Bump the go-modules group with 6 updates#1127
Merged
paketo-bot merged 1 commit intomainfrom May 4, 2026
Merged
Conversation
Bumps the go-modules group with 6 updates: | Package | From | To | | --- | --- | --- | | [github.com/anchore/syft](https://github.com/anchore/syft) | `1.43.0` | `1.44.0` | | [github.com/docker/cli](https://github.com/docker/cli) | `29.4.1+incompatible` | `29.4.2+incompatible` | | [github.com/gookit/color](https://github.com/gookit/color) | `1.6.0` | `1.6.1` | | [github.com/pelletier/go-toml/v2](https://github.com/pelletier/go-toml) | `2.3.0` | `2.3.1` | | [github.com/pjbgf/sha1cd](https://github.com/pjbgf/sha1cd) | `0.5.0` | `0.6.0` | | [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.80.0` | `1.81.0` | Updates `github.com/anchore/syft` from 1.43.0 to 1.44.0 - [Release notes](https://github.com/anchore/syft/releases) - [Changelog](https://github.com/anchore/syft/blob/main/RELEASE.md) - [Commits](anchore/syft@v1.43.0...v1.44.0) Updates `github.com/docker/cli` from 29.4.1+incompatible to 29.4.2+incompatible - [Commits](docker/cli@v29.4.1...v29.4.2) Updates `github.com/gookit/color` from 1.6.0 to 1.6.1 - [Release notes](https://github.com/gookit/color/releases) - [Commits](gookit/color@v1.6.0...v1.6.1) Updates `github.com/pelletier/go-toml/v2` from 2.3.0 to 2.3.1 - [Release notes](https://github.com/pelletier/go-toml/releases) - [Commits](pelletier/go-toml@v2.3.0...v2.3.1) Updates `github.com/pjbgf/sha1cd` from 0.5.0 to 0.6.0 - [Release notes](https://github.com/pjbgf/sha1cd/releases) - [Commits](pjbgf/sha1cd@v0.5.0...v0.6.0) Updates `google.golang.org/grpc` from 1.80.0 to 1.81.0 - [Release notes](https://github.com/grpc/grpc-go/releases) - [Commits](grpc/grpc-go@v1.80.0...v1.81.0) --- updated-dependencies: - dependency-name: github.com/anchore/syft dependency-version: 1.44.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: go-modules - dependency-name: github.com/docker/cli dependency-version: 29.4.2+incompatible dependency-type: indirect update-type: version-update:semver-patch dependency-group: go-modules - dependency-name: github.com/gookit/color dependency-version: 1.6.1 dependency-type: indirect update-type: version-update:semver-patch dependency-group: go-modules - dependency-name: github.com/pelletier/go-toml/v2 dependency-version: 2.3.1 dependency-type: indirect update-type: version-update:semver-patch dependency-group: go-modules - dependency-name: github.com/pjbgf/sha1cd dependency-version: 0.6.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: go-modules - dependency-name: google.golang.org/grpc dependency-version: 1.81.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: go-modules ... Signed-off-by: dependabot[bot] <[email protected]>
paketo-bot-reviewer
approved these changes
May 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the go-modules group with 6 updates:
1.43.01.44.029.4.1+incompatible29.4.2+incompatible1.6.01.6.12.3.02.3.10.5.00.6.01.80.01.81.0Updates
github.com/anchore/syftfrom 1.43.0 to 1.44.0Release notes
Sourced from github.com/anchore/syft's releases.
Commits
8cb78cefix: resolve yarn lock aliases to source package (#4836)3b046b3chore: move snippet files from test-fixtures to testdata (#4830)05cc8eeAdd support for linux-riscv64 (#4757)3562dabfix(lua-rockspec): handle empty and whitespace-only rockspec files gracefully...014a4c9chore: tidy go.mod (#4823)3cb838efixed pe dotnet wrong ver , fixed #4813 (#4814)758324bfix: propagate non-EOF errors out of safeCopy (#4807)Updates
github.com/docker/clifrom 29.4.1+incompatible to 29.4.2+incompatibleCommits
Updates
github.com/gookit/colorfrom 1.6.0 to 1.6.1Release notes
Sourced from github.com/gookit/color's releases.
Commits
d232e11ci(release): remove Go version matrix and simplify build steps in release action1245572fix(convert): incorrect conversion between integer types2bb27a5fix(detect): should enable VTP on windows CMD,PWSHe58a899fix: re-apply color after nested reset in RenderString (#119)de1e243Add 'stable' to Go version matrix and update actioned1b9ccbuild(deps): bump actions/checkout from 5 to 6 (#115)2e18426build(deps): bump github/codeql-action from 3 to 4 (#113)Updates
github.com/pelletier/go-toml/v2from 2.3.0 to 2.3.1Release notes
Sourced from github.com/pelletier/go-toml/v2's releases.
Commits
f85c4e8README.md: remove reference to old go versions and modules (#1048)45d4fb4fix: change DisallowUnknownFields error from "missing field" to "unknown fiel...c171216Fix incorrect error positions in unstable parser Range() (#1047) (#1056)Updates
github.com/pjbgf/sha1cdfrom 0.5.0 to 0.6.0Release notes
Sourced from github.com/pjbgf/sha1cd's releases.
Commits
f90af0dMerge pull request #206 from pjbgf/drop-self-registration6ff015aRemove self-registration via crypto.RegisterHashba31b91Merge pull request #205 from pjbgf/performance2f0cc80Enable entire11223cfperf(amd64): Replace LOADCS extract chain with shuffle+store21916d9perf: Pass collision-detection arrays by pointer5470964Merge pull request #201 from pjbgf/dependabot/github_actions/actions/setup-go...d7b3b63build(deps): Bump actions/setup-go from 5.5.0 to 6.1.08750e70Merge pull request #202 from pjbgf/dependabot/docker/golang-1.253bed41fMerge pull request #203 from pjbgf/dependabot/github_actions/github/codeql-ac...Updates
google.golang.org/grpcfrom 1.80.0 to 1.81.0Release notes
Sourced from google.golang.org/grpc's releases.
Commits
cb18228Change version to 1.81.0 (#9062)96748f9Cherry-pick #9105 to 1.81.x (#9106)9183222Cherry pick #9055, #9032 to v1.81.x (#9095)5cba6daRevert "deps: update dependencies for all modules (#9065)" (#9067)af8a936deps: update dependencies for all modules (#9065)cdc60dftransport: optimize heap allocations in ready reader and update syscall conne...208d053xds/resolver: pass complete XDSConfig in RPC context for HTTP filters (gRFC A...50fe1cctest: Fix flaky testTestServerStreaming_ClientCallRecvMsgTwicein `end2end...d574badbuild(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 (#9050)b8bf4d0build(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 in /inte...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions