-
Notifications
You must be signed in to change notification settings - Fork 2.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): bump the common group with 11 updates #8110
Conversation
Bumps the common group with 11 updates: | Package | From | To | | --- | --- | --- | | [github.com/containerd/containerd/v2](https://github.com/containerd/containerd) | `2.0.0` | `2.0.1` | | [github.com/gocsaf/csaf/v3](https://github.com/gocsaf/csaf) | `3.1.0` | `3.1.1` | | [github.com/secure-systems-lab/go-securesystemslib](https://github.com/secure-systems-lab/go-securesystemslib) | `0.8.0` | `0.9.0` | | [github.com/sigstore/rekor](https://github.com/sigstore/rekor) | `1.3.6` | `1.3.7` | | [github.com/tetratelabs/wazero](https://github.com/tetratelabs/wazero) | `1.8.1` | `1.8.2` | | [github.com/zclconf/go-cty](https://github.com/zclconf/go-cty) | `1.15.0` | `1.15.1` | | [golang.org/x/net](https://github.com/golang/net) | `0.31.0` | `0.32.0` | | [golang.org/x/xerrors](https://github.com/golang/xerrors) | `0.0.0-20231012003039-104605ab7028` | `0.0.0-20240716161551-93cc26a95ae9` | | [k8s.io/api](https://github.com/kubernetes/api) | `0.31.2` | `0.32.0` | | [k8s.io/utils](https://github.com/kubernetes/utils) | `0.0.0-20240711033017-18e509b52bc8` | `0.0.0-20241104100929-3ea5e8cea738` | | [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) | `1.34.1` | `1.34.2` | Updates `github.com/containerd/containerd/v2` from 2.0.0 to 2.0.1 - [Release notes](https://github.com/containerd/containerd/releases) - [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md) - [Commits](containerd/containerd@v2.0.0...v2.0.1) Updates `github.com/gocsaf/csaf/v3` from 3.1.0 to 3.1.1 - [Release notes](https://github.com/gocsaf/csaf/releases) - [Changelog](https://github.com/gocsaf/csaf/blob/main/docs/release-process-hints.md) - [Commits](gocsaf/csaf@v3.1.0...v3.1.1) Updates `github.com/secure-systems-lab/go-securesystemslib` from 0.8.0 to 0.9.0 - [Release notes](https://github.com/secure-systems-lab/go-securesystemslib/releases) - [Commits](secure-systems-lab/go-securesystemslib@v0.8.0...v0.9.0) Updates `github.com/sigstore/rekor` from 1.3.6 to 1.3.7 - [Release notes](https://github.com/sigstore/rekor/releases) - [Changelog](https://github.com/sigstore/rekor/blob/main/CHANGELOG.md) - [Commits](sigstore/rekor@v1.3.6...v1.3.7) Updates `github.com/tetratelabs/wazero` from 1.8.1 to 1.8.2 - [Release notes](https://github.com/tetratelabs/wazero/releases) - [Commits](tetratelabs/wazero@v1.8.1...v1.8.2) Updates `github.com/zclconf/go-cty` from 1.15.0 to 1.15.1 - [Release notes](https://github.com/zclconf/go-cty/releases) - [Changelog](https://github.com/zclconf/go-cty/blob/main/CHANGELOG.md) - [Commits](zclconf/go-cty@v1.15.0...v1.15.1) Updates `golang.org/x/net` from 0.31.0 to 0.32.0 - [Commits](golang/net@v0.31.0...v0.32.0) Updates `golang.org/x/xerrors` from 0.0.0-20231012003039-104605ab7028 to 0.0.0-20240716161551-93cc26a95ae9 - [Commits](https://github.com/golang/xerrors/commits) Updates `k8s.io/api` from 0.31.2 to 0.32.0 - [Commits](kubernetes/api@v0.31.2...v0.32.0) Updates `k8s.io/utils` from 0.0.0-20240711033017-18e509b52bc8 to 0.0.0-20241104100929-3ea5e8cea738 - [Commits](https://github.com/kubernetes/utils/commits) Updates `modernc.org/sqlite` from 1.34.1 to 1.34.2 - [Commits](https://gitlab.com/cznic/sqlite/compare/v1.34.1...v1.34.2) --- updated-dependencies: - dependency-name: github.com/containerd/containerd/v2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common - dependency-name: github.com/gocsaf/csaf/v3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common - dependency-name: github.com/secure-systems-lab/go-securesystemslib dependency-type: direct:production update-type: version-update:semver-minor dependency-group: common - dependency-name: github.com/sigstore/rekor dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common - dependency-name: github.com/tetratelabs/wazero dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common - dependency-name: github.com/zclconf/go-cty dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common - dependency-name: golang.org/x/net dependency-type: direct:production update-type: version-update:semver-minor dependency-group: common - dependency-name: golang.org/x/xerrors dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common - dependency-name: k8s.io/api dependency-type: direct:production update-type: version-update:semver-minor dependency-group: common - dependency-name: k8s.io/utils dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common - dependency-name: modernc.org/sqlite dependency-type: direct:production update-type: version-update:semver-patch dependency-group: common ... Signed-off-by: dependabot[bot] <[email protected]>
I'll take a look: go: github.com/aquasecurity/trivy/pkg/iac/scanners/helm/parser imports
helm.sh/helm/v3/pkg/chartutil imports
k8s.io/client-go/kubernetes/scheme imports
k8s.io/api/coordination/v1alpha1: module k8s.io/api@latest found (v0.32.0), but does not contain package k8s.io/api/coordination/v1alpha1 |
@knqyf263 We need to wait for helm to update |
OK, so can you downgrade k8s.io/api to v0.31.2 and see if it works? You can push the change to this branch. |
This version does not cause conflicts, but |
Adding |
It also updates the minimal version of Go in addition to the toolchain. |
We might want to bump Go in a separate PR. Can you please open it? |
Created #8123 |
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the common group with 11 updates:
2.0.0
2.0.1
3.1.0
3.1.1
0.8.0
0.9.0
1.3.6
1.3.7
1.8.1
1.8.2
1.15.0
1.15.1
0.31.0
0.32.0
0.0.0-20231012003039-104605ab7028
0.0.0-20240716161551-93cc26a95ae9
0.31.2
0.32.0
0.0.0-20240711033017-18e509b52bc8
0.0.0-20241104100929-3ea5e8cea738
1.34.1
1.34.2
Updates
github.com/containerd/containerd/v2
from 2.0.0 to 2.0.1Release notes
Sourced from github.com/containerd/containerd/v2's releases.
... (truncated)
Commits
88aa2f5
Merge pull request #11158 from dmcgowan/prepare-v2.0.1b0ece5d
Prepare release notes for v2.0.1e206c07
Merge pull request #11154 from k8s-infra-cherrypick-robot/cherry-pick-11122-t...fe69570
build(deps): bump actions/attest-build-provenance from 1.4.4 to 2.1.0eb2d0c4
Merge pull request #11153 from k8s-infra-cherrypick-robot/cherry-pick-11130-t...eb2ce68
update xx to v1.6.1 for compatibility with alpine 3.21 and file 5.46+c11f124
Merge pull request #11139 from k8s-infra-cherrypick-robot/cherry-pick-11086-t...8c6dd50
Merge pull request #11151 from k8s-infra-cherrypick-robot/cherry-pick-11104-t...e9004f0
Merge pull request #11146 from k8s-infra-cherrypick-robot/cherry-pick-11135-t...c403b64
Merge pull request #11140 from k8s-infra-cherrypick-robot/cherry-pick-11061-t...Updates
github.com/gocsaf/csaf/v3
from 3.1.0 to 3.1.1Release notes
Sourced from github.com/gocsaf/csaf/v3's releases.
Commits
1daaed2
ensure HTTP requests use proxy env vars (#597)18af28f
Merge pull request #600 from gocsaf/docs-proxy-for-2b8a9803
fix docs link to standard678f232
Merge pull request #593 from gocsaf/add-upload-permission2435abe
Merge pull request #594 from gocsaf/update_go_3rd_party_libs_2024_11_223dc84f3
Merge pull request #598 from gocsaf/docs-readme-12b218084
Update README.md that go paths can be adjusted9495d8b
Update Go 3rd party libsf6d7589
Add required upload permissionsUpdates
github.com/secure-systems-lab/go-securesystemslib
from 0.8.0 to 0.9.0Commits
7d19192
Merge pull request #103 from secure-systems-lab/dependabot/go_modules/golang....21102fa
chore(deps): bump golang.org/x/crypto from 0.30.0 to 0.31.01fb13ff
Merge pull request #102 from secure-systems-lab/dependabot/github_actions/act...4e1c22d
chore(deps): bump actions/setup-go from 5.1.0 to 5.2.0847cabc
Merge pull request #101 from secure-systems-lab/dependabot/go_modules/golang....06fac2f
chore(deps): bump golang.org/x/crypto from 0.29.0 to 0.30.0c1aadb2
Merge pull request #100 from secure-systems-lab/dependabot/go_modules/github....8fef2d7
chore(deps): bump github.com/stretchr/testify from 1.9.0 to 1.10.0c65f6c8
Merge pull request #99 from secure-systems-lab/dependabot/go_modules/golang.o...35b687d
chore(deps): bump golang.org/x/crypto from 0.27.0 to 0.29.0Updates
github.com/sigstore/rekor
from 1.3.6 to 1.3.7Release notes
Sourced from github.com/sigstore/rekor's releases.
Changelog
Sourced from github.com/sigstore/rekor's changelog.
Commits
4caadbc
changelog for v1.3.7 (#2284)9fddf00
log request body on 500 error to aid debugging (#2283)92584b7
remove unneeded value in log message (#2282)56ea4b5
Add error message when computing consistency proof (#2278)3eb84f9
build(deps): Bump the all group with 2 updates28aa29c
build(deps): Bump google/cloud-sdk from 500.0.0 to 501.0.0d7e2d1d
build(deps): Bump codecov/codecov-action from 4.6.0 to 5.0.2a018e78
build(deps): Bump google.golang.org/api from 0.205.0 to 0.206.038d5f67
build(deps): Bump golang fromd56c3e0
to73f06be
ded5cd1
build(deps): Bump google.golang.org/api from 0.204.0 to 0.205.0Updates
github.com/tetratelabs/wazero
from 1.8.1 to 1.8.2Release notes
Sourced from github.com/tetratelabs/wazero's releases.
Commits
610c202
arm64: account for imported functions when encoding relocation islands (#2346)2c4b66b
compiler: require ARMv8.1 (#2345)d25ce10
chore: update action deps (#2344)0a20795
Enable compiler on NetBSD, DragonFly, illumos and Solaris (#2343)e5ba948
Add DragonFly, illumos, Solaris to CI. (#2341)c5e90c5
Add *BSD to CI. (#2338)dc08732
Fix users list (#2334)05b2499
Add Modus to "who's using wazero" list (#2333)c8d0f0a
experimental: clarify memory allocator context is for module instantiation (#...Updates
github.com/zclconf/go-cty
from 1.15.0 to 1.15.1Changelog
Sourced from github.com/zclconf/go-cty's changelog.
Commits
3149f9d
Prepare for v1.15.1 release63279be
Update CHANGELOG.mdda16ad4
function: include marks when returning early with an unknown valueea922e7
Add GitHub's "funding" metadata file7313684
function/stdlib: Even more Distinct testsb843884
function/stdlib: unit tests for Distinct function0b7ccb8
docs: fix little typo in value marks9a4ed1e
Prepare for possible future v1.15.1 releaseUpdates
golang.org/x/net
from 0.31.0 to 0.32.0Commits
285e1cf
go.mod: update golang.org/x dependenciesd0a1049
route: remove unused sizeof* consts on freebsd6e41410
http2: fix benchmarks using common frame read/write functions4be1253
route: change from syscall to x/sys/unixbc37675
http2: limit number of PINGs bundled with RST_STREAMse9cd716
route: fix parse of zero-length sockaddrs in RIBs9a51899
http2: add SETTINGS_ENABLE_CONNECT_PROTOCOL supportUpdates
golang.org/x/xerrors
from 0.0.0-20231012003039-104605ab7028 to 0.0.0-20240716161551-93cc26a95ae9Commits
Updates
k8s.io/api
from 0.31.2 to 0.32.0Commits
e622342
Update dependencies to v0.32.0 tagb0543a3
Merge remote-tracking branch 'origin/master' into release-1.32f6bae9a
Drop use of winreadlinkvolume godebug optionea815d5
Merge remote-tracking branch 'origin/master' into release-1.32c331a79
Revert to go1.22 windows filesystem stdlib behaviorf8e5e36
Merge pull request #128407 from ndixita/pod-level-resources84e0db8
Merge pull request #127857 from Jefftree/cle-v1alpha2cbaf5a0
Merge pull request #128686 from thockin/take_over_pr-125233a503a4f
Merge pull request #128687 from tallclair/allocated-status3f43b5a
Merge pull request #128240 from LionelJouin/KEP-4817Updates
k8s.io/utils
from 0.0.0-20240711033017-18e509b52bc8 to 0.0.0-20241104100929-3ea5e8cea738Commits
Updates
modernc.org/sqlite
from 1.34.1 to 1.34.2Commits
fe367e3
merge dev@2573fa9f, updates #198Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions