Skip to content

chore: bump github.com/oasdiff/oasdiff from 1.12.7 to 1.13.1 in /tools/cli#1197

Merged
matt-condon merged 1 commit intomainfrom
dependabot/go_modules/tools/cli/github.com/oasdiff/oasdiff-1.13.1
Apr 8, 2026
Merged

chore: bump github.com/oasdiff/oasdiff from 1.12.7 to 1.13.1 in /tools/cli#1197
matt-condon merged 1 commit intomainfrom
dependabot/go_modules/tools/cli/github.com/oasdiff/oasdiff-1.13.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Apr 7, 2026

Bumps github.com/oasdiff/oasdiff from 1.12.7 to 1.13.1.

Release notes

Sourced from github.com/oasdiff/oasdiff's releases.

v1.13.1

Changelog

  • 4a92d9796a5034ce96f65ce4f2abefe6238207a5 feat: add --allow-external-refs flag to mitigate SSRF (#831)
  • f3941fb3956c6c646a438d999f28b671ac2d4ef6 fix: bump kin-openapi to v0.136.10, add $ref-root source tracking test (#830)
  • 01b2eb62380f3f54d956e77f2f0a424ea49d06c7 data: add ref-chain-example for $ref resolution testing

v1.13.0

Changes

  • Bump github.com/oasdiff/kin-openapi to v0.136.9, which includes the OriginTree approach for origin tracking — a two-pass design replacing ad-hoc __origin__ inline stripping. Fixes performance regressions on large specs.
  • Bump github.com/oasdiff/yaml to v0.0.8 and github.com/oasdiff/yaml3 to v0.0.8.

v1.12.9

What's Changed

  • Bump kin-openapi to v0.136.8 — removes dead origin-stripping code (no functional change)
  • Bump github.com/wI2L/jsondiff from v0.7.0 to v0.7.1

v1.12.8

What's Changed

  • Bump kin-openapi to v0.136.7 — compact __origin__ format (~4x less YAML overhead), fix origin tracking for integer HTTP status codes
Commits
  • 4a92d97 feat: add --allow-external-refs flag to mitigate SSRF (#831)
  • f3941fb fix: bump kin-openapi to v0.136.10, add $ref-root source tracking test (#830)
  • 01b2eb6 data: add ref-chain-example for $ref resolution testing
  • 07ccfe2 chore: bump kin-openapi to v0.136.9 with OriginTree origin tracking (#829)
  • 99e4474 Merge pull request #827: bump kin-openapi to v0.136.8
  • 3ac6faf chore: bump kin-openapi to v0.136.8
  • 798d43e Merge pull request #825: bump github.com/wI2L/jsondiff from 0.7.0 to 0.7.1
  • aa19459 Merge pull request #826 from oasdiff/bump/kin-openapi-v0.136.7
  • f344d08 chore: bump kin-openapi to v0.136.7 with compact origin format
  • 04418bb chore(deps): bump github.com/wI2L/jsondiff from 0.7.0 to 0.7.1
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/oasdiff/oasdiff](https://github.com/oasdiff/oasdiff) from 1.12.7 to 1.13.1.
- [Release notes](https://github.com/oasdiff/oasdiff/releases)
- [Changelog](https://github.com/oasdiff/oasdiff/blob/main/docs/CHANGELOG-TEMPLATE.md)
- [Commits](oasdiff/oasdiff@v1.12.7...v1.13.1)

---
updated-dependencies:
- dependency-name: github.com/oasdiff/oasdiff
  dependency-version: 1.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Apr 7, 2026
@dependabot dependabot bot requested a review from a team as a code owner April 7, 2026 21:53
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Apr 7, 2026
@dependabot dependabot bot requested review from drinkbird and wtrocki April 7, 2026 21:53
@dependabot dependabot bot added the go Pull requests that update Go code label Apr 7, 2026
@matt-condon matt-condon merged commit 3be54c2 into main Apr 8, 2026
9 checks passed
@matt-condon matt-condon deleted the dependabot/go_modules/tools/cli/github.com/oasdiff/oasdiff-1.13.1 branch April 8, 2026 10:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant