paketo-buildpacks / npm-install

A Cloud Native Buildpack for npm
Apache License 2.0
10 stars 17 forks source link

Bump the go-modules group with 29 updates #549

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps the go-modules group with 29 updates:

Package From To
github.com/CycloneDX/cyclonedx-go 0.7.1 0.7.2
github.com/cenkalti/backoff/v4 4.2.0 4.2.1
github.com/containerd/containerd 1.7.0 1.7.6
github.com/docker/distribution 2.8.2+incompatible 2.8.3+incompatible
github.com/docker/docker-credential-helpers 0.7.0 0.8.0
github.com/go-git/go-billy/v5 5.4.1 5.5.0
github.com/go-git/go-git/v5 5.6.1 5.9.0
github.com/google/go-containerregistry 0.15.1 0.16.1
github.com/google/uuid 1.3.0 1.3.1
github.com/jinzhu/copier 0.3.5 0.4.0
github.com/klauspost/compress 1.16.5 1.17.0
github.com/mattn/go-runewidth 0.0.14 0.0.15
github.com/moby/patternmatcher 0.5.0 0.6.0
github.com/opencontainers/runc 1.1.5 1.1.9
github.com/pierrec/lz4/v4 4.1.17 4.1.18
github.com/sirupsen/logrus 1.9.1 1.9.3
github.com/skeema/knownhosts 1.2.0 1.2.1
github.com/spdx/tools-golang 0.5.0 0.5.3
github.com/spf13/afero 1.9.5 1.10.0
github.com/spf13/cast 1.5.0 1.5.1
github.com/sylabs/sif/v2 2.11.3 2.15.0
github.com/testcontainers/testcontainers-go 0.21.0 0.25.0
github.com/vbatts/tar-split 0.11.3 0.11.5
golang.org/x/crypto 0.13.0 0.14.0
golang.org/x/mod 0.12.0 0.13.0
golang.org/x/net 0.15.0 0.16.0
golang.org/x/sync 0.3.0 0.4.0
golang.org/x/tools 0.13.0 0.14.0
google.golang.org/grpc 1.57.0 1.58.2

Updates github.com/CycloneDX/cyclonedx-go from 0.7.1 to 0.7.2

Release notes

Sourced from github.com/CycloneDX/cyclonedx-go's releases.

v0.7.2

This is a bugfix release that ships with minimal support for the CycloneDX v1.5 specification.

Full support is being worked on and planned to be released soon. The progress may be tracked in #90.

The reason for publishing partial support like this is to allow the consumption of v1.5 BOMs, which fails with cyclonedx-go <= v0.7.1.

Warning
The default SpecVersion has been updated to SpecVersion1_5. If your application generates BOMs, and you're not ready (or willing) to distribute BOMs following the v1.5 specification yet, consider using EncodeVersion to generate output for an older version of the spec.

Changelog

Features

  • 7128a921f3e83a43feef75bc8ab95642c236ef82: feat: raise baseline go version to 1.18 (@​nscuro)

Fixes

  • ff719b64835af6e75dcfd6e7ff90d070f271ae07: fix: unmarshal bom on v1.5 return invalid specification version (@​chen-keinan)

Building and Packaging

  • 966c223154527621395473cc045a7672609c879f: build(deps): bump CycloneDX/gh-gomod-generate-sbom from 1.1.0 to 2.0.0 (@​dependabot[bot])
  • 1e83e8598d07b6303522cb63458be2577223f8d3: build(deps): bump actions/checkout from 3.5.0 to 3.5.1 (@​dependabot[bot])
  • 78f6593ed81da036aec671c19ea937b3a80586bf: build(deps): bump actions/checkout from 3.5.1 to 3.5.2 (@​dependabot[bot])
  • 868f6db7d03da581dbe9b6d283acd6c477529c0a: build(deps): bump actions/checkout from 3.5.2 to 3.5.3 (@​dependabot[bot])
  • 5885827e4246b82e08d37f6f0b95c6c0a4ef821b: build(deps): bump actions/setup-go from 4.0.0 to 4.0.1 (@​dependabot[bot])
  • d772b5438430be7879f3a4e7064c1ccbdbf153a1: build(deps): bump actions/setup-go from 4.0.1 to 4.1.0 (@​dependabot[bot])
  • 578e8621c93869b9e0368eebb619cd96c7e9e2bb: build(deps): bump github.com/stretchr/testify from 1.8.2 to 1.8.4 (@​dependabot[bot])
  • f83e6a7c9d196eff9f99ecf8291cd4adeabce31a: build(deps): bump gitpod/workspace-go from 2be827f to 910daeb (@​dependabot[bot])
  • cd7b23a68ff1c7467e211c9c69f9fb67c2244043: build(deps): bump gitpod/workspace-go from 910daeb to d7a41f5 (@​dependabot[bot])
  • 668553d1667110b8b34c7a4a954c3ac4707816ba: build(deps): bump gitpod/workspace-go from d7a41f5 to f37c673 (@​dependabot[bot])
  • d9a5f8cf07fa834c02969fba2128bdb14c0865ff: build(deps): bump golangci/golangci-lint-action from 3.4.0 to 3.5.0 (@​dependabot[bot])
  • 66f96dfacf866f8d2ca686659e964fc535c72f92: build(deps): bump golangci/golangci-lint-action from 3.5.0 to 3.6.0 (@​dependabot[bot])
  • 8b51c39974573c22ba0a14ba1d5a0cd5b50c68fa: build(deps): bump golangci/golangci-lint-action from 3.6.0 to 3.7.0 (@​dependabot[bot])
  • e44f7de374a51cd1228117d43ccedfdcbe50cd73: build(deps): bump goreleaser/goreleaser-action from 4.2.0 to 4.3.0 (@​dependabot[bot])
  • 6360fe1474853e461a6af83fc6214882b4647f09: build(deps): bump goreleaser/goreleaser-action from 4.3.0 to 4.4.0 (@​dependabot[bot])

Others

  • a06990657b338db19fec11a677ea915eea2b5c74: feat(spec1-5): add initial support for spec v1.5 (@​nscuro)
  • 67a7567143eb3373099f100bbe17143239cf5d4e: feat(spec1-5): add licensing, license properties, and license bom-ref (@​nscuro)
  • d2f3bb95bf740da7a6d36c6a1c324356afed5356: feat(spec1-5): add lifecycle support (@​nscuro)
  • eb041b55b2eb8685a37be6f7a9c265fb6528377b: feat(spec1-5): add new component types (@​nscuro)
  • c45ba618028d9f0cb593784e6483f4392a78ff3b: feat(spec1-5): add new external reference types (@​nscuro)
  • d84947d74d7df97f851211bf7b72786e3583b9e3: feat(spec1-5): add support for annotations (@​nscuro)
  • 0ba04965ce8c5df710eb2a1cae1e7546ffb6321b: feat(spec1-5): bump schema to 1.5 for round-trip tests (@​nscuro)
  • 4e20914ebfc2aa80fbe0fa32650567554ebaaf49: misc(dx): add project icon for intellij and goland (@​nscuro)
Commits
  • 83031d6 Merge pull request #117 from CycloneDX/dependabot/github_actions/golangci/gol...
  • 8b51c39 build(deps): bump golangci/golangci-lint-action from 3.6.0 to 3.7.0
  • 0ed4535 Merge pull request #114 from CycloneDX/dependabot/github_actions/goreleaser/g...
  • 6360fe1 build(deps): bump goreleaser/goreleaser-action from 4.3.0 to 4.4.0
  • 5c1db8e Merge pull request #113 from CycloneDX/dependabot/github_actions/actions/setu...
  • d772b54 build(deps): bump actions/setup-go from 4.0.1 to 4.1.0
  • 3d592d2 Merge pull request #112 from CycloneDX/dependabot/docker/gitpod/workspace-go-...
  • 668553d build(deps): bump gitpod/workspace-go from d7a41f5 to f37c673
  • fdeec7e Merge pull request #111 from CycloneDX/idea-project-icon
  • 4e20914 misc(dx): add project icon for intellij and goland
  • Additional commits viewable in compare view


Updates github.com/cenkalti/backoff/v4 from 4.2.0 to 4.2.1

Commits


Updates github.com/containerd/containerd from 1.7.0 to 1.7.6

Release notes

Sourced from github.com/containerd/containerd's releases.

containerd 1.7.6

Welcome to the v1.7.6 release of containerd!

The sixth patch release for containerd 1.7 contains various fixes and updates.

Notable Updates

  • Fix log package for clients overwriting the global logger (#9032)
  • Fix blockfile snapshotter copy on Darwin (#9047)
  • Add support for Linux usernames on non-Linux platforms (#9015)
  • Update Windows platform matcher to invoke stable ABI compability function (#9069)
  • Update Golang to 1.20.8 (#9074)
  • Update push to inherit distribution sources from parent (#9084)

See the changelog for complete list of changes

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors

  • Derek McGowan
  • Kirtana Ashok
  • Phil Estes
  • Akihiro Suda
  • Danny Canter
  • Sebastiaan van Stijn
  • Akhil Mohan
  • Maksym Pavlenko
  • Samuel Karp
  • Wei Fu

Changes

  • [release/1.7] Prepare release notes for 1.7.6 (#9085)
  • [release/1.7] Invoke Stable ABI compatibility function in windows platform matcher (#9069)
    • c7a35ccdc Fix transfer service dependencies:
    • 38d4e506d Invoke Stable ABI compatibility function in windows platform matcher
  • [release/1.7] push: inherit distribution sources from parent (#9084)
    • 5ebf05d97 push: inherit distribution sources from parent
    • d206896dd content: add InfoProvider interface
  • [release/1.7] update to go1.20.8 (#9074)
  • [release/1.7] Update hcsshim tag to v0.11.0 (#9063)
  • [release/1.7] CRI: Support Linux usernames for !linux platforms (#9015)
    • b449440a4 CRI: Support Linux usernames for !linux platforms

... (truncated)

Commits
  • 091922f Merge pull request #9085 from dmcgowan/prepare-1.7.6
  • 8542d0e Merge pull request #9069 from kiashok/portStableAbi-1.7
  • 78874ec Merge pull request #9084 from dmcgowan/backport-1.7-inherit-distribution-sources
  • 3e09c65 Prepare release notes for v1.7.6
  • 5ebf05d push: inherit distribution sources from parent
  • d206896 content: add InfoProvider interface
  • f0d3109 Merge pull request #9074 from thaJeztah/1.7_update_golang_1.20.8
  • 423693d [release/1.7] update to go1.20.8
  • c7a35cc Fix transfer service dependencies:
  • 38d4e50 Invoke Stable ABI compatibility function in windows platform matcher
  • Additional commits viewable in compare view


Updates github.com/docker/distribution from 2.8.2+incompatible to 2.8.3+incompatible

Release notes

Sourced from github.com/docker/distribution's releases.

v2.8.3

What's Changed

New Contributors

Full Changelog: https://github.com/distribution/distribution/compare/v2.8.2...v2.8.3

Commits
  • 4772604 Merge pull request #4088 from distribution/2.8.3-release-notes
  • a4fa699 Add v2.8.3 release notes
  • 1eb2c30 Merge pull request #4068 from milosgajdos/2_8-dont-close-request-body
  • 5e6b1b5 Do not close HTTP request body in HTTP handler
  • 2b76378 Merge pull request #4064 from thaJeztah/2.8_backport_nodigestset
  • 29b00e8 digestset: deprecate package in favor of go-digest/digestset
  • d1ab243 [release/2.8] vendor: github.com/opencontainers/go-digest v1.0.0
  • 11eb419 Merge pull request #4063 from thaJeztah/2.8_backport_switch_reference
  • 3dda067 deprecate reference package, migrate to github.com/distribution/reference
  • da05539 Merge pull request #4053 from thaJeztah/2.8_backport_set-content-type-client-...
  • Additional commits viewable in compare view


Updates github.com/docker/docker-credential-helpers from 0.7.0 to 0.8.0

Release notes

Sourced from github.com/docker/docker-credential-helpers's releases.

v0.8.0

What's Changed

New Contributors

Full Changelog: https://github.com/docker/docker-credential-helpers/compare/v0.7.0...v0.8.0

Commits
  • 8396edb Merge pull request #297 from thaJeztah/update_go_1.20.6
  • a3d1ffc update go to go1.20.6
  • c03d56c deb: update to golang bullseye
  • 7f48455 Merge pull request #294 from thaJeztah/use_designated_domains_step1
  • a90e3fa secretservice: use designated domains in tests (RFC2606)
  • ffb3232 pass: use designated domains in tests (RFC2606)
  • 1050848 client: use designated domains in tests (RFC2606)
  • 7d66ae0 osxkeychain: use designated domains in tests (RFC2606)
  • 13475b4 credentials: use designated domains in tests (RFC2606)
  • 91af1de registryurl: use designated domains in tests (RFC2606)
  • Additional commits viewable in compare view


Updates github.com/go-git/go-billy/v5 from 5.4.1 to 5.5.0

Release notes

Sourced from github.com/go-git/go-billy/v5's releases.

v5.5.0

What's Changed

Full Changelog: https://github.com/go-git/go-billy/compare/v5.4.1...v5.5.0

Commits


Updates github.com/go-git/go-git/v5 from 5.6.1 to 5.9.0

Release notes

Sourced from github.com/go-git/go-git/v5's releases.

v5.9.0

What's Changed

New Contributors

Full Changelog: https://github.com/go-git/go-git/compare/v5.8.1...v5.9.0

v5.8.1

What's Changed

Full Changelog: https://github.com/go-git/go-git/compare/v5.8.0...v5.8.1

v5.8.0

What's Changed

New Contributors

Full Changelog: https://github.com/go-git/go-git/compare/v5.7.0...v5.7.1

... (truncated)

Commits
  • e24e0f7 *: Bump go-billy to v5.5.0
  • ff0bd08 Merge pull request #837 from pjbgf/bump
  • cbbeb49 *: Bump to Go 1.19
  • cf3a75c *: Bump dependencies
  • 51e9c9f Merge pull request #835 from matejrisek/feature/do-not-swallow-vcs-host-errors
  • 5ad72db plumbing: Do not swallow http message coming from VCS providers.
  • 0377d06 Merge pull request #821 from daolis/bug/resetfix
  • 753b0d5 git: worktree, reset ignored files that are part of the worktree: Fixes #819
  • cd3a21c Merge pull request #832 from svghadi/CVE-2023-37788
  • f71a449 *: Bump goproxy dep. Fixes #826
  • Additional commits viewable in compare view


Updates github.com/google/go-containerregistry from 0.15.1 to 0.16.1

Release notes

Sourced from github.com/google/go-containerregistry's releases.

v0.16.1

Release is broken due to goreleaser error, 0.16.1 has the fix

What's Changed

New Contributors

Full Changelog: https://github.com/google/go-containerregistry/compare/v0.15.2...v0.16.1

Container Images

https://gcr.io/go-containerregistry/crane:v0.16.1 https://gcr.io/go-containerregistry/gcrane:v0.16.1

For example:

docker pull gcr.io/go-containerregistry/crane:v0.16.1
docker pull gcr.io/go-containerregistry/gcrane:v0.16.1

v0.16.0

Release is broken due to goreleaser error, 0.16.1 has the fix

... (truncated)

Commits
  • a54d642 fix: pin to goreleaser v1.18 to unblock release (#1763)
  • ea19b57 Return OCI Index content-type for referrers response (#1762)
  • b850480 Drop localhost to support crane registry serve in a container (#1746)
  • fe268b7 Don't try cross-origin mounting against dockerhub (#1743)
  • 2472cbb Let the filesystem handle atomicity (#1735)
  • db818dc Use RWLock, limit scope of locking, write digest first (#1734)
  • 44a6e2e Allow concurrent blob Sets, use RWMutex (#1733)
  • 9010ce1 Correct crane registry help text (#1732)
  • 03ad2ac add --blobs-to-disk to 'crane registry serve' (#1731)
  • 4e4b03a Don't load into daemon if the image already exists (#1724)
  • Additional commits viewable in compare view


Updates github.com/google/uuid from 1.3.0 to 1.3.1

Release notes

Sourced from github.com/google/uuid's releases.

v1.3.1

1.3.1 (2023-08-18)

Bug Fixes

  • Use .EqualFold() to parse urn prefixed UUIDs (#118) (574e687)
Changelog

Sourced from github.com/google/uuid's changelog.

1.3.1 (2023-08-18)

Bug Fixes

  • Use .EqualFold() to parse urn prefixed UUIDs (#118) (574e687)

Changelog

Commits


Updates github.com/jinzhu/copier from 0.3.5 to 0.4.0

Commits
  • 70b1d4e Merge pull request #190 from driventokill/feature/custom-field-names
  • 1835b1a ci: upgrade ci go version >=1.17
  • 5a54efd style: format copier_file_name_mapping_test.go
  • bacc10b fix: use CaseSensitive=true for legacy test cases
  • 7d39583 feat: Support custom file name mappings
  • 83982c7 Merge pull request #177 from jiang4869/master
  • f036a42 Merge pull request #178 from QianChenglong/master
  • 1885609 Merge pull request #180 from driventokill/issue/170
  • 780b83e fix: several issues while copy with custom converter
  • 61dc501 support case-insensitive copy
  • Additional commits viewable in compare view


Updates github.com/klauspost/compress from 1.16.5 to 1.17.0

Release notes

Sourced from github.com/klauspost/compress's releases.

v1.17.0

What's Changed

dependabot[bot] commented 1 year ago

Looks like these dependencies are updatable in another way, so this is no longer needed.