Skip to content

chore(deps): bump osv-scanner to v2.3.8 and update indirect dependencies#592

Open
tolzhabayev wants to merge 2 commits into
mainfrom
chore/bump-osv-scanner-v2.3.8
Open

chore(deps): bump osv-scanner to v2.3.8 and update indirect dependencies#592
tolzhabayev wants to merge 2 commits into
mainfrom
chore/bump-osv-scanner-v2.3.8

Conversation

@tolzhabayev
Copy link
Copy Markdown
Contributor

Summary

  • Bumps github.com/google/osv-scanner/v2 from v2.3.1 to v2.3.8
  • Updates all indirect dependencies pulled in transitively (docker, containerd, moby, go-containerregistry, etc.)
  • Go toolchain version in go.mod bumped from 1.25.5 → 1.26.2 (required by osv-scanner v2.3.8)

Test plan

  • go build ./... succeeds
  • go test ./pkg/analysis/passes/osvscanner/... passes

@tolzhabayev tolzhabayev requested a review from a team as a code owner May 20, 2026 15:15
@tolzhabayev tolzhabayev self-assigned this May 20, 2026
@tolzhabayev tolzhabayev moved this from 📬 Triage to 🔬 In review in Grafana Catalog Team May 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: 🔬 In review

Development

Successfully merging this pull request may close these issues.

1 participant