Skip to content

Bump github.com/carabiner-dev/collector from 0.3.12 to 0.3.13 in the gomod group - #85

Merged
miniprow[bot] merged 1 commit into
mainfrom
dependabot/go_modules/gomod-a1787c37ad
Sep 1, 2026
Merged

Bump github.com/carabiner-dev/collector from 0.3.12 to 0.3.13 in the gomod group#85
miniprow[bot] merged 1 commit into
mainfrom
dependabot/go_modules/gomod-a1787c37ad

Bump github.com/carabiner-dev/collector in the gomod group

a70c088
Select commit
Loading
Failed to load commit list.
Kusari Inspector / Kusari Inspector succeeded Sep 1, 2026 in 1m 54s

Security Analysis Passed

No security issues found

Details

Kusari Inspector

Kusari Analysis Results:

Proceed with these changes

✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.

Both analyses support proceeding. Dependency analysis: 6 Go dependencies updated with permissive licenses (Apache-2.0, BSD-3-Clause, MIT) and strong scorecard ratings; no deprecated, EOL, or blocked packages; no typosquatting/confusion risks found. Two advisories (GO-2026-6179, GO-2026-6180) affecting golang.org/x/mod are pre-existing, carried over from the prior version, not introduced or worsened by this PR, and both are marked notAffected since govulncheck confirms the vulnerable code path is not called. As an optional hardening step, running go get golang.org/x/mod@v0.40.0 would pin a direct fix, but this is good hygiene rather than a merge blocker. Code analysis found no code issues, exposed secrets, or workflow issues. Combined, there are no critical or actionable security concerns that warrant delaying this PR.

Note

View full detailed analysis result for more information on the output and the checks that were run.


@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: a70c088, performed at: 2026-09-01T09:11:35Z