pomerium / ingress-controller

Pomerium Kubernetes Ingress Controller
https://pomerium.com
Apache License 2.0
22 stars 11 forks source link

build(deps): bump the go group with 10 updates #931

Closed dependabot[bot] closed 5 months ago

dependabot[bot] commented 5 months ago

Bumps the go group with 10 updates:

Package From To
github.com/cenkalti/backoff/v4 4.2.1 4.3.0
github.com/go-playground/validator/v10 10.18.0 10.19.0
github.com/open-policy-agent/opa 0.62.1 0.63.0
github.com/pomerium/pomerium 0.25.1-0.20240327152537-ecbd84b7df91 0.25.1
k8s.io/api 0.29.0 0.29.3
k8s.io/apiextensions-apiserver 0.29.0 0.29.3
k8s.io/apimachinery 0.29.2 0.29.3
k8s.io/apiserver 0.29.0 0.29.3
k8s.io/client-go 0.29.0 0.29.3
sigs.k8s.io/controller-tools 0.11.4 0.14.0

Updates github.com/cenkalti/backoff/v4 from 4.2.1 to 4.3.0

Commits
  • 720b789 remove travis badge from readme
  • a83af7f feat(backoff): Add functional options for ExponentialBackOff Closes #136
  • See full diff in compare view


Updates github.com/go-playground/validator/v10 from 10.18.0 to 10.19.0

Release notes

Sourced from github.com/go-playground/validator/v10's releases.

Release 10.19.0

What was added?

Added opt-in ability to validate private fields in PR, thanks @​nikolaianohyn via the new WithPrivateFieldValidation option when initializing validator.

Commits


Updates github.com/open-policy-agent/opa from 0.62.1 to 0.63.0

Changelog

Sourced from github.com/open-policy-agent/opa's changelog.

0.63.0

This release contains a mix of features, performance improvements, and bugfixes.

Runtime, Tooling, SDK

Topdown and Rego

Docs + Website + Ecosystem

Miscellaneous

  • chore: Remove repetitive words (#6644) authored by @​occupyhabit
  • Dependency updates; notably:
    • build(deps): bump github.com/containerd/containerd from 1.7.13 to 1.7.14
    • build(deps): bump github.com/golang/protobuf from 1.5.3 to 1.5.4
    • build(deps): bump google.golang.org/grpc from 1.62.0 to 1.62.1
Commits
  • bb30b15 Prepare v0.63.0 release (#6656)
  • b705d5b docs: Clear up some uses of future keywords (#6653)
  • a7d27ef Add Rego v1 keywords (#6649)
  • d3a4a87 plugins/rest: Update service name while generating signature
  • 630b746 download: Surface bundle download errors via debug logging
  • ea0dc02 Adding a new function crypto.x509.parse_and_verify_certificates_with_options....
  • 5f16f4a plugins/rest: Add support to get temp creds via AssumeRole
  • 6c08d3f docs: Update delta bundle patch doc for remove op
  • d6c8c1b chore: remove repetitive words
  • 143a8e6 topdown: Fixing overactive Early Exit suppression
  • Additional commits viewable in compare view


Updates github.com/pomerium/pomerium from 0.25.1-0.20240327152537-ecbd84b7df91 to 0.25.1

Release notes

Sourced from github.com/pomerium/pomerium's releases.

v0.25.1

What's Changed

Changed

Full Changelog: https://github.com/pomerium/pomerium/compare/v0.25.0...v0.25.1

Commits


Updates k8s.io/api from 0.29.0 to 0.29.3

Commits
  • 067c548 Update dependencies to v0.29.3 tag
  • f98a503 Merge pull request #123763 from liggitt/proto-1.29
  • 1e39277 [CVE-2024-24786] Bump github.com/golang/protobuf v1.5.4, google.golang.org/pr...
  • f5eca04 Merge pull request #122959RomanBednar/automated-cherry-pick-of-#122728
  • fd1786f flag PersistentVolumeLastPhaseTransitionTime field as beta
  • a48c0a4 Merge pull request #122429 from MadhavJivrajani/tools-bump-129
  • 656e18f .*: bump golang.org/x/tools to v0.16.1
  • See full diff in compare view


Updates k8s.io/apiextensions-apiserver from 0.29.0 to 0.29.3

Commits
  • d5d0a65 Update dependencies to v0.29.3 tag
  • 4b0ba87 Merge pull request #123763 from liggitt/proto-1.29
  • d499055 [CVE-2024-24786] Bump github.com/golang/protobuf v1.5.4, google.golang.org/pr...
  • f14ac67 Merge pull request #122369cici37/automated-cherry-pick-of-#122193
  • eccd921 Merge pull request #122429 from MadhavJivrajani/tools-bump-129
  • 06c0a98 Merge pull request #122343jpbetz/automated-cherry-pick-of-#122329
  • 4a82ea0 .*: bump golang.org/x/tools to v0.16.1
  • 2d320bc Wire in field dropping for CRDs
  • 510e9f2 Keep presence cost to 0 to ensure backward compatibility.
  • See full diff in compare view


Updates k8s.io/apimachinery from 0.29.2 to 0.29.3

Commits
  • d794766 Merge pull request #123763 from liggitt/proto-1.29
  • 9b124b1 [CVE-2024-24786] Bump github.com/golang/protobuf v1.5.4, google.golang.org/pr...
  • See full diff in compare view


Updates k8s.io/apiserver from 0.29.0 to 0.29.3

Commits


Updates k8s.io/client-go from 0.29.0 to 0.29.3

Commits
  • 46588f2 Update dependencies to v0.29.3 tag
  • 403b37f Merge pull request #123763 from liggitt/proto-1.29
  • 92199ae [CVE-2024-24786] Bump github.com/golang/protobuf v1.5.4, google.golang.org/pr...
  • baea19d Merge pull request #122429 from MadhavJivrajani/tools-bump-129
  • 3373afd .*: bump golang.org/x/tools to v0.16.1
  • See full diff in compare view


Updates sigs.k8s.io/controller-tools from 0.11.4 to 0.14.0

Release notes

Sourced from sigs.k8s.io/controller-tools's releases.

v0.14.0

What's Changed

Dependency bumps

New Contributors

Full Changelog: https://github.com/kubernetes-sigs/controller-tools/compare/v0.13.0...v0.14.0

v0.13.0

What's Changed

Dependency bumps

... (truncated)

Commits
  • 5ac2d0e Merge pull request #872 from Neo2308/feature/master/bump-to-k8s-0.29.0
  • 6177f44 Bump k8s deps to v0.29.0
  • 419500a Merge pull request #870 from qinqon/crd-description-respect-multiline-comment...
  • 7488021 crd: Respect multiline comments at godocs
  • 943de6e Merge pull request #869 from kubernetes-sigs/dependabot/go_modules/golang.org...
  • ef54a04 :seedling: Bump golang.org/x/tools from 0.16.0 to 0.16.1
  • 8e85f22 Merge pull request #867 from kubernetes-sigs/dependabot/github_actions/kubern...
  • e184937 :seedling: Bump kubernetes-sigs/kubebuilder-release-tools
  • 72d3440 Merge pull request #863 from Danil-Grigorev/support-empty-maps-lists
  • 498f1db Merge pull request #866 from kubernetes-sigs/dependabot/go_modules/golang.org...
  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
wasaga commented 5 months ago

we need exclude kubernetes related packages from dependabot

wasaga commented 5 months ago

@dependabot rebase

dependabot[bot] commented 5 months ago

Looks like these dependencies are updatable in another way, so this is no longer needed.