Skip to content

build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.7 to 1.32.17 - #91

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/github.com/aws/aws-sdk-go-v2/config-1.32.16
Open

build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.7 to 1.32.17#91
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/github.com/aws/aws-sdk-go-v2/config-1.32.16

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 23, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/aws/aws-sdk-go-v2/config from 1.32.7 to 1.32.17.

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Apr 23, 2026

@ghost ghost left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — approved (automated review)

Routine dependabot bump of aws-sdk-go-v2/config 1.32.7 → 1.32.16 and transitive AWS SDK dependencies.

Checked:

  • Only go.mod and go.sum changed — zero application code touched
  • All version bumps are patch/minor within the AWS SDK v2 ecosystem
  • No new dependencies introduced, no non-AWS deps changed
  • internal/ini indirect dep dropped (normal go mod tidy behavior)
  • smithy-go 1.24.2 → 1.25.0 minor bump is compatible
  • Not protocol-critical — no VTXO, signing, forfeit, round, or exit code affected

Low risk. Ship it.

@dependabot
dependabot Bot force-pushed the dependabot/go_modules/github.com/aws/aws-sdk-go-v2/config-1.32.16 branch from 885905a to d2a5bf8 Compare April 25, 2026 15:57

@ghost ghost left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-approved after rebase (automated review)

New commit d2a5bf8 — same dependabot bump, rebased. Still only go.mod / go.sum:

  • aws-sdk-go-v2 1.41.5 → 1.41.6
  • aws-sdk-go-v2/config 1.32.7 → 1.32.16
  • aws-sdk-go-v2/service/sts 1.41.6 → 1.42.0
  • smithy-go 1.24.2 → 1.25.0
  • Transitive AWS deps bumped accordingly; internal/ini indirect dep dropped

Zero application code changed. Not protocol-critical. Ship it.

@dependabot dependabot Bot changed the title build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.7 to 1.32.16 build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.7 to 1.32.17 May 17, 2026
Bumps [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) from 1.32.7 to 1.32.17.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@v1.32.7...config/v1.32.17)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.32.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/github.com/aws/aws-sdk-go-v2/config-1.32.16 branch from d2a5bf8 to 459c483 Compare May 17, 2026 13:46

@arkana-ai-bot arkana-ai-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependabot bump of aws-sdk-go-v2/config 1.32.7 → 1.32.17 and cascading AWS SDK indirect deps (sts 1.41.6 → 1.42.1, smithy-go 1.24.2 → 1.25.1, etc.), plus removal of the now-unused internal/ini indirect. All within the same v1 major line — no API breakage expected.

Scope observations:

  • Module is github.com/ArkLabsHQ/introspector-enclave — an AWS-hosted enclave introspection binary using KMS/EC2/S3/SSM/CloudWatchLogs. Not on the VTXO/round/forfeit/signing path, so no protocol-critical review triggered.
  • Only go.mod/go.sum touched; no consumer code changes needed to verify.
  • Upstream changelogs for these config/sts/smithy-go micro-bumps are routine (endpoint model refreshes, regenerated clients, smithy-go v1.25.1 minor). Nothing flagged in known-CVE space at time of review.

Nothing to block on. Confirm go build ./... and go test ./... are green in CI before merge; note the PR has been open >30d so auto-rebase is disabled — a manual rebase against current main is worth doing to catch any drift in the transitive graph.

@arkana-ai-bot

Copy link
Copy Markdown

This dependabot PR has been open for 9+ days without review. Could someone take a look and merge or close it?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant