Skip to content

chore(deps): bump golang.org/x/crypto from 0.48.0 to 0.51.0#3689

Merged
mdelapenya merged 5 commits into
testcontainers:mainfrom
mdelapenya:dependabot/go_modules/golang.org/x/crypto-0.50.0
May 11, 2026
Merged

chore(deps): bump golang.org/x/crypto from 0.48.0 to 0.51.0#3689
mdelapenya merged 5 commits into
testcontainers:mainfrom
mdelapenya:dependabot/go_modules/golang.org/x/crypto-0.50.0

Conversation

@mdelapenya
Copy link
Copy Markdown
Member

@mdelapenya mdelapenya commented May 11, 2026

Bumps golang.org/x/crypto from 0.48.0 to 0.51.0.

Commits
  • b8a14a8 go.mod: update golang.org/x dependencies
  • 9d9d507 x509roots/fallback/bundle: fix bundle test with Go 1.27+
  • fd0b90d acme: include Problem in OrderError.Error
  • b9e5359 pbkdf2: turn into a wrapper for crypto/pbkdf2
  • cc0e4fc hkdf: forward Extract to the standard library
  • a8e9237 x509roots/fallback: update bundle
  • 03ca0dc go.mod: update golang.org/x dependencies
  • 8400f4a ssh: respect signer's algorithm preference in pickSignatureAlgorithm
  • 81c6cb3 ssh: swap cbcMinPaddingSize to cbcMinPacketSize to get encLength
  • 982eaa6 go.mod: update golang.org/x dependencies
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

dependabot Bot and others added 4 commits May 1, 2026 13:16
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.48.0 to 0.50.0.
- [Commits](golang/crypto@v0.48.0...v0.50.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.50.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…50.0

* main:
  feat(modules/dex): add Dex OIDC provider module (testcontainers#3659)
  chore(deps): bump github.com/in-toto/in-toto-golang in /modules/compose (testcontainers#3674)
  chore(deps): bump docker/setup-docker-action from 4.5.0 to 5.1.0 (testcontainers#3664)
  chore(deps): bump mkdocs-include-markdown-plugin from 7.2.1 to 7.2.2 (testcontainers#3665)
  chore(deps): bump github.com/apache/thrift in /modules/nebulagraph (testcontainers#3673)
  fix: close temp file handle before removal  (testcontainers#3672)
  chore: update usage metrics (2026-05) (testcontainers#3670)
@mdelapenya mdelapenya requested a review from a team as a code owner May 11, 2026 05:58
@netlify
Copy link
Copy Markdown

netlify Bot commented May 11, 2026

Deploy Preview for testcontainers-go ready!

Name Link
🔨 Latest commit 7698a54
🔍 Latest deploy log https://app.netlify.com/projects/testcontainers-go/deploys/6a0190a9914d8700088f61cc
😎 Deploy Preview https://deploy-preview-3689--testcontainers-go.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@coderabbitai
Copy link
Copy Markdown

coderabbitai Bot commented May 11, 2026

Review Change Stack
No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: b73660be-16aa-4675-a0e8-07b2fb79263c

📥 Commits

Reviewing files that changed from the base of the PR and between b390a14 and 7698a54.

⛔ Files ignored due to path filters (1)
  • modules/gcloud/go.sum is excluded by !**/*.sum
📒 Files selected for processing (1)
  • modules/gcloud/go.mod
🚧 Files skipped from review as they are similar to previous changes (1)
  • modules/gcloud/go.mod

Summary by CodeRabbit

  • Chores
    • Updated Go dependency versions across the project and submodules to newer upstream releases for various golang.org/x packages. No public APIs, user-facing behavior, or functionality were changed.

Walkthrough

All 64 go.mod files are updated to bump golang.org/x/crypto from v0.48.0 to v0.51.0 and golang.org/x/sys from v0.42.0 to v0.44.0. Several modules additionally update golang.org/x/net, golang.org/x/text, golang.org/x/sync, golang.org/x/term, golang.org/x/mod, and golang.org/x/tools to newer versions.

Changes

Golang.org/x Dependency Updates

Golang.org/x Dependency Updates

Layer / File(s) Summary
Root and Examples Dependencies
go.mod, examples/nginx/go.mod
Root and examples module go.mod files are updated with golang.org/x/crypto and golang.org/x/sys version bumps.
Modules with Crypto and Sys Updates
modules/{aerospike,artemis,azurite,cassandra,clickhouse,dolt,dind,dockermcpgateway,dockermodelrunner,databend,elasticsearch,forgejo,k6,localstack,mariadb,meilisearch,memcached,neo4j,ollama,openldap,opensearch,openfga,rabbitmq,redpanda,registry,scylladb,socat,solace,surrealdb,tidb,toxiproxy,valkey,vault,vearch,yugabytedb}/go.mod
Many modules updated with identical golang.org/x/crypto (v0.48.0→v0.51.0) and golang.org/x/sys (v0.42.0→v0.44.0) version bumps.
Modules with Extended golang.org/x Updates
modules/{arangodb,azure,chroma,cockroachdb,compose,couchbase,etcd,gcloud,grafana-lgtm,influxdb,k3s,milvus,minio,mockserver,mongodb,mssql,mysql,nats,nebulagraph,pinecone,postgres,pulsar,qdrant,weaviate}/go.mod
Selected modules also bump additional golang.org/x/* packages such as net, text, sync, term, mod, and tools.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

Poem

🐰 The deps march onward, version by version,
Crypto and system calls find their way,
Through every module, no code conversion,
Just newer pins to brighten the day!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely identifies the main change: bumping golang.org/x/crypto from 0.48.0 to 0.51.0, which is the primary focus of this changeset across all go.mod files.
Description check ✅ Passed The description is directly related to the changeset, detailing the version bump of golang.org/x/crypto and providing upstream commit information, though it is focused on one dependency while the changeset also updates golang.org/x/sys and other golang.org/x packages.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@mdelapenya mdelapenya self-assigned this May 11, 2026
@mdelapenya mdelapenya added the dependencies Dependencies or external services label May 11, 2026
…50.0

* main:
  chore(deps): bump google.golang.org/grpc in /modules/gcloud (testcontainers#3690)
  chore(deps): bump google.golang.org/grpc in /modules/dex (testcontainers#3686)
@mdelapenya mdelapenya merged commit de5466d into testcontainers:main May 11, 2026
225 checks passed
@mdelapenya mdelapenya deleted the dependabot/go_modules/golang.org/x/crypto-0.50.0 branch May 11, 2026 09:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependencies or external services

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant