Bump the "backend" group with 1 update across multiple ecosystems#4762
Open
dependabot[bot] wants to merge 1 commit intomasterfrom
Open
Bump the "backend" group with 1 update across multiple ecosystems#4762dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps the backend group with 12 updates: | Package | From | To | | --- | --- | --- | | [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy) | `0.69.3` | `0.69.4` | | [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) | `5.17.0` | `5.17.2` | | [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry) | `0.21.2` | `0.21.3` | | [github.com/open-policy-agent/opa](https://github.com/open-policy-agent/opa) | `1.14.0` | `1.15.1` | | [github.com/operator-framework/api](https://github.com/operator-framework/api) | `0.41.0` | `0.42.0` | | [github.com/rs/zerolog](https://github.com/rs/zerolog) | `1.34.0` | `1.35.0` | | [github.com/tektoncd/pipeline](https://github.com/tektoncd/pipeline) | `1.10.0` | `1.11.0` | | [golang.org/x/crypto](https://github.com/golang/crypto) | `0.48.0` | `0.49.0` | | [golang.org/x/oauth2](https://github.com/golang/oauth2) | `0.35.0` | `0.36.0` | | [golang.org/x/text](https://github.com/golang/text) | `0.34.0` | `0.35.0` | | [google.golang.org/api](https://github.com/googleapis/google-api-go-client) | `0.269.0` | `0.273.1` | | [helm.sh/helm/v3](https://github.com/helm/helm) | `3.20.0` | `3.20.1` | Updates `github.com/aquasecurity/trivy` from 0.69.3 to 0.69.4 - [Release notes](https://github.com/aquasecurity/trivy/releases) - [Changelog](https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md) - [Commits](https://github.com/aquasecurity/trivy/commits) Updates `github.com/go-git/go-git/v5` from 5.17.0 to 5.17.2 - [Release notes](https://github.com/go-git/go-git/releases) - [Commits](go-git/go-git@v5.17.0...v5.17.2) Updates `github.com/google/go-containerregistry` from 0.21.2 to 0.21.3 - [Release notes](https://github.com/google/go-containerregistry/releases) - [Commits](google/go-containerregistry@v0.21.2...v0.21.3) Updates `github.com/open-policy-agent/opa` from 1.14.0 to 1.15.1 - [Release notes](https://github.com/open-policy-agent/opa/releases) - [Changelog](https://github.com/open-policy-agent/opa/blob/main/CHANGELOG.md) - [Commits](open-policy-agent/opa@v1.14.0...v1.15.1) Updates `github.com/operator-framework/api` from 0.41.0 to 0.42.0 - [Release notes](https://github.com/operator-framework/api/releases) - [Changelog](https://github.com/operator-framework/api/blob/master/RELEASE.md) - [Commits](operator-framework/api@v0.41.0...v0.42.0) Updates `github.com/rs/zerolog` from 1.34.0 to 1.35.0 - [Commits](rs/zerolog@v1.34.0...v1.35.0) Updates `github.com/tektoncd/pipeline` from 1.10.0 to 1.11.0 - [Release notes](https://github.com/tektoncd/pipeline/releases) - [Changelog](https://github.com/tektoncd/pipeline/blob/main/releases.md) - [Commits](tektoncd/pipeline@v1.10.0...v1.11.0) Updates `golang.org/x/crypto` from 0.48.0 to 0.49.0 - [Commits](golang/crypto@v0.48.0...v0.49.0) Updates `golang.org/x/oauth2` from 0.35.0 to 0.36.0 - [Commits](golang/oauth2@v0.35.0...v0.36.0) Updates `golang.org/x/text` from 0.34.0 to 0.35.0 - [Release notes](https://github.com/golang/text/releases) - [Commits](golang/text@v0.34.0...v0.35.0) Updates `google.golang.org/api` from 0.269.0 to 0.273.1 - [Release notes](https://github.com/googleapis/google-api-go-client/releases) - [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md) - [Commits](googleapis/google-api-go-client@v0.269.0...v0.273.1) Updates `helm.sh/helm/v3` from 3.20.0 to 3.20.1 - [Release notes](https://github.com/helm/helm/releases) - [Commits](helm/helm@v3.20.0...v3.20.1) --- updated-dependencies: - dependency-name: github.com/aquasecurity/trivy dependency-version: 0.69.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: backend - dependency-name: github.com/go-git/go-git/v5 dependency-version: 5.17.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: backend - dependency-name: github.com/google/go-containerregistry dependency-version: 0.21.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: backend - dependency-name: github.com/open-policy-agent/opa dependency-version: 1.15.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend - dependency-name: github.com/operator-framework/api dependency-version: 0.42.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend - dependency-name: github.com/rs/zerolog dependency-version: 1.35.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend - dependency-name: github.com/tektoncd/pipeline dependency-version: 1.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend - dependency-name: golang.org/x/crypto dependency-version: 0.49.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend - dependency-name: golang.org/x/oauth2 dependency-version: 0.36.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend - dependency-name: golang.org/x/text dependency-version: 0.35.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend - dependency-name: google.golang.org/api dependency-version: 0.273.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend - dependency-name: helm.sh/helm/v3 dependency-version: 3.20.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: backend ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the backend group with 12 updates:
0.69.30.69.45.17.05.17.20.21.20.21.31.14.01.15.10.41.00.42.01.34.01.35.01.10.01.11.00.48.00.49.00.35.00.36.00.34.00.35.00.269.00.273.13.20.03.20.1Updates
github.com/aquasecurity/trivyfrom 0.69.3 to 0.69.4Commits
Updates
github.com/go-git/go-git/v5from 5.17.0 to 5.17.2Release notes
Sourced from github.com/go-git/go-git/v5's releases.
Commits
45ae193Merge pull request #1944 from go-git/fix-permsfda4f74storage: filesystem/dotgit, Skip writing pack files that already exist on disk2212dc7Merge pull request #1941 from go-git/renovate/releases/v5.x-go-gitlite.zycloud.tk-go-...ebb2d7dbuild: Update module github.com/go-git/go-git/v5 to v5.17.1 [SECURITY]5e23dfdMerge pull request #1937 from pjbgf/idx-v56b38a32Merge pull request #1935 from pjbgf/index-v5cd757fcplumbing: format/idxfile, Fix version and fanout checks3ec0d70plumbing: format/index, Fix tree extension invalidated entry parsingdbe10b6plumbing: format/index, Align V2/V3 long name and V4 prefix encoding with Gite9b65dfplumbing: format/index, Improve v4 entry name validationUpdates
github.com/google/go-containerregistryfrom 0.21.2 to 0.21.3Release notes
Sourced from github.com/google/go-containerregistry's releases.
Commits
3888fb8bump golang to 1.25.7 (#2236)f439624tarball: detect symlink cycles in extractFileFromTar (#2232)400c263mutate: reject path traversal and symlink escape in Extract (#2227)47eedc9Bump goreleaser/goreleaser-action in the actions group (#2220)be0a845Bump the go-deps group across 4 directories with 7 updates (#2233)e916301migrate to github.com/moby/moby modules (#2228)8b2478eAdds local file support to thecrane indexsubcommand (#2223)Updates
github.com/open-policy-agent/opafrom 1.14.0 to 1.15.1Release notes
Sourced from github.com/open-policy-agent/opa's releases.
... (truncated)
Changelog
Sourced from github.com/open-policy-agent/opa's changelog.
... (truncated)
Commits
2120bd8Patch v1.15.1251ba9dlogging: make WithContext() optionalf9e7302Prepare v1.15.0 release (#8446)d0041c6runtime+server: logger plugins (#8434)8954525build(deps): bump picomatch from 2.3.1 to 2.3.2 in /docs (#8443)39a4c0eoptimized bundles: filter metadata comments properly (#8388)9fd6f93build(deps): bump the gha-dependencies group with 5 updates (#8440)01814e9docs: Update KubeCon event listing (#8439)857457bbuild(deps): bump google.golang.org/grpc from 1.79.1 to 1.79.3 in /e2e908ac78build(deps): bump flatted from 3.4.1 to 3.4.2 in /docsUpdates
github.com/operator-framework/apifrom 0.41.0 to 0.42.0Release notes
Sourced from github.com/operator-framework/api's releases.
Commits
3b53b73Bump the k8s-dependencies group with 4 updates (#482)aae9a89Bump google.golang.org/grpc from 1.78.0 to 1.79.3 (#481)2b3f088Bump sigs.k8s.io/controller-runtime in the k8s-dependencies group (#480)8653fdaBump the k8s-dependencies group with 4 updates (#479)Updates
github.com/rs/zerologfrom 1.34.0 to 1.35.0Commits
1396655Bump CI Go matrix minimum from 1.21 to 1.234b65a2fBump actions/cache from 4 to 5 (#741)b835796Bump actions/setup-go from 5 to 6 (#742)134caf8Added sanitization of journald keys (#751)e133b6aAdded variadic StrsV, ObjectsV, and StringersV (#752)82017d8Bump github.com/coreos/go-systemd/v22 from 22.6.0 to 22.7.0 (#753)2f5b8a9fix: UpdateContext skips Nop and zero-value loggers (#754)d64c9a7Add slog.Handler implementation for zerolog (#755)a0d61dcfix: return dict to Event pool (#749)f6fbd33Test coverage improvements (#748)Updates
github.com/tektoncd/pipelinefrom 1.10.0 to 1.11.0Release notes
Sourced from github.com/tektoncd/pipeline's releases.
... (truncated)
Commits
383d57bFix: Add SSH Host aliases to support multiple SSH credentials on same host2530f24Add multi-URL support and per-resolution url param to Hub Resolver0e9378bfeat: add optional PVC auto-cleanup annotation for workspaces mode6d461eefix: use os.IsExist instead of errors.Is per review feedback4b8046efix: handle os.Remove errors and add init idempotency testbc5524cfix: make step-init symlink creation idempotent1b4a945ci: fix remaining zizmor findings (permissions, injection, actions)2ba1b9fci: add zizmor GitHub Actions security analysis96c066bci: fix GitHub Actions security issues found by zizmor291fdd6tests: add pending TaskRun lifecycle transition coverageUpdates
golang.org/x/cryptofrom 0.48.0 to 0.49.0Commits
982eaa6go.mod: update golang.org/x dependencies159944fssh,acme: clean up tautological/impossible nil conditionsa408498acme: only require prompt if server has terms of servicecab0f71all: upgrade go directive to at least 1.25.0 [generated]2f26647x509roots/fallback: update bundleUpdates
golang.org/x/oauth2from 0.35.0 to 0.36.0Commits
4d954e6all: upgrade go directive to at least 1.25.0 [generated]Updates
golang.org/x/textfrom 0.34.0 to 0.35.0Commits
7ca2c6dgo.mod: update golang.org/x dependencies73d1ba9all: upgrade go directive to at least 1.25.0 [generated]Updates
google.golang.org/apifrom 0.269.0 to 0.273.1Release notes
Sourced from google.golang.org/api's releases.
... (truncated)
Changelog
Sourced from google.golang.org/api's changelog.
... (truncated)
Commits
550f00cchore(main): release 0.273.1 (#3551)da01f6achore(deps): bump github.com/go-git/go-git/v5 (#3552)2008108fix: merge duplicate x-goog-request-params header (#3547)2e86962chore(main): release 0.273.0 (#3545)50ea74cchore(google-api-go-generator): restore aiplatform:v1beta1 (#3549)0cacfa8feat(all): auto-regenerate discovery clients (#3546)d38a129chore(all): update all (#3548)a4b4711feat(all): auto-regenerate discovery clients (#3542)67cf706chore(all): update module google.golang.org/grpc to v1.79.3 [SECURITY] (#3544)e7df9fechore(main): release 0.272.0 (#3535)Updates
helm.sh/helm/v3from 3.20.0 to 3.20.1Release notes
Sourced from helm.sh/helm/v3's releases.
... (truncated)
Commits
a2369cachore(deps): bump the k8s-io group with 7 updates90e1056add image index test911f2e9fix pulling charts from OCI indices76dad33Remove refactorring changes from coalesce_test.go45c12f7Fix import26c6f19Update pkg/chart/common/util/coalesce_test.go09f5129Fix lint warning417deb2Preserve nil values in chart already5417bfafix(values): preserve nil values when chart default is empty mapDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions