Skip to content

chore(deps): bump the go-deps group across 1 directory with 3 updates - #467

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-deps-3698aea13b
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-deps-3698aea13b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-deps group with 3 updates in the / directory: github.com/go-git/go-billy/v5, github.com/moby/buildkit and github.com/olekukonko/tablewriter.

Updates github.com/go-git/go-billy/v5 from 5.9.1 to 5.9.2

Release notes

Sourced from github.com/go-git/go-billy/v5's releases.

v5.9.2

What's Changed

Full Changelog: go-git/go-billy@v5.9.0...v5.9.2

Commits

Updates github.com/moby/buildkit from 0.33.0 to 0.33.1

Release notes

Sourced from github.com/moby/buildkit's releases.

v0.33.1

Welcome to the v0.33.1 release of buildkit!

Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.

Contributors

  • Tõnis Tiigi
  • CrazyMax
  • Sebastiaan van Stijn

Notable Changes

  • Built-in Dockerfile frontend has been updated to v1.27.1 changelog.
  • Fix proxy CA cleanup so build steps cannot redirect it outside the build rootfs, block it with a special file, or succeed when cleanup fails. GHSA-2f5p-x9ph-g97x
  • Fix a daemon panic when a build requests CDI devices while CDI support is disabled. Optional devices are ignored; required devices produce an error. GHSA-r456-g3gm-cvxf
  • Verify container blob contents against their claimed digest before caching them. This protects shared caches from unverified blobs supplied through the low-level LLB API. GHSA-p3rc-w3hc-pqvv
  • Verify applied image layer DiffIDs, bind lazy stargz snapshots to their verified TOC digest, and isolate legacy layer snapshots. Image source cache keys no longer rely on unverified DiffIDs. GHSA-f2v9-hprr-32q3
  • Prevent malicious external frontends from crashing the daemon through gateway container lifecycle races or malformed requests and definitions. GHSA-4hgw-qrhw-fhg8
  • Reject special files in daemon-side snapshot reads and replace existing special files safely in LLB mkfile operations. GHSA-9728-qjrv-2xh2
  • Reject malformed LLB file operations with invalid symlink owner inputs instead of allowing a daemon panic. GHSA-fjj4-h6vf-m9hj
  • Reject malformed LLB merge operations with mismatched input counts instead of allowing a daemon panic. GHSA-cv6p-7w7g-xjwq
  • Limit Dockerfile, .dockerignore, gateway file, and nested LLB definition reads to prevent oversized inputs from exhausting daemon memory. GHSA-mgqf-486f-49vp
  • Apply source policies to Git bundle locators and reject Git full remote URLs that do not match the source identifier. GHSA-66hf-6vf5-87hc

Dependency Changes

  • github.com/containerd/containerd/v2 v2.3.4 -> v2.3.6
  • golang.org/x/crypto v0.55.0 -> v0.56.0

Previous release can be found at v0.33.0

Commits
  • 8c91502 Merge pull request #7230 from crazy-max/v0.33_picks_v0.33.1
  • a9d42a8 vendor: github.com/containerd/containerd/v2 v2.3.6
  • 9d198b8 vendor: github.com/containerd/containerd/v2 v2.3.5
  • 98f8583 vendor: golang.org/x/crypto v0.56.0
  • adc9d52 client: preserve the caller context for local cache reset
  • e7379bc sourcepolicy: evaluate Git bundle sources
  • 86ea38d vendor: gomod regen
  • dbf9012 security: validate Git full remote URLs
  • d26401f security: limit daemon file reads
  • 7d1ec17 dockerfile: limit epoch archive reads
  • Additional commits viewable in compare view

Updates github.com/olekukonko/tablewriter from 1.1.4 to 1.1.5

Commits
  • 5f0c87a change readme to v1.1.5
  • 8535cd2 Merge pull request #331 from olekukonko/makawhy
  • 8db545f markdown game
  • 569d938 Merge pull request #330 from olekukonko/makawhy
  • ce371fa Merge pull request #326 from olekukonko/makawhy
  • e1d22bb Merge pull request #329 from team-humaki/fix/global-width-wrap-split
  • c9a710f Merge pull request #327 from youdie006/wrapwords-last-word-hang
  • cbd4eb4 wrap: split Widths.Global across columns
  • 2a7896c Broaden the WrapWords table to the shapes around the last-word case
  • cb595f4 Terminate WrapWords when the last word is wider than the limit
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-deps group with 3 updates in the / directory: [github.com/go-git/go-billy/v5](https://github.com/go-git/go-billy), [github.com/moby/buildkit](https://github.com/moby/buildkit) and [github.com/olekukonko/tablewriter](https://github.com/olekukonko/tablewriter).


Updates `github.com/go-git/go-billy/v5` from 5.9.1 to 5.9.2
- [Release notes](https://github.com/go-git/go-billy/releases)
- [Commits](go-git/go-billy@v5.9.1...v5.9.2)

Updates `github.com/moby/buildkit` from 0.33.0 to 0.33.1
- [Release notes](https://github.com/moby/buildkit/releases)
- [Commits](moby/buildkit@v0.33.0...v0.33.1)

Updates `github.com/olekukonko/tablewriter` from 1.1.4 to 1.1.5
- [Release notes](https://github.com/olekukonko/tablewriter/releases)
- [Commits](olekukonko/tablewriter@v1.1.4...v1.1.5)

---
updated-dependencies:
- dependency-name: github.com/go-git/go-billy/v5
  dependency-version: 5.9.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/moby/buildkit
  dependency-version: 0.33.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/olekukonko/tablewriter
  dependency-version: 1.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants