build(deps): bump the go_modules group across 3 directories with 10 updates#17
Open
dependabot[bot] wants to merge 1 commit intomasterfrom
Open
build(deps): bump the go_modules group across 3 directories with 10 updates#17dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
…pdates Bumps the go_modules group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github.com/coredns/coredns](https://github.com/coredns/coredns) | `1.11.1` | `1.14.0` | | [github.com/eclipse/paho.mqtt.golang](https://github.com/eclipse/paho.mqtt.golang) | `1.4.3` | `1.5.1` | | [github.com/nats-io/nats-server/v2](https://github.com/nats-io/nats-server) | `2.9.23` | `2.11.12` | | [github.com/rs/cors](https://github.com/rs/cors) | `1.10.1` | `1.11.0` | | [github.com/lestrrat-go/jwx](https://github.com/lestrrat-go/jwx) | `1.2.26` | `1.2.29` | Bumps the go_modules group with 1 update in the /docs/debugging/inspect directory: [golang.org/x/crypto](https://github.com/golang/crypto). Bumps the go_modules group with 1 update in the /docs/debugging/s3-verify directory: [golang.org/x/crypto](https://github.com/golang/crypto). Updates `github.com/coredns/coredns` from 1.11.1 to 1.14.0 - [Release notes](https://github.com/coredns/coredns/releases) - [Commits](coredns/coredns@v1.11.1...v1.14.0) Updates `github.com/eclipse/paho.mqtt.golang` from 1.4.3 to 1.5.1 - [Release notes](https://github.com/eclipse/paho.mqtt.golang/releases) - [Commits](eclipse-paho/paho.mqtt.golang@v1.4.3...v1.5.1) Updates `github.com/golang-jwt/jwt/v4` from 4.5.0 to 4.5.2 - [Release notes](https://github.com/golang-jwt/jwt/releases) - [Commits](golang-jwt/jwt@v4.5.0...v4.5.2) Updates `github.com/nats-io/nats-server/v2` from 2.9.23 to 2.11.12 - [Release notes](https://github.com/nats-io/nats-server/releases) - [Changelog](https://github.com/nats-io/nats-server/blob/main/RELEASES.md) - [Commits](nats-io/nats-server@v2.9.23...v2.11.12) Updates `github.com/rs/cors` from 1.10.1 to 1.11.0 - [Commits](rs/cors@v1.10.1...v1.11.0) Updates `golang.org/x/crypto` from 0.14.0 to 0.47.0 - [Commits](golang/crypto@v0.6.0...v0.45.0) Updates `golang.org/x/oauth2` from 0.13.0 to 0.34.0 - [Commits](golang/oauth2@v0.13.0...v0.34.0) Updates `github.com/lestrrat-go/jwx` from 1.2.26 to 1.2.29 - [Release notes](https://github.com/lestrrat-go/jwx/releases) - [Changelog](https://github.com/lestrrat-go/jwx/blob/v1.2.29/Changes) - [Commits](lestrrat-go/jwx@v1.2.26...v1.2.29) Updates `golang.org/x/net` from 0.17.0 to 0.48.0 - [Commits](golang/net@v0.17.0...v0.48.0) Updates `google.golang.org/protobuf` from 1.31.0 to 1.36.11 Updates `golang.org/x/crypto` from 0.6.0 to 0.45.0 - [Commits](golang/crypto@v0.6.0...v0.45.0) Updates `golang.org/x/crypto` from 0.14.0 to 0.45.0 - [Commits](golang/crypto@v0.6.0...v0.45.0) Updates `golang.org/x/net` from 0.17.0 to 0.47.0 - [Commits](golang/net@v0.17.0...v0.48.0) --- updated-dependencies: - dependency-name: github.com/coredns/coredns dependency-version: 1.14.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/eclipse/paho.mqtt.golang dependency-version: 1.5.1 dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/golang-jwt/jwt/v4 dependency-version: 4.5.2 dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/nats-io/nats-server/v2 dependency-version: 2.11.12 dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/rs/cors dependency-version: 1.11.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/crypto dependency-version: 0.47.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/oauth2 dependency-version: 0.34.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/lestrrat-go/jwx dependency-version: 1.2.29 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.48.0 dependency-type: indirect dependency-group: go_modules - dependency-name: google.golang.org/protobuf dependency-version: 1.36.11 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/crypto dependency-version: 0.45.0 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/crypto dependency-version: 0.45.0 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.47.0 dependency-type: indirect dependency-group: go_modules ... Signed-off-by: dependabot[bot] <[email protected]>
This was referenced Feb 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the go_modules group with 5 updates in the / directory:
1.11.11.14.01.4.31.5.12.9.232.11.121.10.11.11.01.2.261.2.29Bumps the go_modules group with 1 update in the /docs/debugging/inspect directory: golang.org/x/crypto.
Bumps the go_modules group with 1 update in the /docs/debugging/s3-verify directory: golang.org/x/crypto.
Updates
github.com/coredns/corednsfrom 1.11.1 to 1.14.0Release notes
Sourced from github.com/coredns/coredns's releases.
... (truncated)
Commits
1c964f2Bump version to 1.14.0 (#7803)b723bd9fix(plugins): add regex length limit (#7802)adba778Refactor: Update the cache getter function (#7800)6dca5b2fix(lint): address G114 gosec findings in ready, pprof, and health plugins (#...7b38eb8plugin: fix gosec G115 integer overflow warnings (#7799)be934b2perf(metrics): implement plugin chain tracking (#7791)b21c752chore(lint): enable gosec (#7792)1e0095dbuild(deps): bump github.com/oschwald/geoip2-golang/v2 (#7797)748f494build(deps): bump google.golang.org/grpc from 1.77.0 to 1.78.0 (#7796)376c712chore(ci): bump golangci-lint to v2.7.2 (#7783)Updates
github.com/eclipse/paho.mqtt.golangfrom 1.4.3 to 1.5.1Release notes
Sourced from github.com/eclipse/paho.mqtt.golang's releases.
Commits
b305237Update dependencies in docker examples35ee03dPotential panic when using manual ACK433bd22address data race in test4debe3aPotential panic when using manual ACK601453bResolve issues in fvt_client_test439e2abDependency update (also rise Go version to 1.24)d276593ConnectionNotificationHandler - generic callback for all types of connection ...8a350a9notifications5620c5enotifications45048ccnotificationsUpdates
github.com/golang-jwt/jwt/v4from 4.5.0 to 4.5.2Release notes
Sourced from github.com/golang-jwt/jwt/v4's releases.
Commits
2f0e9adBackporting 0951d18 to v47b1c1c0Merge commit from forkUpdates
github.com/nats-io/nats-server/v2from 2.9.23 to 2.11.12Release notes
Sourced from github.com/nats-io/nats-server/v2's releases.
... (truncated)
Commits
2d97cb7Release v2.11.12ea9680aCherry-picks for 2.11.12 (#7776)eb53e0d[IMPROVED] Remove no interest messages from head of streamdc0d365[FIXED] Many concurrent checkInterestState goroutines360db02[FIXED] Interest stream desync after consumer filter update74802ff[IMPROVED] Simplify recalculate pending with updated filter subject(s)6f77800Release v2.11.12-RC.7134ebc2Revert "Perform_writeFullStateunder read lock only"ddd1442Release v2.11.12-RC.659b2eb8Cherry-picks for 2.11.12-RC.6 (#7768)Updates
github.com/rs/corsfrom 1.10.1 to 1.11.0Commits
4c32059Normalize allowed request headers and store them in a sorted set (fixes #170)...8d33ca4Complete documentation; deprecate AllowOriginRequestFunc in favour of AllowOr...af821aeMerge branch 'jub0bs-master'0bcf73fUpdate benchmarkeacc8e8Fix skewed middleware benchmarks (#165)9297f15Respect the documented precedence of options (#163)73f81b4Fix readme benchmark rendering (#161)Updates
golang.org/x/cryptofrom 0.14.0 to 0.47.0Commits
4e0068cgo.mod: update golang.org/x dependenciese79546essh: curb GSSAPI DoS risk by limiting number of specified OIDsf91f7a7ssh/agent: prevent panic on malformed constraint2df4153acme/autocert: let automatic renewal work with short lifetime certsbcf6a84acme: pass context to requestb4f2b62ssh: fix error message on unsupported cipher79ec3a5ssh: allow to bind to a hostname in remote forwarding122a78fgo.mod: update golang.org/x dependenciesc0531f9all: eliminate vet diagnostics0997000all: fix some commentsUpdates
golang.org/x/oauth2from 0.13.0 to 0.34.0Commits
acc3815endpoints: fix %q verb use with wrong typef28b0b5all: fix some commentsfd15e0fx/oauth2: populate RetrieveError from DeviceAuth792c877oauth2: use strings.Builder instead of bytes.Buffer014cf77all: upgrade go directive to at least 1.24.0 [generated]3c76ce5endpoints: correct Naver OAuth2 endpoint URLscf14319oauth2: fix expiration time window check32d34efinternal: include clientID in auth style cache key2d34e30oauth2: replace a magic number with AuthStyleUnknown696f7b3all: modernize with doc links and anyUpdates
github.com/lestrrat-go/jwxfrom 1.2.26 to 1.2.29Release notes
Sourced from github.com/lestrrat-go/jwx's releases.
Changelog
Sourced from github.com/lestrrat-go/jwx's changelog.
Commits
1025f8eMerge pull request #1092 from lestrrat-go/develop/v14399aceMerge branch 'v1' into develop/v1dc80fedUpdate Changese4c1511silence linterd01027dMerge pull request from GHSA-hj3v-m684-v2593d6e0e0Bump github.com/stretchr/testify from 1.8.4 to 1.9.0 (#1085)3af5916Bump golang.org/x/crypto from 0.19.0 to 0.21.0 (#1087)7a05818Bump golang.org/x/crypto from 0.18.0 to 0.19.0 (#1074)8e2aacdBump golangci/golangci-lint-action from 3 to 4 (#1076)4b1fd05Bump kentaro-m/auto-assign-action from 1.2.6 to 2.0.0 (#1068)Updates
golang.org/x/netfrom 0.17.0 to 0.48.0Commits
35e1306go.mod: update golang.org/x dependencies7c36036http2, webdav, websocket: fix %q verb uses with wrong typeec11ecctrace: fix data race in RenderEventsbff14c5http2: don't PING a responsive server when resetting a stream88a6421dns/dnsmessage: avoid use of "strings" and "math" in dns/dnsmessage123d099http2: support net/http.Transport.NewClientConn346cc61webdav: relax test to check for any redirect status, not just 3019a29643go.mod: update golang.org/x dependencies07cefd8context: deprecate5ac9dacpublicsuffix: don't treat ip addresses as domain namesUpdates
google.golang.org/protobuffrom 1.31.0 to 1.36.11Updates
golang.org/x/cryptofrom 0.6.0 to 0.45.0Commits
4e0068cgo.mod: update golang.org/x dependenciese79546essh: curb GSSAPI DoS risk by limiting number of specified OIDsf91f7a7ssh/agent: prevent panic on malformed constraint2df4153acme/autocert: let automatic renewal work with short lifetime certsbcf6a84acme: pass context to requestb4f2b62ssh: fix error message on unsupported cipher79ec3a5ssh: allow to bind to a hostname in remote forwarding122a78fgo.mod: update golang.org/x dependenciesc0531f9all: eliminate vet diagnostics0997000all: fix some commentsUpdates
golang.org/x/cryptofrom 0.14.0 to 0.45.0Commits
4e0068cgo.mod: update golang.org/x dependenciese79546essh: curb GSSAPI DoS risk by limiting number of specified OIDsf91f7a7ssh/agent: prevent panic on malformed constraint2df4153acme/autocert: let automatic renewal work with short lifetime certsbcf6a84acme: pass context to requestb4f2b62ssh: fix error message on unsupported cipher79ec3a5ssh: allow to bind to a hostname in remote forwarding122a78fgo.mod: update golang.org/x dependenciesc0531f9all: eliminate vet diagnostics0997000all: fix some commentsUpdates
golang.org/x/netfrom 0.17.0 to 0.47.0Commits
35e1306go.mod: update golang.org/x dependencies7c36036http2, webdav, websocket: fix %q verb uses with wrong typeec11ecctrace: fix data race in RenderEventsbff14c5http2: don't PING a responsive server when resetting a stream88a6421dns/dnsmessage: avoid use of "strings" and "math" in dns/dnsmessage123d099http2: support net/http.Transport.NewClientConn346cc61webdav: relax test to check for any redirect status, not just 3019a29643go.mod: update golang.org/x dependencies07cefd8context: deprecate5ac9dacpublicsuffix: don't treat ip addresses as domain namesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.