Skip to content

build(deps): bump the go_modules group across 1 directory with 2 updates - #101

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go_modules-c76b47e5b1
Open

build(deps): bump the go_modules group across 1 directory with 2 updates#101
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go_modules-c76b47e5b1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 25, 2026

Copy link
Copy Markdown

Bumps the go_modules group with 2 updates in the / directory: github.com/go-git/go-git/v5 and github.com/labstack/echo/v4.

Updates github.com/go-git/go-git/v5 from 5.19.1 to 5.19.2

Release notes

Sourced from github.com/go-git/go-git/v5's releases.

v5.19.2

What's Changed

Full Changelog: go-git/go-git@v5.19.1...v5.19.2

Commits
  • 3eeb238 Merge pull request #2277 from go-git/checkout-v5
  • 008a78f git: worktree, make the filesystem wrapper a symlink-safe boundary
  • 2263fb5 Merge pull request #2268 from go-git/renovate/releases/v5.x-go-golang.org-x-t...
  • 77b7625 build: Update module golang.org/x/text to v0.39.0 [SECURITY]
  • 85ea767 Merge pull request #2267 from go-git/renovate/releases/v5.x-go-golang.org-x-n...
  • 198675a build: Update module golang.org/x/net to v0.56.0 [SECURITY]
  • 4a0e66d Merge pull request #2254 from pjbgf/v5-dotgit-ref-name-containment
  • 3b306ef storage: dotgit, align reference-name safety with refname_is_safe
  • f3d0cc1 storage: dotgit, reject path traversal in reference names
  • 979cfe9 Merge pull request #2262 from joshblum/joshblum/to-slash-v5
  • Additional commits viewable in compare view

Updates github.com/labstack/echo/v4 from 4.15.2 to 4.15.3

Release notes

Sourced from github.com/labstack/echo/v4's releases.

v4.15.3 - Static encoded-separator route bypass fix (GHSA-vfp3-v2gw-7wfq)

Security

Fixes GHSA-vfp3-v2gw-7wfq: an encoded path separator (%2F or %5C) in a static file URL could bypass route-level middleware (e.g. authentication on a sibling route) and disclose static files. Both StaticDirectoryHandler (used by Static/StaticFS) and the Static middleware are affected. Backport of the v5 fix (#3009, released in v5.2.0). Thanks to @​a-tt-om and @​oran-gugu for reporting.

Full Changelog: labstack/echo@v4.15.2...v4.15.3

Changelog

Sourced from github.com/labstack/echo/v4's changelog.

v4.15.3 - 2026-06-14

Security

Fixes GHSA-vfp3-v2gw-7wfq: an encoded path separator (%2F or %5C) in a static file URL could bypass route-level middleware (e.g. authentication on a sibling route) and disclose static files. Both StaticDirectoryHandler (used by Static/StaticFS) and the Static middleware are affected. Backport of the v5 fix (#3009). Thanks to @​a-tt-om and @​oran-gugu for reporting.

Commits
  • 8800212 Changelog for v4.15.3 (#3012)
  • c3fa2a2 fix(static): reject encoded path separators that bypass route-level middlewar...
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the go_modules group with 2 updates in the / directory: [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) and [github.com/labstack/echo/v4](https://github.com/labstack/echo).


Updates `github.com/go-git/go-git/v5` from 5.19.1 to 5.19.2
- [Release notes](https://github.com/go-git/go-git/releases)
- [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md)
- [Commits](go-git/go-git@v5.19.1...v5.19.2)

Updates `github.com/labstack/echo/v4` from 4.15.2 to 4.15.3
- [Release notes](https://github.com/labstack/echo/releases)
- [Changelog](https://github.com/labstack/echo/blob/v4.15.3/CHANGELOG.md)
- [Commits](labstack/echo@v4.15.2...v4.15.3)

---
updated-dependencies:
- dependency-name: github.com/go-git/go-git/v5
  dependency-version: 5.19.2
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: github.com/labstack/echo/v4
  dependency-version: 4.15.3
  dependency-type: indirect
  dependency-group: go_modules
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 25, 2026
@github-actions

Copy link
Copy Markdown

Gavel summary

Source Pass Fail Skip Duration

Totals: 0 passed · 0 failed · 0 skipped · -

View full results

@github-actions

Copy link
Copy Markdown

Gavel summary

Source Pass Fail Skip Duration
(unknown) 0 4 0 -
./pkg/cli 0 1 0 -
./pkg/database 0 1 0 -
./pkg/gitagent 0 1 0 -
./pkg/session 0 1 0 -
agentcreds 11 0 0 808.28µs
ai 87 0 0 25ms
aichat 135 0 2 17.7s
anthropicmock 1 0 0 1ms
api 223 0 0 62ms
attachments 5 0 0 5ms
bash 4 0 0 222.152µs
callertools 10 0 0 105ms
captain 17 0 0 13.0s
claude 22 0 0 25ms
claudeagent 13 0 0 275ms
cmux 4 0 0 464.377µs
collections 12 0 0 823.179µs
credentials 5 0 0 38ms
credsync 11 0 0 445ms
deploy 110 0 0 239ms
genkit 25 0 0 100ms
github.com/flanksource/captain/migrations 11 0 0 4.6s
github.com/flanksource/captain/pkg/ai 250 0 0 620ms
github.com/flanksource/captain/pkg/ai/agent 26 0 0 450ms
github.com/flanksource/captain/pkg/ai/agent/commit 56 0 0 4.4s
github.com/flanksource/captain/pkg/ai/agent/setup 16 0 0 60ms
github.com/flanksource/captain/pkg/ai/agent/verify 21 0 0 390ms
github.com/flanksource/captain/pkg/ai/agent/worktree 6 0 0 -
github.com/flanksource/captain/pkg/ai/assistanttags 15 0 0 -
github.com/flanksource/captain/pkg/ai/fixture 42 0 0 360ms
github.com/flanksource/captain/pkg/ai/fixture/kubeproxy 2 0 0 30ms
github.com/flanksource/captain/pkg/ai/fixture/mcpproxy 6 0 0 -
github.com/flanksource/captain/pkg/ai/history 54 0 0 -
github.com/flanksource/captain/pkg/ai/internal/gen-model-registry 12 0 0 -
github.com/flanksource/captain/pkg/ai/middleware 25 0 0 -
github.com/flanksource/captain/pkg/ai/pricing 9 0 0 10ms
github.com/flanksource/captain/pkg/ai/prompt 16 0 0 20ms
github.com/flanksource/captain/pkg/ai/provider 169 0 1 10ms
github.com/flanksource/captain/pkg/ai/provider/claudeagent 54 0 0 2.0s
github.com/flanksource/captain/pkg/ai/provider/cmux 128 0 0 870ms
github.com/flanksource/captain/pkg/ai/provider/genkit 36 0 0 -
github.com/flanksource/captain/pkg/ai/provider/jsonrpc 6 0 0 50ms
github.com/flanksource/captain/pkg/aichat 9 0 0 100ms
github.com/flanksource/captain/pkg/aimock 50 0 7 480ms
github.com/flanksource/captain/pkg/aimock/anthropicmock 14 0 0 10ms
github.com/flanksource/captain/pkg/aimock/openaimock 18 0 0 80ms
github.com/flanksource/captain/pkg/api 143 0 0 500ms
github.com/flanksource/captain/pkg/api/registry 96 0 0 -
github.com/flanksource/captain/pkg/bash 348 0 0 20ms
github.com/flanksource/captain/pkg/captainconfig 25 0 0 -
github.com/flanksource/captain/pkg/captaintoken 23 0 0 2.2s
github.com/flanksource/captain/pkg/claude 138 0 0 -
github.com/flanksource/captain/pkg/claude/tools 18 0 0 -
github.com/flanksource/captain/pkg/cli 779 0 1 1m15s
github.com/flanksource/captain/pkg/cmux 1 0 0 -
github.com/flanksource/captain/pkg/codexconfig 10 0 0 10ms
github.com/flanksource/captain/pkg/container 72 0 1 -
github.com/flanksource/captain/pkg/database 130 0 0 21.2s
github.com/flanksource/captain/pkg/dod 11 0 0 1m0s
github.com/flanksource/captain/pkg/gitagent 31 0 0 370ms
github.com/flanksource/captain/pkg/gitagent/proxy 12 0 0 20ms
github.com/flanksource/captain/pkg/monitor 60 0 0 3.1s
github.com/flanksource/captain/pkg/sandbox 13 0 0 -
github.com/flanksource/captain/pkg/sandbox/adapter 39 0 0 20ms
github.com/flanksource/captain/pkg/sandbox/presets 13 0 0 -
github.com/flanksource/captain/pkg/session 71 0 0 20ms
history 69 0 0 29ms
migrations 12 0 0 4.7s
openaimock 2 0 0 152.606µs
provider 12 0 0 15ms
registry 38 0 0 1ms
tools 53 0 0 3ms

Totals: 3965 passed · 8 failed · 12 skipped · 3m34s

Failing tests

ginkgo Timeout

�[2m16:57:04.546�[0m �[92mINF�[0m reusing existing embedded postgres on port 7432
�[2m16:57:04.947�[0m �[92mINF�[0m reusing existing embedded postgres on port 7432
�[2m16:57:05.565�[0m �[92mINF�[0m reusing existing embedded postgres on port 7432
�[2m16:57:05.977�[0m �[92mINF�[0m reusing existing embedded postgres on port 7432
... (11 more lines truncated)```

#### ginkgo Timeout

Running Suite: GitAgent Suite - /home/runner/work/captain/captain/pkg/gitagent

Random Seed: �[1m1787677018�[0m

... (97 more lines truncated)```

ginkgo Timeout

[1/2] run "direct" iteration 1/1 (model=direct-model)…
    · pid=41944, awaiting first stream-json event…
      → Bash 
      → Bash 
... (92 more lines truncated)```

#### ginkgo Timeout

killed by gavel test-timeout supervisor after 1.805s


#### ginkgo Execution

'/home/runner/work/captain/captain/.ginkgo/ginkgo-report-.-pkg-session-1787677030698867063.json' not found


_... and 3 more failing tests — see the full gavel-results artifact._

[View full results](https://github.com/flanksource/captain/actions/runs/32874007106/artifacts/9573524807)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants