chore(deps): dependabot - #3131
Conversation
Bumps [github.com/in-toto/in-toto-golang](https://github.com/in-toto/in-toto-golang) from 0.10.0 to 0.11.0. - [Release notes](https://github.com/in-toto/in-toto-golang/releases) - [Changelog](https://github.com/in-toto/in-toto-golang/blob/master/CHANGELOG.md) - [Commits](in-toto/in-toto-golang@v0.10.0...v0.11.0) --- updated-dependencies: - dependency-name: github.com/in-toto/in-toto-golang dependency-version: 0.11.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [anyhow](https://github.com/dtolnay/anyhow) from 1.0.102 to 1.0.103. - [Release notes](https://github.com/dtolnay/anyhow/releases) - [Commits](dtolnay/anyhow@1.0.102...1.0.103) --- updated-dependencies: - dependency-name: anyhow dependency-version: 1.0.103 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [insta](https://github.com/mitsuhiko/insta) from 1.47.2 to 1.48.0. - [Release notes](https://github.com/mitsuhiko/insta/releases) - [Changelog](https://github.com/mitsuhiko/insta/blob/master/CHANGELOG.md) - [Commits](mitsuhiko/insta@1.47.2...1.48.0) --- updated-dependencies: - dependency-name: insta dependency-version: 1.48.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [torch](https://github.com/pytorch/pytorch) from 2.12.0 to 2.13.0. - [Release notes](https://github.com/pytorch/pytorch/releases) - [Changelog](https://github.com/pytorch/pytorch/blob/main/RELEASE.md) - [Commits](pytorch/pytorch@v2.12.0...v2.13.0) --- updated-dependencies: - dependency-name: torch dependency-version: 2.13.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [torch](https://github.com/pytorch/pytorch) from 2.8.0 to 2.13.0. - [Release notes](https://github.com/pytorch/pytorch/releases) - [Changelog](https://github.com/pytorch/pytorch/blob/main/RELEASE.md) - [Commits](pytorch/pytorch@v2.8.0...v2.13.0) --- updated-dependencies: - dependency-name: torch dependency-version: 2.13.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [rustls](https://github.com/rustls/rustls) from 0.23.37 to 0.23.42. - [Release notes](https://github.com/rustls/rustls/releases) - [Changelog](https://github.com/rustls/rustls/blob/main/CHANGELOG.md) - [Commits](rustls/rustls@v/0.23.37...v/0.23.42) --- updated-dependencies: - dependency-name: rustls dependency-version: 0.23.42 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [pillow](https://github.com/python-pillow/Pillow) from 12.1.1 to 12.3.0. - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](python-pillow/Pillow@12.1.1...12.3.0) --- updated-dependencies: - dependency-name: pillow dependency-version: 12.3.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [pillow](https://github.com/python-pillow/Pillow) from 12.2.0 to 12.3.0. - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](python-pillow/Pillow@12.2.0...12.3.0) --- updated-dependencies: - dependency-name: pillow dependency-version: 12.3.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.80.0 to 1.82.1. - [Release notes](https://github.com/grpc/grpc-go/releases) - [Commits](grpc/grpc-go@v1.80.0...v1.82.1) --- updated-dependencies: - dependency-name: google.golang.org/grpc dependency-version: 1.82.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7. - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@v6...v7) --- updated-dependencies: - dependency-name: actions/setup-python dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/getkin/kin-openapi](https://github.com/getkin/kin-openapi) from 0.140.0 to 0.144.0. - [Release notes](https://github.com/getkin/kin-openapi/releases) - [Commits](getkin/kin-openapi@v0.140.0...v0.144.0) --- updated-dependencies: - dependency-name: github.com/getkin/kin-openapi dependency-version: 0.144.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [jdx/mise-action](https://github.com/jdx/mise-action) from 4 to 4.2.3. - [Release notes](https://github.com/jdx/mise-action/releases) - [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md) - [Commits](jdx/mise-action@v4...v4.2.3) --- updated-dependencies: - dependency-name: jdx/mise-action dependency-version: 4.2.3 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4 to 4.37.3. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v4...v4.37.3) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.37.3 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…/in-toto/in-toto-golang-0.11.0' into deps
…/codeql-action-4.37.3' into deps
…se-action-4.2.3' into deps
…/getkin/kin-openapi-0.144.0' into deps
…s/setup-python-7' into deps
…ang.org/grpc-1.82.1' into deps
…illow-12.3.0' into deps
…low-12.3.0' into deps
….23.42' into deps
…turbo/torch-2.13.0' into deps
…g-text/torch-2.13.0' into deps
….0.103' into deps
There was a problem hiding this comment.
Pull request overview
This PR applies Dependabot-driven dependency updates across Cog’s Go modules, Rust workspace lockfile, Python example requirements, and GitHub Actions workflows to keep the project’s toolchain and libraries current.
Changes:
- Bump Go dependencies (notably
kin-openapi,grpc,genproto, and related indirect deps). - Refresh Rust dependency lockfile entries (e.g.,
anyhow,insta,rustls, transitive Windows-related crates). - Update example Python requirements and pin several GitHub Actions to specific patch versions.
Reviewed changes
Copilot reviewed 13 out of 15 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| go.mod | Updates selected Go module versions (e.g., kin-openapi, grpc, in-toto, oasdiff/yaml*, genproto). |
| go.sum | Updates Go module checksums to match the go.mod bumps. |
| crates/Cargo.lock | Refreshes Rust dependency lockfile after dependency resolution changes. |
| examples/z-image-turbo/requirements.txt | Updates pinned Python dependencies for the example (includes a torch version bump). |
| examples/streaming-text/requirements.txt | Updates pinned Python dependencies for the example (includes a torch version bump). |
| examples/resnet/requirements.txt | Updates pinned Pillow version for the example. |
| examples/blur/requirements.txt | Updates pinned Pillow version for the example. |
| .github/workflows/update-compatibility-matrices.yaml | Pins jdx/mise-action to v4.2.3. |
| .github/workflows/rust-advisories.yaml | Pins jdx/mise-action to v4.2.3. |
| .github/workflows/release-publish.yaml | Pins jdx/mise-action to v4.2.3. |
| .github/workflows/release-build.yaml | Pins jdx/mise-action to v4.2.3 in both relevant jobs. |
| .github/workflows/mirror-cog-base-images.yaml | Pins jdx/mise-action to v4.2.3. |
| .github/workflows/docs.yaml | Pins jdx/mise-action to v4.2.3. |
| .github/workflows/codeql.yml | Pins github/codeql-action/* steps to v4.37.3. |
| .github/workflows/ci.yaml | Pins jdx/mise-action to v4.2.3 and updates actions/setup-python major version. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
@anish-sahoo Bonk workflow was cancelled. View workflow run · To retry, trigger Bonk again. |
| with: | ||
| fetch-depth: 0 | ||
| - uses: jdx/mise-action@v4 | ||
| - uses: jdx/mise-action@v4.2.3 |
There was a problem hiding this comment.
why do we have to pin the minor/patch version? shouldnt pinning the major always use the latest minor/patch?
There was a problem hiding this comment.
good point - I've updated all of them to stay pinned to the major version + updated the dependabot config for github actions to only track major version changes
Revert the jdx/mise-action and github/codeql-action pins from specific minor/patch versions back to floating major tags (@v4), matching the rest of the workflows. Keep the actions/setup-python major bump (v6 -> v7). Add a github-actions ignore rule for semver-minor/patch so Dependabot only opens PRs for major-version bumps, which the floating major tags don't already track.
adds dependabot fixes from the last month