Skip to content

Bump the tools group in /tools with 2 updates - #39

Merged
xet7 merged 1 commit into
main-v1from
dependabot/go_modules/tools/tools-517f3ffe34
Oct 7, 2026
Merged

xet7 merged 1 commit into
main-v1from
dependabot/go_modules/tools/tools-517f3ffe34

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown

Bumps the tools group in /tools with 2 updates: github.com/go-task/task/v3 and golang.org/x/tools.

Updates github.com/go-task/task/v3 from 3.53.1 to 3.54.0

Release notes

Sourced from github.com/go-task/task/v3's releases.

v3.54.0

🚀 Features

  • Added versioned Homebrew casks (go-task@<major>.<minor>) to install a specific minor version of Task (#3023 by @​vmaerten).
  • Added a remote.headers config option to send HTTP headers when downloading a remote Taskfile, configured per host. Header values support templating functions, e.g. {{env "GITLAB_TOKEN"}}. This keeps the credential out of the include URL, where it would leak into error messages and the confirmation prompt (#2329 by @​vmaerten).

🐛 Fixes

  • Fixed remote Git Taskfile cache poisoning on shared hosts (GHSA-679p-658w-m3wr, reported by @​danielcadev, fixed by @​vmaerten).

  • Fixed tasks cancelled by the user returning exit code 201 instead of 205 (#3040, #3041 by @​r3wretrhy).

  • Fixed a bug on Windows where watching source paths did not work as expected (#2863, #3028 by @​pd93).

  • Fixed a remote Taskfile whose server refuses the credentials being reported as a missing Taskfile. A 401 now stops the search and reports the status code, instead of retrying every default Taskfile name and concluding that no Taskfile exists (#2329 by @​vmaerten).

  • task --completion <shell> now serves a new completion engine that unifies Bash, Fish, Zsh, Nushell and PowerShell behind a single task __complete command, so every shell offers the same suggestions: task names, aliases, flags, flag values and per-task CLI variables. The Zsh show-aliases and verbose zstyles keep working, now backed by the --no-aliases and --no-descriptions completion flags (#2897 by @​vmaerten).

📦 Package API

  • Bumped the minimum Go version to 1.26. Task follows Go's two-latest support window, and is now tested against 1.26 and 1.27. This only affects projects importing Task as a Go module (#2920 by @​vmaerten).

Other

  • Refactored some functional options to always return a concrete type instead of an interface and moved options into their own file (#3037 by @​pd93).
  • Refactored the execext package to use mvdan/sh's new BashOpts API (#3035 by @​pd93).
Changelog

Sourced from github.com/go-task/task/v3's changelog.

v3.54.0 - 2026-10-01

🚀 Features

  • Added versioned Homebrew casks (go-task@<major>.<minor>) to install a specific minor version of Task (#3023 by @​vmaerten).
  • Added a remote.headers config option to send HTTP headers when downloading a remote Taskfile, configured per host. Header values support templating functions, e.g. {{env "GITLAB_TOKEN"}}. This keeps the credential out of the include URL, where it would leak into error messages and the confirmation prompt (#2329 by @​vmaerten).

🐛 Fixes

  • Fixed remote Git Taskfile cache poisoning on shared hosts (GHSA-679p-658w-m3wr, reported by @​danielcadev, fixed by @​vmaerten).

  • Fixed tasks cancelled by the user returning exit code 201 instead of 205 (#3040, #3041 by @​r3wretrhy).

  • Fixed a bug on Windows where watching source paths did not work as expected (#2863, #3028 by @​pd93).

  • Fixed a remote Taskfile whose server refuses the credentials being reported as a missing Taskfile. A 401 now stops the search and reports the status code, instead of retrying every default Taskfile name and concluding that no Taskfile exists (#2329 by @​vmaerten).

  • task --completion <shell> now serves a new completion engine that unifies Bash, Fish, Zsh, Nushell and PowerShell behind a single task __complete command, so every shell offers the same suggestions: task names, aliases, flags, flag values and per-task CLI variables. The Zsh show-aliases and verbose zstyles keep working, now backed by the --no-aliases and --no-descriptions completion flags (#2897 by @​vmaerten).

📦 Package API

  • Bumped the minimum Go version to 1.26. Task follows Go's two-latest support window, and is now tested against 1.26 and 1.27. This only affects projects importing Task as a Go module (#2920 by @​vmaerten).

Other

  • Refactored some functional options to always return a concrete type instead of an interface and moved options into their own file (#3037 by @​pd93).
  • Refactored the execext package to use mvdan/sh's new BashOpts API (#3035 by @​pd93).
Commits

Updates golang.org/x/tools from 0.50.0 to 0.51.0

Commits
  • ea2f152 go.mod: update golang.org/x dependencies
  • 00443da go/analysis/passes/printf: pin testdata Go versions
  • 9ba0a15 internal/refactor/inline: check import accessibility before Go version
  • 25196fc cmd/toolstash: check -linkobj files to support early export
  • ead0503 gopls/internal/golang: unexport dragon*Question variables
  • 5693030 gopls/internal/golang: call arguments mistreated in inlineAllCalls
  • 134264d gopls/internal/golang/stubmethods: do not panic when FindByPos fails
  • 01d93d7 gopls/internal/golang: slay the dragon: update questions
  • 405de39 go/callgraph: fix benchmarks to analyze whole program
  • 231a7fa go/ssa, cmd/deadcode: release type information once functions are built
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the tools group in /tools with 2 updates: [github.com/go-task/task/v3](https://github.com/go-task/task) and [golang.org/x/tools](https://github.com/golang/tools).


Updates `github.com/go-task/task/v3` from 3.53.1 to 3.54.0
- [Release notes](https://github.com/go-task/task/releases)
- [Changelog](https://github.com/go-task/task/blob/main/CHANGELOG.md)
- [Commits](go-task/task@v3.53.1...v3.54.0)

Updates `golang.org/x/tools` from 0.50.0 to 0.51.0
- [Release notes](https://github.com/golang/tools/releases)
- [Commits](golang/tools@v0.50.0...v0.51.0)

---
updated-dependencies:
- dependency-name: github.com/go-task/task/v3
  dependency-version: 3.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: tools
- dependency-name: golang.org/x/tools
  dependency-version: 0.51.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: tools
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Author

Assignees

The following users could not be added as assignees: AlekSi. Either the username does not exist or it does not have the correct permissions to be added as an assignee.

Labels

The following labels could not be found: deps, not ready. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@xet7
xet7 merged commit fa05d11 into main-v1 Oct 7, 2026
2 checks passed
@dependabot
dependabot Bot deleted the dependabot/go_modules/tools/tools-517f3ffe34 branch October 7, 2026 08:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant