-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): Bump the go_modules group with 12 updates #19
Open
dependabot
wants to merge
1
commit into
master
Choose a base branch
from
dependabot/go_modules/go_modules-3050203fac
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the go_modules group with 12 updates: | Package | From | To | | --- | --- | --- | | [github.com/docker/docker](https://github.com/docker/docker) | `24.0.6+incompatible` | `24.0.9+incompatible` | | [github.com/jackc/pgx/v4](https://github.com/jackc/pgx) | `4.18.1` | `4.18.2` | | [github.com/nats-io/nats-server/v2](https://github.com/nats-io/nats-server) | `2.9.9` | `2.9.23` | | [golang.org/x/crypto](https://github.com/golang/crypto) | `0.14.0` | `0.20.0` | | [golang.org/x/net](https://github.com/golang/net) | `0.17.0` | `0.21.0` | | google.golang.org/protobuf | `1.31.0` | `1.33.0` | | [github.com/cloudevents/sdk-go/v2](https://github.com/cloudevents/sdk-go) | `2.14.0` | `2.15.2` | | [github.com/containerd/containerd](https://github.com/containerd/containerd) | `1.7.6` | `1.7.11` | | [github.com/dvsekhvalnov/jose2go](https://github.com/dvsekhvalnov/jose2go) | `1.5.0` | `1.6.0` | | [github.com/jackc/pgproto3/v2](https://github.com/jackc/pgproto3) | `2.3.2` | `2.3.3` | | [github.com/nats-io/nkeys](https://github.com/nats-io/nkeys) | `0.4.5` | `0.4.6` | | [github.com/opencontainers/runc](https://github.com/opencontainers/runc) | `1.1.5` | `1.1.12` | Updates `github.com/docker/docker` from 24.0.6+incompatible to 24.0.9+incompatible - [Release notes](https://github.com/docker/docker/releases) - [Commits](moby/moby@v24.0.6...v24.0.9) Updates `github.com/jackc/pgx/v4` from 4.18.1 to 4.18.2 - [Changelog](https://github.com/jackc/pgx/blob/v4.18.2/CHANGELOG.md) - [Commits](jackc/pgx@v4.18.1...v4.18.2) Updates `github.com/nats-io/nats-server/v2` from 2.9.9 to 2.9.23 - [Release notes](https://github.com/nats-io/nats-server/releases) - [Changelog](https://github.com/nats-io/nats-server/blob/main/.goreleaser.yml) - [Commits](nats-io/nats-server@v2.9.9...v2.9.23) Updates `golang.org/x/crypto` from 0.14.0 to 0.20.0 - [Commits](golang/crypto@v0.14.0...v0.20.0) Updates `golang.org/x/net` from 0.17.0 to 0.21.0 - [Commits](golang/net@v0.17.0...v0.21.0) Updates `google.golang.org/protobuf` from 1.31.0 to 1.33.0 Updates `github.com/cloudevents/sdk-go/v2` from 2.14.0 to 2.15.2 - [Release notes](https://github.com/cloudevents/sdk-go/releases) - [Commits](cloudevents/sdk-go@v2.14.0...v2.15.2) Updates `github.com/containerd/containerd` from 1.7.6 to 1.7.11 - [Release notes](https://github.com/containerd/containerd/releases) - [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md) - [Commits](containerd/containerd@v1.7.6...v1.7.11) Updates `github.com/dvsekhvalnov/jose2go` from 1.5.0 to 1.6.0 - [Commits](dvsekhvalnov/jose2go@v1.5...v1.6.0) Updates `github.com/jackc/pgproto3/v2` from 2.3.2 to 2.3.3 - [Commits](jackc/pgproto3@v2.3.2...v2.3.3) Updates `github.com/nats-io/nkeys` from 0.4.5 to 0.4.6 - [Release notes](https://github.com/nats-io/nkeys/releases) - [Changelog](https://github.com/nats-io/nkeys/blob/main/.goreleaser.yml) - [Commits](nats-io/nkeys@v0.4.5...v0.4.6) Updates `github.com/opencontainers/runc` from 1.1.5 to 1.1.12 - [Release notes](https://github.com/opencontainers/runc/releases) - [Changelog](https://github.com/opencontainers/runc/blob/main/CHANGELOG.md) - [Commits](opencontainers/runc@v1.1.5...v1.1.12) --- updated-dependencies: - dependency-name: github.com/docker/docker dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/jackc/pgx/v4 dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/nats-io/nats-server/v2 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/crypto dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/net dependency-type: direct:production dependency-group: go_modules - dependency-name: google.golang.org/protobuf dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/cloudevents/sdk-go/v2 dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/containerd/containerd dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/dvsekhvalnov/jose2go dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/jackc/pgproto3/v2 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/nats-io/nkeys dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/opencontainers/runc dependency-type: indirect dependency-group: go_modules ... Signed-off-by: dependabot[bot] <[email protected]>
dependabot
bot
added
the
dependencies
Pull requests that update a dependency file
label
Apr 19, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the go_modules group with 12 updates:
24.0.6+incompatible
24.0.9+incompatible
4.18.1
4.18.2
2.9.9
2.9.23
0.14.0
0.20.0
0.17.0
0.21.0
1.31.0
1.33.0
2.14.0
2.15.2
1.7.6
1.7.11
1.5.0
1.6.0
2.3.2
2.3.3
0.4.5
0.4.6
1.1.5
1.1.12
Updates
github.com/docker/docker
from 24.0.6+incompatible to 24.0.9+incompatibleRelease notes
Sourced from github.com/docker/docker's releases.
... (truncated)
Commits
fca702d
Merge pull request from GHSA-xw73-rw38-6vjcf78a772
Merge pull request #47281 from thaJeztah/24.0_backport_bump_containerd_binary...61afffe
Merge pull request #47270 from thaJeztah/24.0_backport_bump_runc_binary_1.1.12b38e74c
Merge pull request #47276 from thaJeztah/24.0_backport_bump_runc_1.1.12dac5663
update containerd binary to v1.7.1320e1af3
vendor: github.com/opencontainers/runc v1.1.12858919d
update runc binary to v1.1.12141ad39
Merge pull request #47266 from vvoland/ci-fix-makeps1-templatefail-24db968c6
hack/make.ps1: Fix go list pattern61c51fb
Merge pull request #47221 from vvoland/pkg-pools-close-noop-24Updates
github.com/jackc/pgx/v4
from 4.18.1 to 4.18.2Changelog
Sourced from github.com/jackc/pgx/v4's changelog.
Commits
14690df
Update changelog779548e
Update required Go version to 1.1780e9662
Update github.com/jackc/pgconn to v1.14.30bf9ac3
Fix erroneous test casef94eb0e
Always wrap arguments in parentheses in the SQL sanitizer826a892
Fix SQL injection via line comment creation in simple protocol7d882f9
Fix *dbTx.Exec not checking if it is already closed1d07b8b
go mod tidyUpdates
github.com/nats-io/nats-server/v2
from 2.9.9 to 2.9.23Release notes
Sourced from github.com/nats-io/nats-server/v2's releases.
... (truncated)
Commits
45436e1
Release v2.9.23 (#4652)72ffa38
Release v2.9.2305fe77f
Backport #4592 to 2.9 (#4651)6a73e68
[2.9.x] Bump Travis Go version to 1.20.10 (#4650)8b981a2
Backports from v2.10 for v2.9.23 release (#4647)28eb7c0
Only setup auto no-auth for $G account iff no authorization block was defined.9f16edd
Make sure to not forward a message across a route for dq sub when we are a sp...0ac7895
Add in utility to detect and delete any NRG orphans.50722e9
When scaling a consumer down make sure to pop the loopAndForwardProposals go ...770cf2e
Backport JetStream benchmarks improvements to 2.9.x (#4644)Updates
golang.org/x/crypto
from 0.14.0 to 0.20.0Commits
0aab8d0
all: update go.mod x/net dependency5bead59
ocsp: don't use iota for externally defined constants1a86580
x/crypto/internal/poly1305: improve sum_ppc64le.s1c981e6
ssh/test: don't use DSA keys in integrations tests, update test RSA key62c9f17
x509roots/nss: manually exclude a confusingly constrained root405cb3b
go.mod: update golang.org/x dependencies913d3ae
x509roots/fallback: update bundledbb6ec1
ssh/test: skip tests on darwin that fail on the darwin-amd64-longtest LUCI bu...403f699
ssh/test: avoid leaking a net.UnixConn in server.TryDialWithAddr055043d
go.mod: update golang.org/x dependenciesUpdates
golang.org/x/net
from 0.17.0 to 0.21.0Commits
73d21fd
go.mod: update golang.org/x dependencies643fd16
html: fix SOLIDUS '/' handling in attribute parsing73e4b50
dns/dnsmessage: allow name compression for SRV resource parsingb2208d0
internal/quic/qlog: fix typo0d0b98c
http2: avoid goroutine starvation in TestServer_Push_RejectAfterGoAway07e05fd
http2: remove suspicious uint32->v conversion in frame code26b646e
quic: avoid deadlock in Endpoint.Closecb5b10f
go.mod: update golang.org/x dependencies689bbc7
quic: deflake TestStreamsCreateConcurrencyf12db26
internal/quic/cmd/interop: use wget --no-verbose in DockerfileUpdates
google.golang.org/protobuf
from 1.31.0 to 1.33.0Updates
github.com/cloudevents/sdk-go/v2
from 2.14.0 to 2.15.2Release notes
Sourced from github.com/cloudevents/sdk-go/v2's releases.
... (truncated)
Commits
de2f283
Merge pull request from GHSA-5pf6-2qwx-pxm2c5f8d9d
Update v2/protocol/http/protocol.goc17d949
Avoid modifying the DefaultClient's Transport67e3899
Merge pull request #1020 from duglin/oopsf0061e0
oops4cc6c2d
Merge pull request #1011 from cloudevents/dependabot/bundler/docs/bundler-sec...b6949b0
Bump the bundler group across 1 directories with 1 updatedf51395
Merge pull request #1016 from cloudevents/dependabot/github_actions/golangci/...1af6e06
Bump golangci/golangci-lint-action from 3 to 42574a05
Merge pull request #1013 from jafossum/fix-nats-typosUpdates
github.com/containerd/containerd
from 1.7.6 to 1.7.11Release notes
Sourced from github.com/containerd/containerd's releases.
... (truncated)
Changelog
Sourced from github.com/containerd/containerd's changelog.
... (truncated)
Commits
64b8a81
Merge pull request #9491 from dmcgowan/prepare-1.7.11ea5a477
Merge pull request #9352 from thaJeztah/1.7_update_golang_1.20.1167d356c
Merge pull request from GHSA-7ww5-4wqc-m92cdfae68b
Prepare release notes for v1.7.11de6d8a8
Merge pull request #9482 from ambarve/sn_cleanup_1.7ed7c689
Don't block snapshot garbage collection on Remove failures467de56
Merge pull request #9481 from ruiwen-zhao/cri-ud94f8ff
Merge pull request #9483 from dmcgowan/backport-1.7-fix-otel-http1fdefdd
Add warning for CRIU config usage8e06899
Merge pull request #9479 from ruiwen-zhao/cri-api-warningUpdates
github.com/dvsekhvalnov/jose2go
from 1.5.0 to 1.6.0Commits
48ba0b7
Merge pull request #32 from dvsekhvalnov/issue-31-security-tuning05eb007
docse0264a2
added helper matchers: Alg and Eng0f6c7c3
MatchAlg helpercf0a53b
docs2995762
docs9a18aff
docs675bb14
docs8e9e0d1
updated p2c limits with new OWASP numbers, docsed5dd96
Unit tests for custom 'p2c' headers min/max limitsUpdates
github.com/jackc/pgproto3/v2
from 2.3.2 to 2.3.3Commits
945c212
Backport fixes from pgx v5Updates
github.com/nats-io/nkeys
from 0.4.5 to 0.4.6Release notes
Sourced from github.com/nats-io/nkeys's releases.
Commits
62e5d8c
Merge pull request #60 from nats-io/0_4_6f63761b
[BUMP] release version and dependenciesd2e442e
Merge pull request #59 from nats-io/empty58fb9d6
Make sure to use byte slice to receive proper copy, otherwise empty public ke...Updates
github.com/opencontainers/runc
from 1.1.5 to 1.1.12Release notes
Sourced from github.com/opencontainers/runc's releases.
... (truncated)
Changelog
Sourced from github.com/opencontainers/runc's changelog.
... (truncated)
Commits
51d5e94
VERSION: release 1.1.122a4ed3e
merge 1.1-GHSA-xr7r-f8xq-vfvv into release-1.1e9665f4
init: don't special-case logrus fds683ad2f
libcontainer: mark all non-stdio fds O_CLOEXEC before spawning initb6633f4
cgroup: plug leaks of /sys/fs/cgroup handle284ba30
init: close internal fds before execvefbe3eed
setns init: do explicit lookup of execve argument early0994249
init: verify after chdir that cwd is inside the container506552a
Fix File to Close099ff69
merge #4177 into opencontainers/runc:release-1.1Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.