Skip to content

chore(deps): Bump github.com/automa-saga/automa from 0.11.0 to 0.11.1 - #844

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/automa-saga/automa-0.11.1
Open

chore(deps): Bump github.com/automa-saga/automa from 0.11.0 to 0.11.1#844
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/automa-saga/automa-0.11.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 13, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/automa-saga/automa from 0.11.0 to 0.11.1.

Release notes

Sourced from github.com/automa-saga/automa's releases.

v0.11.1

0.11.1 (2026-07-11)

Bug Fixes

  • deps: upgrade Go to 1.26.5 to remediate SNYK-GOLANG-STDOS-17905377 (#108) (88afed7)
Commits
  • 88afed7 fix(deps): upgrade Go to 1.26.5 to remediate SNYK-GOLANG-STDOS-17905377 (#108)
  • f38858d build(deps): bump actions/setup-node from 6.2.0 to 6.4.0 (#102)
  • dc5aa9c build(deps): bump actions/checkout from 6.0.2 to 7.0.0 (#103)
  • ea45fed build(deps): bump actions/setup-go from 6.2.0 to 6.5.0 (#104)
  • 22eb10f build(deps): bump arduino/setup-task from 2.0.0 to 3.0.0 (#105)
  • 7c6e4bb chore(deps): upgrade Go to 1.26.5 to align with org standard (#107)
  • 8d74568 build(deps): bump step-security/harden-runner from 2.14.1 to 2.19.4 (#100)
  • bee2b08 build(deps): bump golang.org/x/sync from 0.19.0 to 0.22.0 (#106)
  • 20288c2 docs: add specification docs (#97)
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Jul 13, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner July 13, 2026 02:24
@dependabot
dependabot Bot requested a review from tomzhenghedera July 13, 2026 02:24
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Jul 13, 2026
@swirlds-automation

swirlds-automation commented Jul 13, 2026

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@dependabot
dependabot Bot force-pushed the dependabot/go_modules/github.com/automa-saga/automa-0.11.1 branch 2 times, most recently from 63b0ebf to 4dde9f3 Compare July 24, 2026 04:23
@alex-au

alex-au commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/go_modules/github.com/automa-saga/automa-0.11.1 branch from 4dde9f3 to 9303db4 Compare July 28, 2026 07:57
@radkomih
radkomih force-pushed the dependabot/go_modules/github.com/automa-saga/automa-0.11.1 branch from 9303db4 to 6c5eed4 Compare July 29, 2026 07:10
@alex-au

alex-au commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

🤖 Dependabot review — no concerns

Reviewed the diff for github.com/automa-saga/automa: 0.11.00.11.1 (Go non-vendored upgrade).

Purpose: Security bump — upgrades the module’s minimum Go toolchain from 1.25.0 to 1.26.5 to remediate SNYK-GOLANG-STDOS-17905377, plus bumps golang.org/x/sync from 0.19.0 to 0.22.0.

Upstream compare (v0.11.0...v0.11.1) — 10 files, 9 commits:

File Verdict
go.mod / go.sum Go 1.25.0→1.26.5, golang.org/x/sync 0.19.0→0.22.0 — expected
.github/workflows/*.yaml (4 files) Upstream-only CI; Go version pin + SHA-pinned action bumps — all action refs remain commit-SHA pinned, no tag-only downgrades
docs/ (4 added files) Documentation only — no runtime impact

Checks performed:

  • ✅ Diff scoped to expected files (go.mod, go.sum only — no vendor/ changes, no application source)
  • ✅ No Go source (.go) files changed in upstream module between v0.11.0 and v0.11.1
  • ✅ No install/build hooks added or modified
  • ✅ No new process spawning, network, or credential-access patterns
  • ✅ No workflow / CI changes in our repo
  • ✅ No obfuscated payloads (base64 blobs, bidi/zero-width chars)
  • ✅ No unexpected file additions or deletions in our diff
  • go.sum hash entries updated (2 old removed, 2 new added) — consistent with a single module version change
  • ✅ Upstream commit authors are known maintainers (leninmehedy) and dependabot[bot]
  • ✅ All upstream CI action refs remain commit-SHA pinned (no tag-only pins introduced)
  • ✅ No bidi/zero-width obfuscation in diff

Automated review by Claude. Verify before merging — this is a second pair of eyes, not a replacement for human review.

@alex-au

alex-au commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Jul 31, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

Bumps [github.com/automa-saga/automa](https://github.com/automa-saga/automa) from 0.11.0 to 0.11.1.
- [Release notes](https://github.com/automa-saga/automa/releases)
- [Commits](automa-saga/automa@v0.11.0...v0.11.1)

---
updated-dependencies:
- dependency-name: github.com/automa-saga/automa
  dependency-version: 0.11.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Rado M <radkomih@gmail.com>
@radkomih
radkomih force-pushed the dependabot/go_modules/github.com/automa-saga/automa-0.11.1 branch from 6c5eed4 to 90097c2 Compare August 4, 2026 12:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants