Skip to content

build(deps): bump golang.org/x/net from 0.47.0 to 0.55.0 - #749

Closed
dependabot[bot] wants to merge 2 commits into
masterfrom
dependabot/go_modules/golang.org/x/net-0.55.0
Closed

build(deps): bump golang.org/x/net from 0.47.0 to 0.55.0#749
dependabot[bot] wants to merge 2 commits into
masterfrom
dependabot/go_modules/golang.org/x/net-0.55.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 3, 2026

Copy link
Copy Markdown
Contributor

Bumps golang.org/x/net from 0.47.0 to 0.55.0.

Commits
  • 7770ec4 go.mod: update golang.org/x dependencies
  • 4ece7b6 html: escape greater-than symbol in doctype identifiers
  • 08be507 html: improve Noah's Ark clause performance
  • a8fb2fe html: properly render fostered elements in foreign content
  • 0dc5b7a html: properly check namespace in "in body" any other end tag
  • a452f3c html: ignore duplicate attributes during tokenization
  • f865199 quic: fix appendMaxDataFrame erroneously accumulating sentLimit
  • 210ed3c quic: establish a "happened-before" relationship between stream write and read
  • ad8140e quic: fix buffer slicing when handling overlapping stream data
  • 23ee2ef http2: avoid API changes when built with go1.27
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Summary by CodeRabbit

  • Chores
    • Updated several Go dependency versions to newer releases.
    • Upgraded the required Go version and removed the pinned toolchain setting.

Bumps [golang.org/x/net](https://github.com/golang/net) from 0.47.0 to 0.55.0.
- [Commits](golang/net@v0.47.0...v0.55.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-version: 0.55.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Jul 3, 2026
@openshift-ci
openshift-ci Bot requested review from fbm3307 and jrosental July 3, 2026 11:14
@openshift-ci

openshift-ci Bot commented Jul 3, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: dependabot[bot]
Once this PR has been reviewed and has the lgtm label, please assign fbm3307 for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci

openshift-ci Bot commented Jul 3, 2026

Copy link
Copy Markdown

Hi @dependabot[bot]. Thanks for your PR.

I'm waiting for a codeready-toolchain member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@coderabbitai

coderabbitai Bot commented Jul 3, 2026

Copy link
Copy Markdown

Walkthrough

Updates go.mod by bumping several golang.org/x/* indirect dependency versions, raising the go directive from 1.24.4 to 1.25.0, and removing the toolchain go1.24.13 line.

Changes

Dependency and Go version bump

Layer / File(s) Summary
Indirect dependency and Go directive updates
go.mod
Several golang.org/x/* indirect dependencies (x/crypto, x/mod, x/net, x/sync, x/sys, x/term, x/text, x/tools) are bumped to newer versions, the go directive is raised from 1.24.4 to 1.25.0, and the toolchain go1.24.13 line is removed.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Suggested reviewers: alexeykazakov

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title matches one of the dependency updates in the PR, though the changes also include several other x/* bumps and a Go version directive update.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/go_modules/golang.org/x/net-0.55.0

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@go.mod`:
- Line 129: The Go toolchain version is out of sync between the module and CI
tooling: go.mod requires Go 1.25.0 while openshift-ci/Dockerfile.tools still
installs Go 1.24.13. Update the Go version used in Dockerfile.tools to match
go.mod, or adjust go.mod to the intended shared version, so the compiler version
is consistent across builds and CI.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Enterprise

Run ID: e4513e1b-fdc4-4dc1-9154-a5b7117f06aa

📥 Commits

Reviewing files that changed from the base of the PR and between 96b779e and 17a6afe.

⛔ Files ignored due to path filters (1)
  • go.sum is excluded by !**/*.sum
📒 Files selected for processing (1)
  • go.mod
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • codeready-toolchain/api (manual) → reviewed against open PR #512 dependabot/go_modules/golang.org/x/net-0.55.0 instead of the default branch
  • codeready-toolchain/toolchain-common (manual)
  • codeready-toolchain/host-operator (manual)
  • codeready-toolchain/toolchain-e2e (manual)
📜 Review details
⏰ Context from checks skipped due to timeout. (2)
  • GitHub Check: test
  • GitHub Check: Build & push operator bundles & dashboard image for e2e tests
⚠️ CI failures not shown inline (2)

GitHub Actions: ci-build / 0_GolangCI Lint.txt: build(deps): bump golang.org/x/net from 0.47.0 to 0.55.0

Conclusion: failure

View job details

##[group]run golangci-lint
 Running [/home/runner/golangci-lint-2.1.6-linux-amd64/golangci-lint config path --config=./.golangci.yml] in [/home/runner/work/member-operator/member-operator] ...
 Running [/home/runner/golangci-lint-2.1.6-linux-amd64/golangci-lint run  --config=./.golangci.yml --verbose] in [/home/runner/work/member-operator/member-operator] ...
 level=info msg="golangci-lint has version 2.1.6 built with go1.24.2 from eabc2638 on "
 level=info msg="[config_reader] Used config file .golangci.yml"
 level=info msg="[config_reader] Module name \"github.com/codeready-toolchain/member-operator\""
 Error: can't load config: the Go language version (go1.24) used to build golangci-lint is lower than the targeted Go version (1.25.0)
 Failed executing command with error: can't load config: the Go language version (go1.24) used to build golangci-lint is lower than the targeted Go version (1.25.0)
 ##[error]golangci-lint exit with code 3

GitHub Actions: ci-build / GolangCI Lint: build(deps): bump golang.org/x/net from 0.47.0 to 0.55.0

Conclusion: failure

View job details

##[group]run golangci-lint
 Running [/home/runner/golangci-lint-2.1.6-linux-amd64/golangci-lint config path --config=./.golangci.yml] in [/home/runner/work/member-operator/member-operator] ...
 Running [/home/runner/golangci-lint-2.1.6-linux-amd64/golangci-lint run  --config=./.golangci.yml --verbose] in [/home/runner/work/member-operator/member-operator] ...
 level=info msg="golangci-lint has version 2.1.6 built with go1.24.2 from eabc2638 on "
 level=info msg="[config_reader] Used config file .golangci.yml"
 level=info msg="[config_reader] Module name \"github.com/codeready-toolchain/member-operator\""
 Error: can't load config: the Go language version (go1.24) used to build golangci-lint is lower than the targeted Go version (1.25.0)
 Failed executing command with error: can't load config: the Go language version (go1.24) used to build golangci-lint is lower than the targeted Go version (1.25.0)
 ##[error]golangci-lint exit with code 3
🧰 Additional context used
📓 Path-based instructions (1)
**

⚙️ CodeRabbit configuration file

-Focus on major issues impacting performance, readability, maintainability and security. Avoid nitpicks and avoid verbosity.

Files:

  • go.mod
🔀 Multi-repo context

Linked repositories findings

codeready-toolchain/api ([ref: PR branch refs/pull/512/head])

  • go.mod:41 and go.sum:116-117 already pin golang.org/x/net v0.55.0 indirectly.
  • No direct golang.org/x/net/* imports were found.

codeready-toolchain/toolchain-common

  • go.mod:41 / go.sum:116-117 pin golang.org/x/net v0.55.0 indirectly.
  • No direct golang.org/x/net/* imports were found.

codeready-toolchain/host-operator

  • go.mod:41 / go.sum:116-117 pin golang.org/x/net v0.55.0 indirectly.
  • No direct golang.org/x/net/* imports were found.

codeready-toolchain/toolchain-e2e

  • go.mod:41 / go.sum:116-117 pin golang.org/x/net v0.55.0 indirectly.
  • No direct golang.org/x/net/* imports were found.
🔇 Additional comments (1)
go.mod (1)

101-111: LGTM!

Comment thread go.mod
go 1.24.4

toolchain go1.24.13
go 1.25.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf 'go.mod version lines:\n'
rg -n '^(go|toolchain)\s+' go.mod || true

printf '\nDocker/tooling Go version pins:\n'
rg -n 'go1\.(24\.13|25\.0)|toolchain go1\.24\.13|toolchain go1\.25\.0|FROM .*go:1\.(24\.13|25\.0)' openshift-ci .github . || true

printf '\nRelevant file contents:\n'
for f in go.mod openshift-ci/Dockerfile.tools; do
  if [ -f "$f" ]; then
    echo "--- $f ---"
    cat -n "$f" | sed -n '1,220p'
  fi
done

Repository: codeready-toolchain/member-operator

Length of output: 9692


Align the Go toolchain versions
go.mod now requires Go 1.25.0, but openshift-ci/Dockerfile.tools still downloads Go 1.24.13. Update the image or keep the module version in sync so CI and tooling use the same compiler.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@go.mod` at line 129, The Go toolchain version is out of sync between the
module and CI tooling: go.mod requires Go 1.25.0 while
openshift-ci/Dockerfile.tools still installs Go 1.24.13. Update the Go version
used in Dockerfile.tools to match go.mod, or adjust go.mod to the intended
shared version, so the compiler version is consistent across builds and CI.

Source: Path instructions

@sonarqubecloud

Copy link
Copy Markdown

@xcoulon

xcoulon commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

can't do it now, we need to upgrade to Go 1.25, first

@xcoulon xcoulon closed this Jul 21, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 21, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/go_modules/golang.org/x/net-0.55.0 branch July 21, 2026 06:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code needs-ok-to-test

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants