Skip to content

build(go): bump github.com/anchore/quill from 0.5.1 to 0.7.1#99

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/go_modules/github.com/anchore/quill-0.7.1
Open

build(go): bump github.com/anchore/quill from 0.5.1 to 0.7.1#99
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/go_modules/github.com/anchore/quill-0.7.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Mar 11, 2026

Bumps github.com/anchore/quill from 0.5.1 to 0.7.1.

Release notes

Sourced from github.com/anchore/quill's releases.

v0.7.1

Security Fixes

(Full Changelog)

v0.7.0

Added Features

Bug Fixes

Additional Changes

(Full Changelog)

Commits
  • 9cdb082 do not allow for unbounded reads for user controlled input (#681)
  • 80cf3fe account for excessive read limits in macho parsing code (#682)
  • e41d66a validate developer log URL requests (#680)
  • 899202c update cred var values for p12 in release (#679)
  • c73a37b remove goreleaser config for release step + update tool refs (#678)
  • 95e119c persist credentials for git (#677)
  • 02e765a chore(deps): bump github.com/aws/aws-sdk-go-v2/config (#663)
  • 530bb7f add test notarize command (#618)
  • 3e8269c Set team ID during signing (#675)
  • 12b3e8e chore(deps): bump github.com/blacktop/go-macho from 1.1.259 to 1.1.263 (#661)
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Mar 11, 2026
@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/anchore/quill-0.7.1 branch from 600e84a to 1037948 Compare March 11, 2026 11:39
@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/anchore/quill-0.7.1 branch from 1037948 to 3ca2977 Compare April 8, 2026 17:54
@ethanjli ethanjli enabled auto-merge April 8, 2026 18:02
@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/anchore/quill-0.7.1 branch from 3ca2977 to ebf04b2 Compare April 8, 2026 18:07
Bumps [github.com/anchore/quill](https://github.com/anchore/quill) from 0.5.1 to 0.7.1.
- [Release notes](https://github.com/anchore/quill/releases)
- [Changelog](https://github.com/anchore/quill/blob/main/RELEASE.md)
- [Commits](anchore/quill@v0.5.1...v0.7.1)

---
updated-dependencies:
- dependency-name: github.com/anchore/quill
  dependency-version: 0.7.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/anchore/quill-0.7.1 branch from ebf04b2 to 4c7712f Compare April 8, 2026 21:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants