Skip to content

build(deps): bump the minor-and-patch group across 1 directory with 4 updates - #127

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/minor-and-patch-e53cc38e04
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/minor-and-patch-e53cc38e04

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 4 updates in the / directory: github.com/go-webauthn/webauthn, github.com/moby/moby/api, go.mongodb.org/mongo-driver/v2 and golang.org/x/oauth2.

Updates github.com/go-webauthn/webauthn from 0.17.4 to 0.18.2

Release notes

Sourced from github.com/go-webauthn/webauthn's releases.

v0.18.2

v0.18.2 (2026-09-19)

Bug Fixes

  • protocol: accept anonca attestation trust anchors (#801) (b1dfbf2)
  • protocol: convey safetynet attestation trust path (#800) (5f8a38c)
  • protocol: validate fido-u2f credential curve and certificate validity (#802) (55d49f8)
  • protocol: validate safetynet version and response age (#799) (dda068d)
  • protocol: validate tpm aik certificate validity period (#797) (9ab858d)
  • webauthn: require authorization to initialize uv (#795) (597882d)
  • webauthn: validate session challenge when finishing ceremonies (#794) (bbe2902)

Features

  • protocol: determine fido-u2f attestation type from metadata (#798) (ccbbb4b)
  • protocol: validate authenticator data against metadata (#793) (1ee00cf)

v0.18.1

0.18.1 (2026-09-10)

This release just updates dependencies.

v0.18.0

0.18.0 (2026-08-27)

This release is a fairly major milestone in the development of this library. It has quite a few breaking changes but has added support for most if not all of the extension requirements natively, and adds formal support for Post-Quantum Cryptography with support for ML-DSA-44, ML-DSA-65, and ML-DSA-87 when used with go 1.27.

Details on the migration requirements for this version can be found int https://github.com/go-webauthn/webauthn/blob/HEAD/MIGRATION.md as they are substantial between ths version and prior versions.

Bug Fixes

  • metadata: align members with mds 3.1.1 and ctap 2.3 (#739) (397152c)
  • metadata: consistent revocation policy and client timeouts (#740) (34d324b)
  • metadata: handle certificate chains of any depth (#737) (309ea69)
  • metadata: honour status report order and effective dates (#736) (8be5355)
  • metadata: mds3 parsing conformance and cache integrity (#735) (8115143)
  • metadata: prevent panic corrupt blob (#698) (c5fd013)
  • metadata: report malformed status report urls (#738) (ed82f7c)
  • protocol: allow any attestation eku (#728) (f4e33fc)
  • protocol: androidkey missing authorization list member (#727) (9b02b19)
  • protocol: androidkey union generated (#729) (3ed3e75)
  • protocol: bind credential public key curve to its algorithm (#752) (314c2be)
  • protocol: compound attestation sub-statement unmarshalling (#751) (a582ecf)
  • protocol: compound returns incorrect type (#731) (025d897)

... (truncated)

Changelog

Sourced from github.com/go-webauthn/webauthn's changelog.

v0.18.2 (2026-09-19)

Bug Fixes

  • protocol: accept anonca attestation trust anchors (#801) (b1dfbf2)
  • protocol: convey safetynet attestation trust path (#800) (5f8a38c)
  • protocol: validate fido-u2f credential curve and certificate validity (#802) (55d49f8)
  • protocol: validate safetynet version and response age (#799) (dda068d)
  • protocol: validate tpm aik certificate validity period (#797) (9ab858d)
  • webauthn: require authorization to initialize uv (#795) (597882d)
  • webauthn: validate session challenge when finishing ceremonies (#794) (bbe2902)

Features

  • protocol: determine fido-u2f attestation type from metadata (#798) (ccbbb4b)
  • protocol: validate authenticator data against metadata (#793) (1ee00cf)

0.18.1 (2026-09-10)

This release just updates dependencies.

0.18.0 (2026-08-27)

This release is a fairly major milestone in the development of this library. It has quite a few breaking changes but has added support for most if not all of the extension requirements natively, and adds formal support for Post-Quantum Cryptography with support for ML-DSA-44, ML-DSA-65, and ML-DSA-87 when used with go 1.27.

Details on the migration requirements for this version can be found int [MIGRATION.md] as they are substantial between ths version and prior versions.

Bug Fixes

  • metadata: align members with mds 3.1.1 and ctap 2.3 (#739) (397152c)
  • metadata: consistent revocation policy and client timeouts (#740) (34d324b)
  • metadata: handle certificate chains of any depth (#737) (309ea69)
  • metadata: honour status report order and effective dates (#736) (8be5355)
  • metadata: mds3 parsing conformance and cache integrity (#735) (8115143)
  • metadata: prevent panic corrupt blob (#698) (c5fd013)
  • metadata: report malformed status report urls (#738) (ed82f7c)
  • protocol: allow any attestation eku (#728) (f4e33fc)
  • protocol: androidkey missing authorization list member (#727) (9b02b19)
  • protocol: androidkey union generated (#729) (3ed3e75)
  • protocol: bind credential public key curve to its algorithm (#752) (314c2be)
  • protocol: compound attestation sub-statement unmarshalling (#751) (a582ecf)
  • protocol: compound returns incorrect type (#731) (025d897)
  • protocol: credential public key match limited to ECDSA (#732) (b4df26e)
  • protocol: harden credential response and options handling (#763) (de0ae6c)
  • protocol: missing tpm steps (#725) (f9a63f9)

... (truncated)

Commits
  • a4c6fc6 release: v0.18.2 (#803)
  • 55d49f8 fix(protocol): validate fido-u2f credential curve and certificate validity (#...
  • 5f8a38c fix(protocol): convey safetynet attestation trust path (#800)
  • b1dfbf2 fix(protocol): accept anonca attestation trust anchors (#801)
  • dda068d fix(protocol): validate safetynet version and response age (#799)
  • ccbbb4b feat(protocol): determine fido-u2f attestation type from metadata (#798)
  • 9ab858d fix(protocol): validate tpm aik certificate validity period (#797)
  • 1ee00cf feat(protocol): validate authenticator data against metadata (#793)
  • 3f8af2b build(deps): update github/codeql-action action to v4.38.1 (#796)
  • 597882d fix(webauthn): require authorization to initialize uv (#795)
  • Additional commits viewable in compare view

Updates github.com/moby/moby/api from 1.55.0 to 1.56.1

Release notes

Sourced from github.com/moby/moby/api's releases.

api/v1.56.1

1.56.1

Changelog

api/v1.56.0

1.56.0

Changelog

  • GET /containers/json now supports an annotation filter to filter containers by annotation, either by key (annotation=key) or by key and value (annotation="key=value"), similar to the existing label filter. moby/moby#53538
  • POST /containers/create now supports HostConfig.Umask to set the initial umask for a Unix container. When set, the daemon includes the value in the OCI process configuration for the container's entrypoint, exec processes, and healthchecks. When omitted, the runtime's default behavior applies.moby/moby#53463
  • api/docs: sync API docs v1.25 - v1.55. moby/moby#53246
  • api/swagger: Align Healthcheck name with Go struct. moby/moby#53567
  • api/types/plugin: Deprecated plugin.Privileges sorting methods in favor of slices.SortFunc. moby/moby#53511
  • api/types/plugin: fix Privileges Swap implementation. moby/moby#53510
  • api: Bump to 1.56. moby/moby#53425
  • api: document Task.NetworksAttachments in the swagger definition. moby/moby#53082
  • api: remove gotest.tools from tests. moby/moby#53535
  • api: swagger: Use int64 for build query params. moby/moby#53520
  • api: use blackbox testing. moby/moby#53525
  • Fix API reference documenting an unsupported names filter for GET /configs. moby/moby#53447
Commits
  • 14ebc60 Merge pull request #53830 from tonistiigi/update-buildkit-v0.34.0-rc1
  • 8eded0e Merge pull request #53671 from thaJeztah/add_WithHTTPRequestHook
  • c4e39af Merge pull request #53596 from vvoland/c8d-refactor-imgload
  • b8a569e client: add WithHTTPRequestHook option
  • 0fed273 Merge pull request #53803 from thaJeztah/etchosts_cleanups
  • 80c72a3 Merge pull request #53831 from corhere/fix-dnsproxy-servfail-test
  • 1cfa161 daemon/containerd: Split image loading into import and unpack steps
  • e7272aa Merge pull request #53606 from flostellbrink/fix/swagger-yaml-indentation
  • 357096e libnetwork/etchosts: keep file open when updating hosts
  • 012b2ef libnetwork/etchosts: propagate file close errors
  • Additional commits viewable in compare view

Updates go.mongodb.org/mongo-driver/v2 from 2.9.1 to 2.9.2

Release notes

Sourced from go.mongodb.org/mongo-driver/v2's releases.

MongoDB Go Driver 2.9.2

The MongoDB Go Driver Team is pleased to release version 2.9.2 of the official MongoDB Go Driver.

Release Highlights

[!WARNING] Go Driver versions v2.1.0 through v2.8.1 and v2.9.0 through v2.9.1 are affected by a security issue CVE-2026-81521 in Client.BulkWrite. The fix shipped in v2.8.2 but was not included in v2.9.0 or v2.9.1. This release restores the fix for the 2.9 line. Users on v2.9.0 or v2.9.1 are encouraged to upgrade to Go Driver v2.9.2 as soon as possible. Go Driver v1 is not affected.

[!WARNING]
Go Driver versions v1.1.0 and later and v2.0.0 through v2.9.1 are affected by a security issue CVE-2026-107325 in the bson.RawArray.Validate method. This release resolves that security issue in Go Driver v2. Users are encouraged to upgrade to Go Driver v2.9.2 as soon as possible.

This release addresses CVE-2026-81521, a security issue in calling Client.BulkWrite. A caller-controlled database name containing a period ('.') may be interpreted as a different namespace when forwarded to MongoDB. This could redirect operations to a database or collection other than the one intended by the application.

This release addresses CVE-2026-107325, a security issue in calling bson.RawArray.Validate. Calling bson.RawArray.Validate on an array whose declared length is 0 causes a runtime panic.

It also restores a fix from v2.8.1 that was likewise missing from v2.9.0 and v2.9.1: when a command's first attempt failed with a server error and the retry reported NoWritesPerformed, operations such as Database.RunCommand could return a nil error instead of the server error. They now return the original server error.

Sessions now inherit timeoutMS from the client, so operations run in a session honor the client-level timeout.

What's Changed

🐛 Fixed

Full Changelog: mongodb/mongo-go-driver@v2.9.1...v2.9.2

Commits
  • df261dc BUMP v2.9.2
  • 16b6195 GODRIVER-4088 Return the server error when the first attempt fails wi… (#2666)
  • de647b7 GODRIVER-4075 Return an error if there are invalid characters in the … (#2665)
  • 59c2e6b GODRIVER-4177 guard empty documents slice in decodeOpReply QueryFailure branc...
  • 15edca6 GODRIVER-4138 Latest server binary downloads require private S3. (#2660)
  • 74278b9 GODRIVER-4118 fix: correct Truncate boundary handling for multi-byte UTF-8 ch...
  • 13954c2 GODRIVER-4168: Authenticate the Claude review with the drivers PR bot app (#2...
  • 8f9da57 GODRIVER-4168: Run Claude review only when the claude-review label is applied...
  • 44ee9af GODRIVER-4168: Add Claude GitHub workflow (#2632)
  • a097394 GODRIVER-4136: reject BSON lengths below the 5-byte minimum before slicing (#...
  • Additional commits viewable in compare view

Updates golang.org/x/oauth2 from 0.36.0 to 0.37.0

Commits
  • c624b89 google: change the snake case endpoint to kebab-case
  • 09a82f6 all: upgrade go directive to at least 1.26.0 [generated]
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

… updates

Bumps the minor-and-patch group with 4 updates in the / directory: [github.com/go-webauthn/webauthn](https://github.com/go-webauthn/webauthn), [github.com/moby/moby/api](https://github.com/moby/moby), [go.mongodb.org/mongo-driver/v2](https://github.com/mongodb/mongo-go-driver) and [golang.org/x/oauth2](https://github.com/golang/oauth2).


Updates `github.com/go-webauthn/webauthn` from 0.17.4 to 0.18.2
- [Release notes](https://github.com/go-webauthn/webauthn/releases)
- [Changelog](https://github.com/go-webauthn/webauthn/blob/master/CHANGELOG.md)
- [Commits](go-webauthn/webauthn@v0.17.4...v0.18.2)

Updates `github.com/moby/moby/api` from 1.55.0 to 1.56.1
- [Release notes](https://github.com/moby/moby/releases)
- [Commits](moby/moby@api/v1.55.0...api/v1.56.1)

Updates `go.mongodb.org/mongo-driver/v2` from 2.9.1 to 2.9.2
- [Release notes](https://github.com/mongodb/mongo-go-driver/releases)
- [Commits](mongodb/mongo-go-driver@v2.9.1...v2.9.2)

Updates `golang.org/x/oauth2` from 0.36.0 to 0.37.0
- [Commits](golang/oauth2@v0.36.0...v0.37.0)

---
updated-dependencies:
- dependency-name: github.com/go-webauthn/webauthn
  dependency-version: 0.18.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/moby/moby/api
  dependency-version: 1.56.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: go.mongodb.org/mongo-driver/v2
  dependency-version: 2.9.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: golang.org/x/oauth2
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 9, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants