* chore(deps): bump the go-all group across 1 directory with 4 updates Bumps the go-all group with 4 updates in the / directory: [github.com/stretchr/testify](https://github.com/stretchr/testify), [golang.org/x/net](https://github.com/golang/net), [golang.org/x/sys](https://github.com/golang/sys) and [golang.org/x/term](https://github.com/golang/term). Updates `github.com/stretchr/testify` from 1.11.1 to 1.12.1 - [Release notes](https://github.com/stretchr/testify/releases) - [Commits](https://github.com/stretchr/testify/compare/v1.11.1...v1.12.1) Updates `golang.org/x/net` from 0.57.0 to 0.59.0 - [Commits](https://github.com/golang/net/compare/v0.57.0...v0.59.0) Updates `golang.org/x/sys` from 0.47.0 to 0.48.0 - [Commits](https://github.com/golang/sys/compare/v0.47.0...v0.48.0) Updates `golang.org/x/term` from 0.45.0 to 0.46.0 - [Commits](https://github.com/golang/term/compare/v0.45.0...v0.46.0) --- updated-dependencies: - dependency-name: github.com/stretchr/testify dependency-version: 1.12.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-all - dependency-name: golang.org/x/net dependency-version: 0.59.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-all - dependency-name: golang.org/x/sys dependency-version: 0.48.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-all - dependency-name: golang.org/x/term dependency-version: 0.46.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-all ... Signed-off-by: dependabot[bot] <support@github.com> * fix(deps): keep go directive unpinned so CI uses latest patch Dependabot's go mod tidy on a newer toolchain rewrote the directive to go 1.26.0, which makes actions/setup-go (go-version-file: go.mod) install exactly 1.26.0 instead of the latest 1.26.x patch. govulncheck then fails on 18 standard-library CVEs already fixed in 1.26.6. Restore the go 1.26 + toolchain form used on next. * fix(ci): install latest Go 1.26 patch instead of pinning 1.26.0 The x/net, x/sys and x/term bumps declare go 1.26.0, so go mod tidy now requires the module's go directive to be go 1.26.0 rather than go 1.26. setup-go's go-version-file reads that directive verbatim and installs exactly 1.26.0, which govulncheck flags for 18 standard-library CVEs already fixed in later 1.26 patches. Resolve the Go version from the 1.26 minor line so the latest patch is installed. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jo <me@jguer.space>
37 lines
1.2 KiB
AMPL
37 lines
1.2 KiB
AMPL
module github.com/Jguer/yay/v13
|
|
|
|
require (
|
|
github.com/Jguer/aur v1.3.1
|
|
github.com/Jguer/dyalpm v0.1.4
|
|
github.com/Jguer/votar v1.0.0
|
|
github.com/Morganamilo/go-pacmanconf v0.0.0-20210502114700-cff030e927a5
|
|
github.com/Morganamilo/go-srcinfo v1.0.0
|
|
github.com/adrg/strutil v0.3.1
|
|
github.com/bradleyjkemp/cupaloy v2.3.0+incompatible
|
|
github.com/deckarep/golang-set/v2 v2.9.0
|
|
github.com/hashicorp/go-multierror v1.1.1
|
|
github.com/leonelquinteros/gotext v1.7.2
|
|
github.com/stretchr/testify v1.12.1
|
|
github.com/yuin/gopher-lua v1.1.2
|
|
golang.org/x/net v0.59.0
|
|
golang.org/x/sys v0.48.0
|
|
golang.org/x/term v0.46.0
|
|
gopkg.in/h2non/gock.v1 v1.1.2
|
|
)
|
|
|
|
require (
|
|
github.com/davecgh/go-spew v1.1.1 // indirect
|
|
github.com/ebitengine/purego v0.10.1 // indirect
|
|
github.com/go-viper/mapstructure/v2 v2.5.0 // indirect
|
|
github.com/h2non/parth v0.0.0-20190131123155-b4df798d6542 // indirect
|
|
github.com/hashicorp/errwrap v1.1.0 // indirect
|
|
github.com/itchyny/gojq v0.12.19 // indirect
|
|
github.com/itchyny/timefmt-go v0.1.8 // indirect
|
|
github.com/ohler55/ojg v1.28.1 // indirect
|
|
github.com/pmezard/go-difflib v1.0.0 // indirect
|
|
go.mongodb.org/mongo-driver v1.17.9 // indirect
|
|
go.yaml.in/yaml/v3 v3.0.5 // indirect
|
|
)
|
|
|
|
go 1.26.0
|