Skip to content

build(deps): bump golang.org/x/mod from 0.38.0 to 0.40.0 - #20

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/golang.org/x/mod-0.40.0
Open

build(deps): bump golang.org/x/mod from 0.38.0 to 0.40.0#20
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/golang.org/x/mod-0.40.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 22, 2026

Copy link
Copy Markdown
Contributor

Bumps golang.org/x/mod from 0.38.0 to 0.40.0.

Commits
  • d3398d0 go.mod: update golang.org/x dependencies
  • 57549bf sumdb: ignore unrelated hashes in Lookup
  • 96f62ae sumdb/tlog: fix TileHashReader authentication bypass
  • 13be902 go.mod: update golang.org/x dependencies
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [golang.org/x/mod](https://github.com/golang/mod) from 0.38.0 to 0.40.0.
- [Commits](golang/mod@v0.38.0...v0.40.0)

---
updated-dependencies:
- dependency-name: golang.org/x/mod
  dependency-version: 0.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 22, 2026
@github-actions

Copy link
Copy Markdown

bulwark

  • scan — failed, see error output below
error output
typescript: using ambient node 22.23.2 (no version declared by this repo)
go: using go1.26.6 via GOTOOLCHAIN (declared in go.mod; ambient go is 1.24.13)
The `json` and `json-pretty` reporters are experimental and may change in patch releases.
lint ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

  × Some errors were emitted while running checks.
  

go: downloading go1.26.6 (linux/amd64)
go: downloading github.com/securego/gosec/v2 v2.28.0
go: downloading golang.org/x/tools v0.48.0
go: downloading golang.org/x/sync v0.22.0
go: downloading github.com/anthropics/anthropic-sdk-go v1.57.0
go: downloading github.com/openai/openai-go/v3 v3.42.0
go: downloading google.golang.org/genai v1.63.0
go: downloading github.com/ccojocar/zxcvbn-go v1.0.4
go: downloading github.com/tidwall/sjson v1.2.5
go: downloading github.com/invopop/jsonschema v0.14.0
go: downloading github.com/pb33f/ordered-map/v2 v2.3.1
go: downloading github.com/standard-webhooks/standard-webhooks/libraries v0.0.1
go: downloading github.com/tidwall/gjson v1.19.0
go: downloading github.com/google/uuid v1.6.0
go: downloading github.com/gookit/color v1.6.1
go: downloading go.yaml.in/yaml/v3 v3.0.4
go: downloading golang.org/x/mod v0.38.0
go: downloading cloud.google.com/go/auth v0.21.0
go: downloading cloud.google.com/go v0.123.0
go: downloading github.com/google/go-cmp v0.7.0
go: downloading github.com/gorilla/websocket v1.5.3
go: downloading github.com/bahlo/generic-list-go v0.2.0
go: downloading github.com/buger/jsonparser v1.2.0
go: downloading go.yaml.in/yaml/v4 v4.0.0-rc.6
go: downloading github.com/tidwall/match v1.2.0
go: downloading github.com/tidwall/pretty v1.2.1
go: downloading github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e
go: downloading github.com/googleapis/gax-go/v2 v2.23.0
go: downloading cloud.google.com/go/compute/metadata v0.9.0
go: downloading go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0
go: downloading go.opentelemetry.io/otel v1.44.0
go: downloading go.opentelemetry.io/otel/trace v1.44.0
go: downloading golang.org/x/net v0.57.0
go: downloading google.golang.org/api v0.288.0
go: downloading github.com/google/s2a-go v0.1.9
go: downloading google.golang.org/grpc v1.82.0
go: downloading github.com/googleapis/enterprise-certificate-proxy v0.3.18
go: downloading go.opentelemetry.io/otel/metric v1.44.0
go: downloading google.golang.org/protobuf v1.36.11
go: downloading github.com/felixge/httpsnoop v1.1.0
go: downloading google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800
go: downloading github.com/go-logr/logr v1.4.3
go: downloading golang.org/x/text v0.40.0
go: downloading github.com/cespare/xxhash/v2 v2.3.0
go: downloading github.com/go-logr/stdr v1.2.2
go: downloading go.opentelemetry.io/auto/sdk v1.2.1
go: downloading golang.org/x/sys v0.47.0
go: downloading golang.org/x/crypto v0.54.0
[gosec] 2026/08/22 16:06:48 Including rules: default
[gosec] 2026/08/22 16:06:48 Excluding rules: default
[gosec] 2026/08/22 16:06:48 Including analyzers: default
[gosec] 2026/08/22 16:06:48 Excluding analyzers: default
[gosec] 2026/08/22 16:06:48 Import directory: /home/runner/work/cubit/cubit/internal/dashboard
[gosec] 2026/08/22 16:06:48 Import directory: /home/runner/work/cubit/cubit/internal/criterion
[gosec] 2026/08/22 16:06:48 Import directory: /home/runner/work/cubit/cubit/internal/gitstore
[gosec] 2026/08/22 16:06:48 Import directory: /home/runner/work/cubit/cubit/internal/model
[gosec] 2026/08/22 16:06:48 Checking package: model
[gosec] 2026/08/22 16:06:48 Checking file: /home/runner/work/cubit/cubit/internal/model/model.go
[gosec] 2026/08/22 16:06:48 Checking package: criterion
[gosec] 2026/08/22 16:06:48 Checking file: /home/runner/work/cubit/cubit/internal/criterion/ingest.go
[gosec] 2026/08/22 16:06:48 Import directory: /home/runner/work/cubit/cubit/internal/report
[gosec] 2026/08/22 16:06:48 Import directory: /home/runner/work/cubit/cubit/cmd/cubit
[gosec] 2026/08/22 16:06:48 Checking package: gitstore
[gosec] 2026/08/22 16:06:48 Checking file: /home/runner/work/cubit/cubit/internal/gitstore/gitstore.go
[gosec] 2026/08/22 16:06:48 Checking package: report
[gosec] 2026/08/22 16:06:48 Checking file: /home/runner/work/cubit/cubit/internal/report/report.go
[gosec] 2026/08/22 16:06:48 Checking package: dashboard
[gosec] 2026/08/22 16:06:48 Checking file: /home/runner/work/cubit/cubit/internal/dashboard/dashboard.go
[gosec] 2026/08/22 16:06:49 Checking package: main
[gosec] 2026/08/22 16:06:49 Checking file: /home/runner/work/cubit/cubit/cmd/cubit/compare.go
[gosec] 2026/08/22 16:06:49 Checking file: /home/runner/work/cubit/cubit/cmd/cubit/main.go
[gosec] 2026/08/22 16:06:49 Checking file: /home/runner/work/cubit/cubit/cmd/cubit/record.go
[gosec] 2026/08/22 16:06:49 Checking file: /home/runner/work/cubit/cubit/cmd/cubit/root.go
[gosec] 2026/08/22 16:06:49 Checking file: /home/runner/work/cubit/cubit/cmd/cubit/run.go
[gosec] 2026/08/22 16:06:49 Checking file: /home/runner/work/cubit/cubit/cmd/cubit/serve.go
[gosec] 2026/08/22 16:06:49 Checking file: /home/runner/work/cubit/cubit/cmd/cubit/update.go
[gosec] 2026/08/22 16:06:49 Checking file: /home/runner/work/cubit/cubit/cmd/cubit/version.go
Results:


Summary:
  Gosec  : dev
  Files  : 13
  Lines  : 1679
  Nosec  : 11
  Issues : 0

go: downloading golang.org/x/vuln v1.7.0
go: downloading golang.org/x/telemetry v0.0.0-20260811182544-a038080d80e5
go: downloading golang.org/x/mod v0.39.0
go: downloading golang.org/x/tools v0.49.0
No vulnerabilities found.
From https://github.com/wardnet/cubit
 * branch            main       -> FETCH_HEAD
51dfca0199be2a82dfa1853a1218df611c0eff4a
creating virtual environment...
installing semgrep from spec 'semgrep==1.173.0'...
done! ✨ 🌟 ✨
  installed package semgrep 1.173.0, installed using Python 3.12.3
  These apps are now available
    - pysemgrep
    - semgrep
               
               
┌─────────────┐
│ Scan Status │
└─────────────┘
  Scanning 2 files tracked by git with 1074 Code rules:
  Scanning 2 files with 47 <multilang> rules.
  Current version has 0 findings.

Skipping baseline scan, because there are no current findings.
                
                
┌──────────────┐
│ Scan Summary │
└──────────────┘
✅ Scan completed successfully.
 • Findings: 0 (0 blocking)
 • Rules run: 47
 • Targets scanned: 2
 • Parsed lines: ~100.0%
 • Scan was limited to files changed since baseline commit.
 • For a detailed list of skipped files and lines, run semgrep with the --verbose flag
Ran 47 rules on 2 files: 0 findings.
(need more rules? `semgrep login` for additional free Semgrep Registry rules)

If Semgrep missed a finding, please send us feedback to let us know!
See https://semgrep.dev/docs/reporting-false-negatives/
[FAIL] biome(./web)
  src/LineChart.tsx:41  lint/correctness/noUnusedFunctionParameters  This parameter p is unused.
[PASS] gosec
[PASS] govulncheck
[PASS] semgrep
Error: 1 check(s) failed
bulwark: 1 check(s) failed
  • coverage — go: 33.7% (baseline 33.7%)

📦 Full bulwark output — complete scan and coverage logs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants