From 426789115ce9f660a62295b0c0eeb1eaba67b143 Mon Sep 17 00:00:00 2001
From: "mergify[bot]" <37929162+mergify[bot]@users.noreply.github.com>
Date: Mon, 27 Jul 2026 09:58:39 +0200
Subject: [PATCH 01/70] [9.5](backport #7473) [Cloud Asset Inventory] Fix
entity.attribute mapping bug by renaming it to entity.Details (#7474)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
### Summary of your changes
For: #incident-3395-failing-quality-gate-for-entity-store-synthetics
Incident Slack: https://elastic.slack.com/archives/C0BJQCSBT47
Publishing asset details as `entity.attributes` breaks Entity Store
extraction. This, along with related integrations PR, fixes the issue by
using `entity.Details` instead. Integrations PR contains an ingest
pipeline that ensures even old Cloudbeat versions that publish
`entity.attributes` get remapped to `Details`. This allows extraction to
work as intended.
### Related Issues
Towards https://github.com/elastic/security-team/issues/18408
This is an automatic backport of pull request #7473 done by
[Mergify](https://mergify.com).
Co-authored-by: Kuba Soboń
---
internal/inventory/asset.go | 26 ++++++++---------
.../awsfetcher/fetcher_ec2_instance.go | 28 +++++++++----------
.../awsfetcher/fetcher_ec2_instance_test.go | 4 +--
internal/inventory/awsfetcher/fetcher_eks.go | 22 +++++++--------
.../inventory/awsfetcher/fetcher_eks_test.go | 4 +--
internal/inventory/awsfetcher/fetcher_elb.go | 16 +++++------
.../inventory/awsfetcher/fetcher_elb_test.go | 4 +--
internal/inventory/awsfetcher/fetcher_rds.go | 8 +++---
.../inventory/awsfetcher/fetcher_rds_test.go | 4 +--
.../inventory/awsfetcher/fetcher_route53.go | 28 +++++++++----------
.../awsfetcher/fetcher_route53_test.go | 4 +--
11 files changed, 74 insertions(+), 74 deletions(-)
diff --git a/internal/inventory/asset.go b/internal/inventory/asset.go
index 859dec963d..0fe6ba8d05 100644
--- a/internal/inventory/asset.go
+++ b/internal/inventory/asset.go
@@ -182,11 +182,11 @@ type URL struct {
// Entity contains the identifiers of the asset
type Entity struct {
- Id string `json:"id"`
- Name string `json:"name"`
- Source *string `json:"source"`
- Raw *any `json:"raw"`
- Attributes map[string]any `json:"attributes,omitempty"`
+ Id string `json:"id"`
+ Name string `json:"name"`
+ Source *string `json:"source"`
+ Raw *any `json:"raw"`
+ Details map[string]any `json:"Details,omitempty"`
AssetClassification
// non exported fields
@@ -451,28 +451,28 @@ func WithContainer(container Container) AssetEnricher {
}
}
-// WithEntityAttributes sets non-ECS resource-specific attributes on the entity.
+// WithEntityDetails sets non-ECS resource-specific attributes on the entity (entity.Details).
// Keys should use UpperCamelCase per the non-ECS field naming convention.
// A nil or empty map is a no-op.
-func WithEntityAttributes(attrs map[string]any) AssetEnricher {
+func WithEntityDetails(details map[string]any) AssetEnricher {
return func(a *AssetEvent) {
- if len(attrs) == 0 {
+ if len(details) == 0 {
return
}
- a.Entity.Attributes = attrs
+ a.Entity.Details = details
}
}
-// WithCreatedAt sets the resource creation timestamp in entity.attributes["CreatedAt"].
+// WithCreatedAt sets the resource creation timestamp in entity.Details["CreatedAt"].
// A nil time is a no-op.
func WithCreatedAt(t *time.Time) AssetEnricher {
return func(a *AssetEvent) {
if t == nil {
return
}
- if a.Entity.Attributes == nil {
- a.Entity.Attributes = make(map[string]any)
+ if a.Entity.Details == nil {
+ a.Entity.Details = make(map[string]any)
}
- a.Entity.Attributes["CreatedAt"] = t
+ a.Entity.Details["CreatedAt"] = t
}
}
diff --git a/internal/inventory/awsfetcher/fetcher_ec2_instance.go b/internal/inventory/awsfetcher/fetcher_ec2_instance.go
index a81dfd537a..6d59401cf9 100644
--- a/internal/inventory/awsfetcher/fetcher_ec2_instance.go
+++ b/internal/inventory/awsfetcher/fetcher_ec2_instance.go
@@ -128,7 +128,7 @@ func (e *ec2InstanceFetcher) Fetch(ctx context.Context, assetChannel chan<- inve
IP: buildIPs(i.PublicIpAddress, i.PrivateIpAddress),
MacAddress: i.GetResourceMacAddresses(),
}),
- inventory.WithEntityAttributes(e.buildAttributes(i, tags, roleArnCache)),
+ inventory.WithEntityDetails(e.buildDetails(i, tags, roleArnCache)),
inventory.WithCreatedAt(i.LaunchTime),
iamFetcher,
)
@@ -177,43 +177,43 @@ func profileNameFromArn(arn string) string {
return arn[idx+len(marker):]
}
-// buildAttributes collects non-ECS, resource-specific EC2 fields into entity.attributes,
+// buildDetails collects non-ECS, resource-specific EC2 fields into entity.Details,
// using UpperCamelCase keys. Empty values are omitted so events stay clean and struct
// comparison in tests is stable.
-func (e *ec2InstanceFetcher) buildAttributes(i *ec2.Ec2Instance, tags map[string]string, roleArnCache map[string]string) map[string]any {
- attrs := map[string]any{}
+func (e *ec2InstanceFetcher) buildDetails(i *ec2.Ec2Instance, tags map[string]string, roleArnCache map[string]string) map[string]any {
+ details := map[string]any{}
if v := pointers.Deref(i.ImageId); v != "" {
- attrs["ImageId"] = v
+ details["ImageId"] = v
}
if v := string(i.Platform); v != "" {
- attrs["Platform"] = v
+ details["Platform"] = v
}
if v := pointers.Deref(i.VpcId); v != "" {
- attrs["VpcId"] = v
+ details["VpcId"] = v
}
if v := pointers.Deref(i.SubnetId); v != "" {
- attrs["SubnetId"] = v
+ details["SubnetId"] = v
}
if i.State != nil {
if v := string(i.State.Name); v != "" {
- attrs["State"] = v
+ details["State"] = v
}
}
if i.IamInstanceProfile != nil {
if profileArn := pointers.Deref(i.IamInstanceProfile.Arn); profileArn != "" {
- attrs["InstanceProfileArn"] = profileArn
+ details["InstanceProfileArn"] = profileArn
if roleArn, ok := roleArnCache[profileArn]; ok && roleArn != "" {
- attrs["RoleArn"] = roleArn
+ details["RoleArn"] = roleArn
}
}
}
if v := awslib.LookupTag(tags, "owner"); v != "" {
- attrs["Owner"] = v
+ details["Owner"] = v
}
if v := awslib.LookupTag(tags, "costcenter", "cost-center", "cost_center"); v != "" {
- attrs["CostCenter"] = v
+ details["CostCenter"] = v
}
- return attrs
+ return details
}
// buildIPs collects non-empty IP address strings into a slice, returning nil when none exist.
diff --git a/internal/inventory/awsfetcher/fetcher_ec2_instance_test.go b/internal/inventory/awsfetcher/fetcher_ec2_instance_test.go
index b4d022b025..32d6d2f779 100644
--- a/internal/inventory/awsfetcher/fetcher_ec2_instance_test.go
+++ b/internal/inventory/awsfetcher/fetcher_ec2_instance_test.go
@@ -124,7 +124,7 @@ func TestEC2InstanceFetcher_Fetch(t *testing.T) {
IP: []string{"public-ip-addr", "private-ip-addre"},
MacAddress: []string{"mac1", "mac2"},
}),
- inventory.WithEntityAttributes(map[string]any{
+ inventory.WithEntityDetails(map[string]any{
"ImageId": "image-id",
"Platform": "linux",
"VpcId": "vpc-id",
@@ -213,7 +213,7 @@ func TestEC2InstanceFetcher_Fetch_ResolverError(t *testing.T) {
IP: []string{"public-ip-addr", "private-ip-addre"},
MacAddress: []string{"mac1", "mac2"},
}),
- inventory.WithEntityAttributes(map[string]any{
+ inventory.WithEntityDetails(map[string]any{
"ImageId": "image-id",
"Platform": "linux",
"VpcId": "vpc-id",
diff --git a/internal/inventory/awsfetcher/fetcher_eks.go b/internal/inventory/awsfetcher/fetcher_eks.go
index 4b13fc070f..0b62537534 100644
--- a/internal/inventory/awsfetcher/fetcher_eks.go
+++ b/internal/inventory/awsfetcher/fetcher_eks.go
@@ -78,37 +78,37 @@ func (f *eksFetcher) Fetch(ctx context.Context, assetChannel chan<- inventory.As
AccountName: f.accountName,
ServiceName: "AWS EKS",
}),
- inventory.WithEntityAttributes(buildEKSAttributes(cluster)),
+ inventory.WithEntityDetails(buildEKSDetails(cluster)),
inventory.WithCreatedAt(cluster.CreatedAt),
)
}
}
-// buildEKSAttributes maps a cluster's non-ECS fields into entity.attributes using
+// buildEKSDetails maps a cluster's non-ECS fields into entity.Details using
// UpperCamelCase keys. The endpoint-access booleans are always included as they are
// meaningful even when false; other empty values are omitted.
-func buildEKSAttributes(cluster eks.Cluster) map[string]any {
- attrs := map[string]any{
+func buildEKSDetails(cluster eks.Cluster) map[string]any {
+ details := map[string]any{
"EndpointPublicAccess": cluster.EndpointPublicAccess,
"EndpointPrivateAccess": cluster.EndpointPrivateAccess,
}
if cluster.Status != "" {
- attrs["Status"] = cluster.Status
+ details["Status"] = cluster.Status
}
if cluster.Version != "" {
- attrs["Version"] = cluster.Version
+ details["Version"] = cluster.Version
}
if cluster.Endpoint != "" {
- attrs["Endpoint"] = cluster.Endpoint
+ details["Endpoint"] = cluster.Endpoint
}
if cluster.RoleArn != "" {
- attrs["RoleArn"] = cluster.RoleArn
+ details["RoleArn"] = cluster.RoleArn
}
if cluster.PlatformVersion != "" {
- attrs["PlatformVersion"] = cluster.PlatformVersion
+ details["PlatformVersion"] = cluster.PlatformVersion
}
if v := cluster.GetOwnerTag(); v != "" {
- attrs["OwnerTag"] = v
+ details["OwnerTag"] = v
}
- return attrs
+ return details
}
diff --git a/internal/inventory/awsfetcher/fetcher_eks_test.go b/internal/inventory/awsfetcher/fetcher_eks_test.go
index bae2a1fa6c..c37998a1d4 100644
--- a/internal/inventory/awsfetcher/fetcher_eks_test.go
+++ b/internal/inventory/awsfetcher/fetcher_eks_test.go
@@ -68,7 +68,7 @@ func TestEKSFetcher_Fetch(t *testing.T) {
AccountName: "alias",
ServiceName: "AWS EKS",
}),
- inventory.WithEntityAttributes(map[string]any{
+ inventory.WithEntityDetails(map[string]any{
"EndpointPublicAccess": true,
"EndpointPrivateAccess": false,
"Status": "ACTIVE",
@@ -91,7 +91,7 @@ func TestEKSFetcher_Fetch(t *testing.T) {
AccountName: "alias",
ServiceName: "AWS EKS",
}),
- inventory.WithEntityAttributes(map[string]any{
+ inventory.WithEntityDetails(map[string]any{
"EndpointPublicAccess": false,
"EndpointPrivateAccess": false,
}),
diff --git a/internal/inventory/awsfetcher/fetcher_elb.go b/internal/inventory/awsfetcher/fetcher_elb.go
index 18c57c82e8..e1aa0d912c 100644
--- a/internal/inventory/awsfetcher/fetcher_elb.go
+++ b/internal/inventory/awsfetcher/fetcher_elb.go
@@ -94,27 +94,27 @@ func (f *elbFetcher) fetch(ctx context.Context, resourceName string, function el
}
for _, item := range awsResources {
- var attrs map[string]any
+ var details map[string]any
var createdAt *time.Time
if r, ok := item.(elbInventoryResource); ok {
- attrs = map[string]any{
+ details = map[string]any{
"DNSName": r.GetDNSName(),
"PubliclyAccessible": r.IsPubliclyAccessible(),
}
if f.AccountId != "" {
- attrs["AccountID"] = f.AccountId
+ details["AccountID"] = f.AccountId
}
if v := r.GetLoadBalancerType(); v != "" {
- attrs["LoadBalancerType"] = v
+ details["LoadBalancerType"] = v
}
if v := r.GetState(); v != "" {
- attrs["State"] = v
+ details["State"] = v
}
if v := r.GetIPAddresses(); len(v) > 0 {
- attrs["IPAddresses"] = v
+ details["IPAddresses"] = v
}
if v := r.GetOwnerTag(); v != "" {
- attrs["OwnerTag"] = v
+ details["OwnerTag"] = v
}
createdAt = r.GetCreatedAt()
}
@@ -131,7 +131,7 @@ func (f *elbFetcher) fetch(ctx context.Context, resourceName string, function el
AccountName: f.AccountName,
ServiceName: "AWS Networking",
}),
- inventory.WithEntityAttributes(attrs),
+ inventory.WithEntityDetails(details),
inventory.WithCreatedAt(createdAt),
)
}
diff --git a/internal/inventory/awsfetcher/fetcher_elb_test.go b/internal/inventory/awsfetcher/fetcher_elb_test.go
index eee28cc2fd..2f4dbc2be1 100644
--- a/internal/inventory/awsfetcher/fetcher_elb_test.go
+++ b/internal/inventory/awsfetcher/fetcher_elb_test.go
@@ -79,7 +79,7 @@ func TestELBv1Fetcher_Fetch(t *testing.T) {
AccountName: "alias",
ServiceName: "AWS Networking",
}),
- inventory.WithEntityAttributes(map[string]any{
+ inventory.WithEntityDetails(map[string]any{
"DNSName": "internal-my-elb-v1.us-east-1.elb.amazonaws.com",
"PubliclyAccessible": false, // scheme is "internal"
"AccountID": "123",
@@ -134,7 +134,7 @@ func TestELBv2Fetcher_Fetch(t *testing.T) {
AccountName: "alias",
ServiceName: "AWS Networking",
}),
- inventory.WithEntityAttributes(map[string]any{
+ inventory.WithEntityDetails(map[string]any{
"DNSName": "internal-my-elb-v2.us-east-1.elb.amazonaws.com",
"PubliclyAccessible": false, // scheme is internal
"AccountID": "123",
diff --git a/internal/inventory/awsfetcher/fetcher_rds.go b/internal/inventory/awsfetcher/fetcher_rds.go
index c436dd02ba..ad6a81cc01 100644
--- a/internal/inventory/awsfetcher/fetcher_rds.go
+++ b/internal/inventory/awsfetcher/fetcher_rds.go
@@ -70,14 +70,14 @@ func (s *rdsFetcher) Fetch(ctx context.Context, assetChannel chan<- inventory.As
})
for _, item := range rdsInstances {
- attrs := map[string]any{
+ details := map[string]any{
"PubliclyAccessible": item.PubliclyAccessible,
}
if item.Engine != "" {
- attrs["Engine"] = item.Engine
+ details["Engine"] = item.Engine
}
if item.EngineVersion != "" {
- attrs["EngineVersion"] = item.EngineVersion
+ details["EngineVersion"] = item.EngineVersion
}
assetChannel <- inventory.NewAssetEvent(
@@ -93,7 +93,7 @@ func (s *rdsFetcher) Fetch(ctx context.Context, assetChannel chan<- inventory.As
AccountName: s.AccountName,
ServiceName: "AWS RDS",
}),
- inventory.WithEntityAttributes(attrs),
+ inventory.WithEntityDetails(details),
inventory.WithCreatedAt(item.CreatedAt),
)
}
diff --git a/internal/inventory/awsfetcher/fetcher_rds_test.go b/internal/inventory/awsfetcher/fetcher_rds_test.go
index 0ad735df19..89d2deb49a 100644
--- a/internal/inventory/awsfetcher/fetcher_rds_test.go
+++ b/internal/inventory/awsfetcher/fetcher_rds_test.go
@@ -103,7 +103,7 @@ func TestRDSInstanceFetcher_Fetch(t *testing.T) {
AccountName: "alias",
ServiceName: "AWS RDS",
}),
- inventory.WithEntityAttributes(map[string]any{
+ inventory.WithEntityDetails(map[string]any{
"PubliclyAccessible": false,
"Engine": "postgres",
"EngineVersion": "15.4",
@@ -122,7 +122,7 @@ func TestRDSInstanceFetcher_Fetch(t *testing.T) {
AccountName: "alias",
ServiceName: "AWS RDS",
}),
- inventory.WithEntityAttributes(map[string]any{
+ inventory.WithEntityDetails(map[string]any{
"PubliclyAccessible": true,
"Engine": "mysql",
"EngineVersion": "8.0.35",
diff --git a/internal/inventory/awsfetcher/fetcher_route53.go b/internal/inventory/awsfetcher/fetcher_route53.go
index 8e8e6ac26e..5412b552dd 100644
--- a/internal/inventory/awsfetcher/fetcher_route53.go
+++ b/internal/inventory/awsfetcher/fetcher_route53.go
@@ -78,41 +78,41 @@ func (f *route53Fetcher) Fetch(ctx context.Context, assetChannel chan<- inventor
AccountName: f.accountName,
ServiceName: "AWS Route 53",
}),
- inventory.WithEntityAttributes(buildRoute53Attributes(record)),
+ inventory.WithEntityDetails(buildRoute53Details(record)),
)
}
}
-// buildRoute53Attributes maps a record's non-ECS fields into entity.attributes using
+// buildRoute53Details maps a record's non-ECS fields into entity.Details using
// UpperCamelCase keys. Empty values are omitted.
-func buildRoute53Attributes(record route53.Record) map[string]any {
- attrs := map[string]any{}
+func buildRoute53Details(record route53.Record) map[string]any {
+ details := map[string]any{}
if record.Type != "" {
- attrs["Type"] = record.Type
+ details["Type"] = record.Type
}
if len(record.Records) > 0 {
- attrs["ResourceRecords"] = record.Records
+ details["ResourceRecords"] = record.Records
}
if record.Weight != nil {
- attrs["Weight"] = *record.Weight
+ details["Weight"] = *record.Weight
}
if record.RoutingRegion != "" {
- attrs["Region"] = record.RoutingRegion
+ details["Region"] = record.RoutingRegion
}
if record.ZoneID != "" {
- attrs["ZoneID"] = record.ZoneID
+ details["ZoneID"] = record.ZoneID
}
if record.ZoneName != "" {
- attrs["ZoneName"] = record.ZoneName
+ details["ZoneName"] = record.ZoneName
}
if record.AliasTargetDNS != "" {
- attrs["AliasTargetDNS"] = record.AliasTargetDNS
+ details["AliasTargetDNS"] = record.AliasTargetDNS
}
if record.AliasTargetZoneID != "" {
- attrs["AliasTargetZoneId"] = record.AliasTargetZoneID
+ details["AliasTargetZoneId"] = record.AliasTargetZoneID
}
if record.HealthCheckID != "" {
- attrs["HealthCheckId"] = record.HealthCheckID
+ details["HealthCheckId"] = record.HealthCheckID
}
- return attrs
+ return details
}
diff --git a/internal/inventory/awsfetcher/fetcher_route53_test.go b/internal/inventory/awsfetcher/fetcher_route53_test.go
index ab531d5daa..424f0148c7 100644
--- a/internal/inventory/awsfetcher/fetcher_route53_test.go
+++ b/internal/inventory/awsfetcher/fetcher_route53_test.go
@@ -68,7 +68,7 @@ func TestRoute53Fetcher_Fetch(t *testing.T) {
AccountName: "alias",
ServiceName: "AWS Route 53",
}),
- inventory.WithEntityAttributes(map[string]any{
+ inventory.WithEntityDetails(map[string]any{
"Type": "A",
"ResourceRecords": []string{"203.0.113.10"},
"Weight": int64(10),
@@ -92,7 +92,7 @@ func TestRoute53Fetcher_Fetch(t *testing.T) {
AccountName: "alias",
ServiceName: "AWS Route 53",
}),
- inventory.WithEntityAttributes(map[string]any{
+ inventory.WithEntityDetails(map[string]any{
"Type": "NS",
"ZoneID": "Z123",
"ZoneName": "example.com.",
From 935bf22bca075e34914090918f95ecc7770402af Mon Sep 17 00:00:00 2001
From: "mergify[bot]" <37929162+mergify[bot]@users.noreply.github.com>
Date: Mon, 3 Aug 2026 13:34:09 +0200
Subject: [PATCH 02/70] [9.5](backport #7277) [Asset Inventory][AWS] Update
EC2, ELB and RDS fetchers for InfoSec (#7482)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
### Summary of your changes
> [!NOTE]
> **Stacked on #7473.** This PR is based on
`asset-inventory/fix-entity-attributes`, which renames the
`entity.attributes` (flattened) bag to `entity.Details` to fix the
Entity Store generic-extraction bug. All new fields below are therefore
emitted under **`entity.Details.*`** (not `entity.attributes.*`). Please
review/merge #7473 first; this PR's diff shows only the InfoSec fetcher
changes on top of it.
| Resource | Field | Change |
| -------------------- | --------------------------------- |
------------------------------------------------------------------------------------------------------------------------
|
| **EC2** | `entity.Details.Role` | Added `LookupTag(tags, "role")` in
`buildDetails` |
| **RDS** | `entity.Details.DBInstanceStatus` | Added `Status` field to
wrapper struct; mapped from `DBInstanceStatus` in provider; emitted in
fetcher |
| **ELB v2** (ALB/NLB) | `entity.Details.IPAddresses` |
`GetIPAddresses()` now also collects `PrivateIPv4Address` and
`IPv6Address` per AZ address (previously only `IpAddress`) |
| **ELB v1** (Classic) | `entity.Details.State` | `GetState()` returns
`"active"` (hardcoded as classic API exposes no state field) |
| **ELB v1** (Classic) | `entity.Details.IPAddresses` | DNS-resolves the
ELB `DNSName` at fetch time via injectable `hostResolver`; soft-fails to
empty on error |
### Related Issues
Closes https://github.com/elastic/security-team/issues/18294
### Checklist
- [x] I have added tests that prove my fix is effective or that my
feature works
This is an automatic backport of pull request #7277 done by
[Mergify](https://mergify.com).
Co-authored-by: Kuba Soboń
---
.../awsfetcher/fetcher_ec2_instance.go | 3 +
.../awsfetcher/fetcher_ec2_instance_test.go | 7 +-
.../inventory/awsfetcher/fetcher_elb_test.go | 12 +-
internal/inventory/awsfetcher/fetcher_rds.go | 3 +
.../inventory/awsfetcher/fetcher_rds_test.go | 4 +
.../resources/providers/awslib/elb/elb.go | 9 ++
.../providers/awslib/elb/elb_mock.go | 95 ++++++++++++
.../providers/awslib/elb/load_balancer.go | 24 ++-
.../providers/awslib/elb/provider.go | 23 ++-
.../providers/awslib/elb/provider_test.go | 146 +++++++++++-------
.../awslib/elb_v2/load_balancer_v2.go | 11 +-
.../awslib/elb_v2/provider_v2_test.go | 3 +-
.../providers/awslib/rds/provider.go | 1 +
.../providers/awslib/rds/provider_test.go | 5 +-
.../resources/providers/awslib/rds/rds.go | 1 +
15 files changed, 276 insertions(+), 71 deletions(-)
diff --git a/internal/inventory/awsfetcher/fetcher_ec2_instance.go b/internal/inventory/awsfetcher/fetcher_ec2_instance.go
index 6d59401cf9..a8d174478a 100644
--- a/internal/inventory/awsfetcher/fetcher_ec2_instance.go
+++ b/internal/inventory/awsfetcher/fetcher_ec2_instance.go
@@ -213,6 +213,9 @@ func (e *ec2InstanceFetcher) buildDetails(i *ec2.Ec2Instance, tags map[string]st
if v := awslib.LookupTag(tags, "costcenter", "cost-center", "cost_center"); v != "" {
details["CostCenter"] = v
}
+ if v := awslib.LookupTag(tags, "role"); v != "" {
+ details["Role"] = v
+ }
return details
}
diff --git a/internal/inventory/awsfetcher/fetcher_ec2_instance_test.go b/internal/inventory/awsfetcher/fetcher_ec2_instance_test.go
index 32d6d2f779..7842b68776 100644
--- a/internal/inventory/awsfetcher/fetcher_ec2_instance_test.go
+++ b/internal/inventory/awsfetcher/fetcher_ec2_instance_test.go
@@ -52,6 +52,7 @@ func makeTestInstance(launchTime *time.Time) *ec2beat.Ec2Instance {
{Key: pointers.Ref("key"), Value: pointers.Ref("value")},
{Key: pointers.Ref("Owner"), Value: pointers.Ref("team-infra")},
{Key: pointers.Ref("CostCenter"), Value: pointers.Ref("cc-1234")},
+ {Key: pointers.Ref("Role"), Value: pointers.Ref("sre")},
},
InstanceId: pointers.Ref("234567890"),
Architecture: ec2types.ArchitectureValuesX8664,
@@ -104,7 +105,7 @@ func TestEC2InstanceFetcher_Fetch(t *testing.T) {
"private-dns",
inventory.WithRelatedAssetIds([]string{"234567890"}),
inventory.WithRawAsset(instance1),
- inventory.WithLabels(map[string]string{"Name": "test-server", "key": "value", "Owner": "team-infra", "CostCenter": "cc-1234"}),
+ inventory.WithLabels(map[string]string{"Name": "test-server", "key": "value", "Owner": "team-infra", "CostCenter": "cc-1234", "Role": "sre"}),
inventory.WithCloud(inventory.Cloud{
Provider: inventory.AwsCloudProvider,
Region: "us-east",
@@ -134,6 +135,7 @@ func TestEC2InstanceFetcher_Fetch(t *testing.T) {
"RoleArn": testRoleArn,
"Owner": "team-infra",
"CostCenter": "cc-1234",
+ "Role": "sre",
}),
inventory.WithCreatedAt(&launchTime),
inventory.WithUser(inventory.User{
@@ -193,7 +195,7 @@ func TestEC2InstanceFetcher_Fetch_ResolverError(t *testing.T) {
"private-dns",
inventory.WithRelatedAssetIds([]string{"234567890"}),
inventory.WithRawAsset(instance),
- inventory.WithLabels(map[string]string{"Name": "test-server", "key": "value", "Owner": "team-infra", "CostCenter": "cc-1234"}),
+ inventory.WithLabels(map[string]string{"Name": "test-server", "key": "value", "Owner": "team-infra", "CostCenter": "cc-1234", "Role": "sre"}),
inventory.WithCloud(inventory.Cloud{
Provider: inventory.AwsCloudProvider,
Region: "us-east",
@@ -223,6 +225,7 @@ func TestEC2InstanceFetcher_Fetch_ResolverError(t *testing.T) {
// RoleArn is absent because the resolver failed.
"Owner": "team-infra",
"CostCenter": "cc-1234",
+ "Role": "sre",
}),
inventory.WithCreatedAt(&launchTime),
// WithUser falls back to the profile ARN when role resolution fails.
diff --git a/internal/inventory/awsfetcher/fetcher_elb_test.go b/internal/inventory/awsfetcher/fetcher_elb_test.go
index 2f4dbc2be1..24606ae17b 100644
--- a/internal/inventory/awsfetcher/fetcher_elb_test.go
+++ b/internal/inventory/awsfetcher/fetcher_elb_test.go
@@ -37,8 +37,8 @@ import (
)
func TestELBv1Fetcher_Fetch(t *testing.T) {
- asset := elb.ElasticLoadBalancerInfo{
- LoadBalancer: types.LoadBalancerDescription{
+ asset := elb.NewElasticLoadBalancerInfo(
+ types.LoadBalancerDescription{
AvailabilityZones: []string{"us-east-1a"},
CanonicalHostedZoneName: pointers.Ref("HZ-NAME"),
CanonicalHostedZoneNameID: pointers.Ref("HZ-ID"),
@@ -64,7 +64,11 @@ func TestELBv1Fetcher_Fetch(t *testing.T) {
Subnets: []string{"subnet-123"},
VPCId: pointers.Ref("vpc-id"),
},
- }
+ "", // awsAccount
+ "", // region
+ nil,
+ []string{"203.0.113.1", "203.0.113.2"}, // DNS-resolved by the provider in real code
+ )
in := []awslib.AwsResource{asset}
expected := []inventory.AssetEvent{
@@ -84,6 +88,8 @@ func TestELBv1Fetcher_Fetch(t *testing.T) {
"PubliclyAccessible": false, // scheme is "internal"
"AccountID": "123",
"LoadBalancerType": "classic",
+ "State": "active",
+ "IPAddresses": []string{"203.0.113.1", "203.0.113.2"},
}),
inventory.WithCreatedAt(asset.GetCreatedAt()),
),
diff --git a/internal/inventory/awsfetcher/fetcher_rds.go b/internal/inventory/awsfetcher/fetcher_rds.go
index ad6a81cc01..4aee6eafd1 100644
--- a/internal/inventory/awsfetcher/fetcher_rds.go
+++ b/internal/inventory/awsfetcher/fetcher_rds.go
@@ -79,6 +79,9 @@ func (s *rdsFetcher) Fetch(ctx context.Context, assetChannel chan<- inventory.As
if item.EngineVersion != "" {
details["EngineVersion"] = item.EngineVersion
}
+ if item.Status != "" {
+ details["DBInstanceStatus"] = item.Status
+ }
assetChannel <- inventory.NewAssetEvent(
inventory.AssetClassificationAwsRds,
diff --git a/internal/inventory/awsfetcher/fetcher_rds_test.go b/internal/inventory/awsfetcher/fetcher_rds_test.go
index 89d2deb49a..7fd8a5d8e8 100644
--- a/internal/inventory/awsfetcher/fetcher_rds_test.go
+++ b/internal/inventory/awsfetcher/fetcher_rds_test.go
@@ -44,6 +44,7 @@ func TestRDSInstanceFetcher_Fetch(t *testing.T) {
PubliclyAccessible: false,
Engine: "postgres",
EngineVersion: "15.4",
+ Status: "available",
CreatedAt: &createdAt,
Subnets: []rds.Subnet{
{
@@ -68,6 +69,7 @@ func TestRDSInstanceFetcher_Fetch(t *testing.T) {
PubliclyAccessible: true,
Engine: "mysql",
EngineVersion: "8.0.35",
+ Status: "available",
Subnets: []rds.Subnet{
{
ID: "subnet-aabbccdd",
@@ -107,6 +109,7 @@ func TestRDSInstanceFetcher_Fetch(t *testing.T) {
"PubliclyAccessible": false,
"Engine": "postgres",
"EngineVersion": "15.4",
+ "DBInstanceStatus": "available",
}),
inventory.WithCreatedAt(&createdAt),
),
@@ -126,6 +129,7 @@ func TestRDSInstanceFetcher_Fetch(t *testing.T) {
"PubliclyAccessible": true,
"Engine": "mysql",
"EngineVersion": "8.0.35",
+ "DBInstanceStatus": "available",
}),
),
}
diff --git a/internal/resources/providers/awslib/elb/elb.go b/internal/resources/providers/awslib/elb/elb.go
index 1ab79536e1..ca108996bd 100644
--- a/internal/resources/providers/awslib/elb/elb.go
+++ b/internal/resources/providers/awslib/elb/elb.go
@@ -19,6 +19,7 @@ package elb
import (
"context"
+ "net"
"github.com/aws/aws-sdk-go-v2/aws"
elb "github.com/aws/aws-sdk-go-v2/service/elasticloadbalancing"
@@ -28,6 +29,12 @@ import (
"github.com/elastic/cloudbeat/internal/resources/providers/awslib"
)
+// hostResolver abstracts DNS resolution so that tests can inject a fake without hitting the
+// real network. *net.Resolver satisfies this interface.
+type hostResolver interface {
+ LookupHost(ctx context.Context, host string) ([]string, error)
+}
+
type Client interface {
elb.DescribeLoadBalancersAPIClient
DescribeTags(ctx context.Context, params *elb.DescribeTagsInput, optFns ...func(*elb.Options)) (*elb.DescribeTagsOutput, error)
@@ -43,6 +50,7 @@ type Provider struct {
client Client
clients map[string]Client
awsAccountID string
+ resolver hostResolver
}
func NewElbProvider(ctx context.Context, log *clog.Logger, awsAccountID string, cfg aws.Config, factory awslib.CrossRegionFactory[Client]) *Provider {
@@ -55,5 +63,6 @@ func NewElbProvider(ctx context.Context, log *clog.Logger, awsAccountID string,
client: elb.NewFromConfig(cfg),
clients: m.GetMultiRegionsClientMap(),
awsAccountID: awsAccountID,
+ resolver: net.DefaultResolver,
}
}
diff --git a/internal/resources/providers/awslib/elb/elb_mock.go b/internal/resources/providers/awslib/elb/elb_mock.go
index d2da91ebdf..93ada95477 100644
--- a/internal/resources/providers/awslib/elb/elb_mock.go
+++ b/internal/resources/providers/awslib/elb/elb_mock.go
@@ -31,6 +31,101 @@ import (
mock "github.com/stretchr/testify/mock"
)
+// newMockHostResolver creates a new instance of mockHostResolver. It also registers a testing interface on the mock and a cleanup function to assert the mocks expectations.
+// The first argument is typically a *testing.T value.
+func newMockHostResolver(t interface {
+ mock.TestingT
+ Cleanup(func())
+}) *mockHostResolver {
+ mock := &mockHostResolver{}
+ mock.Mock.Test(t)
+
+ t.Cleanup(func() { mock.AssertExpectations(t) })
+
+ return mock
+}
+
+// mockHostResolver is an autogenerated mock type for the hostResolver type
+type mockHostResolver struct {
+ mock.Mock
+}
+
+type mockHostResolver_Expecter struct {
+ mock *mock.Mock
+}
+
+func (_m *mockHostResolver) EXPECT() *mockHostResolver_Expecter {
+ return &mockHostResolver_Expecter{mock: &_m.Mock}
+}
+
+// LookupHost provides a mock function for the type mockHostResolver
+func (_mock *mockHostResolver) LookupHost(ctx context.Context, host string) ([]string, error) {
+ ret := _mock.Called(ctx, host)
+
+ if len(ret) == 0 {
+ panic("no return value specified for LookupHost")
+ }
+
+ var r0 []string
+ var r1 error
+ if returnFunc, ok := ret.Get(0).(func(context.Context, string) ([]string, error)); ok {
+ return returnFunc(ctx, host)
+ }
+ if returnFunc, ok := ret.Get(0).(func(context.Context, string) []string); ok {
+ r0 = returnFunc(ctx, host)
+ } else {
+ if ret.Get(0) != nil {
+ r0 = ret.Get(0).([]string)
+ }
+ }
+ if returnFunc, ok := ret.Get(1).(func(context.Context, string) error); ok {
+ r1 = returnFunc(ctx, host)
+ } else {
+ r1 = ret.Error(1)
+ }
+ return r0, r1
+}
+
+// mockHostResolver_LookupHost_Call is a *mock.Call that shadows Run/Return methods with type explicit version for method 'LookupHost'
+type mockHostResolver_LookupHost_Call struct {
+ *mock.Call
+}
+
+// LookupHost is a helper method to define mock.On call
+// - ctx context.Context
+// - host string
+func (_e *mockHostResolver_Expecter) LookupHost(ctx interface{}, host interface{}) *mockHostResolver_LookupHost_Call {
+ return &mockHostResolver_LookupHost_Call{Call: _e.mock.On("LookupHost", ctx, host)}
+}
+
+func (_c *mockHostResolver_LookupHost_Call) Run(run func(ctx context.Context, host string)) *mockHostResolver_LookupHost_Call {
+ _c.Call.Run(func(args mock.Arguments) {
+ var arg0 context.Context
+ if args[0] != nil {
+ arg0 = args[0].(context.Context)
+ }
+ var arg1 string
+ if args[1] != nil {
+ arg1 = args[1].(string)
+ }
+ run(
+ arg0,
+ arg1,
+ )
+ })
+ return _c
+}
+
+func (_c *mockHostResolver_LookupHost_Call) Return(strings []string, err error) *mockHostResolver_LookupHost_Call {
+ _c.Call.Return(strings, err)
+ return _c
+}
+
+func (_c *mockHostResolver_LookupHost_Call) RunAndReturn(run func(ctx context.Context, host string) ([]string, error)) *mockHostResolver_LookupHost_Call {
+ _c.Call.Return(run)
+ return _c
+}
+
// NewMockClient creates a new instance of MockClient. It also registers a testing interface on the mock and a cleanup function to assert the mocks expectations.
// The first argument is typically a *testing.T value.
func NewMockClient(t interface {
diff --git a/internal/resources/providers/awslib/elb/load_balancer.go b/internal/resources/providers/awslib/elb/load_balancer.go
index 6c43aee676..8875b13215 100644
--- a/internal/resources/providers/awslib/elb/load_balancer.go
+++ b/internal/resources/providers/awslib/elb/load_balancer.go
@@ -33,6 +33,19 @@ type ElasticLoadBalancerInfo struct {
awsAccount string
region string
tags map[string]string
+ ipAddresses []string
+}
+
+// NewElasticLoadBalancerInfo constructs a classic load balancer wrapper. ipAddresses are the
+// addresses resolved from the load balancer's DNS name (classic ELBs expose no IPs via the API).
+func NewElasticLoadBalancerInfo(lb types.LoadBalancerDescription, awsAccount, region string, tags map[string]string, ipAddresses []string) *ElasticLoadBalancerInfo {
+ return &ElasticLoadBalancerInfo{
+ LoadBalancer: lb,
+ awsAccount: awsAccount,
+ region: region,
+ tags: tags,
+ ipAddresses: ipAddresses,
+ }
}
func (v ElasticLoadBalancerInfo) GetResourceArn() string {
@@ -73,14 +86,17 @@ func (v ElasticLoadBalancerInfo) GetLoadBalancerType() string {
return "classic"
}
-// GetState is not exposed for classic load balancers by the AWS SDK.
+// GetState returns "active" for classic load balancers. The classic ELB API does not expose
+// a state field, but any LB returned by DescribeLoadBalancers is live.
func (v ElasticLoadBalancerInfo) GetState() string {
- return ""
+ return "active"
}
-// GetIPAddresses is not exposed for classic load balancers (they are DNS-only).
+// GetIPAddresses returns the IP addresses resolved from the load balancer's DNS name.
+// Classic ELBs do not expose IPs directly via the AWS API; the addresses are resolved at
+// fetch time (see Provider.DescribeAllLoadBalancers) and stored here.
func (v ElasticLoadBalancerInfo) GetIPAddresses() []string {
- return nil
+ return v.ipAddresses
}
// GetOwnerTag returns the value of the "Owner" tag (case-insensitive), if present.
diff --git a/internal/resources/providers/awslib/elb/provider.go b/internal/resources/providers/awslib/elb/provider.go
index 9ab72a8a36..f1ed2e87fb 100644
--- a/internal/resources/providers/awslib/elb/provider.go
+++ b/internal/resources/providers/awslib/elb/provider.go
@@ -20,6 +20,7 @@ package elb
import (
"context"
"fmt"
+ "sort"
elb "github.com/aws/aws-sdk-go-v2/service/elasticloadbalancing"
"github.com/aws/aws-sdk-go-v2/service/elasticloadbalancing/types"
@@ -78,12 +79,22 @@ func (p *Provider) DescribeAllLoadBalancers(ctx context.Context) ([]awslib.AwsRe
var result []awslib.AwsResource
for _, item := range all {
- result = append(result, &ElasticLoadBalancerInfo{
- LoadBalancer: item,
- awsAccount: p.awsAccountID,
- region: region,
- tags: tagsByName[pointers.Deref(item.LoadBalancerName)],
- })
+ var ipAddresses []string
+ if dnsName := pointers.Deref(item.DNSName); dnsName != "" {
+ if ips, err := p.resolver.LookupHost(ctx, dnsName); err != nil {
+ p.log.Debugf("Could not resolve IPs for classic ELB %q: %v", dnsName, err)
+ } else {
+ sort.Strings(ips)
+ ipAddresses = ips
+ }
+ }
+ result = append(result, NewElasticLoadBalancerInfo(
+ item,
+ p.awsAccountID,
+ region,
+ tagsByName[pointers.Deref(item.LoadBalancerName)],
+ ipAddresses,
+ ))
}
return result, nil
})
diff --git a/internal/resources/providers/awslib/elb/provider_test.go b/internal/resources/providers/awslib/elb/provider_test.go
index a85bfb71b8..23b7199fc2 100644
--- a/internal/resources/providers/awslib/elb/provider_test.go
+++ b/internal/resources/providers/awslib/elb/provider_test.go
@@ -119,13 +119,63 @@ func TestProvider_DescribeLoadBalancers(t *testing.T) {
}
}
+// elbV1ClientWithResources builds a mock Client that returns one classic ELB with a DNSName.
+func elbV1ClientWithResources() Client {
+ m := &MockClient{}
+ m.On("DescribeLoadBalancers", mock.Anything, mock.Anything).
+ Return(&elasticloadbalancing.DescribeLoadBalancersOutput{
+ LoadBalancerDescriptions: []types.LoadBalancerDescription{
+ {
+ AvailabilityZones: []string{"us-east-1a"},
+ CanonicalHostedZoneName: pointers.Ref("HZ-NAME"),
+ CanonicalHostedZoneNameID: pointers.Ref("HZ-ID"),
+ CreatedTime: pointers.Ref(time.Now()),
+ DNSName: pointers.Ref("internal-my-elb-v1.us-east-1.elb.amazonaws.com"),
+ ListenerDescriptions: []types.ListenerDescription{
+ {
+ Listener: &types.Listener{
+ Protocol: pointers.Ref("HTTP"),
+ LoadBalancerPort: 80,
+ InstanceProtocol: pointers.Ref("HTTP"),
+ InstancePort: pointers.Ref(int32(80)),
+ },
+ },
+ },
+ LoadBalancerName: pointers.Ref("my-elb-v1"),
+ Scheme: pointers.Ref("internal"),
+ SecurityGroups: []string{"sg-123"},
+ SourceSecurityGroup: &types.SourceSecurityGroup{
+ OwnerAlias: pointers.Ref("123"),
+ GroupName: pointers.Ref("default"),
+ },
+ Subnets: []string{"subnet-123"},
+ VPCId: pointers.Ref("vpc-id"),
+ },
+ },
+ }, nil)
+ m.On("DescribeTags", mock.Anything, mock.Anything, mock.Anything).
+ Return(&elasticloadbalancing.DescribeTagsOutput{
+ TagDescriptions: []types.TagDescription{
+ {
+ LoadBalancerName: pointers.Ref("my-elb-v1"),
+ Tags: []types.Tag{
+ {Key: pointers.Ref("Owner"), Value: pointers.Ref("team-infra")},
+ },
+ },
+ },
+ }, nil)
+ return m
+}
+
func TestProvider_DescribeAllLoadBalancers(t *testing.T) {
tests := []struct {
name string
client func() Client
+ resolver func(t *testing.T) hostResolver
expectedResults int
wantErr bool
regions []string
+ checkResult func(t *testing.T, got []awslib.AwsResource)
}{
{
name: "with error",
@@ -134,59 +184,52 @@ func TestProvider_DescribeAllLoadBalancers(t *testing.T) {
m.On("DescribeLoadBalancers", mock.Anything, mock.Anything).Return(nil, errors.New("failed"))
return m
},
+ resolver: func(t *testing.T) hostResolver {
+ t.Helper()
+ // LookupHost is never reached: DescribeLoadBalancers fails first.
+ return newMockHostResolver(t)
+ },
wantErr: true,
regions: onlyDefaultRegion,
},
{
- name: "with resources",
- client: func() Client {
- m := &MockClient{}
- m.On("DescribeLoadBalancers", mock.Anything, mock.Anything).
- Return(&elasticloadbalancing.DescribeLoadBalancersOutput{
- LoadBalancerDescriptions: []types.LoadBalancerDescription{
- {
- AvailabilityZones: []string{"us-east-1a"},
- CanonicalHostedZoneName: pointers.Ref("HZ-NAME"),
- CanonicalHostedZoneNameID: pointers.Ref("HZ-ID"),
- CreatedTime: pointers.Ref(time.Now()),
- DNSName: pointers.Ref("internal-my-elb-v1.us-east-1.elb.amazonaws.com"),
- ListenerDescriptions: []types.ListenerDescription{
- {
- Listener: &types.Listener{
- Protocol: pointers.Ref("HTTP"),
- LoadBalancerPort: 80,
- InstanceProtocol: pointers.Ref("HTTP"),
- InstancePort: pointers.Ref(int32(80)),
- },
- },
- },
- LoadBalancerName: pointers.Ref("my-elb-v1"),
- Scheme: pointers.Ref("internal"),
- SecurityGroups: []string{"sg-123"},
- SourceSecurityGroup: &types.SourceSecurityGroup{
- OwnerAlias: pointers.Ref("123"),
- GroupName: pointers.Ref("default"),
- },
- Subnets: []string{"subnet-123"},
- VPCId: pointers.Ref("vpc-id"),
- },
- },
- }, nil)
- m.On("DescribeTags", mock.Anything, mock.Anything, mock.Anything).
- Return(&elasticloadbalancing.DescribeTagsOutput{
- TagDescriptions: []types.TagDescription{
- {
- LoadBalancerName: pointers.Ref("my-elb-v1"),
- Tags: []types.Tag{
- {Key: pointers.Ref("Owner"), Value: pointers.Ref("team-infra")},
- },
- },
- },
- }, nil)
+ name: "with resources and DNS IPs",
+ client: elbV1ClientWithResources,
+ resolver: func(t *testing.T) hostResolver {
+ t.Helper()
+ m := newMockHostResolver(t)
+ // unsorted on purpose: the provider is expected to sort the IPs
+ m.EXPECT().LookupHost(mock.Anything, mock.Anything).Return([]string{"10.0.0.2", "10.0.0.1"}, nil)
return m
},
regions: onlyDefaultRegion,
expectedResults: 1,
+ checkResult: func(t *testing.T, got []awslib.AwsResource) {
+ t.Helper()
+ lb, ok := got[0].(*ElasticLoadBalancerInfo)
+ require.True(t, ok)
+ assert.Equal(t, "team-infra", lb.GetOwnerTag())
+ assert.Equal(t, []string{"10.0.0.1", "10.0.0.2"}, lb.GetIPAddresses(), "IPs should be sorted")
+ },
+ },
+ {
+ name: "with resolver error (soft-fail)",
+ client: elbV1ClientWithResources,
+ resolver: func(t *testing.T) hostResolver {
+ t.Helper()
+ m := newMockHostResolver(t)
+ m.EXPECT().LookupHost(mock.Anything, mock.Anything).Return(nil, errors.New("dns timeout"))
+ return m
+ },
+ regions: onlyDefaultRegion,
+ expectedResults: 1,
+ checkResult: func(t *testing.T, got []awslib.AwsResource) {
+ t.Helper()
+ lb, ok := got[0].(*ElasticLoadBalancerInfo)
+ require.True(t, ok)
+ assert.Equal(t, "team-infra", lb.GetOwnerTag())
+ assert.Nil(t, lb.GetIPAddresses(), "IPs should be nil on DNS error (soft-fail)")
+ },
},
}
for _, tt := range tests {
@@ -198,9 +241,10 @@ func TestProvider_DescribeAllLoadBalancers(t *testing.T) {
client = tt.client()
}
p := &Provider{
- log: testhelper.NewLogger(t),
- clients: clients,
- client: client,
+ log: testhelper.NewLogger(t),
+ clients: clients,
+ client: client,
+ resolver: tt.resolver(t),
}
got, err := p.DescribeAllLoadBalancers(t.Context())
if tt.wantErr {
@@ -210,10 +254,8 @@ func TestProvider_DescribeAllLoadBalancers(t *testing.T) {
require.NoError(t, err)
assert.Len(t, got, tt.expectedResults)
- if len(got) > 0 {
- lb, ok := got[0].(*ElasticLoadBalancerInfo)
- require.True(t, ok)
- assert.Equal(t, "team-infra", lb.GetOwnerTag())
+ if tt.checkResult != nil && len(got) > 0 {
+ tt.checkResult(t, got)
}
})
}
diff --git a/internal/resources/providers/awslib/elb_v2/load_balancer_v2.go b/internal/resources/providers/awslib/elb_v2/load_balancer_v2.go
index 266f9b375b..e615a64584 100644
--- a/internal/resources/providers/awslib/elb_v2/load_balancer_v2.go
+++ b/internal/resources/providers/awslib/elb_v2/load_balancer_v2.go
@@ -75,8 +75,9 @@ func (v ElasticLoadBalancerInfo) GetState() string {
return string(v.LoadBalancer.State.Code)
}
-// GetIPAddresses returns the static IP addresses of the load balancer. Only Network Load
-// Balancers expose static IPs (via per-AZ addresses); ALB/Gateway return nil.
+// GetIPAddresses returns the IP addresses of the load balancer. Network Load Balancers with
+// an Elastic IP expose them via IpAddress; internal NLBs use PrivateIPv4Address; IPv6 NLBs
+// use IPv6Address. All three are collected so that no NLB address type is missed.
func (v ElasticLoadBalancerInfo) GetIPAddresses() []string {
var ips []string
for _, az := range v.LoadBalancer.AvailabilityZones {
@@ -84,6 +85,12 @@ func (v ElasticLoadBalancerInfo) GetIPAddresses() []string {
if ip := pointers.Deref(addr.IpAddress); ip != "" {
ips = append(ips, ip)
}
+ if ip := pointers.Deref(addr.PrivateIPv4Address); ip != "" {
+ ips = append(ips, ip)
+ }
+ if ip := pointers.Deref(addr.IPv6Address); ip != "" {
+ ips = append(ips, ip)
+ }
}
}
return ips
diff --git a/internal/resources/providers/awslib/elb_v2/provider_v2_test.go b/internal/resources/providers/awslib/elb_v2/provider_v2_test.go
index 84ca305bd5..3c15fcd5a4 100644
--- a/internal/resources/providers/awslib/elb_v2/provider_v2_test.go
+++ b/internal/resources/providers/awslib/elb_v2/provider_v2_test.go
@@ -90,6 +90,7 @@ func TestProvider_DescribeLoadBalancers(t *testing.T) {
{
LoadBalancerAddresses: []types.LoadBalancerAddress{
{IpAddress: pointers.Ref("203.0.113.10")},
+ {PrivateIPv4Address: pointers.Ref("10.0.1.5")},
},
},
},
@@ -186,7 +187,7 @@ func TestProvider_DescribeLoadBalancers(t *testing.T) {
assert.Equal(t, "team-infra", lb.GetOwnerTag())
assert.Equal(t, "network", lb.GetLoadBalancerType())
assert.Equal(t, "active", lb.GetState())
- assert.Equal(t, []string{"203.0.113.10"}, lb.GetIPAddresses())
+ assert.Equal(t, []string{"203.0.113.10", "10.0.1.5"}, lb.GetIPAddresses())
}
})
}
diff --git a/internal/resources/providers/awslib/rds/provider.go b/internal/resources/providers/awslib/rds/provider.go
index 5e14b423ed..749f228578 100644
--- a/internal/resources/providers/awslib/rds/provider.go
+++ b/internal/resources/providers/awslib/rds/provider.go
@@ -74,6 +74,7 @@ func (p Provider) DescribeDBInstances(ctx context.Context) ([]awslib.AwsResource
PubliclyAccessible: aws.ToBool(dbInstance.PubliclyAccessible),
Engine: aws.ToString(dbInstance.Engine),
EngineVersion: aws.ToString(dbInstance.EngineVersion),
+ Status: aws.ToString(dbInstance.DBInstanceStatus),
CreatedAt: dbInstance.InstanceCreateTime,
Subnets: subnets,
region: region,
diff --git a/internal/resources/providers/awslib/rds/provider_test.go b/internal/resources/providers/awslib/rds/provider_test.go
index 2e649efdb1..1fc8624390 100644
--- a/internal/resources/providers/awslib/rds/provider_test.go
+++ b/internal/resources/providers/awslib/rds/provider_test.go
@@ -96,6 +96,7 @@ func (s *ProviderTestSuite) TestProvider_DescribeDBInstances() {
StorageEncrypted: aws.Bool(true),
AutoMinorVersionUpgrade: aws.Bool(true),
PubliclyAccessible: aws.Bool(true),
+ DBInstanceStatus: aws.String("available"),
DBSubnetGroup: &types.DBSubnetGroup{VpcId: &identifier, Subnets: []types.Subnet{
{SubnetIdentifier: &identifier},
{SubnetIdentifier: &identifier2},
@@ -124,7 +125,9 @@ func (s *ProviderTestSuite) TestProvider_DescribeDBInstances() {
Arn: arn2,
StorageEncrypted: true,
AutoMinorVersionUpgrade: true,
- PubliclyAccessible: true, Subnets: []Subnet{
+ PubliclyAccessible: true,
+ Status: "available",
+ Subnets: []Subnet{
{ID: identifier, RouteTable: nil},
{ID: identifier2, RouteTable: &RouteTable{
ID: identifier,
diff --git a/internal/resources/providers/awslib/rds/rds.go b/internal/resources/providers/awslib/rds/rds.go
index 978e61fdd9..7286e4f5f1 100644
--- a/internal/resources/providers/awslib/rds/rds.go
+++ b/internal/resources/providers/awslib/rds/rds.go
@@ -36,6 +36,7 @@ type DBInstance struct {
PubliclyAccessible bool `json:"publicly_accessible"`
Engine string `json:"engine,omitempty"`
EngineVersion string `json:"engine_version,omitempty"`
+ Status string `json:"status,omitempty"`
CreatedAt *time.Time `json:"created_at,omitempty"`
Subnets []Subnet `json:"subnets"`
region string
From 1fe176967ef708ed6fae785e3d2194c33e45fd87 Mon Sep 17 00:00:00 2001
From: "elastic-vault-github-plugin-prod[bot]"
<150874479+elastic-vault-github-plugin-prod[bot]@users.noreply.github.com>
Date: Wed, 5 Aug 2026 11:12:47 -0500
Subject: [PATCH 03/70] Bump cloudbeat version 9.5 to 9.5.1 (#7591)
Bump cloudbeat version to `9.5.1`
Co-authored-by: Cloud Security Machine
---
version/version.go | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/version/version.go b/version/version.go
index 063e78059a..203d1e7ad5 100644
--- a/version/version.go
+++ b/version/version.go
@@ -18,7 +18,7 @@
package version
// name matches github.com/elastic/beats/v7/dev-tools/mage/settings.go parseBeatVersion
-const defaultBeatVersion = "9.5.0"
+const defaultBeatVersion = "9.5.1"
var qualifier = ""
From 02412ebfef4a00a6466b1bbb5be5aecc24bc4610 Mon Sep 17 00:00:00 2001
From: Oleg Sucharevich
Date: Fri, 7 Aug 2026 15:47:24 -0500
Subject: [PATCH 04/70] chore(deps): bump github.com/aquasecurity/trivy to
v0.71.1 (9.5) (#7695)
## Summary
Bumps `github.com/aquasecurity/trivy` from `v0.71.0` to `v0.71.1` on the
`9.5` branch.
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 6956703f3d..5e7079fbd2 100644
--- a/go.mod
+++ b/go.mod
@@ -20,7 +20,7 @@ require (
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.57.0 // indirect
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.57.0 // indirect
github.com/aquasecurity/go-dep-parser v0.0.0-20240606050805-1de9a375c629
- github.com/aquasecurity/trivy v0.71.0
+ github.com/aquasecurity/trivy v0.71.1
github.com/aquasecurity/trivy-db v0.0.0-20260528104838-11b0c9f9e5e4
github.com/aws/aws-sdk-go-v2 v1.42.1
github.com/aws/aws-sdk-go-v2/config v1.32.25
diff --git a/go.sum b/go.sum
index 9a10c0a159..839a9249ad 100644
--- a/go.sum
+++ b/go.sum
@@ -201,8 +201,8 @@ github.com/aquasecurity/testdocker v0.0.0-20260423080828-99e7cbfdbe56 h1:VUjEtNq
github.com/aquasecurity/testdocker v0.0.0-20260423080828-99e7cbfdbe56/go.mod h1:4ahMSJAwow5T1YsPOvyUpCz6faBXlD7p/fdKmA9baEQ=
github.com/aquasecurity/tml v0.6.1 h1:y2ZlGSfrhnn7t4ZJ/0rotuH+v5Jgv6BDDO5jB6A9gwo=
github.com/aquasecurity/tml v0.6.1/go.mod h1:OnYMWY5lvI9ejU7yH9LCberWaaTBW7hBFsITiIMY2yY=
-github.com/aquasecurity/trivy v0.71.0 h1:mXskgiicbR/z5dzTjD9UjwNfwaFJORAs81M/gTwHv94=
-github.com/aquasecurity/trivy v0.71.0/go.mod h1:GRZTF7odD36IsTb8FD+SD79sIxv+G6fo1K+e9nWhW84=
+github.com/aquasecurity/trivy v0.71.1 h1:dXCZlFUoDQe8g6CCXqojNU3jAsmqeWOwfiYD1h2ePNQ=
+github.com/aquasecurity/trivy v0.71.1/go.mod h1:GRZTF7odD36IsTb8FD+SD79sIxv+G6fo1K+e9nWhW84=
github.com/aquasecurity/trivy-checks v1.12.2-0.20251219190323-79d27547baf5 h1:8HnXyjgCiJwVX1mTKeqdyizd7ZBmXMPL+BMQ5UZd0Nk=
github.com/aquasecurity/trivy-checks v1.12.2-0.20251219190323-79d27547baf5/go.mod h1:hBSA3ziBFwGENK6/PYNIKm6N24SFg0wsv1VXeqPG/3M=
github.com/aquasecurity/trivy-db v0.0.0-20260528104838-11b0c9f9e5e4 h1:xjGYWLpVWWpSFr6oyKB6jKnpdJ10J/PokzPacDV2dVA=
From 3316841cea737a062897dc95100f232efb2e0552 Mon Sep 17 00:00:00 2001
From: "mergify[bot]" <37929162+mergify[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 14:09:13 +0000
Subject: [PATCH 05/70] [9.5](backport #7424) fix(azure): drive Resource Graph
pagination by SkipToken, not ResultTruncated (#7688)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
## Summary
Most Azure subscriptions in CSPM scans were showing only
subscription-level findings, with zero resource-level findings (storage
accounts, VMs, key vaults, etc.). Root cause: cloudbeat's Azure Resource
Graph (ARG) pagination loop stopped after the first page of results on
every real-world query, silently dropping resources per scan cycle.
## Root cause
In
`internal/resources/providers/azurelib/inventory/resource_graph_provider.go`,
`runPaginatedQuery` broke out of its pagination loop whenever
`response.ResultTruncated == false`. That flag does not mean "no more
pages" — per Microsoft's Resource Graph pagination contract, `SkipToken`
presence/absence is the only reliable continuation signal. In practice,
ordinary paginated ARG responses report `ResultTruncated: false` even
when a valid `SkipToken` for the next page is present, so the loop
always exited after page 1.
## Fix
Pagination now continues based solely on whether `SkipToken` is empty,
matching Microsoft's reference pagination pattern, instead of trusting
`ResultTruncated`.
## Regression test
Added a test in
`internal/resources/providers/azurelib/inventory/resource_graph_provider_test.go`
that mocks a 3-page ARG response sequence where every page reports
`ResultTruncated: false` but carries a `SkipToken` until the final page.
It fails against the pre-fix code (only page 1's asset is returned) and
passes with the fix.
This is an automatic backport of pull request
#7424 done by [Mergify](https://mergify.com).
Co-authored-by: Evgeniy Belyi
---
.../inventory/resource_graph_provider.go | 17 +++-
.../inventory/resource_graph_provider_test.go | 80 +++++++++++++++++++
2 files changed, 94 insertions(+), 3 deletions(-)
diff --git a/internal/resources/providers/azurelib/inventory/resource_graph_provider.go b/internal/resources/providers/azurelib/inventory/resource_graph_provider.go
index b61c187de0..231f79fd7f 100644
--- a/internal/resources/providers/azurelib/inventory/resource_graph_provider.go
+++ b/internal/resources/providers/azurelib/inventory/resource_graph_provider.go
@@ -99,11 +99,22 @@ func (p *ResourceGraphProvider) runPaginatedQuery(ctx context.Context, query arm
resourceAssets = append(resourceAssets, structuredAsset)
}
- if *response.ResultTruncated == armresourcegraph.ResultTruncatedFalse ||
- pointers.Deref(response.SkipToken) == "" {
+ // Per Azure Resource Graph's documented pagination contract, the presence of a
+ // SkipToken is the sole authoritative signal that more pages are available
+ // (see https://learn.microsoft.com/azure/governance/resource-graph/concepts/paging-results,
+ // whose reference implementations loop "while SkipToken is not nil").
+ // ResultTruncated does NOT indicate "more pages exist" - it flags cases where
+ // paging itself is unavailable (e.g. the query uses `limit`/`take`, or returns
+ // only dynamic/null columns), and is false on ordinary, fully-paginated
+ // responses even when a SkipToken for the next page is present. Treating
+ // ResultTruncated == false as a stop condition (as this code previously did)
+ // caused the loop to exit after the very first page for any multi-page result
+ // set, silently dropping every subsequent page of resources.
+ skipToken := pointers.Deref(response.SkipToken)
+ if skipToken == "" {
break
}
- query.Options.SkipToken = response.SkipToken
+ query.Options.SkipToken = to.Ptr(skipToken)
}
return resourceAssets, nil
diff --git a/internal/resources/providers/azurelib/inventory/resource_graph_provider_test.go b/internal/resources/providers/azurelib/inventory/resource_graph_provider_test.go
index ce4e0e5e05..bb314e530e 100644
--- a/internal/resources/providers/azurelib/inventory/resource_graph_provider_test.go
+++ b/internal/resources/providers/azurelib/inventory/resource_graph_provider_test.go
@@ -31,6 +31,7 @@ import (
"github.com/stretchr/testify/require"
"github.com/stretchr/testify/suite"
+ "github.com/elastic/cloudbeat/internal/resources/utils/pointers"
"github.com/elastic/cloudbeat/internal/resources/utils/strings"
"github.com/elastic/cloudbeat/internal/resources/utils/testhelper"
)
@@ -176,6 +177,85 @@ func (s *ProviderTestSuite) TestListAllAssetTypesByName() {
})
}
+// TestListAllAssetTypesByName_ContinuesAcrossAllPagesRegardlessOfResultTruncated is a
+// regression test for the pagination bug where most Azure subscriptions
+// returned only subscription-level findings with zero resource-level findings.
+//
+// Real Azure Resource Graph responses set ResultTruncated=false on every ordinary
+// paginated page - ResultTruncated only communicates that paging itself is unavailable
+// (e.g. because the query uses a `limit`/`take` operator), not whether more pages exist.
+// The authoritative "more data available" signal, per Microsoft's own reference
+// implementations (which loop "while SkipToken is not nil"), is solely the presence of
+// SkipToken. Before the fix, ListAllAssetTypesByName stopped fetching as soon as it saw
+// ResultTruncated == false, which meant it always stopped after the very first page and
+// silently dropped every subsequent page of resources - even though SkipToken indicated
+// more pages were available. This test fails against the pre-fix implementation (it
+// returns only the first page's single asset) and passes once pagination is driven
+// exclusively by SkipToken.
+func (s *ProviderTestSuite) TestListAllAssetTypesByName_ContinuesAcrossAllPagesRegardlessOfResultTruncated() {
+ pages := []armresourcegraph.QueryResponse{
+ {
+ Count: to.Ptr(int64(1)),
+ Data: []any{rawAsset("1")},
+ ResultTruncated: to.Ptr(armresourcegraph.ResultTruncatedFalse),
+ SkipToken: to.Ptr("page-2-token"),
+ },
+ {
+ Count: to.Ptr(int64(1)),
+ Data: []any{rawAsset("2")},
+ ResultTruncated: to.Ptr(armresourcegraph.ResultTruncatedFalse),
+ SkipToken: to.Ptr("page-3-token"),
+ },
+ {
+ Count: to.Ptr(int64(1)),
+ Data: []any{rawAsset("3")},
+ ResultTruncated: to.Ptr(armresourcegraph.ResultTruncatedFalse),
+ SkipToken: nil,
+ },
+ }
+ expectedIncomingSkipTokens := []string{"", "page-2-token", "page-3-token"}
+
+ callCount := 0
+ client := &ResourceGraphAzureClientWrapper{
+ AssetQuery: func(_ context.Context, query armresourcegraph.QueryRequest, _ *armresourcegraph.ClientResourcesOptions) (armresourcegraph.ClientResourcesResponse, error) {
+ s.Require().Lessf(callCount, len(pages), "provider requested a %dth page, but the mock server only has %d pages", callCount+1, len(pages))
+ s.Equal(expectedIncomingSkipTokens[callCount], pointers.Deref(query.Options.SkipToken), "unexpected SkipToken sent for call #%d", callCount)
+
+ response := armresourcegraph.ClientResourcesResponse{QueryResponse: pages[callCount]}
+ callCount++
+ return response, nil
+ },
+ }
+
+ provider := &ResourceGraphProvider{
+ log: testhelper.NewLogger(s.T()),
+ client: client,
+ }
+
+ values, err := provider.ListAllAssetTypesByName(s.T().Context(), "test", []string{"test"})
+ s.Require().NoError(err)
+ s.Equal(len(pages), callCount, "expected the provider to fetch every page")
+ s.Len(values, len(pages), "expected assets from all pages to be aggregated, not just the first page")
+
+ ids := lo.Map(values, func(a AzureAsset, _ int) string { return a.Id })
+ s.ElementsMatch([]string{"1", "2", "3"}, ids)
+}
+
+func rawAsset(id string) map[string]any {
+ return map[string]any{
+ "id": id,
+ "name": id,
+ "location": id,
+ "properties": map[string]any{"test": "test"},
+ "resourceGroup": id,
+ "subscriptionId": id,
+ "tenantId": id,
+ "type": id,
+ "sku": map[string]any{"test": "test"},
+ "identity": map[string]any{"test": "test"},
+ }
+}
+
func Test_generateQuery(t *testing.T) {
tests := []struct {
assetsGroup string
From 0234baf08d622943d0eb24770c3161065b3256c8 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 21:33:12 +0000
Subject: [PATCH 06/70] chore(deps): update module oras.land/oras-go/v2 to
v2.6.2 (9.5) (#7717)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| oras.land/oras-go/v2 | `v2.6.1` → `v2.6.2` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 4 ++--
go.sum | 8 ++++----
2 files changed, 6 insertions(+), 6 deletions(-)
diff --git a/go.mod b/go.mod
index 5e7079fbd2..f56bcd9298 100644
--- a/go.mod
+++ b/go.mod
@@ -571,7 +571,7 @@ require (
golang.org/x/crypto v0.53.0 // indirect
golang.org/x/mod v0.37.0 // indirect
golang.org/x/net v0.56.0 // indirect
- golang.org/x/sync v0.21.0
+ golang.org/x/sync v0.22.0
golang.org/x/sys v0.46.0 // indirect
golang.org/x/term v0.44.0 // indirect
golang.org/x/text v0.39.0 // indirect
@@ -594,7 +594,7 @@ require (
k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 // indirect
modernc.org/mathutil v1.7.1 // indirect
modernc.org/memory v1.11.0 // indirect
- oras.land/oras-go/v2 v2.6.1 // indirect
+ oras.land/oras-go/v2 v2.6.2 // indirect
sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect
sigs.k8s.io/kustomize/api v0.21.1 // indirect
sigs.k8s.io/kustomize/kyaml v0.21.1 // indirect
diff --git a/go.sum b/go.sum
index 839a9249ad..523bb868df 100644
--- a/go.sum
+++ b/go.sum
@@ -1615,8 +1615,8 @@ golang.org/x/sync v0.0.0-20181108010431-42b317875d0f/go.mod h1:RxMgew5VJxzue5/jJ
golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
-golang.org/x/sync v0.21.0 h1:HLII4xRRTtCRkxYp4HNFF0Js/Og6q2i++KXbg0gHCwM=
-golang.org/x/sync v0.21.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
+golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek=
+golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
golang.org/x/sys v0.0.0-20180830151530-49385e6e1522/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
golang.org/x/sys v0.0.0-20180909124046-d0be0721c37e/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
@@ -1811,8 +1811,8 @@ modernc.org/token v1.1.0 h1:Xl7Ap9dKaEs5kLoOQeQmPWevfnk/DM5qcLcYlA8ys6Y=
modernc.org/token v1.1.0/go.mod h1:UGzOrNV1mAFSEB63lOFHIpNRUVMvYTc6yu1SMY/XTDM=
mvdan.cc/sh/v3 v3.13.1 h1:DP3TfgZhDkT7lerUdnp6PTGKyxxzz6T+cOlY/xEvfWk=
mvdan.cc/sh/v3 v3.13.1/go.mod h1:lXJ8SexMvEVcHCoDvAGLZgFJ9Wsm2sulmoNEXGhYZD0=
-oras.land/oras-go/v2 v2.6.1 h1:bonOEkjLfp8tt6qXWRRWP6p1F+9octchOf2EqnWB4Zs=
-oras.land/oras-go/v2 v2.6.1/go.mod h1:dhtFrFOuZuDtAVeZ9FUnaa5zfzplG3ZnFX9/uH1J/Yk=
+oras.land/oras-go/v2 v2.6.2 h1:N04RXngAp1LJKTG6ifz3xHPipasEkWr+hFmInja5YKo=
+oras.land/oras-go/v2 v2.6.2/go.mod h1:PlTtg4JTDJkDe8yVHpM2wz7/YDc00GVas+i4jAW2TZ4=
pgregory.net/rapid v1.2.0 h1:keKAYRcjm+e1F0oAuU5F5+YPAWcyxNNRK2wud503Gnk=
pgregory.net/rapid v1.2.0/go.mod h1:PY5XlDGj0+V1FCq0o192FdRhpKHGTRIWBgqjDBTrq04=
sigs.k8s.io/controller-runtime v0.24.1 h1:miPEwrmirImAvgME1L9qebGHrOnGJoVmVdtOU9fRfo4=
From c4234cc777bca8dc4cc13bc875f1dee7728b0d15 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:13:53 +0000
Subject: [PATCH 07/70] chore(deps): update actions/checkout digest to 11d5960
(9.5) (#7749)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [actions/checkout](https://redirect.github.com/actions/checkout)
([changelog](https://redirect.github.com/actions/checkout/compare/34e114876b0b11c390a56381ad16ebd13914f8d5..11d5960a326750d5838078e36cf38b85af677262))
| action | digest | `34e1148` → `11d5960` |
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
.github/actions/kibana-ftr/action.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/.github/actions/kibana-ftr/action.yml b/.github/actions/kibana-ftr/action.yml
index 77fc9c1d9b..40a0ba2198 100644
--- a/.github/actions/kibana-ftr/action.yml
+++ b/.github/actions/kibana-ftr/action.yml
@@ -40,7 +40,7 @@ runs:
echo "KIBANA_DIR=kibana" >> "${GITHUB_OUTPUT}"
- name: Checkout Kibana Repository
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
+ uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
repository: elastic/kibana
ref: ${{ inputs.kibana_ref }}
From a77e540c6d592c196cfe09ef91cb140683b03e28 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:15:00 +0000
Subject: [PATCH 08/70] chore(deps): update debian docker digest to 34cd9e9
(9.5) (#7750)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| debian | final | digest | `35b8ff7` → `34cd9e9` |
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
deploy/Dockerfile | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/deploy/Dockerfile b/deploy/Dockerfile
index 5bebc0c51f..752efce3ad 100644
--- a/deploy/Dockerfile
+++ b/deploy/Dockerfile
@@ -1,4 +1,4 @@
-FROM debian@sha256:35b8ff74ead4880f22090b617372daff0ccae742eb5674455d542bef71ef1999
+FROM debian@sha256:34cd9e9fd437c0a095ec39cb2e73422c9f30821b0d0848ed74fd0d43bae4d958
RUN set -x && \
apt-get update && \
apt-get install -y --no-install-recommends \
From d8144706c0374a2b0fd872bfc2c24f5b1da31515 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:15:35 +0000
Subject: [PATCH 09/70] chore(deps): update github.com/bitnami/go-version
digest to 2aa268a (9.5) (#7751)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
|
[github.com/bitnami/go-version](https://redirect.github.com/bitnami/go-version)
| indirect | digest | `4eabdf0` → `2aa268a` |
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index f56bcd9298..63bc25f9f7 100644
--- a/go.mod
+++ b/go.mod
@@ -147,7 +147,7 @@ require (
github.com/aws/aws-sdk-go-v2/service/signin v1.2.0 // indirect
github.com/aws/aws-sdk-go-v2/service/sqs v1.44.0 // indirect
github.com/bitfield/gotestdox v0.2.2 // indirect
- github.com/bitnami/go-version v0.0.0-20260630102209-4eabdf0a8acc // indirect
+ github.com/bitnami/go-version v0.0.0-20260728133343-2aa268af0217 // indirect
github.com/blakesmith/ar v0.0.0-20190502131153-809d4375e1fb // indirect
github.com/blang/semver v3.5.1+incompatible // indirect
github.com/blang/semver/v4 v4.0.0 // indirect
diff --git a/go.sum b/go.sum
index 523bb868df..c166078da3 100644
--- a/go.sum
+++ b/go.sum
@@ -309,8 +309,8 @@ github.com/bgentry/go-netrc v0.0.0-20140422174119-9fd32a8b3d3d h1:xDfNPAt8lFiC1U
github.com/bgentry/go-netrc v0.0.0-20140422174119-9fd32a8b3d3d/go.mod h1:6QX/PXZ00z/TKoufEY6K/a0k6AhaJrQKdFe6OfVXsa4=
github.com/bitfield/gotestdox v0.2.2 h1:x6RcPAbBbErKLnapz1QeAlf3ospg8efBsedU93CDsnE=
github.com/bitfield/gotestdox v0.2.2/go.mod h1:D+gwtS0urjBrzguAkTM2wodsTQYFHdpx8eqRJ3N+9pY=
-github.com/bitnami/go-version v0.0.0-20260630102209-4eabdf0a8acc h1:6lVy3UwTwLfvnTniDGOPVZEdQTDJRiNK73Z4QwWiTgs=
-github.com/bitnami/go-version v0.0.0-20260630102209-4eabdf0a8acc/go.mod h1:9iglf1GG4oNRJ39bZ5AZrjgAFD2RwQbXw6Qf7Cs47wo=
+github.com/bitnami/go-version v0.0.0-20260728133343-2aa268af0217 h1:nF+AjKjJXxD5f3v5peVWQQG0cDQxD5i1ATzSel+bA6E=
+github.com/bitnami/go-version v0.0.0-20260728133343-2aa268af0217/go.mod h1:9iglf1GG4oNRJ39bZ5AZrjgAFD2RwQbXw6Qf7Cs47wo=
github.com/blakesmith/ar v0.0.0-20190502131153-809d4375e1fb h1:m935MPodAbYS46DG4pJSv7WO+VECIWUQ7OJYSoTrMh4=
github.com/blakesmith/ar v0.0.0-20190502131153-809d4375e1fb/go.mod h1:PkYb9DJNAwrSvRx5DYA+gUcOIgTGVMNkfSCbZM8cWpI=
github.com/blang/semver v3.5.1+incompatible h1:cQNTCjp13qL8KC3Nbxr/y2Bqb63oX6wdnnjpJbkM4JQ=
From ed49238596221d1e17bcf8edddbcd07859a42632 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:16:30 +0000
Subject: [PATCH 10/70] chore(deps): update github.com/dop251/goja digest to
493f220 (9.5) (#7752)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [github.com/dop251/goja](https://redirect.github.com/dop251/goja) |
indirect | digest | `b07b744` → `493f220` |
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/go.mod b/go.mod
index 63bc25f9f7..d23e72294e 100644
--- a/go.mod
+++ b/go.mod
@@ -395,7 +395,7 @@ require (
github.com/docker/docker-credential-helpers v0.9.8 // indirect
github.com/docker/go-connections v0.7.0 // indirect
github.com/docker/go-units v0.5.0 // indirect
- github.com/dop251/goja v0.0.0-20260701091749-b07b74453ea9 // indirect
+ github.com/dop251/goja v0.0.0-20260806115107-493f22071ef6 // indirect
github.com/dop251/goja_nodejs v0.0.0-20171011081505-adff31b136e6 // indirect
github.com/dustin/go-humanize v1.0.1 // indirect
github.com/eapache/go-resiliency v1.7.0 // indirect
From 3b60b7f52df4f3cb3e1797f77f70f6d3d32ec8ee Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:17:13 +0000
Subject: [PATCH 11/70] chore(deps): update github.com/google/pprof digest to
ef3492d (9.5) (#7754)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [github.com/google/pprof](https://redirect.github.com/google/pprof) |
indirect | digest | `7023385` → `ef3492d` |
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index d23e72294e..6d494cca4c 100644
--- a/go.mod
+++ b/go.mod
@@ -208,7 +208,7 @@ require (
github.com/google/go-github/v62 v62.0.0 // indirect
github.com/google/go-querystring v1.2.0 // indirect
github.com/google/jsonschema-go v0.4.3 // indirect
- github.com/google/pprof v0.0.0-20260604005048-7023385849c0 // indirect
+ github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3 // indirect
github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0 // indirect
github.com/hashicorp/aws-sdk-go-base/v2 v2.0.0-beta.73 // indirect
github.com/hashicorp/go-getter v1.8.6 // indirect
diff --git a/go.sum b/go.sum
index c166078da3..99983dba9c 100644
--- a/go.sum
+++ b/go.sum
@@ -757,8 +757,8 @@ github.com/google/licenseclassifier/v2 v2.0.0/go.mod h1:cOjbdH0kyC9R22sdQbYsFkto
github.com/google/martian/v3 v3.3.3 h1:DIhPTQrbPkgs2yJYdXU/eNACCG5DVQjySNRNlflZ9Fc=
github.com/google/martian/v3 v3.3.3/go.mod h1:iEPrYcgCF7jA9OtScMFQyAlZZ4YXTKEtJ1E6RWzmBA0=
github.com/google/pprof v0.0.0-20210407192527-94a9f03dee38/go.mod h1:kpwsk12EmLew5upagYY7GY0pfYCcupk39gWOCRROcvE=
-github.com/google/pprof v0.0.0-20260604005048-7023385849c0 h1:h1QTMDl6q9wDvDCJVpKQSjgleGFYnd2fOxmg2K+6BGE=
-github.com/google/pprof v0.0.0-20260604005048-7023385849c0/go.mod h1:MxpfABSjhmINe3F1It9d+8exIHFvUqtLIRCdOGNXqiI=
+github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3 h1:LMLX+LgTNWpfvCBdFebv6EsYotImrt/Ppc5cXIriCSo=
+github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3/go.mod h1:jl5iWTm0/hd5PjEYEOuwAJ57L/CibdZfrqZ5XA5GrCk=
github.com/google/s2a-go v0.1.9 h1:LGD7gtMgezd8a/Xak7mEWL0PjoTQFvpRudN895yqKW0=
github.com/google/s2a-go v0.1.9/go.mod h1:YA0Ei2ZQL3acow2O62kdp9UlnvMmU7kA6Eutn0dXayM=
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 h1:El6M4kTTCOh6aBiKaUGG7oYTSPP8MxqL4YI3kZKwcP4=
From 1edd12de5c90e8bcc056e99f9f5035798443d842 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:17:53 +0000
Subject: [PATCH 12/70] chore(deps): update github.com/power-devops/perfstat
digest to 8845660 (9.5) (#7758)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
|
[github.com/power-devops/perfstat](https://redirect.github.com/power-devops/perfstat)
| indirect | digest | `82ca368` → `8845660` |
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 6d494cca4c..aa982841ad 100644
--- a/go.mod
+++ b/go.mod
@@ -523,7 +523,7 @@ require (
github.com/pjbgf/sha1cd v0.6.0 // indirect
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
- github.com/power-devops/perfstat v0.0.0-20240221224432-82ca36839d55 // indirect
+ github.com/power-devops/perfstat v0.0.0-20260805114148-88456608a4f6 // indirect
github.com/prometheus/client_golang v1.23.2 // indirect
github.com/prometheus/client_model v0.6.2 // indirect
github.com/prometheus/common v0.69.0 // indirect
diff --git a/go.sum b/go.sum
index 99983dba9c..0b004f25e4 100644
--- a/go.sum
+++ b/go.sum
@@ -1142,8 +1142,8 @@ github.com/planetscale/vtprotobuf v0.6.1-0.20250313105119-ba97887b0a25/go.mod h1
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 h1:Jamvg5psRIccs7FGNTlIRMkT8wgtp5eCXdBlqhYGL6U=
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
-github.com/power-devops/perfstat v0.0.0-20240221224432-82ca36839d55 h1:o4JXh1EVt9k/+g42oCprj/FisM4qX9L3sZB3upGN2ZU=
-github.com/power-devops/perfstat v0.0.0-20240221224432-82ca36839d55/go.mod h1:OmDBASR4679mdNQnz2pUhc2G8CO2JrUAVFDRBDP/hJE=
+github.com/power-devops/perfstat v0.0.0-20260805114148-88456608a4f6 h1:jL3a8soXdzuTCcRnKhOmtcsVOObdDTFf4O2B403HPRU=
+github.com/power-devops/perfstat v0.0.0-20260805114148-88456608a4f6/go.mod h1:OmDBASR4679mdNQnz2pUhc2G8CO2JrUAVFDRBDP/hJE=
github.com/poy/onpar v1.1.2 h1:QaNrNiZx0+Nar5dLgTVp5mXkyoVFIbepjyEoGSnhbAY=
github.com/poy/onpar v1.1.2/go.mod h1:6X8FLNoxyr9kkmnlqpK6LSoiOtrO6MICtWwEuWkLjzg=
github.com/prometheus/client_golang v1.23.2 h1:Je96obch5RDVy3FDMndoUsjAhG5Edi49h0RJWRi/o0o=
From 0bf155cb331bff59c1a16781509760267e39a020 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:18:07 +0000
Subject: [PATCH 13/70] chore(deps): update github.com/ianlancetaylor/demangle
digest to 83e58ba (9.5) (#7755)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
|
[github.com/ianlancetaylor/demangle](https://redirect.github.com/ianlancetaylor/demangle)
| indirect | digest | `1ff4bf4` → `83e58ba` |
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index aa982841ad..8646be6b69 100644
--- a/go.mod
+++ b/go.mod
@@ -215,7 +215,7 @@ require (
github.com/hashicorp/go-retryablehttp v0.7.8 // indirect
github.com/huandu/go-clone v1.7.3 // indirect
github.com/huandu/go-sqlbuilder v1.42.1 // indirect
- github.com/ianlancetaylor/demangle v0.0.0-20260505044615-1ff4bf46051f // indirect
+ github.com/ianlancetaylor/demangle v0.0.0-20260724033716-83e58baca724 // indirect
github.com/in-toto/attestation v1.2.0 // indirect
github.com/jcmturner/goidentity/v6 v6.0.1 // indirect
github.com/jedisct1/go-minisign v0.0.0-20260527172527-a09352b57a22 // indirect
diff --git a/go.sum b/go.sum
index 0b004f25e4..5fbdf35d25 100644
--- a/go.sum
+++ b/go.sum
@@ -843,8 +843,8 @@ github.com/huandu/go-sqlbuilder v1.42.1/go.mod h1:BEm32AHl29lzKDeV3HAIkzrz9cgRyu
github.com/huandu/xstrings v1.5.0 h1:2ag3IFq9ZDANvthTwTiqSSZLjDc+BedvHPAp5tJy2TI=
github.com/huandu/xstrings v1.5.0/go.mod h1:y5/lhBue+AyNmUVz9RLU9xbLR0o4KIIExikq4ovT0aE=
github.com/ianlancetaylor/demangle v0.0.0-20200824232613-28f6c0f3b639/go.mod h1:aSSvb/t6k1mPoxDqO4vJh6VOCGPwU4O0C2/Eqndh1Sc=
-github.com/ianlancetaylor/demangle v0.0.0-20260505044615-1ff4bf46051f h1:NW3E2QSchEk63/fjeEvWOa2cE02FSv9ox//VE/N4c8g=
-github.com/ianlancetaylor/demangle v0.0.0-20260505044615-1ff4bf46051f/go.mod h1:gx7rwoVhcfuVKG5uya9Hs3Sxj7EIvldVofAWIUtGouw=
+github.com/ianlancetaylor/demangle v0.0.0-20260724033716-83e58baca724 h1:QixF8Mcbe87ET7pK/fPbBJ9GXFddmEY8yYMepzMzo30=
+github.com/ianlancetaylor/demangle v0.0.0-20260724033716-83e58baca724/go.mod h1:gx7rwoVhcfuVKG5uya9Hs3Sxj7EIvldVofAWIUtGouw=
github.com/in-toto/attestation v1.2.0 h1:aPRUZ3azbqD7yEBD5fP3TD8Dszf+YHo284SOcpahjQk=
github.com/in-toto/attestation v1.2.0/go.mod h1:r79G45gOmzPismgObLSL+rZTFxUgZLOQJI6LofTZgXk=
github.com/in-toto/in-toto-golang v0.11.0 h1:nfidMYBFx+E0lnmX5KUnN2Pdm8zdNKal1ayjJuzzRoA=
From 9b771523cfc522ebdd92681b5893bfbb9536b542 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:18:19 +0000
Subject: [PATCH 14/70] chore(deps): update python:3.14-slim docker digest to
a7fb1e6 (9.5) (#7761)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| python | final | digest | `5b3879b` → `a7fb1e6` |
| python | stage | digest | `5b3879b` → `a7fb1e6` |
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
tests/Dockerfile | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/tests/Dockerfile b/tests/Dockerfile
index ec24cb9b46..f621348af5 100644
--- a/tests/Dockerfile
+++ b/tests/Dockerfile
@@ -1,4 +1,4 @@
-FROM python:3.14-slim@sha256:5b3879b6f3cb77e712644d50262d05a7c146b7312d784a18eff7ff5462e77033 as builder
+FROM python:3.14-slim@sha256:a7fb1e634c4a578f9e0bd6327f11a3cde11b7a9395f48e24360c0988bcc5c2bc as builder
WORKDIR /usr/src/app
@@ -11,7 +11,7 @@ COPY pyproject.toml poetry.lock ./
RUN poetry export --without-hashes -f requirements.txt --output requirements.txt
-FROM python:3.14-slim@sha256:5b3879b6f3cb77e712644d50262d05a7c146b7312d784a18eff7ff5462e77033
+FROM python:3.14-slim@sha256:a7fb1e634c4a578f9e0bd6327f11a3cde11b7a9395f48e24360c0988bcc5c2bc
ENV PYTHONUNBUFFERED=1
From 41ffed415e4c2d73388c02e9645eadc2ddcb34af Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:18:39 +0000
Subject: [PATCH 15/70] chore(deps): update github.com/lufia/plan9stats digest
to 341c2f0 (9.5) (#7756)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
|
[github.com/lufia/plan9stats](https://redirect.github.com/lufia/plan9stats)
| indirect | digest | `477a660` → `341c2f0` |
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 8646be6b69..d81fb28490 100644
--- a/go.mod
+++ b/go.mod
@@ -483,7 +483,7 @@ require (
github.com/lann/ps v0.0.0-20150810152359-62de8c46ede0 // indirect
github.com/lib/pq v1.12.3 // indirect
github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de // indirect
- github.com/lufia/plan9stats v0.0.0-20260627054121-477a66015f15 // indirect
+ github.com/lufia/plan9stats v0.0.0-20260802145828-341c2f0c90b5 // indirect
github.com/lunixbochs/struc v0.0.0-20241101090106-8d528fa2c543 // indirect
github.com/magiconair/properties v1.8.10 // indirect
github.com/masahiro331/go-disk v0.0.0-20260423015231-f7a470ebd472 // indirect
diff --git a/go.sum b/go.sum
index 5fbdf35d25..ce2fc96dbe 100644
--- a/go.sum
+++ b/go.sum
@@ -952,8 +952,8 @@ github.com/lib/pq v1.12.3 h1:tTWxr2YLKwIvK90ZXEw8GP7UFHtcbTtty8zsI+YjrfQ=
github.com/lib/pq v1.12.3/go.mod h1:/p+8NSbOcwzAEI7wiMXFlgydTwcgTr3OSKMsD2BitpA=
github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de h1:9TO3cAIGXtEhnIaL+V+BEER86oLrvS+kWobKpbJuye0=
github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de/go.mod h1:zAbeS9B/r2mtpb6U+EI2rYA5OAXxsYw6wTamcNW+zcE=
-github.com/lufia/plan9stats v0.0.0-20260627054121-477a66015f15 h1:YkjVPl/YH5XlJ+/NiwzJtPYXXKRcyjmEUhsDci6YK3c=
-github.com/lufia/plan9stats v0.0.0-20260627054121-477a66015f15/go.mod h1:autxFIvghDt3jPTLoqZ9OZ7s9qTGNAWmYCjVFWPX/zg=
+github.com/lufia/plan9stats v0.0.0-20260802145828-341c2f0c90b5 h1:eveIIGn4BGM3qknO74omf6HYr30/exH+eVUTuAgwjZ0=
+github.com/lufia/plan9stats v0.0.0-20260802145828-341c2f0c90b5/go.mod h1:autxFIvghDt3jPTLoqZ9OZ7s9qTGNAWmYCjVFWPX/zg=
github.com/lunixbochs/struc v0.0.0-20241101090106-8d528fa2c543 h1:GxMuVb9tJajC1QpbQwYNY1ZAo1EIE8I+UclBjOfjz/M=
github.com/lunixbochs/struc v0.0.0-20241101090106-8d528fa2c543/go.mod h1:vy1vK6wD6j7xX6O6hXe621WabdtNkou2h7uRtTfRMyg=
github.com/magefile/mage v1.17.2 h1:fyXVu1eadI8Ap1HCCNgEhJ5McIWiYhLR8uol64ZZc40=
From e2c8fd94480444b743a1b7c98bbc0ce4356d0229 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:18:52 +0000
Subject: [PATCH 16/70] chore(deps): update containerd (9.5) (#7763)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/containerd/containerd/v2](https://redirect.github.com/containerd/containerd)
| `v2.3.2` → `v2.3.3` |

|

|
|
[github.com/containerd/ttrpc](https://redirect.github.com/containerd/ttrpc)
| `v1.2.8` → `v1.2.9` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
containerd/containerd
(github.com/containerd/containerd/v2)
###
[`v2.3.3`](https://redirect.github.com/containerd/containerd/releases/tag/v2.3.3):
containerd 2.3.3
[Compare
Source](https://redirect.github.com/containerd/containerd/compare/v2.3.2...v2.3.3)
Welcome to the v2.3.3 release of containerd!
The third patch release for containerd 2.3 contains various fixes and
updates.
##### Highlights
- Set SystemTemp environment variable on Windows so temp directory
overrides work for SYSTEM services
([#13694](https://redirect.github.com/containerd/containerd/pull/13694))
##### Container Runtime Interface (CRI)
- Fix nil pointer dereference in NRI GetIPs during pod sandbox teardown
or container exit
([#13697](https://redirect.github.com/containerd/containerd/pull/13697))
- Reject CreateContainer calls when the target sandbox is not running
([#13668](https://redirect.github.com/containerd/containerd/pull/13668))
- Ensure sandbox shutdown on RunPodSandbox hook failures to avoid mount
leaks
([#13645](https://redirect.github.com/containerd/containerd/pull/13645))
##### Image Distribution
- Surface OCI error bodies in registry 403 responses by falling back to
GET requests
([#13738](https://redirect.github.com/containerd/containerd/pull/13738))
##### Snapshotters
- Align default 4K mkfs block size for EROFS across all platforms
([#13632](https://redirect.github.com/containerd/containerd/pull/13632))
Please try out the release binaries and report any issues at
.
##### Contributors
- Maksym Pavlenko
- Samuel Karp
- Chris Henzie
- Phil Estes
- Sebastiaan van Stijn
- Akihiro Suda
- Austin Vazquez
- Chris Crone
- Derek McGowan
- Maksim An
- crawfordxx
- cshung
- lauralorenz
##### Changes
14 commits
- Prepare release notes for v2.3.3
([#13750](https://redirect.github.com/containerd/containerd/pull/13750))
-
[`7f6cee02a`](https://redirect.github.com/containerd/containerd/commit/7f6cee02ad5afc5f3244ec36937d8eed61f7057d)
Prepare release notes for v2.3.3
- CI: migrate Vagrant to Lima
([#13744](https://redirect.github.com/containerd/containerd/pull/13744))
-
[`7316210ce`](https://redirect.github.com/containerd/containerd/commit/7316210ce6bd95e8afd2856e256b5d9855385d01)
CI: migrate Vagrant to Lima
- remotes: surface OCI error body in registry 4xx responses
([#13738](https://redirect.github.com/containerd/containerd/pull/13738))
-
[`457fba3a3`](https://redirect.github.com/containerd/containerd/commit/457fba3a380dab10ef7e9334352352f72caf8423)
remotes: surface OCI error body on HEAD 403 via GET fallback
- Update go to 1.26.5
([#13732](https://redirect.github.com/containerd/containerd/pull/13732))
-
[`dc2df934e`](https://redirect.github.com/containerd/containerd/commit/dc2df934efebc78523d6821c2520f538ff65986d)
Update go to 1.26.5
- ci: pin fog-json to resolve gem conflict
([#13711](https://redirect.github.com/containerd/containerd/pull/13711))
-
[`5be0495df`](https://redirect.github.com/containerd/containerd/commit/5be0495dff529910a85b6ca1b2a1a35ea220da59)
ci: pin fog-json to resolve gem conflict
- Fix nil pointer dereference in NRI GetIPs
([#13697](https://redirect.github.com/containerd/containerd/pull/13697))
-
[`36c713971`](https://redirect.github.com/containerd/containerd/commit/36c7139715fee7ff2f87f78a8b3d6fea4e2e7b35)
Fix nil pointer dereference in NRI GetIPs
- Set SystemTemp env var to config temp on Windows
([#13694](https://redirect.github.com/containerd/containerd/pull/13694))
-
[`26dce170d`](https://redirect.github.com/containerd/containerd/commit/26dce170df24e227aeb5ccd1cec1e5c91b307595)
Set SystemTemp env var to config temp on Windows
- update runhcs to v0.15.0-rc.3
([#13693](https://redirect.github.com/containerd/containerd/pull/13693))
-
[`9bc2c2349`](https://redirect.github.com/containerd/containerd/commit/9bc2c23496073c3b48b083f6bede9e82d879a7d4)
update runhcs to v0.15.0-rc.3
- Update to current setup-go version
([#13686](https://redirect.github.com/containerd/containerd/pull/13686))
-
[`3e97edeb7`](https://redirect.github.com/containerd/containerd/commit/3e97edeb7d3dfcee903c37ab531b1fdfe0a49ae4)
Update to current setup-go version
- cri: reject CreateContainer when sandbox is not running
([#13668](https://redirect.github.com/containerd/containerd/pull/13668))
-
[`8856b0f9c`](https://redirect.github.com/containerd/containerd/commit/8856b0f9c3ae50efe6f2a84ab7337953faeb129f)
cri: reject CreateContainer when sandbox is not running
- update runhcs to v0.15.0-rc.2
([#13666](https://redirect.github.com/containerd/containerd/pull/13666))
-
[`ae796cec5`](https://redirect.github.com/containerd/containerd/commit/ae796cec596341f3db4ea324199b83670aaa8162)
update runhcs to v0.15.0-rc.2
- test: fix flaky image timestamp check on coarse clocks
([#13643](https://redirect.github.com/containerd/containerd/pull/13643))
-
[`168d56783`](https://redirect.github.com/containerd/containerd/commit/168d56783608354301e6f6dfb3ceb9af342c7dde)
test: fix flaky image timestamp check on coarse clocks
- Add defer in event of mid-function failures in RunPodSandbox to avoid
mount leaks
([#13645](https://redirect.github.com/containerd/containerd/pull/13645))
-
[`d1db61db8`](https://redirect.github.com/containerd/containerd/commit/d1db61db8d6b59cdb27e5e1843911ad12e25a5e7)
Add deferred call to ShutdownSandbox to avoid leaks
- erofs: align default mkfs block size across platforms
([#13632](https://redirect.github.com/containerd/containerd/pull/13632))
-
[`01b0f03f6`](https://redirect.github.com/containerd/containerd/commit/01b0f03f676c19bf5beca591524f274b61537694)
erofs: align default mkfs block size across platforms
##### Dependency Changes
This release has no dependency changes
Previous release can be found at
[v2.3.2](https://redirect.github.com/containerd/containerd/releases/tag/v2.3.2)
##### Which file should I download?
- `containerd---.tar.gz`: ✅Recommended. Dynamically
linked with glibc 2.35 (Ubuntu 22.04).
- `containerd-static---.tar.gz`: Statically linked.
Expected to be used on Linux distributions that do not use glibc >=
2.35. Not position-independent.
In addition to containerd, typically you will have to install
[runc](https://redirect.github.com/opencontainers/runc/releases)
and [CNI
plugins](https://redirect.github.com/containernetworking/plugins/releases)
from their official sites too.
See also the [Getting
Started](https://redirect.github.com/containerd/containerd/blob/main/docs/getting-started.md)
documentation.
containerd/ttrpc (github.com/containerd/ttrpc)
###
[`v1.2.9`](https://redirect.github.com/containerd/ttrpc/releases/tag/v1.2.9)
[Compare
Source](https://redirect.github.com/containerd/ttrpc/compare/v1.2.8...v1.2.9)
#### What's Changed
- Migrate from protobuild to buf by
[@kzys](https://redirect.github.com/kzys) in
[#226](https://redirect.github.com/containerd/ttrpc/pull/226)
- build(deps): bump actions/setup-go from 6.3.0 to 6.4.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#228](https://redirect.github.com/containerd/ttrpc/pull/228)
- Fix proto generation by
[@dmcgowan](https://redirect.github.com/dmcgowan) in
[#232](https://redirect.github.com/containerd/ttrpc/pull/232)
- Set buf version from file and match dev version by
[@dmcgowan](https://redirect.github.com/dmcgowan) in
[#233](https://redirect.github.com/containerd/ttrpc/pull/233)
- server: cancel per-stream context when handler returns by
[@eginez](https://redirect.github.com/eginez) in
[#231](https://redirect.github.com/containerd/ttrpc/pull/231)
- Fix deadlock when stream is not consumed by
[@dmcgowan](https://redirect.github.com/dmcgowan) in
[#229](https://redirect.github.com/containerd/ttrpc/pull/229)
- Remove gogo vanity command and gogo dependency by
[@liggitt](https://redirect.github.com/liggitt) in
[#239](https://redirect.github.com/containerd/ttrpc/pull/239)
- build(deps): bump actions/checkout from 6.0.2 to 6.0.3 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#240](https://redirect.github.com/containerd/ttrpc/pull/240)
- build(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#238](https://redirect.github.com/containerd/ttrpc/pull/238)
- build(deps): bump google.golang.org/grpc from 1.69.2 to 1.81.1 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#237](https://redirect.github.com/containerd/ttrpc/pull/237)
- build(deps): bump golang.org/x/sys from 0.42.0 to 0.46.0 in the
golang-x group across 1 directory by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#215](https://redirect.github.com/containerd/ttrpc/pull/215)
#### New Contributors
- [@eginez](https://redirect.github.com/eginez) made their first
contribution in
[#231](https://redirect.github.com/containerd/ttrpc/pull/231)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 4 ++--
go.sum | 8 ++++----
2 files changed, 6 insertions(+), 6 deletions(-)
diff --git a/go.mod b/go.mod
index d81fb28490..0af04512c5 100644
--- a/go.mod
+++ b/go.mod
@@ -157,7 +157,7 @@ require (
github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2 // indirect
github.com/containerd/cgroups/v3 v3.1.3 // indirect
github.com/containerd/containerd/api v1.11.1 // indirect
- github.com/containerd/containerd/v2 v2.3.2 // indirect
+ github.com/containerd/containerd/v2 v2.3.3 // indirect
github.com/containerd/errdefs v1.0.0 // indirect
github.com/containerd/errdefs/pkg v0.3.0 // indirect
github.com/containerd/log v0.1.0 // indirect
@@ -385,7 +385,7 @@ require (
github.com/cloudflare/circl v1.6.4 // indirect
github.com/containerd/continuity v0.5.0 // indirect
github.com/containerd/fifo v1.1.0 // indirect
- github.com/containerd/ttrpc v1.2.8 // indirect
+ github.com/containerd/ttrpc v1.2.9 // indirect
github.com/containerd/typeurl/v2 v2.3.0 // indirect
github.com/cyphar/filepath-securejoin v0.7.0 // indirect
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
diff --git a/go.sum b/go.sum
index ce2fc96dbe..46ad1e0465 100644
--- a/go.sum
+++ b/go.sum
@@ -363,8 +363,8 @@ github.com/containerd/cgroups/v3 v3.1.3 h1:eUNflyMddm18+yrDmZPn3jI7C5hJ9ahABE5q6
github.com/containerd/cgroups/v3 v3.1.3/go.mod h1:PKZ2AcWmSBsY/tJUVhtS/rluX0b1uq1GmPO1ElCmbOw=
github.com/containerd/containerd/api v1.11.1 h1:h8nfoDW9+fNsC/9TwiAHj8B1GzXKtR4eFtkhi/X5RLU=
github.com/containerd/containerd/api v1.11.1/go.mod h1:CaQFRu+N1MtbgL6JDOJLUB1hCKESU1lD6MuTJhgtdlw=
-github.com/containerd/containerd/v2 v2.3.2 h1:eLven1YxRMkeiKu7IcMrPKE+gn8sGR1DqHbbshMEvWM=
-github.com/containerd/containerd/v2 v2.3.2/go.mod h1:rHKGm3VW6wNrINb3x8mNT+w7qYXFVElTt/8HTuxVhD4=
+github.com/containerd/containerd/v2 v2.3.3 h1:MUNBVVBTBpPll7KPh5GTvkC3cfG03PQLAHVdsUoue9k=
+github.com/containerd/containerd/v2 v2.3.3/go.mod h1:rHKGm3VW6wNrINb3x8mNT+w7qYXFVElTt/8HTuxVhD4=
github.com/containerd/continuity v0.5.0 h1:7a85HZpCSs+1Zps0Ee3DPSuAWY+0SJM1JNM51nlEVDg=
github.com/containerd/continuity v0.5.0/go.mod h1:/lNJvtJKUQStBzpVQ1+rasXO1LAWtUQssk28EZvJ3nE=
github.com/containerd/errdefs v1.0.0 h1:tg5yIfIlQIrxYtu9ajqY42W3lpS19XqdxRQeEwYG8PI=
@@ -379,8 +379,8 @@ github.com/containerd/platforms v1.0.0-rc.4 h1:M42JrUT4zfZTqtkUwkr0GzmUWbfyO5VO0
github.com/containerd/platforms v1.0.0-rc.4/go.mod h1:lKlMXyLybmBedS/JJm11uDofzI8L2v0J2ZbYvNsbq1A=
github.com/containerd/plugin v1.1.0 h1:O+7lczNJVMy8rz0YNx3xGB8tTf5qY4i5abF041Ew19U=
github.com/containerd/plugin v1.1.0/go.mod h1:qBTum+A8lJ6lO44A19Eo7y1OlcLj4OWFH1DA/vnHmcc=
-github.com/containerd/ttrpc v1.2.8 h1:xbVu6D4qF2jihdh9rDVOKqUMiFBQk6YctTdo1zk087Y=
-github.com/containerd/ttrpc v1.2.8/go.mod h1:wyZW2K79t4Hfcxl+GUvkZqRBzJlqFFvgEeeWXa42tyE=
+github.com/containerd/ttrpc v1.2.9 h1:ha0ak962T0s3CA/RoZ6S6xiWZQF24GrBaEpiGX1uihg=
+github.com/containerd/ttrpc v1.2.9/go.mod h1:jjtQRwXm4DL3KsHKW8vDiUOV6wO0hi6IPhmJhxU7aEs=
github.com/containerd/typeurl/v2 v2.3.0 h1:HZHPhRWo5XMy3QGQoPrUzbW/2ckwjfweHmOwlkIrPAQ=
github.com/containerd/typeurl/v2 v2.3.0/go.mod h1:Qk+PAdUYArVj41TnGi6rJ+48RF0PkcTc4i/taoBcK0w=
github.com/coreos/go-oidc/v3 v3.19.0 h1:F/xyOi3x1UnG1U27YVnM1N6bHiL1K2upi6U/0qr8r+I=
From 7bbced611d8c9060fc9936898d7725fb9d9ad875 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:19:09 +0000
Subject: [PATCH 17/70] chore(deps): update golang docker digest to 2005724
(9.5) (#7759)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| golang | final | digest | `efaccb5` → `2005724` |
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
deploy/Dockerfile.debug | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/deploy/Dockerfile.debug b/deploy/Dockerfile.debug
index 739e478828..bf342f8f8d 100644
--- a/deploy/Dockerfile.debug
+++ b/deploy/Dockerfile.debug
@@ -1,4 +1,4 @@
-FROM golang@sha256:efaccb5b497e90df3ebe5216cc25cd9f98e73874e2d638b56e38d4a3f098c41c
+FROM golang@sha256:2005724102f45917a63e9d092fc0e4ea56ea575048ce147caad5f5f61502c365
RUN go install github.com/go-delve/delve/cmd/dlv@latest
RUN set -x && \
apt-get update && \
From 71b8b1c8244c64ddd37e53d71e668e8f676b569e Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:19:31 +0000
Subject: [PATCH 18/70] chore(deps): update k8s.io/kube-openapi digest to
d427ff9 (9.5) (#7760)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
|
[k8s.io/kube-openapi](https://redirect.github.com/kubernetes/kube-openapi)
| indirect | digest | `cdb1db5` → `d427ff9` |
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 29 ++++++++++++------------
go.sum | 70 ++++++++++++++++++++++++++++++----------------------------
2 files changed, 51 insertions(+), 48 deletions(-)
diff --git a/go.mod b/go.mod
index 0af04512c5..c03340736b 100644
--- a/go.mod
+++ b/go.mod
@@ -189,17 +189,18 @@ require (
github.com/go-jose/go-jose/v4 v4.1.4 // indirect
github.com/go-ldap/ldap/v3 v3.4.13 // indirect
github.com/go-openapi/runtime/server-middleware v0.32.2 // indirect
- github.com/go-openapi/swag/cmdutils v0.26.0 // indirect
- github.com/go-openapi/swag/conv v0.26.0 // indirect
- github.com/go-openapi/swag/fileutils v0.26.0 // indirect
+ github.com/go-openapi/swag/cmdutils v0.27.1 // indirect
+ github.com/go-openapi/swag/conv v0.27.1 // indirect
+ github.com/go-openapi/swag/fileutils v0.27.1 // indirect
github.com/go-openapi/swag/jsonname v0.26.0 // indirect
- github.com/go-openapi/swag/jsonutils v0.26.0 // indirect
- github.com/go-openapi/swag/loading v0.26.0 // indirect
- github.com/go-openapi/swag/mangling v0.26.0 // indirect
- github.com/go-openapi/swag/netutils v0.26.0 // indirect
- github.com/go-openapi/swag/stringutils v0.26.0 // indirect
- github.com/go-openapi/swag/typeutils v0.26.0 // indirect
- github.com/go-openapi/swag/yamlutils v0.26.0 // indirect
+ github.com/go-openapi/swag/jsonutils v0.27.1 // indirect
+ github.com/go-openapi/swag/loading v0.27.1 // indirect
+ github.com/go-openapi/swag/mangling v0.27.1 // indirect
+ github.com/go-openapi/swag/netutils v0.27.1 // indirect
+ github.com/go-openapi/swag/pools v0.27.1 // indirect
+ github.com/go-openapi/swag/stringutils v0.27.1 // indirect
+ github.com/go-openapi/swag/typeutils v0.27.1 // indirect
+ github.com/go-openapi/swag/yamlutils v0.27.1 // indirect
github.com/gocsaf/csaf/v3 v3.5.1 // indirect
github.com/gofrs/uuid/v5 v5.4.0 // indirect
github.com/gohugoio/hashstructure v0.6.0 // indirect
@@ -424,13 +425,13 @@ require (
github.com/go-ole/go-ole v1.3.0 // indirect
github.com/go-openapi/analysis v0.25.1 // indirect
github.com/go-openapi/errors v0.22.8 // indirect
- github.com/go-openapi/jsonpointer v0.23.1 // indirect
- github.com/go-openapi/jsonreference v0.21.6 // indirect
+ github.com/go-openapi/jsonpointer v1.0.0 // indirect
+ github.com/go-openapi/jsonreference v1.0.0 // indirect
github.com/go-openapi/loads v0.23.3 // indirect
github.com/go-openapi/runtime v0.32.2 // indirect
github.com/go-openapi/spec v0.22.5 // indirect
github.com/go-openapi/strfmt v0.26.3 // indirect
- github.com/go-openapi/swag v0.26.0 // indirect
+ github.com/go-openapi/swag v0.27.1 // indirect
github.com/go-openapi/validate v0.25.3 // indirect
github.com/go-sourcemap/sourcemap v2.1.4+incompatible // indirect
github.com/gobwas/glob v0.2.3 // indirect
@@ -589,7 +590,7 @@ require (
k8s.io/apiserver v0.36.2 // indirect
k8s.io/cli-runtime v0.36.2 // indirect
k8s.io/component-base v0.36.2 // indirect
- k8s.io/kube-openapi v0.0.0-20260706235625-cdb1db5517a0 // indirect
+ k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad // indirect
k8s.io/kubectl v0.36.2 // indirect
k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 // indirect
modernc.org/mathutil v1.7.1 // indirect
diff --git a/go.sum b/go.sum
index 46ad1e0465..80434c1c76 100644
--- a/go.sum
+++ b/go.sum
@@ -601,10 +601,10 @@ github.com/go-openapi/analysis v0.25.1 h1:We0FXVvCY5XNSb8GrE+k+wsgkUqTJqnkqsVAC9
github.com/go-openapi/analysis v0.25.1/go.mod h1:/S7h3rOOTHDGoPwyyjTGQpGeLKxWecr8QWSBdE68UgM=
github.com/go-openapi/errors v0.22.8 h1:oP7sW7TWc3wFFjrzzj0nI83H2qMBkNjNfSd+XRejk/I=
github.com/go-openapi/errors v0.22.8/go.mod h1:BuUoHcYrU6E7V9gfj1I5wLQqgtIHnup/alXZ8KdgQ0w=
-github.com/go-openapi/jsonpointer v0.23.1 h1:1HBACs7XIwR2RcmItfdSFlALhGbe6S92p0ry4d1GWg4=
-github.com/go-openapi/jsonpointer v0.23.1/go.mod h1:iWRmZTrGn7XwYhtPt/fvdSFj1OfNBngqRT2UG3BxSqY=
-github.com/go-openapi/jsonreference v0.21.6 h1:NZ5nGfnaM1n4I43Xjm1e5/M2GjOwQwndQz22uhxwD+Y=
-github.com/go-openapi/jsonreference v0.21.6/go.mod h1:xzbgtQ3ZbWxvET3AxdzCJlJt6vkovbf+IfSPJjD0tUY=
+github.com/go-openapi/jsonpointer v1.0.0 h1:kR9tHqY0CtZaOPVFm622dPVNhrvYpwr4uCxgL3h1H8s=
+github.com/go-openapi/jsonpointer v1.0.0/go.mod h1:Z3rw7dWu1p9IgitXCFamSlA5lmDiklEB6vkaxcNZW5Y=
+github.com/go-openapi/jsonreference v1.0.0 h1:jlmTr6torcd1YgDQvSfNmRtKzYDO4FGBkrAdlAVWnpY=
+github.com/go-openapi/jsonreference v1.0.0/go.mod h1:jtwdyGbJk0Xhe5Y+rwtglQP6Sb1WZST4rT32LWB+sv0=
github.com/go-openapi/loads v0.23.3 h1:g5Xap1JfwKkUnZdn+S0L3SzBDpcTIYzZ5Qaag0YDkKQ=
github.com/go-openapi/loads v0.23.3/go.mod h1:NOH07zLajXo8y55hom0omlHWDVVvCwBM/S+csCK8LqA=
github.com/go-openapi/runtime v0.32.2 h1:X9mZz716lFwYZ6bFV1BBnthNdHTy46zKM5Em4D1UISI=
@@ -615,36 +615,38 @@ github.com/go-openapi/spec v0.22.5 h1:KhO7RBlKQfonUWX2WzQCoLIXVA6AcNqDGZ3a1Dutdl
github.com/go-openapi/spec v0.22.5/go.mod h1:vxpOtMya5TXtENXKE5bKqv5NjocVhyhxHrlZfvKnZ74=
github.com/go-openapi/strfmt v0.26.3 h1:rzmslHarJgBbf2qfGge+X3htclQfmXqBZMm0Too0HhU=
github.com/go-openapi/strfmt v0.26.3/go.mod h1:a5nsUw0oRpQzZeOwx8bi6cKbzFZslpbCKt1LEot+KnQ=
-github.com/go-openapi/swag v0.26.0 h1:GVDXCmfvhfu1BxiHo8/FA+BbKmhecHnG3varjON5/RI=
-github.com/go-openapi/swag v0.26.0/go.mod h1:82g3193sZJRbocs7bNCqGfIgq8pkuwVwCfhKIRlEQF0=
-github.com/go-openapi/swag/cmdutils v0.26.0 h1:iowihOcvq7y4egO8cOq0dmfohz6wfeQ63U1EnuhO2TU=
-github.com/go-openapi/swag/cmdutils v0.26.0/go.mod h1:Sm1MVFMkF6guJJ+pQqHnQA3N0j9qALV3NxzDSv6bETM=
-github.com/go-openapi/swag/conv v0.26.0 h1:5yGGsPYI1ZCva93U0AoKi/iZrNhaJEjr324YVsiD89I=
-github.com/go-openapi/swag/conv v0.26.0/go.mod h1:tpAmIL7X58VPnHHiSO4uE3jBeRamGsFsfdDeDtb5ECE=
-github.com/go-openapi/swag/fileutils v0.26.0 h1:WJoPRvsA7QRiiWluowkLJa9jaYR7FCuxmDvnCgaRRxU=
-github.com/go-openapi/swag/fileutils v0.26.0/go.mod h1:0WDJ7lp67eNjPMO50wAWYlKvhOb6CQ37rzR7wrgI8Tc=
+github.com/go-openapi/swag v0.27.1 h1:VotvOLWW8q/EAxB0YdsBBGC8XYyeL1YwBj2ungAGPNg=
+github.com/go-openapi/swag v0.27.1/go.mod h1:GTkJPwHfhJp6MWr4/rCh64HVI3Ofu+tcsbfjfHmTxpE=
+github.com/go-openapi/swag/cmdutils v0.27.1 h1:I7sYqaWVl5mq0NEmNQkAmFDyNin9ufvMX/p2zwtQaOE=
+github.com/go-openapi/swag/cmdutils v0.27.1/go.mod h1:Sm1MVFMkF6guJJ+pQqHnQA3N0j9qALV3NxzDSv6bETM=
+github.com/go-openapi/swag/conv v0.27.1 h1:8wi9ZG+olmY1wXphl93EWniPtbSPkXM/feH7FgjsvrU=
+github.com/go-openapi/swag/conv v0.27.1/go.mod h1:QbqMivkpKhC3g1B1GGGOJ6ANewI3S62dbzYu3Duowqs=
+github.com/go-openapi/swag/fileutils v0.27.1 h1:QQqBSoi5mW4XpU85nS0mLcA+zAE6vLzrb0QkmLKf9oM=
+github.com/go-openapi/swag/fileutils v0.27.1/go.mod h1:VvJFZLTZS0AI854gEQz5tk7dBESdLjiNUMSZ/th2ry8=
github.com/go-openapi/swag/jsonname v0.26.0 h1:gV1NFX9M8avo0YSpmWogqfQISigCmpaiNci8cGECU5w=
github.com/go-openapi/swag/jsonname v0.26.0/go.mod h1:urBBR8bZNoDYGr653ynhIx+gTeIz0ARZxHkAPktJK2M=
-github.com/go-openapi/swag/jsonutils v0.26.0 h1:FawFML2iAXsPqmERscuMPIHmFsoP1tOqWkxBaKNMsnA=
-github.com/go-openapi/swag/jsonutils v0.26.0/go.mod h1:2VmA0CJlyFqgawOaPI9psnjFDqzyivIqLYN34t9p91E=
-github.com/go-openapi/swag/jsonutils/fixtures_test v0.26.0 h1:apqeINu/ICHouqiRZbyFvuDge5jCmmLTqGQ9V95EaOM=
-github.com/go-openapi/swag/jsonutils/fixtures_test v0.26.0/go.mod h1:AyM6QT8uz5IdKxk5akv0y6u4QvcL9GWERt0Jx/F/R8Y=
-github.com/go-openapi/swag/loading v0.26.0 h1:Apg6zaKhCJurpJer0DCxq99qwmhFddBhaMX7kilDcko=
-github.com/go-openapi/swag/loading v0.26.0/go.mod h1:dBxQ/6V2uBaAQdevN18VELE6xSpJWZxLX4txe12JwDg=
-github.com/go-openapi/swag/mangling v0.26.0 h1:Du2YC4YLA/Y5m/YKQd7AnY5qq0wRKSFZTTt8ktFaXcQ=
-github.com/go-openapi/swag/mangling v0.26.0/go.mod h1:jifS7W9vbg+pw63bT+GI53otluMQL3CeemuyCHKwVx0=
-github.com/go-openapi/swag/netutils v0.26.0 h1:CmZp+ZT7HrmFwrC3GdGsXBq2+42T1bjKBapcqVpIs3c=
-github.com/go-openapi/swag/netutils v0.26.0/go.mod h1:5iK+Ok3ZohWWex1C50BFTPexi03UaPwjW4Oj8kgrpwo=
-github.com/go-openapi/swag/stringutils v0.26.0 h1:qZQngLxs5s7SLijc3N2ZO+fUq2o8LjuWAASSrJuh+xg=
-github.com/go-openapi/swag/stringutils v0.26.0/go.mod h1:sWn5uY+QIIspwPhvgnqJsH8xqFT2ZbYcvbcFanRyhFE=
-github.com/go-openapi/swag/typeutils v0.26.0 h1:2kdEwdiNWy+JJdOvu5MA2IIg2SylWAFuuyQIKYybfq4=
-github.com/go-openapi/swag/typeutils v0.26.0/go.mod h1:oovDuIUvTrEHVMqWilQzKzV4YlSKgyZmFh7AlfABNVE=
-github.com/go-openapi/swag/yamlutils v0.26.0 h1:H7O8l/8NJJQ/oiReEN+oMpnGMyt8G0hl460nRZxhLMQ=
-github.com/go-openapi/swag/yamlutils v0.26.0/go.mod h1:1evKEGAtP37Pkwcc7EWMF0hedX0/x3Rkvei2wtG/TbU=
-github.com/go-openapi/testify/enable/yaml/v2 v2.5.1 h1:q9NtHwK4qHF7yZziBPvZyv7zWAIk8ok88Gh2mR6Jpc8=
-github.com/go-openapi/testify/enable/yaml/v2 v2.5.1/go.mod h1:JW0MXIotCYps/XsgJnG3a8Q7rE5xAiBwoOD5OfaIQBk=
-github.com/go-openapi/testify/v2 v2.5.1 h1:TMdhCaw8fUNraVSf3Omoob1dO/AzBfhtFAPW0an6sBo=
-github.com/go-openapi/testify/v2 v2.5.1/go.mod h1:SgsVHtfooshd0tublTtJ50FPKhujf47YRqauXXOUxfw=
+github.com/go-openapi/swag/jsonutils v0.27.1 h1:SVgK3i4USzCU5mibOOS/l4ea2h9UQXy7J7RNLTjuXjU=
+github.com/go-openapi/swag/jsonutils v0.27.1/go.mod h1:tdlEpZqdcQ17uj6J4YdK9vd8It5qWMwjWXOs0tjpRlk=
+github.com/go-openapi/swag/jsonutils/fixtures_test v0.27.1 h1:mJu3COL9WEaZVp/Kf2PRMi7tPszPEJfSr/OO75ynCs8=
+github.com/go-openapi/swag/jsonutils/fixtures_test v0.27.1/go.mod h1:mofwUWx70wvskwESqRJ//k/9kURmCgyJl5m5Ppoh5kY=
+github.com/go-openapi/swag/loading v0.27.1 h1:/DxUgDXKbBX4bcn7r9uEXfJyzN5XpiJmZplzQTjrRCY=
+github.com/go-openapi/swag/loading v0.27.1/go.mod h1:jvGh3iA2+zyUUycB5fgJWzeHnhrpvGnJJM0RVE9ZShE=
+github.com/go-openapi/swag/mangling v0.27.1 h1:yC9D0HyUE8gbP+BfmGx9+AA89ikwZTMjESK3OnnoaqA=
+github.com/go-openapi/swag/mangling v0.27.1/go.mod h1:jtBE2+V+3pILxOR7Vgce+Cwp6A2PgZbvVqfNntbVs0w=
+github.com/go-openapi/swag/netutils v0.27.1 h1:mICMFoS82F5TZ4Zy3cqmcQk+BFeCp3Uyq3Np7GI0/qU=
+github.com/go-openapi/swag/netutils v0.27.1/go.mod h1:J+WYyFMLtvtCGqa6jLv+YNUmIKI3ZRQRrvfNDMoQoEQ=
+github.com/go-openapi/swag/pools v0.27.1 h1:9LeadcMyb2GJCbXX5hVQDbZ2Lq9TL4dCs/nx1j5DO0E=
+github.com/go-openapi/swag/pools v0.27.1/go.mod h1:kVQefhSK5RWuRe7BXsL8htgBPAMpN7HDGpGEknqugeE=
+github.com/go-openapi/swag/stringutils v0.27.1 h1:ZXePZ0r2p1qSjo8tD3Un4vFj8+FqlCkczxDrJIhYUp8=
+github.com/go-openapi/swag/stringutils v0.27.1/go.mod h1:lzRN95CxXmA03XcDWHLOb6nOMcxCqR5rGY0lOgsfRoM=
+github.com/go-openapi/swag/typeutils v0.27.1 h1:KSTdFlfnse4r6dP9IrEnwMldjE+zs71UeEB3//PtVXc=
+github.com/go-openapi/swag/typeutils v0.27.1/go.mod h1:Srm0xFNRZ1Y+vCxJclo5qzx8aj+1pAKda/YfFPrG0dQ=
+github.com/go-openapi/swag/yamlutils v0.27.1 h1:ftxv6xvXb1E3zohUc+okZ9nSqNb9StQX/FXnKZ98sQA=
+github.com/go-openapi/swag/yamlutils v0.27.1/go.mod h1:bnxFIB1qewGRiZHypXGZ3fNgf13/0HfRgnS/iZBDrOo=
+github.com/go-openapi/testify/enable/yaml/v2 v2.6.0 h1:gGHwAJ0R/5jU8BEGDbfRNR3hL68dAVi84WuOApp29B0=
+github.com/go-openapi/testify/enable/yaml/v2 v2.6.0/go.mod h1:tY+St1SGq4NFl0QIqdTY4aEdbChAHxhyB77XQi9iJCo=
+github.com/go-openapi/testify/v2 v2.6.0 h1:5PKH2HE7YJ/LuRPQGvSxBRlFXNQhSetBLlGAgUEu3ug=
+github.com/go-openapi/testify/v2 v2.6.0/go.mod h1:SgsVHtfooshd0tublTtJ50FPKhujf47YRqauXXOUxfw=
github.com/go-openapi/validate v0.25.3 h1:4nzAIavcJ7WveHK2+V1UAkZK3kWcjzxZCzjfZAfavKs=
github.com/go-openapi/validate v0.25.3/go.mod h1:GemfuGMyYpIaBoKpX3z8sLywrmxpzWVOoJ7R0VeAVuk=
github.com/go-quicktest/qt v1.101.0 h1:O1K29Txy5P2OK0dGo59b7b0LR6wKfIhttaAhHUyn7eI=
@@ -1771,8 +1773,8 @@ k8s.io/component-base v0.36.2 h1:Z0VH80O7Ng0HDZnZj3WRR3urEGa0kTwmO8CwEwjVK1w=
k8s.io/component-base v0.36.2/go.mod h1:mGfFOA7Gwpdm1VW2cwSQYbiDIlz8GD2WGwH88QSeCyA=
k8s.io/klog/v2 v2.140.0 h1:Tf+J3AH7xnUzZyVVXhTgGhEKnFqye14aadWv7bzXdzc=
k8s.io/klog/v2 v2.140.0/go.mod h1:o+/RWfJ6PwpnFn7OyAG3QnO47BFsymfEfrz6XyYSSp0=
-k8s.io/kube-openapi v0.0.0-20260706235625-cdb1db5517a0 h1:CVjOUCTXINUThEmDs25FNSna0+vnGSoTleN+wiJu6hE=
-k8s.io/kube-openapi v0.0.0-20260706235625-cdb1db5517a0/go.mod h1:rcZ+P5cEvHQB+m154WBOatIGBgOEPjzmLkXjkHfg3ms=
+k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad h1:oXImqH8mQNk7PmvzKhmN3ddJoY6OnyM225MXwGHPm0A=
+k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad/go.mod h1:0/mqHCVhlumdJ3BhCfnjSZQE037nAhNodh1/hK0T8/I=
k8s.io/kubectl v0.36.2 h1:rpUGGpeL09XVOLep2yle5jrtk//JA1L6ZHfkQQtVEwk=
k8s.io/kubectl v0.36.2/go.mod h1:gVbQ3B/yb4bSR2ggQ7rd0W6icUSWs7sduH4e16Vii+0=
k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 h1:wU4tMEhLGgIbLvXQb1cfN+EcM0wf7zC6CPF+C79jroc=
From 1533e1048cf735d27ab5fe9a7c6e0521878e9700 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:22:53 +0000
Subject: [PATCH 19/70] chore(deps): update module github.com/ebitengine/purego
to v0.10.2 (9.5) (#7768)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/ebitengine/purego](https://redirect.github.com/ebitengine/purego)
| `v0.10.1` → `v0.10.2` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
ebitengine/purego (github.com/ebitengine/purego)
###
[`v0.10.2`](https://redirect.github.com/ebitengine/purego/releases/tag/v0.10.2)
[Compare
Source](https://redirect.github.com/ebitengine/purego/compare/v0.10.1...v0.10.2)
- Fixed an issue with FreeBSD 15 or later
([#480](https://redirect.github.com/ebitengine/purego/issues/480))
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index c03340736b..8a857c9605 100644
--- a/go.mod
+++ b/go.mod
@@ -171,7 +171,7 @@ require (
github.com/distribution/reference v0.6.0 // indirect
github.com/dlclark/regexp2 v1.12.0 // indirect
github.com/dylibso/observe-sdk/go v0.0.0-20240828172851-9145d8ad07e1 // indirect
- github.com/ebitengine/purego v0.10.1 // indirect
+ github.com/ebitengine/purego v0.10.2 // indirect
github.com/elastic/gokrb5/v8 v8.0.0-20251105095404-23cc45e6a102 // indirect
github.com/elastic/sarama v1.19.1-0.20260310070522-abae92ca1603 // indirect
github.com/envoyproxy/go-control-plane/envoy v1.37.0 // indirect
diff --git a/go.sum b/go.sum
index 80434c1c76..48ef4d1e1b 100644
--- a/go.sum
+++ b/go.sum
@@ -460,8 +460,8 @@ github.com/eapache/go-xerial-snappy v0.0.0-20230731223053-c322873962e3 h1:Oy0F4A
github.com/eapache/go-xerial-snappy v0.0.0-20230731223053-c322873962e3/go.mod h1:YvSRo5mw33fLEx1+DlK6L2VV43tJt5Eyel9n9XBcR+0=
github.com/eapache/queue v1.1.0 h1:YOEu7KNc61ntiQlcEeUIoDTJ2o8mQznoNvUhiigpIqc=
github.com/eapache/queue v1.1.0/go.mod h1:6eCeP0CKFpHLu8blIFXhExK/dRa7WDZfr6jVFPTqq+I=
-github.com/ebitengine/purego v0.10.1 h1:dewVBCBT2GaMu1SrNTYxQhgQBethzfhiwvZiLGP/qyY=
-github.com/ebitengine/purego v0.10.1/go.mod h1:iIjxzd6CiRiOG0UyXP+V1+jWqUXVjPKLAI0mRfJZTmQ=
+github.com/ebitengine/purego v0.10.2 h1:W809HbnvzAxgdm+aOvlSekrM16wGCdT/e76+9tS7gzE=
+github.com/ebitengine/purego v0.10.2/go.mod h1:iIjxzd6CiRiOG0UyXP+V1+jWqUXVjPKLAI0mRfJZTmQ=
github.com/elastic/beats/v7 v7.0.0-alpha2.0.20260604204725-a6d4c42eeb5a h1:30eIvk0M6zk0wbbQ9Bjx+WpodYrOLbb8DBhuttJWv/M=
github.com/elastic/beats/v7 v7.0.0-alpha2.0.20260604204725-a6d4c42eeb5a/go.mod h1:9Z39x2PXbT0CTQQUsg70i2nAjOXIcUxmtXUBkTH0lRk=
github.com/elastic/e2e-testing v1.2.3 h1:XKF91O+Y6RcrTuNc7kMM4/HE9pvkvjASIYhEWS5XkT0=
From af10badcdc691350adfcf42426578834e225d411 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:23:56 +0000
Subject: [PATCH 20/70] chore(deps): update module
github.com/go-git/go-billy/v5 to v5.9.1 (9.5) (#7770)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/go-git/go-billy/v5](https://redirect.github.com/go-git/go-billy)
| `v5.9.0` → `v5.9.1` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
go-git/go-billy (github.com/go-git/go-billy/v5)
###
[`v5.9.1`](https://redirect.github.com/go-git/go-billy/releases/tag/v5.9.1)
[Compare
Source](https://redirect.github.com/go-git/go-billy/compare/v5.9.0...v5.9.1)
#### What's Changed
- build: Update module golang.org/x/net to v0.55.0 \[SECURITY]
(releases/v5.x) by
[@go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#216](https://redirect.github.com/go-git/go-billy/pull/216)
- build: Update module golang.org/x/text to v0.39.0 \[SECURITY]
(releases/v5.x) by
[@go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#230](https://redirect.github.com/go-git/go-billy/pull/230)
- build: Update module golang.org/x/net to v0.56.0 \[SECURITY]
(releases/v5.x) by
[@go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#229](https://redirect.github.com/go-git/go-billy/pull/229)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 8a857c9605..872cad1619 100644
--- a/go.mod
+++ b/go.mod
@@ -417,7 +417,7 @@ require (
github.com/fatih/color v1.19.0 // indirect
github.com/fsnotify/fsnotify v1.10.1 // indirect
github.com/go-errors/errors v1.5.1 // indirect
- github.com/go-git/go-billy/v5 v5.9.0 // indirect
+ github.com/go-git/go-billy/v5 v5.9.1 // indirect
github.com/go-gorp/gorp/v3 v3.1.0 // indirect
github.com/go-ini/ini v1.67.0 // indirect
github.com/go-logr/logr v1.4.3
diff --git a/go.sum b/go.sum
index 48ef4d1e1b..adc17771cd 100644
--- a/go.sum
+++ b/go.sum
@@ -573,8 +573,8 @@ github.com/go-errors/errors v1.5.1 h1:ZwEMSLRCapFLflTpT7NKaAc7ukJ8ZPEjzlxt8rPN8b
github.com/go-errors/errors v1.5.1/go.mod h1:sIVyrIiJhuEF+Pj9Ebtd6P/rEYROXFi3BopGUQ5a5Og=
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 h1:+zs/tPmkDkHx3U66DAb0lQFJrpS6731Oaa12ikc+DiI=
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376/go.mod h1:an3vInlBmSxCcxctByoQdvwPiA7DTK7jaaFDBTtu0ic=
-github.com/go-git/go-billy/v5 v5.9.0 h1:jItGXszUDRtR/AlferWPTMN4j38BQ88XnXKbilmmBPA=
-github.com/go-git/go-billy/v5 v5.9.0/go.mod h1:jCnQMLj9eUgGU7+ludSTYoZL/GGmii14RxKFj7ROgHw=
+github.com/go-git/go-billy/v5 v5.9.1 h1:8U73XiOTfINdItHVa6z4Gv7ToObcZ6grkqQbLryLCdA=
+github.com/go-git/go-billy/v5 v5.9.1/go.mod h1:ExsU+jcGwXTBOnyilvAnEM1wug1IxHr4yP2ZXsNRtV0=
github.com/go-git/go-git-fixtures/v4 v4.3.2-0.20231010084843-55a94097c399 h1:eMje31YglSBqCdIqdhKBW8lokaMrL3uTkpGYlE2OOT4=
github.com/go-git/go-git-fixtures/v4 v4.3.2-0.20231010084843-55a94097c399/go.mod h1:1OCfN199q1Jm3HZlxleg+Dw/mwps2Wbk9frAWm+4FII=
github.com/go-git/go-git/v5 v5.19.1 h1:nX27AnaU43/K5bKktKwgBmR9lawoYVe1Ckg0rgzzN00=
From 0bc977cf5b24cb76c352eaf8353b0c52b75f98f6 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:24:16 +0000
Subject: [PATCH 21/70] chore(deps): update module github.com/go-git/go-git/v5
to v5.19.2 (9.5) (#7771)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/go-git/go-git/v5](https://redirect.github.com/go-git/go-git)
| `v5.19.1` → `v5.19.2` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
go-git/go-git (github.com/go-git/go-git/v5)
###
[`v5.19.2`](https://redirect.github.com/go-git/go-git/releases/tag/v5.19.2)
[Compare
Source](https://redirect.github.com/go-git/go-git/compare/v5.19.1...v5.19.2)
#### What's Changed
- build: Update module golang.org/x/crypto to v0.52.0 \[SECURITY]
(releases/v5.x) by
[@go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#2150](https://redirect.github.com/go-git/go-git/pull/2150)
- build: Update module github.com/go-git/go-git/v5 to v5.19.1
\[SECURITY] (releases/v5.x) by
[@go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#2141](https://redirect.github.com/go-git/go-git/pull/2141)
- build: Update module golang.org/x/net to v0.55.0 \[SECURITY]
(releases/v5.x) by
[@go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#2152](https://redirect.github.com/go-git/go-git/pull/2152)
- git: Worktree: Add stores index entires with backslashes on Windows by
[@joshblum](https://redirect.github.com/joshblum) in
[#2262](https://redirect.github.com/go-git/go-git/pull/2262)
- storage: dotgit, reject path traversal in reference names by
[@pjbgf](https://redirect.github.com/pjbgf) in
[#2254](https://redirect.github.com/go-git/go-git/pull/2254)
- build: Update module golang.org/x/net to v0.56.0 \[SECURITY]
(releases/v5.x) by
[@go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#2267](https://redirect.github.com/go-git/go-git/pull/2267)
- build: Update module golang.org/x/text to v0.39.0 \[SECURITY]
(releases/v5.x) by
[@go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#2268](https://redirect.github.com/go-git/go-git/pull/2268)
- \[v5] git: worktree, make the filesystem wrapper a symlink-safe
boundary by [@pjbgf](https://redirect.github.com/pjbgf) in
[#2277](https://redirect.github.com/go-git/go-git/pull/2277)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 872cad1619..8da685cb13 100644
--- a/go.mod
+++ b/go.mod
@@ -185,7 +185,7 @@ require (
github.com/go-asn1-ber/asn1-ber v1.5.8-0.20260416181348-e7dc79048676 // indirect
github.com/go-chi/chi/v5 v5.3.1 // indirect
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
- github.com/go-git/go-git/v5 v5.19.1 // indirect
+ github.com/go-git/go-git/v5 v5.19.2 // indirect
github.com/go-jose/go-jose/v4 v4.1.4 // indirect
github.com/go-ldap/ldap/v3 v3.4.13 // indirect
github.com/go-openapi/runtime/server-middleware v0.32.2 // indirect
diff --git a/go.sum b/go.sum
index adc17771cd..308e8bcfc9 100644
--- a/go.sum
+++ b/go.sum
@@ -577,8 +577,8 @@ github.com/go-git/go-billy/v5 v5.9.1 h1:8U73XiOTfINdItHVa6z4Gv7ToObcZ6grkqQbLryL
github.com/go-git/go-billy/v5 v5.9.1/go.mod h1:ExsU+jcGwXTBOnyilvAnEM1wug1IxHr4yP2ZXsNRtV0=
github.com/go-git/go-git-fixtures/v4 v4.3.2-0.20231010084843-55a94097c399 h1:eMje31YglSBqCdIqdhKBW8lokaMrL3uTkpGYlE2OOT4=
github.com/go-git/go-git-fixtures/v4 v4.3.2-0.20231010084843-55a94097c399/go.mod h1:1OCfN199q1Jm3HZlxleg+Dw/mwps2Wbk9frAWm+4FII=
-github.com/go-git/go-git/v5 v5.19.1 h1:nX27AnaU43/K5bKktKwgBmR9lawoYVe1Ckg0rgzzN00=
-github.com/go-git/go-git/v5 v5.19.1/go.mod h1:Pb1v0c7/g8aGQJwx9Us09W85yGoyvSwuhEGMH7zjDKQ=
+github.com/go-git/go-git/v5 v5.19.2 h1:wkfn7vOlUBu8ivAWKBWisTiwJK4jYHzTF8Ndv1LyGqY=
+github.com/go-git/go-git/v5 v5.19.2/go.mod h1:QqCBE1EFN5ddFmrliLQ3/ntRCUjZU3EJuwuB/jWEHjk=
github.com/go-gorp/gorp/v3 v3.1.0 h1:ItKF/Vbuj31dmV4jxA1qblpSwkl9g1typ24xoe70IGs=
github.com/go-gorp/gorp/v3 v3.1.0/go.mod h1:dLEjIyyRNiXvNZ8PSmzpt1GsWAUK8kjVhEpjH8TixEw=
github.com/go-ini/ini v1.67.0 h1:z6ZrTEZqSWOTyH2FlglNbNgARyHG8oLW9gMELqKr06A=
From f6fb221575d6a297cb732e16118d5df83c7a1b4e Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:24:59 +0000
Subject: [PATCH 22/70] chore(deps): update module
github.com/googleapis/enterprise-certificate-proxy to v0.3.20 (9.5) (#7774)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/googleapis/enterprise-certificate-proxy](https://redirect.github.com/googleapis/enterprise-certificate-proxy)
| `v0.3.18` → `v0.3.20` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
googleapis/enterprise-certificate-proxy
(github.com/googleapis/enterprise-certificate-proxy)
###
[`v0.3.20`](https://redirect.github.com/googleapis/enterprise-certificate-proxy/releases/tag/v0.3.20)
[Compare
Source](https://redirect.github.com/googleapis/enterprise-certificate-proxy/compare/v0.3.19...v0.3.20)
#### What's Changed
- chore(deps): update actions/upload-artifact action to v7 by
[@renovate-bot](https://redirect.github.com/renovate-bot) in
[#156](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/156)
- chore(deps): update actions/checkout action to v7 by
[@renovate-bot](https://redirect.github.com/renovate-bot) in
[#201](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/201)
- build(deps): bump golang.org/x/crypto from 0.47.0 to 0.52.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#205](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/205)
- chore(deps): update actions/setup-go action to v7 by
[@renovate-bot](https://redirect.github.com/renovate-bot) in
[#207](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/207)
- Update CODEOWNERS by
[@andyrzhao](https://redirect.github.com/andyrzhao) in
[#218](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/218)
- feat: Transition from localized logging to a robust, standardized
logging utility across the entire ECP repository. by
[@agrawalradhika-cell](https://redirect.github.com/agrawalradhika-cell)
in
[#217](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/217)
- chore: Bump version from v0.3.19 to v0.3.20 by
[@agrawalradhika-cell](https://redirect.github.com/agrawalradhika-cell)
in
[#221](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/221)
**Full Changelog**:
###
[`v0.3.19`](https://redirect.github.com/googleapis/enterprise-certificate-proxy/releases/tag/v0.3.19)
[Compare
Source](https://redirect.github.com/googleapis/enterprise-certificate-proxy/compare/v0.3.18...v0.3.19)
#### What's Changed
- fix: use legacy OpenSSL algorithms for keychain import by
[@nolanleastin](https://redirect.github.com/nolanleastin) in
[#210](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/210)
- chore: Update version.txt to 0.3.18 by
[@nolanleastin](https://redirect.github.com/nolanleastin) in
[#204](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/204)
- fix: mTLS routing for hosts starting with 'mtls.' by
[@nolanleastin](https://redirect.github.com/nolanleastin) in
[#209](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/209)
- chore: update go.mod toolchain to 1.26.5 by
[@nolanleastin](https://redirect.github.com/nolanleastin) in
[#212](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/212)
- fix: serialize PKCS11 operations to resolve thread exhaustion by
[@nolanleastin](https://redirect.github.com/nolanleastin) in
[#211](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/211)
- chore: update version.txt to v0.3.19 by
[@nolanleastin](https://redirect.github.com/nolanleastin) in
[#214](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/214)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 8da685cb13..0807286e54 100644
--- a/go.mod
+++ b/go.mod
@@ -450,7 +450,7 @@ require (
github.com/google/s2a-go v0.1.9 // indirect
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
github.com/google/uuid v1.6.0
- github.com/googleapis/enterprise-certificate-proxy v0.3.18 // indirect
+ github.com/googleapis/enterprise-certificate-proxy v0.3.20 // indirect
github.com/gosuri/uitable v0.0.4 // indirect
github.com/h2non/filetype v1.1.3 // indirect
github.com/hashicorp/errwrap v1.1.0 // indirect
diff --git a/go.sum b/go.sum
index 308e8bcfc9..d74c9db86e 100644
--- a/go.sum
+++ b/go.sum
@@ -770,8 +770,8 @@ github.com/google/trillian v1.7.3/go.mod h1:qh8iy4x/GvnVXUBd5pK4oncuT1Y9vVYfibQV
github.com/google/uuid v1.1.2/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0=
github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
-github.com/googleapis/enterprise-certificate-proxy v0.3.18 h1:hvVi34VucdrV1IIsiWuqYM8kutw/92MxNEFxCJZEh0k=
-github.com/googleapis/enterprise-certificate-proxy v0.3.18/go.mod h1:rSEsBUemEBZEexP2y6jPp16LUmUbjmSbcPMQizR0o4k=
+github.com/googleapis/enterprise-certificate-proxy v0.3.20 h1:t/xL64VUoN69MuMRQuJETqYGOw4Z9mSRJK9epIEtwFk=
+github.com/googleapis/enterprise-certificate-proxy v0.3.20/go.mod h1:L3D/IQExI6LqEjBdXcZQ1WluSgigQmSwBboFstVPM4w=
github.com/googleapis/gax-go/v2 v2.22.0 h1:PjIWBpgGIVKGoCXuiCoP64altEJCj3/Ei+kSU5vlZD4=
github.com/googleapis/gax-go/v2 v2.22.0/go.mod h1:irWBbALSr0Sk3qlqb9SyJ1h68WjgeFuiOzI4Rqw5+aY=
github.com/gorilla/handlers v1.5.2 h1:cLTUSsNkgcwhgRqvCNmdbRWG0A3N4F+M2nWKdScwyEE=
From 763126cf216fd916d19b23ae932e9ef76a53f81c Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 22:25:24 +0000
Subject: [PATCH 23/70] chore(deps): update module
github.com/go-asn1-ber/asn1-ber to v1.5.8 (9.5) (#7769)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/go-asn1-ber/asn1-ber](https://redirect.github.com/go-asn1-ber/asn1-ber)
| `v1.5.8-0.20260416181348-e7dc79048676` → `v1.5.8` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
go-asn1-ber/asn1-ber
(github.com/go-asn1-ber/asn1-ber)
###
[`v1.5.8`](https://redirect.github.com/go-asn1-ber/asn1-ber/releases/tag/v1.5.8)
[Compare
Source](https://redirect.github.com/go-asn1-ber/asn1-ber/compare/v1.5.7...v1.5.8)
#### What's Changed
- Correct Implementation for Relative OIDs by
[@s00500](https://redirect.github.com/s00500) in
[#45](https://redirect.github.com/go-asn1-ber/asn1-ber/pull/45)
- add test for result of tests/tc10.ber by
[@vetinari](https://redirect.github.com/vetinari) in
[#46](https://redirect.github.com/go-asn1-ber/asn1-ber/pull/46)
- set ldap boolean length to 1 byte by
[@borislavfra](https://redirect.github.com/borislavfra) in
[#47](https://redirect.github.com/go-asn1-ber/asn1-ber/pull/47)
- fix: guard against stack overflow on deeply-nested BER packets
([#49](https://redirect.github.com/go-asn1-ber/asn1-ber/issues/49))
by [@cpuschma](https://redirect.github.com/cpuschma) in
[#50](https://redirect.github.com/go-asn1-ber/asn1-ber/pull/50)
- fix: enforce `MaxPacketLengthBytes` for constructed packets by
[@cpuschma](https://redirect.github.com/cpuschma) in
[#53](https://redirect.github.com/go-asn1-ber/asn1-ber/pull/53)
- fix: reject long-form definite lengths that wrap negative by
[@cpuschma](https://redirect.github.com/cpuschma) in
[#54](https://redirect.github.com/go-asn1-ber/asn1-ber/pull/54)
#### New Contributors
- [@borislavfra](https://redirect.github.com/borislavfra) made
their first contribution in
[#47](https://redirect.github.com/go-asn1-ber/asn1-ber/pull/47)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 0807286e54..62e6122924 100644
--- a/go.mod
+++ b/go.mod
@@ -182,7 +182,7 @@ require (
github.com/fluxcd/cli-utils v1.2.2 // indirect
github.com/fvbommel/sortorder v1.1.0 // indirect
github.com/fxamacker/cbor/v2 v2.9.2 // indirect
- github.com/go-asn1-ber/asn1-ber v1.5.8-0.20260416181348-e7dc79048676 // indirect
+ github.com/go-asn1-ber/asn1-ber v1.5.8 // indirect
github.com/go-chi/chi/v5 v5.3.1 // indirect
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
github.com/go-git/go-git/v5 v5.19.2 // indirect
diff --git a/go.sum b/go.sum
index d74c9db86e..84fe4c6286 100644
--- a/go.sum
+++ b/go.sum
@@ -565,8 +565,8 @@ github.com/glebarez/go-sqlite v1.20.3 h1:89BkqGOXR9oRmG58ZrzgoY/Fhy5x0M+/WV48U5z
github.com/glebarez/go-sqlite v1.20.3/go.mod h1:u3N6D/wftiAzIOJtZl6BmedqxmmkDfH3q+ihjqxC9u0=
github.com/gliderlabs/ssh v0.3.8 h1:a4YXD1V7xMF9g5nTkdfnja3Sxy1PVDCj1Zg4Wb8vY6c=
github.com/gliderlabs/ssh v0.3.8/go.mod h1:xYoytBv1sV0aL3CavoDuJIQNURXkkfPA/wxQ1pL1fAU=
-github.com/go-asn1-ber/asn1-ber v1.5.8-0.20260416181348-e7dc79048676 h1:/8x2r8Tu++vpNYlO8ACB3cdwoFYDGGxkOSOLLHN9E2o=
-github.com/go-asn1-ber/asn1-ber v1.5.8-0.20260416181348-e7dc79048676/go.mod h1:hEBeB/ic+5LoWskz+yKT7vGhhPYkProFKoKdwZRWMe0=
+github.com/go-asn1-ber/asn1-ber v1.5.8 h1:H9AZkK22UOmfX8J84ubyaZxKJZ3FMHVwn8swoMML7iQ=
+github.com/go-asn1-ber/asn1-ber v1.5.8/go.mod h1:hEBeB/ic+5LoWskz+yKT7vGhhPYkProFKoKdwZRWMe0=
github.com/go-chi/chi/v5 v5.3.1 h1:3j4HZLGZQ3JpMCrPJF/Jl3mYJfWLKBfNJ6quurUGCf8=
github.com/go-chi/chi/v5 v5.3.1/go.mod h1:R+tYY2hNuVUUjxoPtqUdgBqevM9s9njzkTLutVsOCto=
github.com/go-errors/errors v1.5.1 h1:ZwEMSLRCapFLflTpT7NKaAc7ukJ8ZPEjzlxt8rPN8bk=
From 3b7425dfb189c30374e74b828ab57ff072f29608 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 23:39:08 +0000
Subject: [PATCH 24/70] chore(deps): update kubernetes packages to v0.36.3
(9.5) (#7765)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[k8s.io/apiextensions-apiserver](https://redirect.github.com/kubernetes/apiextensions-apiserver)
| `v0.36.2` → `v0.36.3` |

|

|
| [k8s.io/apiserver](https://redirect.github.com/kubernetes/apiserver) |
`v0.36.2` → `v0.36.3` |

|

|
|
[k8s.io/cli-runtime](https://redirect.github.com/kubernetes/cli-runtime)
| `v0.36.2` → `v0.36.3` |

|

|
|
[k8s.io/component-base](https://redirect.github.com/kubernetes/component-base)
| `v0.36.2` → `v0.36.3` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
kubernetes/apiextensions-apiserver
(k8s.io/apiextensions-apiserver)
###
[`v0.36.3`](https://redirect.github.com/kubernetes/apiextensions-apiserver/compare/v0.36.2...v0.36.3)
[Compare
Source](https://redirect.github.com/kubernetes/apiextensions-apiserver/compare/v0.36.2...v0.36.3)
kubernetes/apiserver (k8s.io/apiserver)
###
[`v0.36.3`](https://redirect.github.com/kubernetes/apiserver/compare/v0.36.2...v0.36.3)
[Compare
Source](https://redirect.github.com/kubernetes/apiserver/compare/v0.36.2...v0.36.3)
kubernetes/cli-runtime (k8s.io/cli-runtime)
###
[`v0.36.3`](https://redirect.github.com/kubernetes/cli-runtime/compare/v0.36.2...v0.36.3)
[Compare
Source](https://redirect.github.com/kubernetes/cli-runtime/compare/v0.36.2...v0.36.3)
kubernetes/component-base (k8s.io/component-base)
###
[`v0.36.3`](https://redirect.github.com/kubernetes/component-base/compare/v0.36.2...v0.36.3)
[Compare
Source](https://redirect.github.com/kubernetes/component-base/compare/v0.36.2...v0.36.3)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 14 +++++++-------
go.sum | 28 ++++++++++++++--------------
2 files changed, 21 insertions(+), 21 deletions(-)
diff --git a/go.mod b/go.mod
index 62e6122924..11ed030005 100644
--- a/go.mod
+++ b/go.mod
@@ -107,9 +107,9 @@ require (
google.golang.org/api v0.287.0
gopkg.in/yaml.v3 v3.0.1
gotest.tools/gotestsum v1.13.0
- k8s.io/api v0.36.2
- k8s.io/apimachinery v0.36.2
- k8s.io/client-go v0.36.2
+ k8s.io/api v0.36.3
+ k8s.io/apimachinery v0.36.3
+ k8s.io/client-go v0.36.3
k8s.io/klog/v2 v2.140.0
modernc.org/sqlite v1.53.0
)
@@ -586,10 +586,10 @@ require (
gopkg.in/inf.v0 v0.9.1 // indirect
gopkg.in/warnings.v0 v0.1.2 // indirect
howett.net/plist v1.0.1 // indirect
- k8s.io/apiextensions-apiserver v0.36.2 // indirect
- k8s.io/apiserver v0.36.2 // indirect
- k8s.io/cli-runtime v0.36.2 // indirect
- k8s.io/component-base v0.36.2 // indirect
+ k8s.io/apiextensions-apiserver v0.36.3 // indirect
+ k8s.io/apiserver v0.36.3 // indirect
+ k8s.io/cli-runtime v0.36.3 // indirect
+ k8s.io/component-base v0.36.3 // indirect
k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad // indirect
k8s.io/kubectl v0.36.2 // indirect
k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 // indirect
diff --git a/go.sum b/go.sum
index 84fe4c6286..c7a47a8e70 100644
--- a/go.sum
+++ b/go.sum
@@ -1757,20 +1757,20 @@ honnef.co/go/tools v0.0.0-20190102054323-c2f93a96b099/go.mod h1:rf3lG4BRIbNafJWh
honnef.co/go/tools v0.0.0-20190523083050-ea95bdfd59fc/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4=
howett.net/plist v1.0.1 h1:37GdZ8tP09Q35o9ych3ehygcsL+HqKSwzctveSlarvM=
howett.net/plist v1.0.1/go.mod h1:lqaXoTrLY4hg8tnEzNru53gicrbv7rrk+2xJA/7hw9g=
-k8s.io/api v0.36.2 h1:TF6YDLIzKfccK7cq9YpTcGX8TJmEkHVRv78DM51fRYY=
-k8s.io/api v0.36.2/go.mod h1:F4LbMO4brjZYh7yFkXWhynSvtB7YauxV4c+HHkNRGNg=
-k8s.io/apiextensions-apiserver v0.36.2 h1:3O5gqOj/dt2XWWbpMe+TXWpE9yU6pjM/tXxtHHJT/K4=
-k8s.io/apiextensions-apiserver v0.36.2/go.mod h1:cL1tBWe8XSaP1H30iWKGo7hf6iAUUUJPEU70dskmAnA=
-k8s.io/apimachinery v0.36.2 h1:0PE/W/WNy1UX61NLbXY5TMbJ6UwLL6E6lAPkYrKFxbQ=
-k8s.io/apimachinery v0.36.2/go.mod h1:fvf/HOLXq9RId0rnDIbN1OEBvHXdQbLMM8nu0LcBUf4=
-k8s.io/apiserver v0.36.2 h1:6vMnkmHZPeBloNkHUhmZYq7Ylv8WIB8xjyEl+eSt26E=
-k8s.io/apiserver v0.36.2/go.mod h1:9PoQ2ikCytrZyZg11mGhLEF5m8Rgsb5FJmYJ4Wvnl1k=
-k8s.io/cli-runtime v0.36.2 h1:CconTvEeV4DJs4ZX3HQKCFbFRGsm6OtuBM9yjmMP2VM=
-k8s.io/cli-runtime v0.36.2/go.mod h1:LddcjiMf4YlnHO7c1Y7rEtDqL84FyiYVLco7V679GUU=
-k8s.io/client-go v0.36.2 h1:bfgxmFKc9CgqsgX4xKLAAdmTQlWee7Ob/HlDOrJ5TBI=
-k8s.io/client-go v0.36.2/go.mod h1:1vgO4OAlfPnoLcb+Rze2GF5rAr14w8qjrYMoyXJzQj0=
-k8s.io/component-base v0.36.2 h1:Z0VH80O7Ng0HDZnZj3WRR3urEGa0kTwmO8CwEwjVK1w=
-k8s.io/component-base v0.36.2/go.mod h1:mGfFOA7Gwpdm1VW2cwSQYbiDIlz8GD2WGwH88QSeCyA=
+k8s.io/api v0.36.3 h1:NxB+05W2UGqXWFXcLO0RB5cnqnUPP5v5sVlaOH0Iz4w=
+k8s.io/api v0.36.3/go.mod h1:JzLQKqRHC5+I8RVj/lS3lCg0mg6nWI9Fo/Sk3ElxHzg=
+k8s.io/apiextensions-apiserver v0.36.3 h1:dPmOAPhwTtqb1bTxbFPsy18KHPhktQeO3WUPXunZIB0=
+k8s.io/apiextensions-apiserver v0.36.3/go.mod h1:KTXFqgXiuw2pRoL+Wpmttqc+up9Xt/GohadPWeLLOa4=
+k8s.io/apimachinery v0.36.3 h1:PkzMRBRG8joFD8EhCuQAtNPvJlxb82FwplP26HIzvAM=
+k8s.io/apimachinery v0.36.3/go.mod h1:cTSjBWgPe/6CQyBKzY/hDIRWCQQQeK0mfLbml0UYFHE=
+k8s.io/apiserver v0.36.3 h1:MGSg2SkdfuytiDEcRylT5mQFmmSsbx90XFUO67Y4bsQ=
+k8s.io/apiserver v0.36.3/go.mod h1:fVH7zv9EUNUA7Fl7LtDKh8aB9W7u1VQPSGtWV5SjUxg=
+k8s.io/cli-runtime v0.36.3 h1:g+eJ+M1sYpnNYp/q5fzaw2KejIL0Q7DH+xFl6YVoL4U=
+k8s.io/cli-runtime v0.36.3/go.mod h1:hZpAqK8nSFXvvLaVCbzUPVp8e9TRLSTCfpNzMt7s3tE=
+k8s.io/client-go v0.36.3 h1:M4JdVzXxYcZk4fGpfDdYnxSwhLKWCFoQsHW6t+z8Hfg=
+k8s.io/client-go v0.36.3/go.mod h1:gcPwr0c87vjjG6HB6pWEqOeuYVoXSsREjzux2j6GF30=
+k8s.io/component-base v0.36.3 h1:vc/UFvPCkW0irPz84LAodAL1j3f4xktPM6dDJIEheAY=
+k8s.io/component-base v0.36.3/go.mod h1:hZbNFG+gCMl9EbykDGEu73feKP9/Cq6JsV4pTo9GTO8=
k8s.io/klog/v2 v2.140.0 h1:Tf+J3AH7xnUzZyVVXhTgGhEKnFqye14aadWv7bzXdzc=
k8s.io/klog/v2 v2.140.0/go.mod h1:o+/RWfJ6PwpnFn7OyAG3QnO47BFsymfEfrz6XyYSSp0=
k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad h1:oXImqH8mQNk7PmvzKhmN3ddJoY6OnyM225MXwGHPm0A=
From 8c95b3a85da44602aa6e1da2e7946b4ffd0d8383 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 23:40:20 +0000
Subject: [PATCH 25/70] chore(deps): update module
github.com/bitfield/gotestdox to v0.2.3 (9.5) (#7766)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/bitfield/gotestdox](https://redirect.github.com/bitfield/gotestdox)
| `v0.2.2` → `v0.2.3` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
bitfield/gotestdox (github.com/bitfield/gotestdox)
###
[`v0.2.3`](https://redirect.github.com/bitfield/gotestdox/compare/v0.2.2...v0.2.3)
[Compare
Source](https://redirect.github.com/bitfield/gotestdox/compare/v0.2.2...v0.2.3)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 11ed030005..f8c201980c 100644
--- a/go.mod
+++ b/go.mod
@@ -146,7 +146,7 @@ require (
github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery v1.12.6 // indirect
github.com/aws/aws-sdk-go-v2/service/signin v1.2.0 // indirect
github.com/aws/aws-sdk-go-v2/service/sqs v1.44.0 // indirect
- github.com/bitfield/gotestdox v0.2.2 // indirect
+ github.com/bitfield/gotestdox v0.2.3 // indirect
github.com/bitnami/go-version v0.0.0-20260728133343-2aa268af0217 // indirect
github.com/blakesmith/ar v0.0.0-20190502131153-809d4375e1fb // indirect
github.com/blang/semver v3.5.1+incompatible // indirect
diff --git a/go.sum b/go.sum
index c7a47a8e70..b6e2b7a3e2 100644
--- a/go.sum
+++ b/go.sum
@@ -307,8 +307,8 @@ github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM=
github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6rlkpw=
github.com/bgentry/go-netrc v0.0.0-20140422174119-9fd32a8b3d3d h1:xDfNPAt8lFiC1UJrqV3uuy861HCTo708pDMbjHHdCas=
github.com/bgentry/go-netrc v0.0.0-20140422174119-9fd32a8b3d3d/go.mod h1:6QX/PXZ00z/TKoufEY6K/a0k6AhaJrQKdFe6OfVXsa4=
-github.com/bitfield/gotestdox v0.2.2 h1:x6RcPAbBbErKLnapz1QeAlf3ospg8efBsedU93CDsnE=
-github.com/bitfield/gotestdox v0.2.2/go.mod h1:D+gwtS0urjBrzguAkTM2wodsTQYFHdpx8eqRJ3N+9pY=
+github.com/bitfield/gotestdox v0.2.3 h1:H8Wy07kYacr3YSF5aJON/m9ASE+PGKOSufXkTjqQGb8=
+github.com/bitfield/gotestdox v0.2.3/go.mod h1:bq/HemlNNqEvjOzy7brevVhzZD8WTGFDGq59DOIsHqI=
github.com/bitnami/go-version v0.0.0-20260728133343-2aa268af0217 h1:nF+AjKjJXxD5f3v5peVWQQG0cDQxD5i1ATzSel+bA6E=
github.com/bitnami/go-version v0.0.0-20260728133343-2aa268af0217/go.mod h1:9iglf1GG4oNRJ39bZ5AZrjgAFD2RwQbXw6Qf7Cs47wo=
github.com/blakesmith/ar v0.0.0-20190502131153-809d4375e1fb h1:m935MPodAbYS46DG4pJSv7WO+VECIWUQ7OJYSoTrMh4=
From c4cdeb5afa9c2b1b9e9ca8c201951da2d3df62c4 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 23:40:54 +0000
Subject: [PATCH 26/70] chore(deps): update module github.com/cloudflare/circl
to v1.6.5 (9.5) (#7767)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/cloudflare/circl](https://redirect.github.com/cloudflare/circl)
| `v1.6.4` → `v1.6.5` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
cloudflare/circl (github.com/cloudflare/circl)
###
[`v1.6.5`](https://redirect.github.com/cloudflare/circl/releases/tag/v1.6.5):
CIRCL v1.6.5
[Compare
Source](https://redirect.github.com/cloudflare/circl/compare/v1.6.4...v1.6.5)
#### What's Changed
- ascon: don't output plaintext if authentication fails by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#631](https://redirect.github.com/cloudflare/circl/pull/631)
- Dilithium: don't accept signatures with trailing data by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#632](https://redirect.github.com/cloudflare/circl/pull/632)
- Fix HPKE/KEM exact-length key unmarshaling by
[@drmikecrypto](https://redirect.github.com/drmikecrypto) in
[#627](https://redirect.github.com/cloudflare/circl/pull/627)
- Bump x/crypto and golangci-lint by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#637](https://redirect.github.com/cloudflare/circl/pull/637)
- ecc/bls12381: reject trailing data in G1/G2 SetBytes by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#636](https://redirect.github.com/cloudflare/circl/pull/636)
- eddilithium: fail verification if signature is wrong length by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#633](https://redirect.github.com/cloudflare/circl/pull/633)
- tss/rsa: fix length check to prevent runtime out-of-bounds panic by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#640](https://redirect.github.com/cloudflare/circl/pull/640)
- dleq: verify: return false instead of panic()ing on nil parameters by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#641](https://redirect.github.com/cloudflare/circl/pull/641)
- ed448: document verification behaviour by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#642](https://redirect.github.com/cloudflare/circl/pull/642)
- ed448: reject non-canonical point encodings by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#635](https://redirect.github.com/cloudflare/circl/pull/635)
- slhdsa: ensure full reads when rand source is provided by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#634](https://redirect.github.com/cloudflare/circl/pull/634)
- ed{25519,448}: don't accept trailing data for keys by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#643](https://redirect.github.com/cloudflare/circl/pull/643)
- frodo: pack: fix accidental zero buffer assumption by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#645](https://redirect.github.com/cloudflare/circl/pull/645)
- secretsharing: check that share ID is not zero. by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#644](https://redirect.github.com/cloudflare/circl/pull/644)
- kyber: document pk isn't checked like ML-KEM by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#648](https://redirect.github.com/cloudflare/circl/pull/648)
- zk/dleq: Don't accept trailing data on proof by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#649](https://redirect.github.com/cloudflare/circl/pull/649)
- slhdsa: don't panic if prehash-hash is out of range by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#647](https://redirect.github.com/cloudflare/circl/pull/647)
- goldilocks: don't panic when unmarshalling invalid point by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#646](https://redirect.github.com/cloudflare/circl/pull/646)
- hpke: don't panic when unmarshalling opener/sealer from empty buffer
by [@bwesterb](https://redirect.github.com/bwesterb) in
[#656](https://redirect.github.com/cloudflare/circl/pull/656)
- ot/simot: don't panic on mismatched ciphertext lengths by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#655](https://redirect.github.com/cloudflare/circl/pull/655)
- fourq: document point decoding is lenient by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#654](https://redirect.github.com/cloudflare/circl/pull/654)
- oprf: add note on multiple Point encodings by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#653](https://redirect.github.com/cloudflare/circl/pull/653)
- tss/rsa: don't panic when combining empty list of shares by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#652](https://redirect.github.com/cloudflare/circl/pull/652)
- ecc/p384: document that package is not fully constant time by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#651](https://redirect.github.com/cloudflare/circl/pull/651)
- ristretto: reject non-canonical scalars by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#650](https://redirect.github.com/cloudflare/circl/pull/650)
- Add more explicit constant time warnings by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#638](https://redirect.github.com/cloudflare/circl/pull/638)
- mlsbset: make Encode() constant time by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#639](https://redirect.github.com/cloudflare/circl/pull/639)
- mlsbset: fix stray index in Encode comment by
[@lukevalenta](https://redirect.github.com/lukevalenta) in
[#658](https://redirect.github.com/cloudflare/circl/pull/658)
- removeLen32Prefixed: check for possible data overflow by
[@mdosch](https://redirect.github.com/mdosch) in
[#629](https://redirect.github.com/cloudflare/circl/pull/629)
- expander: panic if requested output length overflows DST. by
[@cjpatton](https://redirect.github.com/cjpatton) in
[#664](https://redirect.github.com/cloudflare/circl/pull/664)
- zk/dleq: add base point `a` to challenge derivation. by
[@cjpatton](https://redirect.github.com/cjpatton) in
[#663](https://redirect.github.com/cloudflare/circl/pull/663)
- dh/sidh: document Import() side-effect for kem/sike. by
[@cjpatton](https://redirect.github.com/cjpatton) in
[#662](https://redirect.github.com/cloudflare/circl/pull/662)
- ecc/fourq: improve constant-timeness of fpSgn, fqSqrt. by
[@cjpatton](https://redirect.github.com/cjpatton) in
[#666](https://redirect.github.com/cloudflare/circl/pull/666)
- blinsign/blindrsa/partiallyblindrsa: reject malformed moduli. by
[@cjpatton](https://redirect.github.com/cjpatton) in
[#665](https://redirect.github.com/cloudflare/circl/pull/665)
- blindsign/blindrsa: align PSSZERO behavior with RFC 9474. by
[@cjpatton](https://redirect.github.com/cjpatton) in
[#660](https://redirect.github.com/cloudflare/circl/pull/660)
- ecc/fourq: fix fqSqr arithmetic error on amd64 by
[@cjpatton](https://redirect.github.com/cjpatton) in
[#659](https://redirect.github.com/cloudflare/circl/pull/659)
- README: warn that not all packages are constant time by
[@frangelbarrera](https://redirect.github.com/frangelbarrera) in
[#668](https://redirect.github.com/cloudflare/circl/pull/668)
- internal/test: unify ACVP test vector parsing by
[@ihopenre-eng](https://redirect.github.com/ihopenre-eng) in
[#667](https://redirect.github.com/cloudflare/circl/pull/667)
- blindrsa: fix interface documentation by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#672](https://redirect.github.com/cloudflare/circl/pull/672)
- ecc/fourq: fix legacy (non-BMI2) GF(p^2) multiplication on amd64 by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#669](https://redirect.github.com/cloudflare/circl/pull/669)
- p384: document assumed reductions by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#670](https://redirect.github.com/cloudflare/circl/pull/670)
-
[`ed25519`](https://redirect.github.com/cloudflare/circl/commit/ed25519):
document another divergence with crypto/ed25519 by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#671](https://redirect.github.com/cloudflare/circl/pull/671)
- prio3/histogram: don't panic on measurement equal to the bucket count
by [@bwesterb](https://redirect.github.com/bwesterb) in
[#673](https://redirect.github.com/cloudflare/circl/pull/673)
- zk/qndleq: document Qn membership precondition by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#675](https://redirect.github.com/cloudflare/circl/pull/675)
- vdaf/prio3: require all prep shares by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#676](https://redirect.github.com/cloudflare/circl/pull/676)
- vdaf/prio3: document prep sequencing requirement by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#677](https://redirect.github.com/cloudflare/circl/pull/677)
- zk/dl: reject identity proof inputs by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#678](https://redirect.github.com/cloudflare/circl/pull/678)
- tss/rsa: document trusted modulus requirement by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#680](https://redirect.github.com/cloudflare/circl/pull/680)
- dh/csidh: harden key imports by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#689](https://redirect.github.com/cloudflare/circl/pull/689)
- zk/dleq: validate batch shape by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#684](https://redirect.github.com/cloudflare/circl/pull/684)
- ot/simot: make sender sessions one-shot by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#679](https://redirect.github.com/cloudflare/circl/pull/679)
- vdaf/prio3/sum: reject unsafe measurement bounds by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#682](https://redirect.github.com/cloudflare/circl/pull/682)
- tss/rsa: validate sign share protocol parameters by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#674](https://redirect.github.com/cloudflare/circl/pull/674)
- vdaf/prio3/sum: reject aggregate field overflow by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#681](https://redirect.github.com/cloudflare/circl/pull/681)
- vdaf/prio3: validate preparation inputs by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#683](https://redirect.github.com/cloudflare/circl/pull/683)
- oprf: reject invalid deterministic blinds by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#688](https://redirect.github.com/cloudflare/circl/pull/688)
- vdaf/prio3: reject degenerate parameters by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#685](https://redirect.github.com/cloudflare/circl/pull/685)
- oprf: validate finalize state by
[@bwesterb](https://redirect.github.com/bwesterb) in
[#687](https://redirect.github.com/cloudflare/circl/pull/687)
#### New Contributors
- [@drmikecrypto](https://redirect.github.com/drmikecrypto) made
their first contribution in
[#627](https://redirect.github.com/cloudflare/circl/pull/627)
- [@lukevalenta](https://redirect.github.com/lukevalenta) made
their first contribution in
[#658](https://redirect.github.com/cloudflare/circl/pull/658)
- [@mdosch](https://redirect.github.com/mdosch) made their first
contribution in
[#629](https://redirect.github.com/cloudflare/circl/pull/629)
- [@frangelbarrera](https://redirect.github.com/frangelbarrera)
made their first contribution in
[#668](https://redirect.github.com/cloudflare/circl/pull/668)
- [@ihopenre-eng](https://redirect.github.com/ihopenre-eng) made
their first contribution in
[#667](https://redirect.github.com/cloudflare/circl/pull/667)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 10 +++++-----
go.sum | 20 ++++++++++----------
2 files changed, 15 insertions(+), 15 deletions(-)
diff --git a/go.mod b/go.mod
index f8c201980c..6d19abd8bc 100644
--- a/go.mod
+++ b/go.mod
@@ -383,7 +383,7 @@ require (
github.com/cespare/xxhash/v2 v2.3.0 // indirect
github.com/chai2010/gettext-go v1.0.3 // indirect
github.com/cheggaaa/pb/v3 v3.1.7 // indirect
- github.com/cloudflare/circl v1.6.4 // indirect
+ github.com/cloudflare/circl v1.6.5 // indirect
github.com/containerd/continuity v0.5.0 // indirect
github.com/containerd/fifo v1.1.0 // indirect
github.com/containerd/ttrpc v1.2.9 // indirect
@@ -569,13 +569,13 @@ require (
go.etcd.io/bbolt v1.5.0 // indirect
go.opencensus.io v0.24.0 // indirect
go.uber.org/multierr v1.11.0 // indirect
- golang.org/x/crypto v0.53.0 // indirect
+ golang.org/x/crypto v0.54.0 // indirect
golang.org/x/mod v0.37.0 // indirect
golang.org/x/net v0.56.0 // indirect
golang.org/x/sync v0.22.0
- golang.org/x/sys v0.46.0 // indirect
- golang.org/x/term v0.44.0 // indirect
- golang.org/x/text v0.39.0 // indirect
+ golang.org/x/sys v0.47.0 // indirect
+ golang.org/x/term v0.45.0 // indirect
+ golang.org/x/text v0.40.0 // indirect
golang.org/x/time v0.15.0
golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
google.golang.org/genproto v0.0.0-20260706201446-f0a921348800 // indirect
diff --git a/go.sum b/go.sum
index b6e2b7a3e2..e93a67afad 100644
--- a/go.sum
+++ b/go.sum
@@ -352,8 +352,8 @@ github.com/cilium/ebpf v0.21.0/go.mod h1:1kHKv6Kvh5a6TePP5vvvoMa1bclRyzUXELSs272
github.com/client9/misspell v0.3.4/go.mod h1:qj6jICC3Q7zFZvVWo7KLAzC3yx5G7kyvSDkc90ppPyw=
github.com/clipperhouse/uax29/v2 v2.7.0 h1:+gs4oBZ2gPfVrKPthwbMzWZDaAFPGYK72F0NJv2v7Vk=
github.com/clipperhouse/uax29/v2 v2.7.0/go.mod h1:EFJ2TJMRUaplDxHKj1qAEhCtQPW2tJSwu5BF98AuoVM=
-github.com/cloudflare/circl v1.6.4 h1:pOXuDTCEYyzydgUpQ0CQz3LsinKjiSk6nNP5Lt5K64U=
-github.com/cloudflare/circl v1.6.4/go.mod h1:YxarevkLlbaHuWsxG6vmYNWBEsSp4pnp7j+4VljMavY=
+github.com/cloudflare/circl v1.6.5 h1:O64F26HEqNhznd/hrC5KZXVKYuKM2rx4deZDTc4ihQA=
+github.com/cloudflare/circl v1.6.5/go.mod h1:h5LNyxAc5nTue9DS5jT+48en2PSDYt3zdGnz5OstK6c=
github.com/cncf/udpa/go v0.0.0-20191209042840-269d4d468f6f/go.mod h1:M8M6+tZqaGXZJjfX53e64911xZQV5JYwmTeXPW+k8Sc=
github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2 h1:aBangftG7EVZoUb69Os8IaYg++6uMOdKK83QtkkvJik=
github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2/go.mod h1:qwXFYgsP6T7XnJtbKlf1HP8AjxZZyzxMmc+Lq5GjlU4=
@@ -1571,8 +1571,8 @@ golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPh
golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc=
golang.org/x/crypto v0.0.0-20220622213112-05595931fe9d/go.mod h1:IxCIyHEi3zRg3s0A5j5BB6A9Jmi73HwBIUl50j+osU4=
golang.org/x/crypto v0.6.0/go.mod h1:OFC/31mSvZgRz0V1QTNCzfAI1aIRzbiufJtkMIlEp58=
-golang.org/x/crypto v0.53.0 h1:QZ4Muo8THX6CizN2vPPd5fBGHyogrdK9fG4wLPFUsto=
-golang.org/x/crypto v0.53.0/go.mod h1:DNLU434OwVakk9PzuwV8w62mAJpRJL3vsgcfp4Qnsio=
+golang.org/x/crypto v0.54.0 h1:YLIA59K4fiNzHzjnZt2tUJQjQtUWfWbeHBqKtk3eScw=
+golang.org/x/crypto v0.54.0/go.mod h1:KWL8ny2AZdGR2cWmzeHrp2azQPGogOv+HeQaVEXC2dk=
golang.org/x/exp v0.0.0-20190121172915-509febef88a4/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA=
golang.org/x/exp v0.0.0-20260410095643-746e56fc9e2f h1:W3F4c+6OLc6H2lb//N1q4WpJkhzJCK5J6kUi1NTVXfM=
golang.org/x/exp v0.0.0-20260410095643-746e56fc9e2f/go.mod h1:J1xhfL/vlindoeF/aINzNzt2Bket5bjo9sdOYzOsU80=
@@ -1646,13 +1646,13 @@ golang.org/x/sys v0.0.0-20220715151400-c0bba94af5f8/go.mod h1:oPkhp1MJrh7nUepCBc
golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.1.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
-golang.org/x/sys v0.46.0 h1:noSf2Fq6F8DBgS+LysIkx7rIExoNHJsxOAtPp4rthXw=
-golang.org/x/sys v0.46.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
+golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
+golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8=
golang.org/x/term v0.5.0/go.mod h1:jMB1sMXY+tzblOD4FWmEbocvup2/aLOaQEp7JmGp78k=
-golang.org/x/term v0.44.0 h1:0rLvDRCtNj0gZkyIXhCyOb2OAzEhLVqc4B+hrsBhrmc=
-golang.org/x/term v0.44.0/go.mod h1:7ze4MdzUzLXpSAoFP1H0bOI9aXDqveSvatT5vKcFh2Y=
+golang.org/x/term v0.45.0 h1:NwWyBmoJCbfTHpxrWoZ9C6/VxOf7ic219I8xZZFdrf0=
+golang.org/x/term v0.45.0/go.mod h1:9aqxs0blBcrm/n0L9QW0aRVD+ktan8ssZromtqJC43w=
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
golang.org/x/text v0.3.2/go.mod h1:bEr9sfX3Q8Zfm5fL9x+3itogRgK3+ptLWKqgva+5dAk=
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
@@ -1661,8 +1661,8 @@ golang.org/x/text v0.3.6/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ=
golang.org/x/text v0.3.8/go.mod h1:E6s5w1FMmriuDzIBO73fBruAKo1PCIq6d2Q6DHfQ8WQ=
golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8=
-golang.org/x/text v0.39.0 h1:UbZz4pLOvn600D6Oh6GGEI6VAmndrEBLv8/6BEXzyus=
-golang.org/x/text v0.39.0/go.mod h1:3UwRclnC2g0TU9x8PZiyfOajCd1zaUNHF9cvqcQZ+ZM=
+golang.org/x/text v0.40.0 h1:Ub2Z6/xjgF1WrYQz2nuITOEegKFtiIy+rieRJ5lHZKs=
+golang.org/x/text v0.40.0/go.mod h1:hpnzDAfGV753zIKo+wk3u1bVKCGPbrnF7+7LBF/UHVY=
golang.org/x/time v0.15.0 h1:bbrp8t3bGUeFOx08pvsMYRTCVSMk89u4tKbNOZbp88U=
golang.org/x/time v0.15.0/go.mod h1:Y4YMaQmXwGQZoFaVFk4YpCt4FLQMYKZe9oeV/f4MSno=
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
From 6e23d233cdbebc1de71e53e8011a8fdd0de9f74c Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 23:41:49 +0000
Subject: [PATCH 27/70] chore(deps): update module
github.com/klauspost/compress to v1.19.2 (9.5) (#7776)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/klauspost/compress](https://redirect.github.com/klauspost/compress)
| `v1.19.0` → `v1.19.2` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
klauspost/compress (github.com/klauspost/compress)
###
[`v1.19.2`](https://redirect.github.com/klauspost/compress/releases/tag/v1.19.2)
[Compare
Source](https://redirect.github.com/klauspost/compress/compare/v1.19.1...v1.19.2)
#### What's Changed
- huff0: add arm64 assembly for Decompress4X/1X via avo lowering by
[@lizthegrey](https://redirect.github.com/lizthegrey) in
[#1172](https://redirect.github.com/klauspost/compress/pull/1172)
- zstd: Re-enable unsafe decodeSync memory copies
([#1168](https://redirect.github.com/klauspost/compress/issues/1168))
by [@lizthegrey](https://redirect.github.com/lizthegrey) in
[#1171](https://redirect.github.com/klauspost/compress/pull/1171)
- zstd: fix arm64 asm frame offsets placing locals on the saved LR slot
by [@lizthegrey](https://redirect.github.com/lizthegrey) in
[#1176](https://redirect.github.com/klauspost/compress/pull/1176)
- zstd: avoid racing MaxDecodedSize write on shared dict litEnc by
[@zanarellidev](https://redirect.github.com/zanarellidev) in
[#1182](https://redirect.github.com/klauspost/compress/pull/1182)
- zstd: keep BuildDict recent-offsets positive and loadable by
[@zanarellidev](https://redirect.github.com/zanarellidev) in
[#1184](https://redirect.github.com/klauspost/compress/pull/1184)
- zstd: handle zero-literal BuildDict corpus by
[@cyphercodes](https://redirect.github.com/cyphercodes) in
[#1178](https://redirect.github.com/klauspost/compress/pull/1178)
- zstd: don't clear the registered dictionary when decoding past the
window by [@sueun-dev](https://redirect.github.com/sueun-dev) in
[#1177](https://redirect.github.com/klauspost/compress/pull/1177)
#### New Contributors
- [@zanarellidev](https://redirect.github.com/zanarellidev) made
their first contribution in
[#1183](https://redirect.github.com/klauspost/compress/pull/1183)
- [@cyphercodes](https://redirect.github.com/cyphercodes) made
their first contribution in
[#1178](https://redirect.github.com/klauspost/compress/pull/1178)
- [@sueun-dev](https://redirect.github.com/sueun-dev) made their
first contribution in
[#1177](https://redirect.github.com/klauspost/compress/pull/1177)
**Full Changelog**:
###
[`v1.19.1`](https://redirect.github.com/klauspost/compress/releases/tag/v1.19.1)
[Compare
Source](https://redirect.github.com/klauspost/compress/compare/v1.19.0...v1.19.1)
#### What's Changed
- zstd: Validate SnappyConverter literal copies by
[@klauspost](https://redirect.github.com/klauspost) in
[#1170](https://redirect.github.com/klauspost/compress/pull/1170)
- flate: use `Peek` instead of `ReadByte` for the `bufio.Reader` decode
path by [@joechenrh](https://redirect.github.com/joechenrh) in
[#1169](https://redirect.github.com/klauspost/compress/pull/1169)
- zstd: bump avo pin, regenerate arm64 asm by
[@lizthegrey](https://redirect.github.com/lizthegrey) in
[#1167](https://redirect.github.com/klauspost/compress/pull/1167)
#### New Contributors
- [@joechenrh](https://redirect.github.com/joechenrh) made their
first contribution in
[#1169](https://redirect.github.com/klauspost/compress/pull/1169)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 6d19abd8bc..f929eebfcf 100644
--- a/go.mod
+++ b/go.mod
@@ -473,7 +473,7 @@ require (
github.com/josephspurrier/goversioninfo v1.7.0 // indirect
github.com/json-iterator/go v1.1.12 // indirect
github.com/kevinburke/ssh_config v1.6.0 // indirect
- github.com/klauspost/compress v1.19.0 // indirect
+ github.com/klauspost/compress v1.19.2 // indirect
github.com/knqyf263/go-apk-version v0.0.0-20200609155635-041fdbb8563f // indirect
github.com/knqyf263/go-deb-version v0.0.0-20241115132648-6f4aee6ccd23 // indirect
github.com/knqyf263/go-rpm-version v0.0.0-20240918084003-2afd7dc6a38f // indirect
diff --git a/go.sum b/go.sum
index e93a67afad..7d63b271de 100644
--- a/go.sum
+++ b/go.sum
@@ -898,8 +898,8 @@ github.com/kevinburke/ssh_config v1.6.0 h1:J1FBfmuVosPHf5GRdltRLhPJtJpTlMdKTBjRg
github.com/kevinburke/ssh_config v1.6.0/go.mod h1:q2RIzfka+BXARoNexmF9gkxEX7DmvbW9P4hIVx2Kg4M=
github.com/keybase/go-keychain v0.0.1 h1:way+bWYa6lDppZoZcgMbYsvC7GxljxrskdNInRtuthU=
github.com/keybase/go-keychain v0.0.1/go.mod h1:PdEILRW3i9D8JcdM+FmY6RwkHGnhHxXwkPPMeUgOK1k=
-github.com/klauspost/compress v1.19.0 h1:sXLILfc9jV2QYWkzFOPWStmcUVH2RHEB1JCdY2oVvCQ=
-github.com/klauspost/compress v1.19.0/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ=
+github.com/klauspost/compress v1.19.2 h1:hMRETovs/pu/dVWN7zIT1PGG8t509MwT6bO7XSi26R8=
+github.com/klauspost/compress v1.19.2/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ=
github.com/klauspost/cpuid/v2 v2.4.0 h1:S6Hrbc7+ywsr0r+RLapfGBHfyefhCTwEh3A0tV913Dw=
github.com/klauspost/cpuid/v2 v2.4.0/go.mod h1:19jmZ9mjzoF//ddRSUsv0zfBTJWh3QJh9FNxZTMrGxU=
github.com/knadh/koanf/maps v0.1.2 h1:RBfmAW5CnZT+PJ1CVc1QSJKf4Xu9kxfQgYVQSu8hpbo=
From 62c16b6cb06876b54750963e42ec11b36fcdccd9 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 23:42:51 +0000
Subject: [PATCH 28/70] chore(deps): update module github.com/mattn/go-isatty
to v0.0.24 (9.5) (#7779)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/mattn/go-isatty](https://redirect.github.com/mattn/go-isatty)
| `v0.0.22` → `v0.0.24` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
mattn/go-isatty (github.com/mattn/go-isatty)
###
[`v0.0.24`](https://redirect.github.com/mattn/go-isatty/compare/v0.0.23...v0.0.24)
[Compare
Source](https://redirect.github.com/mattn/go-isatty/compare/v0.0.23...v0.0.24)
###
[`v0.0.23`](https://redirect.github.com/mattn/go-isatty/compare/v0.0.22...v0.0.23)
[Compare
Source](https://redirect.github.com/mattn/go-isatty/compare/v0.0.22...v0.0.23)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index f929eebfcf..c776730fae 100644
--- a/go.mod
+++ b/go.mod
@@ -493,7 +493,7 @@ require (
github.com/masahiro331/go-mvn-version v0.0.0-20260119054159-d21fcd2e7de1 // indirect
github.com/masahiro331/go-vmdk-parser v0.0.0-20260425175348-040a3994f0b4 // indirect
github.com/mattn/go-colorable v0.1.15 // indirect
- github.com/mattn/go-isatty v0.0.22 // indirect
+ github.com/mattn/go-isatty v0.0.24 // indirect
github.com/mattn/go-runewidth v0.0.24 // indirect
github.com/miekg/dns v1.1.72 // indirect
github.com/mitchellh/copystructure v1.2.0 // indirect
diff --git a/go.sum b/go.sum
index 7d63b271de..615683389c 100644
--- a/go.sum
+++ b/go.sum
@@ -976,8 +976,8 @@ github.com/masahiro331/go-xfs-filesystem v0.0.0-20260422061116-d21e5e4481bb h1:2
github.com/masahiro331/go-xfs-filesystem v0.0.0-20260422061116-d21e5e4481bb/go.mod h1:QKBZqdn6teT0LK3QhAf3K6xakItd1LonOShOEC44idQ=
github.com/mattn/go-colorable v0.1.15 h1:+u9SLTRGnXv73cEsnsmoZBom+dMU88B2M0aDcWy0/jY=
github.com/mattn/go-colorable v0.1.15/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8=
-github.com/mattn/go-isatty v0.0.22 h1:j8l17JJ9i6VGPUFUYoTUKPSgKe/83EYU2zBC7YNKMw4=
-github.com/mattn/go-isatty v0.0.22/go.mod h1:ZXfXG4SQHsB/w3ZeOYbR0PrPwLy+n6xiMrJlRFqopa4=
+github.com/mattn/go-isatty v0.0.24 h1:tGZZoVgT/KiqK1c8ocVLeDS8BSWMRd47J3Lbz7vsReI=
+github.com/mattn/go-isatty v0.0.24/go.mod h1:nMCL3Zebbrt45jsMDgnfIwz6ydEQApk5oEI3HqDio6A=
github.com/mattn/go-runewidth v0.0.24 h1:cpokDiIn0MGnhdHwuWnJBITySJ20QyNGnY2kR/ay2DU=
github.com/mattn/go-runewidth v0.0.24/go.mod h1:XBkDxAl56ILZc9knddidhrOlY5R/pDhgLpndooCuJAs=
github.com/mattn/go-shellwords v1.0.13 h1:DC0OMEpGjm6LfNFU4ckYcvbQKyp2vE8atyFGXNtDcf4=
From 11c782e2c38cde0bf5b03f7b6bc881e29082e7de Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 23:43:20 +0000
Subject: [PATCH 29/70] chore(deps): update module
github.com/knadh/koanf/providers/confmap to v1.0.1 (9.5) (#7777)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/knadh/koanf/providers/confmap](https://redirect.github.com/knadh/koanf)
| `v1.0.0` → `v1.0.1` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index c776730fae..1f32268d91 100644
--- a/go.mod
+++ b/go.mod
@@ -223,7 +223,7 @@ require (
github.com/josephburnett/jd/v2 v2.5.0 // indirect
github.com/klauspost/cpuid/v2 v2.4.0 // indirect
github.com/knadh/koanf/maps v0.1.2 // indirect
- github.com/knadh/koanf/providers/confmap v1.0.0 // indirect
+ github.com/knadh/koanf/providers/confmap v1.0.1 // indirect
github.com/knadh/koanf/v2 v2.3.5 // indirect
github.com/lestrrat-go/blackmagic v1.0.4 // indirect
github.com/lestrrat-go/dsig v1.3.0 // indirect
diff --git a/go.sum b/go.sum
index 615683389c..a14013c7e3 100644
--- a/go.sum
+++ b/go.sum
@@ -904,8 +904,8 @@ github.com/klauspost/cpuid/v2 v2.4.0 h1:S6Hrbc7+ywsr0r+RLapfGBHfyefhCTwEh3A0tV91
github.com/klauspost/cpuid/v2 v2.4.0/go.mod h1:19jmZ9mjzoF//ddRSUsv0zfBTJWh3QJh9FNxZTMrGxU=
github.com/knadh/koanf/maps v0.1.2 h1:RBfmAW5CnZT+PJ1CVc1QSJKf4Xu9kxfQgYVQSu8hpbo=
github.com/knadh/koanf/maps v0.1.2/go.mod h1:npD/QZY3V6ghQDdcQzl1W4ICNVTkohC8E73eI2xW4yI=
-github.com/knadh/koanf/providers/confmap v1.0.0 h1:mHKLJTE7iXEys6deO5p6olAiZdG5zwp8Aebir+/EaRE=
-github.com/knadh/koanf/providers/confmap v1.0.0/go.mod h1:txHYHiI2hAtF0/0sCmcuol4IDcuQbKTybiB1nOcUo1A=
+github.com/knadh/koanf/providers/confmap v1.0.1 h1:L15hbvMqlvhwUuCtL9BkL+rqiMAjk6cZc8O9XoDtE3A=
+github.com/knadh/koanf/providers/confmap v1.0.1/go.mod h1:txHYHiI2hAtF0/0sCmcuol4IDcuQbKTybiB1nOcUo1A=
github.com/knadh/koanf/v2 v2.3.5 h1:2dXJUYaKGm4SGYeoAtBviq9+02JZo/pxQ2ssOd60rJg=
github.com/knadh/koanf/v2 v2.3.5/go.mod h1:gRb40VRAbd4iJMYYD5IxZ6hfuopFcXBpc9bbQpZwo28=
github.com/knqyf263/go-apk-version v0.0.0-20200609155635-041fdbb8563f h1:GvCU5GXhHq+7LeOzx/haG7HSIZokl3/0GkoUFzsRJjg=
From f6fab5a1c2516e24ab4d11e095a8c89a89b7ccad Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 23:43:58 +0000
Subject: [PATCH 30/70] chore(deps): update module github.com/oklog/ulid/v2 to
v2.1.2 (9.5) (#7782)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/oklog/ulid/v2](https://redirect.github.com/oklog/ulid) |
`v2.1.1` → `v2.1.2` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
oklog/ulid (github.com/oklog/ulid/v2)
###
[`v2.1.2`](https://redirect.github.com/oklog/ulid/releases/tag/v2.1.2)
[Compare
Source](https://redirect.github.com/oklog/ulid/compare/v2.1.1...v2.1.2)
#### What's Changed
- fix: Scan accepts text-encoded ULIDs in \[]byte by
[@sonnemusk](https://redirect.github.com/sonnemusk) in
[#134](https://redirect.github.com/oklog/ulid/pull/134)
#### New Contributors
- [@sonnemusk](https://redirect.github.com/sonnemusk) made their
first contribution in
[#134](https://redirect.github.com/oklog/ulid/pull/134)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 1f32268d91..1035400e1a 100644
--- a/go.mod
+++ b/go.mod
@@ -250,7 +250,7 @@ require (
github.com/ncruces/go-strftime v1.0.0 // indirect
github.com/nikolalohinski/gonja/v2 v2.8.0 // indirect
github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481 // indirect
- github.com/oklog/ulid/v2 v2.1.1 // indirect
+ github.com/oklog/ulid/v2 v2.1.2 // indirect
github.com/openvex/discovery v0.1.1-0.20260629103619-4287cf7d3781 // indirect
github.com/owenrumney/go-sarif/v2 v2.3.3 // indirect
github.com/pandatix/go-cvss v0.6.2 // indirect
diff --git a/go.sum b/go.sum
index a14013c7e3..99813f9e34 100644
--- a/go.sum
+++ b/go.sum
@@ -1079,8 +1079,8 @@ github.com/nxadm/tail v1.4.4/go.mod h1:kenIhsEOeOJmVchQTgglprH7qJGnHDVpk1VPCcaMI
github.com/nxadm/tail v1.4.8/go.mod h1:+ncqLTQzXmGhMZNUePPaPqPvBxHAIsmXswZKocGu+AU=
github.com/nxadm/tail v1.4.11 h1:8feyoE3OzPrcshW5/MJ4sGESc5cqmGkGCWlco4l0bqY=
github.com/nxadm/tail v1.4.11/go.mod h1:OTaG3NK980DZzxbRq6lEuzgU+mug70nY11sMd4JXXHc=
-github.com/oklog/ulid/v2 v2.1.1 h1:suPZ4ARWLOJLegGFiZZ1dFAkqzhMjL3J1TzI+5wHz8s=
-github.com/oklog/ulid/v2 v2.1.1/go.mod h1:rcEKHmBBKfef9DhnvX7y1HZBYxjXb0cP5ExxNsTT1QQ=
+github.com/oklog/ulid/v2 v2.1.2 h1:IEclFb9JNvzYA6MW2SCxbLzcHTVsfqm3PrqGQJH5zec=
+github.com/oklog/ulid/v2 v2.1.2/go.mod h1:rcEKHmBBKfef9DhnvX7y1HZBYxjXb0cP5ExxNsTT1QQ=
github.com/onsi/ginkgo v1.6.0/go.mod h1:lLunBs/Ym6LB5Z9jYTR76FiuTmxDTDusOGeTQH+WWjE=
github.com/onsi/ginkgo v1.12.1/go.mod h1:zj2OWP4+oCPe1qIXoGWkgMRwljMUYCdkwsT2108oapk=
github.com/onsi/ginkgo v1.16.4/go.mod h1:dX+/inL/fNMqNlz0e9LfyB9TswhZpCVdJM/Z6Vvnwo0=
From 788ff6d9faac7f1693b1e90711c54766b5726129 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 23:44:56 +0000
Subject: [PATCH 31/70] chore(deps): update module
github.com/mattn/go-shellwords to v1.0.14 (9.5) (#7781)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/mattn/go-shellwords](https://redirect.github.com/mattn/go-shellwords)
| `v1.0.13` → `v1.0.14` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
mattn/go-shellwords (github.com/mattn/go-shellwords)
###
[`v1.0.14`](https://redirect.github.com/mattn/go-shellwords/compare/v1.0.13...v1.0.14)
[Compare
Source](https://redirect.github.com/mattn/go-shellwords/compare/v1.0.13...v1.0.14)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 1035400e1a..c17440c7ec 100644
--- a/go.mod
+++ b/go.mod
@@ -233,7 +233,7 @@ require (
github.com/lestrrat-go/jwx/v3 v3.1.1 // indirect
github.com/lestrrat-go/option/v2 v2.0.0 // indirect
github.com/letsencrypt/boulder v0.20260630.0 // indirect
- github.com/mattn/go-shellwords v1.0.13 // indirect
+ github.com/mattn/go-shellwords v1.0.14 // indirect
github.com/microsoft/kiota-authentication-azure-go v1.3.1 // indirect
github.com/microsoft/kiota-http-go v1.5.6 // indirect
github.com/microsoft/kiota-serialization-form-go v1.1.3 // indirect
diff --git a/go.sum b/go.sum
index 99813f9e34..0b26807714 100644
--- a/go.sum
+++ b/go.sum
@@ -980,8 +980,8 @@ github.com/mattn/go-isatty v0.0.24 h1:tGZZoVgT/KiqK1c8ocVLeDS8BSWMRd47J3Lbz7vsRe
github.com/mattn/go-isatty v0.0.24/go.mod h1:nMCL3Zebbrt45jsMDgnfIwz6ydEQApk5oEI3HqDio6A=
github.com/mattn/go-runewidth v0.0.24 h1:cpokDiIn0MGnhdHwuWnJBITySJ20QyNGnY2kR/ay2DU=
github.com/mattn/go-runewidth v0.0.24/go.mod h1:XBkDxAl56ILZc9knddidhrOlY5R/pDhgLpndooCuJAs=
-github.com/mattn/go-shellwords v1.0.13 h1:DC0OMEpGjm6LfNFU4ckYcvbQKyp2vE8atyFGXNtDcf4=
-github.com/mattn/go-shellwords v1.0.13/go.mod h1:EZzvwXDESEeg03EKmM+RmDnNOPKG4lLtQsUlTZDWQ8Y=
+github.com/mattn/go-shellwords v1.0.14 h1:yUKzIgsCnosndOASY6/enly1EAuaXeFSQ7cdyA3OuYg=
+github.com/mattn/go-shellwords v1.0.14/go.mod h1:EZzvwXDESEeg03EKmM+RmDnNOPKG4lLtQsUlTZDWQ8Y=
github.com/mattn/go-sqlite3 v1.14.22/go.mod h1:Uh1q+B4BYcTPb+yiD3kU8Ct7aC0hY9fxUwlHK0RXw+Y=
github.com/mattn/go-sqlite3 v1.14.32 h1:JD12Ag3oLy1zQA+BNn74xRgaBbdhbNIDYvQUEuuErjs=
github.com/mattn/go-sqlite3 v1.14.32/go.mod h1:Uh1q+B4BYcTPb+yiD3kU8Ct7aC0hY9fxUwlHK0RXw+Y=
From 036736e5dfbe22506bc75382efb60fab4fa3b92f Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 23:45:31 +0000
Subject: [PATCH 32/70] chore(deps): update module
github.com/shirou/gopsutil/v4 to v4.26.7 (9.5) (#7786)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/shirou/gopsutil/v4](https://redirect.github.com/shirou/gopsutil)
| `v4.26.6` → `v4.26.7` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
shirou/gopsutil (github.com/shirou/gopsutil/v4)
###
[`v4.26.7`](https://redirect.github.com/shirou/gopsutil/releases/tag/v4.26.7)
[Compare
Source](https://redirect.github.com/shirou/gopsutil/compare/v4.26.6...v4.26.7)
#### What's Changed
##### cpu
- fix: harden parsers against malformed/truncated input by
[@shirou](https://redirect.github.com/shirou) in
[#2109](https://redirect.github.com/shirou/gopsutil/pull/2109)
- \[cpu]\[windows]: compute cpu-total times from integer ticks by
[@skartikey](https://redirect.github.com/skartikey) in
[#2111](https://redirect.github.com/shirou/gopsutil/pull/2111)
- \[darwin]\[process]: fix errno handling and library lifetime on darwin
by [@shirou](https://redirect.github.com/shirou) in
[#2119](https://redirect.github.com/shirou/gopsutil/pull/2119)
- \[cpu]\[windows]: compute total counters from individual stats to
handle processor groups correctly by
[@srebhan](https://redirect.github.com/srebhan) in
[#2125](https://redirect.github.com/shirou/gopsutil/pull/2125)
- \[cpu]\[windows]: harden the cpu-total computation added in
[#2125](https://redirect.github.com/shirou/gopsutil/issues/2125)
by [@shirou](https://redirect.github.com/shirou) in
[#2128](https://redirect.github.com/shirou/gopsutil/pull/2128)
##### net
- fix(net): pad GetExtendedTcpTable buffer to prevent GC thrashing on
Windows by
[@HarshalPatel1972](https://redirect.github.com/HarshalPatel1972)
in [#2108](https://redirect.github.com/shirou/gopsutil/pull/2108)
##### process
- process: implement Darwin IOCounters via proc\_pid\_rusage by
[@DavRack](https://redirect.github.com/DavRack) in
[#2117](https://redirect.github.com/shirou/gopsutil/pull/2117)
##### other
- feat: add psutil comparison tests for cpu, mem and load by
[@shirou](https://redirect.github.com/shirou) in
[#2114](https://redirect.github.com/shirou/gopsutil/pull/2114)
#### New Contributors
- [@DavRack](https://redirect.github.com/DavRack) made their
first contribution in
[#2117](https://redirect.github.com/shirou/gopsutil/pull/2117)
- [@srebhan](https://redirect.github.com/srebhan) made their
first contribution in
[#2125](https://redirect.github.com/shirou/gopsutil/pull/2125)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index c17440c7ec..911167764b 100644
--- a/go.mod
+++ b/go.mod
@@ -264,7 +264,7 @@ require (
github.com/sassoftware/go-rpmutils v0.4.0 // indirect
github.com/sassoftware/relic v7.2.1+incompatible // indirect
github.com/segmentio/asm v1.2.1 // indirect
- github.com/shirou/gopsutil/v4 v4.26.6 // indirect
+ github.com/shirou/gopsutil/v4 v4.26.7 // indirect
github.com/sigstore/cosign/v2 v2.6.3 // indirect
github.com/sigstore/protobuf-specs v0.5.1 // indirect
github.com/sigstore/rekor-tiles/v2 v2.2.1 // indirect
diff --git a/go.sum b/go.sum
index 0b26807714..8fe94318c4 100644
--- a/go.sum
+++ b/go.sum
@@ -1205,8 +1205,8 @@ github.com/sergi/go-diff v1.4.0 h1:n/SP9D5ad1fORl+llWyN+D6qoUETXNZARKjyY2/KVCw=
github.com/sergi/go-diff v1.4.0/go.mod h1:A0bzQcvG0E7Rwjx0REVgAGH58e96+X0MeOfepqsbeW4=
github.com/shibumi/go-pathspec v1.3.0 h1:QUyMZhFo0Md5B8zV8x2tesohbb5kfbpTi9rBnKh5dkI=
github.com/shibumi/go-pathspec v1.3.0/go.mod h1:Xutfslp817l2I1cZvgcfeMQJG5QnU2lh5tVaaMCl3jE=
-github.com/shirou/gopsutil/v4 v4.26.6 h1:Mzr/npDtQC/xpeEuQKHZt8Zo9CmPvhTj8nkR8w5TLDs=
-github.com/shirou/gopsutil/v4 v4.26.6/go.mod h1:LZ6ewCSkBqUpvSOf+LsTGnRinC6iaNUNMGBtDkJBaLQ=
+github.com/shirou/gopsutil/v4 v4.26.7 h1:IXzpHz/dkMRYAhKkOXr1HB6SuzWU3eoyyeWe7g3bNZc=
+github.com/shirou/gopsutil/v4 v4.26.7/go.mod h1:5O9FjBiXoTDFatIWjZZosqj4pV0DRtLx598xGbBehzM=
github.com/shopspring/decimal v1.3.1/go.mod h1:DKyhrW/HYNuLGql+MJL6WCR6knT2jwCFRcu2hWCYk4o=
github.com/shopspring/decimal v1.4.0 h1:bxl37RwXBklmTi0C79JfXCEBD1cqqHt0bbgBAGFp81k=
github.com/shopspring/decimal v1.4.0/go.mod h1:gawqmDU56v4yIKSwfBSFip1HdCCXN8/+DMd9qYNcwME=
From 5dce82136627846e06a79ca781c56b3231fcdb6b Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 23:45:52 +0000
Subject: [PATCH 33/70] chore(deps): update module
github.com/santhosh-tekuri/jsonschema/v6 to v6.0.3 (9.5) (#7785)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/santhosh-tekuri/jsonschema/v6](https://redirect.github.com/santhosh-tekuri/jsonschema)
| `v6.0.2` → `v6.0.3` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
santhosh-tekuri/jsonschema
(github.com/santhosh-tekuri/jsonschema/v6)
###
[`v6.0.3`](https://redirect.github.com/santhosh-tekuri/jsonschema/releases/tag/v6.0.3)
[Compare
Source](https://redirect.github.com/santhosh-tekuri/jsonschema/compare/v6.0.2...v6.0.3)
#### bugfixes:
- empty instLocation for propetyNames and contentSchema
- fix intLocation for items and additionalItems validation
- check invalid floats NaN/Inf
- fix closing quote check in email validation
- ensure both are numbers in equals validation
#### features
-
[`ef59f39`](https://redirect.github.com/santhosh-tekuri/jsonschema/commit/ef59f39):
ref like property in custom vocab
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 911167764b..cc6a283805 100644
--- a/go.mod
+++ b/go.mod
@@ -260,7 +260,7 @@ require (
github.com/rust-secure-code/go-rustaudit v0.0.0-20250226111315-e20ec32e963c // indirect
github.com/sagikazarmark/locafero v0.12.0 // indirect
github.com/samber/oops v1.23.0 // indirect
- github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 // indirect
+ github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 // indirect
github.com/sassoftware/go-rpmutils v0.4.0 // indirect
github.com/sassoftware/relic v7.2.1+incompatible // indirect
github.com/segmentio/asm v1.2.1 // indirect
diff --git a/go.sum b/go.sum
index 8fe94318c4..60e8dea82d 100644
--- a/go.sum
+++ b/go.sum
@@ -1188,8 +1188,8 @@ github.com/samber/lo v1.53.0 h1:t975lj2py4kJPQ6haz1QMgtId2gtmfktACxIXArw3HM=
github.com/samber/lo v1.53.0/go.mod h1:4+MXEGsJzbKGaUEQFKBq2xtfuznW9oz/WrgyzMzRoM0=
github.com/samber/oops v1.23.0 h1:27aIZSRreSy4yveT0ZV4s3gLZp7/ra9Zbb84gwWbA9I=
github.com/samber/oops v1.23.0/go.mod h1:8ZDRxwQdphVhmLtEX9I6134LHJe5yeCV8cTfHz3m91Y=
-github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 h1:KRzFb2m7YtdldCEkzs6KqmJw4nqEVZGK7IN2kJkjTuQ=
-github.com/santhosh-tekuri/jsonschema/v6 v6.0.2/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU=
+github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 h1:1EYB5IzjZawrrnELUi78f9fPu57HuXjmddZPjrls/28=
+github.com/santhosh-tekuri/jsonschema/v6 v6.0.3/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU=
github.com/sassoftware/go-rpmutils v0.4.0 h1:ojND82NYBxgwrV+mX1CWsd5QJvvEZTKddtCdFLPWhpg=
github.com/sassoftware/go-rpmutils v0.4.0/go.mod h1:3goNWi7PGAT3/dlql2lv3+MSN5jNYPjT5mVcQcIsYzI=
github.com/sassoftware/relic v7.2.1+incompatible h1:Pwyh1F3I0r4clFJXkSI8bOyJINGqpgjJU3DYAZeI05A=
From 0d2dc71575a90cf74fbfe64cb7d93984f23761e4 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 23:46:11 +0000
Subject: [PATCH 34/70] chore(deps): update module github.com/pierrec/lz4/v4 to
v4.1.28 (9.5) (#7784)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/pierrec/lz4/v4](https://redirect.github.com/pierrec/lz4) |
`v4.1.27` → `v4.1.28` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
pierrec/lz4 (github.com/pierrec/lz4/v4)
###
[`v4.1.28`](https://redirect.github.com/pierrec/lz4/compare/v4.1.27...v4.1.28)
[Compare
Source](https://redirect.github.com/pierrec/lz4/compare/v4.1.27...v4.1.28)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index cc6a283805..44d68acfa2 100644
--- a/go.mod
+++ b/go.mod
@@ -520,7 +520,7 @@ require (
github.com/package-url/packageurl-go v0.1.6 // indirect
github.com/pelletier/go-toml/v2 v2.4.3 // indirect
github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
- github.com/pierrec/lz4/v4 v4.1.27 // indirect
+ github.com/pierrec/lz4/v4 v4.1.28 // indirect
github.com/pjbgf/sha1cd v0.6.0 // indirect
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
diff --git a/go.sum b/go.sum
index 60e8dea82d..b25f1eef34 100644
--- a/go.sum
+++ b/go.sum
@@ -1127,8 +1127,8 @@ github.com/pelletier/go-toml/v2 v2.4.3 h1:GTRvJQutkOSftxIFD5xw9aepkYNuPWmVJpffdD
github.com/pelletier/go-toml/v2 v2.4.3/go.mod h1:2gIqNv+qfxSVS7cM2xJQKtLSTLUE9V8t9Stt+h56mCY=
github.com/peterbourgon/diskv v2.0.1+incompatible h1:UBdAOUP5p4RWqPBg048CAvpKN+vxiaj6gdUUzhl4XmI=
github.com/peterbourgon/diskv v2.0.1+incompatible/go.mod h1:uqqh8zWWbv1HBMNONnaR/tNboyR3/BZd58JJSHlUSCU=
-github.com/pierrec/lz4/v4 v4.1.27 h1:+PhzhWDrjRj89TH2sw43nE3+4+W8lSxIuQadEHZyjUk=
-github.com/pierrec/lz4/v4 v4.1.27/go.mod h1:EoQMVJgeeEOMsCqCzqFm2O0cJvljX2nGZjcRIPL34O4=
+github.com/pierrec/lz4/v4 v4.1.28 h1:pPEPwRJ4kybBTfGt28q7lQsRJQHhC08axprdLD5Ppio=
+github.com/pierrec/lz4/v4 v4.1.28/go.mod h1:EoQMVJgeeEOMsCqCzqFm2O0cJvljX2nGZjcRIPL34O4=
github.com/pierrre/gotestcover v0.0.0-20160517101806-924dca7d15f0 h1:i5VIxp6QB8oWZ8IkK8zrDgeT6ORGIUeiN+61iETwJbI=
github.com/pierrre/gotestcover v0.0.0-20160517101806-924dca7d15f0/go.mod h1:4xpMLz7RBWyB+ElzHu8Llua96TRCB3YwX+l5EP1wmHk=
github.com/pjbgf/sha1cd v0.6.0 h1:3WJ8Wz8gvDz29quX1OcEmkAlUg9diU4GxJHqs0/XiwU=
From 63b7d6832d71ac9cdbaa63d5ada1141fe9c919a1 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 01:57:16 +0000
Subject: [PATCH 35/70] chore(deps): update module
github.com/mattn/go-runewidth to v0.0.27 (9.5) (#7780)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/mattn/go-runewidth](https://redirect.github.com/mattn/go-runewidth)
| `v0.0.24` → `v0.0.27` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
mattn/go-runewidth (github.com/mattn/go-runewidth)
###
[`v0.0.27`](https://redirect.github.com/mattn/go-runewidth/compare/v0.0.26...v0.0.27)
[Compare
Source](https://redirect.github.com/mattn/go-runewidth/compare/v0.0.26...v0.0.27)
###
[`v0.0.26`](https://redirect.github.com/mattn/go-runewidth/compare/v0.0.25...v0.0.26)
[Compare
Source](https://redirect.github.com/mattn/go-runewidth/compare/v0.0.25...v0.0.26)
###
[`v0.0.25`](https://redirect.github.com/mattn/go-runewidth/compare/v0.0.24...v0.0.25)
[Compare
Source](https://redirect.github.com/mattn/go-runewidth/compare/v0.0.24...v0.0.25)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 44d68acfa2..1f8a7891c0 100644
--- a/go.mod
+++ b/go.mod
@@ -494,7 +494,7 @@ require (
github.com/masahiro331/go-vmdk-parser v0.0.0-20260425175348-040a3994f0b4 // indirect
github.com/mattn/go-colorable v0.1.15 // indirect
github.com/mattn/go-isatty v0.0.24 // indirect
- github.com/mattn/go-runewidth v0.0.24 // indirect
+ github.com/mattn/go-runewidth v0.0.27 // indirect
github.com/miekg/dns v1.1.72 // indirect
github.com/mitchellh/copystructure v1.2.0 // indirect
github.com/mitchellh/go-homedir v1.1.0 // indirect
diff --git a/go.sum b/go.sum
index b25f1eef34..0c2f1f8501 100644
--- a/go.sum
+++ b/go.sum
@@ -978,8 +978,8 @@ github.com/mattn/go-colorable v0.1.15 h1:+u9SLTRGnXv73cEsnsmoZBom+dMU88B2M0aDcWy
github.com/mattn/go-colorable v0.1.15/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8=
github.com/mattn/go-isatty v0.0.24 h1:tGZZoVgT/KiqK1c8ocVLeDS8BSWMRd47J3Lbz7vsReI=
github.com/mattn/go-isatty v0.0.24/go.mod h1:nMCL3Zebbrt45jsMDgnfIwz6ydEQApk5oEI3HqDio6A=
-github.com/mattn/go-runewidth v0.0.24 h1:cpokDiIn0MGnhdHwuWnJBITySJ20QyNGnY2kR/ay2DU=
-github.com/mattn/go-runewidth v0.0.24/go.mod h1:XBkDxAl56ILZc9knddidhrOlY5R/pDhgLpndooCuJAs=
+github.com/mattn/go-runewidth v0.0.27 h1:Feg/Oou5zI/wnpgDF6omIU0OokC9GxLC/WRknhVlIR0=
+github.com/mattn/go-runewidth v0.0.27/go.mod h1:3qAiGCV4Koz/yuveO58qUefmUTRm8r0IGEXZ9jeHp/8=
github.com/mattn/go-shellwords v1.0.14 h1:yUKzIgsCnosndOASY6/enly1EAuaXeFSQ7cdyA3OuYg=
github.com/mattn/go-shellwords v1.0.14/go.mod h1:EZzvwXDESEeg03EKmM+RmDnNOPKG4lLtQsUlTZDWQ8Y=
github.com/mattn/go-sqlite3 v1.14.22/go.mod h1:Uh1q+B4BYcTPb+yiD3kU8Ct7aC0hY9fxUwlHK0RXw+Y=
From c1f36e78b08153d351b52ce9aeb49a64e67e49c2 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 01:57:36 +0000
Subject: [PATCH 36/70] chore(deps): update module
github.com/std-uritemplate/std-uritemplate/go/v2 to v2.0.12 (9.5) (#7788)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/std-uritemplate/std-uritemplate/go/v2](https://redirect.github.com/std-uritemplate/std-uritemplate)
| `v2.0.11` → `v2.0.12` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
std-uritemplate/std-uritemplate
(github.com/std-uritemplate/std-uritemplate/go/v2)
###
[`v2.0.12`](https://redirect.github.com/std-uritemplate/std-uritemplate/compare/2.0.11...2.0.12)
[Compare
Source](https://redirect.github.com/std-uritemplate/std-uritemplate/compare/2.0.11...2.0.12)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 1f8a7891c0..6cfff97d8c 100644
--- a/go.mod
+++ b/go.mod
@@ -272,7 +272,7 @@ require (
github.com/sigstore/sigstore-go v1.1.4 // indirect
github.com/sigstore/timestamp-authority/v2 v2.1.2 // indirect
github.com/spiffe/go-spiffe/v2 v2.8.1 // indirect
- github.com/std-uritemplate/std-uritemplate/go/v2 v2.0.11 // indirect
+ github.com/std-uritemplate/std-uritemplate/go/v2 v2.0.12 // indirect
github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d // indirect
github.com/tetratelabs/wabin v0.0.0-20230304001439-f6f874872834 // indirect
github.com/theupdateframework/go-tuf v0.7.0 // indirect
diff --git a/go.sum b/go.sum
index 0c2f1f8501..4453f7cf14 100644
--- a/go.sum
+++ b/go.sum
@@ -1255,8 +1255,8 @@ github.com/spf13/viper v1.21.0 h1:x5S+0EU27Lbphp4UKm1C+1oQO+rKx36vfCoaVebLFSU=
github.com/spf13/viper v1.21.0/go.mod h1:P0lhsswPGWD/1lZJ9ny3fYnVqxiegrlNrEmgLjbTCAY=
github.com/spiffe/go-spiffe/v2 v2.8.1 h1:eXZMLsu+3MLEPJyGJkolqtVrteZfQdUpOWj6LTiDl/E=
github.com/spiffe/go-spiffe/v2 v2.8.1/go.mod h1:47Q0Q9/AqGha8QLHp+kxpH4Wca7X7EnOtlIJy3mxZ3U=
-github.com/std-uritemplate/std-uritemplate/go/v2 v2.0.11 h1:Z15B48tgHrex1p1plHHeP4Wpu9eAI5+DJBCAtEDQH8A=
-github.com/std-uritemplate/std-uritemplate/go/v2 v2.0.11/go.mod h1:Z5KcoM0YLC7INlNhEezeIZ0TZNYf7WSNO0Lvah4DSeQ=
+github.com/std-uritemplate/std-uritemplate/go/v2 v2.0.12 h1:wxCxe+V5vu01YFrFgKj22gViqn8Yj4i9d9ecvdHvTGU=
+github.com/std-uritemplate/std-uritemplate/go/v2 v2.0.12/go.mod h1:Z5KcoM0YLC7INlNhEezeIZ0TZNYf7WSNO0Lvah4DSeQ=
github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
github.com/stretchr/objx v0.4.0/go.mod h1:YvHI0jy2hoMjB+UWwv71VJQ9isScKT/TqJzVSSt89Yw=
github.com/stretchr/objx v0.5.0/go.mod h1:Yh+to48EsGEfYuaHDzXPcE3xhTkx73EhmCGUpEOglKo=
From d13710b51a575bc4811d99867fedafa26017461d Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 01:58:13 +0000
Subject: [PATCH 37/70] chore(deps): update module github.com/ulikunitz/xz to
v0.5.16 (9.5) (#7789)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/ulikunitz/xz](https://redirect.github.com/ulikunitz/xz) |
`v0.5.15` → `v0.5.16` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
ulikunitz/xz (github.com/ulikunitz/xz)
###
[`v0.5.16`](https://redirect.github.com/ulikunitz/xz/compare/v0.5.15...v0.5.16)
[Compare
Source](https://redirect.github.com/ulikunitz/xz/compare/v0.5.15...v0.5.16)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 6cfff97d8c..c610c28791 100644
--- a/go.mod
+++ b/go.mod
@@ -552,7 +552,7 @@ require (
github.com/tklauser/go-sysconf v0.4.0 // indirect
github.com/tklauser/numcpus v0.12.0 // indirect
github.com/twitchtv/twirp v8.1.3+incompatible // indirect
- github.com/ulikunitz/xz v0.5.15 // indirect
+ github.com/ulikunitz/xz v0.5.16 // indirect
github.com/xanzy/ssh-agent v0.3.3 // indirect
github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb // indirect
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect
diff --git a/go.sum b/go.sum
index 4453f7cf14..5ca2c5f63c 100644
--- a/go.sum
+++ b/go.sum
@@ -1322,8 +1322,8 @@ github.com/tsg/go-daemon v0.0.0-20200207173439-e704b93fd89b h1:X/8hkb4rQq3+QuOxp
github.com/tsg/go-daemon v0.0.0-20200207173439-e704b93fd89b/go.mod h1:jAqhj/JBVC1PwcLTWd6rjQyGyItxxrhpiBl8LSuAGmw=
github.com/twitchtv/twirp v8.1.3+incompatible h1:+F4TdErPgSUbMZMwp13Q/KgDVuI7HJXP61mNV3/7iuU=
github.com/twitchtv/twirp v8.1.3+incompatible/go.mod h1:RRJoFSAmTEh2weEqWtpPE3vFK5YBhA6bqp2l1kfCC5A=
-github.com/ulikunitz/xz v0.5.15 h1:9DNdB5s+SgV3bQ2ApL10xRc35ck0DuIX/isZvIk+ubY=
-github.com/ulikunitz/xz v0.5.15/go.mod h1:nbz6k7qbPmH4IRqmfOplQw/tblSgqTqBwxkY0oWt/14=
+github.com/ulikunitz/xz v0.5.16 h1:ld6NyySjx5lowVKwJvMRLnW5nxKX/xnpSiFYZ/Lxur0=
+github.com/ulikunitz/xz v0.5.16/go.mod h1:H9Rt/W6/Qj27PGauhQc6nfCDy7vHpzsOThBSaYDoEhw=
github.com/urfave/cli/v2 v2.3.0/go.mod h1:LJmUH05zAU44vOAcrfzZQKsZbVcdbOG8rtL3/XcUArI=
github.com/valyala/fastjson v1.6.10 h1:/yjJg8jaVQdYR3arGxPE2X5z89xrlhS0eGXdv+ADTh4=
github.com/valyala/fastjson v1.6.10/go.mod h1:e6FubmQouUNP73jtMLmcbxS6ydWIpOfhz34TSfO3JaE=
From 02a2d1a08ecb752dfe8e30414a641f0e71b8a19c Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 01:58:53 +0000
Subject: [PATCH 38/70] fix(deps): update module github.com/aws/smithy-go to
v1.27.7 (9.5) (#7794)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/aws/smithy-go](https://redirect.github.com/aws/smithy-go)
| `v1.27.3` → `v1.27.7` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
aws/smithy-go (github.com/aws/smithy-go)
###
[`v1.27.7`](https://redirect.github.com/aws/smithy-go/blob/HEAD/CHANGELOG.md#Release-2026-08-07)
[Compare
Source](https://redirect.github.com/aws/smithy-go/compare/v1.27.6...v1.27.7)
#### General Highlights
- **Dependency Update**: Updated to the latest SDK module versions
#### Module Highlights
- `github.com/aws/smithy-go`: v1.27.7
- **Bug Fix**: Don't serialize unset JSON documents as `nil` in
structure members.
- **Bug Fix**: Fix a deserialization panic around collection members in
recursive shape configs.
###
[`v1.27.6`](https://redirect.github.com/aws/smithy-go/blob/HEAD/CHANGELOG.md#Release-2026-07-31)
[Compare
Source](https://redirect.github.com/aws/smithy-go/compare/v1.27.5...v1.27.6)
#### General Highlights
- **Dependency Update**: Updated to the latest SDK module versions
#### Module Highlights
- `github.com/aws/smithy-go`: v1.27.6
- **Bug Fix**: Fix failure to deserialize any `@httpPayload` struct with
a non-string member.
- **Bug Fix**: Fix failure to serialize any `@httpPayload` struct with a
nested struct.
###
[`v1.27.5`](https://redirect.github.com/aws/smithy-go/blob/HEAD/CHANGELOG.md#Release-2026-07-27)
[Compare
Source](https://redirect.github.com/aws/smithy-go/compare/v1.27.4...v1.27.5)
#### General Highlights
- **Dependency Update**: Updated to the latest SDK module versions
#### Module Highlights
- `github.com/aws/smithy-go`: v1.27.5
- **Bug Fix**: Fix a performance issue in awsQuery with large response
payloads.
###
[`v1.27.4`](https://redirect.github.com/aws/smithy-go/compare/v1.27.3...v1.27.4)
[Compare
Source](https://redirect.github.com/aws/smithy-go/compare/v1.27.3...v1.27.4)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index c610c28791..3872d91a2f 100644
--- a/go.mod
+++ b/go.mod
@@ -46,7 +46,7 @@ require (
github.com/aws/aws-sdk-go-v2/service/securityhub v1.71.7
github.com/aws/aws-sdk-go-v2/service/sns v1.40.1
github.com/aws/aws-sdk-go-v2/service/sts v1.43.3
- github.com/aws/smithy-go v1.27.3
+ github.com/aws/smithy-go v1.27.7
github.com/dgraph-io/ristretto/v2 v2.4.2
github.com/djherbis/times v1.6.0
github.com/elastic/beats/v7 v7.0.0-alpha2.0.20260604204725-a6d4c42eeb5a
diff --git a/go.sum b/go.sum
index 5ca2c5f63c..ec9c1103a4 100644
--- a/go.sum
+++ b/go.sum
@@ -301,8 +301,8 @@ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.36.6 h1:yLr03zQE/5Eu5l3QU0Si+xMb
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.36.6/go.mod h1:Q5N6icH+KJZDLh+ESNwzdv6cZ6vLFF/egy3IOxWhmz4=
github.com/aws/aws-sdk-go-v2/service/sts v1.43.3 h1:VrIhKRCSK1umelSgB9RghvA9RTUYeQffyAS5ApXehNI=
github.com/aws/aws-sdk-go-v2/service/sts v1.43.3/go.mod h1:r8wkDOuLaaMFqFiYAb8dGY2A3gJCOujMc6CFOVC4Zhc=
-github.com/aws/smithy-go v1.27.3 h1:F3Zb497UhhskkfpJmfkXswyo+t0sh9OTBnIHjogWbVY=
-github.com/aws/smithy-go v1.27.3/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc=
+github.com/aws/smithy-go v1.27.7 h1:Zgj5z4LfcDYoQIVk+n/yGdTkP/2y6ZT5vYxe0fp7bqE=
+github.com/aws/smithy-go v1.27.7/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc=
github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM=
github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6rlkpw=
github.com/bgentry/go-netrc v0.0.0-20140422174119-9fd32a8b3d3d h1:xDfNPAt8lFiC1UJrqV3uuy861HCTo708pDMbjHHdCas=
From 1d5cf13ccb13141d228da03fe4d0b16b6006145c Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 01:59:10 +0000
Subject: [PATCH 39/70] chore(deps): update module go.yaml.in/yaml/v3 to v3.0.5
(9.5) (#7790)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [go.yaml.in/yaml/v3](https://redirect.github.com/yaml/go-yaml) |
`v3.0.4` → `v3.0.5` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
yaml/go-yaml (go.yaml.in/yaml/v3)
###
[`v3.0.5`](https://redirect.github.com/yaml/go-yaml/compare/v3.0.4...v3.0.5)
[Compare
Source](https://redirect.github.com/yaml/go-yaml/compare/v3.0.4...v3.0.5)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 3 ++-
2 files changed, 3 insertions(+), 2 deletions(-)
diff --git a/go.mod b/go.mod
index 3872d91a2f..b2dbd93199 100644
--- a/go.mod
+++ b/go.mod
@@ -306,7 +306,7 @@ require (
go.opentelemetry.io/collector/pipeline/xpipeline v0.153.0 // indirect
go.uber.org/atomic v1.11.0 // indirect
go.yaml.in/yaml/v2 v2.4.4 // indirect
- go.yaml.in/yaml/v3 v3.0.4 // indirect
+ go.yaml.in/yaml/v3 v3.0.5 // indirect
go.yaml.in/yaml/v4 v4.0.0-rc.6 // indirect
golang.org/x/exp v0.0.0-20260410095643-746e56fc9e2f // indirect
golang.org/x/tools v0.47.0 // indirect
diff --git a/go.sum b/go.sum
index ec9c1103a4..3d3cd7e430 100644
--- a/go.sum
+++ b/go.sum
@@ -1561,8 +1561,9 @@ go.uber.org/zap/exp v0.3.0 h1:6JYzdifzYkGmTdRR59oYH+Ng7k49H9qVpWwNSsGJj3U=
go.uber.org/zap/exp v0.3.0/go.mod h1:5I384qq7XGxYyByIhHm6jg5CHkGY0nsTfbDLgDDlgJQ=
go.yaml.in/yaml/v2 v2.4.4 h1:tuyd0P+2Ont/d6e2rl3be67goVK4R6deVxCUX5vyPaQ=
go.yaml.in/yaml/v2 v2.4.4/go.mod h1:gMZqIpDtDqOfM0uNfy0SkpRhvUryYH0Z6wdMYcacYXQ=
-go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc=
go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
+go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
+go.yaml.in/yaml/v3 v3.0.5/go.mod h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg=
go.yaml.in/yaml/v4 v4.0.0-rc.6 h1:1h7H1ohdUh93/FyE4YaDa1Zh64K6VVbjF4K6WUxMtH4=
go.yaml.in/yaml/v4 v4.0.0-rc.6/go.mod h1:aZqd9kCMsGL7AuUv/m/PvWLdg5sjJsZ4oHDEnfPPfY0=
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
From ec75ba2737d617c96475f1bf0b3ee2ff9280a3f8 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 01:59:34 +0000
Subject: [PATCH 40/70] chore(deps): update module helm.sh/helm/v4 to v4.2.3
(9.5) (#7791)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [helm.sh/helm/v4](https://redirect.github.com/helm/helm) | `v4.2.2` →
`v4.2.3` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
helm/helm (helm.sh/helm/v4)
###
[`v4.2.3`](https://redirect.github.com/helm/helm/releases/tag/v4.2.3):
Helm v4.2.3
[Compare
Source](https://redirect.github.com/helm/helm/compare/v4.2.2...v4.2.3)
Helm v4.2.3 is a patch release. Users are encouraged to upgrade for the
best experience.
The community keeps growing, and we'd love to see you there!
- Join the discussion in [Kubernetes
Slack](https://kubernetes.slack.com):
- for questions and just to hang out
- for discussing PRs, code, and bugs
- Hang out at the Public Developer Call: Thursday, 9:30 Pacific via
[Zoom](https://zoom.us/j/696660622)
- Test, debug, and contribute charts:
[ArtifactHub/packages](https://artifacthub.io/packages/search?kind=0)
##### Installation and Upgrading
Download Helm v4.2.3. The common platform binaries are here:
- [MacOS amd64](https://get.helm.sh/helm-v4.2.3-darwin-amd64.tar.gz)
([checksum](https://get.helm.sh/helm-v4.2.3-darwin-amd64.tar.gz.sha256sum)
/ ff3ac86755a45f3422473bc1200776aac0fe04c5766abe6ca66699f7b564b23b)
- [MacOS arm64](https://get.helm.sh/helm-v4.2.3-darwin-arm64.tar.gz)
([checksum](https://get.helm.sh/helm-v4.2.3-darwin-arm64.tar.gz.sha256sum)
/ 048ecf5ad3160f83d918f9fe945238d2132b079640f7b106175331c25f242c64)
- [Linux amd64](https://get.helm.sh/helm-v4.2.3-linux-amd64.tar.gz)
([checksum](https://get.helm.sh/helm-v4.2.3-linux-amd64.tar.gz.sha256sum)
/ e9b88b4ee95b18c706839c28d3a0220e5bc470e9cd9262410c90793c45ff8b7c)
- [Linux arm](https://get.helm.sh/helm-v4.2.3-linux-arm.tar.gz)
([checksum](https://get.helm.sh/helm-v4.2.3-linux-arm.tar.gz.sha256sum)
/ ba00678361ca7a03ec42ca1ea459543e1d8eab2a7d5429a5eda71dc9741c8a9b)
- [Linux arm64](https://get.helm.sh/helm-v4.2.3-linux-arm64.tar.gz)
([checksum](https://get.helm.sh/helm-v4.2.3-linux-arm64.tar.gz.sha256sum)
/ 21abd9354d39b2cd79a8d76be6912cd137a983cbf997193503fb8a6a6e2f2785)
- [Linux i386](https://get.helm.sh/helm-v4.2.3-linux-386.tar.gz)
([checksum](https://get.helm.sh/helm-v4.2.3-linux-386.tar.gz.sha256sum)
/ 31d57972d36e60388e173327fffcf9d58f272349dfa9ed3e1914f3cd88fe7283)
- [Linux loong64](https://get.helm.sh/helm-v4.2.3-linux-loong64.tar.gz)
([checksum](https://get.helm.sh/helm-v4.2.3-linux-loong64.tar.gz.sha256sum)
/ 232f82d787d530a621b2006965ed2b99644b4391bbc6261e9787f95700fc44f7)
- [Linux ppc64le](https://get.helm.sh/helm-v4.2.3-linux-ppc64le.tar.gz)
([checksum](https://get.helm.sh/helm-v4.2.3-linux-ppc64le.tar.gz.sha256sum)
/ 43fc5a4b20839c3669a0748498bd2613b095e288425bf5678c6ba664eb4a0e70)
- [Linux s390x](https://get.helm.sh/helm-v4.2.3-linux-s390x.tar.gz)
([checksum](https://get.helm.sh/helm-v4.2.3-linux-s390x.tar.gz.sha256sum)
/ 17932091e19d352585b540a482fca9b953d32a8ad7afec72bf9cbbcd96b094cb)
- [Linux riscv64](https://get.helm.sh/helm-v4.2.3-linux-riscv64.tar.gz)
([checksum](https://get.helm.sh/helm-v4.2.3-linux-riscv64.tar.gz.sha256sum)
/ 09ff0772730678c652b9ac4a2b32cd20f4e62a2b040403bcacd4ad845d3d3e9c)
- [Windows amd64](https://get.helm.sh/helm-v4.2.3-windows-amd64.zip)
([checksum](https://get.helm.sh/helm-v4.2.3-windows-amd64.zip.sha256sum)
/ 5ca7de684c92d48b93d5c34a029fdda57b38e1eac04bc8541bdf1eb249388679)
- [Windows arm64](https://get.helm.sh/helm-v4.2.3-windows-arm64.zip)
([checksum](https://get.helm.sh/helm-v4.2.3-windows-arm64.zip.sha256sum)
/ 5f444ed097688ed3abaf1d8801e21110d9bddeb6ed13939afcac302888527ab5)
The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get
you going from there. For **upgrade instructions** or detailed
installation notes, check the [install
guide](https://helm.sh/docs/intro/install/). You can also use a [script
to
install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-4)
on any system with `bash`.
##### What's Next
- 4.2.4 and 3.21.4 are the next patch releases scheduled for August 12,
2026
- 4.3.0 and 3.22.0 are the next minor releases scheduled for September
9, 2026
##### Changelog
- chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0
[`43e8b7f`](https://redirect.github.com/helm/helm/commit/43e8b7feece8beb0fcba47059ec9b522fd929a64)
(Terry Howe)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index b2dbd93199..ab35b9004e 100644
--- a/go.mod
+++ b/go.mod
@@ -313,7 +313,7 @@ require (
gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect
gopkg.in/ini.v1 v1.67.3 // indirect
gopkg.in/yaml.v2 v2.4.0 // indirect
- helm.sh/helm/v4 v4.2.2 // indirect
+ helm.sh/helm/v4 v4.2.3 // indirect
kernel.org/pub/linux/libs/security/libcap/cap v1.2.78 // indirect
kernel.org/pub/linux/libs/security/libcap/psx v1.2.78 // indirect
modernc.org/libc v1.74.0 // indirect
diff --git a/go.sum b/go.sum
index 3d3cd7e430..5abc84b53d 100644
--- a/go.sum
+++ b/go.sum
@@ -1752,8 +1752,8 @@ gotest.tools/gotestsum v1.13.0 h1:+Lh454O9mu9AMG1APV4o0y7oDYKyik/3kBOiCqiEpRo=
gotest.tools/gotestsum v1.13.0/go.mod h1:7f0NS5hFb0dWr4NtcsAsF0y1kzjEFfAil0HiBQJE03Q=
gotest.tools/v3 v3.5.2 h1:7koQfIKdy+I8UTetycgUqXWSDwpgv193Ka+qRsmBY8Q=
gotest.tools/v3 v3.5.2/go.mod h1:LtdLGcnqToBH83WByAAi/wiwSFCArdFIUV/xxN4pcjA=
-helm.sh/helm/v4 v4.2.2 h1:E2zSCA2uUm9PNiZsSC/BioDVGsYk7nF2jNJFg/i+Dng=
-helm.sh/helm/v4 v4.2.2/go.mod h1:dp3ihfy1AhCLKANDaPETmVWhqPkOmwvJtpK/biHfopE=
+helm.sh/helm/v4 v4.2.3 h1:JEejtPE04+SvyRomOfgRXVxyJ/lude7eShio30oQr0Y=
+helm.sh/helm/v4 v4.2.3/go.mod h1:azI2XpxowOGXAgzeXcqyfskUmIfILqIcJxiFw1M6PuM=
honnef.co/go/tools v0.0.0-20190102054323-c2f93a96b099/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4=
honnef.co/go/tools v0.0.0-20190523083050-ea95bdfd59fc/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4=
howett.net/plist v1.0.1 h1:37GdZ8tP09Q35o9ych3ehygcsL+HqKSwzctveSlarvM=
From 8585c4f0e5e7ec437c2cfe851586e945b6294b82 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 01:59:58 +0000
Subject: [PATCH 41/70] fix(deps): update module
github.com/google/go-containerregistry to v0.21.9 (9.5) (#7796)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/google/go-containerregistry](https://redirect.github.com/google/go-containerregistry)
| `v0.21.7` → `v0.21.9` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
google/go-containerregistry
(github.com/google/go-containerregistry)
###
[`v0.21.9`](https://redirect.github.com/google/go-containerregistry/releases/tag/v0.21.9)
[Compare
Source](https://redirect.github.com/google/go-containerregistry/compare/v0.21.8...v0.21.9)
#### What's Changed
- actions: pin slsa generator by version by
[@Subserial](https://redirect.github.com/Subserial) in
[#2395](https://redirect.github.com/google/go-containerregistry/pull/2395)
- fix: prevent data race on scope refreshes within remote.writer by
[@Subserial](https://redirect.github.com/Subserial) in
[#2396](https://redirect.github.com/google/go-containerregistry/pull/2396)
- fix: remove '.' from unsafe path prefixes by
[@Subserial](https://redirect.github.com/Subserial) in
[#2400](https://redirect.github.com/google/go-containerregistry/pull/2400)
- build(deps): bump the actions group with 3 updates by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2398](https://redirect.github.com/google/go-containerregistry/pull/2398)
**Full Changelog**:
###
[`v0.21.8`](https://redirect.github.com/google/go-containerregistry/releases/tag/v0.21.8)
[Compare
Source](https://redirect.github.com/google/go-containerregistry/compare/v0.21.7...v0.21.8)
The artifacts attached to this release are missing SLSA provenance, see
[#2390](https://redirect.github.com/google/go-containerregistry/issues/2390).
#### What's Changed
- build(deps): bump the go-deps group across 1 directory with 3 updates
by [@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2353](https://redirect.github.com/google/go-containerregistry/pull/2353)
- build(deps): bump golang.org/x/crypto from 0.45.0 to 0.52.0 in
/cmd/krane by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2367](https://redirect.github.com/google/go-containerregistry/pull/2367)
- build(deps): bump golang.org/x/crypto from 0.50.0 to 0.52.0 in
/pkg/authn/k8schain by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2368](https://redirect.github.com/google/go-containerregistry/pull/2368)
- build(deps): bump golang.org/x/net from 0.49.0 to 0.55.0 in
/pkg/authn/kubernetes by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2363](https://redirect.github.com/google/go-containerregistry/pull/2363)
- build(deps): bump the go-deps group across 3 directories with 7
updates by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2377](https://redirect.github.com/google/go-containerregistry/pull/2377)
- build(deps): bump the actions group across 1 directory with 5 updates
by [@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2375](https://redirect.github.com/google/go-containerregistry/pull/2375)
- Reject unsafe Windows archive paths in Extract by
[@Haihan-Jiang](https://redirect.github.com/Haihan-Jiang) in
[#2330](https://redirect.github.com/google/go-containerregistry/pull/2330)
- feat(goreleaser): add loong64 build support for crane/gcrane/krane by
[@xuxiaowei-com-cn](https://redirect.github.com/xuxiaowei-com-cn)
in
[#2358](https://redirect.github.com/google/go-containerregistry/pull/2358)
- Document tag and digest reference semantics by
[@Haihan-Jiang](https://redirect.github.com/Haihan-Jiang) in
[#2325](https://redirect.github.com/google/go-containerregistry/pull/2325)
- remote: release pull limiter slot when body is read to EOF by
[@knQzx](https://redirect.github.com/knQzx) in
[#2373](https://redirect.github.com/google/go-containerregistry/pull/2373)
- tarball: bounds-check layer index in uncompressed LayerByDiffID by
[@arpitjain099](https://redirect.github.com/arpitjain099) in
[#2370](https://redirect.github.com/google/go-containerregistry/pull/2370)
- authn: read Podman auth from XDG config by
[@vigneshakaviki](https://redirect.github.com/vigneshakaviki) in
[#2379](https://redirect.github.com/google/go-containerregistry/pull/2379)
- transport: per-host bearer token exchange on cross-host redirect by
[@amitzig](https://redirect.github.com/amitzig) in
[#2360](https://redirect.github.com/google/go-containerregistry/pull/2360)
- mutate: bounds-check layer index when building rebase addendums by
[@arpitjain099](https://redirect.github.com/arpitjain099) in
[#2371](https://redirect.github.com/google/go-containerregistry/pull/2371)
- fix(daemon): copy ExposedPorts from source config in
computeImageConfig by
[@x64vps](https://redirect.github.com/x64vps) in
[#2356](https://redirect.github.com/google/go-containerregistry/pull/2356)
- feat(remote): add WithReferrersTagFallback option by
[@kevinmdavis](https://redirect.github.com/kevinmdavis) in
[#2366](https://redirect.github.com/google/go-containerregistry/pull/2366)
- mutate: apply opaque-directory whiteouts (.wh..wh..opq) in Extract by
[@sadmanf](https://redirect.github.com/sadmanf) in
[#2372](https://redirect.github.com/google/go-containerregistry/pull/2372)
- tarball: use correct file extension for zstd/uncompressed by
[@milas](https://redirect.github.com/milas) in
[#2382](https://redirect.github.com/google/go-containerregistry/pull/2382)
- build(deps): bump github.com/moby/moby/client from 0.5.0 to 0.5.1 in
the go-deps group across 1 directory by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2380](https://redirect.github.com/google/go-containerregistry/pull/2380)
- actions: update actions to be pinned by hash by
[@Subserial](https://redirect.github.com/Subserial) in
[#2384](https://redirect.github.com/google/go-containerregistry/pull/2384)
- Bump go version to 1.26.5 by
[@Subserial](https://redirect.github.com/Subserial) in
[#2388](https://redirect.github.com/google/go-containerregistry/pull/2388)
#### New Contributors
-
[@xuxiaowei-com-cn](https://redirect.github.com/xuxiaowei-com-cn)
made their first contribution in
[#2358](https://redirect.github.com/google/go-containerregistry/pull/2358)
- [@knQzx](https://redirect.github.com/knQzx) made their first
contribution in
[#2373](https://redirect.github.com/google/go-containerregistry/pull/2373)
- [@arpitjain099](https://redirect.github.com/arpitjain099) made
their first contribution in
[#2370](https://redirect.github.com/google/go-containerregistry/pull/2370)
- [@vigneshakaviki](https://redirect.github.com/vigneshakaviki)
made their first contribution in
[#2379](https://redirect.github.com/google/go-containerregistry/pull/2379)
- [@amitzig](https://redirect.github.com/amitzig) made their
first contribution in
[#2360](https://redirect.github.com/google/go-containerregistry/pull/2360)
- [@x64vps](https://redirect.github.com/x64vps) made their first
contribution in
[#2356](https://redirect.github.com/google/go-containerregistry/pull/2356)
- [@kevinmdavis](https://redirect.github.com/kevinmdavis) made
their first contribution in
[#2366](https://redirect.github.com/google/go-containerregistry/pull/2366)
- [@sadmanf](https://redirect.github.com/sadmanf) made their
first contribution in
[#2372](https://redirect.github.com/google/go-containerregistry/pull/2372)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 14 +++++++-------
go.sum | 28 ++++++++++++++--------------
2 files changed, 21 insertions(+), 21 deletions(-)
diff --git a/go.mod b/go.mod
index ab35b9004e..b0018de5c9 100644
--- a/go.mod
+++ b/go.mod
@@ -241,8 +241,8 @@ require (
github.com/microsoft/kiota-serialization-multipart-go v1.1.2 // indirect
github.com/microsoft/kiota-serialization-text-go v1.1.3 // indirect
github.com/moby/docker-image-spec v1.3.1 // indirect
- github.com/moby/moby/api v1.54.2 // indirect
- github.com/moby/moby/client v0.4.1 // indirect
+ github.com/moby/moby/api v1.55.0 // indirect
+ github.com/moby/moby/client v0.5.1 // indirect
github.com/moby/sys/atomicwriter v0.1.0 // indirect
github.com/moby/sys/user v0.4.0 // indirect
github.com/moby/sys/userns v0.1.0 // indirect
@@ -309,7 +309,7 @@ require (
go.yaml.in/yaml/v3 v3.0.5 // indirect
go.yaml.in/yaml/v4 v4.0.0-rc.6 // indirect
golang.org/x/exp v0.0.0-20260410095643-746e56fc9e2f // indirect
- golang.org/x/tools v0.47.0 // indirect
+ golang.org/x/tools v0.48.0 // indirect
gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect
gopkg.in/ini.v1 v1.67.3 // indirect
gopkg.in/yaml.v2 v2.4.0 // indirect
@@ -392,7 +392,7 @@ require (
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
github.com/dimchansky/utfbom v1.1.1 // indirect
github.com/dnephin/pflag v1.0.7 // indirect
- github.com/docker/cli v29.6.1+incompatible // indirect
+ github.com/docker/cli v29.6.2+incompatible // indirect
github.com/docker/docker-credential-helpers v0.9.8 // indirect
github.com/docker/go-connections v0.7.0 // indirect
github.com/docker/go-units v0.5.0 // indirect
@@ -444,7 +444,7 @@ require (
github.com/gomodule/redigo v1.9.3 // indirect
github.com/google/btree v1.1.3 // indirect
github.com/google/go-cmp v0.7.0 // indirect
- github.com/google/go-containerregistry v0.21.7
+ github.com/google/go-containerregistry v0.21.9
github.com/google/licenseclassifier v0.0.0-20260218193730-3cfbab2d0e0d // indirect
github.com/google/licenseclassifier/v2 v2.0.0 // indirect
github.com/google/s2a-go v0.1.9 // indirect
@@ -570,8 +570,8 @@ require (
go.opencensus.io v0.24.0 // indirect
go.uber.org/multierr v1.11.0 // indirect
golang.org/x/crypto v0.54.0 // indirect
- golang.org/x/mod v0.37.0 // indirect
- golang.org/x/net v0.56.0 // indirect
+ golang.org/x/mod v0.38.0 // indirect
+ golang.org/x/net v0.57.0 // indirect
golang.org/x/sync v0.22.0
golang.org/x/sys v0.47.0 // indirect
golang.org/x/term v0.45.0 // indirect
diff --git a/go.sum b/go.sum
index 5abc84b53d..8157385fa5 100644
--- a/go.sum
+++ b/go.sum
@@ -432,8 +432,8 @@ github.com/dlclark/regexp2 v1.12.0 h1:0j4c5qQmnC6XOWNjP3PIXURXN2gWx76rd3KvgdPkCz
github.com/dlclark/regexp2 v1.12.0/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8=
github.com/dnephin/pflag v1.0.7 h1:oxONGlWxhmUct0YzKTgrpQv9AUA1wtPBn7zuSjJqptk=
github.com/dnephin/pflag v1.0.7/go.mod h1:uxE91IoWURlOiTUIA8Mq5ZZkAv3dPUfZNaT80Zm7OQE=
-github.com/docker/cli v29.6.1+incompatible h1:oO7F4nn3Ovr/5TlfTUWFbMwBSS/B7Xs6Epv26gBrUP8=
-github.com/docker/cli v29.6.1+incompatible/go.mod h1:JLrzqnKDaYBop7H2jaqPtU4hHvMKP+vjCwu2uszcLI8=
+github.com/docker/cli v29.6.2+incompatible h1:/bjePvcbbFTnRrMfWJBY7AjfICdsiLVgHn6LwTVOcqw=
+github.com/docker/cli v29.6.2+incompatible/go.mod h1:JLrzqnKDaYBop7H2jaqPtU4hHvMKP+vjCwu2uszcLI8=
github.com/docker/distribution v2.8.3+incompatible h1:AtKxIZ36LoNK51+Z6RpzLpddBirtxJnzDrHLEKxTAYk=
github.com/docker/distribution v2.8.3+incompatible/go.mod h1:J2gT2udsDAN96Uj4KfcMRqY0/ypR+oyYUYmja8H+y+w=
github.com/docker/docker v28.5.2+incompatible h1:DBX0Y0zAjZbSrm1uzOkdr1onVghKaftjlSWt4AFexzM=
@@ -738,8 +738,8 @@ github.com/google/go-cmp v0.5.9/go.mod h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeN
github.com/google/go-cmp v0.6.0/go.mod h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY=
github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8=
github.com/google/go-cmp v0.7.0/go.mod h1:pXiqmnSA92OHEEa9HXL2W4E7lf9JzCmGVUdgjX3N/iU=
-github.com/google/go-containerregistry v0.21.7 h1:/vPFuVXDjtFREsVArW+0h1CIl5urnOhzei4X2DMW9IU=
-github.com/google/go-containerregistry v0.21.7/go.mod h1:kjSbt7/zMsKLWfnHrIvKvhXHUw91jbe9DNjPPJ32gXE=
+github.com/google/go-containerregistry v0.21.9 h1:F+D4uZ3iA3DLMJLfhaqMdHJbzeqm/216WGQq2dokuLs=
+github.com/google/go-containerregistry v0.21.9/go.mod h1:dP5XNKcL7kMFF/TB3LfvWmVhAcv7iqkHb3oDK8aauTo=
github.com/google/go-github/v62 v62.0.0 h1:/6mGCaRywZz9MuHyw9gD1CwsbmBX8GWsbFkwMmHdhl4=
github.com/google/go-github/v62 v62.0.0/go.mod h1:EMxeUqGJq2xRu9DYBMwel/mr7kZrzUOfQmmpYrZn2a4=
github.com/google/go-querystring v1.2.0 h1:yhqkPbu2/OH+V9BfpCVPZkNmUXhb2gBxJArfhIxNtP0=
@@ -1035,10 +1035,10 @@ github.com/moby/go-archive v0.2.0 h1:zg5QDUM2mi0JIM9fdQZWC7U8+2ZfixfTYoHL7rWUcP8
github.com/moby/go-archive v0.2.0/go.mod h1:mNeivT14o8xU+5q1YnNrkQVpK+dnNe/K6fHqnTg4qPU=
github.com/moby/locker v1.0.1 h1:fOXqR41zeveg4fFODix+1Ch4mj/gT0NE1XJbp/epuBg=
github.com/moby/locker v1.0.1/go.mod h1:S7SDdo5zpBK84bzzVlKr2V0hz+7x9hWbYC/kq7oQppc=
-github.com/moby/moby/api v1.54.2 h1:wiat9QAhnDQjA7wk1kh/TqHz2I1uUA7M7t9SAl/JNXg=
-github.com/moby/moby/api v1.54.2/go.mod h1:+RQ6wluLwtYaTd1WnPLykIDPekkuyD/ROWQClE83pzs=
-github.com/moby/moby/client v0.4.1 h1:DMQgisVoMkmMs7fp3ROSdiBnoAu8+vo3GggFl06M/wY=
-github.com/moby/moby/client v0.4.1/go.mod h1:z52C9O2POPOsnxZAy//WtKcQ32P+jT/NGeXu/7nfjGQ=
+github.com/moby/moby/api v1.55.0 h1:2/sexvQyqIWS8pRSCFddBfpW2qE7vR7FCL+vN8pxwMc=
+github.com/moby/moby/api v1.55.0/go.mod h1:+RQ6wluLwtYaTd1WnPLykIDPekkuyD/ROWQClE83pzs=
+github.com/moby/moby/client v0.5.1 h1:tYNaJno4c0HXz12y5BiqEDy0rVTYkWzI26lGvnTMiJw=
+github.com/moby/moby/client v0.5.1/go.mod h1:odLstlZ6uSnfvAgVxMpvgmb8SUdd+siH2T0GBuxVAlM=
github.com/moby/patternmatcher v0.6.1 h1:qlhtafmr6kgMIJjKJMDmMWq7WLkKIo23hsrpR3x084U=
github.com/moby/patternmatcher v0.6.1/go.mod h1:hDPoyOpDY7OrrMDLaYoY3hf52gNCR/YOUYxkhApJIxc=
github.com/moby/sys/atomicwriter v0.1.0 h1:kw5D/EqkBwsBFi0ss9v1VG3wIkVhzGvLklJ+w3A14Sw=
@@ -1585,8 +1585,8 @@ golang.org/x/lint v0.0.0-20241112194109-818c5a804067/go.mod h1:3xt1FjdF8hUf6vQPI
golang.org/x/mod v0.1.1-0.20191105210325-c90efee705ee/go.mod h1:QqPTAvyqsEbceGzBzNggFXnrqF1CaUcvgkdR5Ot7KZg=
golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4=
-golang.org/x/mod v0.37.0 h1:vF1DjpVEshcIqoEaauuHebaLk1O1forxjxBaVn884JQ=
-golang.org/x/mod v0.37.0/go.mod h1:m8S8VeM9r4dzDwjrKO0a1sZP3YjeMamRRlD+fmR2Q/0=
+golang.org/x/mod v0.38.0 h1:MECBjubtXD7yj4HrhIUcywNaGeNVUdfVnxmPajOk4yk=
+golang.org/x/mod v0.38.0/go.mod h1:V6Xz0pq8TQ3dGqVQ1FVHuelZpAL0uNhSkk9ogYP3c40=
golang.org/x/net v0.0.0-20180724234803-3673e40ba225/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
golang.org/x/net v0.0.0-20180826012351-8a410e7b638d/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
golang.org/x/net v0.0.0-20180906233101-161cd47e91fd/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
@@ -1608,8 +1608,8 @@ golang.org/x/net v0.0.0-20220607020251-c690dde0001d/go.mod h1:XRhObCWvk6IyKnWLug
golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c=
golang.org/x/net v0.6.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs=
golang.org/x/net v0.7.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs=
-golang.org/x/net v0.56.0 h1:Rw8j/hFzGvJUZwNBXnAtf5sVDVt+65SK2C7IxCxZt5o=
-golang.org/x/net v0.56.0/go.mod h1:D3Ku6r+V6JROoZK144D2XfMHFcMq/0zSfLelVTCFKec=
+golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE=
+golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU=
golang.org/x/oauth2 v0.0.0-20180821212333-d2e6202438be/go.mod h1:N/0e6XlmueqKjAGxoOufVs8QHGRruUQn6yWY3a++T0U=
golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs=
golang.org/x/oauth2 v0.36.0/go.mod h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7Q=
@@ -1675,8 +1675,8 @@ golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtn
golang.org/x/tools v0.0.0-20200130002326-2f3ba24bd6e7/go.mod h1:TB2adYChydJhpapKDTa4BR/hXlZSLoq2Wpct/0txZ28=
golang.org/x/tools v0.0.0-20201224043029-2b0845dc783e/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA=
golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc=
-golang.org/x/tools v0.47.0 h1:7Kn5x/d1svx/PzryTsqeoZN4TZwqeH5pGWjefhLi/1Q=
-golang.org/x/tools v0.47.0/go.mod h1:dFHnyTvFWY212G+h7ZY4Vsp/K3U4/7W9TyVaAul8uCA=
+golang.org/x/tools v0.48.0 h1:3+hClM1aLL5mjMKm5ovokw9epgRXPuu2tILgismM6RE=
+golang.org/x/tools v0.48.0/go.mod h1:08xX0orndb/F7jJxGDicx061tyd5pcMto75YMAXr6lk=
golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
From a94eaf63f40780596bef8ce43408ddf5ecbe7488 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:00:16 +0000
Subject: [PATCH 42/70] chore(deps): update module k8s.io/kubectl to v0.36.3
(9.5) (#7792)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [k8s.io/kubectl](https://redirect.github.com/kubernetes/kubectl) |
`v0.36.2` → `v0.36.3` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
kubernetes/kubectl (k8s.io/kubectl)
###
[`v0.36.3`](https://redirect.github.com/kubernetes/kubectl/compare/v0.36.2...v0.36.3)
[Compare
Source](https://redirect.github.com/kubernetes/kubectl/compare/v0.36.2...v0.36.3)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index b0018de5c9..2a0ad04070 100644
--- a/go.mod
+++ b/go.mod
@@ -591,7 +591,7 @@ require (
k8s.io/cli-runtime v0.36.3 // indirect
k8s.io/component-base v0.36.3 // indirect
k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad // indirect
- k8s.io/kubectl v0.36.2 // indirect
+ k8s.io/kubectl v0.36.3 // indirect
k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 // indirect
modernc.org/mathutil v1.7.1 // indirect
modernc.org/memory v1.11.0 // indirect
diff --git a/go.sum b/go.sum
index 8157385fa5..47db9e1442 100644
--- a/go.sum
+++ b/go.sum
@@ -1776,8 +1776,8 @@ k8s.io/klog/v2 v2.140.0 h1:Tf+J3AH7xnUzZyVVXhTgGhEKnFqye14aadWv7bzXdzc=
k8s.io/klog/v2 v2.140.0/go.mod h1:o+/RWfJ6PwpnFn7OyAG3QnO47BFsymfEfrz6XyYSSp0=
k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad h1:oXImqH8mQNk7PmvzKhmN3ddJoY6OnyM225MXwGHPm0A=
k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad/go.mod h1:0/mqHCVhlumdJ3BhCfnjSZQE037nAhNodh1/hK0T8/I=
-k8s.io/kubectl v0.36.2 h1:rpUGGpeL09XVOLep2yle5jrtk//JA1L6ZHfkQQtVEwk=
-k8s.io/kubectl v0.36.2/go.mod h1:gVbQ3B/yb4bSR2ggQ7rd0W6icUSWs7sduH4e16Vii+0=
+k8s.io/kubectl v0.36.3 h1:TesKp+XYQEjPYoFvuobcVnuvira2+/xAVlq//+kksaI=
+k8s.io/kubectl v0.36.3/go.mod h1:W+NEb1CzBGmoaI1Nrpn2ETo9omNBl0AsyxnnMT40N6E=
k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 h1:wU4tMEhLGgIbLvXQb1cfN+EcM0wf7zC6CPF+C79jroc=
k8s.io/utils v0.0.0-20260507154919-ff6756f316d2/go.mod h1:xDxuJ0whA3d0I4mf/C4ppKHxXynQ+fxnkmQH0vTHnuk=
kernel.org/pub/linux/libs/security/libcap/cap v1.2.78 h1:jgqg4gyu2BaYW9L6uzEtGLf8GNREwk/z4UFdwt5F3pE=
From 6b6b7deb6f164a06d9656fd7806e2636e7ae85b1 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:00:31 +0000
Subject: [PATCH 43/70] chore(deps): update module github.com/knadh/koanf/v2 to
v2.3.6 (9.5) (#7778)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/knadh/koanf/v2](https://redirect.github.com/knadh/koanf) |
`v2.3.5` → `v2.3.6` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
knadh/koanf (github.com/knadh/koanf/v2)
###
[`v2.3.6`](https://redirect.github.com/knadh/koanf/releases/tag/v2.3.6)
[Compare
Source](https://redirect.github.com/knadh/koanf/compare/v2.3.5...v2.3.6)
#### What's Changed
- fix: error on scalar/map type mismatch in MergeStrict regardless of
order by [@upuddu](https://redirect.github.com/upuddu) in
[#424](https://redirect.github.com/knadh/koanf/pull/424)
- Bump google.golang.org/grpc from 1.56.3 to 1.82.1 in /examples by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#430](https://redirect.github.com/knadh/koanf/pull/430)
- Bump golang.org/x/crypto from 0.45.0 to 0.52.0 in /providers/kiln by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#427](https://redirect.github.com/knadh/koanf/pull/427)
- deps: upgrade go-toml to v2.4.3 by
[@GreyXor](https://redirect.github.com/GreyXor) in
[#419](https://redirect.github.com/knadh/koanf/pull/419)
- skip disabled secret on azure kv read by
[@genlp](https://redirect.github.com/genlp) in
[#437](https://redirect.github.com/knadh/koanf/pull/437)
#### New Contributors
- [@upuddu](https://redirect.github.com/upuddu) made their first
contribution in
[#424](https://redirect.github.com/knadh/koanf/pull/424)
- [@genlp](https://redirect.github.com/genlp) made their first
contribution in
[#437](https://redirect.github.com/knadh/koanf/pull/437)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 2a0ad04070..bac7339ba3 100644
--- a/go.mod
+++ b/go.mod
@@ -224,7 +224,7 @@ require (
github.com/klauspost/cpuid/v2 v2.4.0 // indirect
github.com/knadh/koanf/maps v0.1.2 // indirect
github.com/knadh/koanf/providers/confmap v1.0.1 // indirect
- github.com/knadh/koanf/v2 v2.3.5 // indirect
+ github.com/knadh/koanf/v2 v2.3.6 // indirect
github.com/lestrrat-go/blackmagic v1.0.4 // indirect
github.com/lestrrat-go/dsig v1.3.0 // indirect
github.com/lestrrat-go/dsig-secp256k1 v1.0.0 // indirect
diff --git a/go.sum b/go.sum
index 47db9e1442..dcbe248446 100644
--- a/go.sum
+++ b/go.sum
@@ -906,8 +906,8 @@ github.com/knadh/koanf/maps v0.1.2 h1:RBfmAW5CnZT+PJ1CVc1QSJKf4Xu9kxfQgYVQSu8hpb
github.com/knadh/koanf/maps v0.1.2/go.mod h1:npD/QZY3V6ghQDdcQzl1W4ICNVTkohC8E73eI2xW4yI=
github.com/knadh/koanf/providers/confmap v1.0.1 h1:L15hbvMqlvhwUuCtL9BkL+rqiMAjk6cZc8O9XoDtE3A=
github.com/knadh/koanf/providers/confmap v1.0.1/go.mod h1:txHYHiI2hAtF0/0sCmcuol4IDcuQbKTybiB1nOcUo1A=
-github.com/knadh/koanf/v2 v2.3.5 h1:2dXJUYaKGm4SGYeoAtBviq9+02JZo/pxQ2ssOd60rJg=
-github.com/knadh/koanf/v2 v2.3.5/go.mod h1:gRb40VRAbd4iJMYYD5IxZ6hfuopFcXBpc9bbQpZwo28=
+github.com/knadh/koanf/v2 v2.3.6 h1:JoQPSJmvS4aP0xNc8xMDr5tcrkSEInL23/Il7pITAKo=
+github.com/knadh/koanf/v2 v2.3.6/go.mod h1:gRb40VRAbd4iJMYYD5IxZ6hfuopFcXBpc9bbQpZwo28=
github.com/knqyf263/go-apk-version v0.0.0-20200609155635-041fdbb8563f h1:GvCU5GXhHq+7LeOzx/haG7HSIZokl3/0GkoUFzsRJjg=
github.com/knqyf263/go-apk-version v0.0.0-20200609155635-041fdbb8563f/go.mod h1:q59u9px8b7UTj0nIjEjvmTWekazka6xIt6Uogz5Dm+8=
github.com/knqyf263/go-deb-version v0.0.0-20241115132648-6f4aee6ccd23 h1:dWzdsqjh1p2gNtRKqNwuBvKqMNwnLOPLzVZT1n6DK7s=
From beff32357eafabab8db1df530310c411239beac4 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:00:52 +0000
Subject: [PATCH 44/70] fix(deps): update module github.com/go-logr/logr to
v1.4.4 (9.5) (#7795)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/go-logr/logr](https://redirect.github.com/go-logr/logr) |
`v1.4.3` → `v1.4.4` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
go-logr/logr (github.com/go-logr/logr)
###
[`v1.4.4`](https://redirect.github.com/go-logr/logr/releases/tag/v1.4.4)
[Compare
Source](https://redirect.github.com/go-logr/logr/compare/v1.4.3...v1.4.4)
#### What's Changed
- drop +build tags by [@pohly](https://redirect.github.com/pohly)
in [#401](https://redirect.github.com/go-logr/logr/pull/401)
- CI: avoid floating dependencies, fix issues by
[@pohly](https://redirect.github.com/pohly) in
[#432](https://redirect.github.com/go-logr/logr/pull/432)
- Bump to Go 1.26 by
[@thockin](https://redirect.github.com/thockin) in
[#445](https://redirect.github.com/go-logr/logr/pull/445)
- funcr: bound slog.Group nesting depth to prevent stack overflow by
[@martinholovsky](https://redirect.github.com/martinholovsky) in
[#447](https://redirect.github.com/go-logr/logr/pull/447)
- funcr: Handle and test recursive values by
[@thockin](https://redirect.github.com/thockin) in
[#446](https://redirect.github.com/go-logr/logr/pull/446)
#### New Contributors
- [@martinholovsky](https://redirect.github.com/martinholovsky)
made their first contribution in
[#447](https://redirect.github.com/go-logr/logr/pull/447)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index bac7339ba3..e462fccac5 100644
--- a/go.mod
+++ b/go.mod
@@ -420,7 +420,7 @@ require (
github.com/go-git/go-billy/v5 v5.9.1 // indirect
github.com/go-gorp/gorp/v3 v3.1.0 // indirect
github.com/go-ini/ini v1.67.0 // indirect
- github.com/go-logr/logr v1.4.3
+ github.com/go-logr/logr v1.4.4
github.com/go-logr/stdr v1.2.2 // indirect
github.com/go-ole/go-ole v1.3.0 // indirect
github.com/go-openapi/analysis v0.25.1 // indirect
diff --git a/go.sum b/go.sum
index dcbe248446..6c9286dd87 100644
--- a/go.sum
+++ b/go.sum
@@ -588,8 +588,8 @@ github.com/go-jose/go-jose/v4 v4.1.4/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9
github.com/go-ldap/ldap/v3 v3.4.13 h1:+x1nG9h+MZN7h/lUi5Q3UZ0fJ1GyDQYbPvbuH38baDQ=
github.com/go-ldap/ldap/v3 v3.4.13/go.mod h1:LxsGZV6vbaK0sIvYfsv47rfh4ca0JXokCoKjZxsszv0=
github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=
-github.com/go-logr/logr v1.4.3 h1:CjnDlHq8ikf6E492q6eKboGOC0T8CDaOvkHCIg8idEI=
-github.com/go-logr/logr v1.4.3/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY=
+github.com/go-logr/logr v1.4.4 h1:tG4xh9yMsRCAiodLVTxyrkzSZ9+o0L1Kg/+cPVcbP/8=
+github.com/go-logr/logr v1.4.4/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY=
github.com/go-logr/stdr v1.2.2 h1:hSWxHoqTgW2S2qGc0LTAI563KZ5YKYRhT3MFKZMbjag=
github.com/go-logr/stdr v1.2.2/go.mod h1:mMo/vtBO5dYbehREoey6XUKy/eSumjCCveDpRre4VKE=
github.com/go-logr/zapr v1.3.0 h1:XGdV8XW8zdwFiwOA2Dryh1gj2KRQyOOoNmBy4EplIcQ=
From cb56104d18457f7b39daa4abf25f196241a1e428 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:01:10 +0000
Subject: [PATCH 45/70] chore(deps): update golang.org/x (9.5) (#7799)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [golang.org/x/crypto](https://pkg.go.dev/golang.org/x/crypto) |
[`v0.53.0` →
`v0.54.0`](https://cs.opensource.google/go/x/crypto/+/refs/tags/v0.53.0...refs/tags/v0.54.0)
|

|

|
| [golang.org/x/mod](https://pkg.go.dev/golang.org/x/mod) | [`v0.37.0` →
`v0.38.0`](https://cs.opensource.google/go/x/mod/+/refs/tags/v0.37.0...refs/tags/v0.38.0)
|

|

|
| [golang.org/x/net](https://pkg.go.dev/golang.org/x/net) | [`v0.56.0` →
`v0.57.0`](https://cs.opensource.google/go/x/net/+/refs/tags/v0.56.0...refs/tags/v0.57.0)
|

|

|
| [golang.org/x/text](https://pkg.go.dev/golang.org/x/text) | [`v0.39.0`
→
`v0.40.0`](https://cs.opensource.google/go/x/text/+/refs/tags/v0.39.0...refs/tags/v0.40.0)
|

|

|
| [golang.org/x/tools](https://pkg.go.dev/golang.org/x/tools) |
[`v0.47.0` →
`v0.48.0`](https://cs.opensource.google/go/x/tools/+/refs/tags/v0.47.0...refs/tags/v0.48.0)
|

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
scripts/update_assets_md/go.mod | 6 +++---
scripts/update_assets_md/go.sum | 12 ++++++------
2 files changed, 9 insertions(+), 9 deletions(-)
diff --git a/scripts/update_assets_md/go.mod b/scripts/update_assets_md/go.mod
index aef3af9286..61aae63236 100644
--- a/scripts/update_assets_md/go.mod
+++ b/scripts/update_assets_md/go.mod
@@ -13,7 +13,7 @@ require (
github.com/tiendc/go-deepcopy v1.7.2 // indirect
github.com/xuri/efp v0.0.1 // indirect
github.com/xuri/nfp v0.0.2-0.20250530014748-2ddeb826f9a9 // indirect
- golang.org/x/crypto v0.53.0 // indirect
- golang.org/x/net v0.56.0 // indirect
- golang.org/x/text v0.39.0 // indirect
+ golang.org/x/crypto v0.54.0 // indirect
+ golang.org/x/net v0.57.0 // indirect
+ golang.org/x/text v0.40.0 // indirect
)
diff --git a/scripts/update_assets_md/go.sum b/scripts/update_assets_md/go.sum
index 123ceba7b4..4151e20081 100644
--- a/scripts/update_assets_md/go.sum
+++ b/scripts/update_assets_md/go.sum
@@ -18,13 +18,13 @@ github.com/xuri/excelize/v2 v2.11.0 h1:HxaEFl6sRN2+8J5a8HaKq+0M4FsjBGMnWWtjOCPSG
github.com/xuri/excelize/v2 v2.11.0/go.mod h1:jxFLbzaIwGQ5ufFNvYfUOHqXhfPaNmP14KWfmNz2Uak=
github.com/xuri/nfp v0.0.2-0.20250530014748-2ddeb826f9a9 h1:+C0TIdyyYmzadGaL/HBLbf3WdLgC29pgyhTjAT/0nuE=
github.com/xuri/nfp v0.0.2-0.20250530014748-2ddeb826f9a9/go.mod h1:WwHg+CVyzlv/TX9xqBFXEZAuxOPxn2k1GNHwG41IIUQ=
-golang.org/x/crypto v0.53.0 h1:QZ4Muo8THX6CizN2vPPd5fBGHyogrdK9fG4wLPFUsto=
-golang.org/x/crypto v0.53.0/go.mod h1:DNLU434OwVakk9PzuwV8w62mAJpRJL3vsgcfp4Qnsio=
+golang.org/x/crypto v0.54.0 h1:YLIA59K4fiNzHzjnZt2tUJQjQtUWfWbeHBqKtk3eScw=
+golang.org/x/crypto v0.54.0/go.mod h1:KWL8ny2AZdGR2cWmzeHrp2azQPGogOv+HeQaVEXC2dk=
golang.org/x/image v0.38.0 h1:5l+q+Y9JDC7mBOMjo4/aPhMDcxEptsX+Tt3GgRQRPuE=
golang.org/x/image v0.38.0/go.mod h1:/3f6vaXC+6CEanU4KJxbcUZyEePbyKbaLoDOe4ehFYY=
-golang.org/x/net v0.56.0 h1:Rw8j/hFzGvJUZwNBXnAtf5sVDVt+65SK2C7IxCxZt5o=
-golang.org/x/net v0.56.0/go.mod h1:D3Ku6r+V6JROoZK144D2XfMHFcMq/0zSfLelVTCFKec=
-golang.org/x/text v0.39.0 h1:UbZz4pLOvn600D6Oh6GGEI6VAmndrEBLv8/6BEXzyus=
-golang.org/x/text v0.39.0/go.mod h1:3UwRclnC2g0TU9x8PZiyfOajCd1zaUNHF9cvqcQZ+ZM=
+golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE=
+golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU=
+golang.org/x/text v0.40.0 h1:Ub2Z6/xjgF1WrYQz2nuITOEegKFtiIy+rieRJ5lHZKs=
+golang.org/x/text v0.40.0/go.mod h1:hpnzDAfGV753zIKo+wk3u1bVKCGPbrnF7+7LBF/UHVY=
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
From aecb37199ddb818b54ab339a541db695cf6928ae Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:02:29 +0000
Subject: [PATCH 46/70] chore(deps): update module
github.com/azuread/microsoft-authentication-library-for-go to v1.8.0 (9.5)
(#7802)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/AzureAD/microsoft-authentication-library-for-go](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go)
| `v1.7.2` → `v1.8.0` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
AzureAD/microsoft-authentication-library-for-go
(github.com/AzureAD/microsoft-authentication-library-for-go)
###
[`v1.8.0`](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go/releases/tag/v1.8.0)
[Compare
Source](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go/compare/v1.7.2...v1.8.0)
#### What's Changed
- Recover from panics in `json.Unmarshal` to prevent token-cache crashes
(fixes
[#579](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go/issues/579))
by [@4gust](https://redirect.github.com/4gust) in
[#614](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go/pull/614)
- fix(base.go): empty partition key causing external cache miss by
[@MatteoCalabro-TomTom](https://redirect.github.com/MatteoCalabro-TomTom)
in
[#615](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go/pull/615)
- Add User Federated Identity Credential (`user_fic`) grant type support
by [@Avery-Dunn](https://redirect.github.com/Avery-Dunn) in
[#619](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go/pull/619)
#### New Contributors
-
[@MatteoCalabro-TomTom](https://redirect.github.com/MatteoCalabro-TomTom)
made their first contribution in
[#615](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go/pull/615)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index e462fccac5..2d459197ba 100644
--- a/go.mod
+++ b/go.mod
@@ -334,7 +334,7 @@ require (
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.1
github.com/Azure/azure-sdk-for-go/sdk/internal v1.12.0 // indirect
github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c // indirect
- github.com/AzureAD/microsoft-authentication-library-for-go v1.7.2 // indirect
+ github.com/AzureAD/microsoft-authentication-library-for-go v1.8.0 // indirect
github.com/BurntSushi/toml v1.6.0 // indirect
github.com/CycloneDX/cyclonedx-go v0.11.0 // indirect
github.com/Jeffail/gabs/v2 v2.7.0 // indirect
diff --git a/go.sum b/go.sum
index 6c9286dd87..c5f9c7b31e 100644
--- a/go.sum
+++ b/go.sum
@@ -99,8 +99,8 @@ github.com/Azure/go-ntlmssp v0.1.1 h1:l+FM/EEMb0U9QZE7mKNEDw5Mu3mFiaa2GKOoTSsNDP
github.com/Azure/go-ntlmssp v0.1.1/go.mod h1:NYqdhxd/8aAct/s4qSYZEerdPuH1liG2/X9DiVTbhpk=
github.com/AzureAD/microsoft-authentication-extensions-for-go/cache v0.1.1 h1:WJTmL004Abzc5wDB5VtZG2PJk5ndYDgVacGqfirKxjM=
github.com/AzureAD/microsoft-authentication-extensions-for-go/cache v0.1.1/go.mod h1:tCcJZ0uHAmvjsVYzEFivsRTN00oz5BEsRgQHu5JZ9WE=
-github.com/AzureAD/microsoft-authentication-library-for-go v1.7.2 h1:RHK7bS+HQMslb1sZpAokUt+zTVmue0hKSs2C791hhzU=
-github.com/AzureAD/microsoft-authentication-library-for-go v1.7.2/go.mod h1:HKpQxkWaGLJ+D/5H8QRpyQXA1eKjxkFlOMwck5+33Jk=
+github.com/AzureAD/microsoft-authentication-library-for-go v1.8.0 h1:Nljr4q1GRA/5vCrMONS+g4u4LRHNgOXVSh3O43J2CnI=
+github.com/AzureAD/microsoft-authentication-library-for-go v1.8.0/go.mod h1:Y33QHnf0FfdVewFFISOGe20mkZbxX4H839o955/PoeI=
github.com/BurntSushi/toml v0.3.1/go.mod h1:xHWCNGjB5oqiDr8zfno3MHue2Ht5sIBksp03qcyfWMU=
github.com/BurntSushi/toml v1.6.0 h1:dRaEfpa2VI55EwlIW72hMRHdWouJeRF7TPYhI+AUQjk=
github.com/BurntSushi/toml v1.6.0/go.mod h1:ukJfTF/6rtPPRCnwkur4qwRxa8vTRFBF0uk2lLoLwho=
From bc712eb3d6f1fb1ba1cfb3cdf5884536c63b395e Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:03:08 +0000
Subject: [PATCH 47/70] chore(deps): update module github.com/coreos/go-oidc/v3
to v3.20.0 (9.5) (#7804)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/coreos/go-oidc/v3](https://redirect.github.com/coreos/go-oidc)
| `v3.19.0` → `v3.20.0` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
coreos/go-oidc (github.com/coreos/go-oidc/v3)
###
[`v3.20.0`](https://redirect.github.com/coreos/go-oidc/releases/tag/v3.20.0)
[Compare
Source](https://redirect.github.com/coreos/go-oidc/compare/v3.19.0...v3.20.0)
#### What's Changed
- oidc: modernize with new Go APIs by
[@ericchiang](https://redirect.github.com/ericchiang) in
[#487](https://redirect.github.com/coreos/go-oidc/pull/487)
- oidc: improve documentation for APIs by
[@ericchiang](https://redirect.github.com/ericchiang) in
[#488](https://redirect.github.com/coreos/go-oidc/pull/488)
- SECURITY.md: add a security policy and point to project-level
reporting by
[@ericchiang](https://redirect.github.com/ericchiang) in
[#489](https://redirect.github.com/coreos/go-oidc/pull/489)
- oidc: ignore JWKs with unknown signing algorithms rather than failing
by [@ericchiang](https://redirect.github.com/ericchiang) in
[#491](https://redirect.github.com/coreos/go-oidc/pull/491)
- readme: update README and docs by
[@ericchiang](https://redirect.github.com/ericchiang) in
[#492](https://redirect.github.com/coreos/go-oidc/pull/492)
- oidc: add API for determining when issuer URLs mismatch by
[@ericchiang](https://redirect.github.com/ericchiang) in
[#493](https://redirect.github.com/coreos/go-oidc/pull/493)
- oidc: add constants for "email" and "profile" scopes by
[@ericchiang](https://redirect.github.com/ericchiang) in
[#494](https://redirect.github.com/coreos/go-oidc/pull/494)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 2d459197ba..d9cd441d54 100644
--- a/go.mod
+++ b/go.mod
@@ -163,7 +163,7 @@ require (
github.com/containerd/log v0.1.0 // indirect
github.com/containerd/platforms v1.0.0-rc.4 // indirect
github.com/containerd/plugin v1.1.0 // indirect
- github.com/coreos/go-oidc/v3 v3.19.0 // indirect
+ github.com/coreos/go-oidc/v3 v3.20.0 // indirect
github.com/cyberphone/json-canonicalization v0.0.0-20241213102144-19d51d7fe467 // indirect
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.1 // indirect
github.com/digitorus/pkcs7 v0.0.0-20250730155240-ffadbf3f398c // indirect
diff --git a/go.sum b/go.sum
index c5f9c7b31e..aaa1a152d5 100644
--- a/go.sum
+++ b/go.sum
@@ -383,8 +383,8 @@ github.com/containerd/ttrpc v1.2.9 h1:ha0ak962T0s3CA/RoZ6S6xiWZQF24GrBaEpiGX1uih
github.com/containerd/ttrpc v1.2.9/go.mod h1:jjtQRwXm4DL3KsHKW8vDiUOV6wO0hi6IPhmJhxU7aEs=
github.com/containerd/typeurl/v2 v2.3.0 h1:HZHPhRWo5XMy3QGQoPrUzbW/2ckwjfweHmOwlkIrPAQ=
github.com/containerd/typeurl/v2 v2.3.0/go.mod h1:Qk+PAdUYArVj41TnGi6rJ+48RF0PkcTc4i/taoBcK0w=
-github.com/coreos/go-oidc/v3 v3.19.0 h1:F/xyOi3x1UnG1U27YVnM1N6bHiL1K2upi6U/0qr8r+I=
-github.com/coreos/go-oidc/v3 v3.19.0/go.mod h1:DYCf24+ncYi+XkIH97GY1+dqoRlbaSI26KVTCI9SrY4=
+github.com/coreos/go-oidc/v3 v3.20.0 h1:EtE0WIBHk03N+DqGkY4+UONzzZHk7amKt6IyNd7OsZE=
+github.com/coreos/go-oidc/v3 v3.20.0/go.mod h1:DYCf24+ncYi+XkIH97GY1+dqoRlbaSI26KVTCI9SrY4=
github.com/coreos/go-systemd v0.0.0-20180511133405-39ca1b05acc7 h1:u9SHYsPQNyt5tgDm3YN7+9dYrpK96E5wFilTFWIDZOM=
github.com/coreos/go-systemd/v22 v22.7.0 h1:LAEzFkke61DFROc7zNLX/WA2i5J8gYqe0rSj9KI28KA=
github.com/coreos/go-systemd/v22 v22.7.0/go.mod h1:xNUYtjHu2EDXbsxz1i41wouACIwT7Ybq9o0BQhMwD0w=
From 7f07de645e42ce908ea1c60ba933b6fa3a316546 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:03:18 +0000
Subject: [PATCH 48/70] chore(deps): update module github.com/cheggaaa/pb/v3 to
v3.2.0 (9.5) (#7803)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/cheggaaa/pb/v3](https://redirect.github.com/cheggaaa/pb) |
`v3.1.7` → `v3.2.0` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
cheggaaa/pb (github.com/cheggaaa/pb/v3)
###
[`v3.2.0`](https://redirect.github.com/cheggaaa/pb/compare/v3.1.7...v3.2.0)
[Compare
Source](https://redirect.github.com/cheggaaa/pb/compare/v3.1.7...v3.2.0)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index d9cd441d54..1b484534b7 100644
--- a/go.mod
+++ b/go.mod
@@ -382,7 +382,7 @@ require (
github.com/cenkalti/backoff/v4 v4.3.0 // indirect
github.com/cespare/xxhash/v2 v2.3.0 // indirect
github.com/chai2010/gettext-go v1.0.3 // indirect
- github.com/cheggaaa/pb/v3 v3.1.7 // indirect
+ github.com/cheggaaa/pb/v3 v3.2.0 // indirect
github.com/cloudflare/circl v1.6.5 // indirect
github.com/containerd/continuity v0.5.0 // indirect
github.com/containerd/fifo v1.1.0 // indirect
diff --git a/go.sum b/go.sum
index aaa1a152d5..d118a5f52a 100644
--- a/go.sum
+++ b/go.sum
@@ -342,8 +342,8 @@ github.com/cespare/xxhash/v2 v2.3.0 h1:UL815xU9SqsFlibzuggzjXhog7bL6oX9BbNZnL2UF
github.com/cespare/xxhash/v2 v2.3.0/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs=
github.com/chai2010/gettext-go v1.0.3 h1:9liNh8t+u26xl5ddmWLmsOsdNLwkdRTg5AG+JnTiM80=
github.com/chai2010/gettext-go v1.0.3/go.mod h1:y+wnP2cHYaVj19NZhYKAwEMH2CI1gNHeQQ+5AjwawxA=
-github.com/cheggaaa/pb/v3 v3.1.7 h1:2FsIW307kt7A/rz/ZI2lvPO+v3wKazzE4K/0LtTWsOI=
-github.com/cheggaaa/pb/v3 v3.1.7/go.mod h1:/Ji89zfVPeC/u5j8ukD0MBPHt2bzTYp74lQ7KlgFWTQ=
+github.com/cheggaaa/pb/v3 v3.2.0 h1:ziC7JV5/Ge2iZNa9ckxdXBxHHyPgC+p/QGzhWRoPlHU=
+github.com/cheggaaa/pb/v3 v3.2.0/go.mod h1:KtXGzgipYGqY3avGtFmlQTgiT88AEFvc1LvPk7oA9fM=
github.com/chzyer/logex v1.1.10/go.mod h1:+Ywpsq7O8HXn0nuIou7OrIPyXbp3wmkHB+jjWRnGsAI=
github.com/chzyer/readline v0.0.0-20180603132655-2972be24d48e/go.mod h1:nSuG5e5PlCu98SY8svDHJxuZscDgtXS6KTTbou5AhLI=
github.com/chzyer/test v0.0.0-20180213035817-a1ea475d72b1/go.mod h1:Q3SI9o4m/ZMnBNeIyt5eFwwo7qiLfzFZmjNmxjkiQlU=
From b8eb7df142d1f49f0b6a886cb3391ebb2a52ff96 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:04:22 +0000
Subject: [PATCH 49/70] chore(deps): update module
github.com/googlecloudplatform/opentelemetry-operations-go/detectors/gcp to
v1.35.0 (9.5) (#7808)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go)
| `v1.33.0` → `v1.35.0` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 1b484534b7..cc687c4568 100644
--- a/go.mod
+++ b/go.mod
@@ -16,7 +16,7 @@ require (
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/security/armsecurity v0.15.0
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/sql/armsql v1.2.0
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/storage/armstorage/v3 v3.0.0
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.33.0 // indirect
+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.35.0 // indirect
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.57.0 // indirect
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.57.0 // indirect
github.com/aquasecurity/go-dep-parser v0.0.0-20240606050805-1de9a375c629
diff --git a/go.sum b/go.sum
index d118a5f52a..075a039776 100644
--- a/go.sum
+++ b/go.sum
@@ -114,8 +114,8 @@ github.com/Flaque/filet v0.0.0-20201012163910-45f684403088 h1:PnnQln5IGbhLeJOi6h
github.com/Flaque/filet v0.0.0-20201012163910-45f684403088/go.mod h1:TK+jB3mBs+8ZMWhU5BqZKnZWJ1MrLo8etNVg51ueTBo=
github.com/GoogleCloudPlatform/docker-credential-gcr/v2 v2.1.32 h1:osnkVtr2sms/pE+rwAAsn0VZUAr1AAEaJYbiW3YY5Zs=
github.com/GoogleCloudPlatform/docker-credential-gcr/v2 v2.1.32/go.mod h1:uX2CoogLFWSxfoPl17CT9rMoHlv3RTYudvfNn/d/aOo=
-github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.33.0 h1:l7+6kwRMJNwdCvYdDl7Eax+wzEYHSnNY7zrrfbhDdTA=
-github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.33.0/go.mod h1:pJTkW8hEUIIi3Pf65lPZOnn4Y81yCllX6IWk2jNXdkM=
+github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.35.0 h1:bN1gA3of5bXtbnLsRPrwfmbbe7A5UWFlcTHseujLnpc=
+github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.35.0/go.mod h1:Yj5vHEz/aAepZGliRJsA6uvHAVAQyEwajq9ORCHPxzM=
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.57.0 h1:jLdiS1vO+XJFyDSWRHBx56r4s/NNtcl5J6KyCcWUX/w=
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.57.0/go.mod h1:8lmpHY+1VRoteiOwyrQMDt1YGXOrFKCz+1wJW7n3ODY=
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock v0.57.0 h1:cSjUzZ7KU8hicTgzaSv9NmSyM9fTVK3y5lsBUl3wOis=
From d2495b25c6d90b3f8cae6f9da842c2c638b15e40 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:05:06 +0000
Subject: [PATCH 50/70] chore(deps): update module github.com/gofrs/uuid/v5 to
v5.5.1 (9.5) (#7806)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/gofrs/uuid/v5](https://redirect.github.com/gofrs/uuid) |
`v5.4.0` → `v5.5.1` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
gofrs/uuid (github.com/gofrs/uuid/v5)
###
[`v5.5.1`](https://redirect.github.com/gofrs/uuid/releases/tag/v5.5.1)
[Compare
Source](https://redirect.github.com/gofrs/uuid/compare/v5.5.0...v5.5.1)
#### What's Changed
- Fix integer overflow on 32bit architectures by
[@gibmat](https://redirect.github.com/gibmat) in
[#257](https://redirect.github.com/gofrs/uuid/pull/257)
- Update README.md to remove go report card by
[@cameracker](https://redirect.github.com/cameracker) in
[#255](https://redirect.github.com/gofrs/uuid/pull/255)
- build(deps): bump the all group with 7 updates by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#256](https://redirect.github.com/gofrs/uuid/pull/256)
#### New Contributors
- [@gibmat](https://redirect.github.com/gibmat) made their first
contribution in
[#257](https://redirect.github.com/gofrs/uuid/pull/257)
**Full Changelog**:
###
[`v5.5.0`](https://redirect.github.com/gofrs/uuid/releases/tag/v5.5.0)
[Compare
Source](https://redirect.github.com/gofrs/uuid/compare/v5.4.0...v5.5.0)
#### What's Changed
- fix: prevent UUIDv7 counter wrap after 4096 ids by
[@mistermoe](https://redirect.github.com/mistermoe) in
[#253](https://redirect.github.com/gofrs/uuid/pull/253)
- perf: Improve error handling performance by removing expensive
formatting by [@AmritM18](https://redirect.github.com/AmritM18)
in [#247](https://redirect.github.com/gofrs/uuid/pull/247)
- Feature/uuidv8 by
[@cameracker](https://redirect.github.com/cameracker) in
[#241](https://redirect.github.com/gofrs/uuid/pull/241)
#### New Contributors
- [@AmritM18](https://redirect.github.com/AmritM18) made their
first contribution in
[#247](https://redirect.github.com/gofrs/uuid/pull/247)
- [@mistermoe](https://redirect.github.com/mistermoe) made their
first contribution in
[#253](https://redirect.github.com/gofrs/uuid/pull/253)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index cc687c4568..8eba9bc717 100644
--- a/go.mod
+++ b/go.mod
@@ -202,7 +202,7 @@ require (
github.com/go-openapi/swag/typeutils v0.27.1 // indirect
github.com/go-openapi/swag/yamlutils v0.27.1 // indirect
github.com/gocsaf/csaf/v3 v3.5.1 // indirect
- github.com/gofrs/uuid/v5 v5.4.0 // indirect
+ github.com/gofrs/uuid/v5 v5.5.1 // indirect
github.com/gohugoio/hashstructure v0.6.0 // indirect
github.com/google/certificate-transparency-go v1.3.3 // indirect
github.com/google/gnostic-models v0.7.1 // indirect
diff --git a/go.sum b/go.sum
index 075a039776..1b5e52f058 100644
--- a/go.sum
+++ b/go.sum
@@ -682,8 +682,8 @@ github.com/gofrs/flock v0.13.0 h1:95JolYOvGMqeH31+FC7D2+uULf6mG61mEZ/A8dRYMzw=
github.com/gofrs/flock v0.13.0/go.mod h1:jxeyy9R1auM5S6JYDBhDt+E2TCo7DkratH4Pgi8P+Z0=
github.com/gofrs/uuid v4.4.0+incompatible h1:3qXRTX8/NbyulANqlc0lchS1gqAVxRgsuW1YrTJupqA=
github.com/gofrs/uuid v4.4.0+incompatible/go.mod h1:b2aQJv3Z4Fp6yNu3cdSllBxTCLRxnplIgP/c0N/04lM=
-github.com/gofrs/uuid/v5 v5.4.0 h1:EfbpCTjqMuGyq5ZJwxqzn3Cbr2d0rUZU7v5ycAk/e/0=
-github.com/gofrs/uuid/v5 v5.4.0/go.mod h1:CDOjlDMVAtN56jqyRUZh58JT31Tiw7/oQyEXZV+9bD8=
+github.com/gofrs/uuid/v5 v5.5.1 h1:z1Ce19/JwNidXpy3tOQc3241lnJLKdKyq/xlNvlD4Ng=
+github.com/gofrs/uuid/v5 v5.5.1/go.mod h1:bbAA98EoIlxyRHIVg6ektCSsZ5n8mSbwgEhvhMYlZgg=
github.com/gohugoio/hashstructure v0.6.0 h1:7wMB/2CfXoThFYhdWRGv3u3rUM761Cq29CxUW+NltUg=
github.com/gohugoio/hashstructure v0.6.0/go.mod h1:lapVLk9XidheHG1IQ4ZSbyYrXcaILU1ZEP/+vno5rBQ=
github.com/golang-jwt/jwt/v4 v4.5.2 h1:YtQM7lnr8iZ+j5q71MGKkNw9Mn7AjHM68uc9g5fXeUI=
From 42af012ca1f628f8daab16b20146e47786cf775f Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:05:20 +0000
Subject: [PATCH 51/70] chore(deps): update module
github.com/letsencrypt/boulder to v0.20260804.0 (9.5) (#7813)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/letsencrypt/boulder](https://redirect.github.com/letsencrypt/boulder)
| `v0.20260630.0` → `v0.20260804.0` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
letsencrypt/boulder (github.com/letsencrypt/boulder)
###
[`v0.20260804.0`](https://redirect.github.com/letsencrypt/boulder/releases/tag/v0.20260804.0)
[Compare
Source](https://redirect.github.com/letsencrypt/boulder/compare/v0.20260729.0...v0.20260804.0)
#### What's Changed
- privatekey: Return a deterministic crypto.Signer from verifyMLDSA by
[@beautifulentropy](https://redirect.github.com/beautifulentropy)
in
[#8926](https://redirect.github.com/letsencrypt/boulder/pull/8926)
- cert-checker: configure issuers for CP/CPS lints by
[@aarongable](https://redirect.github.com/aarongable) in
[#8927](https://redirect.github.com/letsencrypt/boulder/pull/8927)
- unsigned: implement RFC 9925 by
[@jsha](https://redirect.github.com/jsha) in
[#8901](https://redirect.github.com/letsencrypt/boulder/pull/8901)
- trees/cosignature: Address remaining comments from
[#8904](https://redirect.github.com/letsencrypt/boulder/issues/8904)
by
[@beautifulentropy](https://redirect.github.com/beautifulentropy)
in
[#8928](https://redirect.github.com/letsencrypt/boulder/pull/8928)
- build(deps): bump github/codeql-action/analyze from 4.36.2 to 4.37.3
by [@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#8929](https://redirect.github.com/letsencrypt/boulder/pull/8929)
- observer: ccadb: check reported CRL shards for completeness by
[@inahga](https://redirect.github.com/inahga) in
[#8890](https://redirect.github.com/letsencrypt/boulder/pull/8890)
- Remove sa.FQDNSetExists dead code by
[@ezekiel](https://redirect.github.com/ezekiel) in
[#8888](https://redirect.github.com/letsencrypt/boulder/pull/8888)
**Full Changelog**:
###
[`v0.20260729.0`](https://redirect.github.com/letsencrypt/boulder/releases/tag/v0.20260729.0)
[Compare
Source](https://redirect.github.com/letsencrypt/boulder/compare/v0.20260728.0...v0.20260729.0)
#### What's Changed
- Update grpc to v1.82.1 by
[@jsha](https://redirect.github.com/jsha) in
[#8910](https://redirect.github.com/letsencrypt/boulder/pull/8910)
- Update CODEOWNERS by
[@aarongable](https://redirect.github.com/aarongable) in
[#8921](https://redirect.github.com/letsencrypt/boulder/pull/8921)
- mtca: write to tiles by
[@jsha](https://redirect.github.com/jsha) in
[#8900](https://redirect.github.com/letsencrypt/boulder/pull/8900)
- Move GenerateSKID into Core for sharing across ca, ceremony, and lints
by [@aarongable](https://redirect.github.com/aarongable) in
[#8922](https://redirect.github.com/letsencrypt/boulder/pull/8922)
- Remove the ability to issue id-kp-clientAuth certificates by
[@aarongable](https://redirect.github.com/aarongable) in
[#8925](https://redirect.github.com/letsencrypt/boulder/pull/8925)
- proof: implement MTCProof by
[@jsha](https://redirect.github.com/jsha) in
[#8907](https://redirect.github.com/letsencrypt/boulder/pull/8907)
- trees/cosignature: Sign and verify MTC checkpoint cosignatures by
[@beautifulentropy](https://redirect.github.com/beautifulentropy)
in
[#8904](https://redirect.github.com/letsencrypt/boulder/pull/8904)
- entry: add MTCLogEntry.ToTBSCertificate() by
[@jsha](https://redirect.github.com/jsha) in
[#8908](https://redirect.github.com/letsencrypt/boulder/pull/8908)
- Create scaffolding for configuring lints with issuers by
[@aarongable](https://redirect.github.com/aarongable) in
[#8923](https://redirect.github.com/letsencrypt/boulder/pull/8923)
**Full Changelog**:
###
[`v0.20260728.0`](https://redirect.github.com/letsencrypt/boulder/releases/tag/v0.20260728.0)
[Compare
Source](https://redirect.github.com/letsencrypt/boulder/compare/v0.20260720.0...v0.20260728.0)
#### What's Changed
- observer: ccadb: use less RAM by
[@inahga](https://redirect.github.com/inahga) in
[#8892](https://redirect.github.com/letsencrypt/boulder/pull/8892)
- Remove GetRevocationStatus dead code by
[@aarongable](https://redirect.github.com/aarongable) in
[#8884](https://redirect.github.com/letsencrypt/boulder/pull/8884)
- bad-key-revoker: also revoke accounts with blocked keys by
[@aarongable](https://redirect.github.com/aarongable) in
[#8837](https://redirect.github.com/letsencrypt/boulder/pull/8837)
- Update golang.org/x/text to v0.39.0 by
[@aarongable](https://redirect.github.com/aarongable) in
[#8897](https://redirect.github.com/letsencrypt/boulder/pull/8897)
- Rename Authz IdInt fields to plain Id. by
[@ezekiel](https://redirect.github.com/ezekiel) in
[#8893](https://redirect.github.com/letsencrypt/boulder/pull/8893)
- ra/sa: Prevent parallel validation attempts by
[@aarongable](https://redirect.github.com/aarongable) in
[#8838](https://redirect.github.com/letsencrypt/boulder/pull/8838)
- Ceremony: generate serials with a prefix to guarantee length by
[@aarongable](https://redirect.github.com/aarongable) in
[#8899](https://redirect.github.com/letsencrypt/boulder/pull/8899)
- mtca: add profile and run Prepare by
[@jsha](https://redirect.github.com/jsha) in
[#8886](https://redirect.github.com/letsencrypt/boulder/pull/8886)
- tiles: add Frontier to read/write tiles by
[@jsha](https://redirect.github.com/jsha) in
[#8896](https://redirect.github.com/letsencrypt/boulder/pull/8896)
- Update otel to v1.44.0 by
[@jsha](https://redirect.github.com/jsha) in
[#8906](https://redirect.github.com/letsencrypt/boulder/pull/8906)
**Full Changelog**:
###
[`v0.20260720.0`](https://redirect.github.com/letsencrypt/boulder/releases/tag/v0.20260720.0)
[Compare
Source](https://redirect.github.com/letsencrypt/boulder/compare/v0.20260713.0...v0.20260720.0)
#### What's Changed
- trees/checkpoint: Add checkpoint.Checkpoint by
[@beautifulentropy](https://redirect.github.com/beautifulentropy)
in
[#8830](https://redirect.github.com/letsencrypt/boulder/pull/8830)
- sa: use tx object in AddPrecertificate by
[@jsha](https://redirect.github.com/jsha) in
[#8865](https://redirect.github.com/letsencrypt/boulder/pull/8865)
- observer: Fix possible panic in TLSProbe check by
[@beautifulentropy](https://redirect.github.com/beautifulentropy)
in
[#8836](https://redirect.github.com/letsencrypt/boulder/pull/8836)
- trees/subtree: Generate and verify MTC subtree consistency proofs by
[@beautifulentropy](https://redirect.github.com/beautifulentropy)
in
[#8808](https://redirect.github.com/letsencrypt/boulder/pull/8808)
- minio: self-initialize container by
[@jsha](https://redirect.github.com/jsha) in
[#8880](https://redirect.github.com/letsencrypt/boulder/pull/8880)
- Remove all string ID fields for Authzs. by
[@ezekiel](https://redirect.github.com/ezekiel) in
[#8828](https://redirect.github.com/letsencrypt/boulder/pull/8828)
- crl-storer: factor out S3 config and initialization by
[@jsha](https://redirect.github.com/jsha) in
[#8873](https://redirect.github.com/letsencrypt/boulder/pull/8873)
- test: run unittests under gotip when appropriate by
[@jsha](https://redirect.github.com/jsha) in
[#8883](https://redirect.github.com/letsencrypt/boulder/pull/8883)
- linter: pass through RawSubject by
[@jsha](https://redirect.github.com/jsha) in
[#8869](https://redirect.github.com/letsencrypt/boulder/pull/8869)
- mtca: add sequencing by
[@jsha](https://redirect.github.com/jsha) in
[#8826](https://redirect.github.com/letsencrypt/boulder/pull/8826)
- issuance: add ProfileConfig.MTC by
[@jsha](https://redirect.github.com/jsha) in
[#8868](https://redirect.github.com/letsencrypt/boulder/pull/8868)
- Update publicsuffix-go by
[@rellem](https://redirect.github.com/rellem) in
[#8882](https://redirect.github.com/letsencrypt/boulder/pull/8882)
- entry: add MTCLogEntry, TBSCertificateLogEntry by
[@jsha](https://redirect.github.com/jsha) in
[#8867](https://redirect.github.com/letsencrypt/boulder/pull/8867)
- mtca: add S3 connection by
[@jsha](https://redirect.github.com/jsha) in
[#8885](https://redirect.github.com/letsencrypt/boulder/pull/8885)
#### New Contributors
- [@rellem](https://redirect.github.com/rellem) made their first
contribution in
[#8882](https://redirect.github.com/letsencrypt/boulder/pull/8882)
**Full Changelog**:
###
[`v0.20260713.0`](https://redirect.github.com/letsencrypt/boulder/releases/tag/v0.20260713.0)
[Compare
Source](https://redirect.github.com/letsencrypt/boulder/compare/v0.20260707.0...v0.20260713.0)
#### What's Changed
- test.sh: Anchor the grep pattern used to exclude one package. by
[@ezekiel](https://redirect.github.com/ezekiel) in
[#8863](https://redirect.github.com/letsencrypt/boulder/pull/8863)
- Don't exit on failure if cert-checker finds bad certs by
[@lenaunderwood22](https://redirect.github.com/lenaunderwood22)
in
[#8866](https://redirect.github.com/letsencrypt/boulder/pull/8866)
- Use DialerRetries from config file in redis RingOptions. by
[@ezekiel](https://redirect.github.com/ezekiel) in
[#8864](https://redirect.github.com/letsencrypt/boulder/pull/8864)
- bdns: error when CAA query response is truncated by
[@Preston12321](https://redirect.github.com/Preston12321) in
[#8839](https://redirect.github.com/letsencrypt/boulder/pull/8839)
- Add conversation resolution requirement to CONTRIBUTING.md. by
[@ezekiel](https://redirect.github.com/ezekiel) in
[#8860](https://redirect.github.com/letsencrypt/boulder/pull/8860)
- Observer: add jitter to each monitor to prevent stampedes by
[@aarongable](https://redirect.github.com/aarongable) in
[#8872](https://redirect.github.com/letsencrypt/boulder/pull/8872)
**Full Changelog**:
###
[`v0.20260707.0`](https://redirect.github.com/letsencrypt/boulder/releases/tag/v0.20260707.0)
[Compare
Source](https://redirect.github.com/letsencrypt/boulder/compare/v0.20260630.0...v0.20260707.0)
#### What's Changed
- trees/cosigned: Add cosigned.Message by
[@jsha](https://redirect.github.com/jsha) in
[#8819](https://redirect.github.com/letsencrypt/boulder/pull/8819)
- admin: close files after reading by
[@aarongable](https://redirect.github.com/aarongable) in
[#8835](https://redirect.github.com/letsencrypt/boulder/pull/8835)
- linter: check that CRL issuers match issuer subjects byte-for-byte by
[@Preston12321](https://redirect.github.com/Preston12321) in
[#8827](https://redirect.github.com/letsencrypt/boulder/pull/8827)
- cert-checker: Allow scraping pprof data by
[@beautifulentropy](https://redirect.github.com/beautifulentropy)
in
[#8833](https://redirect.github.com/letsencrypt/boulder/pull/8833)
- Revert "Replace log package with fully slog-based system" by
[@aarongable](https://redirect.github.com/aarongable) in
[#8853](https://redirect.github.com/letsencrypt/boulder/pull/8853)
- build(deps): bump actions/setup-go from 6.4.0 to 6.5.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#8831](https://redirect.github.com/letsencrypt/boulder/pull/8831)
- Pivot WFE around the string(authzID) to int64(authzID) type change. by
[@ezekiel](https://redirect.github.com/ezekiel) in
[#8856](https://redirect.github.com/letsencrypt/boulder/pull/8856)
- ca: add per-profile MaxCertificateSize by
[@jsha](https://redirect.github.com/jsha) in
[#8806](https://redirect.github.com/letsencrypt/boulder/pull/8806)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 10 +++++-----
go.sum | 20 ++++++++++----------
2 files changed, 15 insertions(+), 15 deletions(-)
diff --git a/go.mod b/go.mod
index 8eba9bc717..47d34adfa9 100644
--- a/go.mod
+++ b/go.mod
@@ -90,14 +90,14 @@ require (
go.opentelemetry.io/contrib/instrumentation/github.com/aws/aws-sdk-go-v2/otelaws v0.68.0
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.68.0 // indirect
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.68.0 // indirect
- go.opentelemetry.io/otel v1.43.0
+ go.opentelemetry.io/otel v1.44.0
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.43.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 // indirect
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0
- go.opentelemetry.io/otel/metric v1.43.0 // indirect
+ go.opentelemetry.io/otel/metric v1.44.0 // indirect
go.opentelemetry.io/otel/sdk v1.43.0
go.opentelemetry.io/otel/sdk/metric v1.43.0
- go.opentelemetry.io/otel/trace v1.43.0
+ go.opentelemetry.io/otel/trace v1.44.0
go.opentelemetry.io/proto/otlp v1.10.0
go.uber.org/goleak v1.3.0
go.uber.org/zap v1.28.0
@@ -232,7 +232,7 @@ require (
github.com/lestrrat-go/httprc/v3 v3.0.6 // indirect
github.com/lestrrat-go/jwx/v3 v3.1.1 // indirect
github.com/lestrrat-go/option/v2 v2.0.0 // indirect
- github.com/letsencrypt/boulder v0.20260630.0 // indirect
+ github.com/letsencrypt/boulder v0.20260804.0 // indirect
github.com/mattn/go-shellwords v1.0.14 // indirect
github.com/microsoft/kiota-authentication-azure-go v1.3.1 // indirect
github.com/microsoft/kiota-http-go v1.5.6 // indirect
@@ -581,7 +581,7 @@ require (
google.golang.org/genproto v0.0.0-20260706201446-f0a921348800 // indirect
google.golang.org/genproto/googleapis/api v0.0.0-20260706201446-f0a921348800 // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800 // indirect
- google.golang.org/grpc v1.82.0
+ google.golang.org/grpc v1.82.1
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af
gopkg.in/inf.v0 v0.9.1 // indirect
gopkg.in/warnings.v0 v0.1.2 // indirect
diff --git a/go.sum b/go.sum
index 1b5e52f058..a22484613e 100644
--- a/go.sum
+++ b/go.sum
@@ -947,8 +947,8 @@ github.com/lestrrat-go/option/v2 v2.0.0 h1:XxrcaJESE1fokHy3FpaQ/cXW8ZsIdWcdFzzLO
github.com/lestrrat-go/option/v2 v2.0.0/go.mod h1:oSySsmzMoR0iRzCDCaUfsCzxQHUEuhOViQObyy7S6Vg=
github.com/lestrrat-go/strftime v1.1.1 h1:zgf8QCsgj27GlKBy3SU9/8MMgegZ8UCzlCyHYrUF0QU=
github.com/lestrrat-go/strftime v1.1.1/go.mod h1:YDrzHJAODYQ+xxvrn5SG01uFIQAeDTzpxNVppCz7Nmw=
-github.com/letsencrypt/boulder v0.20260630.0 h1:+HUzjdVOoT1rTXlGAKfC6NVHcGe5UJ7rgcyXj74eRVo=
-github.com/letsencrypt/boulder v0.20260630.0/go.mod h1:ndln2OL/W/CUm5uqAIZttqw6mldD/7ie8LLfAdJ92y8=
+github.com/letsencrypt/boulder v0.20260804.0 h1:okROEcsDfzgJzPv8F1XpvuoFfzvorbHX02dfOhNFAKE=
+github.com/letsencrypt/boulder v0.20260804.0/go.mod h1:ZnVUajYh/w/W9rZA5IaLGq7nXN7haSz14lQqtbCyiNQ=
github.com/lib/pq v1.10.9/go.mod h1:AlVN5x4E4T544tWzH6hKfbfQvm3HdbOxrmggDNAPY9o=
github.com/lib/pq v1.12.3 h1:tTWxr2YLKwIvK90ZXEw8GP7UFHtcbTtty8zsI+YjrfQ=
github.com/lib/pq v1.12.3/go.mod h1:/p+8NSbOcwzAEI7wiMXFlgydTwcgTr3OSKMsD2BitpA=
@@ -1502,8 +1502,8 @@ go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.68.0 h1:CqXxU8V
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.68.0/go.mod h1:BuhAPThV8PBHBvg8ZzZ/Ok3idOdhWIodywz2xEcRbJo=
go.opentelemetry.io/ebpf-profiler v0.0.202618 h1:4r2HSY8cLb3HoI0TcHtIFws3a2pLOWVvjB4pvGfU+Yc=
go.opentelemetry.io/ebpf-profiler v0.0.202618/go.mod h1:kAIjd+XsfWpzoQdpiiJtQuQHV4cPNgeNpbbiAgNCQ8A=
-go.opentelemetry.io/otel v1.43.0 h1:mYIM03dnh5zfN7HautFE4ieIig9amkNANT+xcVxAj9I=
-go.opentelemetry.io/otel v1.43.0/go.mod h1:JuG+u74mvjvcm8vj8pI5XiHy1zDeoCS2LB1spIq7Ay0=
+go.opentelemetry.io/otel v1.44.0 h1:JjwHmHpA4iZ3wBxluu2fbbE7j4kqlE8jXyAyPXH7HqU=
+go.opentelemetry.io/otel v1.44.0/go.mod h1:BMgjTHL9WPRlRjL2oZCBTL4whCGtXch2H4BhOPIAyYc=
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 h1:Dn8rkudDzY6KV9dr/D/bTUuWgqDf9xe0rr4G2elrn0Y=
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0/go.mod h1:gMk9F0xDgyN9M/3Ed5Y1wKcx/9mlU91NXY2SNq7RQuU=
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp v0.19.0 h1:HIBTQ3VO5aupLKjC90JgMqpezVXwFuq6Ryjn0/izoag=
@@ -1529,16 +1529,16 @@ go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.43.0 h1:mS47AX77OtFfKG4
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.43.0/go.mod h1:PJnsC41lAGncJlPUniSwM81gc80GkgWJWr3cu2nKEtU=
go.opentelemetry.io/otel/log v0.19.0 h1:KUZs/GOsw79TBBMfDWsXS+KZ4g2Ckzksd1ymzsIEbo4=
go.opentelemetry.io/otel/log v0.19.0/go.mod h1:5DQYeGmxVIr4n0/BcJvF4upsraHjg6vudJJpnkL6Ipk=
-go.opentelemetry.io/otel/metric v1.43.0 h1:d7638QeInOnuwOONPp4JAOGfbCEpYb+K6DVWvdxGzgM=
-go.opentelemetry.io/otel/metric v1.43.0/go.mod h1:RDnPtIxvqlgO8GRW18W6Z/4P462ldprJtfxHxyKd2PY=
+go.opentelemetry.io/otel/metric v1.44.0 h1:1w0gILTcHdr3YI+ixLyjemwrVnsMURbTZFrSYCdDdmc=
+go.opentelemetry.io/otel/metric v1.44.0/go.mod h1:8O7hanEPBNgEMmybD3s2VBKcgWOCsA6tzHBPODAiquo=
go.opentelemetry.io/otel/sdk v1.43.0 h1:pi5mE86i5rTeLXqoF/hhiBtUNcrAGHLKQdhg4h4V9Dg=
go.opentelemetry.io/otel/sdk v1.43.0/go.mod h1:P+IkVU3iWukmiit/Yf9AWvpyRDlUeBaRg6Y+C58QHzg=
go.opentelemetry.io/otel/sdk/log v0.19.0 h1:scYVLqT22D2gqXItnWiocLUKGH9yvkkeql5dBDiXyko=
go.opentelemetry.io/otel/sdk/log v0.19.0/go.mod h1:vFBowwXGLlW9AvpuF7bMgnNI95LiW10szrOdvzBHlAg=
go.opentelemetry.io/otel/sdk/metric v1.43.0 h1:S88dyqXjJkuBNLeMcVPRFXpRw2fuwdvfCGLEo89fDkw=
go.opentelemetry.io/otel/sdk/metric v1.43.0/go.mod h1:C/RJtwSEJ5hzTiUz5pXF1kILHStzb9zFlIEe85bhj6A=
-go.opentelemetry.io/otel/trace v1.43.0 h1:BkNrHpup+4k4w+ZZ86CZoHHEkohws8AY+WTX09nk+3A=
-go.opentelemetry.io/otel/trace v1.43.0/go.mod h1:/QJhyVBUUswCphDVxq+8mld+AvhXZLhe+8WVFxiFff0=
+go.opentelemetry.io/otel/trace v1.44.0 h1:jxF5CsGYCe74MCRx2X4g7WsY/VBKRqqpNvXlX/6gtIk=
+go.opentelemetry.io/otel/trace v1.44.0/go.mod h1:oLl1jrMQAVo6v3GAggN+1VH9VIz9iUSvW53sW1Q8PIE=
go.opentelemetry.io/proto/otlp v1.10.0 h1:IQRWgT5srOCYfiWnpqUYz9CVmbO8bFmKcwYxpuCSL2g=
go.opentelemetry.io/proto/otlp v1.10.0/go.mod h1:/CV4QoCR/S9yaPj8utp3lvQPoqMtxXdzn7ozvvozVqk=
go.opentelemetry.io/proto/slim/otlp v1.10.0 h1:iR97Vs/ZDR+y9TfuP9b1XBtdPWeC+OMslIBmhcLU7jM=
@@ -1705,8 +1705,8 @@ google.golang.org/grpc v1.23.0/go.mod h1:Y5yQAOtifL1yxbo5wqy6BxZv8vAUGQwXBOALyac
google.golang.org/grpc v1.25.1/go.mod h1:c3i+UQWmh7LiEpx4sFZnkU36qjEYZ0imhYfXVyQciAY=
google.golang.org/grpc v1.27.0/go.mod h1:qbnxyOmOxrQa7FizSgH+ReBfzJrCY1pSN7KXBS8abTk=
google.golang.org/grpc v1.33.2/go.mod h1:JMHMWHQWaTccqQQlmk3MJZS+GWXOdAesneDmEnv2fbc=
-google.golang.org/grpc v1.82.0 h1:vguDnZUPjE26w09A63VoxZPnvPjB5Riyc0mkXPFmAIU=
-google.golang.org/grpc v1.82.0/go.mod h1:yzTZ1TB1Z3SG+LIYaI+WiE8D5+PZ3ArnrSp8zF3+/ZA=
+google.golang.org/grpc v1.82.1 h1:NnAxzGRA0677vCa4BUkOAnO5+FfQqVl9iUXeD0IqcGE=
+google.golang.org/grpc v1.82.1/go.mod h1:yzTZ1TB1Z3SG+LIYaI+WiE8D5+PZ3ArnrSp8zF3+/ZA=
google.golang.org/protobuf v0.0.0-20200109180630-ec00e32a8dfd/go.mod h1:DFci5gLYBciE7Vtevhsrf46CRTquxDuWsQurQQe4oz8=
google.golang.org/protobuf v0.0.0-20200221191635-4d8936d0db64/go.mod h1:kwYJMbMJ01Woi6D6+Kah6886xMZcty6N08ah7+eCXa0=
google.golang.org/protobuf v0.0.0-20200228230310-ab0ca4ff8a60/go.mod h1:cfTl7dwQJ+fmap5saPgwCLgHXTUD7jkjRqWcaiX5VyM=
From 2d20716220ac4a8e50e5a1d48db5efc29ac9ef91 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:06:07 +0000
Subject: [PATCH 52/70] chore(deps): update module
github.com/googlecloudplatform/opentelemetry-operations-go/internal/resourcemapping
to v0.59.0 (9.5) (#7810)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go)
| `v0.57.0` → `v0.59.0` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
GoogleCloudPlatform/opentelemetry-operations-go
(github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping)
###
[`v0.59.0`](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/releases/tag/v0.59.0)
[Compare
Source](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/compare/v0.58.0...v0.59.0)
#### What's Changed
- Adds support for resolving OpenTelemetry authentication extensions by
[@Angelawork](https://redirect.github.com/Angelawork) in
[#1181](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1181)
- update golang.org/x/crypto by
[@braydonk](https://redirect.github.com/braydonk) in
[#1182](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1182)
- Update module google.golang.org/grpc to v1.82.1 \[SECURITY] by
[@renovate-bot](https://redirect.github.com/renovate-bot) in
[#1184](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1184)
- Prepare release 0.59.0/1.35.0 by
[@braydonk](https://redirect.github.com/braydonk) in
[#1183](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1183)
#### New Contributors
- [@Angelawork](https://redirect.github.com/Angelawork) made
their first contribution in
[#1181](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1181)
**Full Changelog**:
###
[`v0.58.0`](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/releases/tag/v0.58.0):
v1.34.0/v0.58.0
[Compare
Source](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/compare/v0.57.0...v0.58.0)
#### What's Changed
- googlemanagedprometheus: Add `destination_project_quota` by
[@braydonk](https://redirect.github.com/braydonk) in
[#1175](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1175)
- Prepare release v1.34.0/v0.58.0 by
[@braydonk](https://redirect.github.com/braydonk) in
[#1178](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1178)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 47d34adfa9..38671cd060 100644
--- a/go.mod
+++ b/go.mod
@@ -18,7 +18,7 @@ require (
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/storage/armstorage/v3 v3.0.0
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.35.0 // indirect
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.57.0 // indirect
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.57.0 // indirect
+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.59.0 // indirect
github.com/aquasecurity/go-dep-parser v0.0.0-20240606050805-1de9a375c629
github.com/aquasecurity/trivy v0.71.1
github.com/aquasecurity/trivy-db v0.0.0-20260528104838-11b0c9f9e5e4
diff --git a/go.sum b/go.sum
index a22484613e..0fad67bc17 100644
--- a/go.sum
+++ b/go.sum
@@ -120,8 +120,8 @@ github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.57
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.57.0/go.mod h1:8lmpHY+1VRoteiOwyrQMDt1YGXOrFKCz+1wJW7n3ODY=
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock v0.57.0 h1:cSjUzZ7KU8hicTgzaSv9NmSyM9fTVK3y5lsBUl3wOis=
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock v0.57.0/go.mod h1:dzcEjy1WJ0Q4u9twNR3LcLhNoYMRCrMCMafpxa0TjPQ=
-github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.57.0 h1:RoO5+d7uCmDqovLrHCr2/BuViUXvdcrNxyNM1pN9dDQ=
-github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.57.0/go.mod h1:YqwkQPrWSC7+byyc1VlKbWLBF5JsW5IoL6xUkemYSXk=
+github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.59.0 h1:18FRm6ZcN/x9+ZmhMr96hLcTtlLn2/gHPuDLVeg7XcY=
+github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.59.0/go.mod h1:YqwkQPrWSC7+byyc1VlKbWLBF5JsW5IoL6xUkemYSXk=
github.com/Intevation/gval v1.3.0 h1:+Ze5sft5MmGbZrHj06NVUbcxCb67l9RaPTLMNr37mjw=
github.com/Intevation/gval v1.3.0/go.mod h1:xmGyGpP5be12EL0P12h+dqiYG8qn2j3PJxIgkoOHO5o=
github.com/Intevation/jsonpath v0.2.1 h1:rINNQJ0Pts5XTFEG+zamtdL7l9uuE1z0FBA+r55Sw+A=
From 731f10ed372f68c16d44e52814df1622ad65350d Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:06:28 +0000
Subject: [PATCH 53/70] chore(deps): update module
github.com/lestrrat-go/jwx/v3 to v3.2.0 (9.5) (#7812)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/lestrrat-go/jwx/v3](https://redirect.github.com/lestrrat-go/jwx)
| `v3.1.1` → `v3.2.0` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
lestrrat-go/jwx (github.com/lestrrat-go/jwx/v3)
###
[`v3.2.0`](https://redirect.github.com/lestrrat-go/jwx/releases/tag/v3.2.0)
[Compare
Source](https://redirect.github.com/lestrrat-go/jwx/compare/v3.1.1...v3.2.0)
For more detailed release notes, see
[Changes](https://redirect.github.com/lestrrat-go/jwx/blob/v3.2.0/Changes).
#### What's Changed
- build(deps): bump github.com/lestrrat-go/dsig from 1.2.1 to 1.3.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2043](https://redirect.github.com/lestrrat-go/jwx/pull/2043)
- build(deps): bump golang.org/x/crypto from 0.50.0 to 0.51.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2159](https://redirect.github.com/lestrrat-go/jwx/pull/2159)
- build(deps): bump actions/stale from 10.2.0 to 10.3.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2174](https://redirect.github.com/lestrrat-go/jwx/pull/2174)
- build(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2179](https://redirect.github.com/lestrrat-go/jwx/pull/2179)
- build(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2180](https://redirect.github.com/lestrrat-go/jwx/pull/2180)
- build(deps): bump actions/checkout from 6.0.2 to 6.0.3 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2184](https://redirect.github.com/lestrrat-go/jwx/pull/2184)
- bump httprc to v3.0.6 by
[@lestrrat](https://redirect.github.com/lestrrat) in
[#2189](https://redirect.github.com/lestrrat-go/jwx/pull/2189)
- autodoc updates by
[@github-actions](https://redirect.github.com/github-actions)\[bot]
in [#2190](https://redirect.github.com/lestrrat-go/jwx/pull/2190)
- build(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2192](https://redirect.github.com/lestrrat-go/jwx/pull/2192)
- build(deps): bump actions/checkout from 6.0.3 to 7.0.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2226](https://redirect.github.com/lestrrat-go/jwx/pull/2226)
- build(deps): bump actions/cache from 5.0.5 to 6.0.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2231](https://redirect.github.com/lestrrat-go/jwx/pull/2231)
- build(deps): bump actions/setup-go from 6.4.0 to 6.5.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2230](https://redirect.github.com/lestrrat-go/jwx/pull/2230)
- build(deps): bump actions/cache from 6.0.0 to 6.1.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2238](https://redirect.github.com/lestrrat-go/jwx/pull/2238)
- build(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2242](https://redirect.github.com/lestrrat-go/jwx/pull/2242)
- fix misspellings in code comments by
[@lestrrat](https://redirect.github.com/lestrrat) in
[#2249](https://redirect.github.com/lestrrat-go/jwx/pull/2249)
- build(deps): bump actions/stale from 10.3.0 to 10.4.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2254](https://redirect.github.com/lestrrat-go/jwx/pull/2254)
- build(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2250](https://redirect.github.com/lestrrat-go/jwx/pull/2250)
- build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2258](https://redirect.github.com/lestrrat-go/jwx/pull/2258)
- build(deps): bump actions/checkout from 7.0.0 to 7.0.1 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#2261](https://redirect.github.com/lestrrat-go/jwx/pull/2261)
- bump x/crypto to v0.54.0 in codegen modules by
[@lestrrat](https://redirect.github.com/lestrrat) in
[#2266](https://redirect.github.com/lestrrat-go/jwx/pull/2266)
- \[v3] retain unparseable JWK set keys, opt-in by
[@lestrrat](https://redirect.github.com/lestrrat) in
[#2265](https://redirect.github.com/lestrrat-go/jwx/pull/2265)
- \[v3] fix per-call reject-dup-kid override by
[@lestrrat](https://redirect.github.com/lestrrat) in
[#2270](https://redirect.github.com/lestrrat-go/jwx/pull/2270)
- \[v3] test jwe rejects UnsupportedKey placeholder by
[@lestrrat](https://redirect.github.com/lestrrat) in
[#2272](https://redirect.github.com/lestrrat-go/jwx/pull/2272)
- \[v3] doc: recommend retain mode for third-party JWK sets as PQC rolls
out by [@lestrrat](https://redirect.github.com/lestrrat) in
[#2274](https://redirect.github.com/lestrrat-go/jwx/pull/2274)
- fix jwe JSON AAD serialization by
[@lestrrat](https://redirect.github.com/lestrrat) in
[#2276](https://redirect.github.com/lestrrat-go/jwx/pull/2276)
- add JWE authenticated data option by
[@lestrrat](https://redirect.github.com/lestrrat) in
[#2278](https://redirect.github.com/lestrrat-go/jwx/pull/2278)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 38671cd060..bce8263a62 100644
--- a/go.mod
+++ b/go.mod
@@ -230,7 +230,7 @@ require (
github.com/lestrrat-go/dsig-secp256k1 v1.0.0 // indirect
github.com/lestrrat-go/httpcc v1.0.1 // indirect
github.com/lestrrat-go/httprc/v3 v3.0.6 // indirect
- github.com/lestrrat-go/jwx/v3 v3.1.1 // indirect
+ github.com/lestrrat-go/jwx/v3 v3.2.0 // indirect
github.com/lestrrat-go/option/v2 v2.0.0 // indirect
github.com/letsencrypt/boulder v0.20260804.0 // indirect
github.com/mattn/go-shellwords v1.0.14 // indirect
diff --git a/go.sum b/go.sum
index 0fad67bc17..cd4da15b0d 100644
--- a/go.sum
+++ b/go.sum
@@ -941,8 +941,8 @@ github.com/lestrrat-go/httpcc v1.0.1 h1:ydWCStUeJLkpYyjLDHihupbn2tYmZ7m22BGkcvZZ
github.com/lestrrat-go/httpcc v1.0.1/go.mod h1:qiltp3Mt56+55GPVCbTdM9MlqhvzyuL6W/NMDA8vA5E=
github.com/lestrrat-go/httprc/v3 v3.0.6 h1:4FpLQ18KK/ypPbVU3NLWJNRvH3kcYiqKqWfKGqNWxxI=
github.com/lestrrat-go/httprc/v3 v3.0.6/go.mod h1:mSMtkZW92Z98M5YoNNztbRGxbXHql7tSitCvaxvo9l0=
-github.com/lestrrat-go/jwx/v3 v3.1.1 h1:yd9AdPmZ4INnQ7k42IrzXYpnEG803+SrQ6hdMvzHJzw=
-github.com/lestrrat-go/jwx/v3 v3.1.1/go.mod h1:uw/MN2M/Xiu4FhwcIwH11Zsh9JWx9SWzgALl7/uIEkU=
+github.com/lestrrat-go/jwx/v3 v3.2.0 h1:Jb3zBASTSZXz7gzzSAfYqxXF8KejvKC4xWoePLQqXCA=
+github.com/lestrrat-go/jwx/v3 v3.2.0/go.mod h1:38vQ8iWKq3qRSbilbzvzdQPuywhowwuR03lhkYskyrw=
github.com/lestrrat-go/option/v2 v2.0.0 h1:XxrcaJESE1fokHy3FpaQ/cXW8ZsIdWcdFzzLOcID3Ss=
github.com/lestrrat-go/option/v2 v2.0.0/go.mod h1:oSySsmzMoR0iRzCDCaUfsCzxQHUEuhOViQObyy7S6Vg=
github.com/lestrrat-go/strftime v1.1.1 h1:zgf8QCsgj27GlKBy3SU9/8MMgegZ8UCzlCyHYrUF0QU=
From 4108266f230931de327d9633b75341883c9d013b Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:07:46 +0000
Subject: [PATCH 54/70] chore(deps): update module
github.com/magiconair/properties to v1.18.11 (9.5) (#7814)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/magiconair/properties](https://redirect.github.com/magiconair/properties)
| `v1.8.10` → `v1.18.11` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
magiconair/properties
(github.com/magiconair/properties)
###
[`v1.18.11`](https://redirect.github.com/magiconair/properties/releases/tag/v1.18.11)
[Compare
Source](https://redirect.github.com/magiconair/properties/compare/v1.8.10...v1.18.11)
#### What's Changed
- test with go1.25 and go1.26 by
[@magiconair](https://redirect.github.com/magiconair) in
[#88](https://redirect.github.com/magiconair/properties/pull/88)
- fix: strip UTF-8 BOM when loading properties by
[@sonnemusk](https://redirect.github.com/sonnemusk) in
[#87](https://redirect.github.com/magiconair/properties/pull/87)
#### New Contributors
- [@sonnemusk](https://redirect.github.com/sonnemusk) made their
first contribution in
[#87](https://redirect.github.com/magiconair/properties/pull/87)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index bce8263a62..1b451c0b25 100644
--- a/go.mod
+++ b/go.mod
@@ -486,7 +486,7 @@ require (
github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de // indirect
github.com/lufia/plan9stats v0.0.0-20260802145828-341c2f0c90b5 // indirect
github.com/lunixbochs/struc v0.0.0-20241101090106-8d528fa2c543 // indirect
- github.com/magiconair/properties v1.8.10 // indirect
+ github.com/magiconair/properties v1.18.11 // indirect
github.com/masahiro331/go-disk v0.0.0-20260423015231-f7a470ebd472 // indirect
github.com/masahiro331/go-ebs-file v0.0.0-20260422020928-9d24e29aac27 // indirect
github.com/masahiro331/go-ext4-filesystem v0.0.0-20260423010602-fe51f5b5e52b // indirect
diff --git a/go.sum b/go.sum
index cd4da15b0d..e0a81c443d 100644
--- a/go.sum
+++ b/go.sum
@@ -960,8 +960,8 @@ github.com/lunixbochs/struc v0.0.0-20241101090106-8d528fa2c543 h1:GxMuVb9tJajC1Q
github.com/lunixbochs/struc v0.0.0-20241101090106-8d528fa2c543/go.mod h1:vy1vK6wD6j7xX6O6hXe621WabdtNkou2h7uRtTfRMyg=
github.com/magefile/mage v1.17.2 h1:fyXVu1eadI8Ap1HCCNgEhJ5McIWiYhLR8uol64ZZc40=
github.com/magefile/mage v1.17.2/go.mod h1:Yj51kqllmsgFpvvSzgrZPK9WtluG3kUhFaBUVLo4feA=
-github.com/magiconair/properties v1.8.10 h1:s31yESBquKXCV9a/ScB3ESkOjUYYv+X0rg8SYxI99mE=
-github.com/magiconair/properties v1.8.10/go.mod h1:Dhd985XPs7jluiymwWYZ0G4Z61jb3vdS329zhj2hYo0=
+github.com/magiconair/properties v1.18.11 h1:j5ozYZl0zCjG7ahMDH0GWIobOvvUzT0BdAguG0ViKy0=
+github.com/magiconair/properties v1.18.11/go.mod h1:Dhd985XPs7jluiymwWYZ0G4Z61jb3vdS329zhj2hYo0=
github.com/masahiro331/go-disk v0.0.0-20260423015231-f7a470ebd472 h1:QAY4If99Ee10TUP4mdcB6Qlm036ayfYruTLjvlaczbs=
github.com/masahiro331/go-disk v0.0.0-20260423015231-f7a470ebd472/go.mod h1:rojbW5tVhH1cuVYFKZS+QX+VGXK45JVsRO+jW92kkKM=
github.com/masahiro331/go-ebs-file v0.0.0-20260422020928-9d24e29aac27 h1:IrxbYTVKTDTckgMf7DZz2LZ+izZZpidH2mDP4D7GUt4=
From 1e6367c7d1ffdc5f83f9700224dc250a041a5363 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:08:32 +0000
Subject: [PATCH 55/70] chore(deps): update module github.com/redis/go-redis/v9
to v9.22.0 (9.5) (#7818)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/redis/go-redis/v9](https://redirect.github.com/redis/go-redis)
| `v9.21.0` → `v9.22.0` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
redis/go-redis (github.com/redis/go-redis/v9)
###
[`v9.22.0`](https://redirect.github.com/redis/go-redis/releases/tag/v9.22.0):
9.22.0
[Compare
Source](https://redirect.github.com/redis/go-redis/compare/v9.21.0...v9.22.0)
This is a minor release introducing two flagship (experimental) features
— **client-side caching** and **automatic pipelining** — alongside
support for Redis 8.10, new commands, and a large batch of stability and
parser-robustness fixes. It consolidates everything shipped in
9.22.0-beta.1, so the notes below cover the full 9.21.0 → 9.22.0
upgrade.
⚠️ Two changes to be aware of when upgrading from 9.21.0:
- **Default configuration values changed**
([#3918](https://redirect.github.com/redis/go-redis/pull/3918)):
read/write timeouts, retry backoff, cluster state reload interval, and
TCP keep-alive defaults are now aligned with the cross-SDK configuration
proposal (see the highlight below). Explicitly configured values are
unaffected.
- **`WaitAOF` return type corrected**
([#3888](https://redirect.github.com/redis/go-redis/pull/3888)):
`WaitAOF` now returns `*IntSliceCmd`, matching the two-integer reply of
`WAITAOF` (previously `*IntCmd`, which failed to parse the reply at
runtime). Code referencing the old return type needs a one-line update.
#### 🚀 Highlights
##### Client-Side Caching (Experimental)
The standalone `Client` gains server-assisted client-side caching built
on RESP3 `CLIENT TRACKING`. Enable it by setting `ClientSideCacheConfig`
in `Options` (or supply your own cache via `ClientSideCache` — e.g. to
share one cache across clients). Cacheable read results are served from
a local in-process cache and invalidated automatically when the server
reports a change, cutting round trips for read-heavy workloads.
The invalidation architecture is selected by `ClientSideCacheStrategy`;
the default (and currently only) strategy is
`CSCStrategySharedTracking`: one shared cache, every pool connection
runs plain `CLIENT TRACKING ON`, and a background drainer applies
buffered invalidations — portable (no BCAST) and consistent with the
other Redis client libraries. Requirements and guardrails: RESP3
(`Protocol: 3`), standalone client, DB 0 only; commands that would
change the connection identity (`SELECT`, `AUTH`, ...) are rejected
while caching is enabled, and CSC is disabled when a credentials
provider is set (fixed `Username`/`Password` work and are namespaced).
See the README's [client-side caching
section](README.md#client-side-caching) and the runnable
[example](example/client-side-caching).
**Experimental:** the API may change in a minor release.
([#3941](https://redirect.github.com/redis/go-redis/pull/3941))
by [@ofekshenawa](https://redirect.github.com/ofekshenawa)
##### Automatic Pipelining (Experimental)
`AutoPipeliner` is a background batcher that coalesces commands from
many concurrent goroutines into Redis pipelines, multiplying throughput
without any manual pipeline management. It comes in two faces, available
on `Client` and `ClusterClient` (and configurable via
`Options.AutoPipelineOptions` / `UniversalOptions.AutoPipelineOptions`):
- **`AutoPipeline()`** — the blocking face: a drop-in `Cmdable` where
each call blocks until executed, exactly like a plain client, while
concurrent callers' commands batch together under the hood (measured
locally over loopback: \~1M+ SET/sec vs \~100k unpipelined; indicative,
not a guarantee). Per-goroutine command order is preserved.
- **`AsyncAutoPipeline()`** — the deferred face: command calls return
immediately and every typed result accessor (`Val`/`Result`/`Err`/...)
blocks until the command has executed. Submit a window of commands, then
read the results, to keep pipelines deep (\~2–3M SET/sec locally;
indicative).
`AutoPipelineOptions` controls batching: `MaxBatchSize` (soft target,
default 200; the blocking face's preset uses 300), `MaxBatchBytes`
(approximate payload cap so huge values flush as several bounded
writes), `MaxFlushDelay` with optional `AdaptiveDelay` (delay scales
down as the queue fills), and `MaxConcurrentBatches` (default 1 = a
single ordered batch stream; raising it requires `Unordered: true`, so
ordering is never lost by accident — `Validate()` rejects the
combination otherwise). A usage tour and throughput comparison live in
[`example/autopipeline`](example/autopipeline).
**Experimental:** the API may change in a future release — pin your
go-redis version if you adopt it.
([#3942](https://redirect.github.com/redis/go-redis/pull/3942))
by [@ndyakov](https://redirect.github.com/ndyakov), with help
from [@cxljs](https://redirect.github.com/cxljs)
##### Redis 8.10 Support
This release adds support for **Redis 8.10**. The README's
supported-versions list now includes Redis 8.10, and CI runs the full
suite against the `redislabs/client-libs-test:8.10.0` image by default
([#3920](https://redirect.github.com/redis/go-redis/pull/3920),
[#3940](https://redirect.github.com/redis/go-redis/pull/3940)).
Coverage for the new commands and options that ship with Redis 8.10:
- **`HIMPORT`**
([#3919](https://redirect.github.com/redis/go-redis/pull/3919)) —
bulk hash import via server-side fieldsets, exposed as `HImportPrepare`,
`HImportSet`, `HImportDiscard`, and `HImportDiscardAll`. Fieldsets are
session state scoped to a single physical connection, which does not mix
well with connection pooling — so the client keeps a versioned fieldset
registry and lazily replays the `PREPARE` on whichever pooled connection
executes a `SET` that needs it, at most once per connection, with no
extra round trip (the `PREPARE` is injected into the same write as the
`SET`).
- **`LMOVEM` / `BLMOVEM`**
([#3913](https://redirect.github.com/redis/go-redis/pull/3913)) —
move multiple elements between lists in one call.
- **`SUNIONCARD` / `SDIFFCARD`**
([#3897](https://redirect.github.com/redis/go-redis/pull/3897)) —
cardinality of set union/difference without materializing the result.
- **`XREAD` / `XREADGROUP` `MAXCOUNT` and `MAXSIZE`**
([#3898](https://redirect.github.com/redis/go-redis/pull/3898)) —
bound how much data a stream read returns.
- **`TS.READ`**
([#3896](https://redirect.github.com/redis/go-redis/pull/3896)),
**`TS.QUERYLABELS`**
([#3926](https://redirect.github.com/redis/go-redis/pull/3926)),
**`TS.NRANGE` / `TS.NREVRANGE`**
([#3870](https://redirect.github.com/redis/go-redis/pull/3870))
with multiple aggregators per key
([#3937](https://redirect.github.com/redis/go-redis/pull/3937)),
and **`EXCLUDEEMPTY`** on `TS.MRANGE` / `TS.MREVRANGE`
([#3912](https://redirect.github.com/redis/go-redis/pull/3912)) —
new time-series query surface.
- **`FT.ALIASLIST`**
([#3925](https://redirect.github.com/redis/go-redis/pull/3925)),
**`COLLECT` reducer for `FT.AGGREGATE`**
([#3886](https://redirect.github.com/redis/go-redis/pull/3886)),
**`RERANK` on HNSW vector fields in `FT.CREATE`**
([#3927](https://redirect.github.com/redis/go-redis/pull/3927)),
and **`FT.HYBRID` timeout warnings**
([#3911](https://redirect.github.com/redis/go-redis/pull/3911)) —
search coverage.
##### Cross-SDK Aligned Defaults
Default configuration values now follow the cross-SDK configuration
proposal shared by all Redis client libraries
([#3918](https://redirect.github.com/redis/go-redis/pull/3918)):
| Setting | Old default | New default |
| ------------------------------ | ----------- |
--------------------------------------------------------- |
| `ReadTimeout` / `WriteTimeout` | 3s | 5s |
| Retry backoff (min/max) | 8ms / 512ms | 10ms / 1s |
| Cluster state reload interval | 10s | 60s |
| TCP keep-alive | 5min period | 30s idle / 5s interval / 3 probes
(`net.KeepAliveConfig`) |
Applications that set these values explicitly are unaffected;
applications relying on the old defaults inherit the new ones.
##### Data-Race and Parser Hardening Sweep
A systematic audit fixed data races across the client — hooks
(`AddHook`,
[#3868](https://redirect.github.com/redis/go-redis/pull/3868)),
`Ring.SetAddrs`
([#3862](https://redirect.github.com/redis/go-redis/pull/3862)),
cluster node slices
([#3861](https://redirect.github.com/redis/go-redis/pull/3861)),
pub/sub reconnect
([#3906](https://redirect.github.com/redis/go-redis/pull/3906)),
maintenance notifications
([#3894](https://redirect.github.com/redis/go-redis/pull/3894),
[#3872](https://redirect.github.com/redis/go-redis/pull/3872)),
pool handoff
([#3876](https://redirect.github.com/redis/go-redis/pull/3876)),
and `redisotel`
([#3881](https://redirect.github.com/redis/go-redis/pull/3881)) —
and hardened the RESP parsers against malformed or unexpected replies:
over-reads on nil replies
([#3874](https://redirect.github.com/redis/go-redis/pull/3874)),
integer overflow when skipping map/attribute bodies
([#3877](https://redirect.github.com/redis/go-redis/pull/3877)),
unhashable RESP3 map keys
([#3873](https://redirect.github.com/redis/go-redis/pull/3873)),
odd-length flat replies
([#3900](https://redirect.github.com/redis/go-redis/pull/3900)),
mismatched declared array lengths
([#3907](https://redirect.github.com/redis/go-redis/pull/3907)),
unexpected extra reply frames
([#3884](https://redirect.github.com/redis/go-redis/pull/3884)),
and nil elements in numeric/bool slice replies
([#3922](https://redirect.github.com/redis/go-redis/pull/3922)).
##### PubSub `Receive` Hang Fix
`PeekPushNotificationName` blocked until 36 bytes were buffered, so a
short subscribe confirmation (channel name of six or fewer characters)
on an otherwise idle connection hung `PubSub.Receive` forever — a
regression introduced in 9.20.1 by
[#3842](https://redirect.github.com/redis/go-redis/pull/3842).
The peek now parses whatever is already buffered and only waits for one
more byte when the frame prefix is valid but incomplete. Fixes
[#3935](https://redirect.github.com/redis/go-redis/issues/3935).
([#3936](https://redirect.github.com/redis/go-redis/pull/3936))
by [@ndyakov](https://redirect.github.com/ndyakov)
##### Correct Cluster Transaction Retries
The cluster transaction pipeline treated a `MULTI`...`EXEC` block as
independently retryable commands, which could scatter a transaction
across nodes or send malformed transactions on retry. Redirects
(`MOVED`/`ASK`/`TRYAGAIN`) and aborts are now handled at the
whole-transaction level, matching Redis transaction semantics: the
transaction is re-routed and retried as a unit, never partially
([#3909](https://redirect.github.com/redis/go-redis/pull/3909))
by [@cxljs](https://redirect.github.com/cxljs).
##### Credential Redaction in Command Tracing
`rediscmd.AppendCmd` — used by `redisotel` and `rediscensus` to render
commands into span attributes — now redacts credential arguments as
``: `AUTH`, `HELLO ... AUTH`, `CONFIG SET` of `requirepass` /
`masterauth` / TLS key passphrases, `ACL SETUSER` password rules, and
`MIGRATE ... AUTH`/`AUTH2`. The client sends `HELLO ... AUTH` on every
handshake and `AUTH` on every streaming-credentials rotation through the
regular hook chain, so tracing hooks previously captured credentials
even when the application never issued an auth command itself
([#3939](https://redirect.github.com/redis/go-redis/pull/3939))
by [@saddamr3e](https://redirect.github.com/saddamr3e).
#### ✨ New Features
- **Client-side caching**: server-assisted caching for the standalone
client via `ClientSideCacheConfig` / `ClientSideCache`, with the
`CSCStrategySharedTracking` invalidation strategy
([#3941](https://redirect.github.com/redis/go-redis/pull/3941))
by [@ofekshenawa](https://redirect.github.com/ofekshenawa)
- **Automatic pipelining**: `AutoPipeline()` (blocking) and
`AsyncAutoPipeline()` (deferred results) on `Client` and
`ClusterClient`, configured via `AutoPipelineOptions`
([#3942](https://redirect.github.com/redis/go-redis/pull/3942))
by [@ndyakov](https://redirect.github.com/ndyakov), with help
from [@cxljs](https://redirect.github.com/cxljs)
- **`HIMPORT` command family**: `HImportPrepare` / `HImportSet` /
`HImportDiscard` / `HImportDiscardAll` with lazy per-connection fieldset
prepare replay
([#3919](https://redirect.github.com/redis/go-redis/pull/3919))
by [@ndyakov](https://redirect.github.com/ndyakov)
- **`LMOVEM` / `BLMOVEM`**: move multiple list elements in one call,
with `COUNT` (up to N) or `EXACTLY` (all-or-nothing) semantics via
`LMoveMArgs`
([#3913](https://redirect.github.com/redis/go-redis/pull/3913))
by [@ofekshenawa](https://redirect.github.com/ofekshenawa)
- **`SUnionCard` / `SDiffCard`**: cardinality of set union/difference
([#3897](https://redirect.github.com/redis/go-redis/pull/3897))
by [@ofekshenawa](https://redirect.github.com/ofekshenawa)
- **`XRead` / `XReadGroup` `MAXCOUNT` / `MAXSIZE`**: bound stream read
responses by entry count or payload size
([#3898](https://redirect.github.com/redis/go-redis/pull/3898))
by [@ofekshenawa](https://redirect.github.com/ofekshenawa)
- **`TS.READ`**: read samples from a series starting at a given
timestamp, with `TSReadEarliest` (`-`), `TSReadLatest` (`+`), and
`TSReadNew` (`$`) sentinels
([#3896](https://redirect.github.com/redis/go-redis/pull/3896))
by [@ofekshenawa](https://redirect.github.com/ofekshenawa)
- **`TS.QUERYLABELS`**: query label names/values across time series
([#3926](https://redirect.github.com/redis/go-redis/pull/3926))
by [@ndyakov](https://redirect.github.com/ndyakov)
- **`TS.NRANGE` / `TS.NREVRANGE`**: range queries across multiple series
([#3870](https://redirect.github.com/redis/go-redis/pull/3870))
by [@ofekshenawa](https://redirect.github.com/ofekshenawa), with
multiple aggregators per key
([#3937](https://redirect.github.com/redis/go-redis/pull/3937))
by [@ndyakov](https://redirect.github.com/ndyakov)
- **`TS.MRANGE` / `TS.MREVRANGE` `EXCLUDEEMPTY`**: skip series with no
samples in the result
([#3912](https://redirect.github.com/redis/go-redis/pull/3912))
by [@ofekshenawa](https://redirect.github.com/ofekshenawa)
- **`FT.ALIASLIST`**: list all index aliases
([#3925](https://redirect.github.com/redis/go-redis/pull/3925))
by [@ndyakov](https://redirect.github.com/ndyakov)
- **`FT.AGGREGATE` `COLLECT` reducer**: collect grouped values into an
array
([#3886](https://redirect.github.com/redis/go-redis/pull/3886))
by [@ndyakov](https://redirect.github.com/ndyakov)
- **`FT.CREATE` `RERANK`**: `RERANK` parameter on HNSW vector field
definitions
([#3927](https://redirect.github.com/redis/go-redis/pull/3927))
by [@ofekshenawa](https://redirect.github.com/ofekshenawa)
- **`FT.HYBRID` timeout warnings**: timeout warnings are now populated
in hybrid search results
([#3911](https://redirect.github.com/redis/go-redis/pull/3911))
by [@ofekshenawa](https://redirect.github.com/ofekshenawa)
- **`FT.HYBRID` KNN `SHARD_K_RATIO`** (Redis 8.8+): per-shard K ratio
for KNN clauses
([#3841](https://redirect.github.com/redis/go-redis/pull/3841))
by [@ndyakov](https://redirect.github.com/ndyakov)
#### 🐛 Bug Fixes
- **PubSub `Receive` hang**: peek push-notification names without
demanding 36 buffered bytes, fixing a hang on short subscribe
confirmations (fixes
[#3935](https://redirect.github.com/redis/go-redis/issues/3935),
regression from 9.20.1)
([#3936](https://redirect.github.com/redis/go-redis/pull/3936))
by [@ndyakov](https://redirect.github.com/ndyakov)
- **Cluster transactions**: re-route the whole tx pipeline on
redirect/abort instead of per-command
([#3909](https://redirect.github.com/redis/go-redis/pull/3909))
by [@cxljs](https://redirect.github.com/cxljs)
- **Credential leak in traces**: `rediscmd.AppendCmd` redacts credential
arguments (`AUTH`, `HELLO ... AUTH`, `CONFIG SET` secret params, `ACL
SETUSER` password rules, `MIGRATE AUTH`/`AUTH2`), so `redisotel` /
`rediscensus` span attributes no longer contain passwords
([#3939](https://redirect.github.com/redis/go-redis/pull/3939))
by [@saddamr3e](https://redirect.github.com/saddamr3e)
- **`WaitAOF` return type**: returns `*IntSliceCmd` matching the
two-integer `WAITAOF` reply
([#3888](https://redirect.github.com/redis/go-redis/pull/3888))
by [@CipherN9](https://redirect.github.com/CipherN9)
- **`Ring.Publish` routing**: publish to the shard that owns the topic
instead of a round-robined one
([#3893](https://redirect.github.com/redis/go-redis/pull/3893))
by [@dkindel](https://redirect.github.com/dkindel)
- **Pool `OnRemove` hooks**: fire `OnRemove` on `putConn` eviction paths
so removal hooks see every evicted connection
([#3932](https://redirect.github.com/redis/go-redis/pull/3932))
by [@cxljs](https://redirect.github.com/cxljs)
- **`UniversalClient` `InfoMap`**: added `InfoMap` to the `Cmdable`
interface
([#3904](https://redirect.github.com/redis/go-redis/pull/3904))
by
[@nazarli-shabnam](https://redirect.github.com/nazarli-shabnam)
- **`SlowLogGet` context**: pass the caller's context instead of a
background one
([#3915](https://redirect.github.com/redis/go-redis/pull/3915))
by [@sonnemusk](https://redirect.github.com/sonnemusk)
- **`ModuleLoadex` nil config**: return an error instead of panicking on
nil config
([#3916](https://redirect.github.com/redis/go-redis/pull/3916))
by [@sonnemusk](https://redirect.github.com/sonnemusk)
- **`ParseURL` IPv6 hosts**: keep single brackets for IPv6 hosts without
a port
([#3882](https://redirect.github.com/redis/go-redis/pull/3882))
by [@sueun-dev](https://redirect.github.com/sueun-dev)
- **`ParseURL` durations**: treat unit durations `<= 0` as disabled
([#3866](https://redirect.github.com/redis/go-redis/pull/3866))
by [@sueun-dev](https://redirect.github.com/sueun-dev)
- **Nil `*uint8` encoding**: encode nil `*uint8` as `"0"` like other
numeric pointers
([#3869](https://redirect.github.com/redis/go-redis/pull/3869))
by [@sueun-dev](https://redirect.github.com/sueun-dev)
- **`JSONSliceCmd` read errors**: return the read error from `readReply`
instead of swallowing it
([#3903](https://redirect.github.com/redis/go-redis/pull/3903))
by [@saddamr3e](https://redirect.github.com/saddamr3e)
- **RESP parser hardening**: reconcile declared entry-array lengths
([#3907](https://redirect.github.com/redis/go-redis/pull/3907)),
handle nil elements in int/uint/bool slice parsers
([#3922](https://redirect.github.com/redis/go-redis/pull/3922)),
drain unexpected reply frames
([#3884](https://redirect.github.com/redis/go-redis/pull/3884)),
reject odd-length flat replies in Z/KeyValue parsers
([#3900](https://redirect.github.com/redis/go-redis/pull/3900)),
avoid int overflow when skipping map/attr bodies
([#3877](https://redirect.github.com/redis/go-redis/pull/3877)),
don't over-read nil replies in `Reader.Discard`
([#3874](https://redirect.github.com/redis/go-redis/pull/3874))
by [@saddamr3e](https://redirect.github.com/saddamr3e); reject
unhashable keys in RESP3 map parsing
([#3873](https://redirect.github.com/redis/go-redis/pull/3873))
by [@iabdullah215](https://redirect.github.com/iabdullah215)
- **Data races**: hook state during `AddHook`
([#3868](https://redirect.github.com/redis/go-redis/pull/3868)),
`onNewNode` during `Ring.SetAddrs`
([#3862](https://redirect.github.com/redis/go-redis/pull/3862)),
shared masters/slaves slices in cluster
([#3861](https://redirect.github.com/redis/go-redis/pull/3861)),
shared `opt.Addr` during pub/sub reconnect
([#3906](https://redirect.github.com/redis/go-redis/pull/3906)),
`clusterStateReloadCallback` in maintnotifications
([#3894](https://redirect.github.com/redis/go-redis/pull/3894)),
conn reader in `isHealthyConn` during handoff
([#3876](https://redirect.github.com/redis/go-redis/pull/3876))
by [@saddamr3e](https://redirect.github.com/saddamr3e); handoff
race window in maintnotifications
([#3872](https://redirect.github.com/redis/go-redis/pull/3872))
by [@ndyakov](https://redirect.github.com/ndyakov)
- **`redisotel`**: use `ObservableCounter` for cumulative pool stats
([#3914](https://redirect.github.com/redis/go-redis/pull/3914))
by [@Solaris-star](https://redirect.github.com/Solaris-star);
avoid a data race on shared attributes during `MinIdleConns` warmup
([#3881](https://redirect.github.com/redis/go-redis/pull/3881))
by [@ndyakov](https://redirect.github.com/ndyakov)
#### 🧰 Maintenance
- **Cross-SDK default alignment**: new defaults for timeouts, retry
backoff, cluster state reload, and TCP keep-alive
([#3918](https://redirect.github.com/redis/go-redis/pull/3918))
by [@ndyakov](https://redirect.github.com/ndyakov)
- **CI on Redis 8.10**: 8.10 made the default test version
([#3920](https://redirect.github.com/redis/go-redis/pull/3920))
with version gating by major.minor
([#3908](https://redirect.github.com/redis/go-redis/pull/3908))
by [@ofekshenawa](https://redirect.github.com/ofekshenawa); the
test stack now runs the GA `redislabs/client-libs-test:8.10.0` image and
8.8 was dropped from the CI matrix
([#3940](https://redirect.github.com/redis/go-redis/pull/3940))
- **Type-safe atomics**: use typed `sync/atomic` value types
([#3860](https://redirect.github.com/redis/go-redis/pull/3860))
and remove the dead `assertUnstableCommand` RESP3 path
([#3928](https://redirect.github.com/redis/go-redis/pull/3928))
by [@cxljs](https://redirect.github.com/cxljs)
- **Docs**: clarify that `ExpireTime` / `PExpireTime` return Unix
timestamps
([#3917](https://redirect.github.com/redis/go-redis/pull/3917))
by [@sonnemusk](https://redirect.github.com/sonnemusk); remove a
duplicate example step
([#3875](https://redirect.github.com/redis/go-redis/pull/3875))
by
[@andy-stark-redis](https://redirect.github.com/andy-stark-redis)
#### 👥 Contributors
We'd like to thank all the contributors who worked on this release!
[@andy-stark-redis](https://redirect.github.com/andy-stark-redis),
[@CipherN9](https://redirect.github.com/CipherN9),
[@cxljs](https://redirect.github.com/cxljs),
[@dkindel](https://redirect.github.com/dkindel),
[@iabdullah215](https://redirect.github.com/iabdullah215),
[@nazarli-shabnam](https://redirect.github.com/nazarli-shabnam),
[@ndyakov](https://redirect.github.com/ndyakov),
[@ofekshenawa](https://redirect.github.com/ofekshenawa),
[@saddamr3e](https://redirect.github.com/saddamr3e),
[@Solaris-star](https://redirect.github.com/Solaris-star),
[@sonnemusk](https://redirect.github.com/sonnemusk),
[@sueun-dev](https://redirect.github.com/sueun-dev)
***
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 1b451c0b25..58d4cbd152 100644
--- a/go.mod
+++ b/go.mod
@@ -256,7 +256,7 @@ require (
github.com/pandatix/go-cvss v0.6.2 // indirect
github.com/pkg/errors v0.9.1 // indirect
github.com/planetscale/vtprotobuf v0.6.1-0.20250313105119-ba97887b0a25 // indirect
- github.com/redis/go-redis/v9 v9.21.0 // indirect
+ github.com/redis/go-redis/v9 v9.22.0 // indirect
github.com/rust-secure-code/go-rustaudit v0.0.0-20250226111315-e20ec32e963c // indirect
github.com/sagikazarmark/locafero v0.12.0 // indirect
github.com/samber/oops v1.23.0 // indirect
diff --git a/go.sum b/go.sum
index e0a81c443d..5395082273 100644
--- a/go.sum
+++ b/go.sum
@@ -1165,8 +1165,8 @@ github.com/redis/go-redis/extra/rediscmd/v9 v9.5.3 h1:1/BDligzCa40GTllkDnY3Y5DTH
github.com/redis/go-redis/extra/rediscmd/v9 v9.5.3/go.mod h1:3dZmcLn3Qw6FLlWASn1g4y+YO9ycEFUOM+bhBmzLVKQ=
github.com/redis/go-redis/extra/redisotel/v9 v9.5.3 h1:kuvuJL/+MZIEdvtb/kTBRiRgYaOmx1l+lYJyVdrRUOs=
github.com/redis/go-redis/extra/redisotel/v9 v9.5.3/go.mod h1:7f/FMrf5RRRVHXgfk7CzSVzXHiWeuOQUu2bsVqWoa+g=
-github.com/redis/go-redis/v9 v9.21.0 h1:FPBE4hhbAke+TLmcY3WkpbDffJEomdqPn3HYiqAtL9E=
-github.com/redis/go-redis/v9 v9.21.0/go.mod h1:v/M13XI1PVCDcm01VtPFOADfZtHf8YW3baQf57KlIkA=
+github.com/redis/go-redis/v9 v9.22.0 h1:laDvpYXTJtZLloinw1fA5Kqd6HAEH2XKxOkG/PDq2F0=
+github.com/redis/go-redis/v9 v9.22.0/go.mod h1:y2g0Wj8rQvuK0ELM+oxSudcLtC09JScs98I/X9gRWY4=
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec h1:W09IVJc94icq4NjY3clb7Lk8O1qJ8BdBEF8z0ibU0rE=
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec/go.mod h1:qqbHyh8v60DhA7CoWK5oRCqLrMHRGoxYCSS9EjAz6Eo=
github.com/rogpeppe/go-internal v1.15.0 h1:D0RCU5rMAp+SpgkiNdrjfJ+LX4J1M32V2NeCY7EJ6hc=
From bf8ce56f87330e577aa708e729521c47ab8d723a Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:08:47 +0000
Subject: [PATCH 56/70] chore(deps): update module modernc.org/memory to
v1.12.0 (9.5) (#7820)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [modernc.org/memory](https://gitlab.com/cznic/memory) | `v1.11.0` →
`v1.12.0` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
cznic/memory (modernc.org/memory)
###
[`v1.12.0`](https://gitlab.com/cznic/memory/compare/v1.11.0...v1.12.0)
[Compare
Source](https://gitlab.com/cznic/memory/compare/v1.11.0...v1.12.0)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 58d4cbd152..a3b0e451e7 100644
--- a/go.mod
+++ b/go.mod
@@ -594,7 +594,7 @@ require (
k8s.io/kubectl v0.36.3 // indirect
k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 // indirect
modernc.org/mathutil v1.7.1 // indirect
- modernc.org/memory v1.11.0 // indirect
+ modernc.org/memory v1.12.0 // indirect
oras.land/oras-go/v2 v2.6.2 // indirect
sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect
sigs.k8s.io/kustomize/api v0.21.1 // indirect
diff --git a/go.sum b/go.sum
index 5395082273..c02d2ff8dd 100644
--- a/go.sum
+++ b/go.sum
@@ -1800,8 +1800,8 @@ modernc.org/libc v1.74.0 h1:rkouuwU6Yqp7ZhwytqBhAiulUi/wvH2KsizSt9R4Hh0=
modernc.org/libc v1.74.0/go.mod h1:uH4t5bOx3G3g9Xcmj10YKlTcVISlRDwv8VoQJG9n8Os=
modernc.org/mathutil v1.7.1 h1:GCZVGXdaN8gTqB1Mf/usp1Y/hSqgI2vAGGP4jZMCxOU=
modernc.org/mathutil v1.7.1/go.mod h1:4p5IwJITfppl0G4sUEDtCr4DthTaT47/N3aT6MhfgJg=
-modernc.org/memory v1.11.0 h1:o4QC8aMQzmcwCK3t3Ux/ZHmwFPzE6hf2Y5LbkRs+hbI=
-modernc.org/memory v1.11.0/go.mod h1:/JP4VbVC+K5sU2wZi9bHoq2MAkCnrt2r98UGeSK7Mjw=
+modernc.org/memory v1.12.0 h1:twkmYNkGXCvtYWzoux02jtK6eovjZbdI0uHFUYp6kuU=
+modernc.org/memory v1.12.0/go.mod h1:/JP4VbVC+K5sU2wZi9bHoq2MAkCnrt2r98UGeSK7Mjw=
modernc.org/opt v0.2.0 h1:tGyef5ApycA7FSEOMraay9SaTk5zmbx7Tu+cJs4QKZg=
modernc.org/opt v0.2.0/go.mod h1:03fq9lsNfvkYSfxrfUhZCWPk1lm4cq4N+Bh//bEtgns=
modernc.org/sortutil v1.2.1 h1:+xyoGf15mM3NMlPDnFqrteY07klSFxLElE2PVuWIJ7w=
From e002fc2b9405420f7a42f90eea3bfa61e4b4e71a Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:08:50 +0000
Subject: [PATCH 57/70] chore(deps): update module
github.com/nikolalohinski/gonja/v2 to v2.9.0 (9.5) (#7815)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/nikolalohinski/gonja/v2](https://redirect.github.com/nikolalohinski/gonja)
| `v2.8.0` → `v2.9.0` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
nikolalohinski/gonja
(github.com/nikolalohinski/gonja/v2)
###
[`v2.9.0`](https://redirect.github.com/nikolalohinski/gonja/compare/v2.8.0...v2.9.0)
[Compare
Source](https://redirect.github.com/nikolalohinski/gonja/compare/v2.8.0...v2.9.0)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index a3b0e451e7..281395a942 100644
--- a/go.mod
+++ b/go.mod
@@ -248,7 +248,7 @@ require (
github.com/moby/sys/userns v0.1.0 // indirect
github.com/morikuni/aec v1.1.0 // indirect
github.com/ncruces/go-strftime v1.0.0 // indirect
- github.com/nikolalohinski/gonja/v2 v2.8.0 // indirect
+ github.com/nikolalohinski/gonja/v2 v2.9.0 // indirect
github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481 // indirect
github.com/oklog/ulid/v2 v2.1.2 // indirect
github.com/openvex/discovery v0.1.1-0.20260629103619-4287cf7d3781 // indirect
diff --git a/go.sum b/go.sum
index c02d2ff8dd..80d5846a1f 100644
--- a/go.sum
+++ b/go.sum
@@ -1071,8 +1071,8 @@ github.com/natefinch/atomic v1.0.1 h1:ZPYKxkqQOx3KZ+RsbnP/YsgvxWQPGxjC0oBt2AhwV0
github.com/natefinch/atomic v1.0.1/go.mod h1:N/D/ELrljoqDyT3rZrsUmtsuzvHkeB/wWjHV22AZRbM=
github.com/ncruces/go-strftime v1.0.0 h1:HMFp8mLCTPp341M/ZnA4qaf7ZlsbTc+miZjCLOFAw7w=
github.com/ncruces/go-strftime v1.0.0/go.mod h1:Fwc5htZGVVkseilnfgOVb9mKy6w1naJmn9CehxcKcls=
-github.com/nikolalohinski/gonja/v2 v2.8.0 h1:kOQv887+yMXcaSZjbfa5MMlfHVTpCIcTd8yh+liGmhQ=
-github.com/nikolalohinski/gonja/v2 v2.8.0/go.mod h1:UIzXPVuOsr5h7dZ5DUbqk3/Z7oFA/NLGQGMjqT4L2aU=
+github.com/nikolalohinski/gonja/v2 v2.9.0 h1:QICtNWj0siM3PF5xUjVod/l+C9XnGfI+wrfSIBGKQ6o=
+github.com/nikolalohinski/gonja/v2 v2.9.0/go.mod h1:UIzXPVuOsr5h7dZ5DUbqk3/Z7oFA/NLGQGMjqT4L2aU=
github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481 h1:Up6+btDp321ZG5/zdSLo48H9Iaq0UQGthrhWC6pCxzE=
github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481/go.mod h1:yKZQO8QE2bHlgozqWDiRVqTFlLQSj30K/6SAK8EeYFw=
github.com/nxadm/tail v1.4.4/go.mod h1:kenIhsEOeOJmVchQTgglprH7qJGnHDVpk1VPCcaMI8A=
From b199df207fb47e2625adf6c30e99792ae8f3b7c0 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:09:05 +0000
Subject: [PATCH 58/70] chore(deps): update module modernc.org/libc to v1.75.3
(9.5) (#7819)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [modernc.org/libc](https://gitlab.com/cznic/libc) | `v1.74.0` →
`v1.75.3` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
cznic/libc (modernc.org/libc)
### [`v1.75.3`](https://gitlab.com/cznic/libc/compare/v1.75.2...v1.75.3)
[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.75.2...v1.75.3)
### [`v1.75.2`](https://gitlab.com/cznic/libc/compare/v1.75.1...v1.75.2)
[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.75.1...v1.75.2)
### [`v1.75.1`](https://gitlab.com/cznic/libc/compare/v1.75.0...v1.75.1)
[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.75.0...v1.75.1)
### [`v1.75.0`](https://gitlab.com/cznic/libc/compare/v1.74.4...v1.75.0)
[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.74.4...v1.75.0)
### [`v1.74.4`](https://gitlab.com/cznic/libc/compare/v1.74.3...v1.74.4)
[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.74.3...v1.74.4)
### [`v1.74.3`](https://gitlab.com/cznic/libc/compare/v1.74.2...v1.74.3)
[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.74.2...v1.74.3)
### [`v1.74.2`](https://gitlab.com/cznic/libc/compare/v1.74.1...v1.74.2)
[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.74.1...v1.74.2)
### [`v1.74.1`](https://gitlab.com/cznic/libc/compare/v1.74.0...v1.74.1)
[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.74.0...v1.74.1)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 16 ++++++++--------
2 files changed, 9 insertions(+), 9 deletions(-)
diff --git a/go.mod b/go.mod
index 281395a942..f9e2f11aa3 100644
--- a/go.mod
+++ b/go.mod
@@ -316,7 +316,7 @@ require (
helm.sh/helm/v4 v4.2.3 // indirect
kernel.org/pub/linux/libs/security/libcap/cap v1.2.78 // indirect
kernel.org/pub/linux/libs/security/libcap/psx v1.2.78 // indirect
- modernc.org/libc v1.74.0 // indirect
+ modernc.org/libc v1.75.3 // indirect
mvdan.cc/sh/v3 v3.13.1 // indirect
sigs.k8s.io/controller-runtime v0.24.1 // indirect
sigs.k8s.io/randfill v1.0.0 // indirect
diff --git a/go.sum b/go.sum
index 80d5846a1f..66220adbbc 100644
--- a/go.sum
+++ b/go.sum
@@ -1784,20 +1784,20 @@ kernel.org/pub/linux/libs/security/libcap/cap v1.2.78 h1:jgqg4gyu2BaYW9L6uzEtGLf
kernel.org/pub/linux/libs/security/libcap/cap v1.2.78/go.mod h1:VjuVda6m2qGkpCVfrFkpTGyvkdlZ2N5/yfo89tujlg8=
kernel.org/pub/linux/libs/security/libcap/psx v1.2.78 h1:PC3yNs51cX5LZ7U57a7xielBcoXB3xnV+rXD8V0H0DQ=
kernel.org/pub/linux/libs/security/libcap/psx v1.2.78/go.mod h1:+l6Ee2F59XiJ2I6WR5ObpC1utCQJZ/VLsEbQCD8RG24=
-modernc.org/cc/v4 v4.29.0 h1:CXgwL8cvxmyzBQZzbSl/6xFtMCryb6u8IOqDci39cgc=
-modernc.org/cc/v4 v4.29.0/go.mod h1:OnovgIhbbMXMu1aISnJ0wvVD1KnW+cAUJkIrAWh+kVI=
-modernc.org/ccgo/v4 v4.34.6 h1:sBgfIwyN0TQ9C5hwIeuqyeAKyMWnbvj2fvpF4L11uzU=
-modernc.org/ccgo/v4 v4.34.6/go.mod h1:SZ8YcN9NG7XVsQYdm6jYBvi8PQP1qi+kqB6OhjqI3Fk=
+modernc.org/cc/v4 v4.29.2 h1:h6+9ciCnPKutf4I03CvheAvDLX7+IHlqR6Iy6J+cgd8=
+modernc.org/cc/v4 v4.29.2/go.mod h1:OnovgIhbbMXMu1aISnJ0wvVD1KnW+cAUJkIrAWh+kVI=
+modernc.org/ccgo/v4 v4.35.0 h1:F+TUsmw09QxLzmi3aeYYGxjAXarmZaKgj3mKQHNaA8w=
+modernc.org/ccgo/v4 v4.35.0/go.mod h1:qrVGs9S3Sr2Ztcg9ve+kTAYMp5a3YvWjo+SoN06kJ5I=
modernc.org/fileutil v1.4.0 h1:j6ZzNTftVS054gi281TyLjHPp6CPHr2KCxEXjEbD6SM=
modernc.org/fileutil v1.4.0/go.mod h1:EqdKFDxiByqxLk8ozOxObDSfcVOv/54xDs/DUHdvCUU=
modernc.org/gc/v2 v2.6.5 h1:nyqdV8q46KvTpZlsw66kWqwXRHdjIlJOhG6kxiV/9xI=
modernc.org/gc/v2 v2.6.5/go.mod h1:YgIahr1ypgfe7chRuJi2gD7DBQiKSLMPgBQe9oIiito=
-modernc.org/gc/v3 v3.1.4 h1:2g65LGVSmFQrXeITAw97x7hCRvZFcyE1uDP+7Vng7JI=
-modernc.org/gc/v3 v3.1.4/go.mod h1:HFK/6AGESC7Ex+EZJhJ2Gni6cTaYpSMmU/cT9RmlfYY=
+modernc.org/gc/v3 v3.1.5 h1:21ldfPfRYE31Tb7B3mwAK8gy1AxP4+dKjrOQPfqakoc=
+modernc.org/gc/v3 v3.1.5/go.mod h1:HFK/6AGESC7Ex+EZJhJ2Gni6cTaYpSMmU/cT9RmlfYY=
modernc.org/goabi0 v0.2.0 h1:HvEowk7LxcPd0eq6mVOAEMai46V+i7Jrj13t4AzuNks=
modernc.org/goabi0 v0.2.0/go.mod h1:CEFRnnJhKvWT1c1JTI3Avm+tgOWbkOu5oPA8eH8LnMI=
-modernc.org/libc v1.74.0 h1:rkouuwU6Yqp7ZhwytqBhAiulUi/wvH2KsizSt9R4Hh0=
-modernc.org/libc v1.74.0/go.mod h1:uH4t5bOx3G3g9Xcmj10YKlTcVISlRDwv8VoQJG9n8Os=
+modernc.org/libc v1.75.3 h1:vCqT5+R0jPXMnvMkGo0T2zXvFNth+lYXVCx5X7CCX/g=
+modernc.org/libc v1.75.3/go.mod h1:MjAX68G+0oufI+hNuh0QXcK+Ap+sL8bNPPcIC6EqOfo=
modernc.org/mathutil v1.7.1 h1:GCZVGXdaN8gTqB1Mf/usp1Y/hSqgI2vAGGP4jZMCxOU=
modernc.org/mathutil v1.7.1/go.mod h1:4p5IwJITfppl0G4sUEDtCr4DthTaT47/N3aT6MhfgJg=
modernc.org/memory v1.12.0 h1:twkmYNkGXCvtYWzoux02jtK6eovjZbdI0uHFUYp6kuU=
From 277032a00488fc980628acb1a7a7796388b32b94 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 02:30:37 +0000
Subject: [PATCH 59/70] chore(deps): update golang docker digest to 7caba52
(9.5) (#7822)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| golang | final | digest | `2005724` → `7caba52` |
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
deploy/Dockerfile.debug | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/deploy/Dockerfile.debug b/deploy/Dockerfile.debug
index bf342f8f8d..804856347b 100644
--- a/deploy/Dockerfile.debug
+++ b/deploy/Dockerfile.debug
@@ -1,4 +1,4 @@
-FROM golang@sha256:2005724102f45917a63e9d092fc0e4ea56ea575048ce147caad5f5f61502c365
+FROM golang@sha256:7caba5286b4c3613a337b709c573047d8ae62ee76106647313b61e72b99f20af
RUN go install github.com/go-delve/delve/cmd/dlv@latest
RUN set -x && \
apt-get update && \
From 1e99f640f8eaec1777ae645feaeaadf0e4f84d67 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 03:42:43 +0000
Subject: [PATCH 60/70] chore(deps): update module github.com/go-ldap/ldap/v3
to v3.4.14 (9.5) (#7773)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/go-ldap/ldap/v3](https://redirect.github.com/go-ldap/ldap)
| `v3.4.13` → `v3.4.14` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
go-ldap/ldap (github.com/go-ldap/ldap/v3)
###
[`v3.4.14`](https://redirect.github.com/go-ldap/ldap/releases/tag/v3.4.14)
[Compare
Source](https://redirect.github.com/go-ldap/ldap/compare/v3.4.13...v3.4.14)
I want to thank everyone who contributed in the recents months. Compared
to last year, the number of activities and PRs (including open ones) has
increased dramatically. I would like to thank everyone who contributed
to the project.
**Personal note:** Please keep in mind that this project is not funded
or supported by a large company or similar organization. We work on the
library in our free time after work. I appreciate your support, but
please keep this in mind (including with other open-source projects).
#### What's Changed
- make stop-local-server fails with Docker due to unsupported -t option
by [@t2y](https://redirect.github.com/t2y) in
[#584](https://redirect.github.com/go-ldap/ldap/pull/584)
- Fix panic on malformed LDAP responses by
[@Bahtya](https://redirect.github.com/Bahtya) in
[#586](https://redirect.github.com/go-ldap/ldap/pull/586)
- chore(deps): bump github.com/Azure/go-ntlmssp from 0.1.0 to 0.1.1 in
/v3 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#587](https://redirect.github.com/go-ldap/ldap/pull/587)
- Reject unescaped special characters in DN values per RFC 4514 by
[@t2y](https://redirect.github.com/t2y) in
[#588](https://redirect.github.com/go-ldap/ldap/pull/588)
- v3/control: replace unchecked type asserts in DecodeControl with
comma-ok by
[@c-tonneslan](https://redirect.github.com/c-tonneslan) in
[#589](https://redirect.github.com/go-ldap/ldap/pull/589)
- fix(conn): parse ldapi:// URLs per RFC 4516 by
[@c-tonneslan](https://redirect.github.com/c-tonneslan) in
[#590](https://redirect.github.com/go-ldap/ldap/pull/590)
- fix: decode Server Side Sorting controlValue as BER-encoded OCTET
STRING per RFC 2891 by
[@ahanwhite](https://redirect.github.com/ahanwhite) in
[#593](https://redirect.github.com/go-ldap/ldap/pull/593)
- fix: generate digest-md5 cnonce with crypto/rand by
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#594](https://redirect.github.com/go-ldap/ldap/pull/594)
- fix: escape quoted-string metacharacters in digest-md5 response by
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#595](https://redirect.github.com/go-ldap/ldap/pull/595)
- fix: escape attribute and matching rule in DecompileFilter by
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#596](https://redirect.github.com/go-ldap/ldap/pull/596)
- fix: set Result code when decoding ServerSideSortingResult control by
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#597](https://redirect.github.com/go-ldap/ldap/pull/597)
- fix: reject trailing bytes in hex-encoded DN attribute value by
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#598](https://redirect.github.com/go-ldap/ldap/pull/598)
- fix: synchronize writes to Conn.err with GetLastError by
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#601](https://redirect.github.com/go-ldap/ldap/pull/601)
- unescape quoted-pair sequences in digest-md5 challenge parser by
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#600](https://redirect.github.com/go-ldap/ldap/pull/600)
- fix: avoid uint16 overflow in gssapi UnmarshalWrapToken offset by
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#602](https://redirect.github.com/go-ldap/ldap/pull/602)
- fix(conn): finish Unbind message context to prevent Close deadlock by
[@efd6](https://redirect.github.com/efd6) in
[#599](https://redirect.github.com/go-ldap/ldap/pull/599)
- fix: compare multi-valued RDN attributes as a multiset by
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#604](https://redirect.github.com/go-ldap/ldap/pull/604)
- fix: respect backslash parity for escaped trailing space in DN value
by
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#603](https://redirect.github.com/go-ldap/ldap/pull/603)
- fix: skip empty referral sequence in getReferral by
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#610](https://redirect.github.com/go-ldap/ldap/pull/610)
- fix: guard malformed paging control in DecodeControl by
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#611](https://redirect.github.com/go-ldap/ldap/pull/611)
- handle linear whitespace in digest-md5 challenge parser by
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#607](https://redirect.github.com/go-ldap/ldap/pull/607)
- chore: crypto update by
[@CameronJHall](https://redirect.github.com/CameronJHall) in
[#613](https://redirect.github.com/go-ldap/ldap/pull/613)
- fix: guard malformed responseValue in PasswordModify by
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#614](https://redirect.github.com/go-ldap/ldap/pull/614)
- decode extended responseName by context class by
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#605](https://redirect.github.com/go-ldap/ldap/pull/605)
- fix: prevent SearchAsync goroutine leak when context is cancelled
during send by [@t2y](https://redirect.github.com/t2y) in
[#615](https://redirect.github.com/go-ldap/ldap/pull/615)
- fix: guard nil responseValue when parsing WhoAmI result by
[@johnweldon](https://redirect.github.com/johnweldon) in
[#617](https://redirect.github.com/go-ldap/ldap/pull/617)
- fix: guard constructed-form attributeType in server-side sort decode
by [@johnweldon](https://redirect.github.com/johnweldon) in
[#618](https://redirect.github.com/go-ldap/ldap/pull/618)
- chore: Update dependencies by
[@cpuschma](https://redirect.github.com/cpuschma) in
[#620](https://redirect.github.com/go-ldap/ldap/pull/620)
#### New Contributors
- [@Bahtya](https://redirect.github.com/Bahtya) made their first
contribution in
[#586](https://redirect.github.com/go-ldap/ldap/pull/586)
- [@c-tonneslan](https://redirect.github.com/c-tonneslan) made
their first contribution in
[#589](https://redirect.github.com/go-ldap/ldap/pull/589)
- [@ahanwhite](https://redirect.github.com/ahanwhite) made their
first contribution in
[#593](https://redirect.github.com/go-ldap/ldap/pull/593)
-
[@netliomax25-code](https://redirect.github.com/netliomax25-code)
made their first contribution in
[#594](https://redirect.github.com/go-ldap/ldap/pull/594)
- [@efd6](https://redirect.github.com/efd6) made their first
contribution in
[#599](https://redirect.github.com/go-ldap/ldap/pull/599)
- [@CameronJHall](https://redirect.github.com/CameronJHall) made
their first contribution in
[#613](https://redirect.github.com/go-ldap/ldap/pull/613)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index f9e2f11aa3..5112a3d686 100644
--- a/go.mod
+++ b/go.mod
@@ -187,7 +187,7 @@ require (
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
github.com/go-git/go-git/v5 v5.19.2 // indirect
github.com/go-jose/go-jose/v4 v4.1.4 // indirect
- github.com/go-ldap/ldap/v3 v3.4.13 // indirect
+ github.com/go-ldap/ldap/v3 v3.4.14 // indirect
github.com/go-openapi/runtime/server-middleware v0.32.2 // indirect
github.com/go-openapi/swag/cmdutils v0.27.1 // indirect
github.com/go-openapi/swag/conv v0.27.1 // indirect
diff --git a/go.sum b/go.sum
index 66220adbbc..c89f3a7d1e 100644
--- a/go.sum
+++ b/go.sum
@@ -585,8 +585,8 @@ github.com/go-ini/ini v1.67.0 h1:z6ZrTEZqSWOTyH2FlglNbNgARyHG8oLW9gMELqKr06A=
github.com/go-ini/ini v1.67.0/go.mod h1:ByCAeIL28uOIIG0E3PJtZPDL8WnHpFKFOtgjp+3Ies8=
github.com/go-jose/go-jose/v4 v4.1.4 h1:moDMcTHmvE6Groj34emNPLs/qtYXRVcd6S7NHbHz3kA=
github.com/go-jose/go-jose/v4 v4.1.4/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08=
-github.com/go-ldap/ldap/v3 v3.4.13 h1:+x1nG9h+MZN7h/lUi5Q3UZ0fJ1GyDQYbPvbuH38baDQ=
-github.com/go-ldap/ldap/v3 v3.4.13/go.mod h1:LxsGZV6vbaK0sIvYfsv47rfh4ca0JXokCoKjZxsszv0=
+github.com/go-ldap/ldap/v3 v3.4.14 h1:D6PYdEgsaVzsXyr6w/yDC06Ria4uUhWm+Rb+er8lfAs=
+github.com/go-ldap/ldap/v3 v3.4.14/go.mod h1:S4eJUMUNjDkE0ZJtIZdybwyb03sGGLW6gxXT1Hs8VKA=
github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=
github.com/go-logr/logr v1.4.4 h1:tG4xh9yMsRCAiodLVTxyrkzSZ9+o0L1Kg/+cPVcbP/8=
github.com/go-logr/logr v1.4.4/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY=
From 0926995e611024b62653bbca693ef070da8133e8 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 03:43:30 +0000
Subject: [PATCH 61/70] chore(deps): update docker (9.5) (#7797)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/docker/cli](https://redirect.github.com/docker/cli) |
`v29.6.2+incompatible` → `v29.7.2+incompatible` |

|

|
|
[github.com/docker/go-connections](https://redirect.github.com/docker/go-connections)
| `v0.7.0` → `v0.8.1` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
docker/cli (github.com/docker/cli)
###
[`v29.7.2+incompatible`](https://redirect.github.com/docker/cli/compare/v29.7.1...v29.7.2)
[Compare
Source](https://redirect.github.com/docker/cli/compare/v29.7.1...v29.7.2)
###
[`v29.7.1+incompatible`](https://redirect.github.com/docker/cli/compare/v29.7.0...v29.7.1)
[Compare
Source](https://redirect.github.com/docker/cli/compare/v29.7.0...v29.7.1)
###
[`v29.7.0+incompatible`](https://redirect.github.com/docker/cli/compare/v29.6.2...v29.7.0)
[Compare
Source](https://redirect.github.com/docker/cli/compare/v29.6.2...v29.7.0)
docker/go-connections
(github.com/docker/go-connections)
###
[`v0.8.1`](https://redirect.github.com/docker/go-connections/compare/v0.8.0...v0.8.1)
[Compare
Source](https://redirect.github.com/docker/go-connections/compare/v0.8.0...v0.8.1)
###
[`v0.8.0`](https://redirect.github.com/docker/go-connections/compare/v0.7.0...v0.8.0)
[Compare
Source](https://redirect.github.com/docker/go-connections/compare/v0.7.0...v0.8.0)
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 4 ++--
go.sum | 8 ++++----
2 files changed, 6 insertions(+), 6 deletions(-)
diff --git a/go.mod b/go.mod
index 5112a3d686..d98fa5d403 100644
--- a/go.mod
+++ b/go.mod
@@ -392,9 +392,9 @@ require (
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
github.com/dimchansky/utfbom v1.1.1 // indirect
github.com/dnephin/pflag v1.0.7 // indirect
- github.com/docker/cli v29.6.2+incompatible // indirect
+ github.com/docker/cli v29.7.2+incompatible // indirect
github.com/docker/docker-credential-helpers v0.9.8 // indirect
- github.com/docker/go-connections v0.7.0 // indirect
+ github.com/docker/go-connections v0.8.1 // indirect
github.com/docker/go-units v0.5.0 // indirect
github.com/dop251/goja v0.0.0-20260806115107-493f22071ef6 // indirect
github.com/dop251/goja_nodejs v0.0.0-20171011081505-adff31b136e6 // indirect
diff --git a/go.sum b/go.sum
index c89f3a7d1e..62ae4c810c 100644
--- a/go.sum
+++ b/go.sum
@@ -432,16 +432,16 @@ github.com/dlclark/regexp2 v1.12.0 h1:0j4c5qQmnC6XOWNjP3PIXURXN2gWx76rd3KvgdPkCz
github.com/dlclark/regexp2 v1.12.0/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8=
github.com/dnephin/pflag v1.0.7 h1:oxONGlWxhmUct0YzKTgrpQv9AUA1wtPBn7zuSjJqptk=
github.com/dnephin/pflag v1.0.7/go.mod h1:uxE91IoWURlOiTUIA8Mq5ZZkAv3dPUfZNaT80Zm7OQE=
-github.com/docker/cli v29.6.2+incompatible h1:/bjePvcbbFTnRrMfWJBY7AjfICdsiLVgHn6LwTVOcqw=
-github.com/docker/cli v29.6.2+incompatible/go.mod h1:JLrzqnKDaYBop7H2jaqPtU4hHvMKP+vjCwu2uszcLI8=
+github.com/docker/cli v29.7.2+incompatible h1:dlkwallR8XqfeVnA2ELEhdwvb4lsSwuB4IgsG8Q9cLY=
+github.com/docker/cli v29.7.2+incompatible/go.mod h1:JLrzqnKDaYBop7H2jaqPtU4hHvMKP+vjCwu2uszcLI8=
github.com/docker/distribution v2.8.3+incompatible h1:AtKxIZ36LoNK51+Z6RpzLpddBirtxJnzDrHLEKxTAYk=
github.com/docker/distribution v2.8.3+incompatible/go.mod h1:J2gT2udsDAN96Uj4KfcMRqY0/ypR+oyYUYmja8H+y+w=
github.com/docker/docker v28.5.2+incompatible h1:DBX0Y0zAjZbSrm1uzOkdr1onVghKaftjlSWt4AFexzM=
github.com/docker/docker v28.5.2+incompatible/go.mod h1:eEKB0N0r5NX/I1kEveEz05bcu8tLC/8azJZsviup8Sk=
github.com/docker/docker-credential-helpers v0.9.8 h1:bIREROb7So6PRlq6KTtdS9MPEjC29OQRkFNlvK2OX8Q=
github.com/docker/docker-credential-helpers v0.9.8/go.mod h1:v1S+hepowrQXITkEfw6o4+BMbGot02wiKpzWhGUZK6c=
-github.com/docker/go-connections v0.7.0 h1:6SsRfJddP22WMrCkj19x9WKjEDTB+ahsdiGYf0mN39c=
-github.com/docker/go-connections v0.7.0/go.mod h1:no1qkHdjq7kLMGUXYAduOhYPSJxxvgWBh7ogVvptn3Q=
+github.com/docker/go-connections v0.8.1 h1:JibmG5hULs5qXSr/cp/w3Pw5fZuStt4MOHMUExb29/M=
+github.com/docker/go-connections v0.8.1/go.mod h1:no1qkHdjq7kLMGUXYAduOhYPSJxxvgWBh7ogVvptn3Q=
github.com/docker/go-events v0.0.0-20250808211157-605354379745 h1:yOn6Ze6IbYI/KAw2lw/83ELYvZh6hvsygTVkD0dzMC4=
github.com/docker/go-events v0.0.0-20250808211157-605354379745/go.mod h1:Uw6UezgYA44ePAFQYUehOuCzmy5zmg/+nl2ZfMWGkpA=
github.com/docker/go-metrics v0.0.1 h1:AgB/0SvBxihN0X8OR4SjsblXkbMvalQ8cjmtKQ2rQV8=
From 100c41f13f11b4e97a86e3e6e19ee6e11bec58dc Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 03:44:44 +0000
Subject: [PATCH 62/70] chore(deps): update module github.com/gocsaf/csaf/v3 to
v3.6.0 (9.5) (#7805)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/gocsaf/csaf/v3](https://redirect.github.com/gocsaf/csaf) |
`v3.5.1` → `v3.6.0` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
gocsaf/csaf (github.com/gocsaf/csaf/v3)
###
[`v3.6.0`](https://redirect.github.com/gocsaf/csaf/releases/tag/v3.6.0)
[Compare
Source](https://redirect.github.com/gocsaf/csaf/compare/v3.5.1...v3.6.0)
This release was focused on extending the functionality while
maintaining
backwards compatibility. This is why we only changed the minor version.
If you observe anything that has broken the API, please open an issue.
Most of these changes were made to support the [CSAF online
checker](https://redirect.github.com/csaf-tools/provider-online-check).
Issues found during the development of the online checker were also
fixed.
##### Highlights
- Uploader: add option to call external signing tool:
[#738](https://redirect.github.com/gocsaf/csaf/pull/738)
- Optimization of memory usage:
- Checker close http connections:
[#737](https://redirect.github.com/gocsaf/csaf/pull/737)
- Prevent large buffers used in dowloading:
[#745](https://redirect.github.com/gocsaf/csaf/pull/745)
- (Experimental) streaming loading ROLIE feeds:
[#746](https://redirect.github.com/gocsaf/csaf/pull/746)
- Allow cancellation of API calls which use http connections internally:
[#740](https://redirect.github.com/gocsaf/csaf/pull/740)
- New flags for more granular control:
- Add pre\_flight option to csaf\_checker that logs pmdURL on successful
PMD check:
[#729](https://redirect.github.com/gocsaf/csaf/pull/729)
- Add client\_timeout flag in csaf\_checker, csaf\_downloader and
csaf\_aggregator:
[#730](https://redirect.github.com/gocsaf/csaf/pull/730)
- Checker: Implement a requirement evaluation trail to make more
transparent why domains have passed or failed:
[#741](https://redirect.github.com/gocsaf/csaf/pull/741)
- More information logged:
- Log the used PMD found by the loader:
[#725](https://redirect.github.com/gocsaf/csaf/pull/725)
- Add log for redundant PMDs in security.txt:
[#742](https://redirect.github.com/gocsaf/csaf/pull/742)
- Adjust ROLIE Info messages to be more understandable:
[#732](https://redirect.github.com/gocsaf/csaf/pull/732)
##### Other Changes
- Drop null entries when loading a ROLIE feed by
[@arpitjain099](https://redirect.github.com/arpitjain099) in
[#744](https://redirect.github.com/gocsaf/csaf/pull/744)
- Stop checking if there is no valid PMD:
[#731](https://redirect.github.com/gocsaf/csaf/pull/731)
- Add UTF8 validation for files in checker, downloader and validator:
[#736](https://redirect.github.com/gocsaf/csaf/pull/736)
##### New Contributors
- [@arpitjain099](https://redirect.github.com/arpitjain099) made
a first contribution in
[#744](https://redirect.github.com/gocsaf/csaf/pull/744)
Thank you!
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index d98fa5d403..3523912332 100644
--- a/go.mod
+++ b/go.mod
@@ -201,7 +201,7 @@ require (
github.com/go-openapi/swag/stringutils v0.27.1 // indirect
github.com/go-openapi/swag/typeutils v0.27.1 // indirect
github.com/go-openapi/swag/yamlutils v0.27.1 // indirect
- github.com/gocsaf/csaf/v3 v3.5.1 // indirect
+ github.com/gocsaf/csaf/v3 v3.6.0 // indirect
github.com/gofrs/uuid/v5 v5.5.1 // indirect
github.com/gohugoio/hashstructure v0.6.0 // indirect
github.com/google/certificate-transparency-go v1.3.3 // indirect
diff --git a/go.sum b/go.sum
index 62ae4c810c..d6df2c24df 100644
--- a/go.sum
+++ b/go.sum
@@ -674,8 +674,8 @@ github.com/goccy/go-json v0.10.6 h1:p8HrPJzOakx/mn/bQtjgNjdTcN+/S6FcG2CTtQOrHVU=
github.com/goccy/go-json v0.10.6/go.mod h1:oq7eo15ShAhp70Anwd5lgX2pLfOS3QCiwU/PULtXL6M=
github.com/goccy/go-yaml v1.19.2 h1:PmFC1S6h8ljIz6gMRBopkjP1TVT7xuwrButHID66PoM=
github.com/goccy/go-yaml v1.19.2/go.mod h1:XBurs7gK8ATbW4ZPGKgcbrY1Br56PdM69F7LkFRi1kA=
-github.com/gocsaf/csaf/v3 v3.5.1 h1:jTA1fLrK0/JIczPs7itTD53qANoO4tn2VaGvUeitePc=
-github.com/gocsaf/csaf/v3 v3.5.1/go.mod h1:pga89lE+iWJm7smTdzYcXuetYUbgY8caXfaIP4BJG98=
+github.com/gocsaf/csaf/v3 v3.6.0 h1:xU0Tj67HZGsJzHXM+sQGGYlggtASfnZmbjllOxQNXOE=
+github.com/gocsaf/csaf/v3 v3.6.0/go.mod h1:fTLTVo1K+XWavLQDN3blNB1IoKW/94rhx85YYKAB/ag=
github.com/godbus/dbus/v5 v5.1.0 h1:4KLkAxT3aOY8Li4FRJe/KvhoNFFxo0m6fNuFUO8QJUk=
github.com/godbus/dbus/v5 v5.1.0/go.mod h1:xhWf0FNVPg57R7Z0UbKHbJfkEywrmjJnf7w5xrFpKfA=
github.com/gofrs/flock v0.13.0 h1:95JolYOvGMqeH31+FC7D2+uULf6mG61mEZ/A8dRYMzw=
From 90e1b26fb1725001ce58d9f63750b8f4b4917962 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 03:45:40 +0000
Subject: [PATCH 63/70] chore(deps): update module
github.com/prometheus/client_golang to v1.24.1 (9.5) (#7816)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/prometheus/client_golang](https://redirect.github.com/prometheus/client_golang)
| `v1.23.2` → `v1.24.1` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
prometheus/client_golang
(github.com/prometheus/client_golang)
###
[`v1.24.1`](https://redirect.github.com/prometheus/client_golang/releases/tag/v1.24.1):
/ 2026-07-23
[Compare
Source](https://redirect.github.com/prometheus/client_golang/compare/v1.24.0...v1.24.1)
Small bugfix release for promhttp.
#### What's Changed
\[BUGFIX] promhttp: Fix panic on requests with nil URL.
[#2065](https://redirect.github.com/prometheus/client_golang/issues/2065)
**Full Changelog**:
###
[`v1.24.0`](https://redirect.github.com/prometheus/client_golang/releases/tag/v1.24.0):
- 2026-07-20
[Compare
Source](https://redirect.github.com/prometheus/client_golang/compare/v1.23.2...v1.24.0)
##### Changes
- \[CHANGE] Minimum required Go version is now 1.25, only the two latest
Go versions (1.25 and 1.26) are supported from now on.
[#1862](https://redirect.github.com/prometheus/client_golang/issues/1862)
- \[CHANGE] prometheus: Name validation now always uses the UTF-8 scheme
instead of the deprecated `model.NameValidationScheme` global. Default
behavior is unchanged; code that set `NameValidationScheme =
LegacyValidation` no longer gets legacy enforcement at metric, label,
and push-grouping construction.
[#2051](https://redirect.github.com/prometheus/client_golang/issues/2051)
- \[CHANGE] api/prometheus/v1: Support matchers (`matches[]` parameter)
in `Rules` method (`Rules(ctx context.Context, matches []string)
(RulesResult, error)`).
[#1843](https://redirect.github.com/prometheus/client_golang/issues/1843)
- \[CHANGE] api/prometheus/v1: Refactor `LabelNames` method to return
`model.LabelNames` instead of `[]string` for consistency across the API.
[#1850](https://redirect.github.com/prometheus/client_golang/issues/1850)
- \[CHANGE] exp/api/remote: Simplify `Store` interface, rename `Handler`
to `WriteHandler`, and encapsulate write response handling.
[#1855](https://redirect.github.com/prometheus/client_golang/issues/1855)
- \[FEATURE] prometheus: Add new Go 1.26 runtime metrics
(`/sched/goroutines-created:goroutines`,
`/sched/goroutines/not-in-go:goroutines`,
`/sched/goroutines/runnable:goroutines`,
`/sched/goroutines/running:goroutines`,
`/sched/goroutines/waiting:goroutines`, `/sched/threads/total:threads`).
[#1942](https://redirect.github.com/prometheus/client_golang/issues/1942)
- \[FEATURE] prometheus: Add `WithUnit(unit string)` option and explicit
OpenMetrics unit support in `CounterOpts`, `GaugeOpts`, `SummaryOpts`,
and `HistogramOpts`.
[#1392](https://redirect.github.com/prometheus/client_golang/issues/1392)
- \[FEATURE] prometheus: Expose descriptor construction error through
public `Err()` method on `Desc`.
[#1902](https://redirect.github.com/prometheus/client_golang/issues/1902)
- \[FEATURE] promhttp: Add opt-in `HandlerOpts.CoalesceGather` to
deduplicate concurrent `Gather` calls so overlapping scrapes share one
collection cycle, preventing goroutine pile-up when the scrape rate
outpaces collection time.
[#1969](https://redirect.github.com/prometheus/client_golang/issues/1969)
- \[FEATURE] promhttp: HTTP handlers created by `promhttp` package now
support metrics filtering by providing one or more `name[]` query
parameters. The default behavior when none are provided remains the
same, returning all metrics.
[#1925](https://redirect.github.com/prometheus/client_golang/issues/1925)
- \[FEATURE] api/prometheus/v1: Add query formatting endpoint support
(`/format_query`) and `FormatQuery(ctx context.Context, query string)
(string, error)` method.
[#1846](https://redirect.github.com/prometheus/client_golang/issues/1846),
[#1856](https://redirect.github.com/prometheus/client_golang/issues/1856)
- \[FEATURE] api/prometheus/v1: Add support for `/status/tsdb/blocks`
endpoint via `TSDBBlocks(ctx context.Context) ([]TSDBBlock, error)`
method.
[#1896](https://redirect.github.com/prometheus/client_golang/issues/1896)
- \[FEATURE] exp/api/remote: Export `BackoffConfig` to allow
customization when using `WithAPIBackoff`.
[#1895](https://redirect.github.com/prometheus/client_golang/issues/1895)
- \[FEATURE] exp/api/remote: Add `RetryCallBack` to allow custom logging
or handling on retry attempts in the remote write client.
[#1888](https://redirect.github.com/prometheus/client_golang/issues/1888),
[#1890](https://redirect.github.com/prometheus/client_golang/issues/1890)
- \[ENHANCEMENT] prometheus/collectors/version: Allow specifying custom
labels when registering the version collector.
[#1860](https://redirect.github.com/prometheus/client_golang/issues/1860)
- \[ENHANCEMENT] api: Use cloned `http.DefaultTransport` when
constructing default HTTP clients to prevent accidental mutations of
shared global transport state.
[#1885](https://redirect.github.com/prometheus/client_golang/issues/1885)
- \[BUGFIX] prometheus: Recover from collector panics during `Gather()`
and return an error instead of crashing the process.
[#1961](https://redirect.github.com/prometheus/client_golang/issues/1961)
- \[BUGFIX] prometheus: Fix `cpu-seconds` unit suffix handling for
metric `go_cpu_classes_gc_mark_assist_cpu_seconds`.
[#1991](https://redirect.github.com/prometheus/client_golang/issues/1991)
- \[BUGFIX] promhttp: `InstrumentHandlerDuration` and
`InstrumentHandlerCounter` no longer panic when given an
observer/counter that does not implement
`ExemplarObserver`/`ExemplarAdder` (e.g. a `SummaryVec`). The exemplar
is dropped and the value is recorded via the plain `Observe`/`Add` path,
matching the safe-cast already used by
`Timer.ObserveDurationWithExemplar`.
[#2005](https://redirect.github.com/prometheus/client_golang/issues/2005)
- \[BUGFIX] api/prometheus/v1: Fall back to `GET` requests when `POST`
requests return `403 Forbidden` or method not allowed.
[#2030](https://redirect.github.com/prometheus/client_golang/issues/2030)
- \[BUGFIX] api: Respect context cancellation inside `httpClient.Do`.
[#1971](https://redirect.github.com/prometheus/client_golang/issues/1971)
- \[BUGFIX] exp/api/remote: Fix compression buffer pooling where
compressed buffers were released prematurely, causing corrupted
remote-write payloads.
[#1889](https://redirect.github.com/prometheus/client_golang/issues/1889)
- \[BUGFIX] exp/api/remote: Reject malformed snappy payloads declaring
huge decoded sizes. Enforce a 32MB decoded-size limit to prevent OOM
from oversized remote-write requests.
[#1917](https://redirect.github.com/prometheus/client_golang/issues/1917)
- \[BUGFIX] exp/api/remote: Ensure remote write v2 headers cannot be
returned on v1 requests.
[#1927](https://redirect.github.com/prometheus/client_golang/issues/1927)
All commits
- build(deps): bump github.com/prometheus/procfs from 0.16.1 to 0.17.0
by [@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#1839](https://redirect.github.com/prometheus/client_golang/pull/1839)
- build(deps): bump golang.org/x/sys from 0.33.0 to 0.34.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#1838](https://redirect.github.com/prometheus/client_golang/pull/1838)
- prometheus/collectors: use godoc link for runtime/metrics supported
metrics by [@xieyuschen](https://redirect.github.com/xieyuschen)
in
[#1844](https://redirect.github.com/prometheus/client_golang/pull/1844)
- Fix doc typo by [@torrca](https://redirect.github.com/torrca)
in
[#1849](https://redirect.github.com/prometheus/client_golang/pull/1849)
- Merge release-1.23 into main by
[@vesari](https://redirect.github.com/vesari) in
[#1851](https://redirect.github.com/prometheus/client_golang/pull/1851)
- build(deps): bump github/codeql-action from 3.29.2 to 3.29.5 in the
github-actions group by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#1852](https://redirect.github.com/prometheus/client_golang/pull/1852)
- Refactor LabelNames to return model.LabelNames type for consistency by
[@yshngg](https://redirect.github.com/yshngg) in
[#1850](https://redirect.github.com/prometheus/client_golang/pull/1850)
- remote: simplified Store interface; renamed Handler to WriteHandler by
[@bwplotka](https://redirect.github.com/bwplotka) in
[#1855](https://redirect.github.com/prometheus/client_golang/pull/1855)
- feat(api/prometheus): add format\_query endpoint for query formatting
by [@yshngg](https://redirect.github.com/yshngg) in
[#1846](https://redirect.github.com/prometheus/client_golang/pull/1846)
- feat(api): add FormatQuery method to Prometheus v1 API by
[@yshngg](https://redirect.github.com/yshngg) in
[#1856](https://redirect.github.com/prometheus/client_golang/pull/1856)
- Support matchers in rules API by
[@jotak](https://redirect.github.com/jotak) in
[#1843](https://redirect.github.com/prometheus/client_golang/pull/1843)
- Use prometheus/common.expfmt.NewTextParser by
[@aknuds1](https://redirect.github.com/aknuds1) in
[#1859](https://redirect.github.com/prometheus/client_golang/pull/1859)
- Merge release-1.23 into main by
[@aknuds1](https://redirect.github.com/aknuds1) in
[#1861](https://redirect.github.com/prometheus/client_golang/pull/1861)
- chore: Drop support for \
#### New Contributors
* @xieyuschen made their first
contributi[https://github.com/prometheus/client_golang/pull/1844](https://redirect.github.com/prometheus/client_golang/pull/1844)l/1844
* @torrca made their first
contributi[https://github.com/prometheus/client_golang/pull/1849](https://redirect.github.com/prometheus/client_golang/pull/1849)l/1849
* @yshngg made their first
contributi[https://github.com/prometheus/client_golang/pull/1850](https://redirect.github.com/prometheus/client_golang/pull/1850)l/1850
* @jotak made their first
contributi[https://github.com/prometheus/client_golang/pull/1843](https://redirect.github.com/prometheus/client_golang/pull/1843)l/1843
* @SungJin1212 made their first
contributi[https://github.com/prometheus/client_golang/pull/1878](https://redirect.github.com/prometheus/client_golang/pull/1878)l/1878
* @github-actions[bot] made their first
contributi[https://github.com/prometheus/client_golang/pull/1864](https://redirect.github.com/prometheus/client_golang/pull/1864)l/1864
* @pipiland2612 made their first
contributi[https://github.com/prometheus/client_golang/pull/1888](https://redirect.github.com/prometheus/client_golang/pull/1888)l/1888
* @fpetkovski made their first
contributi[https://github.com/prometheus/client_golang/pull/1889](https://redirect.github.com/prometheus/client_golang/pull/1889)l/1889
* @karthikkondapally made their first
contributi[https://github.com/prometheus/client_golang/pull/1885](https://redirect.github.com/prometheus/client_golang/pull/1885)l/1885
* @tjhop made their first
contributi[https://github.com/prometheus/client_golang/pull/1896](https://redirect.github.com/prometheus/client_golang/pull/1896)l/1896
* @duricanikolic made their first
contributi[https://github.com/prometheus/client_golang/pull/1902](https://redirect.github.com/prometheus/client_golang/pull/1902)l/1902
* @makasim made their first
contributi[https://github.com/prometheus/client_golang/pull/1917](https://redirect.github.com/prometheus/client_golang/pull/1917)l/1917
* @kgeckhart made their first
contributi[https://github.com/prometheus/client_golang/pull/1927](https://redirect.github.com/prometheus/client_golang/pull/1927)l/1927
* @90ashish made their first
contributi[https://github.com/prometheus/client_golang/pull/1929](https://redirect.github.com/prometheus/client_golang/pull/1929)l/1929
* @manute made their first
contributi[https://github.com/prometheus/client_golang/pull/1950](https://redirect.github.com/prometheus/client_golang/pull/1950)l/1950
* @Saflaski made their first
contributi[https://github.com/prometheus/client_golang/pull/1961](https://redirect.github.com/prometheus/client_golang/pull/1961)l/1961
* @Retr0-XD made their first
contributi[https://github.com/prometheus/client_golang/pull/1967](https://redirect.github.com/prometheus/client_golang/pull/1967)l/1967
* @pedrampdd made their first
contributi[https://github.com/prometheus/client_golang/pull/1971](https://redirect.github.com/prometheus/client_golang/pull/1971)l/1971
* @thegdsks made their first
contributi[https://github.com/prometheus/client_golang/pull/1981](https://redirect.github.com/prometheus/client_golang/pull/1981)l/1981
* @tie made their first
contributi[https://github.com/prometheus/client_golang/pull/1863](https://redirect.github.com/prometheus/client_golang/pull/1863)l/1863
* @arpitjain099 made their first
contributi[https://github.com/prometheus/client_golang/pull/2003](https://redirect.github.com/prometheus/client_golang/pull/2003)l/2003
* @immanuwell made their first
contributi[https://github.com/prometheus/client_golang/pull/2009](https://redirect.github.com/prometheus/client_golang/pull/2009)l/2009
* @ProjectMutilation made their first
contributi[https://github.com/prometheus/client_golang/pull/2010](https://redirect.github.com/prometheus/client_golang/pull/2010)l/2010
* @s3onghyun made their first
contributi[https://github.com/prometheus/client_golang/pull/2023](https://redirect.github.com/prometheus/client_golang/pull/2023)l/2023
* @MD-Mushfiqur123 made their first
contributi[https://github.com/prometheus/client_golang/pull/2021](https://redirect.github.com/prometheus/client_golang/pull/2021)l/2021
* @spor3006 made their first
contributi[https://github.com/prometheus/client_golang/pull/2005](https://redirect.github.com/prometheus/client_golang/pull/2005)l/2005
* @maxtaran2010 made their first
contributi[https://github.com/prometheus/client_golang/pull/2049](https://redirect.github.com/prometheus/client_golang/pull/2049)l/2049
* @dhanudhanushree made their first
contributi[https://github.com/prometheus/client_golang/pull/1999](https://redirect.github.com/prometheus/client_golang/pull/1999)l/1999
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 4 ++--
go.sum | 8 ++++----
2 files changed, 6 insertions(+), 6 deletions(-)
diff --git a/go.mod b/go.mod
index 3523912332..175f276c83 100644
--- a/go.mod
+++ b/go.mod
@@ -525,9 +525,9 @@ require (
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
github.com/power-devops/perfstat v0.0.0-20260805114148-88456608a4f6 // indirect
- github.com/prometheus/client_golang v1.23.2 // indirect
+ github.com/prometheus/client_golang v1.24.1 // indirect
github.com/prometheus/client_model v0.6.2 // indirect
- github.com/prometheus/common v0.69.0 // indirect
+ github.com/prometheus/common v0.70.1 // indirect
github.com/prometheus/procfs v0.21.1 // indirect
github.com/rcrowley/go-metrics v0.0.0-20250401214520-65e299d6c5c9 // indirect
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
diff --git a/go.sum b/go.sum
index d6df2c24df..2006a4bf67 100644
--- a/go.sum
+++ b/go.sum
@@ -1148,13 +1148,13 @@ github.com/power-devops/perfstat v0.0.0-20260805114148-88456608a4f6 h1:jL3a8soXd
github.com/power-devops/perfstat v0.0.0-20260805114148-88456608a4f6/go.mod h1:OmDBASR4679mdNQnz2pUhc2G8CO2JrUAVFDRBDP/hJE=
github.com/poy/onpar v1.1.2 h1:QaNrNiZx0+Nar5dLgTVp5mXkyoVFIbepjyEoGSnhbAY=
github.com/poy/onpar v1.1.2/go.mod h1:6X8FLNoxyr9kkmnlqpK6LSoiOtrO6MICtWwEuWkLjzg=
-github.com/prometheus/client_golang v1.23.2 h1:Je96obch5RDVy3FDMndoUsjAhG5Edi49h0RJWRi/o0o=
-github.com/prometheus/client_golang v1.23.2/go.mod h1:Tb1a6LWHB3/SPIzCoaDXI4I8UHKeFTEQ1YCr+0Gyqmg=
+github.com/prometheus/client_golang v1.24.1 h1:JnJkREXzWxUdCuPFpIWZiPispT9xVV59uiuyR2bPlnU=
+github.com/prometheus/client_golang v1.24.1/go.mod h1:F+oSRECHg4sse5ucfYpYDeIv/hu68Zo0uoHKetWnzcE=
github.com/prometheus/client_model v0.0.0-20190812154241-14fe0d1b01d4/go.mod h1:xMI15A0UPsDsEKsMN9yxemIoYk6Tm2C1GtYGdfGttqA=
github.com/prometheus/client_model v0.6.2 h1:oBsgwpGs7iVziMvrGhE53c/GrLUsZdHnqNwqPLxwZyk=
github.com/prometheus/client_model v0.6.2/go.mod h1:y3m2F6Gdpfy6Ut/GBsUqTWZqCUvMVzSfMLjcu6wAwpE=
-github.com/prometheus/common v0.69.0 h1:OA85nJQS/T/MaYh/Q2CcgDKSGWqNIgrBDvDH85CuiNk=
-github.com/prometheus/common v0.69.0/go.mod h1:ZzL3f6u94qUxh9p+tJTrF+FvBS1XXbbRAZCQkytAL0Y=
+github.com/prometheus/common v0.70.1 h1:1HvjP4D5oL3t8RsPlwxA9onvvStjtIHYE5XuuwOi/PY=
+github.com/prometheus/common v0.70.1/go.mod h1:VdFUQDMZK3VLkurFUVhia6uys/0suUp86TJz5qbJRhc=
github.com/prometheus/otlptranslator v1.0.0 h1:s0LJW/iN9dkIH+EnhiD3BlkkP5QVIUVEoIwkU+A6qos=
github.com/prometheus/otlptranslator v1.0.0/go.mod h1:vRYWnXvI6aWGpsdY/mOT/cbeVRBlPWtBNDb7kGR3uKM=
github.com/prometheus/procfs v0.21.1 h1:GljZCt+zSTS+NZq88cyQ1LjZ+RCHp3uVuabBWA5+OJI=
From 418265870a93517f08518f5fc8c5d7170d383458 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 03:45:43 +0000
Subject: [PATCH 64/70] chore(deps): update module
github.com/googlecloudplatform/opentelemetry-operations-go/exporter/metric to
v0.59.0 (9.5) (#7809)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go)
| `v0.57.0` → `v0.59.0` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
GoogleCloudPlatform/opentelemetry-operations-go
(github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric)
###
[`v0.59.0`](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/releases/tag/v0.59.0)
[Compare
Source](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/compare/v0.58.0...v0.59.0)
#### What's Changed
- Adds support for resolving OpenTelemetry authentication extensions by
[@Angelawork](https://redirect.github.com/Angelawork) in
[#1181](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1181)
- update golang.org/x/crypto by
[@braydonk](https://redirect.github.com/braydonk) in
[#1182](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1182)
- Update module google.golang.org/grpc to v1.82.1 \[SECURITY] by
[@renovate-bot](https://redirect.github.com/renovate-bot) in
[#1184](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1184)
- Prepare release 0.59.0/1.35.0 by
[@braydonk](https://redirect.github.com/braydonk) in
[#1183](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1183)
#### New Contributors
- [@Angelawork](https://redirect.github.com/Angelawork) made
their first contribution in
[#1181](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1181)
**Full Changelog**:
###
[`v0.58.0`](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/releases/tag/v0.58.0):
v1.34.0/v0.58.0
[Compare
Source](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/compare/v0.57.0...v0.58.0)
#### What's Changed
- googlemanagedprometheus: Add `destination_project_quota` by
[@braydonk](https://redirect.github.com/braydonk) in
[#1175](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1175)
- Prepare release v1.34.0/v0.58.0 by
[@braydonk](https://redirect.github.com/braydonk) in
[#1178](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1178)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 8 ++++----
2 files changed, 5 insertions(+), 5 deletions(-)
diff --git a/go.mod b/go.mod
index 175f276c83..7ca87897a8 100644
--- a/go.mod
+++ b/go.mod
@@ -17,7 +17,7 @@ require (
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/sql/armsql v1.2.0
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/storage/armstorage/v3 v3.0.0
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.35.0 // indirect
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.57.0 // indirect
+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.59.0 // indirect
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.59.0 // indirect
github.com/aquasecurity/go-dep-parser v0.0.0-20240606050805-1de9a375c629
github.com/aquasecurity/trivy v0.71.1
diff --git a/go.sum b/go.sum
index 2006a4bf67..1952043540 100644
--- a/go.sum
+++ b/go.sum
@@ -116,10 +116,10 @@ github.com/GoogleCloudPlatform/docker-credential-gcr/v2 v2.1.32 h1:osnkVtr2sms/p
github.com/GoogleCloudPlatform/docker-credential-gcr/v2 v2.1.32/go.mod h1:uX2CoogLFWSxfoPl17CT9rMoHlv3RTYudvfNn/d/aOo=
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.35.0 h1:bN1gA3of5bXtbnLsRPrwfmbbe7A5UWFlcTHseujLnpc=
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.35.0/go.mod h1:Yj5vHEz/aAepZGliRJsA6uvHAVAQyEwajq9ORCHPxzM=
-github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.57.0 h1:jLdiS1vO+XJFyDSWRHBx56r4s/NNtcl5J6KyCcWUX/w=
-github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.57.0/go.mod h1:8lmpHY+1VRoteiOwyrQMDt1YGXOrFKCz+1wJW7n3ODY=
-github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock v0.57.0 h1:cSjUzZ7KU8hicTgzaSv9NmSyM9fTVK3y5lsBUl3wOis=
-github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock v0.57.0/go.mod h1:dzcEjy1WJ0Q4u9twNR3LcLhNoYMRCrMCMafpxa0TjPQ=
+github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.59.0 h1:c/Ivw7FuawPLfrr+zB0LZKeCchO2cAHQpF2qZ6OV7rQ=
+github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.59.0/go.mod h1:Zba7lknY/d78oxbKqFTmCsaGwfpzeJ3ktrrLXtnTV6g=
+github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock v0.59.0 h1:xTXsqDOj5k9mK3VVWHYUryryJCIdYfXxdjKFwpzINUw=
+github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock v0.59.0/go.mod h1:V9g30lTKzfUsEW+gpWssck6u9IhARajmipodImLLcwI=
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.59.0 h1:18FRm6ZcN/x9+ZmhMr96hLcTtlLn2/gHPuDLVeg7XcY=
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.59.0/go.mod h1:YqwkQPrWSC7+byyc1VlKbWLBF5JsW5IoL6xUkemYSXk=
github.com/Intevation/gval v1.3.0 h1:+Ze5sft5MmGbZrHj06NVUbcxCb67l9RaPTLMNr37mjw=
From 37f9f10468dd35001a8fb9cb1c60aa8599506c80 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 03:46:20 +0000
Subject: [PATCH 65/70] chore(deps): update module golang.org/x/mod to v0.39.0
(9.5) (#7823)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [golang.org/x/mod](https://pkg.go.dev/golang.org/x/mod) | [`v0.38.0` →
`v0.39.0`](https://cs.opensource.google/go/x/mod/+/refs/tags/v0.38.0...refs/tags/v0.39.0)
|

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 7ca87897a8..11c1a452ca 100644
--- a/go.mod
+++ b/go.mod
@@ -570,7 +570,7 @@ require (
go.opencensus.io v0.24.0 // indirect
go.uber.org/multierr v1.11.0 // indirect
golang.org/x/crypto v0.54.0 // indirect
- golang.org/x/mod v0.38.0 // indirect
+ golang.org/x/mod v0.39.0 // indirect
golang.org/x/net v0.57.0 // indirect
golang.org/x/sync v0.22.0
golang.org/x/sys v0.47.0 // indirect
diff --git a/go.sum b/go.sum
index 1952043540..30a9b7147a 100644
--- a/go.sum
+++ b/go.sum
@@ -1585,8 +1585,8 @@ golang.org/x/lint v0.0.0-20241112194109-818c5a804067/go.mod h1:3xt1FjdF8hUf6vQPI
golang.org/x/mod v0.1.1-0.20191105210325-c90efee705ee/go.mod h1:QqPTAvyqsEbceGzBzNggFXnrqF1CaUcvgkdR5Ot7KZg=
golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4=
-golang.org/x/mod v0.38.0 h1:MECBjubtXD7yj4HrhIUcywNaGeNVUdfVnxmPajOk4yk=
-golang.org/x/mod v0.38.0/go.mod h1:V6Xz0pq8TQ3dGqVQ1FVHuelZpAL0uNhSkk9ogYP3c40=
+golang.org/x/mod v0.39.0 h1:UF5zwQdCRRUpHfyPwr7d4UrGiVeldIsogtzWVnczL74=
+golang.org/x/mod v0.39.0/go.mod h1:bvIbwjQ0HUFFf5AKukeeYQG4ZBUG9yxQbR9aEweIwYY=
golang.org/x/net v0.0.0-20180724234803-3673e40ba225/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
golang.org/x/net v0.0.0-20180826012351-8a410e7b638d/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
golang.org/x/net v0.0.0-20180906233101-161cd47e91fd/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
From 9f5ac6590c65a14acfd85197a918b1c4c2fd1578 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 03:47:31 +0000
Subject: [PATCH 66/70] chore(deps): update module github.com/prometheus/common
to v0.70.1 (9.5) (#7817)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/prometheus/common](https://redirect.github.com/prometheus/common)
| `v0.69.0` → `v0.70.1` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
prometheus/common (github.com/prometheus/common)
###
[`v0.70.1`](https://redirect.github.com/prometheus/common/releases/tag/v0.70.1)
[Compare
Source](https://redirect.github.com/prometheus/common/compare/v0.70.0...v0.70.1)
#### What's Changed
- Update CHANGELOG for v0.70.0 by
[@roidelapluie](https://redirect.github.com/roidelapluie) in
[#945](https://redirect.github.com/prometheus/common/pull/945)
- config: clarify sensitive redirect headers match net/http by
[@roidelapluie](https://redirect.github.com/roidelapluie) in
[#924](https://redirect.github.com/prometheus/common/pull/924)
- Synchronize common files from prometheus/prometheus by
[@prombot](https://redirect.github.com/prombot) in
[#946](https://redirect.github.com/prometheus/common/pull/946)
- build(deps): bump actions/checkout from 7.0.0 to 7.0.1 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#950](https://redirect.github.com/prometheus/common/pull/950)
- build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#949](https://redirect.github.com/prometheus/common/pull/949)
- build(deps): bump the codeql group with 4 updates by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#948](https://redirect.github.com/prometheus/common/pull/948)
- build(deps): bump golang.org/x/net from 0.56.0 to 0.57.0 in the
golang-org-x group across 1 directory by
[@dependabot](https://redirect.github.com/dependabot)\[bot] in
[#947](https://redirect.github.com/prometheus/common/pull/947)
**Full Changelog**:
###
[`v0.70.0`](https://redirect.github.com/prometheus/common/blob/HEAD/CHANGELOG.md#v0700--2026-07-10)
[Compare
Source](https://redirect.github.com/prometheus/common/compare/v0.69.0...v0.70.0)
##### Enhancements
- route: add support for the QUERY HTTP method.
[#932](https://redirect.github.com/prometheus/common/issues/932)
##### Bugfixes
- config: fix `TLSVersion.String()` printing a pointer address instead
of the numeric version for unknown TLS versions.
[#929](https://redirect.github.com/prometheus/common/issues/929)
##### Internal
- expfmt: add `BenchmarkConvertMetricFamily` comparing the Prometheus
text and OpenMetrics 1.0 encoders.
[#943](https://redirect.github.com/prometheus/common/issues/943)
- Update Go dependencies.
[#933](https://redirect.github.com/prometheus/common/issues/933)
[#934](https://redirect.github.com/prometheus/common/issues/934)
- Synchronize common files from prometheus/prometheus.
[#923](https://redirect.github.com/prometheus/common/issues/923)
[#927](https://redirect.github.com/prometheus/common/issues/927)
[#930](https://redirect.github.com/prometheus/common/issues/930)
[#937](https://redirect.github.com/prometheus/common/issues/937)
- Update GitHub Actions.
[#938](https://redirect.github.com/prometheus/common/issues/938)
[#939](https://redirect.github.com/prometheus/common/issues/939)
[#940](https://redirect.github.com/prometheus/common/issues/940)
[#941](https://redirect.github.com/prometheus/common/issues/941)
[#942](https://redirect.github.com/prometheus/common/issues/942)
**Full Changelog**:
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
From 37313693a646a270d428b790f24b50b27de41f0e Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 03:55:59 +0000
Subject: [PATCH 67/70] fix(deps): update aws-sdk (9.5) (#7824)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/aws/aws-sdk-go-v2](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.42.1` → `v1.43.4` |

|

|
|
[github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.7.13` → `v1.7.16` |

|

|
|
[github.com/aws/aws-sdk-go-v2/config](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.32.25` → `v1.32.35` |

|

|
|
[github.com/aws/aws-sdk-go-v2/credentials](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.19.24` → `v1.19.34` |

|

|
|
[github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.18.29` → `v1.18.35` |

|

|
|
[github.com/aws/aws-sdk-go-v2/internal/configsources](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.4.30` → `v1.4.35` |

|

|
|
[github.com/aws/aws-sdk-go-v2/internal/endpoints/v2](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v2.7.30` → `v2.7.35` |

|

|
|
[github.com/aws/aws-sdk-go-v2/internal/v4a](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.4.30` → `v1.4.36` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/accessanalyzer](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.49.5` → `v1.51.4` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/autoscaling](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.67.4` → `v1.71.0` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/cloudformation](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.72.1` → `v1.76.1` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/cloudtrail](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.56.4` → `v1.58.4` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/cloudwatch](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.59.0` → `v1.66.3` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.78.0` → `v1.82.0` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/configservice](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.64.1` → `v1.68.4` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/dynamodb](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.59.0` → `v1.63.1` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/ebs](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.34.7` → `v1.36.4` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/ec2](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.308.0` → `v1.321.0` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/ecr](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.58.4` → `v1.60.4` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/eks](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.88.1` → `v1.90.4` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/elasticloadbalancing](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.34.6` → `v1.36.4` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.55.4` → `v1.58.5` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/iam](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.54.5` → `v1.58.1` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.13.12` → `v1.13.15` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/internal/checksum](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.9.22` → `v1.9.28` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.12.6` → `v1.12.12` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/internal/presigned-url](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.13.29` → `v1.13.35` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/internal/s3shared](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.19.29` → `v1.19.36` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/kms](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.53.4` → `v1.55.4` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/lambda](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.93.0` → `v1.101.2` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/organizations](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.51.10` → `v1.53.5` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/rds](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.119.3` → `v1.124.1` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/route53](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.62.5` → `v1.65.6` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/s3](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.104.0` → `v1.107.0` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/s3control](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.71.5` → `v1.73.4` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/securityhub](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.71.7` → `v1.76.0` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/signin](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.2.0` → `v1.5.4` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/sns](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.40.1` → `v1.42.4` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/sqs](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.44.0` → `v1.46.4` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/sso](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.31.3` → `v1.33.4` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/ssooidc](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.36.6` → `v1.38.4` |

|

|
|
[github.com/aws/aws-sdk-go-v2/service/sts](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.43.3` → `v1.45.4` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 84 ++++++++++++++---------------
go.sum | 168 ++++++++++++++++++++++++++++-----------------------------
2 files changed, 126 insertions(+), 126 deletions(-)
diff --git a/go.mod b/go.mod
index 11c1a452ca..5cea650127 100644
--- a/go.mod
+++ b/go.mod
@@ -22,30 +22,30 @@ require (
github.com/aquasecurity/go-dep-parser v0.0.0-20240606050805-1de9a375c629
github.com/aquasecurity/trivy v0.71.1
github.com/aquasecurity/trivy-db v0.0.0-20260528104838-11b0c9f9e5e4
- github.com/aws/aws-sdk-go-v2 v1.42.1
- github.com/aws/aws-sdk-go-v2/config v1.32.25
- github.com/aws/aws-sdk-go-v2/credentials v1.19.24
- github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.29
- github.com/aws/aws-sdk-go-v2/service/accessanalyzer v1.49.5
- github.com/aws/aws-sdk-go-v2/service/autoscaling v1.67.4
- github.com/aws/aws-sdk-go-v2/service/cloudformation v1.72.1
- github.com/aws/aws-sdk-go-v2/service/cloudtrail v1.56.4
- github.com/aws/aws-sdk-go-v2/service/cloudwatch v1.59.0
- github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs v1.78.0
- github.com/aws/aws-sdk-go-v2/service/configservice v1.64.1
- github.com/aws/aws-sdk-go-v2/service/ec2 v1.308.0
- github.com/aws/aws-sdk-go-v2/service/ecr v1.58.4
- github.com/aws/aws-sdk-go-v2/service/elasticloadbalancing v1.34.6
- github.com/aws/aws-sdk-go-v2/service/iam v1.54.5
- github.com/aws/aws-sdk-go-v2/service/kms v1.53.4
- github.com/aws/aws-sdk-go-v2/service/lambda v1.93.0
- github.com/aws/aws-sdk-go-v2/service/organizations v1.51.10
- github.com/aws/aws-sdk-go-v2/service/rds v1.119.3
- github.com/aws/aws-sdk-go-v2/service/s3 v1.104.0
- github.com/aws/aws-sdk-go-v2/service/s3control v1.71.5
- github.com/aws/aws-sdk-go-v2/service/securityhub v1.71.7
- github.com/aws/aws-sdk-go-v2/service/sns v1.40.1
- github.com/aws/aws-sdk-go-v2/service/sts v1.43.3
+ github.com/aws/aws-sdk-go-v2 v1.43.4
+ github.com/aws/aws-sdk-go-v2/config v1.32.35
+ github.com/aws/aws-sdk-go-v2/credentials v1.19.34
+ github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.35
+ github.com/aws/aws-sdk-go-v2/service/accessanalyzer v1.51.4
+ github.com/aws/aws-sdk-go-v2/service/autoscaling v1.71.0
+ github.com/aws/aws-sdk-go-v2/service/cloudformation v1.76.1
+ github.com/aws/aws-sdk-go-v2/service/cloudtrail v1.58.4
+ github.com/aws/aws-sdk-go-v2/service/cloudwatch v1.66.3
+ github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs v1.82.0
+ github.com/aws/aws-sdk-go-v2/service/configservice v1.68.4
+ github.com/aws/aws-sdk-go-v2/service/ec2 v1.321.0
+ github.com/aws/aws-sdk-go-v2/service/ecr v1.60.4
+ github.com/aws/aws-sdk-go-v2/service/elasticloadbalancing v1.36.4
+ github.com/aws/aws-sdk-go-v2/service/iam v1.58.1
+ github.com/aws/aws-sdk-go-v2/service/kms v1.55.4
+ github.com/aws/aws-sdk-go-v2/service/lambda v1.101.2
+ github.com/aws/aws-sdk-go-v2/service/organizations v1.53.5
+ github.com/aws/aws-sdk-go-v2/service/rds v1.124.1
+ github.com/aws/aws-sdk-go-v2/service/s3 v1.107.0
+ github.com/aws/aws-sdk-go-v2/service/s3control v1.73.4
+ github.com/aws/aws-sdk-go-v2/service/securityhub v1.76.0
+ github.com/aws/aws-sdk-go-v2/service/sns v1.42.4
+ github.com/aws/aws-sdk-go-v2/service/sts v1.45.4
github.com/aws/smithy-go v1.27.7
github.com/dgraph-io/ristretto/v2 v2.4.2
github.com/djherbis/times v1.6.0
@@ -117,8 +117,8 @@ require (
require github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/appservice/armappservice/v6 v6.0.0
require (
- github.com/aws/aws-sdk-go-v2/service/eks v1.88.1
- github.com/aws/aws-sdk-go-v2/service/route53 v1.62.5
+ github.com/aws/aws-sdk-go-v2/service/eks v1.90.4
+ github.com/aws/aws-sdk-go-v2/service/route53 v1.65.6
)
require (
@@ -142,10 +142,10 @@ require (
github.com/aquasecurity/iamgo v0.0.10 // indirect
github.com/aquasecurity/jfather v0.0.8 // indirect
github.com/aquasecurity/trivy-checks v1.12.2-0.20251219190323-79d27547baf5 // indirect
- github.com/aws/aws-sdk-go-v2/service/dynamodb v1.59.0 // indirect
- github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery v1.12.6 // indirect
- github.com/aws/aws-sdk-go-v2/service/signin v1.2.0 // indirect
- github.com/aws/aws-sdk-go-v2/service/sqs v1.44.0 // indirect
+ github.com/aws/aws-sdk-go-v2/service/dynamodb v1.63.1 // indirect
+ github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery v1.12.12 // indirect
+ github.com/aws/aws-sdk-go-v2/service/signin v1.5.4 // indirect
+ github.com/aws/aws-sdk-go-v2/service/sqs v1.46.4 // indirect
github.com/bitfield/gotestdox v0.2.3 // indirect
github.com/bitnami/go-version v0.0.0-20260728133343-2aa268af0217 // indirect
github.com/blakesmith/ar v0.0.0-20190502131153-809d4375e1fb // indirect
@@ -363,18 +363,18 @@ require (
github.com/aquasecurity/trivy-java-db v0.0.0-20260513130532-ec095357db14 // indirect
github.com/armon/go-radix v1.0.0 // indirect
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
- github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.13 // indirect
- github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.30 // indirect
- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.30 // indirect
- github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.30 // indirect
- github.com/aws/aws-sdk-go-v2/service/ebs v1.34.7 // indirect
- github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2 v1.55.4
- github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.12 // indirect
- github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.22 // indirect
- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.29 // indirect
- github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.29 // indirect
- github.com/aws/aws-sdk-go-v2/service/sso v1.31.3 // indirect
- github.com/aws/aws-sdk-go-v2/service/ssooidc v1.36.6 // indirect
+ github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.16 // indirect
+ github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.35 // indirect
+ github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.35 // indirect
+ github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.36 // indirect
+ github.com/aws/aws-sdk-go-v2/service/ebs v1.36.4 // indirect
+ github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2 v1.58.5
+ github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.15 // indirect
+ github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.28 // indirect
+ github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.35 // indirect
+ github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.36 // indirect
+ github.com/aws/aws-sdk-go-v2/service/sso v1.33.4 // indirect
+ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.4 // indirect
github.com/beorn7/perks v1.0.1 // indirect
github.com/bgentry/go-netrc v0.0.0-20140422174119-9fd32a8b3d3d // indirect
github.com/bmatcuk/doublestar/v4 v4.10.0 // indirect
diff --git a/go.sum b/go.sum
index 30a9b7147a..5c2fc701c9 100644
--- a/go.sum
+++ b/go.sum
@@ -217,90 +217,90 @@ github.com/armon/go-socks5 v0.0.0-20160902184237-e75332964ef5 h1:0CwZNZbxp69SHPd
github.com/armon/go-socks5 v0.0.0-20160902184237-e75332964ef5/go.mod h1:wHh0iHkYZB8zMSxRWpUBQtwG5a7fFgvEO+odwuTv2gs=
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 h1:DklsrG3dyBCFEj5IhUbnKptjxatkF07cF2ak3yi77so=
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2/go.mod h1:WaHUgvxTVq04UNunO+XhnAqY/wQc+bxr74GqbsZ/Jqw=
-github.com/aws/aws-sdk-go-v2 v1.42.1 h1:9eOTgu1z/dVtYpNZ3/8/XbbaX0x/BqE3HUzAzs6K0ek=
-github.com/aws/aws-sdk-go-v2 v1.42.1/go.mod h1:5pKeft2eJj+gElQ38Jqg4ibCqh+/AK33/0X3hip7IjM=
-github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.13 h1:p1BBrg/Hhp6uK7zpejeI8QFXHJeC/mynzi04Sl03k9g=
-github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.13/go.mod h1:8cIfkE9MDhkRZGpQ22aV6/lkYeYSozpz16Smrs5x4Ls=
-github.com/aws/aws-sdk-go-v2/config v1.32.25 h1:ACCejvStYoilgwrfegSt5ZntCbPrk52qfwyNcnl3omM=
-github.com/aws/aws-sdk-go-v2/config v1.32.25/go.mod h1:LJyU8sDRbXUxFn8xMJIGP+v9QYYwveNLI8a/giAOiAs=
-github.com/aws/aws-sdk-go-v2/credentials v1.19.24 h1:2hQqYCV9yqyePQ9o6dCrZc/zO8U3TwPr9mIKlZnPu/I=
-github.com/aws/aws-sdk-go-v2/credentials v1.19.24/go.mod h1:IDwpACtwqHLISdzfwUUNq4P9DsB/h5BLg4FwJPNfqFY=
-github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.29 h1:r6qZHbT+wxgWO/e9vYNUEtg7lv5+UN3pRqKhLXvnArg=
-github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.29/go.mod h1:QRnaRcTVGKPGRy8w78HMQtKUGRYcnMZAANATkeVA6Mo=
-github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.30 h1:xM/Is9cKMHa8Jj8zkvWhvrFkZsXJV9E+BB4g0HW0duQ=
-github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.30/go.mod h1:WueJeNDZvK1fMYEWJIkcivBfEzUkTpBhzlrUKKY8EuA=
-github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.30 h1:jn46zC9LdsVR/ZpMIJqMqb8hHv31BlLx3ulVqNspUOk=
-github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.30/go.mod h1:1hTMsAgbdS/AtUi4bw8+gUuh1pceo+eXRLfpSuSQj3M=
-github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.30 h1:VTGy885W5DKBxWRUJbym9hytNaYzsyaPkCHGRRMAOhU=
-github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.30/go.mod h1:AS0HycUvJRFvTt613AYDOgO2jzw+00cVSMny8XB3yMY=
-github.com/aws/aws-sdk-go-v2/service/accessanalyzer v1.49.5 h1:YRmgSZDK5hzQGr3WD/tUVFCwVsnELDbTui7yhEgzy7g=
-github.com/aws/aws-sdk-go-v2/service/accessanalyzer v1.49.5/go.mod h1:4v0AkcAcWguJx3gOcZTvunFMbVeJ1e0jiUZPkaDPbhI=
-github.com/aws/aws-sdk-go-v2/service/autoscaling v1.67.4 h1:5xDkTDvStSuTO4qdQfgfmIgQNTjS3kp7CPXHQ3CnqMQ=
-github.com/aws/aws-sdk-go-v2/service/autoscaling v1.67.4/go.mod h1:rvzjcotoLfbMIVBpxSl0b6rCQsuty5V2aNL0LalDBr8=
-github.com/aws/aws-sdk-go-v2/service/cloudformation v1.72.1 h1:vI/iCtlKp8LscUuwiWfTNID18w+naIGXKyWiY5odsZU=
-github.com/aws/aws-sdk-go-v2/service/cloudformation v1.72.1/go.mod h1:67kQqAVkI9zNMo9kj1ca5RQvsDczK6xKCXrXn7ObZA8=
-github.com/aws/aws-sdk-go-v2/service/cloudtrail v1.56.4 h1:vbwtZFqiHIXnOrBDp3B6efVnQKHMI8SiUYCIc74YHI0=
-github.com/aws/aws-sdk-go-v2/service/cloudtrail v1.56.4/go.mod h1:LouyoQcaBYLDjRpqIKNJbWquIWVgnPLDEi/9o4Uf5+s=
-github.com/aws/aws-sdk-go-v2/service/cloudwatch v1.59.0 h1:JOrwHweL6IzRjbDxdjup2YI2QjWa8/h0PGexR8MZpKw=
-github.com/aws/aws-sdk-go-v2/service/cloudwatch v1.59.0/go.mod h1:tsfAcBcMTF2G9UirQTP1In3DrkNO16SyUU527NPLPhs=
-github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs v1.78.0 h1:6r+3E3bDRGiPm2x5t0eKy5jkAtWtgpwdCHi2dMaZy1c=
-github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs v1.78.0/go.mod h1:N336OxQ6TvRbb6V1esVE8PtQFU86YvYaS+lVjsJTmP0=
-github.com/aws/aws-sdk-go-v2/service/configservice v1.64.1 h1:CJ6YcGJiXPJIz6ICOcGBumi2TcUSldUESHeF243WvVo=
-github.com/aws/aws-sdk-go-v2/service/configservice v1.64.1/go.mod h1:oqVF/7XFqk3GY0/zlvY3Dj2+42ynOx4x/Sp875yKcxE=
-github.com/aws/aws-sdk-go-v2/service/dynamodb v1.59.0 h1:S1qETDbdXKZMYVveuxACCKuRqnAt2NlnmYnlq5SeuMY=
-github.com/aws/aws-sdk-go-v2/service/dynamodb v1.59.0/go.mod h1:jLkDwIDBkCIpiENQhAOjAR2L9jwj56mZgVEvuro4gUE=
-github.com/aws/aws-sdk-go-v2/service/ebs v1.34.7 h1:8cSeObfW/xr+s2Hra2kArFisWz05pMrgIV/ZskUeYLw=
-github.com/aws/aws-sdk-go-v2/service/ebs v1.34.7/go.mod h1:u+YbhSelj9tbG7rWdjRbRnUi6izHK5hjZnxxA9dtCvQ=
-github.com/aws/aws-sdk-go-v2/service/ec2 v1.308.0 h1:xBP+yWpveXD/PxK7HRMcoG6yj1vdOjSahAg4qPomF+0=
-github.com/aws/aws-sdk-go-v2/service/ec2 v1.308.0/go.mod h1:8mrDF7OtbuL0QpwP4YCvLuoOE4/5lL7D33MXgp069/Y=
-github.com/aws/aws-sdk-go-v2/service/ecr v1.58.4 h1:fo6cmbxkKq/OtKUG0sK70fDsYjtKuSkjIQZUJwt24YM=
-github.com/aws/aws-sdk-go-v2/service/ecr v1.58.4/go.mod h1:7VJFM2lSPHz2I1rRb0a+lbphoOp7hXIgYjGhSTOLY7k=
-github.com/aws/aws-sdk-go-v2/service/eks v1.88.1 h1:Z05Ct9QXAZXKbC1wNLQln0/6FDzTcWPqI1YTWqs/pRY=
-github.com/aws/aws-sdk-go-v2/service/eks v1.88.1/go.mod h1:MSAmCaKIo6Ph/yg73tj8/HZnILwyk4Px2tXfL4PO/HQ=
-github.com/aws/aws-sdk-go-v2/service/elasticloadbalancing v1.34.6 h1:bucMsYP3fQIJvyNCzb4EAFZFYAwidWsFTGUKpJUTi3M=
-github.com/aws/aws-sdk-go-v2/service/elasticloadbalancing v1.34.6/go.mod h1:uhWp16djmWOwENzHggk29rZ331UcOpfcLciIBdFCkm8=
-github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2 v1.55.4 h1:M/98mES2pXpnSYtBSdBZx/zo3CaT/oSxTXsYk1vYd8A=
-github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2 v1.55.4/go.mod h1:sUBnPF4iTc3KaCTIbLTr8xXjsnw8J0kXwr0nPCaAK3I=
-github.com/aws/aws-sdk-go-v2/service/iam v1.54.5 h1:a/gAOhIOi+vHYeRU224WIXlJrLXs4Z1Qbm92vfX64jc=
-github.com/aws/aws-sdk-go-v2/service/iam v1.54.5/go.mod h1:tMNzI+fYFCk4cIdZ7FEybLzShwnmWkfxQw85ED1b4ng=
-github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.12 h1:ZD2+BSw9vFsNlKYIasSNt3uDbjqqXIBcM13UJv/Lx2k=
-github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.12/go.mod h1:Ms4zlcVBbXbiP7EVLhl+lgjvA/a7YphqQ3Ih3174EmI=
-github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.22 h1:V51LGlOq/1VsDsHUdoklAQi7rMmx4qQubvFYAlP2254=
-github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.22/go.mod h1:4Pzhyz8hJOm2bepgl+NjvRx8vlUFAIIvJnZ/MkcNPpU=
-github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery v1.12.6 h1:Bs2OwYq0HBgHYwfGmUwYIPtTNaGMGAHkRje4jmW2VoI=
-github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery v1.12.6/go.mod h1:OTctu4cW8t7/TRlTKPLT6akzyOkfceMWhtEHqtYDIQQ=
-github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.29 h1:DRebniUGZ2MqiiIVmQJ04vIXr918hubdHMnarSLEWyU=
-github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.29/go.mod h1:LfRkPCD8YHDM2E5eTkos2UpwYeZnBcVarTa8L59bJHA=
-github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.29 h1:hiME6pBzC7OTl9LMtlyTWBuEl1f4QBcUmFDKC7MLXtc=
-github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.29/go.mod h1:G7RP+uhagpKtKhd1BM9N6JQqjCcGEU47K5lBVZQyRQw=
-github.com/aws/aws-sdk-go-v2/service/kms v1.53.4 h1:PEgVSsWtR8NNxsDxFL2Ywisi7R+1EFQARGsT4q3mWwI=
-github.com/aws/aws-sdk-go-v2/service/kms v1.53.4/go.mod h1:3EeKyDGPGSCEphG2OolwNGNF45RvQIfm27AYYpfEWrw=
-github.com/aws/aws-sdk-go-v2/service/lambda v1.93.0 h1:uEB7hBZO61H63g+rtUbJ5fjkxLw369wukdr4hCtaZ+M=
-github.com/aws/aws-sdk-go-v2/service/lambda v1.93.0/go.mod h1:3bF6WydfupDwCv8Q3g/Flt89341w/+NObn+KdQmLA60=
-github.com/aws/aws-sdk-go-v2/service/organizations v1.51.10 h1:k/1HG7/z3Ujtcq5+JDSSjp5GG8PzoPuY08Objd2oryI=
-github.com/aws/aws-sdk-go-v2/service/organizations v1.51.10/go.mod h1:PRk/TRj/93nQOVYKHCuBNCOBBLaH4lKhaKW5EB/ZR50=
-github.com/aws/aws-sdk-go-v2/service/rds v1.119.3 h1:SIGdk+wA+xGXgN+L7Jr3Ot83Mjh3jpjyJIwZd3DqAnU=
-github.com/aws/aws-sdk-go-v2/service/rds v1.119.3/go.mod h1:zCRPUdp05FEZG3OO7LmJq9xkSDjMEhkiVrZV0oJs2a0=
-github.com/aws/aws-sdk-go-v2/service/route53 v1.62.5 h1:Z+/OLsb85Kpq7TVLCspskqePaf68Tdv6GfmJP4kH6i0=
-github.com/aws/aws-sdk-go-v2/service/route53 v1.62.5/go.mod h1:TmxGowuBYwjmHFOsEDxaZdsQE62JJzOmtiWafTi/czg=
-github.com/aws/aws-sdk-go-v2/service/s3 v1.104.0 h1:ta8csKy5vN91F3i5gGR85lFV0srBqySEji7Jroes6rE=
-github.com/aws/aws-sdk-go-v2/service/s3 v1.104.0/go.mod h1:77ZAgynvx1txMvDG8gGWoWkO1augYDxkp9JElWFgjQU=
-github.com/aws/aws-sdk-go-v2/service/s3control v1.71.5 h1:sS08pq42o+zTTacHH2bILnVX+56jIDsAmlSRKYwsB/0=
-github.com/aws/aws-sdk-go-v2/service/s3control v1.71.5/go.mod h1:dCGIfoT6n2eToJDHoP380259fiV2AuqujN+YYZHemxo=
-github.com/aws/aws-sdk-go-v2/service/securityhub v1.71.7 h1:7H0Y7DA+SLT9U0ssRSIPo7+dMY5p6kXMU63ncCx8ayI=
-github.com/aws/aws-sdk-go-v2/service/securityhub v1.71.7/go.mod h1:SS/9UFk3PQyMZyKumEF7C8Z//TkUEd1AShPnzUbAKqQ=
-github.com/aws/aws-sdk-go-v2/service/signin v1.2.0 h1:3nXpRcFwRCW8n7HgO2QGy0Dc20eQNfBuUemGQhpF8m8=
-github.com/aws/aws-sdk-go-v2/service/signin v1.2.0/go.mod h1:LxYujSTLPRlp2vTtcUO/+1ilrew8ytt6SvQyOgejzFQ=
-github.com/aws/aws-sdk-go-v2/service/sns v1.40.1 h1:DLrOlgom0+OYnNaSiVxAXtR6obPjVlbmD+7w5wim9sc=
-github.com/aws/aws-sdk-go-v2/service/sns v1.40.1/go.mod h1:V9szvM64GdG5VJUeDRstvLmt/ozgWiSNg3gYnp3mSkk=
-github.com/aws/aws-sdk-go-v2/service/sqs v1.44.0 h1:6DQ95Zq5xPUSYm6KWcrar7zvreqAMFmyynYCcmzv6yc=
-github.com/aws/aws-sdk-go-v2/service/sqs v1.44.0/go.mod h1:d7eKytKiwDFJeNAP4VWo47VCiNM9z539tkoCGJ6PjXw=
-github.com/aws/aws-sdk-go-v2/service/sso v1.31.3 h1:ey1XLTYXb9PcLt4535632o5kCGXNXEhNb620Dqwuylo=
-github.com/aws/aws-sdk-go-v2/service/sso v1.31.3/go.mod h1:Lk7PlmoTYryQmyBG0EXqj5BcUbj3whXdU2s3yGI3EAc=
-github.com/aws/aws-sdk-go-v2/service/ssooidc v1.36.6 h1:yLr03zQE/5Eu5l3QU0Si+xMbLMbSDF2YXsigqXngs6g=
-github.com/aws/aws-sdk-go-v2/service/ssooidc v1.36.6/go.mod h1:Q5N6icH+KJZDLh+ESNwzdv6cZ6vLFF/egy3IOxWhmz4=
-github.com/aws/aws-sdk-go-v2/service/sts v1.43.3 h1:VrIhKRCSK1umelSgB9RghvA9RTUYeQffyAS5ApXehNI=
-github.com/aws/aws-sdk-go-v2/service/sts v1.43.3/go.mod h1:r8wkDOuLaaMFqFiYAb8dGY2A3gJCOujMc6CFOVC4Zhc=
+github.com/aws/aws-sdk-go-v2 v1.43.4 h1:b9FTvbRwy+JCsfp2Wp6wV/KbOx3Aj7nkoFb2cRX0IhE=
+github.com/aws/aws-sdk-go-v2 v1.43.4/go.mod h1:70vwSy16txshwG+g55WkpgPKDIByzHI8ccBsOteo3bQ=
+github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.16 h1:aiuaKlDweRC5qExJondpWjOgyzMHpofpwspGXUtwn4c=
+github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.16/go.mod h1:nG/LOlmox9BDe9HvQnXWzgcK8uKbgBMZ/Hp5pVt/21I=
+github.com/aws/aws-sdk-go-v2/config v1.32.35 h1:UEzXuET8E42lxBPijuACu/tEK7v5lFPlk0Q+GT5WD9E=
+github.com/aws/aws-sdk-go-v2/config v1.32.35/go.mod h1:KaMtJpFa2JlL2BStjjHQVwQpzZEmw+ND/EgVrfFoo2g=
+github.com/aws/aws-sdk-go-v2/credentials v1.19.34 h1:y6GkSmcv5myd1ngrYbGmiLlwQqB6TQhOuN/tbSSuWDY=
+github.com/aws/aws-sdk-go-v2/credentials v1.19.34/go.mod h1:w3dTcnDVoQIewjo7JG45hduAToikiIFLC4FIO7fndvw=
+github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.35 h1:+S7kbJoLDDQ5tE+lHrUBgMkzC8NLgsaioS2F3dVoFAE=
+github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.35/go.mod h1:Ak7xXviIARfFdNUJ9Etb0bdVDt/KAvKjMGJVLWXDzik=
+github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.35 h1:kzVuGlatQtYinwBJEEyLAbggepCoavosiaHHX9+fD+c=
+github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.35/go.mod h1:0yLx0yEI+SfqeJMPvOtIEFoZbiQYXMGszBueiutQyaI=
+github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.35 h1:WK6CjihTuLisCjSKKbildJ79sGZZgbBz3iNa7VsKIhU=
+github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.35/go.mod h1:KYleN57luLoe97R7vTnx8PMcVrr9gAcRECtOjl91DNg=
+github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.36 h1:jbGY4CXLzZElOXgGsexlC3Hi+3YM0rSmk4opFXKqg/k=
+github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.36/go.mod h1:uBu/9aKsS/UQGc72RAt3y54kjgYQxmhut8ZD2dXCDNE=
+github.com/aws/aws-sdk-go-v2/service/accessanalyzer v1.51.4 h1:DD5SFDxWC2jxmzOTM4b3fWeDSwlYtF52EFbCwyrxLy0=
+github.com/aws/aws-sdk-go-v2/service/accessanalyzer v1.51.4/go.mod h1:QQ3Hgba8rcs2c3Sjxu3cO4lT9140+UhwKRK6lL63sTI=
+github.com/aws/aws-sdk-go-v2/service/autoscaling v1.71.0 h1:hJQ504HwtUQ9g5UMpfnre3/b7Mi0xA6/FGc3DDqLJnY=
+github.com/aws/aws-sdk-go-v2/service/autoscaling v1.71.0/go.mod h1:pdYS3ehcIfN63Ma8l9PHkwwG3eLJ1z4Jxa0AIpg4sGU=
+github.com/aws/aws-sdk-go-v2/service/cloudformation v1.76.1 h1:UDQGJ9AuLcf4yiDKyHPGN4EirOLo/E8+Zfoii8FhyZs=
+github.com/aws/aws-sdk-go-v2/service/cloudformation v1.76.1/go.mod h1:tCsJEKr4HMFIZSnXLx6rU2HlptPtLhWWfw2V2j9p7lE=
+github.com/aws/aws-sdk-go-v2/service/cloudtrail v1.58.4 h1:Fh/6TN1aghBh46UYgRyZNLvqVm1MmB70gpTPMz6Bz4c=
+github.com/aws/aws-sdk-go-v2/service/cloudtrail v1.58.4/go.mod h1:s7TH/kP0aqYvQSWOV13Izaibuc7WqKQl/eGVUxzz1tg=
+github.com/aws/aws-sdk-go-v2/service/cloudwatch v1.66.3 h1:bpL3nRqFErK0i1AAjCnFT5hKovNOZsNzcG+U8wrCbuc=
+github.com/aws/aws-sdk-go-v2/service/cloudwatch v1.66.3/go.mod h1:wvC/zJUFlvcT+KTHLzpKe8PNU21NmTWrXxWBlzh0gTQ=
+github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs v1.82.0 h1:mA1eNuVy5LAapf4aMwIljmz9/MekiEPhohr1maGUwvw=
+github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs v1.82.0/go.mod h1:o61Nvqd2pIpM6QHfChgSyQRvdIJzF0AHTss5ehFFfO0=
+github.com/aws/aws-sdk-go-v2/service/configservice v1.68.4 h1:L37DoV4JOQFqucVUeYaJrrhIc1995EPra+8UtGRCsgo=
+github.com/aws/aws-sdk-go-v2/service/configservice v1.68.4/go.mod h1:CcqHkp94OiUOXcUgSc2moHZ97ISugWDoClGhmW17CFg=
+github.com/aws/aws-sdk-go-v2/service/dynamodb v1.63.1 h1:QKBYxujKuCD0QwBfqmrgnuzORIg4r8ODr53bIYI/7lQ=
+github.com/aws/aws-sdk-go-v2/service/dynamodb v1.63.1/go.mod h1:ygCTS0/CdRkdwVDKMq1yo0NNsKR1cQCGPDP1iY78FRY=
+github.com/aws/aws-sdk-go-v2/service/ebs v1.36.4 h1:e2U8u0Qp4veR4FYo9rJWal5MMg7/QHQkz1KJ1s41uh4=
+github.com/aws/aws-sdk-go-v2/service/ebs v1.36.4/go.mod h1:Nqm1Vp6vQniSVAKzz34cfdHJ1nsuexHzsKkofHNzasU=
+github.com/aws/aws-sdk-go-v2/service/ec2 v1.321.0 h1:XxzwotCCRk2Un1OWcJujk4vAC2OZkGh5l816W1w+Fd8=
+github.com/aws/aws-sdk-go-v2/service/ec2 v1.321.0/go.mod h1:Gi5mEHpABbT34fHwafgyxqrIte9oHUEHscusPBYEdHA=
+github.com/aws/aws-sdk-go-v2/service/ecr v1.60.4 h1:qIgueZwgw+rANqXuL1Cjk2Lm/Pihbw2nx3C1D7eQD+k=
+github.com/aws/aws-sdk-go-v2/service/ecr v1.60.4/go.mod h1:Jr9Mh7l72YtNr8nmEwcJiU4xwCerZB8/krBWW4RckmY=
+github.com/aws/aws-sdk-go-v2/service/eks v1.90.4 h1:WYOOdUEfAom4j2Jfi0iL42d4ROsDX5/Hs1HkH+58Fl8=
+github.com/aws/aws-sdk-go-v2/service/eks v1.90.4/go.mod h1:aRJV0DQ7WnK5npu6r7Fe619TyiLLsyFLGfe8hI2IfVs=
+github.com/aws/aws-sdk-go-v2/service/elasticloadbalancing v1.36.4 h1:iWvY8WbmY6+N4Oj+lLqp7lk5BalgiNtga/JIzvpzR1U=
+github.com/aws/aws-sdk-go-v2/service/elasticloadbalancing v1.36.4/go.mod h1:FqzuVgj0wplQs5Wc+XAo6UmGUjPqLPbmjoMvJlB8+Qg=
+github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2 v1.58.5 h1:3Zphqh8L0blfkrdUv270L8RuNy0RvltPMaskEbs+Xo8=
+github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2 v1.58.5/go.mod h1:Mr4sgkXQN58SJTNJq64yKOrHzA9cqbS2MKExmDCtdcY=
+github.com/aws/aws-sdk-go-v2/service/iam v1.58.1 h1:zfcqlttrsc7l4bPHtnPlOGripqUsq7gH7hK7IOy4Mks=
+github.com/aws/aws-sdk-go-v2/service/iam v1.58.1/go.mod h1:jrh5pABhfjnixtuljy4rP6LiPuibJ61dg3PAKv65XsU=
+github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.15 h1:JJLBQxwY+AFwuPAi5ivGc1ChnTdUt4cXMv7e76m2c/Y=
+github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.15/go.mod h1:lQknBIe78MVL0cQOQDlag8KGflMbMEVFx9mB6O8ENvk=
+github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.28 h1:Q1TF1J9jVD+vFo0LzNnmNdQ9EAt52TS+MQlq9Ir+Yxo=
+github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.28/go.mod h1:4KqXXC/p1hrotmouDFbrRoWaLy962b9PMUReCG6+uWo=
+github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery v1.12.12 h1:JiBaijClgXE98o7qCTU3wXvLY2ht3mbbXUfEV6oP3LY=
+github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery v1.12.12/go.mod h1:2jd+Rjsg3BeToVNAJT2l2FQ4FQt8nd3488jydlmB82E=
+github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.35 h1:BBEElKh4a+rKshvjrfpajTe9CbpZvrbb4Jkg2PB7RzA=
+github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.35/go.mod h1:zaZk983w//8beSruBVec/mr4CmDwgZitW/qzGhAAX0g=
+github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.36 h1:EUIwBoN+q7UmhAejxgD27APiRjh1vwCFo53gSqdT0BM=
+github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.36/go.mod h1:6u00gmlTGR6W0b2k9NBrld7MnOEmf1Spqx0VVt6AqyE=
+github.com/aws/aws-sdk-go-v2/service/kms v1.55.4 h1:8T9CDPlcIUpXTKXXfMMFtD1eujGXbVysGiidx79bTkc=
+github.com/aws/aws-sdk-go-v2/service/kms v1.55.4/go.mod h1:XlYycjMbh9zYnTPpjUropzSDngZd/x37jNa9vGHA7hE=
+github.com/aws/aws-sdk-go-v2/service/lambda v1.101.2 h1:CkTYIMCfXy2/Td2jLBqw341cNYbRxwSCNPxdDm5COXc=
+github.com/aws/aws-sdk-go-v2/service/lambda v1.101.2/go.mod h1:1YzSvApzBChjIuI1UN2cN2roWoGjR/V7Ch3+pfIfyN0=
+github.com/aws/aws-sdk-go-v2/service/organizations v1.53.5 h1:K0Ayr+MNVSkEVbD/dnQ1/bVDcFqKl2CNoF/ZfMUoSDI=
+github.com/aws/aws-sdk-go-v2/service/organizations v1.53.5/go.mod h1:mJSUa59X8tlEX0DVvxdHZvMMrll/65omXLuwk2FCRDw=
+github.com/aws/aws-sdk-go-v2/service/rds v1.124.1 h1:tEeu5kuP2MLQ7drmlN4qYiBKVoUftyBiS6dSFN67pYc=
+github.com/aws/aws-sdk-go-v2/service/rds v1.124.1/go.mod h1:qciN0v66sYiwRf+YRkus1mQR0XldavqGIQEzTxc2vb0=
+github.com/aws/aws-sdk-go-v2/service/route53 v1.65.6 h1:MDZUFQEVG3S6W+VmhQ9qlbprAuPZDfvvWZTg+HZU0o0=
+github.com/aws/aws-sdk-go-v2/service/route53 v1.65.6/go.mod h1:mh85zjA/hf1PtItwFXA9Yb/2zgUCEYpkN9QmzrK4RNc=
+github.com/aws/aws-sdk-go-v2/service/s3 v1.107.0 h1:OkYV+1171za+ab9otU1tGxMXhx6uZvwVEtVddjLuYTg=
+github.com/aws/aws-sdk-go-v2/service/s3 v1.107.0/go.mod h1:5FTZoQxhmLEiCAtYVk6V+t0iS/B5yGZVLZ3Wq5FDJZI=
+github.com/aws/aws-sdk-go-v2/service/s3control v1.73.4 h1:iLaMpTt0YOtycNqDY6vOS8ghR+5lxv3s1CSvCiezhXk=
+github.com/aws/aws-sdk-go-v2/service/s3control v1.73.4/go.mod h1:9mOGHKkx2NOZnCHDis0ykauoNoE8wdUba2MrZjHki38=
+github.com/aws/aws-sdk-go-v2/service/securityhub v1.76.0 h1:J/olEWGa5NIIZiejnuG4u+ahM5liNIKa07sEP5OPbqs=
+github.com/aws/aws-sdk-go-v2/service/securityhub v1.76.0/go.mod h1:zHr00dDys+8JbwQALvat8WGyudYfzc2W3dw79e+bSWs=
+github.com/aws/aws-sdk-go-v2/service/signin v1.5.4 h1:cOJELVNrq5Q3Udry2GLuHUM7MhwpeaQRdYaoa6GI/yI=
+github.com/aws/aws-sdk-go-v2/service/signin v1.5.4/go.mod h1:f4LxzKBtaTxD7xh3PiVg3CE1tchQemfmghaJr+NbK2c=
+github.com/aws/aws-sdk-go-v2/service/sns v1.42.4 h1:cregOIHGsHahN/VX2Jd7oPjYSF0HUnz9YUJDHKsZJMU=
+github.com/aws/aws-sdk-go-v2/service/sns v1.42.4/go.mod h1:EfxXlpPsLpJfVw6ykt9dGnao+OaEDVU4p69UaJQlBHs=
+github.com/aws/aws-sdk-go-v2/service/sqs v1.46.4 h1:Uqz9kiRjrhLwoVHEPt+ZT/n62UeAYxLHPetT6ImySBU=
+github.com/aws/aws-sdk-go-v2/service/sqs v1.46.4/go.mod h1:5QpAlDsMzDn2GUBCgs+pw52OLZzS4Sf3jOQDe4KSoVI=
+github.com/aws/aws-sdk-go-v2/service/sso v1.33.4 h1:AMW7a7S8iQaHjBYZdU3PCq4GKRPijTPRAc7e6XtEThY=
+github.com/aws/aws-sdk-go-v2/service/sso v1.33.4/go.mod h1:QQNsFV1DVXoXcZt18FS8lI8rtUrlDyAuWZLQ5shunv4=
+github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.4 h1:AsbZcJAQPRmHDJG8K1N0pof/1zPWjVT8TFlTWuGLSvo=
+github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.4/go.mod h1:6imqztH0//t0mKbl6yWl7swSEl7F/w32oAmqB3vP1ag=
+github.com/aws/aws-sdk-go-v2/service/sts v1.45.4 h1:w/AryDYMjSUANSQ2uoZxJovUsMTwWJNTv3IMex30Y+4=
+github.com/aws/aws-sdk-go-v2/service/sts v1.45.4/go.mod h1:WeBiAa67azG7Su9Vf+ChGDBLiAozJCXzdjXiPBUwtbc=
github.com/aws/smithy-go v1.27.7 h1:Zgj5z4LfcDYoQIVk+n/yGdTkP/2y6ZT5vYxe0fp7bqE=
github.com/aws/smithy-go v1.27.7/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc=
github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM=
From b46aad0c205109c2f44d58b0d01fe88a53186028 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 03:56:32 +0000
Subject: [PATCH 68/70] fix(deps): update azure-sdk (9.5) (#7825)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/Azure/azure-sdk-for-go/sdk/azcore](https://redirect.github.com/Azure/azure-sdk-for-go)
| `v1.21.1` → `v1.22.0` |

|

|
|
[github.com/Azure/azure-sdk-for-go/sdk/azidentity](https://redirect.github.com/Azure/azure-sdk-for-go)
| `v1.13.1` → `v1.14.0` |

|

|
|
[github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/monitor/armmonitor](https://redirect.github.com/Azure/azure-sdk-for-go)
| `v0.11.0` → `v0.13.0` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 7 +++----
go.sum | 16 ++++++++--------
2 files changed, 11 insertions(+), 12 deletions(-)
diff --git a/go.mod b/go.mod
index 5cea650127..207728b919 100644
--- a/go.mod
+++ b/go.mod
@@ -5,9 +5,9 @@ go 1.26.3
require (
cloud.google.com/go/asset v1.27.0
cloud.google.com/go/iam v1.11.0
- github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1
+ github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.14.0
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/keyvault/armkeyvault/v2 v2.0.2
- github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/monitor/armmonitor v0.11.0
+ github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/monitor/armmonitor v0.13.0
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/mysql/armmysqlflexibleservers v1.2.0
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/postgresql/armpostgresql v1.2.0
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/postgresql/armpostgresqlflexibleservers/v5 v5.0.0
@@ -129,7 +129,6 @@ require (
dario.cat/mergo v1.0.2 // indirect
github.com/Azure/azure-sdk-for-go/sdk/containers/azcontainerregistry v0.2.3 // indirect
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/containerservice/armcontainerservice/v4 v4.8.0 // indirect
- github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/internal/v3 v3.2.0 // indirect
github.com/Azure/go-ntlmssp v0.1.1 // indirect
github.com/DataDog/zstd v1.5.7 // indirect
github.com/GoogleCloudPlatform/docker-credential-gcr/v2 v2.1.32 // indirect
@@ -331,7 +330,7 @@ require (
cloud.google.com/go/orgpolicy v1.20.0 // indirect
cloud.google.com/go/osconfig v1.21.0 // indirect
cloud.google.com/go/storage v1.62.3 // indirect
- github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.1
+ github.com/Azure/azure-sdk-for-go/sdk/azcore v1.22.0
github.com/Azure/azure-sdk-for-go/sdk/internal v1.12.0 // indirect
github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c // indirect
github.com/AzureAD/microsoft-authentication-library-for-go v1.8.0 // indirect
diff --git a/go.sum b/go.sum
index 5c2fc701c9..20b6db06c2 100644
--- a/go.sum
+++ b/go.sum
@@ -45,12 +45,12 @@ github.com/AdaLogics/go-fuzz-headers v0.0.0-20240806141605-e8a1dd7889d6/go.mod h
github.com/AdamKorcz/go-fuzz-headers-1 v0.0.0-20230919221257-8b5d3ce2d11d h1:zjqpY4C7H15HjRPEenkS4SAn3Jy2eRRjkjZbGR30TOg=
github.com/AdamKorcz/go-fuzz-headers-1 v0.0.0-20230919221257-8b5d3ce2d11d/go.mod h1:XNqJ7hv2kY++g8XEHREpi+JqZo3+0l+CH2egBVN4yqM=
github.com/Azure/azure-sdk-for-go v68.0.0+incompatible h1:fcYLmCpyNYRnvJbPerq7U0hS+6+I79yEDJBqVNcqUzU=
-github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.1 h1:jHb/wfvRikGdxMXYV3QG/SzUOPYN9KEUUuC0Yd0/vC0=
-github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.1/go.mod h1:pzBXCYn05zvYIrwLgtK8Ap8QcjRg+0i76tMQdWN6wOk=
-github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1 h1:Hk5QBxZQC1jb2Fwj6mpzme37xbCDdNTxU7O9eb5+LB4=
-github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1/go.mod h1:IYus9qsFobWIc2YVwe/WPjcnyCkPKtnHAqUYeebc8z0=
-github.com/Azure/azure-sdk-for-go/sdk/azidentity/cache v0.3.2 h1:yz1bePFlP5Vws5+8ez6T3HWXPmwOK7Yvq8QxDBD3SKY=
-github.com/Azure/azure-sdk-for-go/sdk/azidentity/cache v0.3.2/go.mod h1:Pa9ZNPuoNu/GztvBSKk9J1cDJW6vk/n0zLtV4mgd8N8=
+github.com/Azure/azure-sdk-for-go/sdk/azcore v1.22.0 h1:aokoqcHvaGjiM3VpjKDfMMnF/8epJ+Q1HLJ7CudztqE=
+github.com/Azure/azure-sdk-for-go/sdk/azcore v1.22.0/go.mod h1:/WYEx9pcM9Y+Dd/APJaNlSvVSvzl54rrMdZT5+Oi2LM=
+github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.14.0 h1:CU4+EJeJi3TKYWEcYuSdWsjzw0nVsK/H0MSQOiPcymU=
+github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.14.0/go.mod h1:q0+UTSRvShwUCrR/s5HtyInYphN7Wvxb7snFM3u+SLA=
+github.com/Azure/azure-sdk-for-go/sdk/azidentity/cache v0.4.0 h1:xFaZZ+IubdftrDHnGGwZ6QvQ3KHTtWl2MCK+GMt2vxs=
+github.com/Azure/azure-sdk-for-go/sdk/azidentity/cache v0.4.0/go.mod h1:mCBhUhlMjLLJKr5aqw2TNS/VqJOie8MzWq3DAMJeKso=
github.com/Azure/azure-sdk-for-go/sdk/containers/azcontainerregistry v0.2.3 h1:ldKsKtEIblsgsr6mPwrd9yRntoX6uLz/K89wsldwx/k=
github.com/Azure/azure-sdk-for-go/sdk/containers/azcontainerregistry v0.2.3/go.mod h1:MAm7bk0oDLmD8yIkvfbxPW04fxzphPyL+7GzwHxOp6Y=
github.com/Azure/azure-sdk-for-go/sdk/internal v1.12.0 h1:fhqpLE3UEXi9lPaBRpQ6XuRW0nU7hgg4zlmZZa+a9q4=
@@ -65,8 +65,8 @@ github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/internal/v3 v3.2.0 h1:+lnL
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/internal/v3 v3.2.0/go.mod h1:tStOHrivWUrcBolspvKV70Us1ckESYGYSHdG4LX8zyY=
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/keyvault/armkeyvault/v2 v2.0.2 h1:O2iuZYGa1nIMDk2uAFR0F7hDALVXMvz8Zwarz6itQ3E=
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/keyvault/armkeyvault/v2 v2.0.2/go.mod h1:7t88hsh6P4xqFM9uzaMX2qYfVsqDFkgFR4qdIX/OP+U=
-github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/monitor/armmonitor v0.11.0 h1:Ds0KRF8ggpEGg4Vo42oX1cIt/IfOhHWJBikksZbVxeg=
-github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/monitor/armmonitor v0.11.0/go.mod h1:jj6P8ybImR+5topJ+eH6fgcemSFBmU6/6bFF8KkwuDI=
+github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/monitor/armmonitor v0.13.0 h1:c7r8eBbYWf2JbQFinuEbHsqq+ukY1tVIgAxt0uND2Fo=
+github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/monitor/armmonitor v0.13.0/go.mod h1:HCaM3KUBkHyt9NJLP/gFdMa16WWzygEQE5oUw9NjiD4=
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/mysql/armmysqlflexibleservers v1.2.0 h1:3jDMffAwnvs6qmOqhjNVHB29AKxs6brnzJeo65E1YwM=
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/mysql/armmysqlflexibleservers v1.2.0/go.mod h1:0mKVz3WT8oNjBunT1zD/HPwMleQ72QClMa7Gmsm+6Kc=
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/postgresql/armpostgresql v1.2.0 h1:0hXKrsbh2M6CQyW0TDC9Bsyd99vQmrOxiBTUfQHZjPA=
From ac774746c93d4d2129a87851c095253e5bfa05a2 Mon Sep 17 00:00:00 2001
From: "elastic-renovate-prod[bot]"
<174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 03:57:53 +0000
Subject: [PATCH 69/70] fix(deps): update module
github.com/microsoftgraph/msgraph-sdk-go to v1.101.0 (9.5) (#7829)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/microsoftgraph/msgraph-sdk-go](https://redirect.github.com/microsoftgraph/msgraph-sdk-go)
| `v1.99.0` → `v1.101.0` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
microsoftgraph/msgraph-sdk-go
(github.com/microsoftgraph/msgraph-sdk-go)
###
[`v1.101.0`](https://redirect.github.com/microsoftgraph/msgraph-sdk-go/releases/tag/v1.101.0)
[Compare
Source](https://redirect.github.com/microsoftgraph/msgraph-sdk-go/compare/v1.100.0...v1.101.0)
##### Features
- **generation:** update request builders and models
([388f40e](https://redirect.github.com/microsoftgraph/msgraph-sdk-go/commit/388f40ebf697f4185a0e7837815257069b44a0de))
###
[`v1.100.0`](https://redirect.github.com/microsoftgraph/msgraph-sdk-go/releases/tag/v1.100.0)
[Compare
Source](https://redirect.github.com/microsoftgraph/msgraph-sdk-go/compare/v1.99.0...v1.100.0)
##### Features
- **generation:** update request builders and models
([c8f08e8](https://redirect.github.com/microsoftgraph/msgraph-sdk-go/commit/c8f08e8aa9e3b2c0058a974015712ea924ec4a06))
- **generation:** update request builders and models
([44f234d](https://redirect.github.com/microsoftgraph/msgraph-sdk-go/commit/44f234dc4000e9ef9c03f176e9fcb7f7ce60c521))
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
---
go.mod | 2 +-
go.sum | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/go.mod b/go.mod
index 207728b919..7b1582d079 100644
--- a/go.mod
+++ b/go.mod
@@ -66,7 +66,7 @@ require (
github.com/magefile/mage v1.17.2
github.com/masahiro331/go-xfs-filesystem v0.0.0-20260422061116-d21e5e4481bb
github.com/microsoft/kiota-abstractions-go v1.9.4
- github.com/microsoftgraph/msgraph-sdk-go v1.99.0
+ github.com/microsoftgraph/msgraph-sdk-go v1.101.0
github.com/microsoftgraph/msgraph-sdk-go-core v1.4.1
github.com/mikefarah/yq/v4 v4.53.3
github.com/mitchellh/gox v1.0.1
diff --git a/go.sum b/go.sum
index 20b6db06c2..b1198789c1 100644
--- a/go.sum
+++ b/go.sum
@@ -999,8 +999,8 @@ github.com/microsoft/kiota-serialization-multipart-go v1.1.2 h1:1pUyA1QgIeKslQwb
github.com/microsoft/kiota-serialization-multipart-go v1.1.2/go.mod h1:j2K7ZyYErloDu7Kuuk993DsvfoP7LPWvAo7rfDpdPio=
github.com/microsoft/kiota-serialization-text-go v1.1.3 h1:8z7Cebn0YAAr++xswVgfdxZjnAZ4GOB9O7XP4+r5r/M=
github.com/microsoft/kiota-serialization-text-go v1.1.3/go.mod h1:NDSvz4A3QalGMjNboKKQI9wR+8k+ih8UuagNmzIRgTQ=
-github.com/microsoftgraph/msgraph-sdk-go v1.99.0 h1:FRR4RcbuhKBQP3klg4jCp05ntz/NrmZtd3tYILqGt8A=
-github.com/microsoftgraph/msgraph-sdk-go v1.99.0/go.mod h1:qxzY5SaoPigY6/Dpyfg4uigQjNDvL+sZl6fzD6EpWeQ=
+github.com/microsoftgraph/msgraph-sdk-go v1.101.0 h1:9Ox6mlDTm9BroNpj9i4B241OIcnyv0kjwJHHNaeXkoY=
+github.com/microsoftgraph/msgraph-sdk-go v1.101.0/go.mod h1:qxzY5SaoPigY6/Dpyfg4uigQjNDvL+sZl6fzD6EpWeQ=
github.com/microsoftgraph/msgraph-sdk-go-core v1.4.1 h1:k3YIaJm57ufoEX0KdsEY4l1X9BAMxEqrwr4a7WMRDzY=
github.com/microsoftgraph/msgraph-sdk-go-core v1.4.1/go.mod h1:yNqPNhXee2w9cZzkJW5mL1utVMSInsQSo/TyEB5sup8=
github.com/miekg/dns v1.1.72 h1:vhmr+TF2A3tuoGNkLDFK9zi36F2LS+hKTRW0Uf8kbzI=
From c7c4cdbbcd6457f1af2ae962a8c3140eab30e5c2 Mon Sep 17 00:00:00 2001
From: Oleg Sucharevich
Date: Tue, 11 Aug 2026 15:11:59 -0500
Subject: [PATCH 70/70] ci: pin security-policies poetry env to python3.11
Hermit's pre-commit package bumped its runtime dependency from
python3@3.9 to python3@3.14 (cashapp/hermit-packages#773), so hooks
launched through pre-commit now see python3.14 first on PATH. Poetry 2.x
resolves the interpreter from PATH, and since security-policies declares
requires-python = ">=3.11", python3.14 satisfies it: the
"poetry run -C security-policies" hooks created a fresh, empty 3.14
virtualenv instead of reusing the 3.11 one built during setup, failing
with "ModuleNotFoundError: No module named 'git'".
Pinning the env with "poetry env use python3.11" records the selection in
envs.toml so every later "poetry run" reuses the env that actually has
the dependencies installed.
Same fix already applied on 9.4 in #4759.
---
.github/actions/hermit/action.yml | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/.github/actions/hermit/action.yml b/.github/actions/hermit/action.yml
index 6a741ffdd8..82cdb155e6 100644
--- a/.github/actions/hermit/action.yml
+++ b/.github/actions/hermit/action.yml
@@ -94,7 +94,10 @@ runs:
- if: ${{ inputs.init-tools == 'true' }}
name: Install security-policies poetry dependencies
shell: bash
- run: cd ./security-policies && poetry install --no-root
+ run: |
+ cd ./security-policies
+ poetry env use python3.11
+ poetry install --no-root
- if: ${{ inputs.init-tools == 'true' }}
name: Install pre-commit repos
shell: bash