Skip to content

chore(deps): bump the go-dependencies group with 2 updates - #1196

Merged
mbevc1 merged 1 commit into
mainfrom
dependabot/go_modules/go-dependencies-bd3d3a2300
Sep 16, 2026
Merged

mbevc1 merged 1 commit into
mainfrom
dependabot/go_modules/go-dependencies-bd3d3a2300

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 16, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-dependencies group with 2 updates: github.com/mattn/go-shellwords and golang.org/x/sync.

Updates github.com/mattn/go-shellwords from 1.0.14 to 1.0.15

Release notes

Sourced from github.com/mattn/go-shellwords's releases.

v1.0.15

What's Changed

New Contributors

Full Changelog: mattn/go-shellwords@v1.0.14...v1.0.15

Commits
  • f40666a Merge pull request #77 from vitalivo/fix/comments-after-empty-quotes
  • f7c60ee Keep hash characters following empty quotes as word content
  • See full diff in compare view

Updates golang.org/x/sync from 0.22.0 to 0.23.0

Commits
  • f75267d semaphore: panic on negative capacity
  • 3ffd83c all: upgrade go directive to at least 1.26.0 [generated]
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-dependencies group with 2 updates: [github.com/mattn/go-shellwords](https://github.com/mattn/go-shellwords) and [golang.org/x/sync](https://github.com/golang/sync).


Updates `github.com/mattn/go-shellwords` from 1.0.14 to 1.0.15
- [Release notes](https://github.com/mattn/go-shellwords/releases)
- [Commits](mattn/go-shellwords@v1.0.14...v1.0.15)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](golang/sync@v0.22.0...v0.23.0)

---
updated-dependencies:
- dependency-name: github.com/mattn/go-shellwords
  dependency-version: 1.0.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 16, 2026
@github-actions github-actions Bot added chore and removed go Pull requests that update go code labels Sep 16, 2026
@claude

claude Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @dependabot[bot]'s task in 1m 55s —— View job


Dependency upgrade review

  • Identify changed dependencies
  • Check upstream changelogs / semver risk
  • Find in-repo usage of each dependency
  • Assess risk per call site
  • Post review

Verdict: safe to merge. Both bumps are patch/minor with narrow upstream changes, and neither touches a code path this repo depends on. No code changes needed.


github.com/mattn/go-shellwords 1.0.14 → 1.0.15

One upstream commit: "Keep hash characters following empty quotes as word content" (#77).

  • Single usage in the repo: shellwords.Parse(cmd) at cmd/kosli/testHelpers.go:60, used to split the cmd string of cmdTestCase into argv. Test-only — it is not linked into the shipped kosli binary, so there is zero runtime risk for users.
  • The behavior change only bites on input where a # directly follows an empty quote pair (""#… / ''#…). I grepped cmd/ for that pattern in test command strings — no matches, so no golden files or test expectations should move.

Risk: negligible.

golang.org/x/sync 0.22.0 → 0.23.0

Two upstream commits, both relevant to check:

  1. semaphore: panic on negative capacity — semaphore.NewWeighted(n) now panics for n < 0 instead of returning a permanently-unacquirable semaphore. The only call site is internal/aws/aws.go:690:

    budget := semaphore.NewWeighted(max(limits.BytesInFlight, 1))

    The max(..., 1) floor means the argument is always ≥ 1, so the new panic is unreachable regardless of what --download-budget resolves to. resolveDownloadLimits (cmd/kosli/snapshotS3.go:178) is also the only producer of non-default limits and it validates before constructing. Also fine: the Acquire weight at aws.go:709 is clamped with max(min(object.size, limits.BytesInFlight), 1), so it can never exceed capacity and deadlock. Nothing else in the repo uses errgroup/singleflight (the sem <- struct{}{} in internal/kube/kube.go:143 is a hand-rolled channel semaphore, unaffected).

  2. all: upgrade go directive to at least 1.26.0 — x/sync's own go.mod now requires Go ≥ 1.26.0. This repo already satisfies it everywhere I checked: go.mod declares go 1.26.7, .go-version (used by every CI workflow via go-version-file) is 1.26, and Dockerfile pins ARG GO_VERSION="1.26". No toolchain bump needed. Worth knowing for anyone building locally on an older Go: this is now a hard floor rather than a preference.

Risk: low.

Suggested follow-up checks

  • The S3 parallel-download suite is the only code exercising the upgraded semaphore — worth a targeted run before merge: make test_integration_single TARGET=S3ParallelTestSuite (see internal/aws/s3_parallel_test.go, incl. the byte-budget assertions at lines 121–148).
  • Normal CI is sufficient coverage for the shellwords bump, since every command test parses its cmd string through it.

Not verified

go build / go test and outbound network fetches weren't permitted in this sandbox, so I did not compile the module or read the upstream diffs directly — the changelog analysis above is based on the release notes/commit titles in the PR body plus static reading of the call sites. CI on this PR covers the compile-and-test half.
· Branch

@mbevc1
mbevc1 enabled auto-merge (squash) September 16, 2026 07:46
@mbevc1
mbevc1 merged commit a358647 into main Sep 16, 2026
17 checks passed
@mbevc1
mbevc1 deleted the dependabot/go_modules/go-dependencies-bd3d3a2300 branch September 16, 2026 07:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant