Skip to content

build(deps): bump github.com/maci0/toktop from 0.21.0 to 0.23.0 in the go-minor-patch group - #53

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-minor-patch-cff1a8e867
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-minor-patch-cff1a8e867

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-minor-patch group with 1 update: github.com/maci0/toktop.

Updates github.com/maci0/toktop from 0.21.0 to 0.23.0

Changelog

Sourced from github.com/maci0/toktop's changelog.

[0.23.0] - 2026-09-30

Binaries, checksums, and a CycloneDX SBOM are on GitHub Releases.

Breaking

  • Five keys of the --once --json report were renamed, and the report's schema field moved from 1 to 2: engines[].proc_rss_mb is engines[].proc_rss_mib, and in system the pairs mem_total_mb and mem_used_mb are mem_total_mib and mem_used_mib, swap_total_mb and swap_used_mb are swap_total_mib and swap_used_mib. The values did not move: a MiB figure is still MiB, as the other _mib keys in the report and the proc_rss_mib the typed report already published were, and the _mb spelling is what disagreed with them. A consumer reading a renamed key decodes a report with no error and reads zero, because the key it asked for is not there and the one beside it is. Read the schema field first and treat 2 as the _mib spelling, or read whichever key is present. No other published field changed name, meaning or unit, and adding a field is not a schema bump, so a consumer reading named fields needs no change for anything else in this report.

  • agentusage.Definition and agentusage.Spec now carry UnmarshalJSON and MarshalJSON. A program that decoded or encoded either one through encoding/json is unaffected, but a program that embedded one in a struct of its own no longer decodes. A UnmarshalJSON on an embedded type is promoted to the outer type, so json.Unmarshal into a T that embeds agentusage.Definition calls Definition's method with the whole document and leaves every field of T beside it at its zero value. On an agents.json entry those fields are where an entry's launch configuration is read into, and the loss is quiet: the entry re-marshals with them, since MarshalJSON writes the keys beside usage back out, so a read, edit and write cycle drops a field no error names. Decode into a Definition and copy it into T afterwards, or give T its own UnmarshalJSON; a program that reads and writes the whole file should decode into agentusage.Definitions, which does the split already. The method's doc comment now says so where a caller embedding the type will read it.

  • agentusage.Definition gained the Extra field, so an unkeyed composite literal of it (agentusage.Definition{spec}) no longer compiles. A keyed literal, and every read of Usage, is unchanged.

Added

  • Every published release file now carries a SLSA provenance attestation signed with this repository's identity and recorded in GitHub's public transparency log, so a downloaded binary can be checked against a log entry instead of against the checksums.txt that sits on the same page as the bytes. gh attestation verify toktop_<version>_<goos>_<goarch> --repo maci0/toktop is the whole check. toktop update still verifies

... (truncated)

Commits
  • 9d47f23 release 0.23.0
  • fb89571 fix: name the live text report in the startup config record
  • 90693ff refactor: split ingest startup out of runMain and drop repeated lookups
  • 6752b34 fix: read a non-finite tok/s rate as no throughput
  • 90a2a76 fix: stop failing every host-key store write on Windows
  • 7eb06f8 test: cover the --json engine serializer and the UI failure feed
  • c86ed9e refactor: name the vendor enum and share the token ceiling across packag
  • d13ae81 fix: release the process trees and foreign verdicts that outlive their o
  • 1e843f9 fix: unduplicate the Unreleased changelog and record the missed entries
  • f703d90 fix: name GOSUMDB and GONOPROXY in the go build inputs, drop duplicate c
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-minor-patch group with 1 update: [github.com/maci0/toktop](https://github.com/maci0/toktop).


Updates `github.com/maci0/toktop` from 0.21.0 to 0.23.0
- [Release notes](https://github.com/maci0/toktop/releases)
- [Changelog](https://github.com/maci0/toktop/blob/main/CHANGELOG.md)
- [Commits](maci0/toktop@v0.21.0...v0.23.0)

---
updated-dependencies:
- dependency-name: github.com/maci0/toktop
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 3, 2026
@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 8f9f2adb-314a-46c7-9364-f8e811efc649

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants