Skip to content

Bump the go group across 1 directory with 3 updates#3482

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/go-828ae07c64
Open

Bump the go group across 1 directory with 3 updates#3482
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/go-828ae07c64

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 12, 2026

Bumps the go group with 3 updates in the / directory: github.com/buger/jsonparser, github.com/jfrog/jfrog-cli-evidence and github.com/jfrog/jfrog-cli-security.

Updates github.com/buger/jsonparser from 1.1.2 to 1.2.0

Release notes

Sourced from github.com/buger/jsonparser's releases.

v1.2.0

What's Changed

Full Changelog: buger/jsonparser@v1.1.2...v1.2.0

Commits
  • c172c16 Merge pull request #269 from buger/tinygo
  • 680cd2e Merge pull request #281 from buger/reqproof-assurance-hardening
  • 9dce61c Migrate review storage from reviews/ folder to per-requirement timestamps
  • c03b9ef feat: add property-based obligation classes with 24 new SYS-REQs
  • 9c46110 chore: fix spec lint warnings — remove stale parent field, set review metadata
  • 8bbb8a8 Close coverage gaps: SYS-REQ-007/008/010 fuzz harness coverage to 100%
  • 552e93b Install Z3 via apt before audit
  • 98133b4 Remove manual Z3 pre-download, now handled by proof-action
  • 1b70ead Debug Z3 pre-download: remove output suppression
  • aac1fbc Pre-download Z3 solver before audit
  • Additional commits viewable in compare view

Updates github.com/jfrog/jfrog-cli-evidence from 0.9.2 to 0.9.4

Release notes

Sourced from github.com/jfrog/jfrog-cli-evidence's releases.

v0.9.3

What's Changed

Improvements & Enhancements 🌱

Other Changes 📚

New Contributors

Full Changelog: jfrog/jfrog-cli-evidence@v0.9.2...v0.9.3

Commits
  • 3916087 Include attachments in create-evidence output (#58)
  • ddc16ad Bump github.com/sigstore/timestamp-authority/v2 from 2.0.5 to 2.0.6 (#50)
  • 7ab5b7f JGC-453 - Fix documentation links (#46)
  • 21c6dd5 Add --format flag support to create-evidence (#54)
  • b58a3e3 ci(e2e): allow fork PR runs via 'safe to test' label (#55)
  • See full diff in compare view

Updates github.com/jfrog/jfrog-cli-security from 1.28.0 to 1.29.0

Release notes

Sourced from github.com/jfrog/jfrog-cli-security's releases.

v1.29.0

What's Changed

Exciting New Features 🎉

Improvements 🌱

Full Changelog: jfrog/jfrog-cli-security@v1.28.0...v1.29.0

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels May 12, 2026
@ehl-jf ehl-jf added the ignore for release Automatically generated release notes label May 12, 2026
Bumps the go group with 3 updates in the / directory: [github.com/buger/jsonparser](https://github.com/buger/jsonparser), [github.com/jfrog/jfrog-cli-evidence](https://github.com/jfrog/jfrog-cli-evidence) and [github.com/jfrog/jfrog-cli-security](https://github.com/jfrog/jfrog-cli-security).


Updates `github.com/buger/jsonparser` from 1.1.2 to 1.2.0
- [Release notes](https://github.com/buger/jsonparser/releases)
- [Commits](buger/jsonparser@v1.1.2...v1.2.0)

Updates `github.com/jfrog/jfrog-cli-evidence` from 0.9.2 to 0.9.4
- [Release notes](https://github.com/jfrog/jfrog-cli-evidence/releases)
- [Commits](jfrog/jfrog-cli-evidence@v0.9.2...v0.9.4)

Updates `github.com/jfrog/jfrog-cli-security` from 1.28.0 to 1.29.0
- [Release notes](https://github.com/jfrog/jfrog-cli-security/releases)
- [Commits](jfrog/jfrog-cli-security@v1.28.0...v1.29.0)

---
updated-dependencies:
- dependency-name: github.com/buger/jsonparser
  dependency-version: 1.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/jfrog/jfrog-cli-evidence
  dependency-version: 0.9.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/jfrog/jfrog-cli-security
  dependency-version: 1.29.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/go_modules/go-828ae07c64 branch from 99dcac1 to 9c4c556 Compare May 13, 2026 07:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code ignore for release Automatically generated release notes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant