Skip to content

chore(deps): bump the minor-and-patch group with 9 updates#34

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/minor-and-patch-cd8f3fd0ab
Open

chore(deps): bump the minor-and-patch group with 9 updates#34
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/minor-and-patch-cd8f3fd0ab

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 19, 2026

Bumps the minor-and-patch group with 9 updates:

Package From To
github.com/a-h/templ 0.3.1001 0.3.1020
github.com/go-webauthn/webauthn 0.15.0 0.17.3
go.mongodb.org/mongo-driver/v2 2.5.0 2.6.0
golang.org/x/crypto 0.48.0 0.51.0
golang.org/x/oauth2 0.35.0 0.36.0
github.com/golang-jwt/jwt/v5 5.3.0 5.3.1
github.com/xraph/dispatch 1.4.0 1.5.1
github.com/xraph/ledger 1.4.0 1.5.1
github.com/xraph/vault 1.4.0 1.5.2

Updates github.com/a-h/templ from 0.3.1001 to 0.3.1020

Release notes

Sourced from github.com/a-h/templ's releases.

v0.3.1020

Changelog

  • 09d6b02 chore: bump version
  • a411f13 chore: fix linter warning in test code
  • 524cd39 feat: add -check flag, closes #1007 (#1373)
  • f3d595c feat: add Range to ExpressionAttribute nodes (#1347)
  • 82af17c feat: add Range to GoCode nodes (#1348)
  • cf98cdc feat: add Range to StringExpression nodes (#1349)
  • ff38cee feat: add ranges for attribute node values (#1383)
  • 552ed02 feat: support concurrent rendering of templ components (#1359)
  • b310a97 fix(generatecmd): check cmd.Start() error before inserting cmd in to running map (#1382)
  • 410a80e fix(lsp): delete $GOROOT hack in uri.File
  • 95a0854 fix: allow JSFuncCall on arbitrary HTML attributes (#1375)
  • e581c01 fix: attributes containing a conditional, are always multiline (#1380)
  • b2952ed fix: clear children context in Fragment.Render (#1360)
  • 8fecf2d fix: prevent corrupted output in watch mode with gzip, fixes #1365 (#1366)
  • 7adcb62 fix: show correct updates based on written Go files without watch (#1363)
  • aa493e0 fix: track Range for non-JavaScript ScriptExpression nodes (#1350)
  • d52d64e fix: use dedicated shadow host in Suspense example to ensure header is rendered (#1370)
  • 83176f9 fix: vulnerabilities in x/net (only affects templ watch mode and tests), fixes #1354
Commits
  • 09d6b02 chore: bump version
  • ff38cee feat: add ranges for attribute node values (#1383)
  • e581c01 fix: attributes containing a conditional, are always multiline (#1380)
  • b310a97 fix(generatecmd): check cmd.Start() error before inserting cmd in to `run...
  • 95a0854 fix: allow JSFuncCall on arbitrary HTML attributes (#1375)
  • 8fecf2d fix: prevent corrupted output in watch mode with gzip, fixes #1365 (#1366)
  • a411f13 chore: fix linter warning in test code
  • 524cd39 feat: add -check flag, closes #1007 (#1373)
  • d52d64e fix: use dedicated shadow host in Suspense example to ensure header is render...
  • 552ed02 feat: support concurrent rendering of templ components (#1359)
  • Additional commits viewable in compare view

Updates github.com/go-webauthn/webauthn from 0.15.0 to 0.17.3

Release notes

Sourced from github.com/go-webauthn/webauthn's releases.

v0.17.3

v0.17.3 (2026-05-09)

Dependency Updates

This release just contains updates to dependencies.

v0.17.2

v0.17.2 (2026-05-03)

Bug Fixes

  • webauthn: include verify attestation func for credential (#679) (1f354c8)

v0.17.1

0.17.1 (2026-05-03)

Bug Fixes

v0.17.0

0.17.0 (2026-04-21)

Bug Fixes

  • protocol: short-circuit apple attestation extension lookup (#664) (5296bc7)

Features

  • webauthn: add authenticator registration filtering (#668) (0be632e)
  • webauthn: credential message pack (#660) (c7d933c)

BREAKING CHANGES

  • A bug with the Credential Record which was introduced early in the libraries lifecycle has resulted in a breaking change to the Credential struct. If you are manually serializing this struct instead of using encoding/json you will be required to make manual changes; though Integrators

... (truncated)

Changelog

Sourced from github.com/go-webauthn/webauthn's changelog.

v0.17.3 (2026-05-09)

Dependency Updates

This release just contains updates to dependencies.

v0.17.2 (2026-05-03)

Bug Fixes

  • webauthn: include verify attestation func for credential (#679) (1f354c8)

0.17.1 (2026-05-03)

Bug Fixes

0.17.0 (2026-04-21)

Bug Fixes

  • protocol: short-circuit apple attestation extension lookup (#664) (5296bc7)

Features

  • webauthn: add authenticator registration filtering (#668) (0be632e)
  • webauthn: credential message pack (#660) (c7d933c)

BREAKING CHANGES

  • A bug with the Credential Record which was introduced early in the libraries lifecycle has resulted in a breaking change to the Credential struct. If you are manually serializing this struct instead of using encoding/json you will be required to make manual changes; though Integrators should consider these notes regardless.

    • protocol.CredentialTypeFIDOU2F has been removed; replace uses with protocol.AttestationFormatFIDOUniversalSecondFactor

... (truncated)

Commits
  • ff07f7c release: v0.17.3 (#687)
  • 85b47be build(deps): update module github.com/go-webauthn/x to v0.2.5 (#685)
  • be289c2 build(deps): update actions/dependency-review-action action to v5 (#684)
  • c8c55a7 build(deps): update go toolchain directive to v1.26.3 (#683)
  • 52dd499 build(deps): update github/codeql-action action to v4.35.4 (#682)
  • ddd7829 build(deps): update module github.com/fxamacker/cbor/v2 to v2.9.2 (#681)
  • 1cdfb45 release: v0.17.2 (#680)
  • 1f354c8 fix(webauthn): include verify attestation func for credential (#679)
  • de0a809 docs: fix changelog (#678)
  • ec12181 release: v0.17.1 (#677)
  • Additional commits viewable in compare view

Updates go.mongodb.org/mongo-driver/v2 from 2.5.0 to 2.6.0

Release notes

Sourced from go.mongodb.org/mongo-driver/v2's releases.

MongoDB Go Driver 2.6.0

The MongoDB Go Driver Team is pleased to release version 2.6.0 of the official MongoDB Go Driver.

Release Highlights

[!IMPORTANT] Go Driver v2.6 will be the last minor version to support MongoDB 4.2. Go Driver v2.7 will require MongoDB 4.4 or newer.

This release adds support for MongoDB's Intelligent Workload Management (IWM) and ingress connection rate limiting features. The driver now gracefully handles write-blocking scenarios and optimizes connection establishment during high-load conditions to maintain application availability.

Two new methods of ClientOptions are available:

  • SetMaxAdaptiveRetries - specifies the maximum number of times the driver should retry operations that fail with a server side overload error. If not invoked, the default is 2. MaxAdaptiveRetries can also be set through the "maxAdaptiveRetries" URI option (e.g. "maxAdaptiveRetries=5").
  • SetEnableOverloadRetargeting - specifies whether the driver should enable overload retargeting for operations that fail with a server side overload error. If not invoked, the default is false. EnableOverloadRetargeting can also be set through the "enableOverloadRetargeting" URI option (e.g. "enableOverloadRetargeting=true").

What's Changed

✨ New Features

Full Changelog: mongodb/mongo-go-driver@v2.5.1...v2.6.0

For a full list of tickets included in this release, please see the list of fixed issues.

Documentation for the Go Driver can be found on pkg.go.dev and the MongoDB documentation site. BSON library documentation is also available on pkg.go.dev. For issues with, questions about, or feedback for the Go Driver, please look into our support channels, including StackOverflow. Bugs can be reported in the Go Driver project in the MongoDB JIRA where a list of current issues can be found. Your feedback on the Go Driver is greatly appreciated!

MongoDB Go Driver 2.5.1

The MongoDB Go Driver Team is pleased to release version 2.5.1 of the official MongoDB Go Driver.

Release Highlights

This release fixes two BSON unmarshaling edge cases.

What's Changed

🐛 Fixed

... (truncated)

Commits
  • fd85a83 BUMP v2.6.0
  • 52b385d GODRIVER-3829 Cleanup skip list. (#2369)
  • 71375d7 Bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp from 1.1...
  • 65f4e94 GODRIVER-3870 Use a generic type parameter for retry func in overload code ex...
  • 00ab776 GODRIVER-3849 Update backpressure errors handling examples. (#2365)
  • fa56c25 Bump github/codeql-action from 4.35.1 to 4.35.2 in the actions group (#2367)
  • 4ee727e GODRIVER-3844 Add maxAdaptiveRetries and enableOverloadRetargeting option...
  • 881269a GODRIVER-3810 Update WithTransaction to raise timeout error. (#2344)
  • c1d47f7 Bump actions/upload-artifact from 7.0.0 to 7.0.1 in the actions group (#2361)
  • 9a15470 GODRIVER-3658 Implement backpressure retry logic. (#2353)
  • Additional commits viewable in compare view

Updates golang.org/x/crypto from 0.48.0 to 0.51.0

Commits
  • b8a14a8 go.mod: update golang.org/x dependencies
  • 9d9d507 x509roots/fallback/bundle: fix bundle test with Go 1.27+
  • fd0b90d acme: include Problem in OrderError.Error
  • b9e5359 pbkdf2: turn into a wrapper for crypto/pbkdf2
  • cc0e4fc hkdf: forward Extract to the standard library
  • a8e9237 x509roots/fallback: update bundle
  • 03ca0dc go.mod: update golang.org/x dependencies
  • 8400f4a ssh: respect signer's algorithm preference in pickSignatureAlgorithm
  • 81c6cb3 ssh: swap cbcMinPaddingSize to cbcMinPacketSize to get encLength
  • 982eaa6 go.mod: update golang.org/x dependencies
  • Additional commits viewable in compare view

Updates golang.org/x/oauth2 from 0.35.0 to 0.36.0

Commits
  • 4d954e6 all: upgrade go directive to at least 1.25.0 [generated]
  • See full diff in compare view

Updates github.com/golang-jwt/jwt/v5 from 5.3.0 to 5.3.1

Release notes

Sourced from github.com/golang-jwt/jwt/v5's releases.

v5.3.1

What's Changed

🔐 Features

👒 Dependencies

New Contributors

Full Changelog: golang-jwt/jwt@v5.3.0...v5.3.1

Commits
  • 7ceae61 Add release.yml for changelog configuration
  • dce8e4d Set token.Signature in ParseUnverified (#414)
  • 8889e20 Save signature to Token struct after successful signing (#417)
  • d237f82 ci: update github-actions schedule interval to monthly
  • d8dce95 Bump crate-ci/typos from 1.41.0 to 1.42.1 (#492)
  • e931803 Bump crate-ci/typos from 1.40.0 to 1.41.0 (#490)
  • e6a0afa Bump actions/checkout from 5 to 6 (#487)
  • 9f85c9e Bump crate-ci/typos from 1.39.0 to 1.40.0 (#488)
  • 60a8669 Bump actions/setup-go from 5 to 6 (#469)
  • 76f5828 Remove misleading ParserOptions documentation (#484)
  • Additional commits viewable in compare view

Updates github.com/xraph/dispatch from 1.4.0 to 1.5.1

Release notes

Sourced from github.com/xraph/dispatch's releases.

v1.5.1

Changes

  • build(deps): update Go version to 1.26 in CI configuration (1825a16)
  • chore: update Go version to 1.26 in CI configuration (bf27b81)
  • chore: update dependencies for xraph/forge and xraph/grove to v1.6.4 and v1.5.2 respectively (226c28f)
  • feat: implement DeleteStaleWorkers method to clean up outdated worker entries (0e37c20)
  • feat: add configurable timeouts for worker and cron operations (cf38109)

Installation

go get github.com/xraph/dispatch@v1.5.1

Full Changelog: xraph/dispatch@v1.5.0...v1.5.1

v1.5.0

Changes

  • refactor: enhance scheduler and worker pool with context cancellation support (6d06398)

Installation

go get github.com/xraph/dispatch@v1.5.0

Full Changelog: xraph/dispatch@v1.4.2...v1.5.0

v1.4.2

Changes

  • refactor: update logger initialization and dashboard base path (c91b7ee)

Installation

go get github.com/xraph/dispatch@v1.4.2

... (truncated)

Commits
  • 1825a16 build(deps): update Go version to 1.26 in CI configuration
  • bf27b81 chore: update Go version to 1.26 in CI configuration
  • 226c28f chore: update dependencies for xraph/forge and xraph/grove to v1.6.4 and v1.5...
  • 0e37c20 feat: implement DeleteStaleWorkers method to clean up outdated worker entries
  • cf38109 feat: add configurable timeouts for worker and cron operations
  • 6d06398 refactor: enhance scheduler and worker pool with context cancellation support
  • c91b7ee refactor: update logger initialization and dashboard base path
  • 9e6e530 chore: update grove and its drivers to v1.4.1 in go.mod and go.sum
  • See full diff in compare view

Updates github.com/xraph/ledger from 1.4.0 to 1.5.1

Release notes

Sourced from github.com/xraph/ledger's releases.

v1.5.1

Changes

  • chore: update dependencies for forge to version 1.6.4 and grove to version 1.5.2 (e52e7b1)

Installation

go get github.com/xraph/ledger@v1.5.1

Full Changelog: xraph/ledger@v1.5.0...v1.5.1

v1.5.0

Changes

  • chore: update dependencies for forge to version 1.6.0 and grove to version 1.5.1 (85439cb)

Installation

go get github.com/xraph/ledger@v1.5.0

Full Changelog: xraph/ledger@v1.4.2...v1.5.0

v1.4.2

Changes

  • chore: update dependencies for forge to version 1.4.5 and grove to version 1.4.3 (dc747a5)

Installation

go get github.com/xraph/ledger@v1.4.2

Full Changelog: xraph/ledger@v1.4.1...v1.4.2

v1.4.1

Changes

... (truncated)

Commits
  • e52e7b1 chore: update dependencies for forge to version 1.6.4 and grove to version 1.5.2
  • 85439cb chore: update dependencies for forge to version 1.6.0 and grove to version 1.5.1
  • dc747a5 chore: update dependencies for forge to version 1.4.5 and grove to version 1.4.3
  • a87d3e4 chore: update dependencies for forge and grove to version 1.4.1 and confy to ...
  • See full diff in compare view

Updates github.com/xraph/vault from 1.4.0 to 1.5.2

Release notes

Sourced from github.com/xraph/vault's releases.

v1.5.2

Changes

  • fix: update forge and grove dependencies to latest versions for improved functionality (42b0d5c)
  • fix: refactor watchLoop to use a stop channel for improved control over polling (ba38a48)
  • feat: add initial README with project overview, features, installation, and usage examples (ea3545f)

Installation

go get github.com/xraph/vault@v1.5.2

Full Changelog: xraph/vault@v1.5.0...v1.5.2

v1.4.1

Changes

  • fix: update forge and grove dependencies to version 1.4.1 and confy to version 0.5.0 (d67bed7)

Installation

go get github.com/xraph/vault@v1.4.1

Full Changelog: xraph/vault@v1.4.0...v1.4.1

Commits
  • 42b0d5c fix: update forge and grove dependencies to latest versions for improved func...
  • ba38a48 fix: refactor watchLoop to use a stop channel for improved control over polling
  • ea3545f feat: add initial README with project overview, features, installation, and u...
  • d344f36 feat: integrate vault with confy for config and secrets management
  • 7000337 Refactor import statements in multiple template files for consistency and cla...
  • d67bed7 fix: update forge and grove dependencies to version 1.4.1 and confy to versio...
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [github.com/a-h/templ](https://github.com/a-h/templ) | `0.3.1001` | `0.3.1020` |
| [github.com/go-webauthn/webauthn](https://github.com/go-webauthn/webauthn) | `0.15.0` | `0.17.3` |
| [go.mongodb.org/mongo-driver/v2](https://github.com/mongodb/mongo-go-driver) | `2.5.0` | `2.6.0` |
| [golang.org/x/crypto](https://github.com/golang/crypto) | `0.48.0` | `0.51.0` |
| [golang.org/x/oauth2](https://github.com/golang/oauth2) | `0.35.0` | `0.36.0` |
| [github.com/golang-jwt/jwt/v5](https://github.com/golang-jwt/jwt) | `5.3.0` | `5.3.1` |
| [github.com/xraph/dispatch](https://github.com/xraph/dispatch) | `1.4.0` | `1.5.1` |
| [github.com/xraph/ledger](https://github.com/xraph/ledger) | `1.4.0` | `1.5.1` |
| [github.com/xraph/vault](https://github.com/xraph/vault) | `1.4.0` | `1.5.2` |


Updates `github.com/a-h/templ` from 0.3.1001 to 0.3.1020
- [Release notes](https://github.com/a-h/templ/releases)
- [Commits](a-h/templ@v0.3.1001...v0.3.1020)

Updates `github.com/go-webauthn/webauthn` from 0.15.0 to 0.17.3
- [Release notes](https://github.com/go-webauthn/webauthn/releases)
- [Changelog](https://github.com/go-webauthn/webauthn/blob/master/CHANGELOG.md)
- [Commits](go-webauthn/webauthn@v0.15.0...v0.17.3)

Updates `go.mongodb.org/mongo-driver/v2` from 2.5.0 to 2.6.0
- [Release notes](https://github.com/mongodb/mongo-go-driver/releases)
- [Commits](mongodb/mongo-go-driver@v2.5.0...v2.6.0)

Updates `golang.org/x/crypto` from 0.48.0 to 0.51.0
- [Commits](golang/crypto@v0.48.0...v0.51.0)

Updates `golang.org/x/oauth2` from 0.35.0 to 0.36.0
- [Commits](golang/oauth2@v0.35.0...v0.36.0)

Updates `github.com/golang-jwt/jwt/v5` from 5.3.0 to 5.3.1
- [Release notes](https://github.com/golang-jwt/jwt/releases)
- [Commits](golang-jwt/jwt@v5.3.0...v5.3.1)

Updates `github.com/xraph/dispatch` from 1.4.0 to 1.5.1
- [Release notes](https://github.com/xraph/dispatch/releases)
- [Commits](xraph/dispatch@v1.4.0...v1.5.1)

Updates `github.com/xraph/ledger` from 1.4.0 to 1.5.1
- [Release notes](https://github.com/xraph/ledger/releases)
- [Commits](xraph/ledger@v1.4.0...v1.5.1)

Updates `github.com/xraph/vault` from 1.4.0 to 1.5.2
- [Release notes](https://github.com/xraph/vault/releases)
- [Commits](xraph/vault@v1.4.0...v1.5.2)

---
updated-dependencies:
- dependency-name: github.com/a-h/templ
  dependency-version: 0.3.1020
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: github.com/go-webauthn/webauthn
  dependency-version: 0.17.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: go.mongodb.org/mongo-driver/v2
  dependency-version: 2.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: golang.org/x/crypto
  dependency-version: 0.51.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: golang.org/x/oauth2
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/golang-jwt/jwt/v5
  dependency-version: 5.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: github.com/xraph/dispatch
  dependency-version: 1.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/xraph/ledger
  dependency-version: 1.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/xraph/vault
  dependency-version: 1.5.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels May 19, 2026
@vercel
Copy link
Copy Markdown

vercel Bot commented May 19, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
authsome Ready Ready Preview, Comment May 19, 2026 3:16am

Request Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants