Skip to content

chore(deps): bump the go-modules-root group across 1 directory with 20 updates - #1071

Draft
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-modules-root-7119ff70f7
Draft

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-modules-root-7119ff70f7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the go-modules-root group with 20 updates in the / directory:

Package From To
github.com/containerd/containerd/v2 2.2.5 2.4.0
github.com/containerd/platforms 1.0.0-rc.4 1.0.0-rc.5
github.com/docker/cli 29.4.1+incompatible 29.8.1+incompatible
github.com/docker/docker-credential-helpers 0.9.6 0.9.9
github.com/gpustack/gguf-parser-go 0.24.0 0.26.3
github.com/jaypipes/ghw 0.24.0 0.25.0
github.com/mattn/go-runewidth 0.0.23 0.0.30
github.com/mattn/go-shellwords 1.0.13 1.0.15
github.com/moby/moby/api 1.54.2 1.56.0
github.com/moby/moby/client 0.4.1 0.6.0
github.com/olekukonko/tablewriter 1.1.4 1.1.5
github.com/prometheus/client_model 0.6.2 0.6.3
github.com/prometheus/common 0.67.5 0.70.1
github.com/stretchr/testify 1.11.1 1.12.1
github.com/testcontainers/testcontainers-go 0.42.0 0.44.0
github.com/testcontainers/testcontainers-go/modules/registry 0.42.0 0.44.0
go.opentelemetry.io/otel 1.44.0 1.46.0
golang.org/x/sync 0.22.0 0.23.0
golang.org/x/sys 0.47.0 0.48.0
golang.org/x/term 0.45.0 0.46.0

Updates github.com/containerd/containerd/v2 from 2.2.5 to 2.4.0

Release notes

Sourced from github.com/containerd/containerd/v2's releases.

containerd 2.4.0

Welcome to the v2.4.0 release of containerd!

containerd 2.4 is a regular (non-LTS) release with a shorter support window, intended for users who want to adopt new features sooner. As the release following the 2.3 LTS, it is the point in the release cycle where previously deprecated features may be removed, so this release may include breaking changes; check the notes below and clear any deprecation warnings from your current version before upgrading.

Users prioritizing stability and a longer support lifecycle should stay on the 2.3 LTS release.

Highlights

Container Runtime Interface (CRI)

  • Enable mount manager for image mounts in CRI (#13542)
  • Export sandbox image and CNI directory configuration in CRI plugin info (#13940)
  • Set default runtimeFeatures.UserNamespacesHostNetwork to true (#13162)
  • Support OCI runtime feature introspection for non-runc runtimes (#13504)

Image Distribution

  • Apply hardening to strip sensitive authentication headers when fetching descriptor URLs (#12889)
  • Support propagating HTTP 299 warning headers from registries to the resolver (#12698)
  • Use klauspost/compress for gzip layer decompression (#13560)

Image Storage

  • Add client options to fetch all layer content during unpack even when snapshots exist (#14126)
  • Include media type in content create events (#13833)
  • Add forward References to the GC collection context (#13634)

Node Resource Interface (NRI)

  • Expose container image name, digest, and config digest to NRI plugins (#13960)
  • Emit deprecation warnings for plugins using deprecated NRI interfaces (#13916)

Runtime

  • Mask /proc/interrupts and CPU thermal throttle sysfs paths in Linux containers by default (#14090)
  • Add UpdateSandbox RPC to propagate sandbox controller updates to the shim (#14105)
  • Avoid immediately restarting containers with restart=always policy after they are explicitly stopped (#13993)
  • Pass tracing context from shim to runc and hooks (#14036)
  • Fix user and group lookup failures in container rootfs containing symlinked /etc/passwd or /etc/group (#13818)
  • Implement Windows named-pipe server and log streaming support in pkg/shim (#13948)
  • Enable log scrubbing by default on Windows (#13837)
  • Allow specifying parent checkpoint directory when checkpointing with runc (#13699)

... (truncated)

Changelog

Sourced from github.com/containerd/containerd/v2's changelog.

Versioning and Release

This document details the versioning and release plan for containerd. Stability is a top goal for this project, and we hope that this document and the processes it entails will help to achieve that. It covers the release process, versioning numbering, backporting, API stability and support horizons.

If you rely on containerd, it would be good to spend time understanding the areas of the API that are and are not supported and how they impact your project in the future.

This document will be considered a living document. Supported timelines, backport targets and API stability guarantees will be updated here as they change.

If there is something that you require or this document leaves out, please reach out by filing an issue.

Releases

Releases of containerd will be versioned using dotted triples, similar to Semantic Version. For the purposes of this document, we will refer to the respective components of this triple as <major>.<minor>.<patch>. The version number may have additional information, such as alpha, beta and release candidate qualifications. Such releases will be considered "pre-releases".

Major and Minor Releases

Major and minor releases of containerd will be made from main. Releases of containerd will be marked with GPG signed tags and announced at https://github.com/containerd/containerd/releases. The tag will be of the format v<major>.<minor>.<patch> and should be made with the command git tag -s v<major>.<minor>.<patch>.

After a minor release, a branch will be created, with the format release/<major>.<minor> from the minor tag. All further patch releases will be done from that branch. For example, once we release v1.0.0, a branch release/1.0 will be created from that tag. All future patch releases will be done against that branch.

Release Cadence

Since containerd v2.3 in April 2026, minor releases are provided on a time basis with a cadence of 4 months. New minor releases are scheduled for April, August, and December of each year. This cadence is synchronized with the Kubernetes release schedule to ensure that new features in containerd can be smoothly adopted by new Kubernetes releases.

The maintainers will maintain a roadmap and milestones for each release, however,

... (truncated)

Commits
  • a7fe631 Merge pull request #14169 from samuelkarp/prepare-release-2.4.0
  • 647fafa Prepare release notes for v2.4.0
  • c6d0192 Merge pull request #14170 from samuelkarp/prepare-api-v1.12.0
  • 5c4ea21 Prepare release notes for api/v1.12.0
  • 610d8d8 Merge pull request #14166 from samuelkarp/deprecations-and-removals-for-2.4
  • 531b3a3 tracing: remove deprecated tracing config options
  • ca8579a tracing: add tests for otlp exporter and env vars
  • ee024b7 tracing: remove deprecated otlp configs
  • f7c654f cri: remove deprecated cni bin_dir
  • 4f7de25 cri: remove enable_cdi config option
  • Additional commits viewable in compare view

Updates github.com/containerd/platforms from 1.0.0-rc.4 to 1.0.0-rc.5

Release notes

Sourced from github.com/containerd/platforms's releases.

v1.0.0-rc.5

What's Changed

New Contributors

Full Changelog: containerd/platforms@v1.0.0-rc.4...v1.0.0-rc.5

Commits

Updates github.com/docker/cli from 29.4.1+incompatible to 29.8.1+incompatible

Commits
  • 4a63305 Merge pull request #7297 from docker/dependabot/github_actions/docker-actions...
  • 87ff477 Merge pull request #7307 from thaJeztah/ci_ubuntu_2604
  • 101ffc0 ci: update to Ubuntu 26.04 runners
  • 32ff1e7 build(deps): bump docker/docker-agent-action/.github/workflows/review-pr.yml
  • d146e67 Merge pull request #7290 from vvoland/port-template
  • ac976d9 Merge pull request #7296 from keeltrace/keeltrace/history-timezone-test
  • 48baf6c Merge pull request #7306 from thaJeztah/bump_x_deps
  • 47a06aa Merge pull request #7293 from thaJeztah/bump_uax29
  • 1bf3eb6 Merge pull request #7295 from thaJeztah/bump_userns
  • 60dffc9 vendor: golang.org/x/net v0.59.0
  • Additional commits viewable in compare view

Updates github.com/docker/docker-credential-helpers from 0.9.6 to 0.9.9

Release notes

Sourced from github.com/docker/docker-credential-helpers's releases.

v0.9.9

What's Changed

  • update to go1.26.7
  • Dockerfile: update to debian trixie, libgcc-12-dev, ubuntu 24.04 (noble)
  • README: remove Go Report Card badge
  • build(deps): bump docker/* actions
  • build(deps): bump actions/checkout from 6.0.3 to 7.0.1
  • build(deps): bump actions/setup-go from 6.4.0 to 7.0.0
  • build(deps): bump codecov/codecov-action from 6.0.1 to 7.0.0
  • build(deps): bump crazy-max/.github/.github/workflows/zizmor.yml from 1.10.0 to 1.11.0
  • build(deps): bump softprops/action-gh-release from 3.0.0 to 3.0.2

Full Changelog: docker/docker-credential-helpers@v0.9.8...v0.9.9

v0.9.8

What's Changed

  • update to go1.26.4
  • wincred: inline label, and append to existing
  • build(deps): bump actions/checkout from 6.0.2 to 6.0.3
  • build(deps): bump codecov/codecov-action from 6.0.0 to 6.0.1
  • build(deps): bump crazy-max/.github/.github/workflows/zizmor.yml from 1.7.1 to 1.10.0
  • build(deps): bump docker/bake-action from 7.1.0 to 7.2.0
  • build(deps): bump docker/setup-buildx-action from 4.0.0 to 4.1.0
  • build(deps): bump docker/setup-qemu-action from 4.0.0 to 4.1.0

Full Changelog: docker/docker-credential-helpers@v0.9.7...v0.9.8

v0.9.7

What's Changed

  • update to go1.26.3
  • ci: update zizmore action to v1.7.1

Full Changelog: docker/docker-credential-helpers@v0.9.6...v0.9.7

Commits
  • 59e7cc0 Merge pull request #463 from thaJeztah/bump_go
  • f1c2632 update to go1.26.7
  • 594c023 Merge pull request #462 from thaJeztah/bump_go
  • 3668361 update to go1.26.6
  • 6f4c9aa Merge pull request #457 from docker/dependabot/github_actions/actions/setup-g...
  • 019be48 Merge pull request #460 from docker/dependabot/github_actions/crazy-max/dot-g...
  • 3a74a75 Merge pull request #461 from docker/dependabot/github_actions/docker-actions-...
  • ec72e5a Merge pull request #458 from docker/dependabot/github_actions/actions/checkou...
  • 57e6dc0 build(deps): bump docker/setup-buildx-action
  • 0679cbb build(deps): bump crazy-max/.github/.github/workflows/zizmor.yml
  • Additional commits viewable in compare view

Updates github.com/gpustack/gguf-parser-go from 0.24.0 to 0.26.3

Commits
  • e11f991 ci: configure project review rules for open-code-review
  • 96a7a9c ci: introduce AI code review workflow and agent onboarding docs (#55)
  • 8ce1632 fix: bound the declared array length in ReadArray before allocating
  • d190a3b fix: Bound the declared string length in ReadString before allocating
  • 4edc567 refactor: Stop two parse panics, refuse a typeless projector, and correct thr...
  • c007ab1 refactor: Count the output layer within n_gpu_layers, as llama.cpp does (#43)
  • 4949ca7 feat: Parse the NVFP4, Q1_0 and Q2_0 files that llama.cpp already loads (#39)
  • a5d9227 fix: resolve the sliding window layout per layer, mirror llama.cpp's per-arch...
  • 9cbe8c1 fix: read the per-layer attention.head_count_kv, charge KV and recurrent stat...
  • 38e2670 test: correct the case of the gemma-4 mmproj fixture
  • Additional commits viewable in compare view

Updates github.com/jaypipes/ghw from 0.24.0 to 0.25.0

Release notes

Sourced from github.com/jaypipes/ghw's releases.

v0.25.0

What's Changed

New Contributors

Full Changelog: jaypipes/ghw@v0.24.0...v0.25.0

Commits
  • 5c7a65f Merge pull request #469 from jaypipes/remove-go-report-card
  • 1c38efe remove retired Go Report card badge
  • cfcf423 Merge pull request #468 from europaul/add-watchdog
  • c15584a Introduce pkg/watchdog to detect hardware watchdogs
  • 6d7ddfe Merge pull request #467 from europaul/cpu-no-colon-test
  • 88fc5d1 cpu_linux: test to ignore non-cpu info on /proc/cpuinfo
  • b959acc Merge pull request #465 from dims/pci-device-tree-walk
  • f65c762 Merge branch 'main' into pci-device-tree-walk
  • d069362 Merge pull request #466 from jimmykarily/fix-context-from-args-env
  • 4476297 use ContextFromEnv() as the base context when args are passed
  • Additional commits viewable in compare view

Updates github.com/mattn/go-runewidth from 0.0.23 to 0.0.30

Commits
  • 14205cc Merge pull request #110 from mattn/truncate-rune-fast-path
  • 67f0b8d Take the rune fast path in the Truncate functions too
  • a42811d Merge pull request #111 from mattn/wrap-invalid-utf8
  • 1156ade Keep strings that are not valid UTF-8 on the segmenter
  • 06120a9 Merge pull request #109 from mattn/skip-segmentation-without-joiners
  • 21388ad Skip grapheme segmentation for text that cannot form clusters
  • 6c7068f Generate a table of runes that can join a grapheme cluster
  • 2793dc5 Merge pull request #108 from youdie006/fix-wrap-grapheme-cluster
  • fd7c07f Add Wrap benchmarks for the ASCII, CJK and emoji paths
  • f5f115c Inline the ASCII width rule in the Wrap fast path
  • Additional commits viewable in compare view

Updates github.com/mattn/go-shellwords from 1.0.13 to 1.0.15

Release notes

Sourced from github.com/mattn/go-shellwords's releases.

v1.0.15

What's Changed

New Contributors

Full Changelog: mattn/go-shellwords@v1.0.14...v1.0.15

Commits
  • f40666a Merge pull request #77 from vitalivo/fix/comments-after-empty-quotes
  • f7c60ee Keep hash characters following empty quotes as word content
  • 2b31b13 Merge pull request #72 from mattn/add-gitignore
  • 925f016 Add .gitignore for .codex
  • ad15017 Merge pull request #71 from mattn/refactor-buffers
  • a3c716b Use byte buffers in Parse to reduce allocations
  • a9af5c2 Merge pull request #70 from mattn/add-benchmarks
  • 6eb4f8d Add benchmarks for Parse variants
  • a51cda8 Merge pull request #69 from mattn/followups
  • 2488652 Fix comment handling inside backticks and drop empty substitution words
  • Additional commits viewable in compare view

Updates github.com/moby/moby/api from 1.54.2 to 1.56.0

Release notes

Sourced from github.com/moby/moby/api's releases.

api/v1.56.0

1.56.0

Changelog

  • GET /containers/json now supports an annotation filter to filter containers by annotation, either by key (annotation=key) or by key and value (annotation="key=value"), similar to the existing label filter. moby/moby#53538
  • POST /containers/create now supports HostConfig.Umask to set the initial umask for a Unix container. When set, the daemon includes the value in the OCI process configuration for the container's entrypoint, exec processes, and healthchecks. When omitted, the runtime's default behavior applies.moby/moby#53463
  • api/docs: sync API docs v1.25 - v1.55. moby/moby#53246
  • api/swagger: Align Healthcheck name with Go struct. moby/moby#53567
  • api/types/plugin: Deprecated plugin.Privileges sorting methods in favor of slices.SortFunc. moby/moby#53511
  • api/types/plugin: fix Privileges Swap implementation. moby/moby#53510
  • api: Bump to 1.56. moby/moby#53425
  • api: document Task.NetworksAttachments in the swagger definition. moby/moby#53082
  • api: remove gotest.tools from tests. moby/moby#53535
  • api: swagger: Use int64 for build query params. moby/moby#53520
  • api: use blackbox testing. moby/moby#53525
  • Fix API reference documenting an unsupported names filter for GET /configs. moby/moby#53447

api/v1.55.0

1.55.0

Changelog

  • POST /containers/{id}/update now supports per-device blkio resource settingss. moby/moby#52651
  • The new GET /images/{name}/attestations endpoint returns in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image, with optional platform selection, predicate type filtering, and an opt-in statement query parameter for retrieving the verbatim statement bodies. Tools can now retrieve attestation metadata and content directly from the daemon instead of performing additional registry round-trips. moby/moby#52636
  • docs: clarify swarm join required fields. moby/moby#52763

api/v1.55.0-rc.1

1.55.0-rc.1

Changelog

  • POST /containers/{id}/update now supports per-device blkio resource settingss. moby/moby#52651
  • The new GET /images/{name}/attestations endpoint returns in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image, with optional platform selection, predicate type filtering, and an opt-in statement query parameter for retrieving the verbatim statement bodies. Tools can now retrieve attestation metadata and content directly from the daemon instead of performing additional registry round-trips. moby/moby#52636
  • docs: clarify swarm join required fields. moby/moby#52763
Commits
  • 9b2179d Merge pull request #53572 from vvoland/api-docs-cut
  • 575cf82 Merge pull request #53571 from thaJeztah/bump_tools
  • 20beedb api/docs: Cut v1.56
  • bb86302 Merge pull request #53569 from vvoland/afvsock-lsm
  • 65be55a Merge pull request #53513 from thaJeztah/daemon_fix_list
  • 0af79c4 Merge pull request #53570 from vvoland/process-release
  • 7d1ce6a Merge pull request #53568 from renovate-bot/renovate/github.com-mdlayher-sock...
  • 0df1a00 Dockerfile: update cli v29.7.2, compose v5.5.1, buildx v0.37.0
  • e1d06bd Drop replace rules
  • b40d37e Merge pull request #53359 from vvoland/ext-namegenerator
  • Additional commits viewable in compare view

Updates github.com/moby/moby/client from 0.4.1 to 0.6.0

Release notes

Sourced from github.com/moby/moby/client's releases.

client/v0.6.0

0.6.0

Changelog

client/v0.5.1

0.5.1

Changelog

  • client/pkg/jsonmessage: Display: fix godoc link. moby/moby#53070
  • client: ServiceCreate, ServiceUpdate: fix duplicate and 'unkown' platforms. moby/moby#53012
  • client: ServiceInspect, ContainerCommit: omit optional query args if not set. moby/moby#53010
  • golangci-lint: enable perfsprint linter. moby/moby#53016

client/0.5.0

0.5.0

Changelog

  • The new GET /images/{name}/attestations endpoint returns in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image, with optional platform selection, predicate type filtering, and an opt-in statement query parameter for retrieving the verbatim statement bodies. Tools can now retrieve attestation metadata and content directly from the daemon instead of performing additional registry round-trips. moby/moby#52636

client/v0.5.0-rc.1

0.5.0-rc.1

Changelog

  • The new GET /images/{name}/attestations endpoint returns in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image, with optional platform selection, predicate type filtering, and an opt-in statement query parameter for retrieving the verbatim statement bodies. Tools can now retrieve attestation metadata and content directly from the daemon instead of performing additional registry round-trips. moby/moby#52636
Changelog

Sourced from github.com/moby/moby/client's changelog.

0.6.0 (2013-08-22)

  • Runtime: Load authConfig only when needed and fix useless WARNING
  • Runtime: Add lxc-conf flag to allow custom lxc options
  • Runtime: Fix race conditions in parallel pull
  • Runtime: Improve CMD, ENTRYPOINT, and attach docs.
  • Documentation: Small fix to docs regarding adding docker groups
  • Documentation: Add MongoDB image example
  • Builder: Add USER instruction do Dockerfile
  • Documentation: updated default -H docs
  • Remote API: Sort Images by most recent creation date.
  • Builder: Add workdir support for the Buildfile
  • Runtime: Add an option to set the working directory
  • Runtime: Show tag used when image is missing
  • Documentation: Update readme with dependencies for building
  • Documentation: Add instructions for creating and using the docker group
  • Remote API: Reworking opaque requests in registry module
  • Runtime: Fix Graph ByParent() to generate list of child images per parent image.
  • Runtime: Add Image name to LogEvent tests
  • Documentation: Add sudo to examples and installation to documentation
  • Hack: Bash Completion: Limit commands to containers of a relevant state
  • Remote API: Add image name in /events
  • Runtime: Apply volumes-from before creating volumes
  • Runtime: Make docker run handle SIGINT/SIGTERM
  • Runtime: Prevent crash when .dockercfg not readable
  • Hack: Add docker dependencies coverage testing into docker-ci
  • Runtime: Add -privileged flag and relevant tests, docs, and examples
  • Packaging: Docker-brew 0.5.2 support and memory footprint reduction
  • Runtime: Install script should be fetched over https, not http.
  • Packaging: Add new docker dependencies into docker-ci
  • Runtime: Use Go 1.1.2 for dockerbuilder
  • Registry: Improve auth push
  • Runtime: API, issue 1471: Use groups for socket permissions
  • Documentation: PostgreSQL service example in documentation
  • Contrib: bash completion script
  • Tests: Improve TestKillDifferentUser to prevent timeout on buildbot
  • Documentation: Fix typo in docs for docker run -dns
  • Documentation: Adding a reference to ps -a
  • Runtime: Correctly detect IPv4 forwarding
  • Packaging: Revert "docker.upstart: avoid spawning a sh process"
  • Runtime: Use ranged for loop on channels
  • Runtime: Fix typo: fmt.Sprint -> fmt.Sprintf
  • Tests: Fix typo in TestBindMounts (runContainer called without image)
  • Runtime: add websocket support to /container//attach/ws
  • Runtime: Mount /dev/shm as a tmpfs
  • Builder: Only count known instructions as build steps
  • Builder: Fix docker build and docker events output
  • Runtime: switch from http to https for get.docker.io
  • Tests: Improve TestGetContainersTop so it does not rely on sleep
  • Packaging: Docker-brew and Docker standard library
  • Testing: Add some tests in server and utils

... (truncated)

Commits
  • f4a4f1c Bump to 0.6.0
  • f925edd Merge pull request #1525 from griff/1503-fix
  • 12715c8 Merge pull request #1609 from jpetazzo/release-docker-with-docker
  • 326dadd Merge pull request #1565 from dotcloud/only_load_authconfig_when_needed
  • a3510c9 Merge pull request #1560 from dotcloud/439-allow-lxc-args
  • 262d57e Merge pull request #1623 from mhennings/1592-fix-race-conditions-in-parallel-...
  • 551092f Add lxc-conf flag to allow custom lxc options
  • 3f802f4 Fix race conditions in parallel pull
  • 0b9c8e2 Merge pull request #1596 from metalivedev/1149-easyfixes
  • 42fe550 Merge pull request #1614 from denibertovic/docs
  • Additional commits viewable in compare view

Updates github.com/olekukonko/tablewriter from 1.1.4 to 1.1.5

Commits
  • 5f0c87a change readme to v1.1.5
  • 8535cd2 Merge pull request #331 from olekukonko/makawhy
  • 8db545f markdown game
  • 569d938 Merge pull request #330 from olekukonko/makawhy
  • ce371fa Merge pull request #326 from olekukonko/makawhy
  • e1d22bb Merge pull request #329 from team-humaki/fix/global-width-wrap-split
  • c9a710f Merge pull request #327 from youdie006/wrapwords-last-word-hang
  • cbd4eb4 wrap: split Widths.Global across columns
  • 2a7896c Broaden the WrapWords table to the shapes around the last-word case
  • cb595f4 Terminate WrapWords when the last word is wider than the limit
  • Additional commits viewable in compare view

Updates github.com/prometheus/client_model from 0.6.2 to 0.6.3

Release notes

Sourced from github.com/prometheus/client_model's releases.

v0.6.3

What's Changed

New Contributors

Full Changelog: prometheus/client_model@v0.6.2...v0.6.3

What's Changed

... (truncated)

Commits

Updates github.com/prometheus/common from 0.67.5 to 0.70.1

Release notes

Sourced from github.com/prometheus/common's releases.

v0.70.1

What's Changed

  • Update CHANGELOG for v0.70.0 ...

    Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 26, 2026
@ericcurtin
ericcurtin requested a lite review from Copilot September 26, 2026 19:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Align the shared Go version and Docker build configuration with the new module requirement.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Updates 20 Go dependencies and refreshes the module checksum set.

Changes:

  • Bumps direct and transitive dependencies.
  • Raises the Go requirement to 1.26.6.
  • Refreshes go.sum checksums.

Critical blocker: Go 1.26.6 is not aligned with the repository’s Go 1.25 selection, causing non-reproducible builds without toolchain downloads.

File Description
go.mod Updates dependency versions and Go requirement.
go.sum Refreshes dependency checksums.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread go.mod
module github.com/docker/model-runner

go 1.25.8
go 1.26.6
@ericcurtin

Copy link
Copy Markdown
Contributor

Build is broken: go.mod bumps go 1.25.8 -> go 1.26.6, but CI runners have go 1.25.14 with GOTOOLCHAIN=local, so lint/test/e2e all fail immediately ("go.mod requires go >= 1.26.6"). Please pin the go directive back to a version CI supports, or bump the CI toolchain first. Also, model-runner is being deprecated in favor of https://github.com/llmmanorg/llmman, please open future PRs there instead. Setting to draft until green.

@ericcurtin
ericcurtin marked this pull request as draft September 26, 2026 20:24
…0 updates

Bumps the go-modules-root group with 20 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/containerd/containerd/v2](https://github.com/containerd/containerd) | `2.2.5` | `2.4.0` |
| [github.com/containerd/platforms](https://github.com/containerd/platforms) | `1.0.0-rc.4` | `1.0.0-rc.5` |
| [github.com/docker/cli](https://github.com/docker/cli) | `29.4.1+incompatible` | `29.8.1+incompatible` |
| [github.com/docker/docker-credential-helpers](https://github.com/docker/docker-credential-helpers) | `0.9.6` | `0.9.9` |
| [github.com/gpustack/gguf-parser-go](https://github.com/gpustack/gguf-parser-go) | `0.24.0` | `0.26.3` |
| [github.com/jaypipes/ghw](https://github.com/jaypipes/ghw) | `0.24.0` | `0.25.0` |
| [github.com/mattn/go-runewidth](https://github.com/mattn/go-runewidth) | `0.0.23` | `0.0.30` |
| [github.com/mattn/go-shellwords](https://github.com/mattn/go-shellwords) | `1.0.13` | `1.0.15` |
| [github.com/moby/moby/api](https://github.com/moby/moby) | `1.54.2` | `1.56.0` |
| [github.com/moby/moby/client](https://github.com/moby/moby) | `0.4.1` | `0.6.0` |
| [github.com/olekukonko/tablewriter](https://github.com/olekukonko/tablewriter) | `1.1.4` | `1.1.5` |
| [github.com/prometheus/client_model](https://github.com/prometheus/client_model) | `0.6.2` | `0.6.3` |
| [github.com/prometheus/common](https://github.com/prometheus/common) | `0.67.5` | `0.70.1` |
| [github.com/stretchr/testify](https://github.com/stretchr/testify) | `1.11.1` | `1.12.1` |
| [github.com/testcontainers/testcontainers-go](https://github.com/testcontainers/testcontainers-go) | `0.42.0` | `0.44.0` |
| [github.com/testcontainers/testcontainers-go/modules/registry](https://github.com/testcontainers/testcontainers-go) | `0.42.0` | `0.44.0` |
| [go.opentelemetry.io/otel](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.46.0` |
| [golang.org/x/sync](https://github.com/golang/sync) | `0.22.0` | `0.23.0` |
| [golang.org/x/sys](https://github.com/golang/sys) | `0.47.0` | `0.48.0` |
| [golang.org/x/term](https://github.com/golang/term) | `0.45.0` | `0.46.0` |



Updates `github.com/containerd/containerd/v2` from 2.2.5 to 2.4.0
- [Release notes](https://github.com/containerd/containerd/releases)
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)
- [Commits](containerd/containerd@v2.2.5...v2.4.0)

Updates `github.com/containerd/platforms` from 1.0.0-rc.4 to 1.0.0-rc.5
- [Release notes](https://github.com/containerd/platforms/releases)
- [Commits](containerd/platforms@v1.0.0-rc.4...v1.0.0-rc.5)

Updates `github.com/docker/cli` from 29.4.1+incompatible to 29.8.1+incompatible
- [Commits](docker/cli@v29.4.1...v29.8.1)

Updates `github.com/docker/docker-credential-helpers` from 0.9.6 to 0.9.9
- [Release notes](https://github.com/docker/docker-credential-helpers/releases)
- [Commits](docker/docker-credential-helpers@v0.9.6...v0.9.9)

Updates `github.com/gpustack/gguf-parser-go` from 0.24.0 to 0.26.3
- [Release notes](https://github.com/gpustack/gguf-parser-go/releases)
- [Commits](gpustack/gguf-parser-go@v0.24.0...v0.26.3)

Updates `github.com/jaypipes/ghw` from 0.24.0 to 0.25.0
- [Release notes](https://github.com/jaypipes/ghw/releases)
- [Commits](jaypipes/ghw@v0.24.0...v0.25.0)

Updates `github.com/mattn/go-runewidth` from 0.0.23 to 0.0.30
- [Commits](mattn/go-runewidth@v0.0.23...v0.0.30)

Updates `github.com/mattn/go-shellwords` from 1.0.13 to 1.0.15
- [Release notes](https://github.com/mattn/go-shellwords/releases)
- [Commits](mattn/go-shellwords@v1.0.13...v1.0.15)

Updates `github.com/moby/moby/api` from 1.54.2 to 1.56.0
- [Release notes](https://github.com/moby/moby/releases)
- [Commits](moby/moby@api/v1.54.2...api/v1.56.0)

Updates `github.com/moby/moby/client` from 0.4.1 to 0.6.0
- [Release notes](https://github.com/moby/moby/releases)
- [Changelog](https://github.com/moby/moby/blob/v0.6.0/CHANGELOG.md)
- [Commits](moby/moby@v0.4.1...v0.6.0)

Updates `github.com/olekukonko/tablewriter` from 1.1.4 to 1.1.5
- [Release notes](https://github.com/olekukonko/tablewriter/releases)
- [Commits](olekukonko/tablewriter@v1.1.4...v1.1.5)

Updates `github.com/prometheus/client_model` from 0.6.2 to 0.6.3
- [Release notes](https://github.com/prometheus/client_model/releases)
- [Commits](prometheus/client_model@v0.6.2...v0.6.3)

Updates `github.com/prometheus/common` from 0.67.5 to 0.70.1
- [Release notes](https://github.com/prometheus/common/releases)
- [Changelog](https://github.com/prometheus/common/blob/main/CHANGELOG.md)
- [Commits](prometheus/common@v0.67.5...v0.70.1)

Updates `github.com/stretchr/testify` from 1.11.1 to 1.12.1
- [Release notes](https://github.com/stretchr/testify/releases)
- [Commits](stretchr/testify@v1.11.1...v1.12.1)

Updates `github.com/testcontainers/testcontainers-go` from 0.42.0 to 0.44.0
- [Release notes](https://github.com/testcontainers/testcontainers-go/releases)
- [Commits](testcontainers/testcontainers-go@v0.42.0...v0.44.0)

Updates `github.com/testcontainers/testcontainers-go/modules/registry` from 0.42.0 to 0.44.0
- [Release notes](https://github.com/testcontainers/testcontainers-go/releases)
- [Commits](testcontainers/testcontainers-go@v0.42.0...v0.44.0)

Updates `go.opentelemetry.io/otel` from 1.44.0 to 1.46.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.44.0...v1.46.0)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](golang/sync@v0.22.0...v0.23.0)

Updates `golang.org/x/sys` from 0.47.0 to 0.48.0
- [Commits](golang/sys@v0.47.0...v0.48.0)

Updates `golang.org/x/term` from 0.45.0 to 0.46.0
- [Commits](golang/term@v0.45.0...v0.46.0)

---
updated-dependencies:
- dependency-name: github.com/containerd/containerd/v2
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules-root
- dependency-name: github.com/containerd/platforms
  dependency-version: 1.0.0-rc.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-modules-root
- dependency-name: github.com/docker/cli
  dependency-version: 29.8.1+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules-root
- dependency-name: github.com/docker/docker-credential-helpers
  dependency-version: 0.9.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-modules-root
- dependency-name: github.com/gpustack/gguf-parser-go
  dependency-version: 0.26.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules-root
- dependency-name: github.com/jaypipes/ghw
  dependency-version: 0.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules-root
- dependency-name: github.com/mattn/go-runewidth
  dependency-version: 0.0.30
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-modules-root
- dependency-name: github.com/mattn/go-shellwords
  dependency-version: 1.0.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-modules-root
- dependency-name: github.com/moby/moby/api
  dependency-version: 1.56.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules-root
- dependency-name: github.com/moby/moby/client
  dependency-version: 0.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules-root
- dependency-name: github.com/olekukonko/tablewriter
  dependency-version: 1.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-modules-root
- dependency-name: github.com/prometheus/client_model
  dependency-version: 0.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-modules-root
- dependency-name: github.com/prometheus/common
  dependency-version: 0.70.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules-root
- dependency-name: github.com/stretchr/testify
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules-root
- dependency-name: github.com/testcontainers/testcontainers-go
  dependency-version: 0.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules-root
- dependency-name: github.com/testcontainers/testcontainers-go/modules/registry
  dependency-version: 0.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules-root
- dependency-name: go.opentelemetry.io/otel
  dependency-version: 1.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules-root
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules-root
- dependency-name: golang.org/x/sys
  dependency-version: 0.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules-root
- dependency-name: golang.org/x/term
  dependency-version: 0.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules-root
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/go-modules-root-7119ff70f7 branch from b4c749d to 8dd5d79 Compare September 26, 2026 20:27

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants