Skip to content

Bump github.com/prometheus/common from 0.37.0 to 0.38.0#41

Merged
github-actions[bot] merged 1 commit intomainfrom
dependabot/go_modules/github.com/prometheus/common-0.38.0
Dec 8, 2022
Merged

Bump github.com/prometheus/common from 0.37.0 to 0.38.0#41
github-actions[bot] merged 1 commit intomainfrom
dependabot/go_modules/github.com/prometheus/common-0.38.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Dec 8, 2022

Bumps github.com/prometheus/common from 0.37.0 to 0.38.0.

Release notes

Sourced from github.com/prometheus/common's releases.

v0.38.0

  • [FEATURE] Implement Stringer on TLSVersion (#405)
  • [FEATURE] Check if TLS certificate and key file have been modified (#345)
  • [ENHANCEMENT] Add the ability to specify the maximum acceptable TLS version (#414)
  • [ENHANCEMENT] Make LoadHTTPConfigFile set directory and move from tests file (#415)
  • [ENHANCEMENT] Get Revision from debug.BuildInfo if not explicitly set (#374)
Commits
  • a33c32f Merge pull request #374 from roidelapluie/go118vcs
  • 5b6c049 go118: Get VCS info from debug.BuildInfo
  • 11bcb5b Merge pull request #415 from FUSAKLA/fus-http-config-from-file
  • 87b669d Add the ability to specify the maximum acceptable TLS version (#414)
  • d9cd6f2 feat: make LoadHTTPConfigFile set directory and move from tests file
  • bebc731 Remove ioutil after merging check client certificates (#407)
  • 8c9cb3f Update common Prometheus files (#399)
  • 1c0fa3e Check if TLS certificate and key file have been modified (#345)
  • 54e041d Implement Stringer on TLSVersion (#405)
  • c206bfc Merge pull request #404 from thaJeztah/bump_protobuf_extensions
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/prometheus/common](https://github.com/prometheus/common) from 0.37.0 to 0.38.0.
- [Release notes](https://github.com/prometheus/common/releases)
- [Commits](prometheus/common@v0.37.0...v0.38.0)

---
updated-dependencies:
- dependency-name: github.com/prometheus/common
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Dec 8, 2022
@github-actions github-actions Bot enabled auto-merge (squash) December 8, 2022 16:10
@guardrails
Copy link
Copy Markdown

guardrails Bot commented Dec 8, 2022

⚠️ We detected 32 security issues in this pull request:

Vulnerable Libraries (32)
Severity Details
High pkg:golang/golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11@v0.0.0-20201209123823-ac852fbbde11 - no patch available
High pkg:golang/golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4@v0.0.0-20220425223048-2871e0cb64e4 - no patch available
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210220050731-9a76102bfb43@v0.0.0-20210220050731-9a76102bfb43 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210305230114-8fe3ee5dd75b@v0.0.0-20210305230114-8fe3ee5dd75b upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/golang.org/x/text@v0.3.4@v0.3.4 - no patch available
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210908233432-aa78b53d3365@v0.0.0-20210908233432-aa78b53d3365 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20220328115105-d36c6a25d886@v0.0.0-20220328115105-d36c6a25d886 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210823070655-63515b42dcdf@v0.0.0-20210823070655-63515b42dcdf upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20220209214540-3681064d5158@v0.0.0-20220209214540-3681064d5158 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20220128215802-99c3d69c2c27@v0.0.0-20220128215802-99c3d69c2c27 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20200905004654-be1d3432aa8f@v0.0.0-20200905004654-be1d3432aa8f upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210119212857-b64e53b001e4@v0.0.0-20210119212857-b64e53b001e4 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210104204734-6f8348627aad@v0.0.0-20210104204734-6f8348627aad upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420@v0.0.0-20210503060351-7fd8e65b6420 - no patch available
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210603125802-9665404d3644@v0.0.0-20210603125802-9665404d3644 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/golang.org/x/net@v0.0.0-20210119194325-5f4716e94777@v0.0.0-20210119194325-5f4716e94777 - no patch available
N/A pkg:golang/golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e@v0.0.0-20220624214902-1bab6f366d9e upgrade to: 1.18.6,1.19.1,0.0.0-20220906165146-f3363e06e74c
N/A pkg:golang/golang.org/x/sys@v0.0.0-20201201145000-ef89a241ccb3@v0.0.0-20201201145000-ef89a241ccb3 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210514084401-e8d321eab015@v0.0.0-20210514084401-e8d321eab015 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4@v0.0.0-20210316092652-d523dce5a7f4 - no patch available
N/A pkg:golang/golang.org/x/net@v0.0.0-20220805013720-a33c5aa5df48@v0.0.0-20220805013720-a33c5aa5df48 upgrade to: 1.18.6,1.19.1,0.0.0-20220906165146-f3363e06e74c
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210315160823-c6e025ad8005@v0.0.0-20210315160823-c6e025ad8005 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210320140829-1e4c9ba3b0c4@v0.0.0-20210320140829-1e4c9ba3b0c4 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/golang.org/x/net@v0.0.0-20220325170049-de3da57026de@v0.0.0-20220325170049-de3da57026de - no patch available
High pkg:golang/golang.org/x/net@v0.0.0-20220412020605-290c469a71a5@v0.0.0-20220412020605-290c469a71a5 - no patch available
N/A pkg:golang/golang.org/x/sys@v0.0.0-20211124211545-fe61309f8881@v0.0.0-20211124211545-fe61309f8881 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20220227234510-4e6760a101f9@v0.0.0-20220227234510-4e6760a101f9 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210806184541-e5e7981a1069@v0.0.0-20210806184541-e5e7981a1069 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22@v0.0.0-20210616094352-59db8d763f22 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/net@v0.0.0-20220607020251-c690dde0001d@v0.0.0-20220607020251-c690dde0001d upgrade to: 1.18.6,1.19.1,0.0.0-20220906165146-f3363e06e74c
N/A pkg:golang/golang.org/x/sys@v0.0.0-20211210111614-af8b64212486@v0.0.0-20211210111614-af8b64212486 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/golang.org/x/net@v0.0.0-20201031054903-ff519b6c9102@v0.0.0-20201031054903-ff519b6c9102 - no patch available

More info on how to fix Vulnerable Libraries in Go.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

@github-actions github-actions Bot merged commit 658c827 into main Dec 8, 2022
@github-actions github-actions Bot deleted the dependabot/go_modules/github.com/prometheus/common-0.38.0 branch December 8, 2022 16:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants