Closed dependabot[bot] closed 1 week ago
This pull request updates the Go module dependencies for the project, including upgrading several key libraries to newer versions, which may include security fixes or improvements, but it's important to review the release notes and changelogs of the updated dependencies and thoroughly test the application to ensure there are no regressions or unexpected behavior.
We ran 9 analyzers
against 2 files
and 1 analyzer
had findings. 8 analyzers
had no findings.
Analyzer | Findings |
---|---|
Sensitive Files Analyzer | 2 findings |
:green_circle: Risk threshold not exceeded.
Looks like github.com/open-policy-agent/opa is up-to-date now, so this is no longer needed.
Bumps github.com/open-policy-agent/opa from 0.67.1 to 0.68.0.
Release notes
Sourced from github.com/open-policy-agent/opa's releases.
... (truncated)
Changelog
Sourced from github.com/open-policy-agent/opa's changelog.
... (truncated)
Commits
db53d77
Prepare v0.68.0 release (#6976)2d28934
build(deps): bump github/codeql-action from 3.26.5 to 3.26.61bec88c
docs: Update contrib docs (#6974)3ac5104
debug: Adding debugger SDK (#6877)b0f417f
build(deps): bump github.com/prometheus/client_golang from 1.20.1 to 1.20.2d613fd1
build(deps): bump google.golang.org/grpc from 1.65.0 to 1.66.0 (#6971)f10cc1f
Change required scope ofentrypoint
fromrule
todocument
(#6963)5d08783
topdown: Adding unification scope to virtual-cache key25d21f5
ast/parser: add hint to future-proof imports (#6968)7b535a7
Docs: suggest usingopa-config.yaml
as name for config file (#6966)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show