Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 11, 2026

Bumps the go-modules group with 7 updates:

Package From To
cloud.google.com/go/storage 1.59.2 1.60.0
github.com/anchore/stereoscope 0.1.19 0.1.20
github.com/anchore/syft 1.41.2 1.42.0
github.com/gpustack/gguf-parser-go 0.23.1 0.24.0
google.golang.org/api 0.265.0 0.266.0
google.golang.org/genproto/googleapis/api 0.0.0-20260128011058-8636f8732409 0.0.0-20260203192932-546029d2fa20
google.golang.org/genproto/googleapis/rpc 0.0.0-20260128011058-8636f8732409 0.0.0-20260203192932-546029d2fa20

Updates cloud.google.com/go/storage from 1.59.2 to 1.60.0

Release notes

Sourced from cloud.google.com/go/storage's releases.

storage 1.60.0

1.60.0 (2026-02-10)

Features

  • adding support for max-retry-duration for all api other than resumable-upload (#13749) (31c352bd)

  • support checksum validation in resumable json uploads (#13573) (337ca078)

  • Added a new field ComposeObjectRequest.delete_source_objects field (PiperOrigin-RevId: 863087065) (611f2392)

Bug Fixes

Documentation

  • Updated documentation for BidiReadObject, ReadObjectRequest, and ObjectContexts (PiperOrigin-RevId: 863087065) (611f2392)
Commits

Updates github.com/anchore/stereoscope from 0.1.19 to 0.1.20

Release notes

Sourced from github.com/anchore/stereoscope's releases.

v0.1.20

Bug Fixes

Dependency Updates

(Full Changelog)

Commits
  • 3e0f488 chore(deps): bump zizmorcore/zizmor-action in /.github/workflows (#519)
  • 87104f7 chore(deps): bump github.com/bmatcuk/doublestar/v4 from 4.9.2 to 4.10.0 (#515)
  • 99f8b53 chore(deps): bump github.com/docker/cli (#516)
  • 79a22ab chore(deps): bump actions/cache in /.github/actions/bootstrap (#517)
  • c61a6f2 chore(deps): bump actions/cache in /.github/workflows (#518)
  • f24caab fix: missing path segments after untarring (#514)
  • See full diff in compare view

Updates github.com/anchore/syft from 1.41.2 to 1.42.0

Release notes

Sourced from github.com/anchore/syft's releases.

v1.42.0

Added Features

Additional Changes

  • CPE detection for APK libavif to use aomedia vendor [#4597 @​naag]

(Full Changelog)

Commits
  • 9872ff3 chore(deps): update anchore dependencies (#4613)
  • 31c5031 chore(deps): bump github.com/go-git/go-git/v5 from 5.16.4 to 5.16.5 (#4612)
  • 2c5e193 feat: Add support for scanning GGUF models from OCI registries (#4335)
  • 3a23cff chore(deps): update CPE dictionary index (#4610)
  • 443de21 chore(deps): bump github.com/bmatcuk/doublestar/v4 (#4606)
  • 1af8b1a chore(deps): bump the actions-minor-patch group across 2 directories with 2 u...
  • c185657 feat: add yarn lock dev dep detection; fixed #4548
  • 48ee12b ci(generate-capabilities): serialize writing and reading yaml (#4602)
  • 0b05f0e chore(deps): update CPE dictionary index (#4601)
  • 138cb1b fix(cpe-generation): set start and end date (#4600)
  • Additional commits viewable in compare view

Updates github.com/gpustack/gguf-parser-go from 0.23.1 to 0.24.0

Commits
  • a25d157 fix: validate GGUF header fields before allocations to prevent OOM (#18)
  • See full diff in compare view

Updates google.golang.org/api from 0.265.0 to 0.266.0

Release notes

Sourced from google.golang.org/api's releases.

v0.266.0

0.266.0 (2026-02-10)

Features

Changelog

Sourced from google.golang.org/api's changelog.

0.266.0 (2026-02-10)

Features

Commits

Updates google.golang.org/genproto/googleapis/api from 0.0.0-20260128011058-8636f8732409 to 0.0.0-20260203192932-546029d2fa20

Commits

Updates google.golang.org/genproto/googleapis/rpc from 0.0.0-20260128011058-8636f8732409 to 0.0.0-20260203192932-546029d2fa20

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-modules group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [cloud.google.com/go/storage](https://github.com/googleapis/google-cloud-go) | `1.59.2` | `1.60.0` |
| [github.com/anchore/stereoscope](https://github.com/anchore/stereoscope) | `0.1.19` | `0.1.20` |
| [github.com/anchore/syft](https://github.com/anchore/syft) | `1.41.2` | `1.42.0` |
| [github.com/gpustack/gguf-parser-go](https://github.com/gpustack/gguf-parser-go) | `0.23.1` | `0.24.0` |
| [google.golang.org/api](https://github.com/googleapis/google-api-go-client) | `0.265.0` | `0.266.0` |
| [google.golang.org/genproto/googleapis/api](https://github.com/googleapis/go-genproto) | `0.0.0-20260128011058-8636f8732409` | `0.0.0-20260203192932-546029d2fa20` |
| [google.golang.org/genproto/googleapis/rpc](https://github.com/googleapis/go-genproto) | `0.0.0-20260128011058-8636f8732409` | `0.0.0-20260203192932-546029d2fa20` |


Updates `cloud.google.com/go/storage` from 1.59.2 to 1.60.0
- [Release notes](https://github.com/googleapis/google-cloud-go/releases)
- [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/CHANGES.md)
- [Commits](googleapis/google-cloud-go@storage/v1.59.2...spanner/v1.60.0)

Updates `github.com/anchore/stereoscope` from 0.1.19 to 0.1.20
- [Release notes](https://github.com/anchore/stereoscope/releases)
- [Changelog](https://github.com/anchore/stereoscope/blob/main/RELEASE.md)
- [Commits](anchore/stereoscope@v0.1.19...v0.1.20)

Updates `github.com/anchore/syft` from 1.41.2 to 1.42.0
- [Release notes](https://github.com/anchore/syft/releases)
- [Changelog](https://github.com/anchore/syft/blob/main/RELEASE.md)
- [Commits](anchore/syft@v1.41.2...v1.42.0)

Updates `github.com/gpustack/gguf-parser-go` from 0.23.1 to 0.24.0
- [Release notes](https://github.com/gpustack/gguf-parser-go/releases)
- [Commits](gpustack/gguf-parser-go@v0.23.1...v0.24.0)

Updates `google.golang.org/api` from 0.265.0 to 0.266.0
- [Release notes](https://github.com/googleapis/google-api-go-client/releases)
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md)
- [Commits](googleapis/google-api-go-client@v0.265.0...v0.266.0)

Updates `google.golang.org/genproto/googleapis/api` from 0.0.0-20260128011058-8636f8732409 to 0.0.0-20260203192932-546029d2fa20
- [Commits](https://github.com/googleapis/go-genproto/commits)

Updates `google.golang.org/genproto/googleapis/rpc` from 0.0.0-20260128011058-8636f8732409 to 0.0.0-20260203192932-546029d2fa20
- [Commits](https://github.com/googleapis/go-genproto/commits)

---
updated-dependencies:
- dependency-name: cloud.google.com/go/storage
  dependency-version: 1.60.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: go-modules
- dependency-name: github.com/anchore/stereoscope
  dependency-version: 0.1.20
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: go-modules
- dependency-name: github.com/anchore/syft
  dependency-version: 1.42.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: go-modules
- dependency-name: github.com/gpustack/gguf-parser-go
  dependency-version: 0.24.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: go-modules
- dependency-name: google.golang.org/api
  dependency-version: 0.266.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: go-modules
- dependency-name: google.golang.org/genproto/googleapis/api
  dependency-version: 0.0.0-20260203192932-546029d2fa20
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: go-modules
- dependency-name: google.golang.org/genproto/googleapis/rpc
  dependency-version: 0.0.0-20260203192932-546029d2fa20
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: go-modules
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Feb 11, 2026
@idiap-bot idiap-bot added the semver:patch A change requiring a patch version bump label Feb 11, 2026
@idiap-bot idiap-bot merged commit 6d64a3e into main Feb 11, 2026
10 of 11 checks passed
@idiap-bot idiap-bot deleted the dependabot/go_modules/go-modules-cc8c39ebc9 branch February 11, 2026 15:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code semver:patch A change requiring a patch version bump

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants