-
Notifications
You must be signed in to change notification settings - Fork 237
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump the backend group with 11 updates #3417
Closed
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
dependabot
bot
added
dependencies
Pull requests that update a dependency file
go
Pull requests that update Go code
labels
Oct 16, 2023
This was referenced Oct 16, 2023
Bumps the backend group with 11 updates: | Package | From | To | | --- | --- | --- | | [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy) | `0.42.1` | `0.46.0` | | [github.com/hashicorp/golang-lru/v2](https://github.com/hashicorp/golang-lru) | `2.0.6` | `2.0.7` | | [github.com/operator-framework/api](https://github.com/operator-framework/api) | `0.17.5` | `0.17.7` | | [github.com/prometheus/client_golang](https://github.com/prometheus/client_golang) | `1.16.0` | `1.17.0` | | [github.com/rs/cors](https://github.com/rs/cors) | `1.10.0` | `1.10.1` | | [github.com/sigstore/cosign](https://github.com/sigstore/cosign) | `1.5.2` | `1.13.1` | | [github.com/spf13/viper](https://github.com/spf13/viper) | `1.16.0` | `1.17.0` | | [github.com/tektoncd/pipeline](https://github.com/tektoncd/pipeline) | `0.31.4` | `0.52.1` | | [golang.org/x/oauth2](https://github.com/golang/oauth2) | `0.12.0` | `0.13.0` | | [google.golang.org/api](https://github.com/googleapis/google-api-go-client) | `0.143.0` | `0.147.0` | | [helm.sh/helm/v3](https://github.com/helm/helm) | `3.12.3` | `3.13.1` | Updates `github.com/aquasecurity/trivy` from 0.42.1 to 0.46.0 - [Release notes](https://github.com/aquasecurity/trivy/releases) - [Changelog](https://github.com/aquasecurity/trivy/blob/main/goreleaser.yml) - [Commits](aquasecurity/trivy@v0.42.1...v0.46.0) Updates `github.com/hashicorp/golang-lru/v2` from 2.0.6 to 2.0.7 - [Release notes](https://github.com/hashicorp/golang-lru/releases) - [Commits](hashicorp/golang-lru@v2.0.6...v2.0.7) Updates `github.com/operator-framework/api` from 0.17.5 to 0.17.7 - [Release notes](https://github.com/operator-framework/api/releases) - [Changelog](https://github.com/operator-framework/api/blob/master/RELEASE.md) - [Commits](operator-framework/api@v0.17.5...v0.17.7) Updates `github.com/prometheus/client_golang` from 1.16.0 to 1.17.0 - [Release notes](https://github.com/prometheus/client_golang/releases) - [Changelog](https://github.com/prometheus/client_golang/blob/main/CHANGELOG.md) - [Commits](prometheus/client_golang@v1.16.0...v1.17.0) Updates `github.com/rs/cors` from 1.10.0 to 1.10.1 - [Release notes](https://github.com/rs/cors/releases) - [Commits](rs/cors@v1.10.0...v1.10.1) Updates `github.com/sigstore/cosign` from 1.5.2 to 1.13.1 - [Release notes](https://github.com/sigstore/cosign/releases) - [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md) - [Commits](sigstore/cosign@v1.5.2...v1.13.1) Updates `github.com/spf13/viper` from 1.16.0 to 1.17.0 - [Release notes](https://github.com/spf13/viper/releases) - [Commits](spf13/viper@v1.16.0...v1.17.0) Updates `github.com/tektoncd/pipeline` from 0.31.4 to 0.52.1 - [Release notes](https://github.com/tektoncd/pipeline/releases) - [Changelog](https://github.com/tektoncd/pipeline/blob/main/releases.md) - [Commits](tektoncd/pipeline@v0.31.4...v0.52.1) Updates `golang.org/x/oauth2` from 0.12.0 to 0.13.0 - [Commits](golang/oauth2@v0.12.0...v0.13.0) Updates `google.golang.org/api` from 0.143.0 to 0.147.0 - [Release notes](https://github.com/googleapis/google-api-go-client/releases) - [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md) - [Commits](googleapis/google-api-go-client@v0.143.0...v0.147.0) Updates `helm.sh/helm/v3` from 3.12.3 to 3.13.1 - [Release notes](https://github.com/helm/helm/releases) - [Commits](helm/helm@v3.12.3...v3.13.1) --- updated-dependencies: - dependency-name: github.com/aquasecurity/trivy dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend - dependency-name: github.com/hashicorp/golang-lru/v2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: backend - dependency-name: github.com/operator-framework/api dependency-type: direct:production update-type: version-update:semver-patch dependency-group: backend - dependency-name: github.com/prometheus/client_golang dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend - dependency-name: github.com/rs/cors dependency-type: direct:production update-type: version-update:semver-patch dependency-group: backend - dependency-name: github.com/sigstore/cosign dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend - dependency-name: github.com/spf13/viper dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend - dependency-name: github.com/tektoncd/pipeline dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend - dependency-name: golang.org/x/oauth2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend - dependency-name: google.golang.org/api dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend - dependency-name: helm.sh/helm/v3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend ... Signed-off-by: dependabot[bot] <[email protected]>
dependabot
bot
force-pushed
the
dependabot/go_modules/backend-2c51a1f627
branch
from
October 17, 2023 08:51
bb426ff
to
fa41698
Compare
Looks like these dependencies are up-to-date now, so this is no longer needed. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the backend group with 11 updates:
0.42.1
0.46.0
2.0.6
2.0.7
0.17.5
0.17.7
1.16.0
1.17.0
1.10.0
1.10.1
1.5.2
1.13.1
1.16.0
1.17.0
0.31.4
0.52.1
0.12.0
0.13.0
0.143.0
0.147.0
3.12.3
3.13.1
Updates
github.com/aquasecurity/trivy
from 0.42.1 to 0.46.0Release notes
Sourced from github.com/aquasecurity/trivy's releases.
... (truncated)
Commits
cbbd1ce
feat(k8s): add support for vulnerability detection (#5268)24a0d92
fix(python): override BOM inrequirements.txt
files (#5375)0c3e2f0
docs: add kbom documentation (#5363)6c12f04
test: use maximize build space for VM tests (#5362)c413422
chore(deps): bump golang.org/x/net from 0.15.0 to 0.17.0 (#5365)20ab703
fix(report): add escaping quotes in misconfig Title for asff template (#5351)91841f5
ci: add workflow to check Go versions of dependencies (#5340)57ba05c
chore(deps): Upgrade defsec to v0.93.1 (#5348)fef3ed4
chore(deps): bump alpine from 3.18.3 to 3.18.4 (#5300)ced54ac
fix: Report error when os.CreateTemp fails (to be consistent with other uses)...Updates
github.com/hashicorp/golang-lru/v2
from 2.0.6 to 2.0.7Release notes
Sourced from github.com/hashicorp/golang-lru/v2's releases.
Commits
d851586
add a Resize method to 2Qd46c1d9
expirable LRU: fix so that Get/Peek cannot return an ok and empty value (#156)56a2dc0
Update arc to base package v2.0.6Updates
github.com/operator-framework/api
from 0.17.5 to 0.17.7Release notes
Sourced from github.com/operator-framework/api's releases.
Commits
92e4341
Makes codecov-action optionalfdfcb35
Fix min kube version validation (#286)bbac502
Adds codecov integration (#285)aa3e498
updating dependencies (#284)ce75af3
Merge pull request #279 from Jamstah/catalog-source-affinity45ebd8b
Add affinity customization to catalog source grpc podsUpdates
github.com/prometheus/client_golang
from 1.16.0 to 1.17.0Release notes
Sourced from github.com/prometheus/client_golang's releases.
... (truncated)
Changelog
Sourced from github.com/prometheus/client_golang's changelog.
Commits
fa1408e
Merge pull request #1352 from prometheus/arthursens/cut-1.17.024a72b8
Add changelog entry for 1.171bae6c1
Deprecated comment should begin with "Deprecated:" (#1347)bbab8fe
Fix typos in comments, tests, and errors (#1346)df7fa49
Extend Counters, Summaries and Histograms with creation timestamp (#1313)74cc262
Add go_godebug_non_default_behavior_tlsmaxrsasize_events_total (#1348)d03abf3
Cleanup golangci-lint errcheck (#1339)ca6ba04
Update common Prometheus files (#1338)51d24f8
Update common Prometheus files (#1332)c17edf0
Merge pull request #1304 from prometheus/dependabot/go_modules/google.golang....Updates
github.com/rs/cors
from 1.10.0 to 1.10.1Commits
e19471c
Prevent empty Access-Control-Expose-Headers header (#160)20a76bd
Update benchmarkUpdates
github.com/sigstore/cosign
from 1.5.2 to 1.13.1Release notes
Sourced from github.com/sigstore/cosign's releases.
... (truncated)
Changelog
Sourced from github.com/sigstore/cosign's changelog.
... (truncated)
Commits
d1c6336
Add CHANGELOG for v1.13.1 (#2349)e79cb5c
chore(deps): bump github.com/spf13/cobra from 1.5.0 to 1.6.0 (#2326)eba132f
chore(deps): bump github.com/go-openapi/runtime from 0.24.1 to 0.24.2 (#2347)2860144
chore(deps): bump google.golang.org/api from 0.98.0 to 0.99.0 (#2348)ef9cf9d
chore(deps): bump google-github-actions/setup-gcloud from 0.6.1 to 0.6.2 (#2344)fc83e43
chore(deps): bump google-github-actions/auth from 0.8.2 to 0.8.3 (#2343)e652561
chore(deps): bump google-github-actions/setup-gcloud from 0.6.0 to 0.6.1 (#2340)d637a3b
verify-blob-attestation: allow multiple subjects in in_toto attestation (#2341)a7ad7e7
Nits for #2337 (#2342)797033c
Add verify-blob-attestation command and tests (#2337)Updates
github.com/spf13/viper
from 1.16.0 to 1.17.0Release notes
Sourced from github.com/spf13/viper's releases.
... (truncated)
Commits
f62f86a
refactor: make use ofstrings.Cut
94632fa
chore: Use pip3 explicitly to install yamllint3f6cadc
chore: Fix copy-paste error for yamllint target287507c
docs: add set subset KV examplef1cb226
chore(deps): update cryptc292b55
test: refactor asserts3d006fe
refactor: replace interface{} with any8a6dc5d
build(deps): bump github/codeql-action from 2.21.8 to 2.21.996c5c00
chore: remove deprecated build tags44911d2
build(deps): bump github/codeql-action from 2.21.7 to 2.21.8Updates
github.com/tektoncd/pipeline
from 0.31.4 to 0.52.1Release notes
Sourced from github.com/tektoncd/pipeline's releases.
... (truncated)
Changelog
Sourced from github.com/tektoncd/pipeline's changelog.
... (truncated)
Commits
e7b5e58
Regression: fix results with out of order tasksfeb943c
Bump github.com/jenkins-x/go-scm from 1.13.13 to 1.14.146364191
fix: clean results when taskrun retries503cc3d
Bump google.golang.org/grpc from 1.56.2 to 1.58.13076240
fix 6093 task results not replaced with their values in childReferences3835c75
Bump github.com/sigstore/sigstore from 1.7.1 to 1.7.3a41fafe
Bump github.com/spiffe/spire-api-sdk from 1.7.1 to 1.7.244e1707
Bump github.com/containerd/containerd from 1.7.3 to 1.7.6d783556
Remove results annotations filteringf27f333
Bump google.golang.org/protobuf from 1.30.0 to 1.31.0Updates
golang.org/x/oauth2
from 0.12.0 to 0.13.0Commits
3c5dbf0
go.mod: update golang.org/x dependencies11625cc
google: add authorized_user conditional to Credentials.UniverseDomain8d6d45b
google: add Credentials.UniverseDomain to support TPC43b6a7b
google: adding support for external account authorized user14b275c
oauth2: workaround misspelling of verification_uri18352fc
google/internal/externalaccount: adding BYOID Metrics9095a51
oauth2: clarify error if endpoint missing DeviceAuthURL2d9e4a2
oauth2/google: remove meta validations for aws external credentials55cd552
oauth2: support PKCEe3fb0fb
oauth2: support device flowUpdates
google.golang.org/api
from 0.143.0 to 0.147.0Release notes
Sourced from google.golang.org/api's releases.