temporalio / sdk-ruby

Temporal Ruby SDK
MIT License
74 stars 7 forks source link

Bump github.com/apache/thrift from 0.0.0-20161221203622-b2a4d4ae21c7 to 0.13.0 in /spec/support/go_server #145

Closed dependabot[bot] closed 4 months ago

dependabot[bot] commented 1 year ago

Bumps github.com/apache/thrift from 0.0.0-20161221203622-b2a4d4ae21c7 to 0.13.0.

Release notes

Sourced from github.com/apache/thrift's releases.

Version 0.13.0

For release 0.13.0 head over to the official release download source: http://thrift.apache.org/download

The assets below are added by Github based on the release tag and they may therefore not match the checkums.

Version 0.12.0

Apache Thrift Release 0.12.0

Version 0.9.3.1

This release is a backport of the security fix for CVE-2018-1320 as documented in THRIFT-4506. The only code change is in Java, and a 0.9.3-1 package was released to Maven Central.

This is marked in GitHub as a pre-release so that it does not become the "latest" release.

Tag to retract lib/go/thrift/go.mod file

The purpose of this tag is to retract the version(s) generated by wrongly added lib/go/thrift/go.mod file. This tag shall not be used in any other way.

To use the latest version of thrift go library, run

go get github.com/apache/thrift@latest

And remove lines containing "github.com/apache/thrift/lib/go/thrift" in your project's go.mod file, if any.

See the following links for more details:

Changelog

Sourced from github.com/apache/thrift's changelog.

0.13.0

New Languages

  • (none)

Deprecated Languages

  • THRIFT-4723 - CSharp and Netcore targets are deprecated and will be removed with the next release) - use NetStd instead.

Removed Languages

  • THRIFT-4719 - Cocoa language was removed) - use swift instead.

Breaking Changes

  • THRIFT-4743 - compiler: removed the plug-in mechanism
  • THRIFT-4720 - cpp: C++03/C++98 support has been removed; also removed boost as a runtime dependency
  • THRIFT-4730 - cpp: BoostThreadFactory, PosixThreadFactory, StdThreadFactory removed
  • THRIFT-4732 - cpp: CMake build changed to use BUILD_SHARED_LIBS
  • THRIFT-4735 - cpp: Removed Qt4 support
  • THRIFT-4740 - cpp: Use std::chrono::duration for timeouts
  • THRIFT-4762 - cpp: TTransport::getOrigin() is now const
  • THRIFT-4702 - java: class org.apache.thrift.AutoExpandingBuffer is no longer public
  • THRIFT-4709 - java: changes to UTF-8 handling require JDK 1.7 at a minimum
  • THRIFT-4712 - java: class org.apache.thrift.ShortStack is no longer public
  • THRIFT-4725 - java: change return type signature of 'process' methods
  • THRIFT-4805 - java: replaced TSaslTransportException with TTransportException
  • THRIFT-2530 - java: TIOStreamTransport's "isOpen" now returns false after "close" is called
  • THRIFT-4675 - js: now uses node-int64 for 64 bit integer constants
  • THRIFT-4841 - delphi: old THTTPTransport is now TMsxmlHTTPTransport
  • THRIFT-4536 - rust: convert from try-from crate to rust stable (1.34+), re-export ordered-float

Known Issues (Blocker or Critical)

  • THRIFT-3877 - C++: library don't work with HTTP (csharp server, cpp client; need cross test enhancement)

As3

  • THRIFT-4784 - Thrift should throw when skipping over unexpected data

Build Process

  • THRIFT-2333 - RPMBUILD: Abort build if user did not disable ruby but ruby build will fail later on
  • THRIFT-4689 - Pull changes from 0.12.0 release branch into master
  • THRIFT-4690 - Update dlang deimos for OpenSSL 1.1 (use 1.1.0h tagged release instead of master)
  • THRIFT-4694 - Upgrade Java to Java 1.8
  • THRIFT-4716 - Create a version alignment tool to make releases easier
  • THRIFT-4760 - Install pkgconfig when using cmake
  • THRIFT-4769 - Change NuGet package to use netstd artifact

... (truncated)

Commits


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/temporalio/sdk-ruby/network/alerts).
CLAassistant commented 1 year ago

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

CLAassistant commented 1 year ago

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

cretz commented 4 months ago

The SDK is undergoing a rewrite/refresh and this PR applied to a previous version and is no longer applicable

dependabot[bot] commented 4 months ago

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.