Skip to content

chore(deps): bump github.com/go-git/go-git/v5 from 5.17.2 to 5.18.0 - #63

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/go-git/go-git/v5-5.18.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/go-git/go-git/v5-5.18.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps github.com/go-git/go-git/v5 from 5.17.2 to 5.18.0.

Release notes

Sourced from github.com/go-git/go-git/v5's releases.

v5.18.0

What's Changed

Full Changelog: go-git/go-git@v5.17.2...v5.18.0

Commits
  • ea3e7ec Merge pull request #2004 from go-git/v5-http-hardening
  • bcd20a9 plumbing: transport/http, Add support for followRedirects policy
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.17.2 to 5.18.0.
- [Release notes](https://github.com/go-git/go-git/releases)
- [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md)
- [Commits](go-git/go-git@v5.17.2...v5.18.0)

---
updated-dependencies:
- dependency-name: github.com/go-git/go-git/v5
  dependency-version: 5.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Apr 28, 2026
@dependabot
dependabot Bot requested a review from phpboyscout as a code owner April 28, 2026 08:41
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Apr 28, 2026
@dependabot @github

dependabot Bot commented on behalf of github May 11, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #68.

@dependabot dependabot Bot closed this May 11, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/github.com/go-git/go-git/v5-5.18.0 branch May 11, 2026 08:22
phpboyscout added a commit that referenced this pull request Sep 15, 2026
"telemetry.enabled" was spelled as a literal eleven times across five
files in four packages; the update.* trust keys three times each; the
ai.* keys had constants in pkg/chat that six call sites in the
generator and the adapter did not use. A key is part of a tool's config
contract, and a copy is a place for the spelling to drift.

pkg/setup/config_keys.go now holds the update and telemetry keys (the
packages that read them already import setup), pkg/chat/constants.go
gains the missing ai keys, and every consumer reads the constant. A
test in internal/repopolicy scans pkg/ and cli/pkg/ for a literal of
those three families outside its constants file; it was red at 41
sites. The server.* family moves with the http/grpc adapter merge.

Closes #63
phpboyscout added a commit that referenced this pull request Sep 15, 2026
"telemetry.enabled" was spelled as a literal eleven times across five
files in four packages; the update.* trust keys three times each; the
ai.* keys had constants in pkg/chat that call sites in the generator
and the adapter did not use. A key is part of a tool's config
contract, and a copy is a place for the spelling to drift.

pkg/setup/config_keys.go now holds the update and telemetry keys (the
packages that read them already import setup), pkg/chat/constants.go
gains the missing ai keys, and every framework consumer reads the
constant. A test in internal/repopolicy scans pkg/ for a literal of
those three families outside its constants file; it was red at 35
sites.

Two CLI sites keep "ai.model" and "ai.claude.local" as literals for
now: cli/go.mod builds against the released framework, so the CLI can
adopt a constant only one release after pkg/ declares it (the
cli-release-build job is what caught it). The guard widens to cli/pkg
and those two sites move once the framework that carries the constants
is released. The server.* family moves with the http/grpc adapter merge.

Refs #63
phpboyscout added a commit that referenced this pull request Sep 15, 2026
"telemetry.enabled" was spelled as a literal eleven times across five
files in four packages; the update.* trust keys three times each; the
ai.* keys had constants in pkg/chat that call sites in the generator
and the adapter did not use. A key is part of a tool's config
contract, and a copy is a place for the spelling to drift.

pkg/setup/config_keys.go now holds the update and telemetry keys (the
packages that read them already import setup), pkg/chat/constants.go
gains the missing ai keys, and every framework consumer reads the
constant. A test in internal/repopolicy scans pkg/ for a literal of
those three families outside its constants file; it was red at 35
sites.

Two CLI sites keep "ai.model" and "ai.claude.local" as literals for
now: cli/go.mod builds against the released framework, so the CLI can
adopt a constant only one release after pkg/ declares it (the
cli-release-build job is what caught it). The guard widens to cli/pkg
and those two sites move once the framework that carries the constants
is released. The server.* family moves with the http/grpc adapter merge.

Refs #63
phpboyscout added a commit that referenced this pull request Sep 17, 2026
… keys once

The first half (5cbbc1a) moved the update, telemetry and ai families to
constants and guarded pkg/ for them. This closes the rest: the forge and
chat credential subtrees, log.*, vcs.provider, and the CLI, which the
workspace now lets adopt a framework constant in the same change.

credentialposture gains SingleToken(prefix) and DualCredential(prefix),
the one statement of the <prefix>.auth.* and Bitbucket key layouts. The
forge profiles read their keys and keychain account from them (the
KeychainAccount field goes, it was the prefix plus ".auth" five times),
and so does the posture declaration in check.go. chat gains
ProviderCredentialKeys, the enumeration of its credential roots.

config migrate's credential table is one table again: each row carries
the keys, keychain account, fallback env var and blob field, with the
chat rows derived from chat and the forge rows from the layout helpers;
jsonBlobFieldFor and defaultEnvVarName look the row up instead of
repeating the keys in a switch. The root's protected project keys read
the same sources. log.level and log.format join setup's keys file,
vcs.provider is vcs.ConfigKeyProvider, and the generator reads the chat
constants for the provider key, ai.model and ai.claude.local.

The repopolicy guard now covers every family above in pkg/ and cli/pkg/,
skipping constant declarations and struct tags. It was red at 71 sites.

Closes #63
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants