chore(deps): bump the security-updates group with 18 updates#153
Open
dependabot[bot] wants to merge 1 commit into
Open
chore(deps): bump the security-updates group with 18 updates#153dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the security-updates group with 18 updates: | Package | From | To | | --- | --- | --- | | [github.com/BurntSushi/toml](https://github.com/BurntSushi/toml) | `1.5.0` | `1.6.0` | | [github.com/gin-gonic/gin](https://github.com/gin-gonic/gin) | `1.11.0` | `1.12.0` | | [github.com/go-sql-driver/mysql](https://github.com/go-sql-driver/mysql) | `1.9.2` | `1.10.0` | | [github.com/mattn/go-isatty](https://github.com/mattn/go-isatty) | `0.0.20` | `0.0.22` | | [github.com/prometheus/client_golang](https://github.com/prometheus/client_golang) | `1.22.0` | `1.23.2` | | [go.etcd.io/etcd/api/v3](https://github.com/etcd-io/etcd) | `3.5.21` | `3.6.11` | | [go.etcd.io/etcd/client/v3](https://github.com/etcd-io/etcd) | `3.5.21` | `3.6.11` | | [go.etcd.io/etcd/server/v3](https://github.com/etcd-io/etcd) | `3.5.21` | `3.6.11` | | [go.opentelemetry.io/contrib/propagators/autoprop](https://github.com/open-telemetry/opentelemetry-go-contrib) | `0.63.0` | `0.68.0` | | [go.opentelemetry.io/otel/bridge/opentracing](https://github.com/open-telemetry/opentelemetry-go) | `1.36.0` | `1.43.0` | | [go.opentelemetry.io/otel/exporters/jaeger](https://github.com/open-telemetry/opentelemetry-go) | `1.16.0` | `1.17.0` | | [go.opentelemetry.io/otel/exporters/otlp/otlptrace](https://github.com/open-telemetry/opentelemetry-go) | `1.38.0` | `1.43.0` | | [go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc](https://github.com/open-telemetry/opentelemetry-go) | `1.38.0` | `1.43.0` | | [go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp](https://github.com/open-telemetry/opentelemetry-go) | `1.36.0` | `1.43.0` | | [go.uber.org/zap](https://github.com/uber-go/zap) | `1.27.0` | `1.28.0` | | [golang.org/x/sys](https://github.com/golang/sys) | `0.42.0` | `0.45.0` | | [gorm.io/gorm](https://github.com/go-gorm/gorm) | `1.30.0` | `1.31.1` | | [k8s.io/client-go](https://github.com/kubernetes/client-go) | `0.34.1` | `0.36.1` | Updates `github.com/BurntSushi/toml` from 1.5.0 to 1.6.0 - [Release notes](https://github.com/BurntSushi/toml/releases) - [Commits](BurntSushi/toml@v1.5.0...v1.6.0) Updates `github.com/gin-gonic/gin` from 1.11.0 to 1.12.0 - [Release notes](https://github.com/gin-gonic/gin/releases) - [Changelog](https://github.com/gin-gonic/gin/blob/master/CHANGELOG.md) - [Commits](gin-gonic/gin@v1.11.0...v1.12.0) Updates `github.com/go-sql-driver/mysql` from 1.9.2 to 1.10.0 - [Release notes](https://github.com/go-sql-driver/mysql/releases) - [Changelog](https://github.com/go-sql-driver/mysql/blob/master/CHANGELOG.md) - [Commits](go-sql-driver/mysql@v1.9.2...v1.10.0) Updates `github.com/mattn/go-isatty` from 0.0.20 to 0.0.22 - [Commits](mattn/go-isatty@v0.0.20...v0.0.22) Updates `github.com/prometheus/client_golang` from 1.22.0 to 1.23.2 - [Release notes](https://github.com/prometheus/client_golang/releases) - [Changelog](https://github.com/prometheus/client_golang/blob/main/CHANGELOG.md) - [Commits](prometheus/client_golang@v1.22.0...v1.23.2) Updates `go.etcd.io/etcd/api/v3` from 3.5.21 to 3.6.11 - [Release notes](https://github.com/etcd-io/etcd/releases) - [Commits](etcd-io/etcd@v3.5.21...v3.6.11) Updates `go.etcd.io/etcd/client/v3` from 3.5.21 to 3.6.11 - [Release notes](https://github.com/etcd-io/etcd/releases) - [Commits](etcd-io/etcd@v3.5.21...v3.6.11) Updates `go.etcd.io/etcd/server/v3` from 3.5.21 to 3.6.11 - [Release notes](https://github.com/etcd-io/etcd/releases) - [Commits](etcd-io/etcd@v3.5.21...v3.6.11) Updates `go.opentelemetry.io/contrib/propagators/autoprop` from 0.63.0 to 0.68.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go-contrib/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go-contrib@zpages/v0.63.0...zpages/v0.68.0) Updates `go.opentelemetry.io/otel/bridge/opentracing` from 1.36.0 to 1.43.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.36.0...v1.43.0) Updates `go.opentelemetry.io/otel/exporters/jaeger` from 1.16.0 to 1.17.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.16.0...v1.17.0) Updates `go.opentelemetry.io/otel/exporters/otlp/otlptrace` from 1.38.0 to 1.43.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.38.0...v1.43.0) Updates `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc` from 1.38.0 to 1.43.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.38.0...v1.43.0) Updates `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp` from 1.36.0 to 1.43.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.36.0...v1.43.0) Updates `go.uber.org/zap` from 1.27.0 to 1.28.0 - [Release notes](https://github.com/uber-go/zap/releases) - [Changelog](https://github.com/uber-go/zap/blob/master/CHANGELOG.md) - [Commits](uber-go/zap@v1.27.0...v1.28.0) Updates `golang.org/x/sys` from 0.42.0 to 0.45.0 - [Commits](golang/sys@v0.42.0...v0.45.0) Updates `gorm.io/gorm` from 1.30.0 to 1.31.1 - [Release notes](https://github.com/go-gorm/gorm/releases) - [Commits](go-gorm/gorm@v1.30.0...v1.31.1) Updates `k8s.io/client-go` from 0.34.1 to 0.36.1 - [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md) - [Commits](kubernetes/client-go@v0.34.1...v0.36.1) --- updated-dependencies: - dependency-name: github.com/BurntSushi/toml dependency-version: 1.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: github.com/gin-gonic/gin dependency-version: 1.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: github.com/go-sql-driver/mysql dependency-version: 1.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: github.com/mattn/go-isatty dependency-version: 0.0.22 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security-updates - dependency-name: github.com/prometheus/client_golang dependency-version: 1.23.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: go.etcd.io/etcd/api/v3 dependency-version: 3.6.11 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: go.etcd.io/etcd/client/v3 dependency-version: 3.6.11 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: go.etcd.io/etcd/server/v3 dependency-version: 3.6.11 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: go.opentelemetry.io/contrib/propagators/autoprop dependency-version: 0.68.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: go.opentelemetry.io/otel/bridge/opentracing dependency-version: 1.43.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: go.opentelemetry.io/otel/exporters/jaeger dependency-version: 1.17.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace dependency-version: 1.43.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc dependency-version: 1.43.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp dependency-version: 1.43.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: go.uber.org/zap dependency-version: 1.28.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: golang.org/x/sys dependency-version: 0.45.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: gorm.io/gorm dependency-version: 1.31.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates - dependency-name: k8s.io/client-go dependency-version: 0.36.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security-updates ... Signed-off-by: dependabot[bot] <support@github.com>
|
|
|
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 0 |
| Duplication | 0 |
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps the security-updates group with 18 updates:
1.5.01.6.01.11.01.12.01.9.21.10.00.0.200.0.221.22.01.23.23.5.213.6.113.5.213.6.113.5.213.6.110.63.00.68.01.36.01.43.01.16.01.17.01.38.01.43.01.38.01.43.01.36.01.43.01.27.01.28.00.42.00.45.01.30.01.31.10.34.10.36.1Updates
github.com/BurntSushi/tomlfrom 1.5.0 to 1.6.0Release notes
Sourced from github.com/BurntSushi/toml's releases.
Commits
5253492Enable TOML 1.1 by default (#457)e954445Reject duplicate arrays (#455)6b16cbdUpdate toml-test test cases from upstream (#456)011fa2bEnsure constant format strings in wf calls4b439bfRemove itemNila473c12Add test for out of range float64b535ff8Add some boring tests for lex.go6011ef0Remove unreachable condition in lexTableNameStartc8ca9e6Remove unreachable condition1121f81Make tomlv read from stdinUpdates
github.com/gin-gonic/ginfrom 1.11.0 to 1.12.0Release notes
Sourced from github.com/gin-gonic/gin's releases.
... (truncated)
Changelog
Sourced from github.com/gin-gonic/gin's changelog.
Commits
73726dcdocs: update documentation to reflect Go version changes (#4552)e292e5cdocs: document and finalize Gin v1.12.0 release (#4551)ae3f524ci: update Go version support to 1.25+ across CI and docs (#4550)38534e2chore(deps): bump golang.org/x/net from 0.50.0 to 0.51.0 (#4548)472d086fix(tree): panic in findCaseInsensitivePathRec with RedirectFixedPath (#4535)fb25834test(context): use http.StatusContinue constant instead of magic number 100 (...6f1d5fetest(render): add comprehensive error handling tests (#4541)5c00df8fix(render): write content length in Data.Render (#4206)db30908chore(logger): allow skipping query string output (#4547)ba093d1chore(binding): upgrade bson dependency to mongo-driver v2 (#4549)Updates
github.com/go-sql-driver/mysqlfrom 1.9.2 to 1.10.0Release notes
Sourced from github.com/go-sql-driver/mysql's releases.
... (truncated)
Changelog
Sourced from github.com/go-sql-driver/mysql's changelog.
Commits
a065b60release v1.10.0 (#1765)09e4187modernize (#1764)6c44a9aEnhance interpolateParams to correctly handle placeholders (#1732)688ce56Update supported Go version to 1.24–1.26 (#1763)118d07fBump filippo.io/edwards25519 from 1.1.1 to 1.2.0 (#1756)d6b2d3eConsolidate Dependabot update noise by grouping weekly dependency PRs (#1762)037dfd8Fix getSystemVar buffer reuse (#1754)900f330Bump actions/checkout from 4 to 6 (#1758)ab9e380fix staticcheck error (#1761)f298c66Bump actions/setup-go from 5 to 6 (#1757)Updates
github.com/mattn/go-isattyfrom 0.0.20 to 0.0.22Commits
9a68506Fix isCygwinPipeName to accept Windows 7 trailing suffix (#90)4237fb1Update Go test matrix to current versions (1.24-1.26)433c12bUpdate GitHub Actions to latest versions1cf5589Add wasip1 and wasip2 to build constraints in isatty_others.go1237245Update dependencies: go 1.15 -> 1.21, golang.org/x/sys v0.6.0 -> v0.28.0ac9c88dFix typo in comment: undocomented -> undocumented8b7124eAdd availability check for NtQueryObject in init08d0313Fix isCygwinPipeName to reject names with extra trailing tokensUpdates
github.com/prometheus/client_golangfrom 1.22.0 to 1.23.2Release notes
Sourced from github.com/prometheus/client_golang's releases.
... (truncated)
Changelog
Sourced from github.com/prometheus/client_golang's changelog.
Commits
8179a56Cut v1.23.2 (#1870)4142b59Merge pull request #1869 from prometheus/arve/upgrade-common4ff40f0Cut v1.23.1 (#1867)989b029Upgrade to prometheus/common v0.66 (#1866)e4b2208Cut v1.23.0 (#1848)d9492afcut v1.23.0-rc.1 (#1842)aeae8a0Cut v1.23.0-rc.0 (#1837)b157309Update common Prometheus files (#1832)a704e28build(deps): bump the github-actions group with 3 updates (#1826)c774311Fix errNotImplemented reference (#1835)Updates
go.etcd.io/etcd/api/v3from 3.5.21 to 3.6.11Release notes
Sourced from go.etcd.io/etcd/api/v3's releases.
... (truncated)
Commits
ec166e2version: bump up to 3.6.11d671fd0Merge pull request #21685 from ahrtr/20260429_auth_3.6633de82Fix the 'read via PrevKv' and 'Put with lease' in TXN bypass rbac check issuefbbd0a1Add an integration test to reproduce the issue of PutWithLease in a TXN bypas...3fe5746Add an integration test case to reproduce the read via PrevKv bypass rbac che...16a8a36Merge pull request #21681 from ahrtr/20260428_auth_refactorc387fa5Get all Put related auth check into a separate function 'checkPutAuth'20e6f23move function CheckTxnAuth from package txn to apply7d4b175Merge pull request #21667 from ahrtr/20260426_add_memberbc2482bMerge pull request #21668 from ahrtr/20260426_dep_3.6Updates
go.etcd.io/etcd/client/v3from 3.5.21 to 3.6.11Release notes
Sourced from go.etcd.io/etcd/client/v3's releases.
... (truncated)
Commits
ec166e2version: bump up to 3.6.11d671fd0Merge pull request #21685 from ahrtr/20260429_auth_3.6633de82Fix the 'read via PrevKv' and 'Put with lease' in TXN bypass rbac check issuefbbd0a1Add an integration test to reproduce the issue of PutWithLease in a TXN bypas...3fe5746Add an integration test case to reproduce the read via PrevKv bypass rbac che...16a8a36Merge pull request #21681 from ahrtr/20260428_auth_refactorc387fa5Get all Put related auth check into a separate function 'checkPutAuth'20e6f23move function CheckTxnAuth from package txn to apply7d4b175Merge pull request #21667 from ahrtr/20260426_add_memberbc2482bMerge pull request #21668 from ahrtr/20260426_dep_3.6Updates
go.etcd.io/etcd/server/v3from 3.5.21 to 3.6.11Release notes
Sourced from go.etcd.io/etcd/server/v3's releases.
... (truncated)
Commits
ec166e2version: bump up to 3.6.11d671fd0Merge pull request #21685 from ahrtr/20260429_auth_3.6633de82Fix the 'read via PrevKv' and 'Put with lease' in TXN bypass rbac check issuefbbd0a1Add an integration test to reproduce the issue of PutWithLease in a TXN bypas...3fe5746Add an integration test case to reproduce the read via PrevKv bypass rbac che...16a8a36Merge pull request #21681 from ahrtr/20260428_auth_refactorc387fa5Get all Put related auth check into a separate function 'checkPutAuth'20e6f23move function CheckTxnAuth from package txn to apply7d4b175Merge pull request #21667 from ahrtr/20260426_add_memberbc2482bMerge pull request #21668 from ahrtr/20260426_dep_3.6Updates
go.opentelemetry.io/contrib/propagators/autopropfrom 0.63.0 to 0.68.0Release notes
Sourced from go.opentelemetry.io/contrib/propagators/autoprop's releases.