chore(deps): bump github.com/gemaraproj/go-gemara from 0.8.0 to 0.9.0 - #801
dependabot[bot] wants to merge 1 commit into
Conversation
|
🤖 Standardized Dependabot Review Summary 🤖 This PR was processed by the organization's reusable CI pipeline.
Auto-approval: ✅ Approved Maintainer check list:
|
CRAP Load AnalysisNo Go code changes detected in this PR. No CRAP impact. |
47e0d6b to
fe89ead
Compare
|
🤖 Standardized Dependabot Review Summary 🤖 This PR was processed by the organization's reusable CI pipeline.
Auto-approval: ✅ Approved Maintainer check list:
|
Bumps [github.com/gemaraproj/go-gemara](https://github.com/gemaraproj/go-gemara) from 0.8.0 to 0.9.0. - [Release notes](https://github.com/gemaraproj/go-gemara/releases) - [Commits](gemaraproj/go-gemara@v0.8.0...v0.9.0) --- updated-dependencies: - dependency-name: github.com/gemaraproj/go-gemara dependency-version: 0.9.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
fe89ead to
735ee57
Compare
|
🤖 Standardized Dependabot Review Summary 🤖 This PR was processed by the organization's reusable CI pipeline.
Auto-approval: ✅ Approved Maintainer check list:
|
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
Triage Review Panel
Consensus: 3/5 APPROVE, 2/5 REQUEST CHANGES Key Behavioral Change
This is a correctness fix (all-not-applicable ≠ passed), but it changes user-visible report output and is not covered by existing tests. ActionClosing this Dependabot PR. A new PR will be created that includes the bump along with:
Divisor Review Panel — automated triage |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Add regression test coverage and documentation for the UpdateAggregateResult behavioral change introduced in go-gemara v0.9.0 (merged via complytime#813, originally proposed in complytime#801). - New tests in evaluator_test.go: - All-skipped steps yields NotApplicable (was Passed pre-v0.9.0) - Mixed passed and skipped yields Passed (dominance preserved) - Multi-control all-skipped yields overall NotApplicable - Fix stale comment in scan_summary_test.go describing pre-v0.9.0 aggregation behavior - CHANGELOG entries for behavioral change and CVE-2026-50163 Assisted-by: OpenCode (claude-opus-4-6) Signed-off-by: Yvonne Devlin <ydevlin@redhat.com>
Add regression test coverage and documentation for the UpdateAggregateResult behavioral change introduced in go-gemara v0.9.0 (merged via complytime#813, originally proposed in complytime#801). - New tests in evaluator_test.go: - All-skipped steps yields NotApplicable (was Passed pre-v0.9.0) - Mixed passed and skipped yields Passed (dominance preserved) - Multi-control all-skipped yields overall NotApplicable - Fix stale comment in scan_summary_test.go describing pre-v0.9.0 aggregation behavior - CHANGELOG entries for behavioral change and CVE-2026-50163 Assisted-by: OpenCode (claude-opus-4-6) Signed-off-by: Yvonne Devlin <ydevlin@redhat.com>
Add regression test coverage and documentation for the UpdateAggregateResult behavioral change introduced in go-gemara v0.9.0 (merged via #813, originally proposed in #801). - New tests in evaluator_test.go: - All-skipped steps yields NotApplicable (was Passed pre-v0.9.0) - Mixed passed and skipped yields Passed (dominance preserved) - Multi-control all-skipped yields overall NotApplicable - Fix stale comment in scan_summary_test.go describing pre-v0.9.0 aggregation behavior - CHANGELOG entries for behavioral change and CVE-2026-50163 Assisted-by: OpenCode (claude-opus-4-6) Signed-off-by: Yvonne Devlin <ydevlin@redhat.com>
Add regression test coverage and documentation for the UpdateAggregateResult behavioral change introduced in go-gemara v0.9.0 (merged via complytime#813, originally proposed in complytime#801). - New tests in evaluator_test.go: - All-skipped steps yields NotApplicable (was Passed pre-v0.9.0) - Mixed passed and skipped yields Passed (dominance preserved) - Multi-control all-skipped yields overall NotApplicable - Fix stale comment in scan_summary_test.go describing pre-v0.9.0 aggregation behavior - CHANGELOG entries for behavioral change and CVE-2026-50163 Assisted-by: OpenCode (claude-opus-4-6) Signed-off-by: Yvonne Devlin <ydevlin@redhat.com>
Bumps github.com/gemaraproj/go-gemara from 0.8.0 to 0.9.0.
Release notes
Sourced from github.com/gemaraproj/go-gemara's releases.
Commits
292707dchore(deps): Bump the dependencies group with 2 updates (#109)b7796b7feat(fetcher): add BasePath to URI for relative file:// resolution (#107)816d828feat!: require Fetcher for lexicon autolink in CatalogToMarkdown (#100)994de6bchore(deps): Bump the dependencies group with 2 updates (#108)21b5908fix: handle NotApplicable in UpdateAggregateResult (#106)6ab76b4chore(deps): Bump github.com/defenseunicorns/go-oscal (#104)1e6788dchore(deps): Bump actions/setup-go from 6.5.0 to 7.0.0 (#105)2c7da20feat(bundle): error by default on unmatched mapping-reference IDs (#98)91154eefeat: add GitHub Issue Templates (#101)132f817docs: add CONTRIBUTING.md (#99)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)