chore(deps): bump the all group with 14 updates#1728
Merged
tekton-robot merged 1 commit intoJun 24, 2026
Merged
Conversation
Bumps the all group with 14 updates: | Package | From | To | | --- | --- | --- | | [cloud.google.com/go/storage](https://github.com/googleapis/google-cloud-go) | `1.57.1` | `1.57.2` | | [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry) | `0.20.7` | `0.20.8` | | [github.com/in-toto/go-witness](https://github.com/in-toto/go-witness) | `0.9.1` | `0.9.2` | | [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) | `2.6.2` | `2.6.3` | | [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) | `1.10.5` | `1.10.8` | | [github.com/sigstore/sigstore/pkg/signature/kms/aws](https://github.com/sigstore/sigstore) | `1.10.5` | `1.10.8` | | [github.com/sigstore/sigstore/pkg/signature/kms/azure](https://github.com/sigstore/sigstore) | `1.10.5` | `1.10.8` | | [github.com/sigstore/sigstore/pkg/signature/kms/gcp](https://github.com/sigstore/sigstore) | `1.10.5` | `1.10.8` | | [github.com/sigstore/sigstore/pkg/signature/kms/hashivault](https://github.com/sigstore/sigstore) | `1.10.5` | `1.10.8` | | [github.com/tektoncd/pipeline](https://github.com/tektoncd/pipeline) | `1.9.3` | `1.9.4` | | [k8s.io/api](https://github.com/kubernetes/api) | `0.34.1` | `0.34.9` | | [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) | `0.34.1` | `0.34.9` | | [k8s.io/client-go](https://github.com/kubernetes/client-go) | `0.34.1` | `0.34.9` | | [k8s.io/code-generator](https://github.com/kubernetes/code-generator) | `0.33.4` | `0.33.13` | Updates `cloud.google.com/go/storage` from 1.57.1 to 1.57.2 - [Release notes](https://github.com/googleapis/google-cloud-go/releases) - [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/CHANGES.md) - [Commits](googleapis/google-cloud-go@storage/v1.57.1...storage/v1.57.2) Updates `github.com/google/go-containerregistry` from 0.20.7 to 0.20.8 - [Release notes](https://github.com/google/go-containerregistry/releases) - [Commits](google/go-containerregistry@v0.20.7...v0.20.8) Updates `github.com/in-toto/go-witness` from 0.9.1 to 0.9.2 - [Release notes](https://github.com/in-toto/go-witness/releases) - [Commits](in-toto/go-witness@v0.9.1...v0.9.2) Updates `github.com/sigstore/cosign/v2` from 2.6.2 to 2.6.3 - [Release notes](https://github.com/sigstore/cosign/releases) - [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md) - [Commits](sigstore/cosign@v2.6.2...v2.6.3) Updates `github.com/sigstore/sigstore` from 1.10.5 to 1.10.8 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.5...v1.10.8) Updates `github.com/sigstore/sigstore/pkg/signature/kms/aws` from 1.10.5 to 1.10.8 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.5...v1.10.8) Updates `github.com/sigstore/sigstore/pkg/signature/kms/azure` from 1.10.5 to 1.10.8 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.5...v1.10.8) Updates `github.com/sigstore/sigstore/pkg/signature/kms/gcp` from 1.10.5 to 1.10.8 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.5...v1.10.8) Updates `github.com/sigstore/sigstore/pkg/signature/kms/hashivault` from 1.10.5 to 1.10.8 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.5...v1.10.8) Updates `github.com/tektoncd/pipeline` from 1.9.3 to 1.9.4 - [Release notes](https://github.com/tektoncd/pipeline/releases) - [Changelog](https://github.com/tektoncd/pipeline/blob/main/releases.md) - [Commits](tektoncd/pipeline@v1.9.3...v1.9.4) Updates `k8s.io/api` from 0.34.1 to 0.34.9 - [Commits](kubernetes/api@v0.34.1...v0.34.9) Updates `k8s.io/apimachinery` from 0.34.1 to 0.34.9 - [Commits](kubernetes/apimachinery@v0.34.1...v0.34.9) Updates `k8s.io/client-go` from 0.34.1 to 0.34.9 - [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md) - [Commits](kubernetes/client-go@v0.34.1...v0.34.9) Updates `k8s.io/code-generator` from 0.33.4 to 0.33.13 - [Commits](kubernetes/code-generator@v0.33.4...v0.33.13) --- updated-dependencies: - dependency-name: cloud.google.com/go/storage dependency-version: 1.57.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/google/go-containerregistry dependency-version: 0.20.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/in-toto/go-witness dependency-version: 0.9.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/sigstore/cosign/v2 dependency-version: 2.6.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/sigstore/sigstore dependency-version: 1.10.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/aws dependency-version: 1.10.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/azure dependency-version: 1.10.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/gcp dependency-version: 1.10.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/hashivault dependency-version: 1.10.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/tektoncd/pipeline dependency-version: 1.9.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: k8s.io/api dependency-version: 0.34.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: k8s.io/apimachinery dependency-version: 0.34.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: k8s.io/client-go dependency-version: 0.34.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: k8s.io/code-generator dependency-version: 0.33.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
|
/lgtm |
Contributor
|
/approve |
1 similar comment
Member
|
/approve |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: anithapriyanatarajan, jkhelil The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the all group with 14 updates:
1.57.11.57.20.20.70.20.80.9.10.9.22.6.22.6.31.10.51.10.81.10.51.10.81.10.51.10.81.10.51.10.81.10.51.10.81.9.31.9.40.34.10.34.90.34.10.34.90.34.10.34.90.33.40.33.13Updates
cloud.google.com/go/storagefrom 1.57.1 to 1.57.2Commits
54f5f63chore: librarian release pull request: 20251114T145800Z (#13361)315f65bfix(spanner): decoding spanner rows using SelectAll should map values in corr...d1224e8test(spanner): additional tests for SelectAll() (#13360)b9196cffeat: Add grpc.xds.resource_type label to xDS client metrics (#13358)b0f1362fix(storage): Handle redirect on takeover. (#13354)5574f5bchore: librarian update image pull request: 20251113T211851Z (#13355)3fef58bchore(internal/librariangen): bump gapic-generator-go to 0.55.1 (#13352)e978a68chore: update the go version in renovate.json (#13348)29b6c97chore: librarian update image pull request: 20251112T170525Z (#13346)1f4da37chore(internal/librariangen): bump gapic-generator-go to 0.55.0 (#13345)Updates
github.com/google/go-containerregistryfrom 0.20.7 to 0.20.8Commits
b58334fDisable taint gosec lints (#2215)88b39edBump the go-deps group across 3 directories with 3 updates (#2213)102ac75join go.mod dependency updates (#2212)d5817d5Bump go version across packages to 1.25.6 (#2211)23f0632Fix error messages in crane_test.go (#2189)438abdeBump the root-deps group across 1 directory with 7 updates (#2195)b6eadd8Bump the actions group across 1 directory with 4 updates (#2207)93aa273Improve performance of v1.NewHash (#2194)795787cmutate: don't skip dir replacements via whiteout in export (#2191)Updates
github.com/in-toto/go-witnessfrom 0.9.1 to 0.9.2Release notes
Sourced from github.com/in-toto/go-witness's releases.
Commits
1b6dcd7chore: bump github.com/aws/aws-sdk-go-v2/config from 1.31.20 to 1.31.21 (#638)e03e418chore: bump github.com/aws/aws-sdk-go-v2/service/kms from 1.48.2 to 1.48.3 (#...b27326cchore: bump github/codeql-action from 4.31.9 to 4.31.10 (#635)d999c86chore: bump github.com/aws/aws-sdk-go-v2/feature/ec2/imds from 1.18.13 to 1.1...df5f3b3chore: bump github.com/sigstore/sigstore from 1.10.0 to 1.10.3 (#633)220bcf5fix: handle cosign encrypted keys with empty passphrase (#632)ea9777bchore: bump github.com/sigstore/fulcio from 1.6.6 to 1.8.3 in the go_modules ...ea8e8b7chore: bump github.com/spdx/tools-golang from 0.5.5 to 0.5.6 (#630)a21b507chore: bump github/codeql-action from 4.31.8 to 4.31.9 (#626)19c07c1feat: support Sigstore encrypted PEM keys (#614)Updates
github.com/sigstore/cosign/v2from 2.6.2 to 2.6.3Release notes
Sourced from github.com/sigstore/cosign/v2's releases.
Changelog
Sourced from github.com/sigstore/cosign/v2's changelog.
Commits
fecddd3Fix DSSE predicate check (#4802)564c5b1Backport bundle detection to sign and attest (#4727)Updates
github.com/sigstore/sigstorefrom 1.10.5 to 1.10.8Release notes
Sourced from github.com/sigstore/sigstore's releases.
Commits
c761681Support standard PKCS#8 encrypted private key decryption (#2333)005faf9Extend PEM private key unmarshalling to support legacy format (#2332)e70e4edadd functional options to DSSE to improve memory usage, validation (#2326)899684dbuild(deps): Bump github.com/letsencrypt/boulder (#2307)181dc40build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2308)2c141a7build(deps): Bump golangci/golangci-lint-action in the all group (#2328)b6c0214build(deps): Bump actions/upload-artifact from 6.0.0 to 7.0.1 (#2329)2ff50c9build(deps): Bump actions/dependency-review-action from 4.8.3 to 5.0.0 (#2330)d0204c3build(deps): Bump hashicorp/vault from 1.21.4 to 2.0.1 in /test/e2e (#2331)afdf897build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp (#2312)Updates
github.com/sigstore/sigstore/pkg/signature/kms/awsfrom 1.10.5 to 1.10.8Release notes
Sourced from github.com/sigstore/sigstore/pkg/signature/kms/aws's releases.
Commits
c761681Support standard PKCS#8 encrypted private key decryption (#2333)005faf9Extend PEM private key unmarshalling to support legacy format (#2332)e70e4edadd functional options to DSSE to improve memory usage, validation (#2326)899684dbuild(deps): Bump github.com/letsencrypt/boulder (#2307)181dc40build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2308)2c141a7build(deps): Bump golangci/golangci-lint-action in the all group (#2328)b6c0214build(deps): Bump actions/upload-artifact from 6.0.0 to 7.0.1 (#2329)2ff50c9build(deps): Bump actions/dependency-review-action from 4.8.3 to 5.0.0 (#2330)d0204c3build(deps): Bump hashicorp/vault from 1.21.4 to 2.0.1 in /test/e2e (#2331)afdf897build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp (#2312)Updates
github.com/sigstore/sigstore/pkg/signature/kms/azurefrom 1.10.5 to 1.10.8Release notes
Sourced from github.com/sigstore/sigstore/pkg/signature/kms/azure's releases.
Commits
c761681Support standard PKCS#8 encrypted private key decryption (#2333)005faf9Extend PEM private key unmarshalling to support legacy format (#2332)e70e4edadd functional options to DSSE to improve memory usage, validation (#2326)899684dbuild(deps): Bump github.com/letsencrypt/boulder (#2307)181dc40build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2308)2c141a7build(deps): Bump golangci/golangci-lint-action in the all group (#2328)b6c0214build(deps): Bump actions/upload-artifact from 6.0.0 to 7.0.1 (#2329)2ff50c9build(deps): Bump actions/dependency-review-action from 4.8.3 to 5.0.0 (#2330)d0204c3build(deps): Bump hashicorp/vault from 1.21.4 to 2.0.1 in /test/e2e (#2331)afdf897build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp (#2312)Updates
github.com/sigstore/sigstore/pkg/signature/kms/gcpfrom 1.10.5 to 1.10.8Release notes
Sourced from github.com/sigstore/sigstore/pkg/signature/kms/gcp's releases.
Commits
c761681Support standard PKCS#8 encrypted private key decryption (#2333)005faf9Extend PEM private key unmarshalling to support legacy format (#2332)e70e4edadd functional options to DSSE to improve memory usage, validation (#2326)899684dbuild(deps): Bump github.com/letsencrypt/boulder (#2307)181dc40build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2308)2c141a7build(deps): Bump golangci/golangci-lint-action in the all group (#2328)b6c0214build(deps): Bump actions/upload-artifact from 6.0.0 to 7.0.1 (#2329)2ff50c9build(deps): Bump actions/dependency-review-action from 4.8.3 to 5.0.0 (#2330)d0204c3build(deps): Bump hashicorp/vault from 1.21.4 to 2.0.1 in /test/e2e (#2331)afdf897build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp (#2312)Updates
github.com/sigstore/sigstore/pkg/signature/kms/hashivaultfrom 1.10.5 to 1.10.8Release notes
Sourced from github.com/sigstore/sigstore/pkg/signature/kms/hashivault's releases.
Commits
c761681Support standard PKCS#8 encrypted private key decryption (#2333)005faf9Extend PEM private key unmarshalling to support legacy format (#2332)e70e4edadd functional options to DSSE to improve memory usage, validation (#2326)899684dbuild(deps): Bump github.com/letsencrypt/boulder (#2307)181dc40build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2308)2c141a7build(deps): Bump golangci/golangci-lint-action in the all group (#2328)b6c0214build(deps): Bump actions/upload-artifact from 6.0.0 to 7.0.1 (#2329)2ff50c9build(deps): Bump actions/dependency-review-action from 4.8.3 to 5.0.0 (#2330)d0204c3build(deps): Bump hashicorp/vault from 1.21.4 to 2.0.1 in /test/e2e (#2331)afdf897build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp (#2312)Updates
github.com/tektoncd/pipelinefrom 1.9.3 to 1.9.4Release notes
Sourced from github.com/tektoncd/pipeline's releases.
... (truncated)
Commits
52d677fbuild(deps): bump the all group in /tekton with 4 updates1eb2fe3fix(resolvers): Allow ResolutionRequests to resolve all Tekton kindsb6b85c5build(deps): bump the all group in /tekton with 4 updates7237155build(deps): bump the all group across 1 directory with 4 updates9937571fix: add automated draft release support to release pipeline7666a7dbuild(deps): bump actions/checkout from 6.0.2 to 6.0.3474b1c7fix: prevent controller CPU variant from leaking into platform commandsdaf477cbuild(deps): bump github.com/spiffe/spire-api-sdk from 1.14.6 to 1.14.78528597fix(pipelinerun): use generateName for anonymous pipeline labeld343c6abuild(deps): bump the all group in /tekton with 4 updatesUpdates
k8s.io/apifrom 0.34.1 to 0.34.9Commits
65439aeUpdate dependencies to v0.34.9 tagad42a1fMerge pull request #138357 from dims/update-moby-spdystream-v0.5.1-1.34f7287d9Merge pull request #138349 from dashpole/update_prop_3439fcc47Update github.com/moby/spdystream from v0.5.0 to v0.5.1dfcdfcdupdate go.opentelemetry.io/otel to v1.41.0Updates
k8s.io/apimachineryfrom 0.34.1 to 0.34.9Commits
454f531Merge pull request #138357 from dims/update-moby-spdystream-v0.5.1-1.34e44e450Merge pull request #138349 from dashpole/update_prop_34e2c5a26Update github.com/moby/spdystream from v0.5.0 to v0.5.103b02abupdate go.opentelemetry.io/otel to v1.41.0Updates
k8s.io/client-gofrom 0.34.1 to 0.34.9Commits
1976477Update dependencies to v0.34.9 tage4156f3Merge pull request #138357 from dims/update-moby-spdystream-v0.5.1-1.34e7de3f2Merge pull request #138349 from dashpole/update_prop_3432b5239Update github.com/moby/spdystream from v0.5.0 to v0.5.13f8d3efupdate go.opentelemetry.io/otel to v1.41.03a88ce1Merge pull request #135716p0lyn0mial/automated-cherry-pick-of-#135591c80976cdowngrade reflector watchlist fallback log to V(4)ab04e77Merge pull request #135592serathius/automated-cherry-pick-of-#13558025da701Use transformer in consistency checker0c76ee5Add unit tests for Data Consistency DetectorUpdates
k8s.io/code-generatorfrom 0.33.4 to 0.33.13Commits
5288b09Update dependencies to v0.33.13 tag32553f2Merge pull request #138358 from dims/update-moby-spdystream-v0.5.1-1.33c78d0c2Merge pull request #138350 from dashpole/update_prop_33e3e80d4Update github.com/moby/spdystream from v0.5.0 to v0.5.18431104update go.opentelemetry.io/otel to v1.41.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions