Skip to content

chore(deps)(deps): bump github.com/compose-spec/compose-go/v2 from 2.10.0 to 2.16.0 - #2135

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/compose-spec/compose-go/v2-2.16.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/compose-spec/compose-go/v2-2.16.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/compose-spec/compose-go/v2 from 2.10.0 to 2.16.0.

Release notes

Sourced from github.com/compose-spec/compose-go/v2's releases.

v2.16.0

⚠️ Breaking change (Go API)

types.ServiceConfig now embeds types.ContainerSpec and types.WorkloadSpec, shared with the new jobs element and pre_start init containers. Field access is unchanged (svc.Image), but struct literals must now set moved fields through the embedded structs, and code walking ServiceConfig with reflection will see these two embedded structs instead of a flat list of fields:

types.ServiceConfig{Name: "web", ContainerSpec: types.ContainerSpec{Image: "nginx"}}

ServiceConfig.PreStart is now a []types.PreStartHook (was []types.ServiceHook), which embeds a full ContainerSpec; Image and PerReplica are no longer fields of ServiceHook.

The order of keys in the YAML and JSON produced for a service also changes (service-level keys first, then container-level, then workload-level ones). The content is the same, but expected files compared as text need to be regenerated.

What's Changed

New Contributors

Full Changelog: compose-spec/compose-go@v2.15.0...v2.16.0

v2.15.0

What's Changed

New Contributors

... (truncated)

Commits
  • 98fd653 loader: reuse deepClone instead of duplicating it as cloneYaml
  • e93a134 loader: merge an extension into the attribute it stands for
  • f33989c loader: pin promotion of extensions before extends merges services
  • 732bdd9 loader: apply !reset and !override to the attribute an extension stands for
  • 7e33be8 loader: promote x-* extensions adopted by the specification
  • f18e211 fix: allow disabled services as build additional contexts
  • 14d7cfa fix: reject non-mapping entries under networks and models
  • 4d56f81 refactor: rename projectNameImperativelySet to projectNameExplicit
  • a1350ea fix: an explicit working dir must survive a remote resource loader
  • 9047519 fix: type=image volume source is always a docker image reference
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/compose-spec/compose-go/v2](https://github.com/compose-spec/compose-go) from 2.10.0 to 2.16.0.
- [Release notes](https://github.com/compose-spec/compose-go/releases)
- [Commits](compose-spec/compose-go@v2.10.0...v2.16.0)

---
updated-dependencies:
- dependency-name: github.com/compose-spec/compose-go/v2
  dependency-version: 2.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Oct 2, 2026
@kubernetes-prow kubernetes-prow Bot added the cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. label Oct 2, 2026
@kubernetes-prow
kubernetes-prow Bot requested review from TessaIO and cdrage October 2, 2026 14:23
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: dependabot[bot]
Once this PR has been reviewed and has the lgtm label, please assign cdrage for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the size/S Denotes a PR that changes 10-29 lines, ignoring generated files. label Oct 2, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #2136.

@dependabot dependabot Bot closed this Oct 5, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/github.com/compose-spec/compose-go/v2-2.16.0 branch October 5, 2026 14:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. dependencies Pull requests that update a dependency file go Pull requests that update Go code size/S Denotes a PR that changes 10-29 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants