borchero / switchboard

Kubernetes Operator for Automatically Issuing DNS Records and TLS Certificates for Traefik Ingress Routes.
MIT License
155 stars 15 forks source link

build(go): bump github.com/traefik/traefik/v2 from 2.9.10 to 2.10.5 #151

Closed dependabot[bot] closed 10 months ago

dependabot[bot] commented 11 months ago

Bumps github.com/traefik/traefik/v2 from 2.9.10 to 2.10.5.

Release notes

Sourced from github.com/traefik/traefik/v2's releases.

v2.10.5

Github Advisory GHSA-7v4p-328v-8v5g Related to CVE-2023-39325

Bug fixes:

  • [accesslogs] Move origin fields capture to service level (#10126 by rtribotte)
  • [accesslogs] Fix preflight response status in access logs (#10142 by rtribotte)
  • [acme] Update go-acme/lego to v4.14.0 (#10087 by ldez)
  • [acme] Update go-acme/lego to v4.13.3 (#10077 by ldez)
  • [http3] Update quic-go to v0.37.5 (#10083 by ldez)
  • [http3] Update quic-go to v0.39.0 (#10137 by ldez)
  • [http3] Update quic-go to v0.37.6 (#10085 by ldez)
  • [http3] Update quic-go to v0.38.0 (#10086 by ldez)
  • [http3] Update quic-go to v0.38.1 (#10090 by ldez)
  • [kv] Ignore ErrKeyNotFound error for the KV provider (#10082 by sunyakun)
  • [middleware,authentication] Adjust forward auth to avoid connection leak (#10096 by wdhongtw)
  • [middleware,server] Improve CNAME flattening to avoid unnecessary error logging (#10128 by niallnsec)
  • [middleware] Allow X-Forwarded-For delete operation (#10132 by rtribotte)
  • [server] Update x/net and grpc/grpc-go (#10161 by rtribotte)
  • [webui] Add missing accessControlAllowOriginListRegex to middleware view (#10157 by DBendit)
  • Fix false positive in url anonymization (#10138 by jspdown)

Documentation:

v2.10.4

Bug fixes:

  • [acme] Update go-acme/lego to v4.13.2 (#10036 by ldez)
  • [acme] Update go-acme/lego to v4.13.0 (#10029 by ldez)
  • [k8s/ingress,k8s] fix: avoid panic on resource backends (#10023 by ldez)
  • [middleware,tracing,plugins] fix: traceability of the middleware plugins (#10028 by ldez)

Documentation:

Misc:

  • [webui] Updates the Hub tooltip content using a web component and adds an option to disable Hub button (#10008 by mdeliatf)

v2.10.3

Bug fixes:

  • [acme] Update go-acme/lego to v4.12.2 (#9935 by ldez)

v2.10.2

Bug fixes:

... (truncated)

Changelog

Sourced from github.com/traefik/traefik/v2's changelog.

v2.10.5 (2023-10-11)

All Commits

Bug fixes:

  • [accesslogs] Move origin fields capture to service level (#10126 by rtribotte)
  • [accesslogs] Fix preflight response status in access logs (#10142 by rtribotte)
  • [acme] Update go-acme/lego to v4.14.0 (#10087 by ldez)
  • [acme] Update go-acme/lego to v4.13.3 (#10077 by ldez)
  • [http3] Update quic-go to v0.37.5 (#10083 by ldez)
  • [http3] Update quic-go to v0.39.0 (#10137 by ldez)
  • [http3] Update quic-go to v0.37.6 (#10085 by ldez)
  • [http3] Update quic-go to v0.38.0 (#10086 by ldez)
  • [http3] Update quic-go to v0.38.1 (#10090 by ldez)
  • [kv] Ignore ErrKeyNotFound error for the KV provider (#10082 by sunyakun)
  • [middleware,authentication] Adjust forward auth to avoid connection leak (#10096 by wdhongtw)
  • [middleware,server] Improve CNAME flattening to avoid unnecessary error logging (#10128 by niallnsec)
  • [middleware] Allow X-Forwarded-For delete operation (#10132 by rtribotte)
  • [server] Update x/net and grpc/grpc-go (#10161 by rtribotte)
  • [webui] Add missing accessControlAllowOriginListRegex to middleware view (#10157 by DBendit)
  • Fix false positive in url anonymization (#10138 by jspdown)

Documentation:

v2.10.4 (2023-07-24)

All Commits

Bug fixes:

  • [acme] Update go-acme/lego to v4.13.2 (#10036 by ldez)
  • [acme] Update go-acme/lego to v4.13.0 (#10029 by ldez)
  • [k8s/ingress,k8s] fix: avoid panic on resource backends (#10023 by ldez)
  • [middleware,tracing,plugins] fix: traceability of the middleware plugins (#10028 by ldez)

Documentation:

Misc:

  • [webui] Updates the Hub tooltip content using a web component and adds an option to disable Hub button (#10008 by mdeliatf)

v2.10.3 (2023-06-17)

All Commits

Bug fixes:

  • [acme] Update go-acme/lego to v4.12.2 (#9935 by ldez)

... (truncated)

Commits
  • 6a34f23 Prepare release v2.10.5
  • 4b2c763 update x/net and grpc/grpc-go
  • d03d8d5 Add missing accessControlAllowOriginListRegex to middleware view
  • e95fde5 Fix preflight response status in access logs
  • ab79934 Improve CNAME flattening to avoid unnecessary error logging
  • b966215 Move origin fields capture to service level
  • b786f58 fix: false positive in url anonymization
  • 173154c Ignore ErrKeyNotFound error for the KV provider
  • c3880a6 Update quic-go to v0.39.0
  • 4d63eb3 Allow X-Forwarded-For delete operation
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
dependabot[bot] commented 10 months ago

Superseded by #156.