[v0.60] Backport pkg/subscriptions: use securejoin for the container path + new 0.60.4 release by @Luap99 in containers/common#2186
Fixes CVE-2024-9341
VirtualMachine.AttachDisk unitNumber param is optional [a316da5c]:
switching from int32 to *int32, otherwise the client must choose a valid unitNumber.
vCenter will choose a unitNumber when not provided.
Most Recent Ignore Conditions Applied to This Pull Request
| Dependency Name | Ignore Conditions |
| --- | --- |
| google.golang.org/api | [>= 0.196.a, < 0.197] |
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
Bumps the go-deps group with 6 updates in the / directory:
1.28.0
1.28.1
1.43.0
1.44.0
1.4.0
1.4.1
0.60.2
0.60.4
0.42.0
0.43.0
0.24.0
0.25.0
Updates
cloud.google.com/go/compute
from 1.28.0 to 1.28.1Changelog
Sourced from cloud.google.com/go/compute's changelog.
Commits
e992f09
chore: release main (#10792)22adc9a
chore(main): release firestore 1.17.0 (#10597)e9a551e
feat(firestore): Adding distance threshold and result field (#10802)839f30e
chore(main): release auth 0.9.4 (#10846)b9dfce5
chore: update gapic-generator-go to 0.47.0 (#10848)9b4b2fa
docs(pubsub): update documentation for 31 day subscription message retention ...2bdedef
fix(compute/metadata): check error chain for retryable error (#10840)2d5a9f9
feat(dataproc): add support for new Dataproc features (#10817)f9869f7
fix(auth): enable self-signed JWT for non-GDU universe domain (#10831)6720291
chore(main): release bigtable 1.32.0 (#10815)Updates
cloud.google.com/go/storage
from 1.43.0 to 1.44.0Release notes
Sourced from cloud.google.com/go/storage's releases.
Commits
8722d72
chore(main): release spanner 1.44.0 (#7311)3f118f9
chore(all): auto-regenerate gapics (#7330)48ba16f
feat(spanner): add support for Optimistic Concurrency Control (#7332)cf1332d
chore: release main (#7313)45c70e3
chore(all): auto-regenerate gapics (#7318)045a8dc
chore: add support_request template (#7328)c37f9ae
refactor(bigquery/storage/managedwriter): introduce send optimizers (#7323)0bf80d7
fix(bigquery): fetch dst table for jobs when readings with Storage API (#7325)2f45776
chore(internal/gapicgen): actually freeze cloud dir (#7326)c88fbdf
fix(pubsub): fix bug with AckWithResult with exactly once disabled (#7319)Updates
github.com/Azure/azure-sdk-for-go/sdk/storage/azblob
from 1.4.0 to 1.4.1Release notes
Sourced from github.com/Azure/azure-sdk-for-go/sdk/storage/azblob's releases.
Commits
47b7a8a
changelog changes for blob and files release (#23452)06f0d9e
Update installed event processor version for net6 to net8 update (#23451)44cdba7
[Release] sdk/resourcemanager/billing/armbilling/1.0.0 (#23450)d5d9188
Update CodeownersLinter for net6 to net8 update (#23449)35f9c0f
prep for release (#23448)7664dd2
Increment package version after release of azidentity (#23447)1d798e7
Auto-generated baselines by 1ES Pipeline Templates (#23438)da9c60f
Sync eng/common directory with azure-sdk-tools for PR 8974 (#23445)500650c
Prepare azidentity v1.8.0-beta.3 for release (#23434)3eb3276
Update PublishCodeCoverageResults task to v2 (#23437)Updates
github.com/containers/common
from 0.60.2 to 0.60.4Release notes
Sourced from github.com/containers/common's releases.
Commits
d31fcd2
Bump to v0.60.4e7db065
pkg/subscriptions: use securejoin for the container path91f5148
Merge pull request #2170 from Luap99/v0.608264002
Bump to v0.60.32776f6b
pkg/netns: remove NewNSWithName()8a5b951
pkg/netns: add NewNSFrom()50870e9
pkg/netns: ensure makeNetnsDir is race free322f2c2
pkg/netns: split out makeNetnsDir logic52c82b1
Merge pull request #2127 from TomSweeneyRedHat/dev/tsweeney/v0.60.2Updates
github.com/vmware/govmomi
from 0.42.0 to 0.43.0Release notes
Sourced from github.com/vmware/govmomi's releases.
... (truncated)
Commits
b17abb2
chore: Update version.go for v0.43.0139b19e
Merge pull request #3527 from bzed/disk_provbc0c8a0
Merge pull request #3544 from akutz/feature/fault476704a
api: Fault helpers0a94649
Merge pull request #3546 from yanleizhao-vmware/feature/vcsim-support-placevm...8421b67
vcsim: Support PlaceVm with relocate placement typed3cb5c6
Merge pull request #3545 from ericvmw/issue-354293b97e1
Update library state info to content library APIc1151f8
Merge pull request #3543 from yanleizhao-vmware/yanleizhao-vmware/feature/sim...988a047
Merge pull request #3539 from dougm/disk-attachUpdates
golang.org/x/tools
from 0.24.0 to 0.25.0Commits
7398f36
all: fix some symbols error in commentf111c72
go/callgraph/rta: skip test on js platform9f9b7e3
gopls/internal/settings: add missing deep cloning in Options.Clonece7eed4
doc/generate: minor cleanup075ae7d
go/callgraph/vta: add basic tests for range-over-func2c7aaab
go/ssa: skip failing test1b5663f
go/callgraph/vta: perform minor cleanups0a49883
gopls/go.mod: update the go directive to 1.23.1ad366a8
go.mod: update golang.org/x dependencies4fb36d1
go/callgraph/rta: add rta analysis test case for multiple go packagesUpdates
google.golang.org/api
from 0.195.0 to 0.197.0Release notes
Sourced from google.golang.org/api's releases.
Changelog
Sourced from google.golang.org/api's changelog.
Commits
c5990e2
chore(main): release 0.197.0 (#2771)dc3697a
chore(all): update all (#2777)cedc5b0
feat(all): auto-regenerate discovery clients (#2779)72cc5c4
feat(all): auto-regenerate discovery clients (#2778)cc62887
feat(all): auto-regenerate discovery clients (#2776)11e2ff6
feat(all): auto-regenerate discovery clients (#2775)6476ddd
feat(all): auto-regenerate discovery clients (#2774)140d0a5
fix(transport): set UniverseDomain in http.NewClient for new auth (#2773)0c7c227
feat(all): auto-regenerate discovery clients (#2772)07782e2
feat(all): auto-regenerate discovery clients (#2770)Most Recent Ignore Conditions Applied to This Pull Request
| Dependency Name | Ignore Conditions | | --- | --- | | google.golang.org/api | [>= 0.196.a, < 0.197] |Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show