-
Notifications
You must be signed in to change notification settings - Fork 550
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): bump the gomod group across 1 directory with 19 updates #3950
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the gomod group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github.com/sigstore/fulcio](https://github.com/sigstore/fulcio) | `1.6.3` | `1.6.5` | | [github.com/sigstore/rekor](https://github.com/sigstore/rekor) | `1.3.6` | `1.3.7` | | [github.com/sigstore/sigstore-go](https://github.com/sigstore/sigstore-go) | `0.6.1` | `0.6.2` | | [github.com/sigstore/timestamp-authority](https://github.com/sigstore/timestamp-authority) | `1.2.2` | `1.2.3` | | [github.com/theupdateframework/go-tuf/v2](https://github.com/theupdateframework/go-tuf) | `2.0.1` | `2.0.2` | Updates `github.com/sigstore/fulcio` from 1.6.3 to 1.6.5 - [Release notes](https://github.com/sigstore/fulcio/releases) - [Changelog](https://github.com/sigstore/fulcio/blob/main/CHANGELOG.md) - [Commits](sigstore/fulcio@v1.6.3...v1.6.5) Updates `github.com/sigstore/rekor` from 1.3.6 to 1.3.7 - [Release notes](https://github.com/sigstore/rekor/releases) - [Changelog](https://github.com/sigstore/rekor/blob/main/CHANGELOG.md) - [Commits](sigstore/rekor@v1.3.6...v1.3.7) Updates `github.com/sigstore/sigstore` from 1.8.9 to 1.8.10 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.8.9...v1.8.10) Updates `github.com/sigstore/sigstore-go` from 0.6.1 to 0.6.2 - [Release notes](https://github.com/sigstore/sigstore-go/releases) - [Commits](sigstore/sigstore-go@v0.6.1...v0.6.2) Updates `github.com/sigstore/sigstore/pkg/signature/kms/aws` from 1.8.8 to 1.8.10 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.8.8...v1.8.10) Updates `github.com/sigstore/sigstore/pkg/signature/kms/azure` from 1.8.8 to 1.8.10 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.8.8...v1.8.10) Updates `github.com/sigstore/sigstore/pkg/signature/kms/gcp` from 1.8.8 to 1.8.10 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.8.8...v1.8.10) Updates `github.com/sigstore/sigstore/pkg/signature/kms/hashivault` from 1.8.8 to 1.8.10 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.8.8...v1.8.10) Updates `github.com/sigstore/timestamp-authority` from 1.2.2 to 1.2.3 - [Release notes](https://github.com/sigstore/timestamp-authority/releases) - [Changelog](https://github.com/sigstore/timestamp-authority/blob/main/CHANGELOG.md) - [Commits](sigstore/timestamp-authority@v1.2.2...v1.2.3) Updates `github.com/spiffe/go-spiffe/v2` from 2.3.0 to 2.4.0 - [Release notes](https://github.com/spiffe/go-spiffe/releases) - [Changelog](https://github.com/spiffe/go-spiffe/blob/main/CHANGELOG.md) - [Commits](spiffe/go-spiffe@v2.3.0...v2.4.0) Updates `github.com/theupdateframework/go-tuf/v2` from 2.0.1 to 2.0.2 - [Release notes](https://github.com/theupdateframework/go-tuf/releases) - [Changelog](https://github.com/theupdateframework/go-tuf/blob/master/.goreleaser.yaml) - [Commits](theupdateframework/go-tuf@v2.0.1...v2.0.2) Updates `go.step.sm/crypto` from 0.51.2 to 0.54.2 - [Release notes](https://github.com/smallstep/crypto/releases) - [Commits](smallstep/crypto@v0.51.2...v0.54.2) Updates `golang.org/x/crypto` from 0.27.0 to 0.29.0 - [Commits](golang/crypto@v0.27.0...v0.29.0) Updates `golang.org/x/oauth2` from 0.23.0 to 0.24.0 - [Commits](golang/oauth2@v0.23.0...v0.24.0) Updates `golang.org/x/sync` from 0.8.0 to 0.9.0 - [Commits](golang/sync@v0.8.0...v0.9.0) Updates `golang.org/x/term` from 0.24.0 to 0.26.0 - [Commits](golang/term@v0.24.0...v0.26.0) Updates `google.golang.org/api` from 0.196.0 to 0.206.0 - [Release notes](https://github.com/googleapis/google-api-go-client/releases) - [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md) - [Commits](googleapis/google-api-go-client@v0.196.0...v0.206.0) Updates `google.golang.org/protobuf` from 1.34.2 to 1.35.2 Updates `sigs.k8s.io/release-utils` from 0.8.4 to 0.8.5 - [Release notes](https://github.com/kubernetes-sigs/release-utils/releases) - [Commits](kubernetes-sigs/release-utils@v0.8.4...v0.8.5) --- updated-dependencies: - dependency-name: github.com/sigstore/fulcio dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: github.com/sigstore/rekor dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: github.com/sigstore/sigstore dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: github.com/sigstore/sigstore-go dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/aws dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/azure dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/gcp dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/hashivault dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: github.com/sigstore/timestamp-authority dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: github.com/spiffe/go-spiffe/v2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gomod - dependency-name: github.com/theupdateframework/go-tuf/v2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod - dependency-name: go.step.sm/crypto dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gomod - dependency-name: golang.org/x/crypto dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gomod - dependency-name: golang.org/x/oauth2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gomod - dependency-name: golang.org/x/sync dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gomod - dependency-name: golang.org/x/term dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gomod - dependency-name: google.golang.org/api dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gomod - dependency-name: google.golang.org/protobuf dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gomod - dependency-name: sigs.k8s.io/release-utils dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gomod ... Signed-off-by: dependabot[bot] <[email protected]>
dependabot
bot
added
dependencies
Pull requests that update a dependency file
go
Pull requests that update Go code
labels
Dec 2, 2024
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the gomod group with 5 updates in the / directory:
1.6.3
1.6.5
1.3.6
1.3.7
0.6.1
0.6.2
1.2.2
1.2.3
2.0.1
2.0.2
Updates
github.com/sigstore/fulcio
from 1.6.3 to 1.6.5Release notes
Sourced from github.com/sigstore/fulcio's releases.
Changelog
Sourced from github.com/sigstore/fulcio's changelog.
Commits
7920be2
Add CHANGELOG for v1.6.5 (#1835)ab24f1c
use go1.23.2 (#1834)8b77b21
Bump chainguard.dev/sdk in the all group across 1 directory (#1833)50cc9ca
Bump github.com/prometheus/common from 0.59.1 to 0.60.0 (#1832)f3c069d
Bump golang from 1.23.1 to 1.23.2 in the all group (#1828)85bf1df
Bump the all group with 4 updates (#1829)04f761b
Bump github.com/spiffe/go-spiffe/v2 from 2.3.0 to 2.4.0 (#1831)a2cba3e
fallback to json default cfg path if yaml does not exist (#1810)c07462d
extend TLS cert used in tests to 100 year expiration (#1826)df65c59
Include IDP type and subject domain in configuration API response (#1824)Updates
github.com/sigstore/rekor
from 1.3.6 to 1.3.7Release notes
Sourced from github.com/sigstore/rekor's releases.
Changelog
Sourced from github.com/sigstore/rekor's changelog.
Commits
4caadbc
changelog for v1.3.7 (#2284)9fddf00
log request body on 500 error to aid debugging (#2283)92584b7
remove unneeded value in log message (#2282)56ea4b5
Add error message when computing consistency proof (#2278)3eb84f9
build(deps): Bump the all group with 2 updates28aa29c
build(deps): Bump google/cloud-sdk from 500.0.0 to 501.0.0d7e2d1d
build(deps): Bump codecov/codecov-action from 4.6.0 to 5.0.2a018e78
build(deps): Bump google.golang.org/api from 0.205.0 to 0.206.038d5f67
build(deps): Bump golang fromd56c3e0
to73f06be
ded5cd1
build(deps): Bump google.golang.org/api from 0.204.0 to 0.205.0Updates
github.com/sigstore/sigstore
from 1.8.9 to 1.8.10Release notes
Sourced from github.com/sigstore/sigstore's releases.
Commits
305ff9e
bump to go 1.22.8 (#1865)d88a949
build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (#1860)cfde863
build(deps): Bump the gomod group across 1 directory with 3 updates (#1859)e928a84
build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#1861)66f05db
build(deps): Bump google.golang.org/api in /pkg/signature/kms/gcp (#1862)f0978ed
build(deps): Bump the all group with 2 updates (#1863)9398b12
build(deps): Bump the all group in /test/e2e with 2 updates (#1864)bd8ee68
Mark TUF client as deprecated (#1858)c59dfa0
build(deps): Bump golang.org/x/crypto from 0.25.0 to 0.28.0 (#1852)bde3e53
build(deps): Bump golang.org/x/term from 0.22.0 to 0.25.0 (#1851)Updates
github.com/sigstore/sigstore-go
from 0.6.1 to 0.6.2Release notes
Sourced from github.com/sigstore/sigstore-go's releases.
Commits
0726854
Bump golang.org/x/crypto from 0.26.0 to 0.27.0 (#289)8c0e75b
Use sentinel errors bundle validation invalidateBundle
func (#291)Updates
github.com/sigstore/sigstore/pkg/signature/kms/aws
from 1.8.8 to 1.8.10Release notes
Sourced from github.com/sigstore/sigstore/pkg/signature/kms/aws's releases.
Commits
305ff9e
bump to go 1.22.8 (#1865)d88a949
build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (#1860)cfde863
build(deps): Bump the gomod group across 1 directory with 3 updates (#1859)e928a84
build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#1861)66f05db
build(deps): Bump google.golang.org/api in /pkg/signature/kms/gcp (#1862)f0978ed
build(deps): Bump the all group with 2 updates (#1863)9398b12
build(deps): Bump the all group in /test/e2e with 2 updates (#1864)bd8ee68
Mark TUF client as deprecated (#1858)c59dfa0
build(deps): Bump golang.org/x/crypto from 0.25.0 to 0.28.0 (#1852)bde3e53
build(deps): Bump golang.org/x/term from 0.22.0 to 0.25.0 (#1851)Updates
github.com/sigstore/sigstore/pkg/signature/kms/azure
from 1.8.8 to 1.8.10Release notes
Sourced from github.com/sigstore/sigstore/pkg/signature/kms/azure's releases.
Commits
305ff9e
bump to go 1.22.8 (#1865)d88a949
build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (#1860)cfde863
build(deps): Bump the gomod group across 1 directory with 3 updates (#1859)e928a84
build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#1861)66f05db
build(deps): Bump google.golang.org/api in /pkg/signature/kms/gcp (#1862)f0978ed
build(deps): Bump the all group with 2 updates (#1863)9398b12
build(deps): Bump the all group in /test/e2e with 2 updates (#1864)bd8ee68
Mark TUF client as deprecated (#1858)c59dfa0
build(deps): Bump golang.org/x/crypto from 0.25.0 to 0.28.0 (#1852)bde3e53
build(deps): Bump golang.org/x/term from 0.22.0 to 0.25.0 (#1851)Updates
github.com/sigstore/sigstore/pkg/signature/kms/gcp
from 1.8.8 to 1.8.10Release notes
Sourced from github.com/sigstore/sigstore/pkg/signature/kms/gcp's releases.
Commits
305ff9e
bump to go 1.22.8 (#1865)d88a949
build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (#1860)cfde863
build(deps): Bump the gomod group across 1 directory with 3 updates (#1859)e928a84
build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#1861)66f05db
build(deps): Bump google.golang.org/api in /pkg/signature/kms/gcp (#1862)f0978ed
build(deps): Bump the all group with 2 updates (#1863)9398b12
build(deps): Bump the all group in /test/e2e with 2 updates (#1864)bd8ee68
Mark TUF client as deprecated (#1858)c59dfa0
build(deps): Bump golang.org/x/crypto from 0.25.0 to 0.28.0 (#1852)bde3e53
build(deps): Bump golang.org/x/term from 0.22.0 to 0.25.0 (#1851)Updates
github.com/sigstore/sigstore/pkg/signature/kms/hashivault
from 1.8.8 to 1.8.10Release notes
Sourced from github.com/sigstore/sigstore/pkg/signature/kms/hashivault's releases.
Commits
305ff9e
bump to go 1.22.8 (#1865)d88a949
build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (#1860)cfde863
build(deps): Bump the gomod group across 1 directory with 3 updates (#1859)e928a84
build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#1861)66f05db
build(deps): Bump google.golang.org/api in /pkg/signature/kms/gcp (#1862)f0978ed
build(deps): Bump the all group with 2 updates (#1863)9398b12
build(deps): Bump the all group in /test/e2e with 2 updates (#1864)bd8ee68
Mark TUF client as deprecated (#1858)c59dfa0
build(deps): Bump golang.org/x/crypto from 0.25.0 to 0.28.0 (#1852)bde3e53
build(deps): Bump golang.org/x/term from 0.22.0 to 0.25.0 (#1851)Updates
github.com/sigstore/timestamp-authority
from 1.2.2 to 1.2.3Release notes
Sourced from github.com/sigstore/timestamp-authority's releases.
... (truncated)
Commits
b3b3209
Bump the gomod group across 1 directory with 8 updates (#828)2cbf49e
Bump golang from 1.22.6 to 1.23.1 in the docker group (#825)5707a1a
bump github/codeql-action from 3.26.8 to 3.26.9 in the actions group (#832)7a56c89
chore: bump go to use v1.23 (#831)4253b65
Bump github/codeql-action from 3.26.7 to 3.26.8 in the actions group (#830)e97ea9d
Bump github/codeql-action from 3.26.6 to 3.26.7 in the actions group (#829)5499788
Bump actions/upload-artifact from 4.3.6 to 4.4.0 in the actions group (#822)deefc7c
Bump github/codeql-action from 3.26.5 to 3.26.6 in the actions group (#819)b242d2c
Bump github/codeql-action from 3.26.4 to 3.26.5 in the actions group (#818)d447b2a
Bump the actions group with 2 updates (#817)Updates
github.com/spiffe/go-spiffe/v2
from 2.3.0 to 2.4.0Release notes
Sourced from github.com/spiffe/go-spiffe/v2's releases.
Changelog
Sourced from github.com/spiffe/go-spiffe/v2's changelog.
Commits
84d40aa
v2.4.0 changelog (#304)7e5a279
feat: add a WithDefaultJWTSVIDPicker source option (#301)1b87745
Bump google.golang.org/grpc from 1.64.0 to 1.67.1 in /v2 (#303)bfb7d34
Add custom backoff strategy option (#302)51299b0
Bump github.com/go-jose/go-jose/v4 from 4.0.2 to 4.0.4 in /v2 (#293)Updates
github.com/theupdateframework/go-tuf/v2
from 2.0.1 to 2.0.2Release notes
Sourced from github.com/theupdateframework/go-tuf/v2's releases.
Commits
4eb06c8
Error in case the delegated role is missing from the snapshot (#652)Updates
go.step.sm/crypto
from 0.51.2 to 0.54.2Commits
74dea0b
Merge pull request #631 from smallstep/mariano/mackms-tagsd01bccd
Remove debug comments05f8a4b
Allow to retry with no tags when loading privatekeys3a8464f
Merge pull request #630 from smallstep/mariano/mackms-conversions9882b2b
Fix cgo data conversion for bytes and strings96300f0
Merge pull request #626 from smallstep/dependabot/go_modules/google.golang.or...a215423
Merge pull request #625 from smallstep/dependabot/go_modules/github.com/aws/a...558b9f3
Bump google.golang.org/api from 0.204.0 to 0.205.0e2b707d
Bump github.com/aws/aws-sdk-go-v2/config from 1.28.1 to 1.28.3a9a4170
Merge pull request #627 from smallstep/dependabot/go_modules/golang.org/x/sys...Updates
golang.org/x/crypto
from 0.27.0 to 0.29.0Commits
6018723
go.mod: update golang.org/x dependencies71ed71b
README: don't recommend go get750a45f
sha3: add MarshalBinary, AppendBinary, and UnmarshalBinary36b1725
sha3: avoid trailing permutation80ea76e
sha3: fix padding for long cSHAKE parametersc17aa50
sha3: avoid buffer copy7cfb916
ssh: return unexpected msg error when server fails keyboard-interactive auth ...b61b08d
chacha20: extend ppc64le support to ppc646c21748
internal/poly1305: extend ppc64le support to ppc64adef4cc
go.mod: update golang.org/x dependenciesUpdates
golang.org/x/oauth2
from 0.23.0 to 0.24.0Commits
22134a4
README: don't recommend go getUpdates
golang.org/x/sync
from 0.8.0 to 0.9.0Commits
151027e
README: don't recommend go getUpdates
golang.org/x/term
from 0.24.0 to 0.26.0Commits
b725e36
go.mod: update golang.org/x dependencies54df7da
README: don't recommend go get9d5441a
go.mod: update golang.org/x dependenciesUpdates
google.golang.org/api
from 0.196.0 to 0.206.0<det...
Description has been truncated