Bump the go_modules group across 1 directory with 11 updates#2
Open
dependabot[bot] wants to merge 1 commit intomasterfrom
Open
Bump the go_modules group across 1 directory with 11 updates#2dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps the go_modules group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github.com/docker/docker](https://github.com/docker/docker) | `20.10.24+incompatible` | `25.0.13+incompatible` | | [github.com/jackc/pgx/v4](https://github.com/jackc/pgx) | `4.18.1` | `4.18.2` | | [github.com/jackc/pgx/v5](https://github.com/jackc/pgx) | `5.3.1` | `5.5.2` | | [github.com/dvsekhvalnov/jose2go](https://github.com/dvsekhvalnov/jose2go) | `1.5.0` | `1.7.0` | | [github.com/golang-jwt/jwt/v4](https://github.com/golang-jwt/jwt) | `4.4.2` | `4.5.2` | Updates `github.com/docker/docker` from 20.10.24+incompatible to 25.0.13+incompatible - [Release notes](https://github.com/docker/docker/releases) - [Commits](moby/moby@v20.10.24...v25.0.13) Updates `github.com/jackc/pgx/v4` from 4.18.1 to 4.18.2 - [Changelog](https://github.com/jackc/pgx/blob/v4.18.2/CHANGELOG.md) - [Commits](jackc/pgx@v4.18.1...v4.18.2) Updates `github.com/jackc/pgx/v5` from 5.3.1 to 5.5.2 - [Changelog](https://github.com/jackc/pgx/blob/master/CHANGELOG.md) - [Commits](jackc/pgx@v5.3.1...v5.5.2) Updates `golang.org/x/oauth2` from 0.8.0 to 0.30.0 - [Commits](golang/oauth2@v0.8.0...v0.30.0) Updates `github.com/dvsekhvalnov/jose2go` from 1.5.0 to 1.7.0 - [Commits](dvsekhvalnov/jose2go@v1.5...v1.7.0) Updates `github.com/golang-jwt/jwt/v4` from 4.4.2 to 4.5.2 - [Release notes](https://github.com/golang-jwt/jwt/releases) - [Changelog](https://github.com/golang-jwt/jwt/blob/main/VERSION_HISTORY.md) - [Commits](golang-jwt/jwt@v4.4.2...v4.5.2) Updates `github.com/jackc/pgproto3/v2` from 2.3.2 to 2.3.3 - [Commits](jackc/pgproto3@v2.3.2...v2.3.3) Updates `golang.org/x/crypto` from 0.9.0 to 0.41.0 - [Commits](golang/crypto@v0.9.0...v0.41.0) Updates `golang.org/x/net` from 0.10.0 to 0.43.0 - [Commits](golang/net@v0.10.0...v0.43.0) Updates `google.golang.org/grpc` from 1.55.0 to 1.75.0 - [Release notes](https://github.com/grpc/grpc-go/releases) - [Commits](grpc/grpc-go@v1.55.0...v1.75.0) Updates `google.golang.org/protobuf` from 1.30.0 to 1.36.8 --- updated-dependencies: - dependency-name: github.com/docker/docker dependency-version: 25.0.13+incompatible dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/jackc/pgx/v4 dependency-version: 4.18.2 dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/jackc/pgx/v5 dependency-version: 5.5.2 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/oauth2 dependency-version: 0.30.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/dvsekhvalnov/jose2go dependency-version: 1.7.0 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/golang-jwt/jwt/v4 dependency-version: 4.5.2 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/jackc/pgproto3/v2 dependency-version: 2.3.3 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/crypto dependency-version: 0.41.0 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.43.0 dependency-type: indirect dependency-group: go_modules - dependency-name: google.golang.org/grpc dependency-version: 1.75.0 dependency-type: indirect dependency-group: go_modules - dependency-name: google.golang.org/protobuf dependency-version: 1.36.8 dependency-type: indirect dependency-group: go_modules ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the go_modules group with 5 updates in the / directory:
20.10.24+incompatible25.0.13+incompatible4.18.14.18.25.3.15.5.21.5.01.7.04.4.24.5.2Updates
github.com/docker/dockerfrom 20.10.24+incompatible to 25.0.13+incompatibleRelease notes
Sourced from github.com/docker/docker's releases.
... (truncated)
Commits
165516eMerge pull request #50551 from corhere/backport-25.0/libn/all-the-overlay-fixesf099e91libnetwork: handle coalesced endpoint eventsbace1b8libnetwork/d/overlay: handle coalesced peer updatesf9e5429libn/d/win/overlay: dedupe NetworkDB definitionsfc3df55libn/d/overlay: extract hashable address typesb22872alibnetwork/driverapi: make EventNotify optionalc7e17aelibn/networkdb: report prev value in update eventsd60c71alibnetwork/d/overlay: fix logical race conditionsad54b8flibn/d/overlay: fix encryption race conditions8075689libn/d/overlay: inline secMapWalk into only callerUpdates
github.com/jackc/pgx/v4from 4.18.1 to 4.18.2Changelog
Sourced from github.com/jackc/pgx/v4's changelog.
Commits
14690dfUpdate changelog779548eUpdate required Go version to 1.1780e9662Update github.com/jackc/pgconn to v1.14.30bf9ac3Fix erroneous test casef94eb0eAlways wrap arguments in parentheses in the SQL sanitizer826a892Fix SQL injection via line comment creation in simple protocol7d882f9Fix *dbTx.Exec not checking if it is already closed1d07b8bgo mod tidyUpdates
github.com/jackc/pgx/v5from 5.3.1 to 5.5.2Changelog
Sourced from github.com/jackc/pgx/v5's changelog.
... (truncated)
Commits
b7de418Release v5.5.2b99e2bbDocument max read and write sizes for large objects52f2151Allow NamedArgs to start with underscoredfb6489fix typo in doc.go9346d48fix OpenDBFromPool example1fdd170feat(pgproto3): expose MaxExpectedBodyLen and ActualBodyLen in ExceededMaxBod...f654d61Make note about possible parse config error message redaction change5d26bbeMake pgconn.ConnectError and pgconn.ParseConfigError public44768b5fix a typo in config_test.go6f2ce92Upgrade golang.org/x/crypto to v0.17.0Updates
golang.org/x/oauth2from 0.8.0 to 0.30.0Commits
cf14319oauth2: fix expiration time window check32d34efinternal: include clientID in auth style cache key2d34e30oauth2: replace a magic number with AuthStyleUnknown696f7b3all: modernize with doc links and any471209boauth2: drop dependency on go-cmp6968da2oauth2: sync Token.ExpiresIn from internal Tokend2c4e0aoauth2: context instead of golang.org/x/net/context in doc883dc3cendpoints: add various endpoints from stale CLs1c06e87all: make use of oauth.Token.ExpiresIn65c15a3oauth2: remove extra periodUpdates
github.com/dvsekhvalnov/jose2gofrom 1.5.0 to 1.7.0Commits
0a0673dMerge pull request #34 from dvsekhvalnov/issue-33-deflate-limitc3fff7cdocse51b47fdocsc7dde52fixing workflowa194baaadded go versions and OSs to matrixf31cfc6fixing yaml1a4ba55added matrix to workflowd2baff2go workflowb14c81aadded limitation for deflate decompression stream48ba0b7Merge pull request #32 from dvsekhvalnov/issue-31-security-tuningUpdates
github.com/golang-jwt/jwt/v4from 4.4.2 to 4.5.2Release notes
Sourced from github.com/golang-jwt/jwt/v4's releases.
Commits
2f0e9adBackporting 0951d18 to v47b1c1c0Merge commit from fork9358574Allow strict base64 decoding (#259)2f0984aUsingtparsefor nicer CI test display (#251)2101c1fNo pointer embedding in the example (#255)35053d4Removed unneeded if statement (#241)0c4e387Add doc comment to ParseWithClaims (#232)bfea432Include https://github.com/golang-jwt/jwe in README (#229)d81acbfBump matrix to support latest go version (go1.19) (#231)fdaf0ebImplement a BearerExtractor (#226)Updates
github.com/jackc/pgproto3/v2from 2.3.2 to 2.3.3Commits
945c212Backport fixes from pgx v5Updates
golang.org/x/cryptofrom 0.9.0 to 0.41.0Commits
ef5341bgo.mod: update golang.org/x dependenciesb999374acme: fix pebble subprocess output data racec247deax509roots/fallback: store bundle certs directly in DER1fda731acme: increase pebble test waitForServer attempts1b4c3d2x509roots/fallback: update bundleb903b53acme: capture pebble test subprocess stdout/stderr459a9dbgo.mod: update golang.org/x dependencies74e709assh: add AlgorithmNegotiationErrorb3790b8acme: fix TLSALPN01ChallengeCert for IP address identifiers1dc4269acme: add Pebble integration testingUpdates
golang.org/x/netfrom 0.10.0 to 0.43.0Commits
e74bc31go.mod: update golang.org/x dependenciesaf6926ehttp2: remove references to defunct http2.golang.org test server76358aago.mod: update golang.org/x dependencies6e41caego.mod: update golang.org/x dependencies15f7d40http2: correctly wrap ErrFrameTooLarge in Framer.ReadFrameef33bc0internal/http3: use bubbled context in synctest tests919c6bchttp2: use an array instead of a map in typeFrameParserbae01a7trace: add missing td tag7d6e62ago.mod: update golang.org/x dependenciesea0c1d9internal/timeseries: use built-in max/min to simplify the codeUpdates
google.golang.org/grpcfrom 1.55.0 to 1.75.0Release notes
Sourced from google.golang.org/grpc's releases.
... (truncated)
Commits
b9788efChange version to 1.75.0 (#8493)2bd74b2credentials: fix behavior of grpc.WithAuthority and credential handshake prec...9fa3267xds: remove xds client fallback environment variable (#8482)62ec29fgrpc: Fix cardinality violations in non-client streaming RPCs. (#8385)85240a5stats: change non-standard units to annotations (#8481)ac13172update deps (#8478)0a895bcexamples/opentelemetry: use experimental metrics in example (#8441)8b61e8fxdsclient: do not process updates from closed server channels (#8389)7238ab1Allow empty nodeID (#8476)9186ebdcleanup: use slices.Equal to simplify code (#8472)Updates
google.golang.org/protobuffrom 1.30.0 to 1.36.8Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.