Skip to content

chore(deps): bump github.com/gemaraproj/go-gemara from 0.8.0 to 0.9.0 - #801

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/gemaraproj/go-gemara-0.9.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/gemaraproj/go-gemara-0.9.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/gemaraproj/go-gemara from 0.8.0 to 0.9.0.

Release notes

Sourced from github.com/gemaraproj/go-gemara's releases.

v0.9.0

Changelog

🚀 Features

🐛 Bug Fixes

🧰 Maintenance

See details of all code changes since previous release

Commits
  • 292707d chore(deps): Bump the dependencies group with 2 updates (#109)
  • b7796b7 feat(fetcher): add BasePath to URI for relative file:// resolution (#107)
  • 816d828 feat!: require Fetcher for lexicon autolink in CatalogToMarkdown (#100)
  • 994de6b chore(deps): Bump the dependencies group with 2 updates (#108)
  • 21b5908 fix: handle NotApplicable in UpdateAggregateResult (#106)
  • 6ab76b4 chore(deps): Bump github.com/defenseunicorns/go-oscal (#104)
  • 1e6788d chore(deps): Bump actions/setup-go from 6.5.0 to 7.0.0 (#105)
  • 2c7da20 feat(bundle): error by default on unmatched mapping-reference IDs (#98)
  • 91154ee feat: add GitHub Issue Templates (#101)
  • 132f817 docs: add CONTRIBUTING.md (#99)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 3, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 3, 2026 01:04
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 3, 2026
@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

🤖 Standardized Dependabot Review Summary 🤖

This PR was processed by the organization's reusable CI pipeline.

Criterion Status Detail
Dependencies Review success View logs
Calculated Risk medium github.com/gemaraproj/go-gemara v0.9.0
Release Age 81h Released 81 hours ago
Ownership third-party External dependency
Dependency Usage 3 repos Informational only — does not affect approval

Auto-approval: ✅ Approved


Maintainer check list:

  1. Ensure the PR passed all CI tests (required status checks).
  2. Investigate failures for Major updates or any manual review requirement.
  3. Don't overlook breaking changes and changelog information.
  4. If the scorecard value is low, consider to contribute to make it higher. Everybody wins!
  5. Be diligent. When in doubt, ask another maintainer for additional review.

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

CRAP Load Analysis

No Go code changes detected in this PR. No CRAP impact.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automatically approved: risk=medium, review=success, ownership=third-party, release_age=81h.

@trevor-vaughan
trevor-vaughan force-pushed the dependabot/go_modules/github.com/gemaraproj/go-gemara-0.9.0 branch from 47e0d6b to fe89ead Compare August 3, 2026 13:57
@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

🤖 Standardized Dependabot Review Summary 🤖

This PR was processed by the organization's reusable CI pipeline.

Criterion Status Detail
Dependencies Review success View logs
Calculated Risk medium github.com/gemaraproj/go-gemara v0.9.0
Release Age 94h Released 94 hours ago
Ownership third-party External dependency
Dependency Usage 3 repos Informational only — does not affect approval

Auto-approval: ✅ Approved


Maintainer check list:

  1. Ensure the PR passed all CI tests (required status checks).
  2. Investigate failures for Major updates or any manual review requirement.
  3. Don't overlook breaking changes and changelog information.
  4. If the scorecard value is low, consider to contribute to make it higher. Everybody wins!
  5. Be diligent. When in doubt, ask another maintainer for additional review.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automatically approved: risk=medium, review=success, ownership=third-party, release_age=94h.

Bumps [github.com/gemaraproj/go-gemara](https://github.com/gemaraproj/go-gemara) from 0.8.0 to 0.9.0.
- [Release notes](https://github.com/gemaraproj/go-gemara/releases)
- [Commits](gemaraproj/go-gemara@v0.8.0...v0.9.0)

---
updated-dependencies:
- dependency-name: github.com/gemaraproj/go-gemara
  dependency-version: 0.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@trevor-vaughan
trevor-vaughan force-pushed the dependabot/go_modules/github.com/gemaraproj/go-gemara-0.9.0 branch from fe89ead to 735ee57 Compare August 4, 2026 13:29

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automatically approved: risk=medium, review=success, ownership=third-party, release_age=117h.

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

🤖 Standardized Dependabot Review Summary 🤖

This PR was processed by the organization's reusable CI pipeline.

Criterion Status Detail
Dependencies Review success View logs
Calculated Risk medium github.com/gemaraproj/go-gemara v0.9.0
Release Age 117h Released 117 hours ago
Ownership third-party External dependency
Dependency Usage unavailable Informational only — does not affect approval

Auto-approval: ✅ Approved


Maintainer check list:

  1. Ensure the PR passed all CI tests (required status checks).
  2. Investigate failures for Major updates or any manual review requirement.
  3. Don't overlook breaking changes and changelog information.
  4. If the scorecard value is low, consider to contribute to make it higher. Everybody wins!
  5. Be diligent. When in doubt, ask another maintainer for additional review.

@trevor-vaughan

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@trevor-vaughan

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@trevor-vaughan

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@yvonnedevlinrh

Copy link
Copy Markdown
Contributor

Triage Review Panel

Agent Verdict Summary
Adversary APPROVE CVE-2026-50163 remediated. Fetcher interface improves SSRF surface. No new attack surface.
Architect APPROVE Breaking APIs not used (0 call sites). Behavioral fix correct. Stale test comment (LOW).
Guard REQUEST CHANGES Undocumented behavioral change affects user-visible reports. Missing tests + CHANGELOG.
SRE APPROVE Healthy dependency. Comprehensive CI. Dependabot rebase failure warrants investigation.
Testing REQUEST CHANGES Missing regression test for all-NotApplicable aggregation. Stale comment.

Consensus: 3/5 APPROVE, 2/5 REQUEST CHANGES

Key Behavioral Change

UpdateAggregateResult() in go-gemara v0.9.0 now returns NotApplicable instead of Passed when all inputs are NotApplicable. This affects three call sites in complyctl:

  • internal/output/evaluator.go:92,107 (EvaluationLog generation)
  • internal/output/sarif.go:61 (SARIF report generation)

This is a correctness fix (all-not-applicable ≠ passed), but it changes user-visible report output and is not covered by existing tests.

Action

Closing this Dependabot PR. A new PR will be created that includes the bump along with:

  1. Tests for the all-NotApplicable aggregation path
  2. Fix for stale comment at scan_summary_test.go:300-302
  3. CHANGELOG entry for behavioral change + CVE fix

Divisor Review Panel — automated triage

@dependabot @github

dependabot Bot commented on behalf of github Aug 18, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/go_modules/github.com/gemaraproj/go-gemara-0.9.0 branch August 18, 2026 14:56
yvonnedevlinrh added a commit to yvonnedevlinrh/complyctl that referenced this pull request Aug 18, 2026
Add regression test coverage and documentation for the
UpdateAggregateResult behavioral change introduced in
go-gemara v0.9.0 (merged via complytime#813, originally proposed in complytime#801).

- New tests in evaluator_test.go:
  - All-skipped steps yields NotApplicable (was Passed pre-v0.9.0)
  - Mixed passed and skipped yields Passed (dominance preserved)
  - Multi-control all-skipped yields overall NotApplicable
- Fix stale comment in scan_summary_test.go describing pre-v0.9.0
  aggregation behavior
- CHANGELOG entries for behavioral change and CVE-2026-50163

Assisted-by: OpenCode (claude-opus-4-6)
Signed-off-by: Yvonne Devlin <ydevlin@redhat.com>
yvonnedevlinrh added a commit to yvonnedevlinrh/complyctl that referenced this pull request Aug 20, 2026
Add regression test coverage and documentation for the
UpdateAggregateResult behavioral change introduced in
go-gemara v0.9.0 (merged via complytime#813, originally proposed in complytime#801).

- New tests in evaluator_test.go:
  - All-skipped steps yields NotApplicable (was Passed pre-v0.9.0)
  - Mixed passed and skipped yields Passed (dominance preserved)
  - Multi-control all-skipped yields overall NotApplicable
- Fix stale comment in scan_summary_test.go describing pre-v0.9.0
  aggregation behavior
- CHANGELOG entries for behavioral change and CVE-2026-50163

Assisted-by: OpenCode (claude-opus-4-6)
Signed-off-by: Yvonne Devlin <ydevlin@redhat.com>
yvonnedevlinrh added a commit that referenced this pull request Aug 24, 2026
Add regression test coverage and documentation for the
UpdateAggregateResult behavioral change introduced in
go-gemara v0.9.0 (merged via #813, originally proposed in #801).

- New tests in evaluator_test.go:
  - All-skipped steps yields NotApplicable (was Passed pre-v0.9.0)
  - Mixed passed and skipped yields Passed (dominance preserved)
  - Multi-control all-skipped yields overall NotApplicable
- Fix stale comment in scan_summary_test.go describing pre-v0.9.0
  aggregation behavior
- CHANGELOG entries for behavioral change and CVE-2026-50163

Assisted-by: OpenCode (claude-opus-4-6)

Signed-off-by: Yvonne Devlin <ydevlin@redhat.com>
em-redhat pushed a commit to em-redhat/complyctl that referenced this pull request Sep 1, 2026
Add regression test coverage and documentation for the
UpdateAggregateResult behavioral change introduced in
go-gemara v0.9.0 (merged via complytime#813, originally proposed in complytime#801).

- New tests in evaluator_test.go:
  - All-skipped steps yields NotApplicable (was Passed pre-v0.9.0)
  - Mixed passed and skipped yields Passed (dominance preserved)
  - Multi-control all-skipped yields overall NotApplicable
- Fix stale comment in scan_summary_test.go describing pre-v0.9.0
  aggregation behavior
- CHANGELOG entries for behavioral change and CVE-2026-50163

Assisted-by: OpenCode (claude-opus-4-6)

Signed-off-by: Yvonne Devlin <ydevlin@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants