Conversation
…fers/go --- updated-dependencies: - dependency-name: buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go dependency-version: 1.36.11-20260415201107-50325440f8f2.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
migmartri
left a comment
There was a problem hiding this comment.
Automated Dependabot review: low-risk patch-level bump (same semver core, manifest-only change). CI is currently red, so approving but holding merge until checks pass.
🤖 Posted by Maximus bot (Claude Code) on behalf of @migmartri
The protovalidate protocolbuffers/go bump changes the regex constraint violation message from 'value does not match regex pattern' to 'does not match regex pattern'. Update the expected string in TestPolicyAttachment accordingly. Assisted-by: Claude Code Signed-off-by: Miguel Martinez Trivino <miguel@chainloop.dev> Chainloop-Trace-Sessions: 8335ea5b-d667-4053-8a95-5633a6aedad0
AI Session Analysis
|
| Status | Policy | Material | Messages |
|---|---|---|---|
| ✅ Passed | ai-config-ai-agents-allowed |
ai-coding-session-8335ea |
- |
| ✅ Passed | ai-config-no-dangerous-commands |
ai-coding-session-8335ea |
- |
ai-config-no-secrets |
ai-coding-session-8335ea |
|
|
| ✅ Passed | ai-config-mcp-servers-allowed |
ai-coding-session-8335ea |
- |
Powered by Chainloop and Chainloop Trace
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)