Skip to content

chore(deps): bump golang.org/x/oauth2 from 0.36.0 to 0.37.0 in /languages/golang - #1015

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/languages/golang/golang.org/x/oauth2-0.37.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/languages/golang/golang.org/x/oauth2-0.37.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Bumps golang.org/x/oauth2 from 0.36.0 to 0.37.0.

Commits
  • c624b89 google: change the snake case endpoint to kebab-case
  • 09a82f6 all: upgrade go directive to at least 1.26.0 [generated]
  • See full diff in compare view

@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: supply-chain. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 2, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 2, 2026 18:26
@changeset-bot

changeset-bot Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 0d709df

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

tobyhede commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2) from 0.36.0 to 0.37.0.
- [Commits](golang/oauth2@v0.36.0...v0.37.0)

---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/languages/golang/golang.org/x/oauth2-0.37.0 branch from a6a031a to 0d709df Compare October 3, 2026 07:28

@tobyhede tobyhede left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed together with #1016. No blocking finding. The upstream v0.36.0→v0.37.0 diff changes the minimum Go version and the Google metadata universe-domain endpoint; the core oauth2.TokenSource/Token API used directly by stackauth.OAuth2TokenSource is unchanged. The adapter's fresh Token() call, error handling and AccessToken extraction remain compatible. Go 1.26 is already the root mise pin and the workflow derives its toolchain from that pin; this does raise the Go module's consumer minimum to 1.26.

Requested Dependabot rebase onto current main to include tests-golang.yml. Validated head 0d709df. Tests (Go) passed: Go lint, WASI core/no-http checks, guest lint/tests/release builds and import checks, Go format/vet/tests on Linux (including 386), macOS and Windows, and live ZeroKMS tests/examples. Refresh-lock replay tests passed on all three platforms. Test JS, Test EQL, CodeQL and OSV also passed on this head.

Go validation: https://github.com/cipherstash/stack/actions/runs/37106450434

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant