Skip to content

Bump github.com/spf13/cobra from 1.8.0 to 1.10.2 in /cli - #4

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/cli/github.com/spf13/cobra-1.10.2
Closed

Bump github.com/spf13/cobra from 1.8.0 to 1.10.2 in /cli#4
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/cli/github.com/spf13/cobra-1.10.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 17, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/spf13/cobra from 1.8.0 to 1.10.2.

Release notes

Sourced from github.com/spf13/cobra's releases.

v1.10.2

🔧 Dependencies

  • chore: Migrate from gopkg.in/yaml.v3 to go.yaml.in/yaml/v3 by @​dims in spf13/cobra#2336 - the gopkg.in/yaml.v3 package has been deprecated for some time: this should significantly cleanup dependency/supply-chains for consumers of spf13/cobra

📈 CI/CD

🔥✍🏼 Docs

🍂 Refactors

🤗 New Contributors

Full Changelog: spf13/cobra@v1.10.1...v1.10.2

Thank you to our amazing contributors!!!!! 🐍 🚀

v1.10.1

🐛 Fix

v1.0.9 of pflags brought back ParseErrorsWhitelist and marked it as deprecated

Full Changelog: spf13/cobra@v1.10.0...v1.10.1

v1.10.0

What's Changed

🚨 Attention!

This version of pflag carried a breaking change: it renamed ParseErrorsWhitelist to ParseErrorsAllowlist which can break builds if both pflag and cobra are dependencies in your project.

  • If you use both pflag and cobra, upgrade pflagto 1.0.8 andcobrato1.10.0`
  • or use the newer, fixed version of pflag v1.0.9 which keeps the deprecated ParseErrorsWhitelist

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot @github

dependabot Bot commented on behalf of github Mar 17, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, go. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Bumps [github.com/spf13/cobra](https://github.com/spf13/cobra) from 1.8.0 to 1.10.2.
- [Release notes](https://github.com/spf13/cobra/releases)
- [Commits](spf13/cobra@v1.8.0...v1.10.2)

---
updated-dependencies:
- dependency-name: github.com/spf13/cobra
  dependency-version: 1.10.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/cli/github.com/spf13/cobra-1.10.2 branch from 4a5f8e8 to 9f72776 Compare March 22, 2026 14:44
@dvcdsys

dvcdsys commented Mar 23, 2026

Copy link
Copy Markdown
Owner

Closing: cobra 1.10.2 upgrade is safe but will be handled as part of a coordinated dependency update.

@dvcdsys dvcdsys closed this Mar 23, 2026
@dependabot @github

dependabot Bot commented on behalf of github Mar 23, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/go_modules/cli/github.com/spf13/cobra-1.10.2 branch March 23, 2026 10:20
dvcdsys added a commit that referenced this pull request May 12, 2026
…dule

Previous backoff streak retried indefinitely with delay capped at 30m,
which meant a permanent GitHub outage produced ~48 polls per day per
server. Now a streak gives up after MaxBackoffAttempts (default 5) and
the next attempt is anchored to streakStart + Interval — i.e. the
regular 6h grid resumes from the FIRST attempt of the failed streak,
not from "now".

Worst case progression with defaults (Interval=6h, Initial=1m, Max=30m):
  attempt #1 fails              T = 0
  attempt #2 fails  (wait ~1m)  T = +1m
  attempt #3 fails  (wait ~2m)  T = +3m
  attempt #4 fails  (wait ~4m)  T = +7m
  attempt #5 fails  (wait ~8m)  T = +15m  → exhaust
  attempt #6 fires             T = T0 + 6h  (anchor)

Successful poll mid-streak resets attempt counter and wait reverts to
Interval. The "anchor from first attempt" choice keeps the long-term
schedule on its grid even when a streak ate up to ~30m of it; an
absurdly long streak (rare; needs Interval < BackoffMax × N) collapses
the wait to 0 and fires immediately, which is the only sensible
behaviour when we already overshot.

  - MaxBackoffAttempts surfaced on Config (default 5).
  - TestRunStreakExhaustedAnchorsToInterval covers the exhaust path:
    3 fails → anchored sleep → #4 fires near streakStart+Interval.
  - Existing TestRunBacksOffOnFailureThenResets unchanged (recovers
    after 2 fails, well below the cap).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant