Bump the backend group with 7 updates #3544
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the backend group with 7 updates:
0.47.0
0.48.0
5.10.1
5.11.0
0.58.0
0.59.0
0.19.0
0.20.0
1.5.2
1.13.2
1.17.0
1.18.1
0.53.2
0.54.0
Updates
github.com/aquasecurity/trivy
from 0.47.0 to 0.48.0Release notes
Sourced from github.com/aquasecurity/trivy's releases.
... (truncated)
Commits
f2aa9bf
chore(deps): bump sigstore/cosign-installer from 4a861528be5e691840a69536975a...6d7e2f8
chore(deps): bump helm/chart-testing-action from 2.4.0 to 2.6.1 (#5694)0ff5f96
feat: filter k8s core components vuln results (#5713)a54d1e9
feat(vuln): remove duplicates in Fixed Version (#5596)99c04c4
feat(report): output plugin (#4863)70078b9
chore(deps): bump alpine from 3.18.4 to 3.18.5 (#5700)49e83a6
chore(deps): bump github.com/google/go-containerregistry from 0.16.1 to 0.17....af32cb3
chore(deps): bump github.com/go-git/go-git/v5 from 5.8.1 to 5.10.1 (#5699)1766271
chore(deps): bump actions/github-script from 6 to 7 (#5697)7ee8547
chore(deps): bump easimon/maximize-build-space from 8 to 9 (#5695)Updates
github.com/go-git/go-git/v5
from 5.10.1 to 5.11.0Release notes
Sourced from github.com/go-git/go-git/v5's releases.
Commits
5d08d3b
Merge pull request #958 from pjbgf/workval5bd1d8f
build: Ensure checkout is the first operationb2c1982
git: worktree, Align validation with upstream rulescec7da6
Merge pull request #953 from pjbgf/alternates8b47ceb
storage: filesystem, Add option to set a specific FS for alternates4f61489
Merge pull request #941 from djmoch/filestats-renameae552ce
Merge pull request #939 from dhoizner/fix-pull-after-shallowcc1895b
Merge pull request #950 from aymanbagabas/validate-refde1d5a5
git: validate reference namesd87110b
Merge pull request #948 from go-git/dependabot/go_modules/cli/go-git/github.c...Updates
github.com/open-policy-agent/opa
from 0.58.0 to 0.59.0Release notes
Sourced from github.com/open-policy-agent/opa's releases.
... (truncated)
Changelog
Sourced from github.com/open-policy-agent/opa's changelog.
... (truncated)
Commits
c8e7863
Prepare v0.59.0 release (#6447)7927156
docs: Update generated CLI docs8497550
Adding--rego-v1
flag tocheck
cmd (#6430)26a02e4
docs: Update generated CLI docs187d688
cmd & format: Adding rego-v1 mode toopa fmt
(#6413)4f9058b
update istio envoy tutorial to use AuthorizationPolicy7a32e8f
topdown/crypto: Add URIStrings field to JSON certs8194a22
Fixed XACML Policy in documentation (Comparing to Other Systems) to be XACML ...0b9bbc5
plugins/rest: masks X-AMZ-SECURITY-TOKEN header in decision logs (#6423)f66f7e0
build(deps): bump golang.org/x/net from 0.18.0 to 0.19.0 (#6441)Updates
github.com/operator-framework/api
from 0.19.0 to 0.20.0Release notes
Sourced from github.com/operator-framework/api's releases.
Commits
5efe1a2
Replacegithub.com/ghodss/yaml
withsigs.k8s.io/yaml
(#308)047dce1
Add additional deprecation types for each level (package, channel, bundle). (...6b3567d
Adds 'OperatorDeprecated' status condition for Subscription. (#306)3417188
OWNERS: Remove timflannagan from reviewers (#305)Updates
github.com/sigstore/cosign
from 1.5.2 to 1.13.2Release notes
Sourced from github.com/sigstore/cosign's releases.
... (truncated)
Changelog
Sourced from github.com/sigstore/cosign's changelog.
... (truncated)
Commits
ea92927
Backport GHSA-vfp6-jrw2-99g9 (#3364)d862088
update builder image that uses go 1.19.4 (#2521)43bde0e
update ci to run jobs in the 1.0-fork branch (#2408)9a2ea28
chore(deps): bump mikefarah/yq from 4.28.2 to 4.29.2 (#2392)97625ff
chore(deps): bump github.com/xanzy/go-gitlab from 0.73.1 to 0.74.0 (#2391)ca0959a
verify: remove SIGSTORE_TRUST_REKOR_API_PUBLIC_KEY test env var for using a k...b603117
Refactor sign command (#2388)c3c4ea9
chore(deps): bump github/codeql-action from 2.1.28 to 2.1.29 (#2386)f0b2074
chore(deps): bump google.golang.org/api from 0.100.0 to 0.101.0 (#2385)ab7370b
chore(deps): bump github.com/spf13/cobra from 1.6.0 to 1.6.1 (#2381)Updates
github.com/spf13/viper
from 1.17.0 to 1.18.1Release notes
Sourced from github.com/spf13/viper's releases.
... (truncated)
Commits
fb6eb1e
fix: merge missing struct keys inside UnmarshalExactf5fcb4a
chore: update cryptf736363
fix isPathShadowedInFlatMap type cast bug (#1585)36a3868
Review changesf0c4ccd
fix: gocritic lint issues3a23b80
ci: enable test shuffle; fix tests73dfb94
feat: make Unmarshal work with AutomaticEnv6ea31ae
refactor: move all settings code to a getterc4dcd31
fix: godot lint issues4c9b2a2
Note Get* behavior on parse failureUpdates
github.com/tektoncd/pipeline
from 0.53.2 to 0.54.0Release notes
Sourced from github.com/tektoncd/pipeline's releases.
... (truncated)
Changelog
Sourced from github.com/tektoncd/pipeline's changelog.
... (truncated)
Commits
30540fc
TEP-0142: Surface step results via sidecar logsb395663
TEP-0142: Surface step results via termination message8a8c0c3
[TEP-0144] Validate PipelineRun for Param Enum140b633
TEP-0142: Introduce StepResults in Steps9f5449c
fix: move getFeatureFlagsBaseOnAPIFlag from custom_task_test to another file5e7b5bb
Bump k8s.io/client-go in /test/custom-task-ctrls/wait-task-beta4054026
Improve migration documentation4e4772e
Cleanup v1beta1 reference in pipelinerun reconciler23581c5
fix: the pr may lose finallyStartTime when pipeline controller is not synchro...a8bbefe
Bump github.com/spiffe/spire-api-sdk from 1.8.1 to 1.8.4Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependencyDescription has been truncated