Skip to content

build(deps): bump github.com/anchore/grype from 0.116.0 to 0.116.1 in the gomod-patch group - #366

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/gomod-patch-85a42adbbe
Open

build(deps): bump github.com/anchore/grype from 0.116.0 to 0.116.1 in the gomod-patch group#366
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/gomod-patch-85a42adbbe

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the gomod-patch group with 1 update: github.com/anchore/grype.

Updates github.com/anchore/grype from 0.116.0 to 0.116.1

Release notes

Sourced from github.com/anchore/grype's releases.

v0.116.1

Bug Fixes

Dependencies

30 dependency changes (30 updated). 1 vulnerability remediated.

🟢 Remediated (1)

  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.31.0v1.32.0
  • github.com/anchore/stereoscope v0.2.2v0.3.0
  • github.com/anchore/syft v1.48.0v1.50.0
  • github.com/cncf/xds/go v0.0.0-ee656c7v0.0.0-dba9d58
  • github.com/containerd/containerd/v2 v2.3.2v2.3.3
  • github.com/docker/cli v29.5.3+incompatiblev29.6.1+incompatible
  • github.com/envoyproxy/go-control-plane/envoy v1.36.0v1.37.0
  • github.com/envoyproxy/protoc-gen-validate v1.3.0v1.3.3
  • github.com/gkampitakis/go-snaps v0.5.22v0.5.23
  • github.com/gpustack/gguf-parser-go v0.24.1v0.25.0
  • github.com/moby/moby/api v1.54.2v1.55.0
  • github.com/moby/moby/client v0.4.1v0.5.0
  • github.com/pelletier/go-toml/v2 v2.3.1v2.4.3
  • go.opentelemetry.io/contrib/detectors/gcp v1.39.0v1.43.0
  • golang.org/x/crypto v0.53.0v0.54.0
  • golang.org/x/mod v0.37.0v0.38.0
  • golang.org/x/net v0.56.0v0.57.0
  • golang.org/x/sync v0.21.0v0.22.0
  • golang.org/x/sys v0.46.0v0.47.0
  • golang.org/x/term v0.44.0v0.45.0
  • golang.org/x/text v0.39.0v0.40.0
  • golang.org/x/tools v0.47.0v0.48.0
  • google.golang.org/genproto/googleapis/api v0.0.0-9d38bb4v0.0.0-afd174a
  • google.golang.org/genproto/googleapis/rpc v0.0.0-6f92a3bv0.0.0-afd174a
  • google.golang.org/grpc v1.80.0v1.82.1 (🟢 remediated GHSA-hrxh-6v49-42gf)
  • modernc.org/cc/v4 v4.28.4v4.29.0
  • modernc.org/ccgo/v4 v4.34.4v4.34.6
  • modernc.org/gc/v3 v3.1.3v3.1.4

... (truncated)

Commits
  • 30394f1 chore(deps): update anchore dependencies (#3590)
  • 545d914 chore(deps): bump google.golang.org/grpc from 1.80.0 to 1.82.1 (#3600)
  • d875145 ensure channel parsing is consistent (#3603)
  • ba11c44 Scope Go GHSA twins by shared CVE (#3592)
  • 072fe59 chore(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 (#3598)
  • 8c4b39f chore(deps): bump github/codeql-action/upload-sarif (#3599)
  • e280ea7 chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#3597)
  • 4562c55 fix(version): do not cache a comparator that failed to build (#3567)
  • ccf53d6 fix(distro): prevent panic on empty version after trimming "v" prefix (#3589)
  • 44ad33f chore(deps): update anchore dependencies (#3577)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the gomod-patch group with 1 update: [github.com/anchore/grype](https://github.com/anchore/grype).


Updates `github.com/anchore/grype` from 0.116.0 to 0.116.1
- [Release notes](https://github.com/anchore/grype/releases)
- [Changelog](https://github.com/anchore/grype/blob/main/RELEASE.md)
- [Commits](anchore/grype@v0.116.0...v0.116.1)

---
updated-dependencies:
- dependency-name: github.com/anchore/grype
  dependency-version: 0.116.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 3, 2026
@dependabot
dependabot Bot requested a review from bomly-guy as a code owner August 3, 2026 18:56
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 3, 2026
@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bomly Diff Summary

Compared 9b8d9c36a33edccb5c081ad4948d12069971b525 to a6245a375c601884c91a9f9da52509c10397b72a.

Overview

Status Manifests Dependencies Findings Duration
✅ Pass +0 / ~1 / -0 0 added / 5 version changed / 0 detail changes / 0 removed 0 introduced / 0 persisted / 0 resolved 1m 19s

Dependency Changes

Summary: 0 added, 5 version changed, 0 detail changes, 0 removed.

Changed Dependencies

Change Package Version Direct? Scope Licenses
changed github.com/anchore/grype v0.116.0 → v0.116.1 Yes runtime Apache-2.0
changed github.com/anchore/syft v1.49.0 → v1.50.0 Yes runtime Apache-2.0
changed github.com/gpustack/gguf-parser-go v0.24.1 → v0.25.0 No runtime MIT
changed modernc.org/libc v1.73.4 → v1.74.1 No runtime BSD-3-Clause
changed modernc.org/sqlite v1.53.0 → v1.54.0 No runtime BSD-3-Clause

Vulnerabilities

✅ No vulnerability changes.

License Changes

✅ No license changes.

Project Posture

✅ No project posture changes (--matchers +scorecard was not selected).

Policy Findings

✅ No policy differences were identified.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants