-
Notifications
You must be signed in to change notification settings - Fork 94
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): bump the security group with 16 updates #1478
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the security group with 16 updates: | Package | From | To | | --- | --- | --- | | [github.com/containers/image/v5](https://github.com/containers/image) | `5.29.0` | `5.29.2` | | [github.com/google/uuid](https://github.com/google/uuid) | `1.4.0` | `1.6.0` | | [github.com/shirou/gopsutil/v3](https://github.com/shirou/gopsutil) | `3.23.12` | `3.24.1` | | [github.com/vmware-tanzu/velero](https://github.com/vmware-tanzu/velero) | `1.10.3` | `1.13.0` | | [go.opentelemetry.io/otel](https://github.com/open-telemetry/opentelemetry-go) | `1.23.0` | `1.23.1` | | [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) | `1.23.0` | `1.23.1` | | [k8s.io/api](https://github.com/kubernetes/api) | `0.29.1` | `0.29.2` | | [k8s.io/apiextensions-apiserver](https://github.com/kubernetes/apiextensions-apiserver) | `0.29.0` | `0.29.2` | | [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) | `0.29.1` | `0.29.2` | | [k8s.io/apiserver](https://github.com/kubernetes/apiserver) | `0.29.0` | `0.29.2` | | [k8s.io/cli-runtime](https://github.com/kubernetes/cli-runtime) | `0.29.1` | `0.29.2` | | [k8s.io/client-go](https://github.com/kubernetes/client-go) | `0.29.1` | `0.29.2` | | [sigs.k8s.io/controller-runtime](https://github.com/kubernetes-sigs/controller-runtime) | `0.17.0` | `0.17.2` | | [golang.org/x/net](https://github.com/golang/net) | `0.19.0` | `0.21.0` | | [helm.sh/helm/v3](https://github.com/helm/helm) | `3.14.0` | `3.14.1` | | [k8s.io/metrics](https://github.com/kubernetes/metrics) | `0.29.0` | `0.29.2` | Updates `github.com/containers/image/v5` from 5.29.0 to 5.29.2 - [Release notes](https://github.com/containers/image/releases) - [Commits](containers/image@v5.29.0...v5.29.2) Updates `github.com/google/uuid` from 1.4.0 to 1.6.0 - [Release notes](https://github.com/google/uuid/releases) - [Changelog](https://github.com/google/uuid/blob/master/CHANGELOG.md) - [Commits](google/uuid@v1.4.0...v1.6.0) Updates `github.com/shirou/gopsutil/v3` from 3.23.12 to 3.24.1 - [Release notes](https://github.com/shirou/gopsutil/releases) - [Commits](shirou/gopsutil@v3.23.12...v3.24.1) Updates `github.com/vmware-tanzu/velero` from 1.10.3 to 1.13.0 - [Release notes](https://github.com/vmware-tanzu/velero/releases) - [Changelog](https://github.com/vmware-tanzu/velero/blob/main/CHANGELOG.md) - [Commits](vmware-tanzu/velero@v1.10.3...v1.13.0) Updates `go.opentelemetry.io/otel` from 1.23.0 to 1.23.1 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.23.0...v1.23.1) Updates `go.opentelemetry.io/otel/sdk` from 1.23.0 to 1.23.1 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.23.0...v1.23.1) Updates `k8s.io/api` from 0.29.1 to 0.29.2 - [Commits](kubernetes/api@v0.29.1...v0.29.2) Updates `k8s.io/apiextensions-apiserver` from 0.29.0 to 0.29.2 - [Release notes](https://github.com/kubernetes/apiextensions-apiserver/releases) - [Commits](kubernetes/apiextensions-apiserver@v0.29.0...v0.29.2) Updates `k8s.io/apimachinery` from 0.29.1 to 0.29.2 - [Commits](kubernetes/apimachinery@v0.29.1...v0.29.2) Updates `k8s.io/apiserver` from 0.29.0 to 0.29.2 - [Commits](kubernetes/apiserver@v0.29.0...v0.29.2) Updates `k8s.io/cli-runtime` from 0.29.1 to 0.29.2 - [Commits](kubernetes/cli-runtime@v0.29.1...v0.29.2) Updates `k8s.io/client-go` from 0.29.1 to 0.29.2 - [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md) - [Commits](kubernetes/client-go@v0.29.1...v0.29.2) Updates `sigs.k8s.io/controller-runtime` from 0.17.0 to 0.17.2 - [Release notes](https://github.com/kubernetes-sigs/controller-runtime/releases) - [Changelog](https://github.com/kubernetes-sigs/controller-runtime/blob/main/RELEASE.md) - [Commits](kubernetes-sigs/controller-runtime@v0.17.0...v0.17.2) Updates `golang.org/x/net` from 0.19.0 to 0.21.0 - [Commits](golang/net@v0.19.0...v0.21.0) Updates `helm.sh/helm/v3` from 3.14.0 to 3.14.1 - [Release notes](https://github.com/helm/helm/releases) - [Commits](helm/helm@v3.14.0...v3.14.1) Updates `k8s.io/metrics` from 0.29.0 to 0.29.2 - [Commits](kubernetes/metrics@v0.29.0...v0.29.2) --- updated-dependencies: - dependency-name: github.com/containers/image/v5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: github.com/google/uuid dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security - dependency-name: github.com/shirou/gopsutil/v3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security - dependency-name: github.com/vmware-tanzu/velero dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security - dependency-name: go.opentelemetry.io/otel dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: go.opentelemetry.io/otel/sdk dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: k8s.io/api dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: k8s.io/apiextensions-apiserver dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: k8s.io/apimachinery dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: k8s.io/apiserver dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: k8s.io/cli-runtime dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: k8s.io/client-go dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: sigs.k8s.io/controller-runtime dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: golang.org/x/net dependency-type: direct:production update-type: version-update:semver-minor dependency-group: security - dependency-name: helm.sh/helm/v3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security - dependency-name: k8s.io/metrics dependency-type: direct:production update-type: version-update:semver-patch dependency-group: security ... Signed-off-by: dependabot[bot] <[email protected]>
This was referenced Feb 20, 2024
xavpaice
approved these changes
Feb 20, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the security group with 16 updates:
5.29.0
5.29.2
1.4.0
1.6.0
3.23.12
3.24.1
1.10.3
1.13.0
1.23.0
1.23.1
1.23.0
1.23.1
0.29.1
0.29.2
0.29.0
0.29.2
0.29.1
0.29.2
0.29.0
0.29.2
0.29.1
0.29.2
0.29.1
0.29.2
0.17.0
0.17.2
0.19.0
0.21.0
3.14.0
3.14.1
0.29.0
0.29.2
Updates
github.com/containers/image/v5
from 5.29.0 to 5.29.2Release notes
Sourced from github.com/containers/image/v5's releases.
Commits
b799d82
[release-5.29] Bump to v5.29.26cbd4f4
[release-5.29] backport Docker Daemon fix #22602f0d9ae
Merge pull request #2262 from mtrmac/5.29-skopeo-reverseef8a7a5
Use a stable Skopeo branch for testing the stable c/image branchd8bbff8
Merge pull request #2253 from mtrmac/releasing-5.29.1540136f
Bump to v5.29.2-devf7fbc0a
Release 5.29.11b5932f
Merge pull request #2252 from mheon/backport_2209_52947bac8f
Add support for pushing image with unknown digest041e291
Merge pull request #2251 from mtrmac/5.29-dest-branchUpdates
github.com/google/uuid
from 1.4.0 to 1.6.0Release notes
Sourced from github.com/google/uuid's releases.
Changelog
Sourced from github.com/google/uuid's changelog.
Commits
0f11ee6
chore(master): release 1.6.0 (#151)16939da
chore(tests): add strict monotonicity test case for uuid v7. (#154)016b199
fix: fix typo in version 7 uuid documentation (#153)1d8b6ea
ci: set token permissions to github workflows (#143)a2b2b32
fix: Monotonicity in UUIDv7 (#150)c58770e
feat: add Max UUID constant (#149)4d47f8e
chore(master): release 1.5.0 (#145)9ee7366
feat: Validate UUID without creating new UUID (#141)b35aa6a
add uuid version 6 and 7 (#139)Updates
github.com/shirou/gopsutil/v3
from 3.23.12 to 3.24.1Release notes
Sourced from github.com/shirou/gopsutil/v3's releases.
Commits
65b5fa3
Merge pull request #1587 from shirou/dependabot/github_actions/actions/upload...2241397
chore(deps): bump actions/upload-artifact from 4.2.0 to 4.3.09de1a42
Merge pull request #1585 from DataDog/bryce.kahle/os-release-version-id9b6f828
Merge pull request #1584 from DataDog/bryce.kahle/host-platformdc01f63
Merge pull request #1583 from shirou/dependabot/github_actions/actions/cache-...e912ebd
Merge pull request #1580 from jnewmano/patch-1b86b36a
Merge pull request #1586 from shirou/dependabot/github_actions/actions/upload...61758d5
chore(deps): bump actions/upload-artifact from 4.1.0 to 4.2.0d753f78
use VERSION_ID from os-releaseb0d976c
ensure host platform are files and have contentsUpdates
github.com/vmware-tanzu/velero
from 1.10.3 to 1.13.0Release notes
Sourced from github.com/vmware-tanzu/velero's releases.
... (truncated)
Commits
76670e9
Merge pull request #7351 from ywk253100/240124_log25d977e
Log the error details94c7d4b
Merge pull request #7346 from ywk253100/240122_changelog09401c8
Check whether the API resource exists before creating the informer cache981d64a
Merge pull request #7338 from ywk253100/240122_changelog16b8b8d
Move unreleased changelogs to 1.13 changelog9fd73b2
Merge pull request #7339 from ywk253100/240122_log_erroc377e47
Log the error got from the discovery helperf5714cb
[cherry-pick]Do not attempt restore resource with no available GVK in cluster...5ffa121
Merge pull request #7328 from ywk253100/240118_release_nodeUpdates
go.opentelemetry.io/otel
from 1.23.0 to 1.23.1Changelog
Sourced from go.opentelemetry.io/otel's changelog.
Commits
c5b112f
Release v1.23.1/v0.43.2 (#4892)11ebd19
Fix callback registration bug (#4888)Updates
go.opentelemetry.io/otel/sdk
from 1.23.0 to 1.23.1Changelog
Sourced from go.opentelemetry.io/otel/sdk's changelog.
Commits
c5b112f
Release v1.23.1/v0.43.2 (#4892)11ebd19
Fix callback registration bug (#4888)Updates
k8s.io/api
from 0.29.1 to 0.29.2Commits
d473130
Update dependencies to v0.29.2 tagf5eca04
Merge pull request #122959RomanBednar/automated-cherry-pick-of-#122728
fd1786f
flag PersistentVolumeLastPhaseTransitionTime field as betaUpdates
k8s.io/apiextensions-apiserver
from 0.29.0 to 0.29.2Commits
e1d6769
Update dependencies to v0.29.2 tagf14ac67
Merge pull request #122369cici37/automated-cherry-pick-of-#122193
eccd921
Merge pull request #122429 from MadhavJivrajani/tools-bump-12906c0a98
Merge pull request #122343jpbetz/automated-cherry-pick-of-#122329
4a82ea0
.*: bump golang.org/x/tools to v0.16.12d320bc
Wire in field dropping for CRDs510e9f2
Keep presence cost to 0 to ensure backward compatibility.Updates
k8s.io/apimachinery
from 0.29.1 to 0.29.2Commits
Updates
k8s.io/apiserver
from 0.29.0 to 0.29.2Commits
4c39f36
Update dependencies to v0.29.2 tagbd6de43
Merge pull request #123080 from alexzielenski/automated-cherry-pick-of-#12300...b7459bd
bugfix: dont skip reconcile for unchanged policy if last sync failede9b5722
Merge pull request #122369cici37/automated-cherry-pick-of-#122193
037e27f
Merge pull request #122478 from liangyuanpeng/automated-cherry-pick-of-#12162...0065398
Merge pull request #122429 from MadhavJivrajani/tools-bump-129919f1ad
.*: bump golang.org/x/tools to v0.16.1ae9ed66
Address comment02998b3
Keep presence cost to 0 to ensure backward compatibility.5348142
use context for lazy evaluation.Updates
k8s.io/cli-runtime
from 0.29.1 to 0.29.2Commits
d173469
Update dependencies to v0.29.2 tagUpdates
k8s.io/client-go
from 0.29.1 to 0.29.2Commits
62c5e9e
Update dependencies to v0.29.2 tagUpdates
sigs.k8s.io/controller-runtime
from 0.17.0 to 0.17.2Release notes
Sourced from sigs.k8s.io/controller-runtime's releases.
Commits
d0396a3
Merge pull request #2688 from k8s-infra-cherrypick-robot/cherry-pick-2687-to-...565aa5b
Fix lazy rest mapper cache invalidation59c26c0
Merge pull request #2681 from k8s-infra-cherrypick-robot/cherry-pick-2679-to-...984aee6
bug: Fakeclient: Do not consider an apply patch to be a strategic merge patch5923139
Merge pull request #2676 from k8s-infra-cherrypick-robot/cherry-pick-2663-to-...0811bad
Address review comments40b41df
Clean restmapper cache if a version is notFoundUpdates
golang.org/x/net
from 0.19.0 to 0.21.0Commits
73d21fd
go.mod: update golang.org/x dependencies643fd16
html: fix SOLIDUS '/' handling in attribute parsing73e4b50
dns/dnsmessage: allow name compression for SRV resource parsingb2208d0
internal/quic/qlog: fix typo0d0b98c
http2: avoid goroutine starvation in TestServer_Push_RejectAfterGoAway07e05fd
http2: remove suspicious uint32->v conversion in frame code26b646e
quic: avoid deadlock in Endpoint.Closecb5b10f
go.mod: update golang.org/x dependencies689bbc7
quic: deflake TestStreamsCreateConcurrencyf12db26
internal/quic/cmd/interop: use wget --no-verbose in DockerfileUpdates
helm.sh/helm/v3
from 3.14.0 to 3.14.1Release notes
Sourced from helm.sh/helm/v3's releases.
Commits
e8858f8
validation fixUpdates
k8s.io/metrics
from 0.29.0 to 0.29.2Commits
bb460c1
Update dependencies to v0.29.2 tagf0708df
Merge pull request #122429 from MadhavJivrajani/tools-bump-1292c11cd8
.*: bump golang.org/x/tools to v0.16.1Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions