Skip to content

chore(deps): bump golang.org/x/text from 0.40.0 to 0.41.0 - #38

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/golang.org/x/text-0.41.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/golang.org/x/text-0.41.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 18, 2026

Copy link
Copy Markdown
Contributor

Bumps golang.org/x/text from 0.40.0 to 0.41.0.

Commits
  • acdba66 go.mod: update golang.org/x dependencies
  • 02aa981 secure/precis: fix short destination buffer handling in Nickname profile
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [golang.org/x/text](https://github.com/golang/text) from 0.40.0 to 0.41.0.
- [Release notes](https://github.com/golang/text/releases)
- [Commits](golang/text@v0.40.0...v0.41.0)

---
updated-dependencies:
- dependency-name: golang.org/x/text
  dependency-version: 0.41.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 18, 2026
jonyoder added a commit that referenced this pull request Aug 28, 2026
Consolidates three dependabot pull requests into one commit, superseding
#41, #38 and #37:

- github.com/stretchr/testify 1.11.1 -> 1.12.1
- golang.org/x/text 0.40.0 -> 0.41.0
- golang.org/x/crypto 0.54.0 -> 0.55.0

testify 1.12 replaces its gopkg.in/yaml.v3 dependency with
go.yaml.in/yaml/v3 v3.0.5, so go.sum drops gopkg.in/yaml.v3 and its
gopkg.in/check.v1 test dependency and gains the new module. Both are
indirect and reached only through testify's assert package.

go mod tidy also moves pgregory.net/rapid v1.3.0 from the indirect to the
direct require block. That is pre-existing drift on main rather than a
consequence of these bumps: tidy makes the same move with the three
versions left alone. rapid is imported by internal/proptest test files,
so direct is the correct classification, and the require-block marker is
metadata that does not affect the import graph. go list -deps ./... still
reports rapid absent and go list -deps -test ./... still reports it
present, so the MPL-2.0 test-only invariant documented in
internal/proptest/gen_test.go is preserved.

Verified with gofmt -l, go build ./..., go vet ./..., go test ./... and
go test -race ./..., all clean with every package reporting ok.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@jonyoder

Copy link
Copy Markdown
Collaborator

Superseded by #50, which consolidated this bump with the other two open dependabot bumps into a single commit so the full suite ran once against all three together. Merged as 2a1fc87. Closing.

@jonyoder jonyoder closed this Aug 28, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 28, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/go_modules/golang.org/x/text-0.41.0 branch August 28, 2026 10:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant