Skip to content

build(deps): bump the gomod group across 1 directory with 2 updates - #3652

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/gomod-4d13c09ff4
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/gomod-4d13c09ff4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the gomod group with 2 updates in the / directory: github.com/jferrl/go-githubauth and golang.org/x/crypto.

Updates github.com/jferrl/go-githubauth from 1.7.0 to 1.9.1

Release notes

Sourced from github.com/jferrl/go-githubauth's releases.

v1.9.1

Changelog

  • 5500ebe3a9dfdca8572d6fccb60be4dc2f90496c fix: publish the Homebrew cask

Installing the CLI

Download the archive for your platform above, or:

go install github.com/jferrl/go-githubauth/cmd/githubauth@v1.9.1

Verify a download against checksums.txt:

sha256sum -c checksums.txt --ignore-missing

The library is unaffected by these artifacts:

go get github.com/jferrl/go-githubauth@v1.9.1

v1.9.0

Changelog

  • 17a86eeeaff8c311f4c40e5bd968f865c6ac4717 feat: add a githubauth command line tool
  • 1240d11b08184cc6f605a56f70b9cb4ad36767ab feat: publish a Homebrew cask for the CLI
  • 0b56e29c33841506764f024a5032e00f01c7adab feat: publish prebuilt CLI binaries with GoReleaser

Installing the CLI

Download the archive for your platform above, or:

go install github.com/jferrl/go-githubauth/cmd/githubauth@v1.9.0

Verify a download against checksums.txt:

sha256sum -c checksums.txt --ignore-missing

The library is unaffected by these artifacts:

go get github.com/jferrl/go-githubauth@v1.9.0

... (truncated)

Changelog

Sourced from github.com/jferrl/go-githubauth's changelog.

[v1.9.1] - 2026-09-19

Fixed

  • The v1.9.0 release published its binaries and checksums but not the Homebrew cask. GoReleaser requires the tap token to be written as exactly {{ .Env.VAR }} and rejects any other form; the config used {{ index .Env "VAR" }}. The rule is enforced when publishing, so goreleaser check and snapshot builds both accepted it.

    brew install jferrl/tap/githubauth works from this release on. The v1.9.0 archives were unaffected and remain valid.

[v1.9.0] - 2026-09-19

The library is unchanged. This release is the githubauth command line tool and the machinery to distribute it, so a shell script or CI step can get an installation token without a Go toolchain.

Added

  • cmd/githubauth, a command line tool that prints an installation token or the App JWT, so a shell script or CI step can authenticate as a GitHub App without reimplementing the JWT-then-exchange chain. Install it with go install github.com/jferrl/go-githubauth/cmd/githubauth@latest.

    The token is the only thing written to stdout, so $(githubauth token) composes with curl and friends. Every flag falls back to an environment variable, and --key accepts a file path, the PEM itself, or - to read stdin so the key never has to touch disk.

    It adds no module dependencies. The CLI is built on the standard library's flag, so the two-dependency footprint is unchanged for anyone importing the library.

  • Prebuilt githubauth binaries on each release, for Linux, macOS and Windows on amd64 and arm64, with a checksums.txt to verify them. A tagged release builds them with GoReleaser; the library is unaffected and is still consumed with go get.

  • A Homebrew cask, so the CLI installs without a Go toolchain:

    brew install jferrl/tap/githubauth

    The cask is generated into jferrl/homebrew-tap when a release is tagged.

Fixed

  • githubauth version reported a pseudo-version for a binary that was not installed with go install. A release build now carries its tag, and a build from a checkout falls

... (truncated)

Commits
  • 50b8e00 Merge pull request #74 from jferrl/fix/cask-token-template
  • 5500ebe fix: publish the Homebrew cask
  • 8761b3f Merge pull request #73 from jferrl/chore/release-v1.9.0
  • 1d4a894 chore: cut the v1.9.0 changelog
  • 2d94e7b Merge pull request #72 from jferrl/feat/goreleaser
  • fc7fad3 ci: say in the log whether the Homebrew cask will publish
  • 1240d11 feat: publish a Homebrew cask for the CLI
  • 9204502 Merge pull request #71 from jferrl/perf/cache-hit-benchmark
  • 0b56e29 feat: publish prebuilt CLI binaries with GoReleaser
  • 487cbe9 test: benchmark the installation token cache hit
  • Additional commits viewable in compare view

Updates golang.org/x/crypto from 0.56.0 to 0.57.0

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the gomod group with 2 updates in the / directory: [github.com/jferrl/go-githubauth](https://github.com/jferrl/go-githubauth) and [golang.org/x/crypto](https://github.com/golang/crypto).


Updates `github.com/jferrl/go-githubauth` from 1.7.0 to 1.9.1
- [Release notes](https://github.com/jferrl/go-githubauth/releases)
- [Changelog](https://github.com/jferrl/go-githubauth/blob/main/CHANGELOG.md)
- [Commits](jferrl/go-githubauth@v1.7.0...v1.9.1)

Updates `golang.org/x/crypto` from 0.56.0 to 0.57.0
- [Commits](golang/crypto@v0.56.0...v0.57.0)

---
updated-dependencies:
- dependency-name: github.com/jferrl/go-githubauth
  dependency-version: 1.9.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod
- dependency-name: golang.org/x/crypto
  dependency-version: 0.57.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 24, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants