Skip to content

build(deps): bump github.com/go-openapi/spec from 0.22.3 to 0.22.9 - #3209

Merged
kubesphere-prow[bot] merged 1 commit into
mainfrom
dependabot-go_modules-github.com-go-openapi-spec-0.22.9
Aug 24, 2026
Merged

build(deps): bump github.com/go-openapi/spec from 0.22.3 to 0.22.9#3209
kubesphere-prow[bot] merged 1 commit into
mainfrom
dependabot-go_modules-github.com-go-openapi-spec-0.22.9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 21, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/go-openapi/spec from 0.22.3 to 0.22.9.

Release notes

Sourced from github.com/go-openapi/spec's releases.

v0.22.9

0.22.9 - 2026-07-20

Full Changelog: go-openapi/spec@v0.22.8...v0.22.9

1 commits in this release.


Implemented enhancements

  • feat(expander): add ExpandParameterWithOptions and ExpandResponseWithOptions by @​fredbi in #292 ...

People who contributed to this release


spec license terms

License

v0.22.8

0.22.8 - 2026-07-20

Full Changelog: go-openapi/spec@v0.22.7...v0.22.8

1 commits in this release.


Implemented enhancements

  • feat(expander): add ExpandSchemaWithOptions for confined schema expansion by @​fredbi in #291 ...

People who contributed to this release

... (truncated)

Commits
  • e682f66 feat(expander): add ExpandParameterWithOptions and ExpandResponseWithOptions ...
  • 9bfe732 feat(expander): add ExpandSchemaWithOptions for confined schema expansion (#291)
  • 5173965 Merge pull request #290 from fredbi/fix/vuln-reports
  • 497d583 build(deps): bump swag modules to v0.27.3
  • fe9f8bd test(expander): validate the SSRF posture of an injected loader
  • 75e4859 build(deps): bump swag/loading to v0.27.2 for confined $ref loading
  • 7229152 docs(security): warn that the default $ref loader is not sandboxed
  • 4e073e1 fix(ref): stop performing a network request in IsValidURI
  • 64655f3 feat(expander): accept an option-aware document loader
  • 5ae1e0d chore: upgrade dependencies ; fix deprecated jsonname
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/go-openapi/spec](https://github.com/go-openapi/spec) from 0.22.3 to 0.22.9.
- [Release notes](https://github.com/go-openapi/spec/releases)
- [Commits](go-openapi/spec@v0.22.3...v0.22.9)

---
updated-dependencies:
- dependency-name: github.com/go-openapi/spec
  dependency-version: 0.22.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Aug 21, 2026
@kubesphere-prow

Copy link
Copy Markdown

Adding the "do-not-merge/release-note-label-needed" label because no release-note block was detected, please follow our release note process to remove it.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@kubesphere-prow kubesphere-prow Bot added do-not-merge/release-note-label-needed size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Aug 21, 2026
@sonarqubecloud

Copy link
Copy Markdown

@redscholar redscholar added lgtm Indicates that a PR is ready to be merged. approved Indicates a PR has been approved by an approver from all required OWNERS files. labels Aug 24, 2026
@kubesphere-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

Approval requirements bypassed by manually added approval.

This pull-request has been approved by: dependabot[bot]

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubesphere-prow
kubesphere-prow Bot merged commit 9b709a3 into main Aug 24, 2026
7 checks passed
@dependabot
dependabot Bot deleted the dependabot-go_modules-github.com-go-openapi-spec-0.22.9 branch August 24, 2026 02:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. dependencies Pull requests that update a dependency file do-not-merge/release-note-label-needed go Pull requests that update Go code lgtm Indicates that a PR is ready to be merged. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant