Skip to content

chore(deps): bump 3 dependencies#27

Open
alaudabot wants to merge 1 commit into
release-0.14from
dependabot/security-updates-c91ca37
Open

chore(deps): bump 3 dependencies#27
alaudabot wants to merge 1 commit into
release-0.14from
dependabot/security-updates-c91ca37

Conversation

@alaudabot

@alaudabot alaudabot commented Apr 13, 2026

Copy link
Copy Markdown

🔒 Security Updates

This pull request updates dependencies to fix security vulnerabilities identified by Trivy scanning.

Dependencies

  • []github.com/moby/spdystream(/tmp/dependabot-clone-3889552842/pkg): → v0.5.1
  • []go.opentelemetry.io/otel/sdk(/tmp/dependabot-clone-3889552842/pkg): → v1.43.0
  • []go.opentelemetry.io/otel(/tmp/dependabot-clone-3889552842/pkg): → v1.41.0

📊 Update Summary

  • Total packages updated: 3

🤖 Automated by DependaBot

This PR was automatically created by DependaBot based on Trivy security scan results.
Please review the changes and merge if everything looks good.

@alaudabot alaudabot added the dependencies Pull requests that update a dependency file label Apr 13, 2026
@danielfbm

Copy link
Copy Markdown

PR Assist Bot — Owner Approval Needed

This PR targets release branch release-0.14. Per policy, release-branch merges require explicit owner approval before the bot proceeds.

PR: AlaudaDevops/pkg#27
Branch: release-0.14
Type: Security / Dependency update (Renovate)

Please reply with /approve-merge or provide explicit approval for the bot to merge this PR on the next sweep.

@alaudabot alaudabot force-pushed the dependabot/security-updates-c91ca37 branch from e451932 to 611fe63 Compare April 20, 2026 09:24
@alaudabot

Copy link
Copy Markdown
Author

/retest

2 similar comments
@alaudabot

Copy link
Copy Markdown
Author

/retest

@alaudabot

Copy link
Copy Markdown
Author

/retest

@alaudabot

Copy link
Copy Markdown
Author

[pr-assist-bot] Repeated CI Failure Analysis — retest limit reached (3+ retests)

Failed check: `Pipelines as Code CI / alaudadevops-pkg` (18m run)

This security dependency update (go.opentelemetry.io/otel/sdk → v1.43.0) has failed the `alaudadevops-pkg` pipeline 3+ times. This pattern suggests either a genuine compatibility issue with the updated package or a persistent CI environment problem.

Recommended action: A maintainer should check the `alaudadevops-pkg` pipeline logs for compilation or test errors that could indicate a breaking API change in the otel/sdk update.

PR: AlaudaDevops/pkg#27

@alaudabot

Copy link
Copy Markdown
Author

PR Assist Bot Analysis

Failure Type: Unknown (logs unavailable)
Failed Checks: Pipelines as Code CI / alaudadevops-pkg (18m duration)
Retest attempts: 3 — stopping (same check failing, no progress)
Root Cause: PipelineRun alaudadevops-pkg-vwm77 GC'd from cluster and not indexed in Tekton Results — unable to retrieve step-level logs for root cause analysis.
Recommendation: Manual investigation needed. Check the alaudadevops-pkg pipeline logs directly in the Alauda console. The otel/sdk v1.43.0 bump itself is a standard dependency update; the CI environment may have an issue.

@alaudabot alaudabot changed the title chore(deps): bump go.opentelemetry.io/otel/sdk from to v1.43.0 chore(deps): bump 2 dependencies Apr 27, 2026
@alaudabot alaudabot force-pushed the dependabot/security-updates-c91ca37 branch 2 times, most recently from a09f867 to 280d22a Compare May 4, 2026 09:29
@alaudabot alaudabot changed the title chore(deps): bump 2 dependencies chore(deps): bump 3 dependencies May 11, 2026
@alaudabot alaudabot force-pushed the dependabot/security-updates-c91ca37 branch from 280d22a to fc5d30d Compare May 11, 2026 10:47
@alaudabot alaudabot force-pushed the dependabot/security-updates-c91ca37 branch from fc5d30d to 9d00e4c Compare May 18, 2026 11:11
@alaudabot alaudabot force-pushed the dependabot/security-updates-c91ca37 branch from 9d00e4c to 7c55a7c Compare May 25, 2026 11:16
@alaudabot alaudabot force-pushed the dependabot/security-updates-c91ca37 branch 2 times, most recently from 2fcd967 to 5129a8d Compare June 8, 2026 12:02
Security updates for multiple packages
@alaudabot alaudabot force-pushed the dependabot/security-updates-c91ca37 branch from 5129a8d to 2a24fd6 Compare June 15, 2026 13:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants