chore(deps): Bump the go_modules group with 12 updates#19
Open
dependabot[bot] wants to merge 1 commit into
Open
chore(deps): Bump the go_modules group with 12 updates#19dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the go_modules group with 12 updates: | Package | From | To | | --- | --- | --- | | [github.com/docker/docker](https://github.com/docker/docker) | `24.0.6+incompatible` | `24.0.9+incompatible` | | [github.com/jackc/pgx/v4](https://github.com/jackc/pgx) | `4.18.1` | `4.18.2` | | [github.com/nats-io/nats-server/v2](https://github.com/nats-io/nats-server) | `2.9.9` | `2.9.23` | | [golang.org/x/crypto](https://github.com/golang/crypto) | `0.14.0` | `0.20.0` | | [golang.org/x/net](https://github.com/golang/net) | `0.17.0` | `0.21.0` | | google.golang.org/protobuf | `1.31.0` | `1.33.0` | | [github.com/cloudevents/sdk-go/v2](https://github.com/cloudevents/sdk-go) | `2.14.0` | `2.15.2` | | [github.com/containerd/containerd](https://github.com/containerd/containerd) | `1.7.6` | `1.7.11` | | [github.com/dvsekhvalnov/jose2go](https://github.com/dvsekhvalnov/jose2go) | `1.5.0` | `1.6.0` | | [github.com/jackc/pgproto3/v2](https://github.com/jackc/pgproto3) | `2.3.2` | `2.3.3` | | [github.com/nats-io/nkeys](https://github.com/nats-io/nkeys) | `0.4.5` | `0.4.6` | | [github.com/opencontainers/runc](https://github.com/opencontainers/runc) | `1.1.5` | `1.1.12` | Updates `github.com/docker/docker` from 24.0.6+incompatible to 24.0.9+incompatible - [Release notes](https://github.com/docker/docker/releases) - [Commits](moby/moby@v24.0.6...v24.0.9) Updates `github.com/jackc/pgx/v4` from 4.18.1 to 4.18.2 - [Changelog](https://github.com/jackc/pgx/blob/v4.18.2/CHANGELOG.md) - [Commits](jackc/pgx@v4.18.1...v4.18.2) Updates `github.com/nats-io/nats-server/v2` from 2.9.9 to 2.9.23 - [Release notes](https://github.com/nats-io/nats-server/releases) - [Changelog](https://github.com/nats-io/nats-server/blob/main/.goreleaser.yml) - [Commits](nats-io/nats-server@v2.9.9...v2.9.23) Updates `golang.org/x/crypto` from 0.14.0 to 0.20.0 - [Commits](golang/crypto@v0.14.0...v0.20.0) Updates `golang.org/x/net` from 0.17.0 to 0.21.0 - [Commits](golang/net@v0.17.0...v0.21.0) Updates `google.golang.org/protobuf` from 1.31.0 to 1.33.0 Updates `github.com/cloudevents/sdk-go/v2` from 2.14.0 to 2.15.2 - [Release notes](https://github.com/cloudevents/sdk-go/releases) - [Commits](cloudevents/sdk-go@v2.14.0...v2.15.2) Updates `github.com/containerd/containerd` from 1.7.6 to 1.7.11 - [Release notes](https://github.com/containerd/containerd/releases) - [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md) - [Commits](containerd/containerd@v1.7.6...v1.7.11) Updates `github.com/dvsekhvalnov/jose2go` from 1.5.0 to 1.6.0 - [Commits](dvsekhvalnov/jose2go@v1.5...v1.6.0) Updates `github.com/jackc/pgproto3/v2` from 2.3.2 to 2.3.3 - [Commits](jackc/pgproto3@v2.3.2...v2.3.3) Updates `github.com/nats-io/nkeys` from 0.4.5 to 0.4.6 - [Release notes](https://github.com/nats-io/nkeys/releases) - [Changelog](https://github.com/nats-io/nkeys/blob/main/.goreleaser.yml) - [Commits](nats-io/nkeys@v0.4.5...v0.4.6) Updates `github.com/opencontainers/runc` from 1.1.5 to 1.1.12 - [Release notes](https://github.com/opencontainers/runc/releases) - [Changelog](https://github.com/opencontainers/runc/blob/main/CHANGELOG.md) - [Commits](opencontainers/runc@v1.1.5...v1.1.12) --- updated-dependencies: - dependency-name: github.com/docker/docker dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/jackc/pgx/v4 dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/nats-io/nats-server/v2 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/crypto dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/net dependency-type: direct:production dependency-group: go_modules - dependency-name: google.golang.org/protobuf dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/cloudevents/sdk-go/v2 dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/containerd/containerd dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/dvsekhvalnov/jose2go dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/jackc/pgproto3/v2 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/nats-io/nkeys dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/opencontainers/runc dependency-type: indirect dependency-group: go_modules ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the go_modules group with 12 updates:
24.0.6+incompatible24.0.9+incompatible4.18.14.18.22.9.92.9.230.14.00.20.00.17.00.21.01.31.01.33.02.14.02.15.21.7.61.7.111.5.01.6.02.3.22.3.30.4.50.4.61.1.51.1.12Updates
github.com/docker/dockerfrom 24.0.6+incompatible to 24.0.9+incompatibleRelease notes
Sourced from github.com/docker/docker's releases.
... (truncated)
Commits
fca702dMerge pull request from GHSA-xw73-rw38-6vjcf78a772Merge pull request #47281 from thaJeztah/24.0_backport_bump_containerd_binary...61afffeMerge pull request #47270 from thaJeztah/24.0_backport_bump_runc_binary_1.1.12b38e74cMerge pull request #47276 from thaJeztah/24.0_backport_bump_runc_1.1.12dac5663update containerd binary to v1.7.1320e1af3vendor: github.com/opencontainers/runc v1.1.12858919dupdate runc binary to v1.1.12141ad39Merge pull request #47266 from vvoland/ci-fix-makeps1-templatefail-24db968c6hack/make.ps1: Fix go list pattern61c51fbMerge pull request #47221 from vvoland/pkg-pools-close-noop-24Updates
github.com/jackc/pgx/v4from 4.18.1 to 4.18.2Changelog
Sourced from github.com/jackc/pgx/v4's changelog.
Commits
14690dfUpdate changelog779548eUpdate required Go version to 1.1780e9662Update github.com/jackc/pgconn to v1.14.30bf9ac3Fix erroneous test casef94eb0eAlways wrap arguments in parentheses in the SQL sanitizer826a892Fix SQL injection via line comment creation in simple protocol7d882f9Fix *dbTx.Exec not checking if it is already closed1d07b8bgo mod tidyUpdates
github.com/nats-io/nats-server/v2from 2.9.9 to 2.9.23Release notes
Sourced from github.com/nats-io/nats-server/v2's releases.
... (truncated)
Commits
45436e1Release v2.9.23 (#4652)72ffa38Release v2.9.2305fe77fBackport #4592 to 2.9 (#4651)6a73e68[2.9.x] Bump Travis Go version to 1.20.10 (#4650)8b981a2Backports from v2.10 for v2.9.23 release (#4647)28eb7c0Only setup auto no-auth for $G account iff no authorization block was defined.9f16eddMake sure to not forward a message across a route for dq sub when we are a sp...0ac7895Add in utility to detect and delete any NRG orphans.50722e9When scaling a consumer down make sure to pop the loopAndForwardProposals go ...770cf2eBackport JetStream benchmarks improvements to 2.9.x (#4644)Updates
golang.org/x/cryptofrom 0.14.0 to 0.20.0Commits
0aab8d0all: update go.mod x/net dependency5bead59ocsp: don't use iota for externally defined constants1a86580x/crypto/internal/poly1305: improve sum_ppc64le.s1c981e6ssh/test: don't use DSA keys in integrations tests, update test RSA key62c9f17x509roots/nss: manually exclude a confusingly constrained root405cb3bgo.mod: update golang.org/x dependencies913d3aex509roots/fallback: update bundledbb6ec1ssh/test: skip tests on darwin that fail on the darwin-amd64-longtest LUCI bu...403f699ssh/test: avoid leaking a net.UnixConn in server.TryDialWithAddr055043dgo.mod: update golang.org/x dependenciesUpdates
golang.org/x/netfrom 0.17.0 to 0.21.0Commits
73d21fdgo.mod: update golang.org/x dependencies643fd16html: fix SOLIDUS '/' handling in attribute parsing73e4b50dns/dnsmessage: allow name compression for SRV resource parsingb2208d0internal/quic/qlog: fix typo0d0b98chttp2: avoid goroutine starvation in TestServer_Push_RejectAfterGoAway07e05fdhttp2: remove suspicious uint32->v conversion in frame code26b646equic: avoid deadlock in Endpoint.Closecb5b10fgo.mod: update golang.org/x dependencies689bbc7quic: deflake TestStreamsCreateConcurrencyf12db26internal/quic/cmd/interop: use wget --no-verbose in DockerfileUpdates
google.golang.org/protobuffrom 1.31.0 to 1.33.0Updates
github.com/cloudevents/sdk-go/v2from 2.14.0 to 2.15.2Release notes
Sourced from github.com/cloudevents/sdk-go/v2's releases.
... (truncated)
Commits
de2f283Merge pull request from GHSA-5pf6-2qwx-pxm2c5f8d9dUpdate v2/protocol/http/protocol.goc17d949Avoid modifying the DefaultClient's Transport67e3899Merge pull request #1020 from duglin/oopsf0061e0oops4cc6c2dMerge pull request #1011 from cloudevents/dependabot/bundler/docs/bundler-sec...b6949b0Bump the bundler group across 1 directories with 1 updatedf51395Merge pull request #1016 from cloudevents/dependabot/github_actions/golangci/...1af6e06Bump golangci/golangci-lint-action from 3 to 42574a05Merge pull request #1013 from jafossum/fix-nats-typosUpdates
github.com/containerd/containerdfrom 1.7.6 to 1.7.11Release notes
Sourced from github.com/containerd/containerd's releases.
... (truncated)
Changelog
Sourced from github.com/containerd/containerd's changelog.
... (truncated)
Commits
64b8a81Merge pull request #9491 from dmcgowan/prepare-1.7.11ea5a477Merge pull request #9352 from thaJeztah/1.7_update_golang_1.20.1167d356cMerge pull request from GHSA-7ww5-4wqc-m92cdfae68bPrepare release notes for v1.7.11de6d8a8Merge pull request #9482 from ambarve/sn_cleanup_1.7ed7c689Don't block snapshot garbage collection on Remove failures467de56Merge pull request #9481 from ruiwen-zhao/cri-ud94f8ffMerge pull request #9483 from dmcgowan/backport-1.7-fix-otel-http1fdefddAdd warning for CRIU config usage8e06899Merge pull request #9479 from ruiwen-zhao/cri-api-warningUpdates
github.com/dvsekhvalnov/jose2gofrom 1.5.0 to 1.6.0Commits
48ba0b7Merge pull request #32 from dvsekhvalnov/issue-31-security-tuning05eb007docse0264a2added helper matchers: Alg and Eng0f6c7c3MatchAlg helpercf0a53bdocs2995762docs9a18affdocs675bb14docs8e9e0d1updated p2c limits with new OWASP numbers, docsed5dd96Unit tests for custom 'p2c' headers min/max limitsUpdates
github.com/jackc/pgproto3/v2from 2.3.2 to 2.3.3Commits
945c212Backport fixes from pgx v5Updates
github.com/nats-io/nkeysfrom 0.4.5 to 0.4.6Release notes
Sourced from github.com/nats-io/nkeys's releases.
Commits
62e5d8cMerge pull request #60 from nats-io/0_4_6f63761b[BUMP] release version and dependenciesd2e442eMerge pull request #59 from nats-io/empty58fb9d6Make sure to use byte slice to receive proper copy, otherwise empty public ke...Updates
github.com/opencontainers/runcfrom 1.1.5 to 1.1.12Release notes
Sourced from github.com/opencontainers/runc's releases.
... (truncated)
Changelog
Sourced from github.com/opencontainers/runc's changelog.
... (truncated)
Commits
51d5e94VERSION: release 1.1.122a4ed3emerge 1.1-GHSA-xr7r-f8xq-vfvv into release-1.1e9665f4init: don't special-case logrus fds683ad2flibcontainer: mark all non-stdio fds O_CLOEXEC before spawning initb6633f4cgroup: plug leaks of /sys/fs/cgroup handle284ba30init: close internal fds before execvefbe3eedsetns init: do explicit lookup of execve argument early0994249init: verify after chdir that cwd is inside the container506552aFix File to Close099ff69merge #4177 into opencontainers/runc:release-1.1Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.