Skip to content

chore(deps): bump github.com/cybozu-go/moco from 0.34.0 to 0.36.0 - #280

Open
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/go_modules/github.com/cybozu-go/moco-0.36.0
Open

chore(deps): bump github.com/cybozu-go/moco from 0.34.0 to 0.36.0#280
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/go_modules/github.com/cybozu-go/moco-0.36.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 22, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/cybozu-go/moco from 0.34.0 to 0.36.0.

Release notes

Sourced from github.com/cybozu-go/moco's releases.

Release v0.36.0

See CHANGELOG.md for details.

Release v0.35.0

See CHANGELOG.md for details.

Changelog

Sourced from github.com/cybozu-go/moco's changelog.

[0.36.0] - 2026-07-01

Added

  • Add a --disable-default-security-context flag to moco-controller that, when enabled, disables default injection of runAsUser/runAsGroup/fsGroup (default: false, existing behavior unchanged). #872
  • Add SECURITY.md #919

Fixed

  • Add predicates to PodWatcher for better event filtering #925
  • Prevent MySQLCluster controller startup slowdown in large clusters #924

Contributors

[0.35.0] - 2026-05-12

Added

  • Support for Azure Blob Storage backups #866
  • Add timezone support to BackupPolicy #886
  • Add instructions for cluster consistency invariants #893
  • Add note about lexicographic pod sort limitation for 10+ replicas #895
  • Introduce golangci-lint and apply lint cleanups #902
  • Add copy-moco-init container to documentation #906
  • Add linters for GitHub Actions workflows and fix issues found by them #907
  • Support for Kubernetes v1.33, v1.34, v1.35 with related dependency, CRD, and tooling updates #911

Changed

  • Update reference link in change-pvc-template.md #885
  • Bump chart version to v0.24.0 #890
  • Refactor kustomization.yaml files to use patches instead of legacy patchesStrategicMerge and apply kustomize edit fix #901
  • Update fluent-bit and mysqld_exporter container images #910

Fixed

  • Fix CLSUTER_NAME typo in documentation #894
  • Add objectSelector to the StatefulSet mutating webhook configuration and confirm StatefulSet revision in partition controller #882
  • Mount /tmp in moco-init container #896
  • Use helper functions for client Options #897
  • Fix flaky test for "should reconcile a pod disruption budget" #898
  • Fix "the object has been modified" error in kubectl-moco switchover #899
  • Increase timeout for kubectl wait to 180s #900
  • Fix "the object has been modified" flaky failure #908
  • Update validation enum for OverwriteableContainerName #905

Contributors

Commits
  • 4ef2d8e Bump version to v0.36.0 (#927)
  • 2313341 Prevent MySQLCluster controller startup slowdown in large clusters (#924)
  • 79765ba Add predicates to PodWatcher for better event filtering (#925)
  • 2c21ab0 Merge pull request #917 from wnevis-cmyk/wnevis/openshift-uidFixes
  • f24ea6b Merge branch 'main' into wnevis/openshift-uidFixes
  • ee34dde Move defaultPodSecurityContext to mysqlcluster_controller.go
  • d650f74 Add SECURITY.md (#919)
  • 2baf81e Make security-context defaults opt-out and restore blockOwnerDeletion
  • 97dc4f2 Drop blockOwnerDeletion on PVC owner reference
  • ff0dd68 Remove default FSGroup injection
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/cybozu-go/moco](https://github.com/cybozu-go/moco) from 0.34.0 to 0.36.0.
- [Release notes](https://github.com/cybozu-go/moco/releases)
- [Changelog](https://github.com/cybozu-go/moco/blob/main/CHANGELOG.md)
- [Commits](cybozu-go/moco@v0.34.0...v0.36.0)

---
updated-dependencies:
- dependency-name: github.com/cybozu-go/moco
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jul 22, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner July 22, 2026 05:33
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jul 22, 2026
@socket-security

socket-security Bot commented Jul 22, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedsigs.k8s.io/​controller-runtime@​v0.22.4 ⏵ v0.23.373 +1100100100100
Updatedgithub.com/​cybozu-go/​moco@​v0.34.0 ⏵ v0.36.093 +6100100100100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant