chore(deps): update go dependencies#370
Open
red-hat-konflux[bot] wants to merge 1 commit into
Open
Conversation
65b0879 to
dae0ecf
Compare
Author
ℹ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
dae0ecf to
94ce3dc
Compare
Author
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: hack/tools/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
b529537 to
4f52300
Compare
f7e04ac to
5ab5acd
Compare
5ab5acd to
196c4df
Compare
Author
|
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.1.52→v0.1.54v0.19.0→v0.20.0v1.6.0→v1.11.0v1.26.0→v1.31.0v0.8.0→v1.0.0v1.19.2→v1.24.0v1.21.0→v1.21.1v1.11.2→v1.12.0v1.7.0→v1.7.2v1.55.7→v1.55.8v1.41.5→v1.41.7v1.32.12→v1.32.17v1.19.13→v1.19.16v1.18.21→v1.18.23v1.4.21→v1.4.23v2.7.21→v2.7.23v1.13.7→v1.13.9v1.13.21→v1.13.23v1.50.3→v1.51.1v1.0.9→v1.0.11v1.30.14→v1.30.17v1.35.18→v1.35.21v1.41.10→v1.42.1v1.24.2→v1.25.1v4.9.1→v4.10.0v4.3.0→v5.0.3v2.2.0→v2.7.0v3.17.0→v3.18.0v1.9.0→v1.10.1v3.0.4→v4.1.4v4.1.3→v4.1.4v2.4.0→v2.5.0v5.3.0→v5.3.1v0.21.3→v0.21.5v2.0.0→v2.3.1v0.3.14→v0.3.15v2.19.0→v2.22.0v1.4.0→v2.3.3v2.27.3→v2.29.0v2.28.0→v2.29.0v1.0.1-vault-7→v2.24.0v0.20260324.0→v0.20260512.0v0.0.21→v0.0.23v0.0.5→v1.1.4v2.2.4→v2.3.1v0.10.0→v0.11.0v0.5.0→v0.5.1v2.1.0→v3.0.0v0.67.0→v0.68.0v0.67.0→v0.68.0v1.42.0→v1.43.0v1.42.0→v1.43.0v1.42.0→v1.43.0v1.42.0→v1.43.0v1.42.0→v1.43.0v1.42.0→v1.43.0v0.77.1→v0.79.0v1.27.1→v1.28.0v2.4.4→v3.0.4v3.23.4→v3.26.0v0.49.0→v0.51.0v0.52.0→v0.54.0v0.42.0→v0.44.0v0.41.0→v0.43.0v0.35.0→v0.37.0v0.273.0→v0.279.0d00831a→3700d41d00831a→3700d41d00831a→3700d41d00831a→3700d41v1.79.3→v1.81.0v1.79.3→v1.81.0v1.6.1→v1.6.2v0.12.3→v0.12.4Warning
Some dependencies could not be looked up. Check the warning logs for more information.
Release Notes
chainguard-dev/sdk (chainguard.dev/sdk)
v0.1.54Compare Source
v0.1.53Compare Source
Full Changelog: chainguard-dev/sdk@v0.1.52...v0.1.53
googleapis/google-cloud-go (cloud.google.com/go/auth)
v0.20.0Compare Source
bigquery: Support SchemaUpdateOptions for load jobs.
bigtable:
datastore: Add OpenCensus tracing.
firestore:
logging: Add a WriteTimeout option.
spanner: Support Batch API.
storage: Add OpenCensus tracing.
AzureAD/microsoft-authentication-library-for-go (github.com/AzureAD/microsoft-authentication-library-for-go)
v1.7.2Compare Source
What's Changed
New Contributors
Full Changelog: AzureAD/microsoft-authentication-library-for-go@v1.7.1...v1.7.2
v1.7.1: 1.7.1Compare Source
What's Changed
Full Changelog: AzureAD/microsoft-authentication-library-for-go@v1.7.0...v1.7.1
aws/aws-sdk-go (github.com/aws/aws-sdk-go)
v1.55.8Compare Source
SDK Features
aws/aws-sdk-go-v2 (github.com/aws/aws-sdk-go-v2)
v1.41.7Compare Source
Module Highlights
github.com/aws/aws-sdk-go-v2/service/ecs: v1.41.7github.com/aws/aws-sdk-go-v2/service/glue: v1.78.0github.com/aws/aws-sdk-go-v2/service/ivschat: v1.12.5github.com/aws/aws-sdk-go-v2/service/rolesanywhere: v1.10.0github.com/aws/aws-sdk-go-v2/service/securityhub: v1.47.2v1.41.6Compare Source
aws/smithy-go (github.com/aws/smithy-go)
v1.25.1Compare Source
General Highlights
Module Highlights
github.com/aws/smithy-go: v1.25.1v1.25.0Compare Source
General Highlights
Module Highlights
github.com/aws/smithy-go: v1.25.0v1.24.3Compare Source
General Highlights
Module Highlights
github.com/aws/smithy-go: v1.24.3github.com/aws/smithy-go/aws-http-auth: v1.1.3bmatcuk/doublestar (github.com/bmatcuk/doublestar/v4)
v4.10.0: Added WithNoHidden optionCompare Source
Added support for a
WithNoHiddenoption to ignore hidden files in patterns that might unintentionally match them. For example, a.configdirectory would not be matched by*or recursed into by**, but would be matched by.*or recursed by.config/**.Thanks to @lukasngl for the initial PR and idea!
What's Changed
New Contributors
Full Changelog: bmatcuk/doublestar@v4.9.2...v4.10.0
v4.9.2: Fixed Handling of Paths With Meta Chars Using AltsCompare Source
@toga4 submitted a PR that fixed a small bug with the way paths were handled when the pattern used
{alts}: if some part of the on-disk path that came before the{alt}included meta characters (say, a directory name that included the character?), these meta characters were not escaped when they were passed back through the globbing routines. This caused doublestar to interpret them as actual meta characters, rather than a fixed-string path as it should have. Nice find, @toga4 !What's Changed
New Contributors
Full Changelog: bmatcuk/doublestar@v4.9.1...v4.9.2
cenkalti/backoff (github.com/cenkalti/backoff/v4)
v5.0.3Compare Source
v5.0.2Compare Source
v5.0.1Compare Source
v5.0.0Compare Source
clipperhouse/uax29 (github.com/clipperhouse/uax29/v2)
v2.7.0Compare Source
v2.6.0Compare Source
v2.5.0Compare Source
What's Changed
Breaking change
The returned iterator type from
FromString()andFromBytes()is now a pointer. This will not present a problem if you are just using it in the typical way, which is assigning to a local variable and iterating.If you are embedding this iterator into another object, and therefore declaring its type, this change might break your compilation. You’ll need to change to a pointer type. Apologies if so — this seems like a small enough change that a v3 would be a bit much.
New Contributors
Full Changelog: clipperhouse/uax29@v2.4.0...v2.5.0
v2.4.0Compare Source
Adds Unicode 16 support
What's Changed
Full Changelog: clipperhouse/uax29@v2.3.0...v2.4.0
v2.3.1Compare Source
v2.3.0Compare Source
coreos/go-oidc (github.com/coreos/go-oidc/v3)
v3.18.0Compare Source
What's Changed
Full Changelog: coreos/go-oidc@v3.17.0...v3.18.0
fsnotify/fsnotify (github.com/fsnotify/fsnotify)
v1.10.1Compare Source
Changes and fixes
inotify: don't remove sibling watches sharing a path prefix (#754)
inotify, windows: don't rename sibling watches sharing a path prefix
(#755)
v1.10.0Compare Source
This version of fsnotify needs Go 1.23.
Changes and fixes
inotify: improve initialization error message (#731)
inotify: send Rename event if recursive watch is renamed (#696)
inotify: avoid copying event buffers when reading names (#741)
kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a bad entry no longer aborts Watcher.Add for the whole directory (#748)
kqueue: drop watches directly in Close() to fix a file descriptor leak when recycling watchers (#740)
windows: fix nil pointer dereference in remWatch (#736)
windows: lock watch field updates against concurrent WatchList to fix a race introduced in v1.9.0 (#709, #749)
go-jose/go-jose (github.com/go-jose/go-jose/v3)
v4.1.4Compare Source
What's Changed
Fixes Panic in JWE decryption. See GHSA-78h2-9frx-2jm8
Full Changelog: go-jose/go-jose@v4.1.3...v4.1.4
v4.1.3Compare Source
This release drops Go 1.23 support as that Go release is no longer supported. With that, we can drop
x/cryptoand no longer have any external dependencies in go-jose outside of the standard library!This release fixes a bug where a critical b64 header was ignored if in an unprotected header. It is now rejected instead of ignored.
What's Changed
Full Changelog: go-jose/go-jose@v4.1.2...v4.1.3
v4.1.2Compare Source
What's Changed
go-jose v4.1.2 improves some documentation, errors, and removes the only 3rd-party dependency.
New Contributors
Full Changelog: go-jose/go-jose@v4.1.1...v4.1.2
v4.1.1Compare Source
What's Changed
New Contributors
Full Changelog: go-jose/go-jose@v4.1.0...v4.1.1
v4.1.0Compare Source
What's Changed
signatureAlgorithmsargument by @tgeoghegan in #163New Contributors
Full Changelog: go-jose/go-jose@v4.0.5...v4.1.0
v4.0.5Compare Source
What's Changed
Fixes GHSA-c6gw-w398-hv78
Various other dependency updates, small fixes, and documentation updates in the full changelog
New Contributors
Full Changelog: go-jose/go-jose@v4.0.4...v4.0.5
v4.0.4: Version 4.0.4Compare Source
Fixed
v4.0.3: Version 4.0.3Compare Source
Changed
v4.0.2: Version 4.0.2Compare Source
What's Changed
New Contributors
Full Changelog: go-jose/go-jose@v4.0.1...v4.0.2
v4.0.1: Version 4.0.1Compare Source
Fixed
amounts of memory and CPU when decompressed by
DecryptorDecryptMulti.Those functions now return an error if the decompressed data would exceed
250kB or 10x the compressed size (whichever is larger). Thanks to
Enze Wang@Alioth and Jianjun Chen@Zhongguancun Lab (@zer0yu and @chenjj)
for reporting.
v4.0.0: Version 4.0.0Compare Source
This release makes some breaking changes in order to more thoroughly address the vulnerabilities discussed in Three New Attacks Against JSON Web Tokens, "Sign/encrypt confusion", "Billion hash attack", and "Polyglot token".
Changed
ParseSigned, ParseDetached, jwt.ParseEncrypted, jwt.ParseSigned,
jwt.ParseSignedAndEncrypted (#69, #74)
Added
v3.0.5Compare Source
What's Changed
Fixes GHSA-78h2-9frx-2jm8
We recommend migrating from v3 to v4, and we will stop support v3 in the near future.
Full Changelog: go-jose/go-jose@v3.0.4...v3.0.5
go-viper/mapstructure (github.com/go-viper/mapstructure/v2)
v2.5.0Compare Source
What's Changed
New Contributors
Full Changelog: go-viper/mapstructure@v2.4.0...v2.5.0
golang-jwt/jwt (github.com/golang-jwt/jwt/v5)
v5.3.1Compare Source
What's Changed
🔐 Features
WithNotBeforeRequiredparser option and add test coverage by @equalsgibson in #456NewWithClaims()by @equalsgibson in #459ParseUnverifiedby @slickwilli in #414👒 Dependencies
New Contributors
Full Changelog: golang-jwt/jwt@v5.3.0...v5.3.1
google/go-containerregistry (github.com/google/go-containerregistry)
v0.21.5Compare Source
What's Changed
Full Changelog: google/go-containerregistry@v0.21.4...v0.21.5
v0.21.4Compare Source
What's Changed
New Contributors
Full Changelog: google/go-containerregistry@v0.21.3...v0.21.4
googleapis/api-linter (github.com/googleapis/api-linter/v2)
v2.3.1Compare Source
Bug Fixes
v2.3.0Compare Source
Features
v2.2.0Compare Source
Features
Bug Fixes
v2.1.0Compare Source
Features
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.