Closed dependabot[bot] closed 4 months ago
VIOLATION DESCRIPTION | NUMBER OF VIOLATIONS |
---|---|
HIGH/CRITICAL SECURITY VULNERABILITIES | 2 |
MAJOR UPDATES AVAILABLE | 0 |
LICENSE REQUIRES REVIEW | 0 |
LICENSE RISK HIGH | 7 |
RESTRICTIED LICENSE FOR ON-PREMISE DELIVERY | 0 |
Superseded by #219.
Bumps the go_modules group with 8 updates:
5.23.0
5.30.1
3.0.1
3.0.2
2.0.16
2.0.21
2.2.1
2.2.4
0.19.0
0.22.0
1.31.0
1.33.0
2.6.1
2.6.3
3.12.3
3.14.3
Updates
github.com/containers/image/v5
from 5.23.0 to 5.30.1Release notes
Sourced from github.com/containers/image/v5's releases.
... (truncated)
Commits
56e750a
Release 5.30.1132678b
Merge pull request #2404 from mtrmac/digest-unmarshal-5.30b724ee7
Validate the tags returned by a registrya9225e4
Call .Validate() before digest.Digest.String() if necessary4a3785d
Refactor the error handling furthera802d65
Refactor the error handling path of saveStream39e7c91
Call .Validate() before digest.Hex() / digest.Encoded()2bcb834
Validate digests before using themb29bde5
Bump to v5.30.03cc0bb4
Merge pull request #2328 from containers/renovate/github.com-containers-stora...Updates
github.com/go-jose/go-jose/v3
from 3.0.1 to 3.0.2Release notes
Sourced from github.com/go-jose/go-jose/v3's releases.
Changelog
Sourced from github.com/go-jose/go-jose/v3's changelog.
Commits
863f73b
v3.0.2: Update changelog (#95)bdbc794
Update golang.org/x/crypto to v0.19 (backport) (#94)25bce79
Updated go-jose v3.0.0 to v3.0.1 in jose-util (#70)aa386df
jwe/CompactSerialize: improve performance. (#67)053c9bf
DecryptMulti: handle decompression error (#19)ca9011b
Bump go version to 1.21.4 to satisfy govulncheck (#68)c8399df
Revert pull request #10 (multiple audiences) (#24)ec819e9
Add a security.md doc for contacting us about potential security vulnerabilit...65351c2
Fix decryption DoS: Reject too high p2c (#66)260aa26
Bump golang to 1.21 GA (#54)Updates
github.com/lestrrat-go/jwx/v2
from 2.0.16 to 2.0.21Release notes
Sourced from github.com/lestrrat-go/jwx/v2's releases.
... (truncated)
Changelog
Sourced from github.com/lestrrat-go/jwx/v2's changelog.
... (truncated)
Commits
611d914
Merge pull request #1091 from lestrrat-go/develop/v2551073b
fix keyset suboption documentation (#1090)cdfaccf
silence linter17e2da9
Update Changesd43f2ce
Merge pull request from GHSA-hj3v-m684-v259778ed27
Bump golang.org/x/crypto from 0.19.0 to 0.21.0 (#1086)38d258e
Bump github.com/stretchr/testify from 1.8.4 to 1.9.0 (#1084)ffcb990
Update httprc to v1.0.5 (#1088)c3b3a17
Merge branch 'develop/v2' into v2ace7a77
Update ChangesUpdates
github.com/sigstore/cosign/v2
from 2.2.1 to 2.2.4Release notes
Sourced from github.com/sigstore/cosign/v2's releases.
... (truncated)
Changelog
Sourced from github.com/sigstore/cosign/v2's changelog.
... (truncated)
Commits
fb651b4
Add v2.2.4 changelog (#3662)629f5f8
Fixes for GHSA-88jx-383q-w4qc and GHSA-95pr-fxf5-86gv (#3661)302aee6
Refactor e2e-tests.yml workflow (#3627)d0b9861
chore(deps): bump golang.org/x/crypto from 0.21.0 to 0.22.0 (#3649)c95439b
chore(deps): bump github.com/spiffe/go-spiffe/v2 from 2.1.7 to 2.2.0 (#3653)430c985
chore(deps): bump golang.org/x/sync from 0.6.0 to 0.7.0 (#3655)48858a2
chore(deps): bump github.com/xanzy/go-gitlab from 0.101.0 to 0.102.0 (#3652)eba7c59
chore(deps): bump golang.org/x/term from 0.18.0 to 0.19.0 (#3651)2d13b65
chore(deps): bump golang.org/x/oauth2 from 0.18.0 to 0.19.0 (#3650)d56c9e8
chore(deps): bump the gomod group with 3 updates (#3648)Updates
golang.org/x/net
from 0.19.0 to 0.22.0Commits
7ee34a0
go.mod: update golang.org/x dependenciesc289c7a
websocket: re-add documentation for DialConfig9fb4a8c
http2: send an error of FLOW_CONTROL_ERROR when exceed the maximum octets3dfd003
websocket: add support for dialing with contextfa11427
quic: move package out of internal591be7f
quic: fix UDP on big-endian Linux, tests on various architectures34cc446
quic: temporarily disable networking tests failing on various platforms4bdc6df
quic: expand package docs, and document Stream22cbde9
quic: set ServerName in client connection TLSConfig57e4cc7
quic: handle PATH_CHALLENGE and PATH_RESPONSE framesUpdates
google.golang.org/protobuf
from 1.31.0 to 1.33.0Updates
gopkg.in/go-jose/go-jose.v2
from 2.6.1 to 2.6.3Updates
helm.sh/helm/v3
from 3.12.3 to 3.14.3Release notes
Sourced from helm.sh/helm/v3's releases.
... (truncated)
Commits
f03cc04
Add a note about --dry-run displaying secrets1a7330f
add error messagesd6acc00
Fix: Ignore alias validation error for index loadb2738fb
chore(deps): bump github.com/containerd/containerd from 1.7.11 to 1.7.125b0847e
chore(deps): bump github.com/DATA-DOG/go-sqlmock from 1.5.0 to 1.5.27e18c39
Update architecture detection methodc309b6f
Some fixese8858f8
validation fix3fc9f4b
Improve release action69dcc92
bump version toDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show