This repository was archived by the owner on Dec 2, 2025. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 1
chore(deps): bump the go_modules group with 9 updates #189
Closed
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the go_modules group with 9 updates: | Package | From | To | | --- | --- | --- | | [github.com/containers/image/v5](https://github.com/containers/image) | `5.29.2` | `5.29.3` | | [github.com/docker/docker](https://github.com/docker/docker) | `24.0.7+incompatible` | `25.0.6+incompatible` | | [github.com/golang-jwt/jwt/v4](https://github.com/golang-jwt/jwt) | `4.5.0` | `4.5.1` | | [github.com/hashicorp/go-retryablehttp](https://github.com/hashicorp/go-retryablehttp) | `0.7.5` | `0.7.7` | | [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) | `2.2.3` | `2.2.4` | | [golang.org/x/crypto](https://github.com/golang/crypto) | `0.19.0` | `0.22.0` | | [golang.org/x/net](https://github.com/golang/net) | `0.20.0` | `0.22.0` | | google.golang.org/protobuf | `1.32.0` | `1.33.0` | | [helm.sh/helm/v3](https://github.com/helm/helm) | `3.14.2` | `3.14.3` | Updates `github.com/containers/image/v5` from 5.29.2 to 5.29.3 - [Release notes](https://github.com/containers/image/releases) - [Commits](containers/image@v5.29.2...v5.29.3) Updates `github.com/docker/docker` from 24.0.7+incompatible to 25.0.6+incompatible - [Release notes](https://github.com/docker/docker/releases) - [Commits](moby/moby@v24.0.7...v25.0.6) Updates `github.com/golang-jwt/jwt/v4` from 4.5.0 to 4.5.1 - [Release notes](https://github.com/golang-jwt/jwt/releases) - [Changelog](https://github.com/golang-jwt/jwt/blob/main/VERSION_HISTORY.md) - [Commits](golang-jwt/jwt@v4.5.0...v4.5.1) Updates `github.com/hashicorp/go-retryablehttp` from 0.7.5 to 0.7.7 - [Changelog](https://github.com/hashicorp/go-retryablehttp/blob/main/CHANGELOG.md) - [Commits](hashicorp/go-retryablehttp@v0.7.5...v0.7.7) Updates `github.com/sigstore/cosign/v2` from 2.2.3 to 2.2.4 - [Release notes](https://github.com/sigstore/cosign/releases) - [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md) - [Commits](sigstore/cosign@v2.2.3...v2.2.4) Updates `golang.org/x/crypto` from 0.19.0 to 0.22.0 - [Commits](golang/crypto@v0.19.0...v0.22.0) Updates `golang.org/x/net` from 0.20.0 to 0.22.0 - [Commits](golang/net@v0.20.0...v0.22.0) Updates `google.golang.org/protobuf` from 1.32.0 to 1.33.0 Updates `helm.sh/helm/v3` from 3.14.2 to 3.14.3 - [Release notes](https://github.com/helm/helm/releases) - [Commits](helm/helm@v3.14.2...v3.14.3) --- updated-dependencies: - dependency-name: github.com/containers/image/v5 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/docker/docker dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/golang-jwt/jwt/v4 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/hashicorp/go-retryablehttp dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/sigstore/cosign/v2 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/crypto dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/net dependency-type: indirect dependency-group: go_modules - dependency-name: google.golang.org/protobuf dependency-type: indirect dependency-group: go_modules - dependency-name: helm.sh/helm/v3 dependency-type: indirect dependency-group: go_modules ... Signed-off-by: dependabot[bot] <support@github.com>
Mend Scan Summary: ❌Repository: open-component-model/replication-controller
|
hilmarf
previously approved these changes
Feb 6, 2025
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the go_modules group with 9 updates:
5.29.25.29.324.0.7+incompatible25.0.6+incompatible4.5.04.5.10.7.50.7.72.2.32.2.40.19.00.22.00.20.00.22.01.32.01.33.03.14.23.14.3Updates
github.com/containers/image/v5from 5.29.2 to 5.29.3Release notes
Sourced from github.com/containers/image/v5's releases.
Commits
3e684b1[release-5.29] Bump to v5.29.3e894804Merge pull request #2418 from mtrmac/digest-unmarshal-5.296e25805Validate the tags returned by a registry086c760Call .Validate() before digest.Digest.String() if necessary0860c58Refactor the error handling further7b58b43Refactor the error handling path of saveStreamaf94ba1Call .Validate() before digest.Hex() / digest.Encoded()9c49ca1Validate digests before using them534068fMerge pull request #2270 from TomSweeneyRedHat/dev/tsweeney/ddaemon0111e79[release-5.29] Bump to v5.29.3-devUpdates
github.com/docker/dockerfrom 24.0.7+incompatible to 25.0.6+incompatibleRelease notes
Sourced from github.com/docker/docker's releases.
... (truncated)
Commits
b08a51fMerge pull request #48231 from austinvazquez/backport-vendor-otel-v0.46.1-to-...d151b0fvendor: OTEL v0.46.1 / v1.21.0c6ba9a5Merge pull request #48225 from austinvazquez/backport-workflow-artifact-reten...4673a3cMerge pull request #48227 from austinvazquez/backport-backport-branch-check-t...30f8908github/ci: Check if backport is opened against the expected branch7454d6aci: update workflow artifacts retention65cc597Merge commit from forkb722836Merge pull request #48199 from austinvazquez/update-containerd-binary-to-1.7.20e8ecb9cupdate containerd binary to v1.7.20e6cae1fupdate containerd binary to v1.7.19Updates
github.com/golang-jwt/jwt/v4from 4.5.0 to 4.5.1Release notes
Sourced from github.com/golang-jwt/jwt/v4's releases.
Commits
7b1c1c0Merge commit from forkUpdates
github.com/hashicorp/go-retryablehttpfrom 0.7.5 to 0.7.7Changelog
Sourced from github.com/hashicorp/go-retryablehttp's changelog.
Commits
1542b31v0.7.7defb9f4v0.7.7a99f07bMerge pull request #158 from dany74q/danny/redacted-url-in-logs8a28c57Merge branch 'main' into danny/redacted-url-in-logs86e852dMerge pull request #227 from hashicorp/dependabot/github_actions/actions/chec...47fe99eBump actions/checkout from 4.1.5 to 4.1.6490fc06Merge pull request #226 from testwill/ioutilf3e9417chore: remove refs to deprecated io/ioutild969eaaMerge pull request #225 from hashicorp/manicminer-patch-22ad8ed4v0.7.6Updates
github.com/sigstore/cosign/v2from 2.2.3 to 2.2.4Release notes
Sourced from github.com/sigstore/cosign/v2's releases.
Changelog
Sourced from github.com/sigstore/cosign/v2's changelog.
Commits
fb651b4Add v2.2.4 changelog (#3662)629f5f8Fixes for GHSA-88jx-383q-w4qc and GHSA-95pr-fxf5-86gv (#3661)302aee6Refactor e2e-tests.yml workflow (#3627)d0b9861chore(deps): bump golang.org/x/crypto from 0.21.0 to 0.22.0 (#3649)c95439bchore(deps): bump github.com/spiffe/go-spiffe/v2 from 2.1.7 to 2.2.0 (#3653)430c985chore(deps): bump golang.org/x/sync from 0.6.0 to 0.7.0 (#3655)48858a2chore(deps): bump github.com/xanzy/go-gitlab from 0.101.0 to 0.102.0 (#3652)eba7c59chore(deps): bump golang.org/x/term from 0.18.0 to 0.19.0 (#3651)2d13b65chore(deps): bump golang.org/x/oauth2 from 0.18.0 to 0.19.0 (#3650)d56c9e8chore(deps): bump the gomod group with 3 updates (#3648)Updates
golang.org/x/cryptofrom 0.19.0 to 0.22.0Commits
d042a39go.mod: update golang.org/x dependenciesb92bf94ssh: respect MaxAuthTries also for "none" auth attempts6f79b5assh: add server side multi-step authentication8d0d405x/crypto/chacha20: cleanup chacha_ppc64le.sb91329dall: remove redundant words in comments and fix some typos7067223go.mod: update golang.org/x dependencies0d2316bssh/test: work around for TestCiphers failures on macOS0aab8d0all: update go.mod x/net dependency5bead59ocsp: don't use iota for externally defined constants1a86580x/crypto/internal/poly1305: improve sum_ppc64le.sUpdates
golang.org/x/netfrom 0.20.0 to 0.22.0Commits
7ee34a0go.mod: update golang.org/x dependenciesc289c7awebsocket: re-add documentation for DialConfig9fb4a8chttp2: send an error of FLOW_CONTROL_ERROR when exceed the maximum octets3dfd003websocket: add support for dialing with contextfa11427quic: move package out of internal591be7fquic: fix UDP on big-endian Linux, tests on various architectures34cc446quic: temporarily disable networking tests failing on various platforms4bdc6dfquic: expand package docs, and document Stream22cbde9quic: set ServerName in client connection TLSConfig57e4cc7quic: handle PATH_CHALLENGE and PATH_RESPONSE framesUpdates
google.golang.org/protobuffrom 1.32.0 to 1.33.0Updates
helm.sh/helm/v3from 3.14.2 to 3.14.3Release notes
Sourced from helm.sh/helm/v3's releases.
Commits
f03cc04Add a note about --dry-run displaying secrets1a7330fadd error messagesd6acc00Fix: Ignore alias validation error for index loadb2738fbchore(deps): bump github.com/containerd/containerd from 1.7.11 to 1.7.125b0847echore(deps): bump github.com/DATA-DOG/go-sqlmock from 1.5.0 to 1.5.27e18c39Update architecture detection methodDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.