build(deps): Bump github.com/spiffe/go-spiffe/v2 from 2.6.0 to 2.8.1 in /authbridge/authlib#541
Conversation
|
@dependabot rebase |
7084d31 to
fe0e819
Compare
Dependency Update AnalysisPackage: github.com/spiffe/go-spiffe/v2 (2.6.0 -> 2.8.1) Changelog SummarySourced from github.com/spiffe/go-spiffe/v2's releases.
Risk Assessment
Automated analysis by Kagenti Dep Bump Fixer (scan 2026-07-09-002) |
Bumps [github.com/spiffe/go-spiffe/v2](https://github.com/spiffe/go-spiffe) from 2.6.0 to 2.8.1. - [Release notes](https://github.com/spiffe/go-spiffe/releases) - [Changelog](https://github.com/spiffe/go-spiffe/blob/main/CHANGELOG.md) - [Commits](spiffe/go-spiffe@v2.6.0...v2.8.1) --- updated-dependencies: - dependency-name: github.com/spiffe/go-spiffe/v2 dependency-version: 2.8.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
fe0e819 to
1eee461
Compare
Dependency Update AnalysisPackage: github.com/spiffe/go-spiffe/v2 (2.6.0 -> 2.8.1) Changelog SummarySourced from github.com/spiffe/go-spiffe/v2's releases.
Risk Assessment
Automated analysis by Kagenti Dep Bump Fixer (scan 2026-07-14-002) |
|
Superseded by #673, which bundles this bump with the other authlib dependency updates and runs |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bundles Dependabot PRs rossoctl#638, rossoctl#639, rossoctl#670, rossoctl#541 into a single update: - github.com/lestrrat-go/jwx/v2 2.1.6 -> 2.1.7 (rossoctl#638) - google.golang.org/grpc 1.81.1 -> 1.82.0 (rossoctl#639) - golang.org/x/net 0.56.0 -> 0.57.0 (rossoctl#670) - github.com/spiffe/go-spiffe/v2 2.6.0 -> 2.8.1 (rossoctl#541) The authbridge-envoy and authbridge-proxy modules replace authlib via a local path directive, so bumping authlib's dependencies leaves their go.sum stale. Dependabot only tidies the module it edits, which is why each of the four PRs failed the envoy/proxy Go CI Lint step (go vet with GOWORK=off: 'updates to go.mod needed; go mod tidy'). This bundle runs go mod tidy in all three modules. Assisted-By: Claude (Anthropic AI) <noreply@anthropic.com> Signed-off-by: Paolo Dettori <dettori@us.ibm.com>
Bumps github.com/spiffe/go-spiffe/v2 from 2.6.0 to 2.8.1.
Release notes
Sourced from github.com/spiffe/go-spiffe/v2's releases.
Changelog
Sourced from github.com/spiffe/go-spiffe/v2's changelog.
Commits
e9973f6v2.8.1 changelog (#396)bbc6dc1Add wit-svid to marshaled WIT bundle keys (#395)dbebcf8v2.8.0 changelog (#394)f685b2dAdd Broker API (#388)76b14bdv2.7.0 changelog (#392)8580a01Add missing witbundle APIs for parity with jwtbundle (#391)280d52efix(x509svid): reject leaf SPIFFE IDs with root path (#375)c7f2701Add WIT-SVID (#385)af3667aBump google.golang.org/grpc from 1.75.0 to 1.79.3 (#380)c925be7Bump christophebedard/dco-check from 0.5.0 to 0.5.1 (#390)