Skip to content

fix(deps): bump the external group across 1 directory with 12 updates - #4010

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/otdfctl/external-8e1b979d50
Open

fix(deps): bump the external group across 1 directory with 12 updates#4010
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/otdfctl/external-8e1b979d50

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the external group with 12 updates in the /otdfctl directory:

Package From To
github.com/charmbracelet/bubbles 0.21.1-0.20250623103423-23b8fd6302d7 1.0.0
github.com/charmbracelet/glamour 0.10.0 1.0.0
github.com/charmbracelet/huh 0.8.0 1.0.0
github.com/evertras/bubble-table 0.19.2 0.22.3
github.com/gabriel-vasile/mimetype 1.4.13 1.4.15
github.com/golang-jwt/jwt/v5 5.3.0 5.3.1
github.com/stretchr/testify 1.11.1 1.12.1
github.com/zitadel/oidc/v3 3.45.1 3.49.6
golang.org/x/oauth2 0.36.0 0.37.0
golang.org/x/term 0.44.0 0.46.0
google.golang.org/grpc 1.83.1 1.83.2
google.golang.org/protobuf 1.36.11 1.36.12

Updates github.com/charmbracelet/bubbles from 0.21.1-0.20250623103423-23b8fd6302d7 to 1.0.0

Release notes

Sourced from github.com/charmbracelet/bubbles's releases.

v1.0.0

This is just an honorary release of Bubbles v1. Stay tuned for the next major version 🫧

Changelog

Fixed

  • d0166363eb8176b331de98dba1d6e997560f216f: fix: changed 'recieve' to 'receive' for 100% quality of Go Report Card (#881) (@​Atennop1)

Thoughts? Questions? We love hearing from you. Feel free to reach out on X, Discord, Slack, The Fediverse, Bluesky.

v0.21.1

Changelog

New!

  • dff42ddb7cf28f022da475c69dba2e74f75af34d: feat: update keybindings in list setSize method (@​Broderick-Westrope)

Fixed

  • c376ce3ef18cc26bbf1f6338cc8518ae329a18d6: fix(cursor): fix data race on blinkTag (#784) (@​DryHumour)
  • 11d52ca426e5c594f7c6c10766935a7f30a83225: fix(table): preventing cursor from being out-of-bounds. (@​s0ders)
  • 49ff5c03b7bada572da36c79269dc15ab03d569b: fix(textinput): improve placeholder (#768) (@​caarlos0)
  • 7c44f63d3185e6f1d795e9369ba85185e6efe956: v1: fix(list): ensure correct cursor positions with page/cursor methods (#831) (@​lrstanley)

Docs

  • 7fcf75da535ee7db938586044a02f0f74f40339e: docs(readme): update footer image and copyright date (@​meowgorithm)
  • d4feefed7d674edbfbc8f09e99c56704706038c5: docs: remove Charm Cloud reference (#785) (@​ShalokShalom)

Other stuff

  • daab808a4d85e0b616ca9e30c1c5d9acd365aa02: ci: sync dependabot config (#786) (@​charmcli)
  • 4b2d311076480670a00b3f24fd9ad280c35c7c57: ci: sync dependabot config (#835) (@​charmcli)
  • 8562e9075fb87edf45e99c5d63a6610254d6c6e7: ci: sync golangci-lint config (#781) (@​github-actions[bot])
  • f54a125f7decd8fefa0db4a0853720200d50a631: test(table): improve table unit tests (#601) (@​Broderick-Westrope)

Thoughts? Questions? We love hearing from you. Feel free to reach out on X, Discord, Slack, The Fediverse, Bluesky.

Commits

Updates github.com/charmbracelet/glamour from 0.10.0 to 1.0.0

Commits
  • 69661fd chore(deps): bump actions/checkout from 5 to 6 in the all group (#491)
  • 0af1a2d chore(deps): bump the all group with 2 updates (#482)
  • a9ec019 chore(deps): bump github.com/charmbracelet/x/ansi in the all group (#477)
  • 7a4cf0c ci: sync dependabot config (#476)
  • 49c8248 chore(deps): bump the all group with 2 updates (#472)
  • c1ce505 chore(deps): bump actions/setup-go from 5 to 6 in the all group (#471)
  • f9c650c ci: sync dependabot config (#470)
  • e3c481b chore(deps): bump actions/checkout from 4 to 5 (#469)
  • 7209389 chore(deps): bump golang.org/x/term from 0.33.0 to 0.34.0 (#468)
  • f447e14 chore(deps): bump github.com/charmbracelet/x/ansi from 0.9.3 to 0.10.1 (#467)
  • Additional commits viewable in compare view

Updates github.com/charmbracelet/huh from 0.8.0 to 1.0.0

Commits
  • 9dc45e3 chore(deps): bump github.com/charmbracelet/bubbles (#733)
  • bffc99a chore(deps): bump github.com/charmbracelet/bubbles (#739)
  • 5c5971e chore(deps): bump github.com/charmbracelet/bubbles (#732)
  • 04fe1e4 ci: sync golangci-lint config
  • cf33835 chore(deps): bump github.com/charmbracelet/x/exp/strings (#729)
  • 6f7d32f chore: minor wording change in match select (#716)
  • 6575a6e chore(deps): bump actions/checkout from 5 to 6 in the all group (#715)
  • 25888d1 chore(deps): bump golangci/golangci-lint-action in the all group (#712)
  • See full diff in compare view

Updates github.com/evertras/bubble-table from 0.19.2 to 0.22.3

Release notes

Sourced from github.com/evertras/bubble-table's releases.

v0.22.3

What's Changed

Full Changelog: Evertras/bubble-table@v0.22.2...v0.22.3

v0.22.2

What's Changed

Full Changelog: Evertras/bubble-table@v0.22.1...v0.22.2

v0.22.1

What's Changed

Full Changelog: Evertras/bubble-table@v0.22.0...v0.22.1

v0.22.0

What's Changed

Full Changelog: Evertras/bubble-table@v0.21.0...v0.22.0

v0.21.0

What's Changed

Full Changelog: Evertras/bubble-table@v0.20.1...v0.21.0

v0.20.1

What's Changed

Full Changelog: Evertras/bubble-table@v0.20.0...v0.20.1

v0.20.0

... (truncated)

Commits
  • 6062daf fix: ensure WithTargetHeight works properly when WithRowBorder is enabled (#230)
  • 38ede76 fix: invalidate pageStartIndices on filter change in targetHeight mode (#229)
  • 88d0435 fix: handle hyphen wrapping bug (#228)
  • 31688b5 feat(#188): add WithTargetHeight for fixed terminal-line pagination (#227)
  • b4aaed1 fix: add WithBorderForeground to all examples (#226)
  • 3017c55 fix(#130): apply column style padding to headers and cells (#225)
  • 1d6b45c feat(#186): add native time.Time sort support (#224)
  • 363b994 fix: prevent HeaderStyle border definitions from breaking table layout (#223)
  • df4a5aa Pr 214 rebased (#222)
  • ffbe1e1 fix(#165): use ansi.StringWidth calculation rather than len (#221)
  • Additional commits viewable in compare view

Updates github.com/gabriel-vasile/mimetype from 1.4.13 to 1.4.15

Release notes

Sourced from github.com/gabriel-vasile/mimetype's releases.

v1.4.15 fix int overflow on 32bit arch

What's Changed

This release fixes an integer overflow panic on 32 bit architectures and retracts the previous release.

Full Changelog: gabriel-vasile/mimetype@v.1.4.14...v1.4.15

v1.4.14 pyc, pcap, cycloned, gedcom support

Media type changes

  • newly added: application/x-bytecode.python, application/vnd.tcpdump.pcap, application/vnd.cyclonedx+xml, application/vnd.cyclonedx+json, text/vnd.familysearch.gedcom
  • superseded and demoted to aliases: image/vnd.mozilla.apng superseded by image/apng video/x-matroska superseded by video/matroska application/x-rar-compressed superseded by application/vnd.rar

Full changelog

New Contributors

Full Changelog: gabriel-vasile/mimetype@v1.4.13...v1.4.14

v1.4.14-rc1 pyc, pcap, cycloned support

... (truncated)

Commits
  • f6bb955 readme: add back contributing section, for #827 (#831)
  • 1b3ab2e fuzz: fuzz for 32 bit too to avoid panics like #829 (#830)
  • 38e5e71 cdf: fix slice index panic on 32bit arch (#829)
  • bcd718d gedcom: add support for text/vnd.familysearch.gedcom (#789)
  • 2995287 build(deps): bump the github-actions group across 1 directory with 7 updates ...
  • 14cefcb fuzz: improvements for exploring more code paths (#824)
  • 5b11e3a scan: fix panic and fuzz flags (#823)
  • 5621f29 charset: stop checking for ascii if utf8 is satisfied (#768)
  • eb8d3f4 docs: mention String() can return different values (#820)
  • 9268756 mkv: use IANA registered media type video/matroska (#819)
  • Additional commits viewable in compare view

Updates github.com/golang-jwt/jwt/v5 from 5.3.0 to 5.3.1

Release notes

Sourced from github.com/golang-jwt/jwt/v5's releases.

v5.3.1

What's Changed

🔐 Features

👒 Dependencies

New Contributors

Full Changelog: golang-jwt/jwt@v5.3.0...v5.3.1

Commits
  • 7ceae61 Add release.yml for changelog configuration
  • dce8e4d Set token.Signature in ParseUnverified (#414)
  • 8889e20 Save signature to Token struct after successful signing (#417)
  • d237f82 ci: update github-actions schedule interval to monthly
  • d8dce95 Bump crate-ci/typos from 1.41.0 to 1.42.1 (#492)
  • e931803 Bump crate-ci/typos from 1.40.0 to 1.41.0 (#490)
  • e6a0afa Bump actions/checkout from 5 to 6 (#487)
  • 9f85c9e Bump crate-ci/typos from 1.39.0 to 1.40.0 (#488)
  • 60a8669 Bump actions/setup-go from 5 to 6 (#469)
  • 76f5828 Remove misleading ParserOptions documentation (#484)
  • Additional commits viewable in compare view

Updates github.com/stretchr/testify from 1.11.1 to 1.12.1

Release notes

Sourced from github.com/stretchr/testify's releases.

v1.12.1

This is the first release which has the minimum dependencies practical in testify v1. The last remaining dependencies are github.com/stretchr/objx which itself has no dependencies, and go.yaml.in/yaml/v3. Removing objx would require v2, it cannot be vendored. Removing YAML would require vendoring the yaml library, which would do more harm than good. It's better to become aware of vulnerabilities in the official yaml package than to attempt to maintain our own.

What's Changed

New Contributors

Full Changelog: stretchr/testify@v1.12.0...v1.12.1

What's Changed

New Contributors

Full Changelog: stretchr/testify@v1.12.0...v1.12.1

v1.12.0

What's Changed

Functional Changes

Fixes

Documentation, Build & CI

... (truncated)

Commits
  • 959dbda Merge pull request #1935 from harryzcy/yaml-update
  • 9bb7176 Update go.yaml.in/yaml/v3 to v3.0.5
  • 001eb79 Merge pull request #1905 from Kentzo/patch-1
  • ad40f38 Merge pull request #1906 from stretchr/dependabot/github_actions/actions/chec...
  • 3bae017 build(deps): bump actions/checkout from 6.0.2 to 6.0.3
  • f8c01f3 mock: Mock.Return does not exist anymore
  • 12f8b56 Merge pull request #1563 from stretchr/make-AssertionFunc-types-aliases
  • a11649e assert: make *AssertionFunc type just aliases
  • dc20f41 Merge pull request #1890 from stretchr/dolmen/codegen-modernize
  • 098f8d7 _codegen: use strings.Builder
  • Additional commits viewable in compare view

Updates github.com/zitadel/oidc/v3 from 3.45.1 to 3.49.6

Release notes

Sourced from github.com/zitadel/oidc/v3's releases.

v3.49.6

3.49.6 (2026-09-04)

Bug Fixes

  • oidc: map ErrSubjectInvalid to invalid_grant instead of server_error (#950) (cb9e7df), closes #945

v3.49.5

3.49.5 (2026-09-03)

Bug Fixes

v3.49.4

3.49.4 (2026-08-28)

Bug Fixes

  • client: avoid mutating caller http.Client in CallRevokeEndpoint (#963) (7a7a91d), closes #911

v3.49.3

3.49.3 (2026-08-27)

Bug Fixes

  • op: guard against nil claims for opaque access tokens in token exchange (#959) (611e1a6), closes #704

v3.49.2

3.49.2 (2026-08-07)

Bug Fixes

  • tracing key, doc rephrasing and guard slog.SetDefault against nil (#935) (65199e0)

v3.49.1

3.49.1 (2026-08-05)

Bug Fixes

  • op: reject requested_token_type that cannot be issued (#932) (1974dae)

v3.49.0

3.49.0 (2026-08-05)

... (truncated)

Commits
  • cb9e7df fix(oidc): map ErrSubjectInvalid to invalid_grant instead of server_error (#950)
  • 2d0c9cb fix(op): stop double-decoding redirect_uri in authorization requests (#969)
  • 24d9a1b chore(deps): bump github/codeql-action from 4.37.8 to 4.37.9 (#970)
  • 7a7a91d fix(client): avoid mutating caller http.Client in CallRevokeEndpoint (#963)
  • 611e1a6 fix(op): guard against nil claims for opaque access tokens in token exchange ...
  • d4abab3 chore: drop v2 support (#960)
  • a1cfbc4 chore(deps): bump github.com/go-chi/chi/v5 from 5.3.1 to 5.3.2 (#956)
  • 101cf01 chore(deps): bump go.opentelemetry.io/otel/trace from 1.44.0 to 1.45.0 (#936)
  • 63d2662 chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.1 (#953)
  • 156df76 chore(deps): bump github/codeql-action from 4.37.6 to 4.37.8 (#958)
  • Additional commits viewable in compare view

Updates golang.org/x/oauth2 from 0.36.0 to 0.37.0

Commits
  • c624b89 google: change the snake case endpoint to kebab-case
  • 09a82f6 all: upgrade go directive to at least 1.26.0 [generated]
  • See full diff in compare view

Updates golang.org/x/term from 0.44.0 to 0.46.0

Commits
  • 6226200 go.mod: update golang.org/x dependencies
  • 7c2fb74 term: process bytes returned with a read error
  • 3963fce all: upgrade go directive to at least 1.26.0 [generated]
  • 9f69229 go.mod: update golang.org/x dependencies
  • See full diff in compare view

Updates google.golang.org/grpc from 1.83.1 to 1.83.2

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.83.2

Security

  • server: Reject requests missing both :authority and Host headers with HTTP 400 and status Internal. (grpc/grpc-go#9365)
Commits

Updates google.golang.org/protobuf from 1.36.11 to 1.36.12

@dependabot
dependabot Bot requested a review from a team as a code owner September 8, 2026 17:54
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 8, 2026
@github-actions github-actions Bot added the size/m label Sep 8, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/otdfctl/external-8e1b979d50 branch from 0443da3 to 4473056 Compare September 8, 2026 18:41
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/otdfctl/external-8e1b979d50 branch from 4473056 to eb36a5c Compare September 9, 2026 17:54
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/otdfctl/external-8e1b979d50 branch from eb36a5c to a84fc65 Compare September 10, 2026 17:54
@coderabbitai

coderabbitai Bot commented Sep 10, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 03c70aad-608d-46c1-90a5-3a0a74026235

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Bumps the external group with 12 updates in the /otdfctl directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/charmbracelet/bubbles](https://github.com/charmbracelet/bubbles) | `0.21.1-0.20250623103423-23b8fd6302d7` | `1.0.0` |
| [github.com/charmbracelet/glamour](https://github.com/charmbracelet/glamour) | `0.10.0` | `1.0.0` |
| [github.com/charmbracelet/huh](https://github.com/charmbracelet/huh) | `0.8.0` | `1.0.0` |
| [github.com/evertras/bubble-table](https://github.com/evertras/bubble-table) | `0.19.2` | `0.22.3` |
| [github.com/gabriel-vasile/mimetype](https://github.com/gabriel-vasile/mimetype) | `1.4.13` | `1.4.15` |
| [github.com/golang-jwt/jwt/v5](https://github.com/golang-jwt/jwt) | `5.3.0` | `5.3.1` |
| [github.com/stretchr/testify](https://github.com/stretchr/testify) | `1.11.1` | `1.12.1` |
| [github.com/zitadel/oidc/v3](https://github.com/zitadel/oidc) | `3.45.1` | `3.49.6` |
| [golang.org/x/oauth2](https://github.com/golang/oauth2) | `0.36.0` | `0.37.0` |
| [golang.org/x/term](https://github.com/golang/term) | `0.44.0` | `0.46.0` |
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.83.1` | `1.83.2` |
| google.golang.org/protobuf | `1.36.11` | `1.36.12` |



Updates `github.com/charmbracelet/bubbles` from 0.21.1-0.20250623103423-23b8fd6302d7 to 1.0.0
- [Release notes](https://github.com/charmbracelet/bubbles/releases)
- [Commits](https://github.com/charmbracelet/bubbles/commits/v1.0.0)

Updates `github.com/charmbracelet/glamour` from 0.10.0 to 1.0.0
- [Release notes](https://github.com/charmbracelet/glamour/releases)
- [Commits](charmbracelet/glamour@v0.10.0...v1.0.0)

Updates `github.com/charmbracelet/huh` from 0.8.0 to 1.0.0
- [Release notes](https://github.com/charmbracelet/huh/releases)
- [Commits](charmbracelet/huh@v0.8.0...v1.0.0)

Updates `github.com/evertras/bubble-table` from 0.19.2 to 0.22.3
- [Release notes](https://github.com/evertras/bubble-table/releases)
- [Commits](Evertras/bubble-table@v0.19.2...v0.22.3)

Updates `github.com/gabriel-vasile/mimetype` from 1.4.13 to 1.4.15
- [Release notes](https://github.com/gabriel-vasile/mimetype/releases)
- [Commits](gabriel-vasile/mimetype@v1.4.13...v1.4.15)

Updates `github.com/golang-jwt/jwt/v5` from 5.3.0 to 5.3.1
- [Release notes](https://github.com/golang-jwt/jwt/releases)
- [Commits](golang-jwt/jwt@v5.3.0...v5.3.1)

Updates `github.com/stretchr/testify` from 1.11.1 to 1.12.1
- [Release notes](https://github.com/stretchr/testify/releases)
- [Commits](stretchr/testify@v1.11.1...v1.12.1)

Updates `github.com/zitadel/oidc/v3` from 3.45.1 to 3.49.6
- [Release notes](https://github.com/zitadel/oidc/releases)
- [Commits](zitadel/oidc@v3.45.1...v3.49.6)

Updates `golang.org/x/oauth2` from 0.36.0 to 0.37.0
- [Commits](golang/oauth2@v0.36.0...v0.37.0)

Updates `golang.org/x/term` from 0.44.0 to 0.46.0
- [Commits](golang/term@v0.44.0...v0.46.0)

Updates `google.golang.org/grpc` from 1.83.1 to 1.83.2
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.83.1...v1.83.2)

Updates `google.golang.org/protobuf` from 1.36.11 to 1.36.12

---
updated-dependencies:
- dependency-name: github.com/charmbracelet/bubbles
  dependency-version: 1.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: external
- dependency-name: github.com/charmbracelet/glamour
  dependency-version: 1.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: external
- dependency-name: github.com/charmbracelet/huh
  dependency-version: 1.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: external
- dependency-name: github.com/evertras/bubble-table
  dependency-version: 0.22.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/gabriel-vasile/mimetype
  dependency-version: 1.4.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: external
- dependency-name: github.com/golang-jwt/jwt/v5
  dependency-version: 5.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: external
- dependency-name: github.com/stretchr/testify
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: github.com/zitadel/oidc/v3
  dependency-version: 3.49.6
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: golang.org/x/oauth2
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: golang.org/x/term
  dependency-version: 0.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: external
- dependency-name: google.golang.org/grpc
  dependency-version: 1.83.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: external
- dependency-name: google.golang.org/protobuf
  dependency-version: 1.36.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: external
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/otdfctl/external-8e1b979d50 branch from a84fc65 to 6e056da Compare September 11, 2026 17:54
@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Govulncheck found vulnerabilities ⚠️

The following modules have known vulnerabilities:

See the workflow run for details.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code size/m

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants