Skip to content

fix(deps): bump the external group across 1 directory with 33 updates - #4050

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/service/external-53652d1dcd
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/service/external-53652d1dcd

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the external group with 33 updates in the /service directory:

Package From To
buf.build/go/protovalidate 1.0.0 1.4.0
connectrpc.com/connect 1.20.0 1.21.0
connectrpc.com/validate 0.6.0 0.7.0
github.com/casbin/casbin/v2 2.108.0 2.135.0
github.com/creasty/defaults 1.8.0 1.11.0
github.com/dgraph-io/ristretto/v2 2.4.0 2.4.2
github.com/eko/gocache/lib/v4 4.2.0 4.4.0
github.com/eko/gocache/store/ristretto/v4 4.3.2 4.3.8
github.com/fsnotify/fsnotify 1.9.0 1.10.1
github.com/go-chi/cors 1.2.1 1.2.2
github.com/go-playground/validator/v10 10.26.0 10.30.5
github.com/go-viper/mapstructure/v2 2.4.0 2.5.0
github.com/jackc/pgx/v5 5.9.2 5.11.0
github.com/lib/pq 1.10.9 1.12.3
github.com/mattn/go-sqlite3 1.14.48 1.14.52
github.com/open-policy-agent/opa 1.5.1 1.20.2
github.com/pressly/goose/v3 3.24.3 3.28.0
github.com/spf13/cobra 1.9.1 1.10.2
github.com/spf13/viper 1.20.1 1.21.0
github.com/stretchr/testify 1.11.1 1.12.1
github.com/testcontainers/testcontainers-go 0.42.0 0.44.0
go.opentelemetry.io/otel 1.45.0 1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace 1.45.0 1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc 1.45.0 1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp 1.45.0 1.46.0
go.opentelemetry.io/otel/exporters/stdout/stdouttrace 1.45.0 1.46.0
go.opentelemetry.io/otel/sdk 1.45.0 1.46.0
go.opentelemetry.io/otel/trace 1.45.0 1.46.0
golang.org/x/net 0.58.0 0.59.0
google.golang.org/grpc 1.83.2 1.84.0
google.golang.org/protobuf 1.36.11 1.36.12
github.com/go-ldap/ldap/v3 3.4.12 3.4.14
golang.org/x/text 0.41.0 0.42.0

Updates buf.build/go/protovalidate from 1.0.0 to 1.4.0

Release notes

Sourced from buf.build/go/protovalidate's releases.

v1.4.0

What's Changed

Full Changelog: bufbuild/protovalidate-go@v1.3.0...v1.4.0

v1.3.0

This release adds support for Native standard validation rules which greatly improve evaluation performance. See bufbuild/protovalidate-go#316 for more details.

What's Changed

New Contributors

Full Changelog: bufbuild/protovalidate-go@v1.2.0...v1.3.0

v1.2.0

This release is compatible with the v1.2.0 release of Protovalidate.

What's Changed

New Contributors

Full Changelog: bufbuild/protovalidate-go@v1.1.3...v1.2.0

v1.1.3

What's Changed

Full Changelog: bufbuild/protovalidate-go@v1.1.2...v1.1.3

... (truncated)

Commits
  • 5c72b38 Bump buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go from 1.36.12-...
  • aa3ed84 Update deps and minimum Go version to 1.26 (#337)
  • ff9e432 Bump github.com/stretchr/testify from 1.12.0 to 1.12.1 in the go group (#336)
  • 99a2379 Bump the go group with 4 updates (#334)
  • 0e5a75c Use CEL PartialVars during AST pruning (#333)
  • 373085b Exclude the trailing dot from the hostname 253-character limit (#332)
  • 37b55cc Bump github.com/google/cel-go from 0.29.2 to 0.30.0 in the go group (#331)
  • f360e52 Bump actions/setup-go from 6 to 7 in the github-actions group (#330)
  • 9292b3d Bump the go group with 2 updates (#329)
  • 24f3f25 Bump github.com/google/cel-go from 0.28.1 to 0.29.1 in the go group (#328)
  • Additional commits viewable in compare view

Updates connectrpc.com/connect from 1.20.0 to 1.21.0

Release notes

Sourced from connectrpc.com/connect's releases.

v1.21.0

What's Changed

[!IMPORTANT]

This release adds a security-related feature for servers. The new handler option WithRequestGate runs after the request headers are available and before any message is received. Use this new option to register checks (e.g. authentication) that should happen before the request is decompressed or unmarshaled, and before any interceptors are run. See the documentation for details.

Governance

Enhancements

Bugfixes

New Contributors

Full Changelog: connectrpc/connect-go@v1.20.0...v1.21.0

Commits
  • 41b7f30 Prepare for v1.21.0 (#972)
  • 6058c20 Fix dropped headers on errStreamingClientConn (#964)
  • 014693a Refine WithRequestGate API and documentation (#968)
  • d9b4b1d Create release binary for protoc-gen-connect-go (#966)
  • 5111260 Add WithRequestGate handler option (#962)
  • febfc19 Fix panic in stream Spec and Peer when client construction failed (#959)
  • cb5da57 Update Go version for CI (#958)
  • 9646326 Only send a 304 when the request was a GET (#957)
  • 2a02fea Fix connect.WithGRPC typo in the missing client option error (#956)
  • eae42d2 Fix off-by-one in WithHTTPGetMaxURLSize URL length check (#955)
  • Additional commits viewable in compare view

Updates connectrpc.com/validate from 0.6.0 to 0.7.0

Release notes

Sourced from connectrpc.com/validate's releases.

v0.7.0

What's Changed

Governance

Other changes

Full Changelog: connectrpc/validate-go@v0.6.0...v0.7.0

Commits

Updates github.com/casbin/casbin/v2 from 2.108.0 to 2.135.0

Release notes

Sourced from github.com/casbin/casbin/v2's releases.

v2.135.0

2.135.0 (2025-12-09)

Features

  • remove Travis script and issue templates (5fc9fd8)

v2.134.0

2.134.0 (2025-11-14)

Features

  • fix inconsistent backslash handling between matcher literals and CSV-parsed values (#1577) (5d3134d)

v2.133.0

2.133.0 (2025-11-14)

Features

  • fix stale g() function cache in BuildRoleLinks causing incorrect permissions (#1580) (0a13664)

v2.132.0

2.132.0 (2025-11-04)

Features

v2.131.0

2.131.0 (2025-11-02)

Features

  • fix EscapeAssertion (matcher) incorrectly matching p./r. patterns inside quoted strings (#1572) (1eef59a)

v2.130.0

2.130.0 (2025-11-01)

Features

  • fix duplicate CI workflow runs and optimize to test only Go 1.21 (#1571) (bb1e443)

v2.129.0

2.129.0 (2025-11-01)

... (truncated)

Commits
  • 5fc9fd8 feat: remove Travis script and issue templates
  • 5d3134d feat: fix inconsistent backslash handling between matcher literals and CSV-pa...
  • 0a13664 feat: fix stale g() function cache in BuildRoleLinks causing incorrect permis...
  • 4b6c4c8 feat: improve README
  • 1eef59a feat: fix EscapeAssertion (matcher) incorrectly matching p./r. patterns insid...
  • bb1e443 feat: fix duplicate CI workflow runs and optimize to test only Go 1.21 (#1571)
  • 91b9cf2 feat: add OrBAC (Organisation-Based Access Control) model support (#1567)
  • 87e9956 feat: add ContextEnforcer: add ctx to AddPolicy and other APIs (#1553)
  • 1ef00ac feat: enable concurrent transactions using optimistic locking, versioning and...
  • 0c5a574 feat: add PBAC model support and test (#1548)
  • Additional commits viewable in compare view

Updates github.com/creasty/defaults from 1.8.0 to 1.11.0

Release notes

Sourced from github.com/creasty/defaults's releases.

v1.11.0

v1.10.0 ended with six known issues. This release fixes three of them — data with a cycle crashed the process, a SetDefaults ran after an unmarshaler had taken the tag, and a failed default left part of itself behind — and half of a fourth: Set no longer writes to a map of slices or maps. The other two, and the rest of the fourth, stay as they are, now documented as intended. The API is unchanged, and so is go.mod.

Behavior changes come first, as before. Two of them can change what a working program does, and neither announces itself: one stops a SetDefaults call, and the other changes what Set leaves behind when it returns an error.

[BREAKING] SetDefaults is skipped behind a pointer once an unmarshaler took the tag (#97)

The README says that when a tag is handed to UnmarshalText, SetDefaults is not called. v1.10.0 made that hold for a struct, behind a pointer or not, and listed the rest as a known issue: a pointer to any other type still got SetDefaults after its unmarshaler took the tag. It no longer does:

type Level int
func (l *Level) UnmarshalText(b []byte) error {
n, err := strconv.Atoi(string(b))
if err != nil {
return err
}
*l = Level(n)
return nil
}
func (l *Level) SetDefaults() { *l += 100 }
type Config struct {
Level *Level default:"3" // v1.10.0: 103. v1.11.0: 3.
}

a field of that Level, left zero v1.10.0 v1.11.0
*Level default:"3" 103 3
**Level default:"3" 103 3
embedded *Level default:"3" 103 3
*Level, with UnmarshalJSON in place of UnmarshalText 103 3
*Level default:"", which no unmarshaler is offered 100 100
*Level default:"0x10", which UnmarshalText rejects and parsing by kind takes 116 116
Level default:"3" 3 3

Nothing reports the missing call. How to tell whether you are affected: look for a type that is not a struct — a named int, string or slice — with both SetDefaults and UnmarshalText or UnmarshalJSON, behind a pointer a tag allocates. If its SetDefaults adjusted what the unmarshaler produced, that adjustment is gone; make it in the unmarshaler instead. A field of the type itself never got the call, and a pointer the caller allocated is still left alone.

[BREAKING] A failed default no longer leaves part of itself behind (#98)

When a default failed, Set returned the error but kept what it had filled on the way down. The value was then no longer zero, so a second Set could skip the tag and return nil, which v1.10.0 listed as a known issue for *scalar, *[]T and *map fields. Now each value Set found zero on the way to the failing default is put back to zero, whatever part of the default it had taken:

after Set returned the error v1.10.0 v1.11.0
*int default:"eighty" &0, and a second Set returns nil nil, and a second Set returns the error again
*[]string default:"[1]" &[], and a second Set returns nil nil, and a second Set returns the error again
a struct field default:"{\"X\": 1, \"Y\": \"two\"}" {X:1 Y:0} {X:0 Y:0}
an untagged struct field whose A took 7 before B failed {A:7 B:0} {A:0 B:0}

... (truncated)

Commits
  • 10a16ef refactor: read tag.value in fillField rather than aliasing it (#112)
  • 08a42cd refactor: move the internal packages back into files (#111)
  • 5012535 refactor: move the unmarshaler handoff to internal/unmarshal (#110)
  • 120766a Move the promoted-method check to internal/method (#109)
  • dc07feb perf: check a value deep in the path against an index, not a scan (#108)
  • 702f9a4 perf: skip joining the int64 parsers' errors for an empty tag (#107)
  • 31d8cbc test: pin a caller's pointer to a slice, map or pointer as a QUIRK (#106)
  • 6852e14 fix: store only a struct copy back into the map holding it (#105)
  • 6545f75 fix: end a cycle in the caller's data instead of overflowing the stack (#104)
  • b9efcfb perf: skip walking a slice or map whose elements cannot hold defaults (#103)
  • Additional commits viewable in compare view

Updates github.com/dgraph-io/ristretto/v2 from 2.4.0 to 2.4.2

Release notes

Sourced from github.com/dgraph-io/ristretto/v2's releases.

v2.4.2

Fixed

  • Revert eager pre-allocation of the sampledLFU keyCosts map (#482), which allocated NumCounters/10 map buckets at boot and caused a large RSS regression for caches with high NumCounters (#494, fixes #493)

Full Changelog: dgraph-io/ristretto@v2.4.1...v2.4.2

v2.4.1

Changed

  • Pre-allocate keyCosts map in sampledLFU (#482)

Fixed

  • Handle mremap size mismatch on Linux s390x (#491)

Full Changelog: dgraph-io/ristretto@v2.4.0...v2.4.1

Changelog

Sourced from github.com/dgraph-io/ristretto/v2's changelog.

[v2.4.2] - 2026-07-07

Fixed

  • Revert eager pre-allocation of the sampledLFU keyCosts map (#482), which allocated NumCounters/10 map buckets at boot and caused a large RSS regression for caches with high NumCounters

Full Changelog: dgraph-io/ristretto@v2.4.1...v2.4.2

[v2.4.1] - 2026-07-06

Changed

  • Pre-allocate keyCosts map in sampledLFU (#482)

Fixed

  • Handle mremap size mismatch on Linux s390x (#491)

Full Changelog: dgraph-io/ristretto@v2.4.0...v2.4.1

Commits
  • 8d05e8a fix: revert eager sampledLFU keyCosts pre-allocation (#482) (#494)
  • e89d89a chore: prepare release v2.4.1 (#492)
  • fe05eab fix: handle mremap size mismatch on Linux s390x
  • bb27952 chore(ci): add stale Action (#488)
  • 7aac03a docs: add contributing guide and code of conduct
  • b483e0c perf: pre-allocate keyCosts map in sampledLFU
  • 469a1a0 Update trunk conf
  • 3ac041b chore: update ci-ristretto-tests.yml
  • See full diff in compare view

Updates github.com/eko/gocache/lib/v4 from 4.2.0 to 4.4.0

Release notes

Sourced from github.com/eko/gocache/lib/v4's releases.

lib/v4.4.0

What's Changed

✨ Features

  • Added a generic marshaler cache usable as a CacheInterface
  • Added SetIfNotExists method on cache and stores (fixes #297)
  • Added Valkey store support

🐛 Bug Fixes

  • Fixed blocking metrics recording and unsupported value types on rueidis and valkey
  • Fixed store versions tagging and valkey module

📚 Documentation

  • Added Valkey store in README documentation
  • Added stores compatibility table and fixed README examples

🔧 Maintenance

  • Updated stores lib version

Full Changelog: eko/gocache@lib/v4.2.5...lib/v4.4.0

store/ristretto/v4.3.5

What's Changed

Full Changelog: eko/gocache@lib/v4.2.3...store/ristretto/v4.3.5

store/redis/v4.2.9

What's Changed

Full Changelog: eko/gocache@lib/v4.2.3...store/redis/v4.2.9

store/bigcache/v4.2.7

What's Changed

Full Changelog: eko/gocache@lib/v4.2.3...store/bigcache/v4.2.7

store/freecache/v4.2.7

What's Changed

Full Changelog: eko/gocache@lib/v4.2.3...store/freecache/v4.2.7

store/go_cache/v4.2.7

... (truncated)

Commits
  • 515e65d Added a generic marshaler cache usable as a CacheInterface
  • e286176 Updated stores lib version
  • 5b2f4a6 Added stores compatibility table and fixed README examples
  • 7e91164 Fixed blocking metrics recording and unsupported value types on rueidis and v...
  • b9ff57f Added SetIfNotExists method on cache and stores (fixes #297)
  • a32e33c Added Valkey store in README documentation
  • 659352b Fixed store versions tagging and valkey module
  • 2aa1081 Updated stores lib version
  • ae22e74 Fixed some issues
  • 05a8479 Merge pull request #310 from eko/dependabot/go_modules/store/pegasus/golang.o...
  • Additional commits viewable in compare view

Updates github.com/eko/gocache/store/ristretto/v4 from 4.3.2 to 4.3.8

Release notes

Sourced from github.com/eko/gocache/store/ristretto/v4's releases.

store/ristretto/v4.3.5

What's Changed

Full Changelog: eko/gocache@lib/v4.2.3...store/ristretto/v4.3.5

Commits
  • bbced83 Updated stores lib version
  • 515e65d Added a generic marshaler cache usable as a CacheInterface
  • e286176 Updated stores lib version
  • 5b2f4a6 Added stores compatibility table and fixed README examples
  • 7e91164 Fixed blocking metrics recording and unsupported value types on rueidis and v...
  • b9ff57f Added SetIfNotExists method on cache and stores (fixes #297)
  • a32e33c Added Valkey store in README documentation
  • 659352b Fixed store versions tagging and valkey module
  • 2aa1081 Updated stores lib version
  • ae22e74 Fixed some issues
  • Additional commits viewable in compare view

Updates github.com/fsnotify/fsnotify from 1.9.0 to 1.10.1

Release notes

Sourced from github.com/fsnotify/fsnotify's releases.

v1.10.1

Changes and fixes

  • inotify: don't remove sibling watches sharing a path prefix (#754)

  • inotify, windows: don't rename sibling watches sharing a path prefix (#755)

#754: fsnotify/fsnotify#754 #755: fsnotify/fsnotify#755

v1.10.0

This version of fsnotify needs Go 1.23.

Changes and fixes

  • inotify: improve initialization error message (#731)

  • inotify: send Rename event if recursive watch is renamed (#696)

  • inotify: avoid copying event buffers when reading names (#741)

  • kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a bad entry no longer aborts Watcher.Add for the whole directory (#748)

  • kqueue: drop watches directly in Close() to fix a file descriptor leak when recycling watchers (#740)

  • windows: fix nil pointer dereference in remWatch (#736)

  • windows: lock watch field updates against concurrent WatchList to fix a race introduced in v1.9.0 (#709, #749)

#696: fsnotify/fsnotify#696 #709: fsnotify/fsnotify#709 #731: fsnotify/fsnotify#731 #736: fsnotify/fsnotify#736 #740: fsnotify/fsnotify#740 #741: fsnotify/fsnotify#741 #748: fsnotify/fsnotify#748 #749: fsnotify/fsnotify#749

Changelog

Sourced from github.com/fsnotify/fsnotify's changelog.

1.10.1 2026-05-04

Changes and fixes

  • inotify: don't remove sibling watches sharing a path prefix (#754)

  • inotify, windows: don't rename sibling watches sharing a path prefix (#755)

#754: fsnotify/fsnotify#754 #755: fsnotify/fsnotify#755

1.10.0 2026-04-30

This version of fsnotify needs Go 1.23.

Changes and fixes

  • inotify: improve initialization error message (#731)

  • inotify: send Rename event if recursive watch is renamed (#696)

  • inotify: avoid copying event buffers when reading names (#741)

  • kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a bad entry no longer aborts Watcher.Add for the whole directory (#748)

  • kqueue: drop watches directly in Close() to fix a file descriptor leak when recycling watchers (#740)

  • windows: fix nil pointer dereference in remWatch (#736)

  • windows: lock watch field updates against concurrent WatchList to fix a race introduced in v1.9.0 (#709, #749)

#696: fsnotify/fsnotify#696 #709: fsnotify/fsnotify#709 #731: fsnotify/fsnotify#731 #736: fsnotify/fsnotify#736 #740: fsnotify/fsnotify#740 #741: fsnotify/fsnotify#741 #748: fsnotify/fsnotify#748 #749: fsnotify/fsnotify#749

Commits
  • 76b01a6 Release 1.10.1
  • fec150b Update changelog
  • 162b421 inotify, windows: don't rename sibling watches sharing a path prefix (#755)
  • 224257f inotify: don't remove sibling watches sharing a path prefix (#754)
  • e0c956c windows: document directory Write events and stabilize tests (#745)
  • 8d01d7b Release 1.10.0
  • 602284e Update changelog
  • 7f03e59 kqueue: skip ENOENT entries in watchDirectoryFiles (#748)
  • dab9dde windows: lock watch field updates against concurrent WatchList (#709) (#749)
  • eadf267 kqueue: drop watches directly in Close() instead of going through remove() (#...
  • Additional commits viewable in compare view

Updates github.com/go-chi/cors from 1.2.1 to 1.2.2

Release notes

Sourced from github.com/go-chi/cors's releases.

v1.2.2

What's Changed

New Contributors

Full Changelog: go-chi/cors@v1.2.1...v1.2.2

Commits

Updates github.com/go-playground/validator/v10 from 10.26.0 to 10.30.5

Release notes

Sourced from github.com/go-playground/validator/v10's releases.

Release 10.30.5

What's Changed

New Contributors

Full Changelog: go-playground/validator@v10.30.4...v10.30.5

v10.30.4

What's Changed

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 15, 2026
@dependabot
dependabot Bot requested review from a team as code owners September 15, 2026 17:55
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 15, 2026
@coderabbitai

coderabbitai Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 5b55b806-9c21-4ae4-81a9-85509dbb8e4b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dependabot
dependabot Bot force-pushed the dependabot/go_modules/service/external-53652d1dcd branch from 813cf01 to a5bcd84 Compare September 16, 2026 16:08
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/service/external-53652d1dcd branch from a5bcd84 to b11211b Compare September 16, 2026 16:28
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/service/external-53652d1dcd branch from b11211b to 2ef88c5 Compare September 16, 2026 17:56
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/service/external-53652d1dcd branch from 2ef88c5 to e2444fa Compare September 17, 2026 17:56
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/service/external-53652d1dcd branch from e2444fa to 20b3e70 Compare September 18, 2026 17:55
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/service/external-53652d1dcd branch from 20b3e70 to 0eec4d6 Compare September 21, 2026 16:18
@github-actions

github-actions Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Dependency Review

The following issues were found:

  • ❌ 1 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses.
  • ⚠️ 3 packages with OpenSSF Scorecard issues.

View full job summary

@dependabot
dependabot Bot force-pushed the dependabot/go_modules/service/external-53652d1dcd branch from 0eec4d6 to 5a7ca55 Compare September 21, 2026 17:55
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/service/external-53652d1dcd branch from 5a7ca55 to 4cb5daa Compare September 22, 2026 17:55
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/service/external-53652d1dcd branch from 4cb5daa to 5c6cb05 Compare September 23, 2026 17:55
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/service/external-53652d1dcd branch from 5c6cb05 to 4983da6 Compare September 24, 2026 17:03
Bumps the external group with 33 updates in the /service directory:

| Package | From | To |
| --- | --- | --- |
| [buf.build/go/protovalidate](https://github.com/bufbuild/protovalidate-go) | `1.0.0` | `1.4.0` |
| [connectrpc.com/connect](https://github.com/connectrpc/connect-go) | `1.20.0` | `1.21.0` |
| [connectrpc.com/validate](https://github.com/connectrpc/validate-go) | `0.6.0` | `0.7.0` |
| [github.com/casbin/casbin/v2](https://github.com/casbin/casbin) | `2.108.0` | `2.135.0` |
| [github.com/creasty/defaults](https://github.com/creasty/defaults) | `1.8.0` | `1.11.0` |
| [github.com/dgraph-io/ristretto/v2](https://github.com/dgraph-io/ristretto) | `2.4.0` | `2.4.2` |
| [github.com/eko/gocache/lib/v4](https://github.com/eko/gocache) | `4.2.0` | `4.4.0` |
| [github.com/eko/gocache/store/ristretto/v4](https://github.com/eko/gocache) | `4.3.2` | `4.3.8` |
| [github.com/fsnotify/fsnotify](https://github.com/fsnotify/fsnotify) | `1.9.0` | `1.10.1` |
| [github.com/go-chi/cors](https://github.com/go-chi/cors) | `1.2.1` | `1.2.2` |
| [github.com/go-playground/validator/v10](https://github.com/go-playground/validator) | `10.26.0` | `10.30.5` |
| [github.com/go-viper/mapstructure/v2](https://github.com/go-viper/mapstructure) | `2.4.0` | `2.5.0` |
| [github.com/jackc/pgx/v5](https://github.com/jackc/pgx) | `5.9.2` | `5.11.0` |
| [github.com/lib/pq](https://github.com/lib/pq) | `1.10.9` | `1.12.3` |
| [github.com/mattn/go-sqlite3](https://github.com/mattn/go-sqlite3) | `1.14.48` | `1.14.52` |
| [github.com/open-policy-agent/opa](https://github.com/open-policy-agent/opa) | `1.5.1` | `1.20.2` |
| [github.com/pressly/goose/v3](https://github.com/pressly/goose) | `3.24.3` | `3.28.0` |
| [github.com/spf13/cobra](https://github.com/spf13/cobra) | `1.9.1` | `1.10.2` |
| [github.com/spf13/viper](https://github.com/spf13/viper) | `1.20.1` | `1.21.0` |
| [github.com/stretchr/testify](https://github.com/stretchr/testify) | `1.11.1` | `1.12.1` |
| [github.com/testcontainers/testcontainers-go](https://github.com/testcontainers/testcontainers-go) | `0.42.0` | `0.44.0` |
| [go.opentelemetry.io/otel](https://github.com/open-telemetry/opentelemetry-go) | `1.45.0` | `1.46.0` |
| [go.opentelemetry.io/otel/exporters/otlp/otlptrace](https://github.com/open-telemetry/opentelemetry-go) | `1.45.0` | `1.46.0` |
| [go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc](https://github.com/open-telemetry/opentelemetry-go) | `1.45.0` | `1.46.0` |
| [go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp](https://github.com/open-telemetry/opentelemetry-go) | `1.45.0` | `1.46.0` |
| [go.opentelemetry.io/otel/exporters/stdout/stdouttrace](https://github.com/open-telemetry/opentelemetry-go) | `1.45.0` | `1.46.0` |
| [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) | `1.45.0` | `1.46.0` |
| [go.opentelemetry.io/otel/trace](https://github.com/open-telemetry/opentelemetry-go) | `1.45.0` | `1.46.0` |
| [golang.org/x/net](https://github.com/golang/net) | `0.58.0` | `0.59.0` |
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.83.2` | `1.84.0` |
| google.golang.org/protobuf | `1.36.11` | `1.36.12` |
| [github.com/go-ldap/ldap/v3](https://github.com/go-ldap/ldap) | `3.4.12` | `3.4.14` |
| [golang.org/x/text](https://github.com/golang/text) | `0.41.0` | `0.42.0` |



Updates `buf.build/go/protovalidate` from 1.0.0 to 1.4.0
- [Release notes](https://github.com/bufbuild/protovalidate-go/releases)
- [Commits](bufbuild/protovalidate-go@v1.0.0...v1.4.0)

Updates `connectrpc.com/connect` from 1.20.0 to 1.21.0
- [Release notes](https://github.com/connectrpc/connect-go/releases)
- [Changelog](https://github.com/connectrpc/connect-go/blob/main/RELEASE.md)
- [Commits](connectrpc/connect-go@v1.20.0...v1.21.0)

Updates `connectrpc.com/validate` from 0.6.0 to 0.7.0
- [Release notes](https://github.com/connectrpc/validate-go/releases)
- [Changelog](https://github.com/connectrpc/validate-go/blob/main/RELEASE.md)
- [Commits](connectrpc/validate-go@v0.6.0...v0.7.0)

Updates `github.com/casbin/casbin/v2` from 2.108.0 to 2.135.0
- [Release notes](https://github.com/casbin/casbin/releases)
- [Commits](apache/casbin@v2.108.0...v2.135.0)

Updates `github.com/creasty/defaults` from 1.8.0 to 1.11.0
- [Release notes](https://github.com/creasty/defaults/releases)
- [Commits](creasty/defaults@v1.8.0...v1.11.0)

Updates `github.com/dgraph-io/ristretto/v2` from 2.4.0 to 2.4.2
- [Release notes](https://github.com/dgraph-io/ristretto/releases)
- [Changelog](https://github.com/dgraph-io/ristretto/blob/main/CHANGELOG.md)
- [Commits](dgraph-io/ristretto@v2.4.0...v2.4.2)

Updates `github.com/eko/gocache/lib/v4` from 4.2.0 to 4.4.0
- [Release notes](https://github.com/eko/gocache/releases)
- [Commits](eko/gocache@lib/v4.2.0...lib/v4.4.0)

Updates `github.com/eko/gocache/store/ristretto/v4` from 4.3.2 to 4.3.8
- [Release notes](https://github.com/eko/gocache/releases)
- [Commits](eko/gocache@store/ristretto/v4.3.2...store/ristretto/v4.3.8)

Updates `github.com/fsnotify/fsnotify` from 1.9.0 to 1.10.1
- [Release notes](https://github.com/fsnotify/fsnotify/releases)
- [Changelog](https://github.com/fsnotify/fsnotify/blob/main/CHANGELOG.md)
- [Commits](fsnotify/fsnotify@v1.9.0...v1.10.1)

Updates `github.com/go-chi/cors` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/go-chi/cors/releases)
- [Commits](go-chi/cors@v1.2.1...v1.2.2)

Updates `github.com/go-playground/validator/v10` from 10.26.0 to 10.30.5
- [Release notes](https://github.com/go-playground/validator/releases)
- [Commits](go-playground/validator@v10.26.0...v10.30.5)

Updates `github.com/go-viper/mapstructure/v2` from 2.4.0 to 2.5.0
- [Release notes](https://github.com/go-viper/mapstructure/releases)
- [Changelog](https://github.com/go-viper/mapstructure/blob/main/CHANGELOG.md)
- [Commits](go-viper/mapstructure@v2.4.0...v2.5.0)

Updates `github.com/jackc/pgx/v5` from 5.9.2 to 5.11.0
- [Release notes](https://github.com/jackc/pgx/releases)
- [Changelog](https://github.com/jackc/pgx/blob/master/CHANGELOG.md)
- [Commits](jackc/pgx@v5.9.2...v5.11.0)

Updates `github.com/lib/pq` from 1.10.9 to 1.12.3
- [Release notes](https://github.com/lib/pq/releases)
- [Changelog](https://github.com/lib/pq/blob/main/CHANGELOG.md)
- [Commits](lib/pq@v1.10.9...v1.12.3)

Updates `github.com/mattn/go-sqlite3` from 1.14.48 to 1.14.52
- [Release notes](https://github.com/mattn/go-sqlite3/releases)
- [Commits](mattn/go-sqlite3@v1.14.48...v1.14.52)

Updates `github.com/open-policy-agent/opa` from 1.5.1 to 1.20.2
- [Release notes](https://github.com/open-policy-agent/opa/releases)
- [Changelog](https://github.com/open-policy-agent/opa/blob/main/CHANGELOG.md)
- [Commits](open-policy-agent/opa@v1.5.1...v1.20.2)

Updates `github.com/pressly/goose/v3` from 3.24.3 to 3.28.0
- [Release notes](https://github.com/pressly/goose/releases)
- [Changelog](https://github.com/pressly/goose/blob/main/CHANGELOG.md)
- [Commits](pressly/goose@v3.24.3...v3.28.0)

Updates `github.com/spf13/cobra` from 1.9.1 to 1.10.2
- [Release notes](https://github.com/spf13/cobra/releases)
- [Commits](spf13/cobra@v1.9.1...v1.10.2)

Updates `github.com/spf13/viper` from 1.20.1 to 1.21.0
- [Release notes](https://github.com/spf13/viper/releases)
- [Commits](spf13/viper@v1.20.1...v1.21.0)

Updates `github.com/stretchr/testify` from 1.11.1 to 1.12.1
- [Release notes](https://github.com/stretchr/testify/releases)
- [Commits](stretchr/testify@v1.11.1...v1.12.1)

Updates `github.com/testcontainers/testcontainers-go` from 0.42.0 to 0.44.0
- [Release notes](https://github.com/testcontainers/testcontainers-go/releases)
- [Commits](testcontainers/testcontainers-go@v0.42.0...v0.44.0)

Updates `go.opentelemetry.io/otel` from 1.45.0 to 1.46.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.45.0...v1.46.0)

Updates `go.opentelemetry.io/otel/exporters/otlp/otlptrace` from 1.45.0 to 1.46.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.45.0...v1.46.0)

Updates `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc` from 1.45.0 to 1.46.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.45.0...v1.46.0)

Updates `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp` from 1.45.0 to 1.46.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.45.0...v1.46.0)

Updates `go.opentelemetry.io/otel/exporters/stdout/stdouttrace` from 1.45.0 to 1.46.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.45.0...v1.46.0)

Updates `go.opentelemetry.io/otel/sdk` from 1.45.0 to 1.46.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.45.0...v1.46.0)

Updates `go.opentelemetry.io/otel/trace` from 1.45.0 to 1.46.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.45.0...v1.46.0)

Updates `golang.org/x/net` from 0.58.0 to 0.59.0
- [Commits](golang/net@v0.58.0...v0.59.0)

Updates `google.golang.org/grpc` from 1.83.2 to 1.84.0
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.83.2...v1.84.0)

Updates `google.golang.org/protobuf` from 1.36.11 to 1.36.12

Updates `github.com/go-ldap/ldap/v3` from 3.4.12 to 3.4.14
- [Release notes](https://github.com/go-ldap/ldap/releases)
- [Commits](go-ldap/ldap@v3.4.12...v3.4.14)

Updates `golang.org/x/text` from 0.41.0 to 0.42.0
- [Release notes](https://github.com/golang/text/releases)
- [Commits](golang/text@v0.41.0...v0.42.0)

---
updated-dependencies:
- dependency-name: buf.build/go/protovalidate
  dependency-version: 1.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: connectrpc.com/connect
  dependency-version: 1.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: connectrpc.com/validate
  dependency-version: 0.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/casbin/casbin/v2
  dependency-version: 2.135.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/creasty/defaults
  dependency-version: 1.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/dgraph-io/ristretto/v2
  dependency-version: 2.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: external
- dependency-name: github.com/eko/gocache/lib/v4
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/eko/gocache/store/ristretto/v4
  dependency-version: 4.3.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: external
- dependency-name: github.com/fsnotify/fsnotify
  dependency-version: 1.10.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/go-chi/cors
  dependency-version: 1.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: external
- dependency-name: github.com/go-ldap/ldap/v3
  dependency-version: 3.4.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: external
- dependency-name: github.com/go-playground/validator/v10
  dependency-version: 10.30.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/go-viper/mapstructure/v2
  dependency-version: 2.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/jackc/pgx/v5
  dependency-version: 5.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/lib/pq
  dependency-version: 1.12.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/mattn/go-sqlite3
  dependency-version: 1.14.52
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: external
- dependency-name: github.com/open-policy-agent/opa
  dependency-version: 1.20.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/pressly/goose/v3
  dependency-version: 3.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/spf13/cobra
  dependency-version: 1.10.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/spf13/viper
  dependency-version: 1.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/stretchr/testify
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/testcontainers/testcontainers-go
  dependency-version: 0.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: go.opentelemetry.io/otel
  dependency-version: 1.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace
  dependency-version: 1.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc
  dependency-version: 1.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp
  dependency-version: 1.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: go.opentelemetry.io/otel/exporters/stdout/stdouttrace
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: go.opentelemetry.io/otel/sdk
  dependency-version: 1.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: go.opentelemetry.io/otel/trace
  dependency-version: 1.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: golang.org/x/net
  dependency-version: 0.58.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: golang.org/x/text
  dependency-version: 0.41.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: google.golang.org/grpc
  dependency-version: 1.83.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: external
- dependency-name: google.golang.org/protobuf
  dependency-version: 1.36.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: external
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/service/external-53652d1dcd branch from 4983da6 to 55af79f Compare September 25, 2026 17:55
@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Govulncheck found vulnerabilities ⚠️

The following modules have known vulnerabilities:

See the workflow run for details.

@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 28, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/service/external-53652d1dcd branch September 28, 2026 15:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code size/l

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants