Skip to content

chore(deps): bump the go-deps group across 1 directory with 10 updates - #724

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-deps-9c82927969
Open

chore(deps): bump the go-deps group across 1 directory with 10 updates#724
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-deps-9c82927969

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-deps group with 9 updates in the / directory:

Package From To
github.com/anthropics/anthropic-sdk-go 1.66.0 1.71.0
github.com/gin-contrib/gzip 1.2.6 1.2.7
github.com/go-webauthn/webauthn 0.17.4 0.18.0
github.com/prometheus/client_model 0.6.2 0.6.3
github.com/prometheus/common 0.70.1 0.71.0
golang.org/x/crypto 0.55.0 0.56.0
golang.org/x/sync 0.22.0 0.23.0
k8s.io/apimachinery 0.36.4 0.37.0
sigs.k8s.io/gateway-api 1.6.1 1.6.2

Updates github.com/anthropics/anthropic-sdk-go from 1.66.0 to 1.71.0

Release notes

Sourced from github.com/anthropics/anthropic-sdk-go's releases.

v1.71.0

1.71.0 (2026-09-04)

Full Changelog: v1.70.1...v1.71.0

Features

  • api: add named types for organization compliance settings state (5ce34ff)

Chores

  • examples: refresh platform model IDs (#327) (4b064a1)
  • tests: reword the skip reason on the path-level query param tests (c0b3d71)

v1.70.1

1.70.1 (2026-09-03)

Full Changelog: v1.70.0...v1.70.1

v1.70.0

1.70.0 (2026-09-02)

Full Changelog: v1.69.0...v1.70.0

Features

  • api: add support for sending a workspace ID on more endpoints (75477bf)

Bug Fixes

  • client: surface non-JSON error response bodies in error messages (7e89315)

Chores

  • internal: narrower codeowners scope (24487eb)
  • internal: revert codeowners change (0717fba)

Documentation

  • api: update a few doc strings (5c4b77b)

v1.69.0

1.69.0 (2026-09-01)

Full Changelog: v1.68.0...v1.69.0

... (truncated)

Changelog

Sourced from github.com/anthropics/anthropic-sdk-go's changelog.

1.71.0 (2026-09-04)

Full Changelog: v1.70.1...v1.71.0

Features

  • api: add named types for organization compliance settings state (5ce34ff)

Chores

  • examples: refresh platform model IDs (#327) (4b064a1)
  • tests: reword the skip reason on the path-level query param tests (c0b3d71)

1.70.1 (2026-09-03)

Full Changelog: v1.70.0...v1.70.1

1.70.0 (2026-09-02)

Full Changelog: v1.69.0...v1.70.0

Features

  • api: add support for sending a workspace ID on more endpoints (75477bf)

Bug Fixes

  • client: surface non-JSON error response bodies in error messages (7e89315)

Chores

  • internal: narrower codeowners scope (24487eb)
  • internal: revert codeowners change (0717fba)

Documentation

  • api: update a few doc strings (5c4b77b)

1.69.0 (2026-09-01)

Full Changelog: v1.68.0...v1.69.0

Features

  • api: beta user profiles: add external_user_onboarded_at, remove relationship in favor of access_type (d8b0de6)
  • api: manual updates (b508af4)

... (truncated)

Commits
  • de6914c Merge pull request #437 from anthropics/release-please--branches--main--chang...
  • b743b14 release: 1.71.0
  • 5ce34ff feat(api): add named types for organization compliance settings state
  • c0b3d71 chore(tests): reword the skip reason on the path-level query param tests
  • 4b064a1 chore(examples): refresh platform model IDs (#327)
  • 1564b6b Merge branch 'main' into next
  • e9c104e Merge pull request #436 from anthropics/release-please--branches--main--chang...
  • b198dfc release: 1.70.1
  • d099cce Merge branch 'main' into next
  • 92209b6 Merge pull request #433 from anthropics/release-please--branches--main--chang...
  • Additional commits viewable in compare view

Updates github.com/gin-contrib/gzip from 1.2.6 to 1.2.7

Release notes

Sourced from github.com/gin-contrib/gzip's releases.

v1.2.7

Changelog

Bug fixes

  • d8207e94576e31ec581ef6ae04c1aeb5499487d4: fix(lint): address golangci-lint v2.12 findings (@鈥媋ppleboy)

Enhancements

  • 2f8b8fb6d9085f1f45c751f1183e5c0ba83099d2: chore(deps): upgrade quic-go to v0.59.1 (@鈥媋ppleboy)
  • 806cace682ac4220ad22dbeaf2bf6a5e527b3062: chore(deps): upgrade golang.org/x/crypto and x/net (@鈥媋ppleboy)
  • 2348539be2fbfc339c2d710cc36951b7a8e2ed6c: chore(deps): update dependencies and bump GitHub Actions (@鈥媋ppleboy)
  • 2f50fec1a5c22020f9aaf875895df22d062583eb: chore(deps): upgrade golang.org/x/crypto to v0.55.0 (#145) (@鈥媋ppleboy)

Build process updates

  • a1f042f4e3f120d6d40603e4aa5c253617b5b3c1: ci(actions): bump codecov/codecov-action from v5 to v6 (@鈥媋ppleboy)
  • 8a6445f62f187acb52cd7c9a69e1b0ff4bca24b3: ci(workflow): pin trivy-action to v0.35.0 tag (@鈥媋ppleboy)
  • 55c4f910369834e2e76a149da930acae78e9f968: ci(workflow): bump trivy-action from v0.35.0 to v0.36.0 (@鈥媋ppleboy)
  • f5623f0d4f280112afa5bbddf005d6e8ff6a161a: ci(lint): bump golangci-lint to v2.12 (@鈥媋ppleboy)
  • f597ceed4dcf0ebf9246ad76f3f7fe5d0b04585d: ci(actions): bump codecov/codecov-action from v6 to v7 (@鈥媋ppleboy)
  • cdef9ec81f5d3b055edcea5094a7de99c333e41e: ci(actions): bump actions/checkout from v6 to v7 (@鈥媋ppleboy)
  • ae5b21359aef62a01091f9e99ae062a5e49cca48: ci(actions): update Go test matrix (#144) (@鈥媋ppleboy)

Documentation updates

  • b21477d8547dc68fa4a66d9891b79586970841a7: docs(readme): remove Go Report Card badge (@鈥媋ppleboy)
  • 6da17507f2641a97677c93c7784cafd9ccbd5115: docs(readme): replace deprecated godoc.org links with pkg.go.dev (@鈥媋ppleboy)

Others

  • bc0be0034fb166d3c7d2b15912687a741e33ca5e: test: update decompression content length assertions (#143) (@鈥媋ppleboy)
  • c5c16498b556d4d789552d19c888a1c0dd214c64: test(static): make gzip size assertion robust on Go 1.27 (#146) (@鈥媋ppleboy)
Commits
  • c5c1649 test(static): make gzip size assertion robust on Go 1.27 (#146)
  • 2f50fec chore(deps): upgrade golang.org/x/crypto to v0.55.0 (#145)
  • ae5b213 ci(actions): update Go test matrix (#144)
  • bc0be00 test: update decompression content length assertions (#143)
  • 6da1750 docs(readme): replace deprecated godoc.org links with pkg.go.dev
  • b21477d docs(readme): remove Go Report Card badge
  • 2348539 chore(deps): update dependencies and bump GitHub Actions
  • 806cace chore(deps): upgrade golang.org/x/crypto and x/net
  • cdef9ec ci(actions): bump actions/checkout from v6 to v7
  • 2f8b8fb chore(deps): upgrade quic-go to v0.59.1
  • Additional commits viewable in compare view

Updates github.com/go-webauthn/webauthn from 0.17.4 to 0.18.0

Release notes

Sourced from github.com/go-webauthn/webauthn's releases.

v0.18.0

0.18.0 (2026-08-27)

This release is a fairly major milestone in the development of this library. It has quite a few breaking changes but has added support for most if not all of the extension requirements natively, and adds formal support for Post-Quantum Cryptography with support for ML-DSA-44, ML-DSA-65, and ML-DSA-87 when used with go 1.27.

Details on the migration requirements for this version can be found int https://github.com/go-webauthn/webauthn/blob/HEAD/MIGRATION.md as they are substantial between ths version and prior versions.

Bug Fixes

  • metadata: align members with mds 3.1.1 and ctap 2.3 (#739) (397152c)
  • metadata: consistent revocation policy and client timeouts (#740) (34d324b)
  • metadata: handle certificate chains of any depth (#737) (309ea69)
  • metadata: honour status report order and effective dates (#736) (8be5355)
  • metadata: mds3 parsing conformance and cache integrity (#735) (8115143)
  • metadata: prevent panic corrupt blob (#698) (c5fd013)
  • metadata: report malformed status report urls (#738) (ed82f7c)
  • protocol: allow any attestation eku (#728) (f4e33fc)
  • protocol: androidkey missing authorization list member (#727) (9b02b19)
  • protocol: androidkey union generated (#729) (3ed3e75)
  • protocol: bind credential public key curve to its algorithm (#752) (314c2be)
  • protocol: compound attestation sub-statement unmarshalling (#751) (a582ecf)
  • protocol: compound returns incorrect type (#731) (025d897)
  • protocol: credential public key match limited to ECDSA (#732) (b4df26e)
  • protocol: harden credential response and options handling (#763) (de0ae6c)
  • protocol: missing tpm steps (#725) (f9a63f9)
  • protocol: opaque origin matching and validation (#758) (37f065a)
  • protocol: possible panic conditions (#719) (0ea14e7)
  • protocol: safetynet validation steps (#726) (e12f6e8)
  • protocol: single signature encoding policy and canonical der (#744) (99bbbdb)
  • webauthncbor: reject data trailing the first cbor item (#762) (0801b5d)
  • webauthncose: validate okp key algorithm (#759) (98c528b)
  • webauthn: deprecations and handle check (#745) (8619bb9)
  • webauthn: include backup flag check in registration (#748) (26a4868)
  • webauthn: only update uv flag (#746) (b39c822)
  • webauthn: use session relying party id (#747) (ebb45e2)

Features

  • metadata: update to r46 anchor (#780) (20f33e6)
  • ml-dsa preference list and gated availability (#768) (db1e068)
  • protocol: client capability enumeration (#765) (62f4489)
  • protocol: compound sub-statement scope (#742) (34271da)
  • protocol: current user details signal constructor (#766) (b6db923)
  • protocol: ecdsa attestation signature encoding policy (#743) (29404e9), closes #710
  • protocol: related origins well-known document (#753) (05d54dc)
  • protocol: relying party attestation policy (#741) (3239ed0)

... (truncated)

Changelog

Sourced from github.com/go-webauthn/webauthn's changelog.

0.18.0 (2026-08-27)

This release is a fairly major milestone in the development of this library. It has quite a few breaking changes but has added support for most if not all of the extension requirements natively, and adds formal support for Post-Quantum Cryptography with support for ML-DSA-44, ML-DSA-65, and ML-DSA-87 when used with go 1.27.

Details on the migration requirements for this version can be found int [MIGRATION.md] as they are substantial between ths version and prior versions.

Bug Fixes

  • metadata: align members with mds 3.1.1 and ctap 2.3 (#739) (397152c)
  • metadata: consistent revocation policy and client timeouts (#740) (34d324b)
  • metadata: handle certificate chains of any depth (#737) (309ea69)
  • metadata: honour status report order and effective dates (#736) (8be5355)
  • metadata: mds3 parsing conformance and cache integrity (#735) (8115143)
  • metadata: prevent panic corrupt blob (#698) (c5fd013)
  • metadata: report malformed status report urls (#738) (ed82f7c)
  • protocol: allow any attestation eku (#728) (f4e33fc)
  • protocol: androidkey missing authorization list member (#727) (9b02b19)
  • protocol: androidkey union generated (#729) (3ed3e75)
  • protocol: bind credential public key curve to its algorithm (#752) (314c2be)
  • protocol: compound attestation sub-statement unmarshalling (#751) (a582ecf)
  • protocol: compound returns incorrect type (#731) (025d897)
  • protocol: credential public key match limited to ECDSA (#732) (b4df26e)
  • protocol: harden credential response and options handling (#763) (de0ae6c)
  • protocol: missing tpm steps (#725) (f9a63f9)
  • protocol: opaque origin matching and validation (#758) (37f065a)
  • protocol: possible panic conditions (#719) (0ea14e7)
  • protocol: safetynet validation steps (#726) (e12f6e8)
  • protocol: single signature encoding policy and canonical der (#744) (99bbbdb)
  • webauthncbor: reject data trailing the first cbor item (#762) (0801b5d)
  • webauthncose: validate okp key algorithm (#759) (98c528b)
  • webauthn: deprecations and handle check (#745) (8619bb9)
  • webauthn: include backup flag check in registration (#748) (26a4868)
  • webauthn: only update uv flag (#746) (b39c822)
  • webauthn: use session relying party id (#747) (ebb45e2)

Features

  • metadata: update to r46 anchor (#780) (20f33e6)
  • ml-dsa preference list and gated availability (#768) (db1e068)
  • protocol: client capability enumeration (#765) (62f4489)
  • protocol: compound sub-statement scope (#742) (34271da)
  • protocol: current user details signal constructor (#766) (b6db923)
  • protocol: ecdsa attestation signature encoding policy (#743) (29404e9), closes #710
  • protocol: related origins well-known document (#753) (05d54dc)
  • protocol: relying party attestation policy (#741) (3239ed0)
  • typed extension inputs and outputs (#734) (0661c81)

... (truncated)

Commits

Updates github.com/prometheus/client_model from 0.6.2 to 0.6.3

Release notes

Sourced from github.com/prometheus/client_model's releases.

v0.6.3

What's Changed

New Contributors

Full Changelog: prometheus/client_model@v0.6.2...v0.6.3

What's Changed

... (truncated)

Commits

Updates github.com/prometheus/common from 0.70.1 to 0.71.0

Release notes

Sourced from github.com/prometheus/common's releases.

v0.71.0

What's Changed

New Contributors

Full Changelog: prometheus/common@v0.70.1...v0.71.0

Commits
  • 9a4aff0 build(deps): bump github.com/stretchr/testify in /assets (#979)
  • 483bb89 Update dependabot config (#978)
  • d29e1ea build(deps): bump golang.org/x/net (#975)
  • e531bd2 build(deps): bump google.golang.org/protobuf from 1.36.11 to 1.36.12 (#976)
  • bc3fc3a build(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.1 (#977)
  • 15e9f45 expfmt: fix OpenMetrics 2.0 decoder error, format docs, and encoder version d...
  • 0acfdb3 expfmt: prevent st@ leaking to Gauge and Untyped samples in OpenMetrics 2.0 (...
  • eb72e27 model: add Duration unit constants and conversion methods (#952)
  • 67b7d90 fix: drop invalid OpenMetrics 2.0 exemplars instead of failing exposition (#970)
  • 715ac36 expfmt: format OpenMetrics 2.0 float values and validate units (#969)
  • Additional commits viewable in compare view

Updates golang.org/x/crypto from 0.55.0 to 0.56.0

Commits
  • 86efde5 ssh: reject unexpected message types on established channels
  • a6cdac6 ssh: drop traffic on undecided channels
  • 39dc44e ssh: don't skip the source-address critical option in CheckCert
  • afebf4c x509roots/fallback/bundle: make subjectsEqual stricter on Go 1.27+
  • 89f4e9b x509roots/fallback: update bundle
  • 71488c4 ssh/knownhosts: compare only public key portions for revocation
  • 82adefa ssh: synchronize unexpected response test
  • c757c98 all: upgrade go directive to at least 1.26.0 [generated]
  • 593c81a ssh: correctly ignore pre-banner lines
  • 46efc8b acme: add crypto.SignMessage test coverage
  • Additional commits viewable in compare view

Updates golang.org/x/sync from 0.22.0 to 0.23.0

Commits
  • f75267d semaphore: panic on negative capacity
  • 3ffd83c all: upgrade go directive to at least 1.26.0 [generated]
  • See full diff in compare view

Updates k8s.io/apimachinery from 0.36.4 to 0.37.0

Commits
  • 7164e39 Update dependencies to v0.37.0 tag
  • e55f9ba feat(api): Update node restriction admission to use new API
  • cb0680d Merge pull request #129125 from pohly/log-client-go-tools-apis
  • 97b2132 Merge pull request #140194 from gnufied/implement-volume-health-api
  • f21afab Add validation for camelcase in reason field
  • d7ad413 Merge pull request #140782 from dims/update-kube-openapi
  • e15ad7c Merge pull request #138808 from chenk008/cbor-streaminglist
  • 464b5d1 Update k8s.io/kube-openapi to v0.0.0-20260721132016-d427ff9ee9ad
  • 0de14ec Merge pull request #140732 from thockin/dv-add-prefixed-label-key

Bumps the go-deps group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/anthropics/anthropic-sdk-go](https://github.com/anthropics/anthropic-sdk-go) | `1.66.0` | `1.71.0` |
| [github.com/gin-contrib/gzip](https://github.com/gin-contrib/gzip) | `1.2.6` | `1.2.7` |
| [github.com/go-webauthn/webauthn](https://github.com/go-webauthn/webauthn) | `0.17.4` | `0.18.0` |
| [github.com/prometheus/client_model](https://github.com/prometheus/client_model) | `0.6.2` | `0.6.3` |
| [github.com/prometheus/common](https://github.com/prometheus/common) | `0.70.1` | `0.71.0` |
| [golang.org/x/crypto](https://github.com/golang/crypto) | `0.55.0` | `0.56.0` |
| [golang.org/x/sync](https://github.com/golang/sync) | `0.22.0` | `0.23.0` |
| [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) | `0.36.4` | `0.37.0` |
| [sigs.k8s.io/gateway-api](https://github.com/kubernetes-sigs/gateway-api) | `1.6.1` | `1.6.2` |



Updates `github.com/anthropics/anthropic-sdk-go` from 1.66.0 to 1.71.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-go/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-go/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-go@v1.66.0...v1.71.0)

Updates `github.com/gin-contrib/gzip` from 1.2.6 to 1.2.7
- [Release notes](https://github.com/gin-contrib/gzip/releases)
- [Commits](gin-contrib/gzip@v1.2.6...v1.2.7)

Updates `github.com/go-webauthn/webauthn` from 0.17.4 to 0.18.0
- [Release notes](https://github.com/go-webauthn/webauthn/releases)
- [Changelog](https://github.com/go-webauthn/webauthn/blob/master/CHANGELOG.md)
- [Commits](go-webauthn/webauthn@v0.17.4...v0.18.0)

Updates `github.com/prometheus/client_model` from 0.6.2 to 0.6.3
- [Release notes](https://github.com/prometheus/client_model/releases)
- [Commits](prometheus/client_model@v0.6.2...v0.6.3)

Updates `github.com/prometheus/common` from 0.70.1 to 0.71.0
- [Release notes](https://github.com/prometheus/common/releases)
- [Changelog](https://github.com/prometheus/common/blob/main/CHANGELOG.md)
- [Commits](prometheus/common@v0.70.1...v0.71.0)

Updates `golang.org/x/crypto` from 0.55.0 to 0.56.0
- [Commits](golang/crypto@v0.55.0...v0.56.0)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](golang/sync@v0.22.0...v0.23.0)

Updates `k8s.io/apimachinery` from 0.36.4 to 0.37.0
- [Commits](kubernetes/apimachinery@v0.36.4...v0.37.0)

Updates `k8s.io/streaming` from 0.36.4 to 0.37.0
- [Commits](kubernetes/streaming@v0.36.4...v0.37.0)

Updates `sigs.k8s.io/gateway-api` from 1.6.1 to 1.6.2
- [Release notes](https://github.com/kubernetes-sigs/gateway-api/releases)
- [Changelog](https://github.com/kubernetes-sigs/gateway-api/blob/main/RELEASE.md)
- [Commits](kubernetes-sigs/gateway-api@v1.6.1...v1.6.2)

---
updated-dependencies:
- dependency-name: github.com/anthropics/anthropic-sdk-go
  dependency-version: 1.71.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/gin-contrib/gzip
  dependency-version: 1.2.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/go-webauthn/webauthn
  dependency-version: 0.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/prometheus/client_model
  dependency-version: 0.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/prometheus/common
  dependency-version: 0.71.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: golang.org/x/crypto
  dependency-version: 0.56.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: k8s.io/streaming
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: sigs.k8s.io/gateway-api
  dependency-version: 1.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants