Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 7, 2025

Bumps the go-dependencies group with 6 updates in the / directory:

Package From To
github.com/cnabio/cnab-to-oci 0.5.1 0.5.2
github.com/cnabio/image-relocation 0.9.1 0.9.2
github.com/google/go-containerregistry 0.20.6 0.20.7
github.com/moby/buildkit 0.26.1 0.26.2
github.com/olekukonko/tablewriter 1.1.1 1.1.2
github.com/spf13/cobra 1.10.1 1.10.2

Updates github.com/cnabio/cnab-to-oci from 0.5.1 to 0.5.2

Release notes

Sourced from github.com/cnabio/cnab-to-oci's releases.

v0.5.2

What's Changed

Full Changelog: cnabio/cnab-to-oci@v0.5.1...v0.5.2

Commits
  • 96b9429 Merge pull request #199 from cnabio/dependabot/go_modules/github.com/docker/c...
  • 9127080 Bump github.com/docker/cli
  • 08eaf4c Merge pull request #198 from cnabio/dependabot/go_modules/go-dependencies-082...
  • 9c13e42 Bump the go-dependencies group with 3 updates
  • See full diff in compare view

Updates github.com/cnabio/image-relocation from 0.9.1 to 0.9.2

Release notes

Sourced from github.com/cnabio/image-relocation's releases.

v0.9.2

What's Changed

New Contributors

Full Changelog: cnabio/image-relocation@v0.9.1...v0.9.2

Commits
  • 27face6 Merge pull request #17 from cnabio/dependabot/github_actions/actions/setup-go-6
  • 97ffc0a Merge pull request #16 from cnabio/dependabot/github_actions/actions/checkout-6
  • f563986 Merge pull request #15 from cnabio/dependabot/github_actions/actions/cache-4
  • 7babefd Merge pull request #14 from cnabio/dependabot/github_actions/codecov/codecov-...
  • 567d7c4 Bump actions/setup-go from 3 to 6
  • 6f4b254 Bump actions/checkout from 3 to 6
  • a941ed4 Bump actions/cache from 3 to 4
  • 154e292 Bump codecov/codecov-action from 3 to 5
  • 102822f Merge pull request #13 from dgannon991/chore/bump-deps-and-introduce-dependabot
  • 4fb00bf Introduced dependabot and set a good baseline
  • See full diff in compare view

Updates github.com/docker/cli from 28.5.2+incompatible to 29.0.2+incompatible

Commits
  • 8108357 Merge pull request #6662 from dvdksn/doc-update-http-proxy-link
  • 3a84258 chore: update link/linktext to dockerd proxy config
  • eedd969 Merge pull request #6659 from vvoland/fix-system-version
  • dd2c493 cli/command/system: Fix missing components in version output
  • 67cef77 Merge pull request #6658 from vvoland/img-list-all-dangling
  • 207bf52 image/tree: Only show untagged images when --all flag is used
  • 2cfd9df Merge pull request #6654 from vvoland/img-list-nocolor
  • be9e630 image/tree: Respect NO_COLOR env variable
  • 88e3241 Merge pull request #6657 from vvoland/img-list-nonexpanded-untagged
  • 2ae51e2 Merge pull request #6656 from vvoland/img-list-notty-width
  • Additional commits viewable in compare view

Updates github.com/google/go-containerregistry from 0.20.6 to 0.20.7

Release notes

Sourced from github.com/google/go-containerregistry's releases.

v0.20.7

What's Changed

New Contributors

Full Changelog: google/go-containerregistry@v0.20.6...v0.20.7

Commits
  • e075f20 go mod tidy on dependabot update (#2171)
  • 45aacf4 Bump the actions group across 1 directory with 3 updates (#2170)
  • 073b936 Update dependencies and deprecate DockerVersion field (#2164)
  • 390dacd Bump golang.org/x/crypto from 0.38.0 to 0.45.0 in /cmd/krane (#2163)
  • ca44d47 Bump golang.org/x/crypto from 0.38.0 to 0.45.0 in /pkg/authn/k8schain (#2162)
  • 999cc1f Bump github.com/docker/docker (#2161)
  • d1809c8 Build artifacts for riscv64 (#2159)
  • 7471efd Bump the auxiliary-deps group across 3 directories with 4 updates (#2156)
  • 2bb5bb0 Bump the actions group with 5 updates (#2155)
  • 16371c1 Remove manual vendor setting for dependabot (#2151)
  • Additional commits viewable in compare view

Updates github.com/moby/buildkit from 0.26.1 to 0.26.2

Release notes

Sourced from github.com/moby/buildkit's releases.

v0.26.2

Welcome to the v0.26.2 release of buildkit!

Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.

Contributors

  • CrazyMax
  • Tõnis Tiigi

Notable Changes

  • Fix possible error when uploading big files to S3 cache exporter #6373

Dependency Changes

This release has no dependency changes

Previous release can be found at v0.26.1

Commits
  • be1f38e Merge pull request #6374 from crazy-max/0.26_picks_0.26.2
  • 8a34dcd cache(s3): request checksum calculation when required
  • See full diff in compare view

Updates github.com/olekukonko/tablewriter from 1.1.1 to 1.1.2

Commits

Updates github.com/spf13/cobra from 1.10.1 to 1.10.2

Release notes

Sourced from github.com/spf13/cobra's releases.

v1.10.2

🔧 Dependencies

  • chore: Migrate from gopkg.in/yaml.v3 to go.yaml.in/yaml/v3 by @​dims in spf13/cobra#2336 - the gopkg.in/yaml.v3 package has been deprecated for some time: this should significantly cleanup dependency/supply-chains for consumers of spf13/cobra

📈 CI/CD

🔥✍🏼 Docs

🍂 Refactors

🤗 New Contributors

Full Changelog: spf13/cobra@v1.10.1...v1.10.2

Thank you to our amazing contributors!!!!! 🐍 🚀

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

… updates

Bumps the go-dependencies group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/cnabio/cnab-to-oci](https://github.com/cnabio/cnab-to-oci) | `0.5.1` | `0.5.2` |
| [github.com/cnabio/image-relocation](https://github.com/cnabio/image-relocation) | `0.9.1` | `0.9.2` |
| [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry) | `0.20.6` | `0.20.7` |
| [github.com/moby/buildkit](https://github.com/moby/buildkit) | `0.26.1` | `0.26.2` |
| [github.com/olekukonko/tablewriter](https://github.com/olekukonko/tablewriter) | `1.1.1` | `1.1.2` |
| [github.com/spf13/cobra](https://github.com/spf13/cobra) | `1.10.1` | `1.10.2` |



Updates `github.com/cnabio/cnab-to-oci` from 0.5.1 to 0.5.2
- [Release notes](https://github.com/cnabio/cnab-to-oci/releases)
- [Commits](cnabio/cnab-to-oci@v0.5.1...v0.5.2)

Updates `github.com/cnabio/image-relocation` from 0.9.1 to 0.9.2
- [Release notes](https://github.com/cnabio/image-relocation/releases)
- [Commits](cnabio/image-relocation@v0.9.1...v0.9.2)

Updates `github.com/docker/cli` from 28.5.2+incompatible to 29.0.2+incompatible
- [Commits](docker/cli@v28.5.2...v29.0.2)

Updates `github.com/google/go-containerregistry` from 0.20.6 to 0.20.7
- [Release notes](https://github.com/google/go-containerregistry/releases)
- [Commits](google/go-containerregistry@v0.20.6...v0.20.7)

Updates `github.com/moby/buildkit` from 0.26.1 to 0.26.2
- [Release notes](https://github.com/moby/buildkit/releases)
- [Commits](moby/buildkit@v0.26.1...v0.26.2)

Updates `github.com/olekukonko/tablewriter` from 1.1.1 to 1.1.2
- [Commits](olekukonko/tablewriter@v1.1.1...v1.1.2)

Updates `github.com/spf13/cobra` from 1.10.1 to 1.10.2
- [Release notes](https://github.com/spf13/cobra/releases)
- [Commits](spf13/cobra@v1.10.1...v1.10.2)

---
updated-dependencies:
- dependency-name: github.com/cnabio/cnab-to-oci
  dependency-version: 0.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/cnabio/image-relocation
  dependency-version: 0.9.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/docker/cli
  dependency-version: 29.0.2+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: go-dependencies
- dependency-name: github.com/google/go-containerregistry
  dependency-version: 0.20.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/moby/buildkit
  dependency-version: 0.26.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/olekukonko/tablewriter
  dependency-version: 1.1.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/spf13/cobra
  dependency-version: 1.10.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependabot 🤖 Created by the dependabot label Dec 7, 2025
@dependabot dependabot bot requested a review from a team as a code owner December 7, 2025 04:01
@dependabot dependabot bot added the dependabot 🤖 Created by the dependabot label Dec 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependabot 🤖 Created by the dependabot

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant