Bump github.com/jedib0t/go-pretty/v6 from 6.7.9 to 6.8.1#322
Bump github.com/jedib0t/go-pretty/v6 from 6.7.9 to 6.8.1#322dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [github.com/jedib0t/go-pretty/v6](https://github.com/jedib0t/go-pretty) from 6.7.9 to 6.8.1. - [Release notes](https://github.com/jedib0t/go-pretty/releases) - [Commits](jedib0t/go-pretty@v6.7.9...v6.8.1) --- updated-dependencies: - dependency-name: github.com/jedib0t/go-pretty/v6 dependency-version: 6.8.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Supply Chain Security Review
⚠️ github.com/jedib0t/go-pretty/v6 v6.8.1 — version published <2 hours ago, not yet indexed by deps.dev
This version was released on GitHub at 2026-06-11T02:37:39Z — well within the 72-hour detection-latency window for supply-chain attacks. deps.dev returns 404 for this version (not yet indexed).
Mitigating factors:
- Well-established package (~1.4k stars) with regular release cadence (v6.7.9 → v6.7.10 → v6.8.0 → v6.8.1)
- No known vulnerabilities (OSV clean)
- Raised by Dependabot (automated)
- OpenSSF Scorecard: 5.7/10
Recommendation: Wait 48–72 hours before merging so that the version is indexed by deps.dev and has passed through the community's early-detection window. Alternatively, pin to v6.8.0 (released June 3) which has had a week to bake.
Tag @mendral-app with feedback or questions. View session
| github.com/google/goexpect v0.0.0-20210430020637-ab937bf7fd6f | ||
| github.com/gorilla/websocket v1.5.3 | ||
| github.com/jedib0t/go-pretty/v6 v6.7.9 | ||
| github.com/jedib0t/go-pretty/v6 v6.8.1 |
There was a problem hiding this comment.
maintainability (P3): Version v6.8.1 was published <2 hours ago and is not yet indexed by deps.dev. Consider waiting 48-72h before merging, or pinning to v6.8.0 (released 2026-06-03) which has had more bake time.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At go.mod, line 18:
<issue>
Version v6.8.1 was published <2 hours ago and is not yet indexed by deps.dev. Consider waiting 48-72h before merging, or pinning to v6.8.0 (released 2026-06-03) which has had more bake time.
</issue>
Bumps github.com/jedib0t/go-pretty/v6 from 6.7.9 to 6.8.1.
Release notes
Sourced from github.com/jedib0t/go-pretty/v6's releases.
... (truncated)
Commits
22c68f6fix panics, races, and injection vectors; speed up render hot paths (#409)45fb00dtext: wrap wide runes when wrapLen is odd in WrapHard (#408)ad17549progress: fix speed decay on done trackers and log overwrite; fixes #405 (#406)66563fdtext: fix panic on align with unicode (#404)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)