Skip to content

fix(deps): update go modules (minor/patch) - #52

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-modules-(minorpatch)
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-modules-(minorpatch)

Conversation

@renovate

@renovate renovate Bot commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence Type Update
github.com/getkin/kin-openapi v0.144.0 → v0.149.0 age confidence require minor
github.com/go-chi/chi/v5 v5.3.1 → v5.3.2 age confidence require patch
github.com/openchami/fabrica v0.4.10 → v0.4.11 age confidence require patch
github.com/openchami/tokensmith v0.4.1 → v0.4.2 age confidence require patch
github.com/stretchr/testify v1.11.1 → v1.12.1 age confidence require minor
go (source) 1.26.5 → 1.27.1 age confidence golang minor

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

getkin/kin-openapi (github.com/getkin/kin-openapi)

v0.149.0

Compare Source

What's Changed

Full Changelog: getkin/kin-openapi@v0.148.0...v0.149.0

v0.148.0

Compare Source

What's Changed

New Contributors

Full Changelog: getkin/kin-openapi@v0.147.0...v0.148.0

v0.147.0

Compare Source

What's Changed

New Contributors

Full Changelog: getkin/kin-openapi@v0.146.0...v0.147.0

v0.146.0

Compare Source

What's Changed

Full Changelog: getkin/kin-openapi@v0.145.0...v0.146.0

v0.145.0

Compare Source

What's Changed

Full Changelog: getkin/kin-openapi@v0.144.0...v0.145.0

go-chi/chi (github.com/go-chi/chi/v5)

v5.3.2

Compare Source

What's Changed

  • feat(middleware): add text/markdown, text/csv, text/vtt to default compressible types by @​VojtechVitek in #​1151
  • docs: deployment recipe for middleware.ClientIPFromXFFTrustedProxies() by @​VojtechVitek in #​1111
  • fix: don't drop handlers that collide with a Mount()/Route() pattern by @​VojtechVitek in #​1148
  • Don't duplicate methods in Allow: header for 405 responses by @​flimzy in #​1029
  • fix(middleware): reject catch-all compress wildcards by @​VojtechVitek in #​1156
    • middleware.NewCompressor(level, "/*") never worked and silently compressed nothing. Instead of turning it into a compress-everything catch-all (as proposed in #​868 and #​1121), we decided to reject both "/" and "/*" at construction and panic. Compressing every response wastes CPU on already-compressed types (zip, jpeg, png), which is why the middleware keeps a curated default list. Users should pass explicit content types.

Full Changelog: go-chi/chi@v5.3.1...v5.3.2

openchami/fabrica (github.com/openchami/fabrica)

v0.4.11

Compare Source

Fabrica 0.4.11

Release Date: 2026-09-24T19:07:57Z

Installation
Installer (Linux and macOS)
curl -fsSL https://github.com/openchami/fabrica/releases/latest/download/install.sh | sh
Binaries

Download the appropriate binary for your platform from the assets below.

Docker
docker pull ghcr.io/openchami/fabrica:0.4.11
Go Install
go install github.com/openchami/fabrica/cmd/fabrica@v0.4.11

Changelog

  • f068837 chore(deps): update actions/setup-go action to v7 (#​108)
  • 18e67fe chore(deps): update github-actions (minor/patch) (#​88)
  • 0cfffe3 chore(reuse): fix copyright (#​113)
  • 809a6ed feat(annotations): define dedicated storage annotation contract (#​98)
  • e045ede feat(codegen): add optional resource emitter extension (#​104)
  • 53b0071 feat(codegen): emit dedicated Ent schema annotations (#​99)
  • 9306bbc feat(codegen): map Go fields to Ent field types (#​100)
  • aa38d7c feat(codegen): support project-owned custom storage (#​106)
  • 08af6ad fix(annotations): make resource parsing order-independent and complete (#​97)
  • 29b6028 fix(codegen): hash by column name, and register Ent's runtime (#​103)
  • a4bd044 fix(deps): update go modules (minor/patch) (#​89)
  • 73e4934 test(codegen): cover generic Ent schemas and adapter (#​102)
  • 7f9592b test(codegen): preserve supplemental Ent schemas (#​105)
  • a9702d9 test(codegen): prove generated dedicated Ent schemas compile (#​101)

Full Changelog: OpenCHAMI/fabrica@v0.4.10...v0.4.11

openchami/tokensmith (github.com/openchami/tokensmith)

v0.4.2

Compare Source

GPG Signature Verification

Each RPM in this release is signed with a short-lived ephemeral key that
is certified by the repository signing key, which is itself certified by
the OpenCHAMI offline master key.

Trust chain
offline master key
    └─[certifies]─> repo key
                        └─[certifies]─> ephemeral key (v0.4.2)
                                            └─[signs]─> RPM files
How to verify
  1. Download repo-cert.pub.asc and ephemeral.pub.asc from this release.
  2. Import both keys:
    gpg --import repo-public.asc ephemeral-public.asc
  3. Verify each RPM:
    rpm --checksig *.rpm
  4. For full chain verification (requires the master public key):
    curl -LO \
      https://raw.githubusercontent.com/OpenCHAMI/gpg-signing-manager/main/scripts/verify-chain.sh
    bash verify-chain.sh \
      --master    master.pub.asc \
      --repo      repo-cert.pub.asc \
      --ephemeral ephemeral.pub.asc \
      --rpm       *.rpm
stretchr/testify (github.com/stretchr/testify)

v1.12.1

Compare Source

This is the first release which has the minimum dependencies practical in testify v1. The last remaining dependencies are github.com/stretchr/objx which itself has no dependencies, and go.yaml.in/yaml/v3. Removing objx would require v2, it cannot be vendored. Removing YAML would require vendoring the yaml library, which would do more harm than good. It's better to become aware of vulnerabilities in the official yaml package than to attempt to maintain our own.

What's Changed
New Contributors

Full Changelog: stretchr/testify@v1.12.0...v1.12.1

What's Changed
New Contributors

Full Changelog: stretchr/testify@v1.12.0...v1.12.1

v1.12.0

Compare Source

What's Changed

Functional Changes
Fixes
Documentation, Build & CI

New Contributors

Full Changelog: stretchr/testify@v1.11.0...v1.12.0

What's Changed

New Contributors

Full Changelog: stretchr/testify@v1.11.0...v1.12.0

golang/go (go)

v1.27.1

v1.27.0

v1.26.8

v1.26.7

v1.26.6


Configuration

📅 Schedule: (in timezone America/Denver)

  • Branch creation
    • "before 5am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file renovate labels Aug 24, 2026
@renovate
renovate Bot force-pushed the renovate/go-modules-(minorpatch) branch 10 times, most recently from f62fcde to 973b53b Compare August 30, 2026 08:36
@renovate

renovate Bot commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 4 additional dependencies were updated

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=3 days

Details:

Package Change
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 -> v6.0.3
go.yaml.in/yaml/v3 v3.0.4 -> v3.0.5
golang.org/x/text v0.40.0 -> v0.41.0
golang.org/x/time v0.12.0 -> v0.15.0

@renovate
renovate Bot force-pushed the renovate/go-modules-(minorpatch) branch 8 times, most recently from cda9b54 to d63338e Compare September 4, 2026 02:35
@renovate
renovate Bot force-pushed the renovate/go-modules-(minorpatch) branch 2 times, most recently from 96d53ab to f76e40b Compare September 21, 2026 21:49
@renovate
renovate Bot force-pushed the renovate/go-modules-(minorpatch) branch from f76e40b to 6494367 Compare September 27, 2026 22:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file renovate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants