go.mod: bump the most-deps group with 6 updates - #175
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the most-deps group with 6 updates: | Package | From | To | | --- | --- | --- | | [github.com/modelcontextprotocol/go-sdk](https://github.com/modelcontextprotocol/go-sdk) | `1.7.0` | `1.8.0` | | [golang.org/x/crypto](https://github.com/golang/crypto) | `0.55.0` | `0.57.0` | | [golang.org/x/term](https://github.com/golang/term) | `0.45.0` | `0.46.0` | | [golang.org/x/text](https://github.com/golang/text) | `0.41.0` | `0.42.0` | | [golang.org/x/time](https://github.com/golang/time) | `0.15.0` | `0.16.0` | | [mvdan.cc/sh/v3](https://github.com/mvdan/sh) | `3.14.0` | `3.14.1` | Updates `github.com/modelcontextprotocol/go-sdk` from 1.7.0 to 1.8.0 - [Release notes](https://github.com/modelcontextprotocol/go-sdk/releases) - [Commits](modelcontextprotocol/go-sdk@v1.7.0...v1.8.0) Updates `golang.org/x/crypto` from 0.55.0 to 0.57.0 - [Commits](golang/crypto@v0.55.0...v0.57.0) Updates `golang.org/x/term` from 0.45.0 to 0.46.0 - [Commits](golang/term@v0.45.0...v0.46.0) Updates `golang.org/x/text` from 0.41.0 to 0.42.0 - [Release notes](https://github.com/golang/text/releases) - [Commits](golang/text@v0.41.0...v0.42.0) Updates `golang.org/x/time` from 0.15.0 to 0.16.0 - [Commits](golang/time@v0.15.0...v0.16.0) Updates `mvdan.cc/sh/v3` from 3.14.0 to 3.14.1 - [Release notes](https://github.com/mvdan/sh/releases) - [Changelog](https://github.com/mvdan/sh/blob/master/CHANGELOG.md) - [Commits](mvdan/sh@v3.14.0...v3.14.1) --- updated-dependencies: - dependency-name: github.com/modelcontextprotocol/go-sdk dependency-version: 1.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: most-deps - dependency-name: golang.org/x/crypto dependency-version: 0.57.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: most-deps - dependency-name: golang.org/x/term dependency-version: 0.46.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: most-deps - dependency-name: golang.org/x/text dependency-version: 0.42.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: most-deps - dependency-name: golang.org/x/time dependency-version: 0.16.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: most-deps - dependency-name: mvdan.cc/sh/v3 dependency-version: 3.14.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: most-deps ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the most-deps group with 6 updates:
1.7.01.8.00.55.00.57.00.45.00.46.00.41.00.42.00.15.00.16.03.14.03.14.1Updates
github.com/modelcontextprotocol/go-sdkfrom 1.7.0 to 1.8.0Release notes
Sourced from github.com/modelcontextprotocol/go-sdk's releases.
... (truncated)
Commits
3f3b699refactor: remove legacy MCPGODEBUG compatibility for new protocol release (#1...830f0b7mcp: update conformance tests (#1231)12cbafeoauthex: oauth discovery checks (#1220)3632967mcp: add an sse event size cap (#1205)0d3036fmcp: allow per request Cacheable customization (#1203)cb0de64mcp: add a max request body size of the old transport (#1224)2fdabdemcp: do not check metatada on notifications (#1215)59185e6build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 (#1217)a6764cfbuild(deps): bump golang/govulncheck-action from 1.0.4 to 1.1.0 (#1218)8227246fix: only subscribe when server advertises capability (#1221)Updates
golang.org/x/cryptofrom 0.55.0 to 0.57.0Commits
3f62bf1go.mod: update golang.org/x dependencies86efde5ssh: reject unexpected message types on established channelsa6cdac6ssh: drop traffic on undecided channels39dc44essh: don't skip the source-address critical option in CheckCertafebf4cx509roots/fallback/bundle: make subjectsEqual stricter on Go 1.27+89f4e9bx509roots/fallback: update bundle71488c4ssh/knownhosts: compare only public key portions for revocation82adefassh: synchronize unexpected response testc757c98all: upgrade go directive to at least 1.26.0 [generated]593c81assh: correctly ignore pre-banner linesUpdates
golang.org/x/termfrom 0.45.0 to 0.46.0Commits
6226200go.mod: update golang.org/x dependencies7c2fb74term: process bytes returned with a read error3963fceall: upgrade go directive to at least 1.26.0 [generated]Updates
golang.org/x/textfrom 0.41.0 to 0.42.0Commits
fafe4a0go.mod: update golang.org/x dependenciesf53c316unicode/norm: don't truncate runes in the recomposition map key37867f6unicode/norm: let any starter block composition in compose0dd525funicode/norm: compose non-Hangul runes after a Hangul syllablebac26e5unicode/norm: avoid improper ErrShortDst return in Form.transform4f55186unicode/norm: simplify short source detection in Form.transforma1b6c10unicode/norm: prevent decomposeSegment from moving backwardscd1cbc9unicode/bidi: panic rather than log.Panicfa459614internal/export/idna: fix conformance with optional validation disabledbe70a61internal/export/idna: drop trie field from ProfilesUpdates
golang.org/x/timefrom 0.15.0 to 0.16.0Commits
fb013b3all: upgrade go directive to at least 1.26.0 [generated]Updates
mvdan.cc/sh/v3from 3.14.0 to 3.14.1Release notes
Sourced from mvdan.cc/sh/v3's releases.
Changelog
Sourced from mvdan.cc/sh/v3's changelog.
Commits
a3f0c75CHANGELOG: add entry for v3.14.129855f3interp: stop confirming a huge brace sequence against bash39a9394expand: keep escaped characters from acting as glob metacharactersa89e798expand: add test cases for globbing with escaped metacharacters755b3e5pattern: treat unclosed extended operator groups as literals63af908fix: gitAtime build fail on 32-bit FreeBSD and NetBSD671a5e2syntax: count columns for bytes written via colCounter.Write7c82969syntax: don't indent heredocs without dashes nested in <<- ones075feedsyntax: keep literal tabs in <<- heredoc bodies intact466c5e8syntax: add test cases for literal tabs in <<- heredoc bodiesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions