build(deps): bump the go-deps group across 1 directory with 8 updates #1506
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the go-deps group with 7 updates in the / directory:
0.2.4
0.2.5
7.0.70
7.0.71
1.0.2
1.0.3
1.1.0
1.1.1
1.19.0
1.19.1
1.8.3
1.8.4
0.177.0
0.183.0
Updates
github.com/cyphar/filepath-securejoin
from 0.2.4 to 0.2.5Release notes
Sourced from github.com/cyphar/filepath-securejoin's releases.
Commits
d861a11
VERSION: release v0.2.587bc53a
join: fix ELOOP error pathe9be397
join: don't allow .. and . in working path during resolution75cdbea
gha: update Go versionsb69b737
VERSION: back to developmentUpdates
github.com/minio/minio-go/v7
from 7.0.70 to 7.0.71Release notes
Sourced from github.com/minio/minio-go/v7's releases.
Commits
14b3aa6
Add ListMultipartUploads mint tests (#1963)7d712b5
feat: support tags for postPolicy Upload (#1967)95db455
Add support for DelMarkerExpiration element (#1959)88c389d
Update version to next releaseUpdates
github.com/notaryproject/notation-core-go
from 1.0.2 to 1.0.3Release notes
Sourced from github.com/notaryproject/notation-core-go's releases.
Commits
4211b09
build(deps): bump golang.org/x/crypto from 0.22.0 to 0.23.0 (#204)6f8b75c
build(deps): bump actions/stale from 8 to 9 (#195)ff5e5b8
build(deps): bump apache/skywalking-eyes from a790ab8dd23a7f861c18bd6aaa9b012...f624dfd
build(deps): bump golang.org/x/crypto from 0.21.0 to 0.22.0 (#200)356b30e
fix: leaf certificate validation (#202)9f13c9e
fix(ci): update codecov token (#199)66ff8c2
chore: org maintainers update (#196)807a338
bump: bump up golang version to v1.21 (#194)9a2ff9e
chore: add GitHub action for stale issues and PRs (#174)93218d9
build(deps): bump golang.org/x/crypto from 0.18.0 to 0.21.0 (#193)Updates
github.com/notaryproject/notation-go
from 1.1.0 to 1.1.1Release notes
Sourced from github.com/notaryproject/notation-go's releases.
Commits
94a0e13
revert: "feat: add support for signing blob (#379)" (#411)1a5b3e3
ci: enable ci for release branch (#409)254dfcd
bump: bump up notation-core-go v1.0.3 (#407)b7fde51
fix: error message for dangling reference index (#402)b8508d0
test: improve test coverage to 80% (#405)5e98995
build(deps): bump golang.org/x/crypto from 0.22.0 to 0.23.0 (#403)378ee83
build(deps): bump golang.org/x/crypto from 0.21.0 to 0.22.0 (#396)a901939
build(deps): bump github.com/go-ldap/ldap/v3 from 3.4.7 to 3.4.8 (#399)97a5a86
build(deps): bump github.com/go-ldap/ldap/v3 from 3.4.6 to 3.4.7 (#395)442ece7
build(deps): bump golang.org/x/mod from 0.16.0 to 0.17.0 (#397)Updates
github.com/prometheus/client_golang
from 1.19.0 to 1.19.1Release notes
Sourced from github.com/prometheus/client_golang's releases.
Changelog
Sourced from github.com/prometheus/client_golang's changelog.
Commits
6e3f4b1
Cut 1.19.1 (#1494)cad1bfa
Merge pull request #1454 from prometheus/small-nits0aa8c9f
Rephrase incompatibility with common v0.48.0Updates
github.com/sigstore/sigstore
from 1.8.3 to 1.8.4Release notes
Sourced from github.com/sigstore/sigstore's releases.
Commits
5cd937f
build(deps): Bump github.com/hashicorp/vault/api96fc144
build(deps): Bump the all group in /pkg/signature/kms/gcp with 2 updates2b99005
build(deps): Bump the all group in /pkg/signature/kms/aws with 3 updatesfa5d64b
sync go mod186a1e5
build(deps): Bump the all group across 1 directory with 4 updates1ba2030
Fix Hashicorp Vault KMS to use PKCS1 v1.5ec88c0b
---bbe51a7
---1d8a874
---acb4db4
build(deps): Bump golangci/golangci-lint-action from 5.3.0 to 6.0.1Updates
golang.org/x/crypto
from 0.22.0 to 0.23.0Commits
905d78a
go.mod: update golang.org/x dependenciesebb717d
ssh: validate key type in SSH_MSG_USERAUTH_PK_OK response0da2a6a
openpgp: fix function name in comment5defcc1
sha3: fix Sum results for SHAKE functions on s390xUpdates
google.golang.org/api
from 0.177.0 to 0.183.0Release notes
Sourced from google.golang.org/api's releases.
... (truncated)
Changelog
Sourced from google.golang.org/api's changelog.
... (truncated)
Commits
c642c84
chore(main): release 0.183.0 (#2615)305d137
chore(all): update all (#2618)0077748
feat(all): auto-regenerate discovery clients (#2622)c7f1614
feat(all): auto-regenerate discovery clients (#2619)08fdd71
feat(all): auto-regenerate discovery clients (#2617)5f21214
feat(all): auto-regenerate discovery clients (#2616)1de148b
feat(all): auto-regenerate discovery clients (#2611)4f98211
fix: add another temporary dep on genproto (#2614)b49e3b9
chore(main): release 0.182.0 (#2591)b6f615b
chore(all): update all (#2607)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions