build(deps): bump golang.org/x/text from 0.40.0 to 0.41.0 - #283
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [golang.org/x/text](https://github.com/golang/text) from 0.40.0 to 0.41.0. - [Release notes](https://github.com/golang/text/releases) - [Commits](golang/text@v0.40.0...v0.41.0) --- updated-dependencies: - dependency-name: golang.org/x/text dependency-version: 0.41.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…11.8 (#330) Supersedes #281, #282, #283 and #284. Closing those four in favour of this one. They had been open since 2026-08-17, and two of them would have landed a repository that was already behind on the day it merged: #281 proposes `golang.org/x/crypto` v0.55.0 when v0.56.0 is out, and #284 pins the nine examples to `authcore` v1.11.7 when v1.11.8 shipped this morning. Re-landing the same four bumps at the versions that are actually current costs one branch and avoids merging a correction that needs correcting. ### What moves Root, still five direct dependencies: | Module | From | To | |---|---|---| | `golang.org/x/crypto` | v0.54.0 | v0.56.0 | | `golang.org/x/net` | v0.57.0 | v0.58.0 | | `golang.org/x/text` | v0.40.0 | v0.41.0 | Examples: `authcore` v1.11.6 to v1.11.8 in all nine, and `gofiber/fiber/v3` v3.4.0 to v3.5.0 in the fiber example, which carries `fasthttp`, `klauspost/compress` and `mattn/go-isatty` with it. `gin` was already on v1.12.0, the current release. ### What I measured | Check | Result | |---|---| | `govulncheck ./...` | exit 0, **No vulnerabilities found** | | `go test -race ./...` | 9/9 packages pass | | Nine examples, `go build && go vet` | 9/9 pass, one package each | | `go` directive, all 11 module files | untouched at 1.26.6 | One latent entry remains, in a module I require but do not call: the standing `GO-2026-5932` advisory that `x/crypto/openpgp` is unmaintained and unsafe by design, `Fixed in: N/A`, applying to every version of the module since 0. Nothing here imports `openpgp`. ### Three files this deliberately does not add `go mod tidy` under `GOWORK=off` wrote a `go.sum` into the apikey, basic and username examples, which have never carried one. Those three depend on nothing but `authcore`, and the workspace resolves it from the checkout, so there is no hash to record. I deleted them and confirmed all three still build and vet. Committing them would add three files that every future bump has to keep in step, which is the coupling the workspace removed. ### Release This changes a dependency floor, which the releases standard counts as something a consumer receives, so it wants a tag rather than sitting on `develop`. It is not urgent the way #328 was: `govulncheck` was already clean at v1.11.8, so nothing here closes an open advisory. Signed-off-by: Jaro-c <75870284+Jaro-c@users.noreply.github.com>
|
Superseded by #330, which landed the same bumps at the versions that are current today. Two of these had gone stale: this one proposed a version that has since been overtaken, or pinned the examples to an |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps golang.org/x/text from 0.40.0 to 0.41.0.
Commits
acdba66go.mod: update golang.org/x dependencies02aa981secure/precis: fix short destination buffer handling in Nickname profileDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)