Skip to content

chore(deps): bump github.com/pb33f/libopenapi from 0.38.6 to 0.38.7 - #208

Merged
SebastienMelki merged 1 commit into
mainfrom
dependabot-go_modules-github.com-pb33f-libopenapi-0.38.7
Aug 6, 2026
Merged

chore(deps): bump github.com/pb33f/libopenapi from 0.38.6 to 0.38.7#208
SebastienMelki merged 1 commit into
mainfrom
dependabot-go_modules-github.com-pb33f-libopenapi-0.38.7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/pb33f/libopenapi from 0.38.6 to 0.38.7.

Release notes

Sourced from github.com/pb33f/libopenapi's releases.

v0.38.7 improves composed bundling by correctly lifting external Security Scheme references—including bare-file and component-fragment refs—into components.securitySchemes, with safeguards against misclassifying wrapper maps or complete OpenAPI documents. Arazzo engines can now inject a context-aware SleepFunc through EngineConfig, enabling replay-safe retry delays in durable workflow runtimes and deterministic tests while preserving existing behavior by default. This release also adds regression coverage for empty Security Requirement objects and updates golang.org/x/sync to v0.22.0.

@​kriptoburak @​khalidDaoud

Commits
  • 0837c9b coverage
  • 1338994 coverage
  • dd2a700 fix: compose external security scheme refs during bundling (#932)
  • a1e9b6a Bump golang.org/x/sync from 0.21.0 to 0.22.0
  • 01d2e4d arazzo: make the retry sleeper injectable via EngineConfig.SleepFunc
  • af8d024 test: cover empty security requirements
  • See full diff in compare view

@dependabot @github

dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, go. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

Copy link
Copy Markdown

🔍 CI Pipeline Status

Lint: success
Test: success
Coverage: success
Build: success
Integration: success


📊 Coverage Report: Available in checks above
🔗 Artifacts: Test results and coverage reports uploaded

@SebastienMelki

Copy link
Copy Markdown
Owner

@dependabot rebase\n\nReview note: dependency bump itself looks low risk and OpenAPI-targeted tests pass, but the branch is stale/diverged from current main. Please rebase and rerun CI before merge.

Bumps [github.com/pb33f/libopenapi](https://github.com/pb33f/libopenapi) from 0.38.6 to 0.38.7.
- [Release notes](https://github.com/pb33f/libopenapi/releases)
- [Commits](pb33f/libopenapi@v0.38.6...v0.38.7)

---
updated-dependencies:
- dependency-name: github.com/pb33f/libopenapi
  dependency-version: 0.38.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot-go_modules-github.com-pb33f-libopenapi-0.38.7 branch from 33d557d to 7e32ffa Compare August 6, 2026 09:23

@SebastienMelki SebastienMelki left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed after Dependabot rebase: libopenapi patch bump; fresh CI is green.

@SebastienMelki
SebastienMelki merged commit 58b294c into main Aug 6, 2026
8 checks passed
@SebastienMelki
SebastienMelki deleted the dependabot-go_modules-github.com-pb33f-libopenapi-0.38.7 branch August 6, 2026 09:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant