Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump github.com/xmidt-org/webpa-common/v2 from 2.0.7 to 2.2.1 #63

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 13, 2023

Bumps github.com/xmidt-org/webpa-common/v2 from 2.0.7 to 2.2.1.

Release notes

Sourced from github.com/xmidt-org/webpa-common/v2's releases.

v2.2.1

Changelog

Other Work

  • 67152463736a7238cfaf61e5119f15eaea88d28e: Bump github.com/aws/aws-sdk-go from 1.44.282 to 1.44.283 (#919) (@​dependabot[bot])
  • 56ca22e65cc032a5c951654f4935c6876449b09f: Bump github.com/aws/aws-sdk-go from 1.44.283 to 1.44.284 (#920) (@​dependabot[bot])
  • 932718bafe6a984c509ba4d51998517f3eb1aab0: Bump github.com/aws/aws-sdk-go from 1.44.284 to 1.44.285 (#923) (@​dependabot[bot])
  • 0caa37308ab5c9f58c9aec3fc90ed36aba484a03: Bump github.com/aws/aws-sdk-go from 1.44.285 to 1.44.286 (#924) (@​dependabot[bot])
  • 288ac7039709cfea5853a1b4706d152defa605a2: Bump github.com/aws/aws-sdk-go from 1.44.286 to 1.44.287 (#926) (@​dependabot[bot])
  • 2a9512d84ddec048b15b2315c04ec5a4fc2f72ae: Bump github.com/aws/aws-sdk-go from 1.44.287 to 1.44.288 (#927) (@​dependabot[bot])
  • 12463528d5ef479493c27fc0e38cce70431571e9: Bump github.com/aws/aws-sdk-go from 1.44.288 to 1.44.289 (#928) (@​dependabot[bot])
  • 8de81738a08881dd0837009ee6915871740221a8: Bump github.com/aws/aws-sdk-go from 1.44.289 to 1.44.290 (#930) (@​dependabot[bot])
  • cca089e1e9eb5b5883e62504d9a0eacac294c0bb: Bump github.com/aws/aws-sdk-go from 1.44.290 to 1.44.291 (#931) (@​dependabot[bot])
  • 04f661eea6c7ac4007d7c36f1a5ff67c5460507a: Bump github.com/aws/aws-sdk-go from 1.44.291 to 1.44.292 (#932) (@​dependabot[bot])
  • 61b7dcd7565b68cfcf5907e6903d44f649129ddb: Bump github.com/aws/aws-sdk-go from 1.44.292 to 1.44.293 (#933) (@​dependabot[bot])
  • 51b8452cadecb79aa77cae2776fd026bf1fe4c9d: Bump github.com/aws/aws-sdk-go from 1.44.293 to 1.44.294 (#934) (@​dependabot[bot])
  • 64747ac0f8eb1febb3219bf05f595bdf26d07290: Bump github.com/aws/aws-sdk-go from 1.44.294 to 1.44.296 (#936) (@​dependabot[bot])
  • f659020bcde5d4e40a43ace5db31a1eb88258381: Bump github.com/aws/aws-sdk-go from 1.44.296 to 1.44.298 (#938) (@​dependabot[bot])
  • d3f7f441e9c7b81b4eccc6403024dea9eb87b904: Bump github.com/hashicorp/consul/api from 1.21.0 to 1.22.0 (#929) (@​dependabot[bot])
  • 55fa0f68452b2f43d186286a73d0de05c2557d16: Bump github.com/miekg/dns from 1.1.54 to 1.1.55 (#921) (@​dependabot[bot])
  • 1956094ae80b2ddcc27efa49441db32644b53b04: Bump github.com/prometheus/client_golang from 1.15.1 to 1.16.0 (#918) (@​dependabot[bot])

v2.1.4

Changelog

Other Work

  • 1e6498b62defc90e4faffedbb0b208432d73f25c: Bump github.com/aws/aws-sdk-go from 1.44.277 to 1.44.279 (#911) (@​dependabot[bot])
  • faf4ed6a07bbe8d68b3ef14501898ee01577c4ff: Bump github.com/aws/aws-sdk-go from 1.44.279 to 1.44.281 (#913) (@​dependabot[bot])
  • 69590fd1f6e116da06d50f790a201ecf96dd91a7: Bump github.com/aws/aws-sdk-go from 1.44.281 to 1.44.282 (#915) (@​dependabot[bot])
  • b5f4dee87698f4870ae945b2d644d4c124a63b15: Bump go.uber.org/fx from 1.19.3 to 1.20.0 (#914) (@​dependabot[bot])
  • 26089fef0d7c5c45d901925d3ba80d625a891af8: added a metric for prometheus gauge (@​maurafortino)
  • 389feaf372b723167b1f25c2ea1fe0ee184a3a5f: added prometheus gauges to registry interface (@​maurafortino)
  • 59e2d1d2a71ce0c10dd572ec9905c401f1a798bb: made Metric implement gauge interface (@​maurafortino)
  • 809e6399fd63815f195e96a4a6509325f987af34: removed the pre-register check for prometheus gauge and added gauge from newPrometheusGauge func (@​maurafortino)

v2.1.3

Changelog

Other Work

  • 8adaad4eb4bdc780ece0385cca83f5578acef7f2: Bump github.com/aws/aws-sdk-go from 1.44.263 to 1.44.264 (#890) (@​dependabot[bot])
  • 0d7046b80b252289da630c24e8d7f2e775d034a1: Bump github.com/aws/aws-sdk-go from 1.44.264 to 1.44.265 (#891) (@​dependabot[bot])
  • 99e85bc53bd47edf8714fcb1353a3ec283464289: Bump github.com/aws/aws-sdk-go from 1.44.265 to 1.44.266 (#893) (@​dependabot[bot])
  • 5344d2f193620719c1a21c06548eee946daabe6e: Bump github.com/aws/aws-sdk-go from 1.44.266 to 1.44.267 (#895) (@​dependabot[bot])
  • d3e8760ab0c7c81bf6cde5972bf868036d3767ed: Bump github.com/aws/aws-sdk-go from 1.44.267 to 1.44.268 (#896) (@​dependabot[bot])
  • ae689d7cac165671bad1ada0317262aa7871f866: Bump github.com/aws/aws-sdk-go from 1.44.268 to 1.44.269 (#897) (@​dependabot[bot])
  • d21e3b08037a0319694a58bb69cd3634e4f816e7: Bump github.com/aws/aws-sdk-go from 1.44.269 to 1.44.271 (#899) (@​dependabot[bot])
  • a7561ecdee7bcecfa325a0e6ec76ac198f2e9a7d: Bump github.com/aws/aws-sdk-go from 1.44.271 to 1.44.272 (#902) (@​dependabot[bot])
  • 3b8c8cce69256ef35e166a8cc59125834c967c84: Bump github.com/aws/aws-sdk-go from 1.44.272 to 1.44.273 (#903) (@​dependabot[bot])
  • 7ddb67eeb2549fd2988e6ceed28eda1e816c1c05: Bump github.com/aws/aws-sdk-go from 1.44.273 to 1.44.274 (#905) (@​dependabot[bot])
  • 28e58391e27f6aa4b109f2b756cf53435a13cd01: Bump github.com/aws/aws-sdk-go from 1.44.274 to 1.44.275 (#906) (@​dependabot[bot])
  • 930965f511f4f64a89d6d821aad9c46d318a1123: Bump github.com/aws/aws-sdk-go from 1.44.275 to 1.44.277 (#908) (@​dependabot[bot])
  • 904eacb09a8f28a5d530d4e2d8f4d31bbf7f533d: Bump github.com/hashicorp/consul/api from 1.20.0 to 1.21.0 (#904) (@​dependabot[bot])
  • d84ef8838bde864d2e97066bd5bdf6ff952454d8: Bump github.com/spf13/viper from 1.15.0 to 1.16.0 (#900) (@​dependabot[bot])

... (truncated)

Changelog

Sourced from github.com/xmidt-org/webpa-common/v2's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog and this project adheres to Semantic Versioning.

[Unreleased]

[v2.1.1]

  • Removed gokit/logger and replaced with zap.logger as part of the webpa-common deprecation for scytale, caduceus, and talaria (xmidt-org/webpa-common#655)

[v2.1.0]

Commits
  • f659020 Bump github.com/aws/aws-sdk-go from 1.44.296 to 1.44.298 (#938)
  • 64747ac Bump github.com/aws/aws-sdk-go from 1.44.294 to 1.44.296 (#936)
  • 51b8452 Bump github.com/aws/aws-sdk-go from 1.44.293 to 1.44.294 (#934)
  • 61b7dcd Bump github.com/aws/aws-sdk-go from 1.44.292 to 1.44.293 (#933)
  • 04f661e Bump github.com/aws/aws-sdk-go from 1.44.291 to 1.44.292 (#932)
  • cca089e Bump github.com/aws/aws-sdk-go from 1.44.290 to 1.44.291 (#931)
  • 8de8173 Bump github.com/aws/aws-sdk-go from 1.44.289 to 1.44.290 (#930)
  • d3f7f44 Bump github.com/hashicorp/consul/api from 1.21.0 to 1.22.0 (#929)
  • 1246352 Bump github.com/aws/aws-sdk-go from 1.44.288 to 1.44.289 (#928)
  • 2a9512d Bump github.com/aws/aws-sdk-go from 1.44.287 to 1.44.288 (#927)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jul 13, 2023
@github-actions github-actions bot enabled auto-merge (squash) July 13, 2023 15:16
@guardrails
Copy link

guardrails bot commented Jul 13, 2023

⚠️ We detected 77 security issues in this pull request:

Vulnerable Libraries (77)
Severity Details
High pkg:golang/golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781 - no patch available
High pkg:golang/golang.org/x/net@v0.0.0-20220325170049-de3da57026de - no patch available
N/A pkg:golang/golang.org/x/text@0.3.7 upgrade to: 0.3.8
High pkg:golang/gopkg.in/yaml.v2@v2.4.0 - no patch available
Critical pkg:golang/github.com/jinzhu/gorm@v1.9.16 - no patch available
Medium pkg:golang/github.com/yuin/goldmark@v1.1.32 - no patch available
Critical pkg:golang/github.com/gogo/protobuf@v1.3.2 - no patch available
High pkg:golang/github.com/hashicorp/consul/api@v1.7.0 - no patch available
High pkg:golang/github.com/prometheus/client_golang@v1.4.0 upgrade to: 1.11.1
N/A pkg:golang/golang.org/x/net@v0.0.0-20200707034311-ab3426394381 upgrade to: 0.7.0
High pkg:golang/github.com/gorilla/websocket@v1.5.0 - no patch available
High pkg:golang/github.com/hashicorp/consul/sdk@v0.3.0 - no patch available
N/A pkg:golang/golang.org/x/sys@v0.0.0-20190508220229-2d0786266e9c upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/github.com/aws/aws-sdk-go@v1.40.45 - no patch available
N/A pkg:golang/github.com/apache/thrift@v0.12.0 upgrade to: 0.13.0
High pkg:golang/github.com/miekg/dns@v1.1.26 - no patch available
N/A pkg:golang/github.com/aws/aws-sdk-go@v1.44.83 - no patch available
High pkg:golang/github.com/hashicorp/consul/api@v1.1.0 - no patch available
High pkg:golang/gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b upgrade to: 3.0.0-20220521103104-8f96da9f5d5e
N/A pkg:golang/golang.org/x/sys@v0.0.0-20190726091711-fc99dfbffb4e upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
Medium pkg:golang/github.com/gorilla/sessions@v1.2.1 - no patch available
High pkg:golang/github.com/hashicorp/consul/sdk@v0.1.1 - no patch available
High pkg:golang/github.com/hashicorp/consul/sdk@v0.4.0 - no patch available
N/A pkg:golang/k8s.io/apimachinery@v0.0.0-20180821005732-488889b0007f upgrade to: 0.0.0-20190927203648-9ce6eca90e73
N/A pkg:golang/golang.org/x/sys@v0.0.0-20190624142023-c5567b49c5d0 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20190904154756-749cb33beabd upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/github.com/hashicorp/vault/sdk@v0.1.13 - no patch available
N/A pkg:golang/golang.org/x/sys@v0.0.0-20191008105621-543471e840be upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20191120155948-bd437916bb0e upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/github.com/hashicorp/consul/sdk@v0.6.0 - no patch available
High pkg:golang/github.com/gorilla/websocket@v1.4.2 - no patch available
High pkg:golang/github.com/hashicorp/vault/api@v1.0.4 - no patch available
N/A pkg:golang/golang.org/x/sys@v0.0.0-20191026070338-33540a1f6037 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
Medium pkg:golang/github.com/yuin/goldmark@v1.1.27 - no patch available
High pkg:golang/gopkg.in/yaml.v2@v2.4.0 - no patch available
High pkg:golang/github.com/hashicorp/consul/api@v1.3.0 - no patch available
N/A pkg:golang/golang.org/x/sys@v0.0.0-20190826190057-c7b8b68b1456 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/gopkg.in/yaml.v2@v2.3.0 - no patch available
N/A pkg:golang/golang.org/x/sys@v0.0.0-20180909124046-d0be0721c37e upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/github.com/hashicorp/consul/api@v1.14.0 - no patch available
N/A pkg:golang/github.com/hashicorp/consul/api@v1.4.0 - no patch available
N/A pkg:golang/golang.org/x/sys@v0.0.0-20180905080454-ebe1bf3edb33 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/golang.org/x/net@v0.0.0-20181201002055-351d144fa1fc upgrade to: 0.0.0-20190813141303-74dc4d7220e7,0.0.0-20190813141303-74dc4d7220e7
High pkg:golang/golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1 - no patch available
High pkg:golang/golang.org/x/net@v0.0.0-20220412020605-290c469a71a5 - no patch available
High pkg:golang/golang.org/x/text@v0.3.7 - no patch available
High pkg:golang/gopkg.in/yaml.v2@v2.2.3 upgrade to: 2.2.4
High pkg:golang/golang.org/x/net@v0.0.0-20181023162649-9b4f9f5ad519 upgrade to: 0.0.0-20190125002852-4b62a64f59f7,0.0.0-20190125002852-4b62a64f59f7
High pkg:golang/golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420 - no patch available
High pkg:golang/github.com/nats-io/nats-server/v2@v2.5.0 - no patch available
High pkg:golang/github.com/dgrijalva/jwt-go@v3.2.0+incompatible - no patch available
High pkg:golang/github.com/hashicorp/consul/api@v1.12.0 - no patch available
High pkg:golang/github.com/hashicorp/consul/sdk@v0.10.0 - no patch available
Medium pkg:golang/github.com/coredns/coredns@v1.1.2 - no patch available
High pkg:golang/github.com/gogo/protobuf@v1.1.1 upgrade to: 1.3.2
Critical pkg:golang/github.com/gogo/protobuf@v1.2.0 - no patch available
Medium pkg:golang/github.com/hashicorp/consul/api@v1.10.1 - no patch available
High pkg:golang/golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110 - no patch available
N/A pkg:golang/github.com/influxdata/influxdb@v1.7.7 - no patch available
High pkg:golang/gopkg.in/yaml.v2@v2.2.4 - no patch available
High pkg:golang/golang.org/x/crypto@v0.0.0-20210314154223-e6e6c4f2bb5b upgrade to: 0.0.0-20211202192323-5770296d904e
High pkg:golang/github.com/aws/aws-sdk-go@v1.31.6 - no patch available
High pkg:golang/github.com/gorilla/websocket@v0.0.0-20170926233335-4201258b820c upgrade to: 1.4.1
High pkg:golang/github.com/gorilla/websocket@v1.4.0 upgrade to: 1.4.1
Medium pkg:golang/github.com/hashicorp/consul/sdk@v0.8.0 - no patch available
Critical pkg:golang/github.com/hashicorp/consul@v1.4.2 - no patch available
High pkg:golang/github.com/aws/aws-sdk-go@v1.8.12 - no patch available
High pkg:golang/github.com/miekg/dns@v1.0.14 - no patch available
High pkg:golang/golang.org/x/text@v0.3.3 - no patch available
Medium pkg:golang/golang.org/x/crypto@v0.0.0-20210915214749-c084706c2272 - no patch available
High pkg:golang/golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b - no patch available
High pkg:golang/github.com/hashicorp/consul@v1.7.0 upgrade to: 1.10.1
Medium pkg:golang/github.com/aws/aws-sdk-go@v1.27.0 - no patch available
Medium pkg:golang/github.com/aws/aws-sdk-go@v1.25.41 - no patch available
Critical pkg:golang/github.com/gogo/protobuf@v1.2.1 - no patch available
High pkg:golang/gopkg.in/yaml.v2@v2.2.2 upgrade to: 2.2.4
Critical pkg:golang/github.com/nats-io/nats-server/v2@v2.1.2 - no patch available

More info on how to fix Vulnerable Libraries in Go.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

Bumps [github.com/xmidt-org/webpa-common/v2](https://github.com/xmidt-org/webpa-common) from 2.0.7 to 2.2.1.
- [Release notes](https://github.com/xmidt-org/webpa-common/releases)
- [Changelog](https://github.com/xmidt-org/webpa-common/blob/main/CHANGELOG.md)
- [Commits](xmidt-org/webpa-common@v2.0.7...v2.2.1)

---
updated-dependencies:
- dependency-name: github.com/xmidt-org/webpa-common/v2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/xmidt-org/webpa-common/v2-2.2.1 branch from 63058e9 to 1f08dba Compare July 24, 2023 15:23
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Aug 9, 2023

Superseded by #65.

@dependabot dependabot bot closed this Aug 9, 2023
auto-merge was automatically disabled August 9, 2023 16:04

Pull request was closed

@dependabot dependabot bot deleted the dependabot/go_modules/github.com/xmidt-org/webpa-common/v2-2.2.1 branch August 9, 2023 16:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants