Bump the minor-patch group across 2 directories with 2 updates#410
Bump the minor-patch group across 2 directories with 2 updates#410dependabot[bot] wants to merge 2 commits intomainfrom
Conversation
|
@kommendorkapten Due to decisions made in #384, we intend to continue supporting go 1.22 until sigstore-go 1.0. We need to decline the upgrade to go-containerregistry until google/go-containerregistry#2047 is merged. |
|
@codysoyland Oh, nice. I missed that. |
|
We also discussed going back to that contributor and discussing this. Trying to fight dependabot up to and past 1.0 is not a great use of maintainer time unfortunately. |
|
@dependabot ignore github.com/google/go-containerregistry 0.20.3 |
|
I think the chat command I just sent should prevent dependabot from reopening this specific update for go-containerregistry again. Hopefully this will save us some time. |
|
@dependabot recreate |
Bumps the minor-patch group with 2 updates in the / directory: [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) and [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry). Bumps the minor-patch group with 2 updates in the /examples/oci-image-verification directory: [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) and [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry). Updates `github.com/sigstore/sigstore` from 1.8.12 to 1.8.14 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.8.12...v1.8.14) Updates `github.com/google/go-containerregistry` from 0.20.2 to 0.20.3 - [Release notes](https://github.com/google/go-containerregistry/releases) - [Changelog](https://github.com/google/go-containerregistry/blob/main/.goreleaser.yml) - [Commits](google/go-containerregistry@v0.20.2...v0.20.3) Updates `github.com/sigstore/sigstore` from 1.8.12 to 1.8.14 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.8.12...v1.8.14) Updates `github.com/google/go-containerregistry` from 0.20.2 to 0.20.3 - [Release notes](https://github.com/google/go-containerregistry/releases) - [Changelog](https://github.com/google/go-containerregistry/blob/main/.goreleaser.yml) - [Commits](google/go-containerregistry@v0.20.2...v0.20.3) --- updated-dependencies: - dependency-name: github.com/sigstore/sigstore dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/google/go-containerregistry dependency-type: indirect update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/sigstore dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/google/go-containerregistry dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
c71c3de to
e122e46
Compare
Signed-off-by: Cody Soyland <codysoyland@github.com>
|
@dependabot ignore github.com/google/go-containerregistry patch version |
|
OK, I won't notify you about version 0.20.3 of github.com/google/go-containerregistry again, unless you unignore it. |
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Pull request was closed
Bumps the minor-patch group with 2 updates in the / directory: github.com/sigstore/sigstore and github.com/google/go-containerregistry.
Bumps the minor-patch group with 2 updates in the /examples/oci-image-verification directory: github.com/sigstore/sigstore and github.com/google/go-containerregistry.
Updates
github.com/sigstore/sigstorefrom 1.8.12 to 1.8.14Release notes
Sourced from github.com/sigstore/sigstore's releases.
Commits
351b102export variable (#1978)0a1ec6fbuild(deps): Bump golang.org/x/oauth2 in /pkg/signature/kms/gcp (#1973)a806b7ebuild(deps): Bump github.com/hashicorp/vault/api (#1974)a235f11build(deps): Bump localstack/localstack in /test/e2e in the all group (#1965)a883eafcliplugin: convert module to package only (#1956)4f6e90czizmor fixes (#1960)cb6fcc5run lint across all submodules (#1959)750295fcliplugin: lint fixes (#1958)67bd820cliplugin: semver, add tests for hash func encoding (#1948)c5b7d21cliplugin: use caller contexts (#1947)Updates
github.com/google/go-containerregistryfrom 0.20.2 to 0.20.3Release notes
Sourced from github.com/google/go-containerregistry's releases.
Commits
c4dd792bump deps using hack/bump-deps.sh (#2042)6bce25eDetect zstd in crane append (#2023)06dcd85mutate: Create a defensive annotations copy (#2030)a9a53a8check for 406 status code when handling referrers endpoint response (#2026)4630c40don't pin chainguard-dev/actions (#2025)808e354bump actions to latest (#2011)a07d1cafix: redact.URL uses (*URL).Redacted to omit basic-auth password (#1947)00f182bExpose compare package (#2001)b8e87edremote/transport: Make bearer transport go-routine-safe (#1806)Updates
github.com/sigstore/sigstorefrom 1.8.12 to 1.8.14Release notes
Sourced from github.com/sigstore/sigstore's releases.
Commits
351b102export variable (#1978)0a1ec6fbuild(deps): Bump golang.org/x/oauth2 in /pkg/signature/kms/gcp (#1973)a806b7ebuild(deps): Bump github.com/hashicorp/vault/api (#1974)a235f11build(deps): Bump localstack/localstack in /test/e2e in the all group (#1965)a883eafcliplugin: convert module to package only (#1956)4f6e90czizmor fixes (#1960)cb6fcc5run lint across all submodules (#1959)750295fcliplugin: lint fixes (#1958)67bd820cliplugin: semver, add tests for hash func encoding (#1948)c5b7d21cliplugin: use caller contexts (#1947)Updates
github.com/google/go-containerregistryfrom 0.20.2 to 0.20.3Release notes
Sourced from github.com/google/go-containerregistry's releases.
Commits
c4dd792bump deps using hack/bump-deps.sh (#2042)6bce25eDetect zstd in crane append (#2023)06dcd85mutate: Create a defensive annotations copy (#2030)a9a53a8check for 406 status code when handling referrers endpoint response (#2026)4630c40don't pin chainguard-dev/actions (#2025)808e354bump actions to latest (#2011)a07d1cafix: redact.URL uses (*URL).Redacted to omit basic-auth password (#1947)00f182bExpose compare package (#2001)b8e87edremote/transport: Make bearer transport go-routine-safe (#1806)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions