path when generating a single package.

cue vet -d/--schema now supports hidden fields, and correctly reports an error when the command inputs are CUE only.

cue fix and cue trim no longer change file modification times when no changes are necessary.

A $CUE_CACHE_DIR directory is no longer required when loading CUE without external dependencies.

The "filetypes" lookup tables now use a more compact encoding, saving about 150KiB in binary size for cmd/cue as well as Go API users.

LSP server

Add an initial version of organize-imports, which sorts the existing imports and removes unneeded imports. It is not yet capable of suggesting missing imports.

Wait for a short period of inactivity before sending diagnostics to the editor. This "debounce" means that a user typing incomplete CUE syntax will not be distracted with syntax errors as much.

The aliasv2 experiment is now fully supported.

The rename function is fixed to distinguish between field names and aliases.

Improve field name analysis in general so that fields with multiple aliases (e.g. v=[k=string]: _) are properly supported.

Improve attribute handling for file-level embedded attributes, and to attach attributes within expressions to the correct struct.

Treat conjunctions (&) and disjunctions (|) the same way for goto-definition. With the cursor on a path, it returns all results that the path MAY resolve to. With the cursor on a field declaration name, it returns all results that the path constructed from the field's name, and its field's name (and so on) MAY resolve to.

Special-case close function calls so that paths can resolve through fields within the argument to close.

Encodings

⚠️ The experimental JSON Schema encoder now emits most definitions without the leading # character, shortening names and ensuring compatibility with the wider JSON Schema ecosystem. This required deprecating encoding/jsonschema.GenerateConfig.NameFunc in favor of NamesFunc.

The JSON Schema encoder is improved to support list.UniqueItems and standalone validators, to use maxItems and minItems instead of maxLength and minLength for lists with prefix elements, and to generate description keywords for doc comments.

Several closedness bugs in the JSON Schema encoder have been fixed, ensuring that the generated JSON Schema behaves the same way as the original CUE definition.

The JSON Schema decoder is improved to better handle the prefixItems keyword.

The ProtoBuf decoder now resolves relative references following the usual scoping rules, instead of always resolving them against the top-level scope.

Standard library

Add time.ToUnix and time.ToUnixNano, which convert an RFC3339Nano time value into seconds or nanoseconds since the Unix epoch, complementing the existing Unix builtin.

strconv.FormatFloat now accepts a string format parameter, like FormatFloat(3.14, "e", 4, 64).

list.MatchN now shows what expected value it's matching against when it fails.

The net IP APIs now consistently return an error on invalid input types.

Go API

Using cue.Values concurrently is now fully supported, which required deprecating cue.Value.Context. If you encounter any races or bugs, please report them via the issue tracker.

cue/load now supports loading from an io/fs.FS, as outlined in proposal #​4285. Loading file embeds through Config.Overlay and Config.FS is supported now as well.

cue/ast/astutil deprecates Sanitize in favor of the new SanitizeFiles API, given that Sanitize on a single file cannot know if another file in the same package shadows builtin names like self.

Add Path.Compare and Selector.Compare, providing allocation-free total ordering suitable for slices.SortFunc.

Clarify that cue/format indents with a tab width of 4 by default.

A new fuzzer has been introduced in the cue package, checking that the parser doesn't crash and that its results are consistent with the rest of the Go APIs like cue/literal. So far, it has already resulted in seventeen bug fixes.

The cue.Interpreter option API has been deprecated in favor of cue.WithInjection, which is a better name going forward.

⚠️ cue/ast.File.Imports, deprecated in mid 2025 in favor of cue/ast.File.ImportSpecs, is now removed.

⚠️ The long-deprecated and hidden cue.Instance methods Lookup, LookupDef, LookupField, and Fill are now removed.

⚠️ The modconfig.Registry interface is changed to report default major versions, which is required for resolving unversioned imports against each dependency module's own defaults. Clients that implement or wrap the interface will need to update. The new interface is future-proofed for upcoming modules changes.

Full list of changes since v0.16.0

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate

renovate Bot commented Feb 27, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: acceptance/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 37 additional dependencies were updated

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=5 days

Details:

Package Change
github.com/sigstore/sigstore v1.10.8 -> v1.10.9
github.com/tektoncd/pipeline v1.12.0 -> v1.14.1
github.com/cockroachdb/apd/v3 v3.2.1 -> v3.2.3
github.com/coreos/go-oidc/v3 v3.19.0 -> v3.20.0
github.com/fatih/color v1.18.0 -> v1.19.0
github.com/fxamacker/cbor/v2 v2.9.0 -> v2.9.1
github.com/go-openapi/analysis v0.25.2 -> v0.25.5
github.com/go-openapi/jsonpointer v0.23.1 -> v1.0.0
github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
github.com/go-openapi/loads v0.24.0 -> v0.25.0
github.com/go-openapi/runtime v0.32.4 -> v0.33.0
github.com/go-openapi/spec v0.22.6 -> v0.22.9
github.com/go-openapi/swag v0.26.1 -> v0.27.1
github.com/go-openapi/swag/cmdutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/conv v0.27.0 -> v0.27.3
github.com/go-openapi/swag/fileutils v0.26.1 -> v0.27.3
github.com/go-openapi/swag/jsonutils v0.26.1 -> v0.27.3
github.com/go-openapi/swag/loading v0.26.1 -> v0.27.3
github.com/go-openapi/swag/mangling v0.26.1 -> v0.27.3
github.com/go-openapi/swag/netutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/stringutils v0.26.1 -> v0.27.3
github.com/go-openapi/swag/typeutils v0.27.0 -> v0.27.3
github.com/go-openapi/swag/yamlutils v0.26.1 -> v0.27.3
github.com/go-openapi/validate v0.26.0 -> v0.26.1
github.com/google/cel-go v0.28.0 -> v0.29.0
github.com/hashicorp/go-memdb v1.3.4 -> v1.3.5
github.com/lufia/plan9stats v0.0.0-20240819163618-b1d8f4d146e7 -> v0.0.0-20260330125221-c963978e514e
github.com/mattn/go-isatty v0.0.20 -> v0.0.21
github.com/moby/patternmatcher v0.6.1 -> v0.6.1
github.com/oklog/ulid/v2 v2.1.1 -> v2.1.2
github.com/rogpeppe/go-internal v1.14.1 -> v1.15.0
github.com/sigstore/timestamp-authority/v2 v2.1.2 -> v2.1.3
github.com/tklauser/go-sysconf v0.3.14 -> v0.4.0
github.com/tklauser/numcpus v0.8.0 -> v0.12.0
k8s.io/kube-openapi v0.0.0-20260319004828-5883c5ee87b9 -> v0.0.0-20260721132016-d427ff9ee9ad
k8s.io/utils v0.0.0-20260319190234-28399d86e0b5 -> v0.0.0-20260626114624-be93311217bd
sigs.k8s.io/structured-merge-diff/v6 v6.3.2 -> v6.4.2
File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 58 additional dependencies were updated

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=5 days

Details:

Package Change
github.com/sirupsen/logrus v1.10.1 -> v1.10.2
k8s.io/kube-openapi v0.0.0-20260319004828-5883c5ee87b9 -> v0.0.0-20260721132016-d427ff9ee9ad
github.com/cockroachdb/apd/v3 v3.2.1 -> v3.2.3
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.0 -> v4.4.1
github.com/dgraph-io/badger/v4 v4.9.1 -> v4.9.6
github.com/fxamacker/cbor/v2 v2.9.0 -> v2.9.1
github.com/go-ole/go-ole v1.2.6 -> v1.3.0
github.com/go-openapi/analysis v0.25.2 -> v1.0.0
github.com/go-openapi/jsonpointer v0.23.1 -> v1.0.0
github.com/go-openapi/jsonreference v0.21.6 -> v1.0.1
github.com/go-openapi/loads v0.24.0 -> v0.25.2
github.com/go-openapi/runtime/server-middleware v0.30.0 -> v0.33.2
github.com/go-openapi/spec v0.22.6 -> v1.0.0
github.com/go-openapi/swag v0.26.1 -> v0.28.0
github.com/go-openapi/swag/cmdutils v0.26.1 -> v0.28.0
github.com/go-openapi/swag/conv v0.27.0 -> v0.29.1
github.com/go-openapi/swag/fileutils v0.26.1 -> v0.29.1
github.com/go-openapi/swag/jsonutils v0.26.1 -> v0.29.1
github.com/go-openapi/swag/loading v0.26.1 -> v0.29.1
github.com/go-openapi/swag/mangling v0.26.1 -> v0.29.1
github.com/go-openapi/swag/netutils v0.26.1 -> v0.28.0
github.com/go-openapi/swag/stringutils v0.26.1 -> v0.29.1
github.com/go-openapi/swag/typeutils v0.27.0 -> v0.29.1
github.com/go-openapi/swag/yamlutils v0.26.1 -> v0.29.1
github.com/go-openapi/validate v0.26.0 -> v1.0.0
github.com/goccy/go-json v0.10.5 -> v0.10.6
github.com/google/cel-go v0.28.0 -> v0.29.2
github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0 -> v2.30.0
github.com/huandu/go-sqlbuilder v1.39.1 -> v1.42.1
github.com/lestrrat-go/dsig v1.0.0 -> v1.3.0
github.com/lestrrat-go/httprc/v3 v3.0.2 -> v3.0.6
github.com/lestrrat-go/jwx/v3 v3.0.13 -> v3.2.0
github.com/lufia/plan9stats v0.0.0-20211012122336-39d0f177ccd0 -> v0.0.0-20260330125221-c963978e514e
github.com/oklog/ulid/v2 v2.1.1 -> v2.1.2
github.com/power-devops/perfstat v0.0.0-20210106213030-5aafc221ea8c -> v0.0.0-20240221224432-82ca36839d55
github.com/protocolbuffers/txtpbfmt v0.0.0-20260217160748-a481f6a22f94 -> v0.0.0-20260420112717-c39628bde8b5
github.com/tklauser/go-sysconf v0.3.12 -> v0.4.0
github.com/tklauser/numcpus v0.6.1 -> v0.12.0
github.com/valyala/fastjson v1.6.7 -> v1.6.10
github.com/vektah/gqlparser/v2 v2.5.32 -> v2.5.36
github.com/yusufpapurcu/wmi v1.2.3 -> v1.2.4
gitlab.com/gitlab-org/api/client-go v1.11.0 -> v1.46.0
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.70.0 -> v0.71.0
go.opentelemetry.io/otel v1.45.0 -> v1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.45.0 -> v1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp v1.45.0 -> v1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.45.0 -> v1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.45.0 -> v1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.45.0 -> v1.46.0
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.42.0 -> v1.45.0
go.opentelemetry.io/otel/metric v1.45.0 -> v1.46.0
go.opentelemetry.io/otel/sdk v1.45.0 -> v1.46.0
go.opentelemetry.io/otel/sdk/metric v1.45.0 -> v1.46.0
go.opentelemetry.io/otel/trace v1.45.0 -> v1.46.0
google.golang.org/genproto/googleapis/api v0.0.0-20260803160001-6ac0973c030d -> v0.0.0-20260819154853-08b0e4226688
google.golang.org/genproto/googleapis/rpc v0.0.0-20260803160001-6ac0973c030d -> v0.0.0-20260819154853-08b0e4226688
k8s.io/utils v0.0.0-20260319190234-28399d86e0b5 -> v0.0.0-20260626114624-be93311217bd
sigs.k8s.io/structured-merge-diff/v6 v6.3.3 -> v6.4.2
File name: tools/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 146 additional dependencies were updated

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=5 days

Details:

Package Change
4d63.com/gocheckcompilerdirectives v1.3.0 -> v1.4.0
cloud.google.com/go/auth v0.20.0 -> v0.21.0
cloud.google.com/go/firestore v1.21.0 -> v1.22.0
cloud.google.com/go/iam v1.11.0 -> v1.13.0
cloud.google.com/go/kms v1.31.0 -> v1.33.0
cloud.google.com/go/longrunning v1.0.0 -> v1.2.0
cloud.google.com/go/monitoring v1.25.0 -> v1.29.0
cloud.google.com/go/storage v1.62.2 -> v1.64.0
cuelang.org/go v0.16.0 -> v0.17.1
dev.gaijin.team/go/golib v0.6.0 -> v0.8.1
github.com/Abirdcfly/dupword v0.1.7 -> v0.1.8
github.com/AlwxSin/noinlineerr v1.0.5 -> v1.0.6
github.com/Antonboom/errname v1.1.1 -> v1.1.2
github.com/Antonboom/nilnil v1.1.1 -> v1.1.2
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.1 -> v1.22.0
github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1 -> v1.14.0
github.com/AzureAD/microsoft-authentication-library-for-go v1.7.0 -> v1.7.2
github.com/CycloneDX/cyclonedx-go v0.10.0 -> v0.11.0
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0 -> v0.57.0
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0 -> v0.57.0
github.com/IBM/sarama v1.45.2 -> v1.47.0
github.com/Masterminds/semver/v3 v3.4.0 -> v3.5.0
github.com/alecthomas/chroma/v2 v2.23.1 -> v2.27.0
github.com/ashanbrown/forbidigo/v2 v2.3.0 -> v2.3.1
github.com/ashanbrown/makezero/v2 v2.1.0 -> v2.2.1
github.com/aws/aws-sdk-go-v2/service/kms v1.52.0 -> v1.55.0
github.com/bombsimon/wsl/v5 v5.6.0 -> v5.9.0
github.com/butuzov/ireturn v0.4.0 -> v0.4.1
github.com/butuzov/mirror v1.3.0 -> v1.3.3
github.com/charmbracelet/colorprofile v0.3.1 -> v0.4.3
github.com/charmbracelet/x/ansi v0.10.1 -> v0.11.8
github.com/charmbracelet/x/term v0.2.1 -> v0.2.2
github.com/clipperhouse/displaywidth v0.10.0 -> v0.11.0
github.com/clipperhouse/uax29/v2 v2.6.0 -> v2.7.0
github.com/cockroachdb/apd/v3 v3.2.1 -> v3.2.3
github.com/coreos/go-oidc/v3 v3.19.0 -> v3.20.0
github.com/cyphar/filepath-securejoin v0.6.1 -> v0.7.0
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.0 -> v4.4.1
github.com/digitorus/pkcs7 v0.0.0-20230818184609-3a137a874352 -> v0.0.0-20250730155240-ffadbf3f398c
github.com/digitorus/timestamp v0.0.0-20231217203849-220c5c2851b7 -> v0.0.0-20250524132541-c45532741eea
github.com/firefart/nonamedreturns v1.0.6 -> v1.0.8
github.com/fxamacker/cbor/v2 v2.9.0 -> v2.9.1
github.com/ghostiam/protogetter v0.3.20 -> v0.3.21
github.com/go-chi/chi/v5 v5.3.0 -> v5.3.1
github.com/go-critic/go-critic v0.14.3 -> v0.14.4
github.com/go-openapi/analysis v0.25.2 -> v0.26.0
github.com/go-openapi/jsonpointer v0.23.1 -> v1.0.0
github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
github.com/go-openapi/loads v0.24.0 -> v0.25.1
github.com/go-openapi/runtime v0.32.4 -> v0.32.5
github.com/go-openapi/spec v0.22.6 -> v0.22.9
github.com/go-openapi/strfmt v0.26.4 -> v0.27.0
github.com/go-openapi/swag v0.26.1 -> v0.27.1
github.com/go-openapi/swag/cmdutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/conv v0.27.0 -> v0.28.0
github.com/go-openapi/swag/fileutils v0.26.1 -> v0.28.0
github.com/go-openapi/swag/jsonutils v0.26.1 -> v0.28.0
github.com/go-openapi/swag/loading v0.26.1 -> v0.28.0
github.com/go-openapi/swag/mangling v0.26.1 -> v0.28.0
github.com/go-openapi/swag/netutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/stringutils v0.26.1 -> v0.28.0
github.com/go-openapi/swag/typeutils v0.27.0 -> v0.28.0
github.com/go-openapi/swag/yamlutils v0.26.1 -> v0.28.0
github.com/go-openapi/validate v0.26.0 -> v0.26.3
github.com/goccy/go-json v0.10.5 -> v0.10.6
github.com/golangci/dupl v0.0.0-20250308024227-f665c8d69b32 -> v0.0.0-20260401084720-c99c5cf5c202
github.com/golangci/gofmt v0.0.0-20250106114630-d62b90e6713d -> v0.0.0-20260820135601-e84e05053792
github.com/google/cel-go v0.28.0 -> v0.29.2
github.com/google/go-containerregistry v0.21.7 -> v0.21.9
github.com/googleapis/enterprise-certificate-proxy v0.3.16 -> v0.3.18
github.com/googleapis/gax-go/v2 v2.22.0 -> v2.23.0
github.com/hashicorp/vault/api v1.22.0 -> v1.23.0
github.com/in-toto/archivista v0.10.0 -> v0.11.1
github.com/in-toto/go-witness v0.9.1 -> v0.12.0
github.com/jellydator/ttlcache/v3 v3.4.0 -> v3.4.1
github.com/jgautheron/goconst v1.8.2 -> v1.11.0
github.com/kisielk/errcheck v1.10.0 -> v1.20.0
github.com/ldez/gomoddirectives v0.8.0 -> v0.9.0
github.com/lestrrat-go/dsig v1.0.0 -> v1.2.1
github.com/lestrrat-go/httprc/v3 v3.0.2 -> v3.0.5
github.com/lestrrat-go/jwx/v3 v3.0.13 -> v3.1.1
github.com/lib/pq v1.11.2 -> v1.12.3
github.com/lucasb-eyer/go-colorful v1.3.0 -> v1.4.1
github.com/manuelarte/funcorder v0.5.0 -> v0.6.0
github.com/mattn/go-colorable v0.1.14 -> v0.1.15
github.com/mattn/go-isatty v0.0.20 -> v0.0.22
github.com/mattn/go-runewidth v0.0.19 -> v0.0.24
github.com/montanaflynn/stats v0.7.1 -> v0.8.2
github.com/nunnatsa/ginkgolinter v0.23.0 -> v0.24.0
github.com/open-policy-agent/opa v1.15.2 -> v1.19.0
github.com/pierrec/lz4/v4 v4.1.22 -> v4.1.26
github.com/protocolbuffers/txtpbfmt v0.0.0-20260217160748-a481f6a22f94 -> v0.0.0-20260420112717-c39628bde8b5
github.com/raeperd/recvcheck v0.2.0 -> v0.3.0
github.com/rogpeppe/go-internal v1.14.1 -> v1.16.0
github.com/sagikazarmark/locafero v0.11.0 -> v0.12.0
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 -> v6.0.3
github.com/secure-systems-lab/go-securesystemslib v0.11.0 -> v0.11.1
github.com/securego/gosec/v2 v2.24.8-0.20260309165252-619ce2117e08 -> v2.28.0
github.com/sigstore/cosign/v2 v2.6.2 -> v2.6.5
github.com/sigstore/protobuf-specs v0.5.1 -> v0.5.2
github.com/sigstore/rekor v1.5.3 -> v1.5.4
github.com/sigstore/sigstore v1.10.8 -> v1.10.9
github.com/sigstore/sigstore/pkg/signature/kms/aws v1.10.8 -> v1.10.9
github.com/sigstore/sigstore/pkg/signature/kms/azure v1.10.8 -> v1.10.9
github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.10.8 -> v1.10.9
github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.10.8 -> v1.10.9
github.com/sourcegraph/go-diff v0.7.0 -> v0.8.0
github.com/spiffe/go-spiffe/v2 v2.7.0 -> v2.8.1
github.com/tektoncd/pipeline v1.12.0 -> v1.15.1
github.com/tektoncd/triggers v0.35.0 -> v0.36.0
github.com/tetafro/godot v1.5.4 -> v1.5.6
github.com/timakin/bodyclose v0.0.0-20241222091800-1db5c5ca4d67 -> v0.0.0-20260129054331-73d1f95b84b4
github.com/uudashr/iface v1.4.1 -> v1.5.1
github.com/valyala/fastjson v1.6.7 -> v1.6.10
github.com/vektah/gqlparser/v2 v2.5.32 -> v2.5.36
github.com/xdg-go/scram v1.1.2 -> v1.2.0
github.com/zclconf/go-cty v1.16.2 -> v1.18.0
go-simpler.org/sloglint v0.11.1 -> v0.12.0
go.augendre.info/fatcontext v0.9.0 -> v0.10.0
go.mongodb.org/mongo-driver v1.17.6 -> v1.17.9
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.43.0 -> v1.44.0
go.step.sm/crypto v0.77.7 -> v0.87.0
goa.design/goa/v3 v3.27.0 -> v3.28.0
gocloud.dev/docstore/mongodocstore v0.43.0 -> v0.46.0
gocloud.dev/pubsub/kafkapubsub v0.43.0 -> v0.46.0
golang.org/x/exp/typeparams v0.0.0-20260209203927-2842357ff358 -> v0.0.0-20260811152304-ee035b5b010f
google.golang.org/api v0.286.0 -> v0.290.0
google.golang.org/genproto v0.0.0-20260406210006-6f92a3bedf2d -> v0.0.0-20260622175928-b703f567277d
honnef.co/go/tools v0.7.0 -> v0.8.1
k8s.io/api v0.36.0 -> v0.36.4
k8s.io/apiextensions-apiserver v0.36.0 -> v0.36.2
k8s.io/apimachinery v0.36.0 -> v0.36.4
k8s.io/apiserver v0.36.0 -> v0.36.2
k8s.io/cli-runtime v0.36.0 -> v0.36.2
k8s.io/client-go v0.36.0 -> v0.36.4
k8s.io/component-base v0.36.0 -> v0.36.2
k8s.io/component-helpers v0.36.0 -> v0.36.2
k8s.io/kube-openapi v0.0.0-20260319004828-5883c5ee87b9 -> v0.0.0-20260721132016-d427ff9ee9ad
k8s.io/kubectl v0.36.0 -> v0.36.2
k8s.io/metrics v0.36.0 -> v0.36.2
k8s.io/streaming v0.36.0 -> v0.36.4
k8s.io/utils v0.0.0-20260319190234-28399d86e0b5 -> v0.0.0-20260626114624-be93311217bd
knative.dev/pkg v0.0.0-20260531000007-52dbd5ece63f -> v0.0.0-20260622140654-39ebae2ee2dc
mvdan.cc/gofumpt v0.9.2 -> v0.11.0
mvdan.cc/unparam v0.0.0-20251027182757-5beb8c8f8f15 -> v0.0.0-20260823230713-2fa3d841b0c8
sigs.k8s.io/structured-merge-diff/v6 v6.3.2 -> v6.4.2
File name: tools/kubectl/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 17 additional dependencies were updated

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=5 days

Details:

Package Change
github.com/fxamacker/cbor/v2 v2.9.0 -> v2.9.1
github.com/go-openapi/jsonpointer v0.23.1 -> v1.0.0
github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
github.com/go-openapi/swag v0.26.1 -> v0.27.1
github.com/go-openapi/swag/cmdutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/conv v0.27.0 -> v0.27.1
github.com/go-openapi/swag/fileutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/jsonutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/loading v0.26.1 -> v0.27.1
github.com/go-openapi/swag/mangling v0.26.1 -> v0.27.1
github.com/go-openapi/swag/netutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/stringutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/typeutils v0.27.0 -> v0.27.1
github.com/go-openapi/swag/yamlutils v0.26.1 -> v0.27.1
k8s.io/kube-openapi v0.0.0-20260319004828-5883c5ee87b9 -> v0.0.0-20260721132016-d427ff9ee9ad
k8s.io/utils v0.0.0-20260319190234-28399d86e0b5 -> v0.0.0-20260626114624-be93311217bd
sigs.k8s.io/structured-merge-diff/v6 v6.3.2 -> v6.4.2

@renovate renovate Bot added the main label Feb 27, 2026
@renovate
renovate Bot force-pushed the renovate/main-go-modules branch 10 times, most recently from b7bbfdc to 02074a5 Compare March 6, 2026 09:52
@renovate
renovate Bot force-pushed the renovate/main-go-modules branch 13 times, most recently from ae12a07 to b6bcb99 Compare March 12, 2026 19:21
@renovate
renovate Bot force-pushed the renovate/main-go-modules branch 2 times, most recently from eb3bd95 to 50d854b Compare March 15, 2026 12:52
fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 17, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 9:03 PM UTC · Completed 9:14 PM UTC

Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 18, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:38 AM UTC · Completed 1:49 AM UTC

Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 18, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 4:07 PM UTC · Completed 4:14 PM UTC

Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 18, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 6:28 PM UTC · Completed 6:37 PM UTC

Commit: 87c4a29 · View workflow run →

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 18, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 9:37 PM UTC · Completed 9:47 PM UTC

Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 19, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 7:56 AM UTC · Completed 8:06 AM UTC

Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 19, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 8:46 AM UTC · Completed 8:55 AM UTC

Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 19, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 2:08 PM UTC · Completed 2:15 PM UTC

Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 19, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 10:01 PM UTC · Completed 10:12 PM UTC

Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 20, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:10 AM UTC · Completed 1:23 AM UTC

Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 20, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 10:59 AM UTC · Completed 11:11 AM UTC

Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 20, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:14 PM UTC · Completed 1:23 PM UTC

Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 20, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 7:27 PM UTC · Completed 7:35 PM UTC

Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@coderabbitai

coderabbitai Bot commented Sep 10, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: fedea48a-31d8-4aa9-b79c-1a281ffd759a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 10, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:47 PM UTC · Completed 1:56 PM UTC

Commit: cd01138 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $4.48

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code main ready-for-merge All reviewers approved — ready to merge renovate Review effort 1/5 size: XXL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants