Closed dependabot[bot] closed 1 year ago
Kudos, SonarCloud Quality Gate passed!
0 Bugs
0 Vulnerabilities
0 Security Hotspots
0 Code Smells
No Coverage information
No Duplication information
The version of Java (11.0.20) you have used to run this analysis is deprecated and we will stop accepting it soon. Please update to at least Java 17. Read more here
All modified and coverable lines are covered by tests :white_check_mark:
:loudspeaker: Thoughts on this report? Let us know!.
Bumps golang.org/x/image from 0.5.0 to 0.10.0.
Commits
cb227cd
tiff: limit work when decoding malicious imagesa5392f0
bmp: support to decode 8-bit format with up to 256 color palettef9550b0
go.mod: update golang.org/x dependencies81c166c
go.mod: update golang.org/x dependenciesed5dba0
go.mod: update golang.org/x dependencies08ca817
font: have Glyph return !ok for U+FFFD substituteb6ac75b
go.mod: update golang.org/x dependencies1b74412
font/sfnt: set type for all NameID constantsf632f7f
tiff, tiff/lzw, vector: use single space in commentsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show