Skip to content

chore(deps): bump the go-crypto-image group across 1 directory with 2 updates - #201

Closed
dependabot[bot] wants to merge 1 commit into
developmentfrom
dependabot/go_modules/apps/backend/development/go-crypto-image-543e03c75b
Closed

dependabot[bot] wants to merge 1 commit into
developmentfrom
dependabot/go_modules/apps/backend/development/go-crypto-image-543e03c75b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 14, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-crypto-image group with 2 updates in the /apps/backend directory: golang.org/x/crypto and golang.org/x/image.

Updates golang.org/x/crypto from 0.52.0 to 0.55.0

Commits
  • f44d03d go.mod: update golang.org/x dependencies
  • 5ed4944 crypto/internal/poly1305: provide optimised assembly for riscv64
  • b07833c ssh: return window credit for discarded extended data
  • d701c51 acme: fix nil pointer dereference in pebble test error reporting
  • 999d053 ssh: fix parsing of GSSAPI payloads offering multiple mechanisms
  • 90f76b8 ssh: reject certificate signature keys before recursing
  • b53964a ssh: permit empty but non-nil HostKeyAlgorithms, KeyExchanges, Ciphers, MACs
  • 626e40f ssh: drain stderr on forwarded TCP and Unix channels
  • 31914c6 x509roots/fallback: update bundle
  • f2135b8 all: clean up minor issues found by staticcheck
  • Additional commits viewable in compare view

Updates golang.org/x/image from 0.41.0 to 0.45.0

Commits
  • 3ebddc7 go.mod: update golang.org/x dependencies
  • 981eaa0 vp8l: avoid allocating many unused Huffman tree groups
  • 315273a vector: using golang.org/x/sys/cpu for feature detection
  • 891abcb go.mod: update golang.org/x dependencies
  • f50490d font: document (lack of) security hardening in font packages
  • 7a0cfda webp: check for VP8L dimension mismatch before allocation
  • 4339315 tiff: consistently skip horizontal padding in tiled images
  • b5baf41 tiff: avoid overflow when reading IFD entries
  • e7513b5 tiff: limit the amount of data read in IFD entries
  • cb9f1a6 tiff: limit uncompressed data reads
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Jun 14, 2026
… updates

Bumps the go-crypto-image group with 2 updates in the /apps/backend directory: [golang.org/x/crypto](https://github.com/golang/crypto) and [golang.org/x/image](https://github.com/golang/image).


Updates `golang.org/x/crypto` from 0.52.0 to 0.55.0
- [Commits](golang/crypto@v0.52.0...v0.55.0)

Updates `golang.org/x/image` from 0.41.0 to 0.45.0
- [Commits](golang/image@v0.41.0...v0.45.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.53.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-crypto-image
- dependency-name: golang.org/x/image
  dependency-version: 0.42.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-crypto-image
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump the go-crypto-image group in /apps/backend with 2 updates chore(deps): bump the go-crypto-image group across 1 directory with 2 updates Aug 16, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/apps/backend/development/go-crypto-image-543e03c75b branch from b5fe35c to 0370a0f Compare August 16, 2026 21:03
nekochanfood added a commit that referenced this pull request Aug 21, 2026
Consolidates the open Dependabot Go module PRs (#195, #201, #202, #204,
#206, #208, #210, #213, #214) into a single update.

Direct:
- github.com/jackc/pgx/v5 5.9.2 -> 5.10.0
- github.com/oapi-codegen/oapi-codegen/v2 2.7.1 -> 2.8.0
- github.com/oapi-codegen/runtime 1.4.1 -> 1.6.0
- golang.org/x/crypto 0.52.0 -> 0.55.0
- golang.org/x/image 0.41.0 -> 0.45.0

Indirect:
- github.com/getkin/kin-openapi 0.138.0 -> 0.146.0
- github.com/gohugoio/hugo 0.161.0 -> 0.163.3
- github.com/google/cel-go 0.28.0 -> 0.29.0
- go.mongodb.org/mongo-driver 1.7.5 -> 1.17.7
- golang.org/x/net 0.54.0 -> 0.57.0
- google.golang.org/grpc 1.80.0 -> 1.82.1

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@nekochanfood

Copy link
Copy Markdown
Member

Superseded by 3954155 / 7831753 on development — these bumps were consolidated into a single update and verified with go build, go test, and next build.

@dependabot @github

dependabot Bot commented on behalf of github Aug 21, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/go_modules/apps/backend/development/go-crypto-image-543e03c75b branch August 21, 2026 07:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant