chore(deps): bump golang.org/x/oauth2 from 0.36.0 to 0.37.0 in /languages/golang - #1015
dependabot[bot] wants to merge 1 commit into
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
|
@dependabot rebase |
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2) from 0.36.0 to 0.37.0. - [Commits](golang/oauth2@v0.36.0...v0.37.0) --- updated-dependencies: - dependency-name: golang.org/x/oauth2 dependency-version: 0.37.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
a6a031a to
0d709df
Compare
tobyhede
left a comment
There was a problem hiding this comment.
Reviewed together with #1016. No blocking finding. The upstream v0.36.0→v0.37.0 diff changes the minimum Go version and the Google metadata universe-domain endpoint; the core oauth2.TokenSource/Token API used directly by stackauth.OAuth2TokenSource is unchanged. The adapter's fresh Token() call, error handling and AccessToken extraction remain compatible. Go 1.26 is already the root mise pin and the workflow derives its toolchain from that pin; this does raise the Go module's consumer minimum to 1.26.
Requested Dependabot rebase onto current main to include tests-golang.yml. Validated head 0d709df. Tests (Go) passed: Go lint, WASI core/no-http checks, guest lint/tests/release builds and import checks, Go format/vet/tests on Linux (including 386), macOS and Windows, and live ZeroKMS tests/examples. Refresh-lock replay tests passed on all three platforms. Test JS, Test EQL, CodeQL and OSV also passed on this head.
Go validation: https://github.com/cipherstash/stack/actions/runs/37106450434
Bumps golang.org/x/oauth2 from 0.36.0 to 0.37.0.
Commits
c624b89google: change the snake case endpoint to kebab-case09a82f6all: upgrade go directive to at least 1.26.0 [generated]