Skip to content

chore(deps): bump the go-patch-minor group with 7 updates - #354

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-patch-minor-11d5862323
Open

chore(deps): bump the go-patch-minor group with 7 updates#354
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-patch-minor-11d5862323

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 31, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-patch-minor group with 7 updates:

Package From To
github.com/anthropics/anthropic-sdk-go 1.67.0 1.68.0
github.com/aws/aws-sdk-go-v2 1.44.0 1.45.1
github.com/aws/aws-sdk-go-v2/config 1.32.40 1.33.1
github.com/aws/aws-sdk-go-v2/credentials 1.19.39 1.20.1
github.com/aws/aws-sdk-go-v2/service/s3 1.108.0 1.109.1
github.com/go-webauthn/webauthn 0.17.4 0.18.0
github.com/openai/openai-go/v3 3.52.0 3.54.0

Updates github.com/anthropics/anthropic-sdk-go from 1.67.0 to 1.68.0

Release notes

Sourced from github.com/anthropics/anthropic-sdk-go's releases.

v1.68.0

1.68.0 (2026-08-27)

Full Changelog: v1.67.0...v1.68.0

Features

  • api: beta files/skills namespaces use GA shapes; drop dated beta header pins (90ee202)

Bug Fixes

  • bedrock: leave non-JSON request bodies untouched (#337) (3a2e758)
  • client: report Windows correctly in X-Stainless-OS header (ceb299f)
  • client: retry attempts that hit the per-request timeout (49b9527)
  • sessions: deliver completed tool calls when the runner terminates (#322) (642d6a0)
  • sessions: read event fields via variant accessors in session helpers (#336) (fb7ec8a)
  • tools: let read return a view_range of a file over the size cap (#341) (33d4f9d)
  • webhooks: require headers to be passed to unwrap() (9a1023a)

Documentation

  • api: clarify pagination on the organization rate-limit list endpoints (0b6ba47)
Changelog

Sourced from github.com/anthropics/anthropic-sdk-go's changelog.

1.68.0 (2026-08-27)

Full Changelog: v1.67.0...v1.68.0

Features

  • api: beta files/skills namespaces use GA shapes; drop dated beta header pins (90ee202)

Bug Fixes

  • bedrock: leave non-JSON request bodies untouched (#337) (3a2e758)
  • client: report Windows correctly in X-Stainless-OS header (ceb299f)
  • client: retry attempts that hit the per-request timeout (49b9527)
  • sessions: deliver completed tool calls when the runner terminates (#322) (642d6a0)
  • sessions: read event fields via variant accessors in session helpers (#336) (fb7ec8a)
  • tools: let read return a view_range of a file over the size cap (#341) (33d4f9d)
  • webhooks: require headers to be passed to unwrap() (9a1023a)

Documentation

  • api: clarify pagination on the organization rate-limit list endpoints (0b6ba47)
Commits
  • d19dea9 release: 1.68.0
  • e3686fc docs(api): clarify pagination on the organization rate-limit list endpoints
  • 8b3cf62 fix(tools): let read return a view_range of a file over the size cap (#341)
  • e39ab89 test(tools): pin that read and edit preserve CRLF and CR line endings (#342)
  • f22c6d4 fix(bedrock): leave non-JSON request bodies untouched (#337)
  • 7990249 feat(api): beta files/skills namespaces use GA shapes; drop dated beta header...
  • 13333fd fix(client): retry attempts that hit the per-request timeout
  • 4cd20fb fix(client): report Windows correctly in X-Stainless-OS header
  • 6634a01 fix(sessions): read event fields via variant accessors in session helpers (#336)
  • 9dbb13f fix(sessions): deliver completed tool calls when the runner terminates (#322)
  • Additional commits viewable in compare view

Updates github.com/aws/aws-sdk-go-v2 from 1.44.0 to 1.45.1

Commits

Updates github.com/aws/aws-sdk-go-v2/config from 1.32.40 to 1.33.1

Commits

Updates github.com/aws/aws-sdk-go-v2/credentials from 1.19.39 to 1.20.1

Commits

Updates github.com/aws/aws-sdk-go-v2/service/s3 from 1.108.0 to 1.109.1

Commits

Updates github.com/go-webauthn/webauthn from 0.17.4 to 0.18.0

Release notes

Sourced from github.com/go-webauthn/webauthn's releases.

v0.18.0

0.18.0 (2026-08-27)

This release is a fairly major milestone in the development of this library. It has quite a few breaking changes but has added support for most if not all of the extension requirements natively, and adds formal support for Post-Quantum Cryptography with support for ML-DSA-44, ML-DSA-65, and ML-DSA-87 when used with go 1.27.

Details on the migration requirements for this version can be found int https://github.com/go-webauthn/webauthn/blob/HEAD/MIGRATION.md as they are substantial between ths version and prior versions.

Bug Fixes

  • metadata: align members with mds 3.1.1 and ctap 2.3 (#739) (397152c)
  • metadata: consistent revocation policy and client timeouts (#740) (34d324b)
  • metadata: handle certificate chains of any depth (#737) (309ea69)
  • metadata: honour status report order and effective dates (#736) (8be5355)
  • metadata: mds3 parsing conformance and cache integrity (#735) (8115143)
  • metadata: prevent panic corrupt blob (#698) (c5fd013)
  • metadata: report malformed status report urls (#738) (ed82f7c)
  • protocol: allow any attestation eku (#728) (f4e33fc)
  • protocol: androidkey missing authorization list member (#727) (9b02b19)
  • protocol: androidkey union generated (#729) (3ed3e75)
  • protocol: bind credential public key curve to its algorithm (#752) (314c2be)
  • protocol: compound attestation sub-statement unmarshalling (#751) (a582ecf)
  • protocol: compound returns incorrect type (#731) (025d897)
  • protocol: credential public key match limited to ECDSA (#732) (b4df26e)
  • protocol: harden credential response and options handling (#763) (de0ae6c)
  • protocol: missing tpm steps (#725) (f9a63f9)
  • protocol: opaque origin matching and validation (#758) (37f065a)
  • protocol: possible panic conditions (#719) (0ea14e7)
  • protocol: safetynet validation steps (#726) (e12f6e8)
  • protocol: single signature encoding policy and canonical der (#744) (99bbbdb)
  • webauthncbor: reject data trailing the first cbor item (#762) (0801b5d)
  • webauthncose: validate okp key algorithm (#759) (98c528b)
  • webauthn: deprecations and handle check (#745) (8619bb9)
  • webauthn: include backup flag check in registration (#748) (26a4868)
  • webauthn: only update uv flag (#746) (b39c822)
  • webauthn: use session relying party id (#747) (ebb45e2)

Features

  • metadata: update to r46 anchor (#780) (20f33e6)
  • ml-dsa preference list and gated availability (#768) (db1e068)
  • protocol: client capability enumeration (#765) (62f4489)
  • protocol: compound sub-statement scope (#742) (34271da)
  • protocol: current user details signal constructor (#766) (b6db923)
  • protocol: ecdsa attestation signature encoding policy (#743) (29404e9), closes #710
  • protocol: related origins well-known document (#753) (05d54dc)
  • protocol: relying party attestation policy (#741) (3239ed0)

... (truncated)

Changelog

Sourced from github.com/go-webauthn/webauthn's changelog.

0.18.0 (2026-08-27)

This release is a fairly major milestone in the development of this library. It has quite a few breaking changes but has added support for most if not all of the extension requirements natively, and adds formal support for Post-Quantum Cryptography with support for ML-DSA-44, ML-DSA-65, and ML-DSA-87 when used with go 1.27.

Details on the migration requirements for this version can be found int [MIGRATION.md] as they are substantial between ths version and prior versions.

Bug Fixes

  • metadata: align members with mds 3.1.1 and ctap 2.3 (#739) (397152c)
  • metadata: consistent revocation policy and client timeouts (#740) (34d324b)
  • metadata: handle certificate chains of any depth (#737) (309ea69)
  • metadata: honour status report order and effective dates (#736) (8be5355)
  • metadata: mds3 parsing conformance and cache integrity (#735) (8115143)
  • metadata: prevent panic corrupt blob (#698) (c5fd013)
  • metadata: report malformed status report urls (#738) (ed82f7c)
  • protocol: allow any attestation eku (#728) (f4e33fc)
  • protocol: androidkey missing authorization list member (#727) (9b02b19)
  • protocol: androidkey union generated (#729) (3ed3e75)
  • protocol: bind credential public key curve to its algorithm (#752) (314c2be)
  • protocol: compound attestation sub-statement unmarshalling (#751) (a582ecf)
  • protocol: compound returns incorrect type (#731) (025d897)
  • protocol: credential public key match limited to ECDSA (#732) (b4df26e)
  • protocol: harden credential response and options handling (#763) (de0ae6c)
  • protocol: missing tpm steps (#725) (f9a63f9)
  • protocol: opaque origin matching and validation (#758) (37f065a)
  • protocol: possible panic conditions (#719) (0ea14e7)
  • protocol: safetynet validation steps (#726) (e12f6e8)
  • protocol: single signature encoding policy and canonical der (#744) (99bbbdb)
  • webauthncbor: reject data trailing the first cbor item (#762) (0801b5d)
  • webauthncose: validate okp key algorithm (#759) (98c528b)
  • webauthn: deprecations and handle check (#745) (8619bb9)
  • webauthn: include backup flag check in registration (#748) (26a4868)
  • webauthn: only update uv flag (#746) (b39c822)
  • webauthn: use session relying party id (#747) (ebb45e2)

Features

  • metadata: update to r46 anchor (#780) (20f33e6)
  • ml-dsa preference list and gated availability (#768) (db1e068)
  • protocol: client capability enumeration (#765) (62f4489)
  • protocol: compound sub-statement scope (#742) (34271da)
  • protocol: current user details signal constructor (#766) (b6db923)
  • protocol: ecdsa attestation signature encoding policy (#743) (29404e9), closes #710
  • protocol: related origins well-known document (#753) (05d54dc)
  • protocol: relying party attestation policy (#741) (3239ed0)
  • typed extension inputs and outputs (#734) (0661c81)

... (truncated)

Commits

Updates github.com/openai/openai-go/v3 from 3.52.0 to 3.54.0

Release notes

Sourced from github.com/openai/openai-go/v3's releases.

v3.54.0

3.54.0 (2026-08-27)

Features

  • api: make function call output call IDs optional (#864) (7095c46)

Bug Fixes

  • auth: harden X.509 workload identity contract (#863) (adefcb3)

v3.53.0

3.53.0 (2026-08-25)

Features

  • api: Add obfuscation field to ChatCompletionChunk (#813) (4b08348)
  • api: add project residency and usage quantity units (#853) (2fd626c)
  • api: add Realtime call creation and recursive filters (#860) (c396b57)
  • auth: add caller-attested X.509 transport capability (#855) (64b2ef2)
  • auth: complete X.509 token lifecycle and setup guidance (#858) (3e3a4e0)
  • auth: implement pinned X.509 token exchange (#856) (a84eb49)
  • option: add attested X.509 workload identity authentication (#857) (b509c12)
  • support named data-residency endpoints (#805) (6e72880)

Bug Fixes

  • apijson: preserve unknown union array variants (#768) (0ab7ee6)
  • apijson: reject non-object root payloads (#769) (2959fbd)
  • azure: isolate provider authentication defaults (#835) (4e5a07a)
  • azure: require secure credential transport (#821) (1dcf764)
  • azure: validate deployment routing bodies (#826) (54189a0)
  • bound retry and polling delays (#828) (6d39b8b)
  • don't drop tool_calls when content is empty but present (#757) (4a73240), closes #756
  • enforce configured request origins (#823) (a71b2d1)
  • harden multipart file metadata encoding (#825) (a4632e5)
  • harden workload identity transport and request lifecycles (#861) (4ce8802)
  • harden X.509 refresh races and empty-body replay (#859) (f95adf1)
  • ignore empty tool call deltas in accumulator (#688) (c2c8590)
  • make chat stream accumulation linear (#819) (0b7382a)
  • make debug logging metadata-only (#815) (2e0743f)
  • normalize registered stream decoder content types (#790) (a689437)
  • preserve request options across pagination (#820) (ee97c12)
  • responses: decode shell output delta stream events (#803) (bb12b7a)
  • sdk: lock and verify the Steady mock server (#811) (37c0f0a)
  • ssestream: finalize stream resources promptly (#839) (71a7aef)

... (truncated)

Changelog

Sourced from github.com/openai/openai-go/v3's changelog.

3.54.0 (2026-08-27)

Features

  • api: make function call output call IDs optional (#864) (7095c46)

Bug Fixes

  • auth: harden X.509 workload identity contract (#863) (adefcb3)

3.53.0 (2026-08-25)

Features

  • api: Add obfuscation field to ChatCompletionChunk (#813) (4b08348)
  • api: add project residency and usage quantity units (#853) (2fd626c)
  • api: add Realtime call creation and recursive filters (#860) (c396b57)
  • auth: add caller-attested X.509 transport capability (#855) (64b2ef2)
  • auth: complete X.509 token lifecycle and setup guidance (#858) (3e3a4e0)
  • auth: implement pinned X.509 token exchange (#856) (a84eb49)
  • option: add attested X.509 workload identity authentication (#857) (b509c12)
  • support named data-residency endpoints (#805) (6e72880)

Bug Fixes

  • apijson: preserve unknown union array variants (#768) (0ab7ee6)
  • apijson: reject non-object root payloads (#769) (2959fbd)
  • azure: isolate provider authentication defaults (#835) (4e5a07a)
  • azure: require secure credential transport (#821) (1dcf764)
  • azure: validate deployment routing bodies (#826) (54189a0)
  • bound retry and polling delays (#828) (6d39b8b)
  • don't drop tool_calls when content is empty but present (#757) (4a73240), closes #756
  • enforce configured request origins (#823) (a71b2d1)
  • harden multipart file metadata encoding (#825) (a4632e5)
  • harden workload identity transport and request lifecycles (#861) (4ce8802)
  • harden X.509 refresh races and empty-body replay (#859) (f95adf1)
  • ignore empty tool call deltas in accumulator (#688) (c2c8590)
  • make chat stream accumulation linear (#819) (0b7382a)
  • make debug logging metadata-only (#815) (2e0743f)
  • normalize registered stream decoder content types (#790) (a689437)
  • preserve request options across pagination (#820) (ee97c12)
  • responses: decode shell output delta stream events (#803) (bb12b7a)
  • sdk: lock and verify the Steady mock server (#811) (37c0f0a)
  • ssestream: finalize stream resources promptly (#839) (71a7aef)
  • track stream accumulator events for every choice (#806) (8fa5f45)
  • validate stream accumulator indices (#822) (02959ba)

... (truncated)

Commits
  • 34c838d release: 3.54.0 (#865)
  • 7095c46 feat(api): make function call output call IDs optional (#864)
  • adefcb3 fix(auth): harden X.509 workload identity contract (#863)
  • aae189f release: 3.53.0 (#798)
  • 4ce8802 fix: harden workload identity transport and request lifecycles (#861)
  • c396b57 feat(api): add Realtime call creation and recursive filters (#860)
  • f95adf1 fix: harden X.509 refresh races and empty-body replay (#859)
  • 3e3a4e0 feat(auth): complete X.509 token lifecycle and setup guidance (#858)
  • b509c12 feat(option): add attested X.509 workload identity authentication (#857)
  • 2fd626c feat(api): add project residency and usage quantity units (#853)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-patch-minor group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [github.com/anthropics/anthropic-sdk-go](https://github.com/anthropics/anthropic-sdk-go) | `1.67.0` | `1.68.0` |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.44.0` | `1.45.1` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.32.40` | `1.33.1` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2) | `1.19.39` | `1.20.1` |
| [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2) | `1.108.0` | `1.109.1` |
| [github.com/go-webauthn/webauthn](https://github.com/go-webauthn/webauthn) | `0.17.4` | `0.18.0` |
| [github.com/openai/openai-go/v3](https://github.com/openai/openai-go) | `3.52.0` | `3.54.0` |


Updates `github.com/anthropics/anthropic-sdk-go` from 1.67.0 to 1.68.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-go/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-go/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-go@v1.67.0...v1.68.0)

Updates `github.com/aws/aws-sdk-go-v2` from 1.44.0 to 1.45.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@v1.44.0...v1.45.1)

Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.40 to 1.33.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@config/v1.32.40...config/v1.33.1)

Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.19.39 to 1.20.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@credentials/v1.19.39...v1.20.1)

Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.108.0 to 1.109.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.108.0...service/s3/v1.109.1)

Updates `github.com/go-webauthn/webauthn` from 0.17.4 to 0.18.0
- [Release notes](https://github.com/go-webauthn/webauthn/releases)
- [Changelog](https://github.com/go-webauthn/webauthn/blob/master/CHANGELOG.md)
- [Commits](go-webauthn/webauthn@v0.17.4...v0.18.0)

Updates `github.com/openai/openai-go/v3` from 3.52.0 to 3.54.0
- [Release notes](https://github.com/openai/openai-go/releases)
- [Changelog](https://github.com/openai/openai-go/blob/main/CHANGELOG.md)
- [Commits](openai/openai-go@v3.52.0...v3.54.0)

---
updated-dependencies:
- dependency-name: github.com/anthropics/anthropic-sdk-go
  dependency-version: 1.68.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-patch-minor
- dependency-name: github.com/aws/aws-sdk-go-v2
  dependency-version: 1.45.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-patch-minor
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.33.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-patch-minor
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
  dependency-version: 1.20.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-patch-minor
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
  dependency-version: 1.109.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-patch-minor
- dependency-name: github.com/go-webauthn/webauthn
  dependency-version: 0.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-patch-minor
- dependency-name: github.com/openai/openai-go/v3
  dependency-version: 3.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-patch-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Aug 31, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: go. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 31, 2026
@dependabot
dependabot Bot requested a review from lin-snow as a code owner August 31, 2026 03:13
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 31, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants