-
Notifications
You must be signed in to change notification settings - Fork 154
Bump the all group across 1 directory with 9 updates #1302
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
Hi @dependabot[bot]. Thanks for your PR. I'm waiting for a tektoncd member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
@dependabot rebase |
|
/approve |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: PuneetPunamiya The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Bumps the all group with 4 updates in the / directory: [github.com/in-toto/attestation](https://github.com/in-toto/attestation), [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign), [github.com/tektoncd/pipeline](https://github.com/tektoncd/pipeline) and [golang.org/x/crypto](https://github.com/golang/crypto). Updates `github.com/in-toto/attestation` from 1.1.0 to 1.1.1 - [Release notes](https://github.com/in-toto/attestation/releases) - [Commits](in-toto/attestation@v1.1.0...v1.1.1) Updates `github.com/sigstore/cosign/v2` from 2.4.1 to 2.4.2 - [Release notes](https://github.com/sigstore/cosign/releases) - [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md) - [Commits](sigstore/cosign@v2.4.1...v2.4.2) Updates `github.com/sigstore/rekor` from 1.3.8 to 1.3.9 - [Release notes](https://github.com/sigstore/rekor/releases) - [Changelog](https://github.com/sigstore/rekor/blob/main/CHANGELOG.md) - [Commits](sigstore/rekor@v1.3.8...v1.3.9) Updates `github.com/spiffe/go-spiffe/v2` from 2.4.0 to 2.5.0 - [Release notes](https://github.com/spiffe/go-spiffe/releases) - [Changelog](https://github.com/spiffe/go-spiffe/blob/main/CHANGELOG.md) - [Commits](spiffe/go-spiffe@v2.4.0...v2.5.0) Updates `github.com/tektoncd/pipeline` from 0.66.0 to 0.68.0 - [Release notes](https://github.com/tektoncd/pipeline/releases) - [Changelog](https://github.com/tektoncd/pipeline/blob/main/releases.md) - [Commits](tektoncd/pipeline@v0.66.0...v0.68.0) Updates `golang.org/x/crypto` from 0.32.0 to 0.33.0 - [Commits](golang/crypto@v0.32.0...v0.33.0) Updates `golang.org/x/exp` from 0.0.0-20240909161429-701f63a606c0 to 0.0.0-20241108190413-2d47ceb2692f - [Commits](https://github.com/golang/exp/commits) Updates `google.golang.org/grpc` from 1.69.4 to 1.70.0 - [Release notes](https://github.com/grpc/grpc-go/releases) - [Commits](grpc/grpc-go@v1.69.4...v1.70.0) Updates `google.golang.org/protobuf` from 1.36.3 to 1.36.4 --- updated-dependencies: - dependency-name: github.com/in-toto/attestation dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/sigstore/cosign/v2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/sigstore/rekor dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/spiffe/go-spiffe/v2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: github.com/tektoncd/pipeline dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: golang.org/x/crypto dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: golang.org/x/exp dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: google.golang.org/grpc dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: google.golang.org/protobuf dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all ... Signed-off-by: dependabot[bot] <[email protected]>
eaa28f5 to
56b6b09
Compare
|
/lgtm |
Bumps the all group with 4 updates in the / directory: github.com/in-toto/attestation, github.com/sigstore/cosign/v2, github.com/tektoncd/pipeline and golang.org/x/crypto.
Updates
github.com/in-toto/attestationfrom 1.1.0 to 1.1.1Release notes
Sourced from github.com/in-toto/attestation's releases.
Commits
7017ad8Regenerate attestation libraries (#435)808ca43Merge pull request #417 from kpauljoseph/in-toto-v0.2-provenance2358a9cMerge pull request #427 from puerco/expose-algos6e0b70aMerge pull request #434 from puerco/vulnsv02-proto4d9125dMerge pull request #408 from lumjjb/update-vuln-02e474a1fFix typo in vulns02 example72054e5Fix inconsistencies in vulnsv2 proto vs spec4a4ddf5add slsa provenance predicate v0.2a50a5a1Expose known algorithms11ca4fcRegenerate attestation libraries (#430)Updates
github.com/sigstore/cosign/v2from 2.4.1 to 2.4.2Release notes
Sourced from github.com/sigstore/cosign/v2's releases.
Changelog
Sourced from github.com/sigstore/cosign/v2's changelog.
Commits
b6df9c7update v2.4.2 changelog (#4045)ff13ba4chore(deps): bump github.com/open-policy-agent/opa from 0.68.0 to 1.1.0 (#4036)4dc18ddtest against newer k8s, scaffolding release (#4044)e4ff8e2chore(deps): bump cuelang.org/go from 0.11.2 to 0.12.0 (#4035)cced656fix warning message from golangci-lint (#4043)486937bchore(deps): move github.com/xanzy/go-gitlab to gitlab.com/gitlab-org/api/cli...9f142a5chore(deps): bump github.com/sigstore/sigstore-go (#4034)4937bcachore(deps): bump the gomod group across 1 directory with 2 updates (#4042)a71220echore(deps): bump google.golang.org/api from 0.218.0 to 0.219.0 (#4038)fcf13ebchore(deps): bump sigs.k8s.io/release-utils from 0.9.0 to 0.11.0 (#4040)Updates
github.com/sigstore/rekorfrom 1.3.8 to 1.3.9Release notes
Sourced from github.com/sigstore/rekor's releases.
Changelog
Sourced from github.com/sigstore/rekor's changelog.
Commits
b67ee82build(deps): Bump google.golang.org/grpc from 1.69.4 to 1.70.040f29babuild(deps): Bump golang from51a6466to8c10f212497b42build(deps): Bump google/cloud-sdk from 506.0.0 to 507.0.0ac42c19build(deps): Bump google.golang.org/api from 0.217.0 to 0.218.010e8115build(deps): Bump the all group with 3 updates2f182a1build(deps): Bump google.golang.org/protobuf in the all groupf3db95bCache checkpoint for inactive shards (#2332)1cb78cabuild(deps): Bump google/cloud-sdk from 505.0.0 to 506.0.0b68f6bbbuild(deps): Bump google.golang.org/api from 0.216.0 to 0.217.015c696cbuild(deps): Bump github.com/tink-crypto/tink-go/v2 from 2.2.0 to 2.3.0Updates
github.com/spiffe/go-spiffe/v2from 2.4.0 to 2.5.0Release notes
Sourced from github.com/spiffe/go-spiffe/v2's releases.
Changelog
Sourced from github.com/spiffe/go-spiffe/v2's changelog.
Commits
dd15542Changelog for 2.5.0 (#326)f1afca7Export function to get target from address (#321)078393fBump google.golang.org/grpc from 1.67.1 to 1.70.0 in /v2 (#324)3a87d63Upgrade to go1.22 (#325)896d311Bump golang.org/x/net from 0.28.0 to 0.33.0 in /v2 (#322)49cafabBump golang.org/x/crypto from 0.26.0 to 0.31.0 in /v2 (#323)d5cb2fcBump google.golang.org/protobuf from 1.34.2 to 1.36.1 in /v2 (#317)b82bceaBump github.com/stretchr/testify from 1.9.0 to 1.10.0 in /v2 (#312)7c29672Bump github.com/zeebo/errs from 1.3.0 to 1.4.0 in /v2 (#308)87cfecfdoc: minor doc updates (#295)Updates
github.com/tektoncd/pipelinefrom 0.66.0 to 0.68.0Release notes
Sourced from github.com/tektoncd/pipeline's releases.
... (truncated)
Changelog
Sourced from github.com/tektoncd/pipeline's changelog.
... (truncated)
Commits
c6d38c9test: check for circular dependency in stepaction validation8df0a96fix: reference params in default values, allow chained referencescc7f613build(deps): bump github.com/google/cel-go from 0.22.1 to 0.23.1f6259fdbuild(deps): bump the all group in /tekton with 2 updates3f8855afix(computeresource/tasklevel): Fixed a bug where abnormal calculations cause...7021f7bFix deprecated golangci-lint configurationcef86d1fix: inline error check and assert invalid step result ref error8777a96docs: parameter substitution precedence68d09e3fix: check for duplicates after applying the substitutions7d5a534test: invalid step result referenceUpdates
golang.org/x/cryptofrom 0.32.0 to 0.33.0Commits
9290511go.mod: update golang.org/x dependenciesfa5273ex509roots/fallback: update bundlea8ea4bessh: add ServerConfig.PreAuthConnCallback, ServerPreAuthConn (banner) interface71d3a4cacme: support challenges that require the ACME client to send a non-empty JSO...Updates
golang.org/x/expfrom 0.0.0-20240909161429-701f63a606c0 to 0.0.0-20241108190413-2d47ceb2692fCommits
Updates
google.golang.org/grpcfrom 1.69.4 to 1.70.0Release notes
Sourced from google.golang.org/grpc's releases.
Commits
98a0092Change version to 1.70.0 (#7984)bf380deCherrypick #7998, #8011, #8010 into 1.70.x (#8028)54b3eb9experimental/credentials: Add credentials that don't enforce ALPN (#7980) (#8...62b9185clustetresolver: Copy endpoints.Addresses slice from DNS updates to avoid dat...724f450examples/features/csm_observability: use helloworld client and server instead...e8d5febrbac: add method name to :path in headers (#7965)e912015cleanup: Fix usages of non-constant format strings (#7959)681334acleanup: replace dial with newclient (#7943)063d352internal/resolver: introduce a new resolver to handle target URI and proxy ad...10c7e13outlierdetection: Support health listener for ejection updates (#7908)Updates
google.golang.org/protobuffrom 1.36.3 to 1.36.4Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions