Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
fix(deps): update osv-scanner minor (#539)
[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [github.com/go-git/go-billy/v5](https://togithub.com/go-git/go-billy) | require | minor | `v5.4.1` -> `v5.5.0` | | [github.com/go-git/go-git/v5](https://togithub.com/go-git/go-git) | require | minor | `v5.8.1` -> `v5.9.0` | | [github.com/owenrumney/go-sarif/v2](https://togithub.com/owenrumney/go-sarif) | require | patch | `v2.2.0` -> `v2.2.2` | --- ### Release Notes <details> <summary>go-git/go-billy (github.com/go-git/go-billy/v5)</summary> ### [`v5.5.0`](https://togithub.com/go-git/go-billy/releases/tag/v5.5.0) [Compare Source](https://togithub.com/go-git/go-billy/compare/v5.4.1...v5.5.0) #### What's Changed - \*: Bump dependencies and go.mod to Go 1.18. Add codeQL workflow. by [@​pjbgf](https://togithub.com/pjbgf) in [https://github.com/go-git/go-billy/pull/30](https://togithub.com/go-git/go-billy/pull/30) - osfs: Add new BoundOS type by [@​pjbgf](https://togithub.com/pjbgf) in [https://github.com/go-git/go-billy/pull/31](https://togithub.com/go-git/go-billy/pull/31) - Re-introduce osfs.Default by [@​pjbgf](https://togithub.com/pjbgf) in [https://github.com/go-git/go-billy/pull/33](https://togithub.com/go-git/go-billy/pull/33) - Revert back to upstream github.com/cyphar/filepath-securejoin by [@​pjbgf](https://togithub.com/pjbgf) in [https://github.com/go-git/go-billy/pull/34](https://togithub.com/go-git/go-billy/pull/34) **Full Changelog**: go-git/go-billy@v5.4.1...v5.5.0 </details> <details> <summary>go-git/go-git (github.com/go-git/go-git/v5)</summary> ### [`v5.9.0`](https://togithub.com/go-git/go-git/releases/tag/v5.9.0) [Compare Source](https://togithub.com/go-git/go-git/compare/v5.8.1...v5.9.0) #### What's Changed - git: worktree: add Amend option to CommitOptions by [@​john-cai](https://togithub.com/john-cai) in [https://github.com/go-git/go-git/pull/438](https://togithub.com/go-git/go-git/pull/438) - git: worktree, reset ignored files that are part of the worktree: Fixes [#​819](https://togithub.com/go-git/go-git/issues/819) by [@​daolis](https://togithub.com/daolis) in [https://github.com/go-git/go-git/pull/821](https://togithub.com/go-git/go-git/pull/821) - plumbing: Do not swallow http message coming from VCS providers by [@​matejrisek](https://togithub.com/matejrisek) in [https://github.com/go-git/go-git/pull/835](https://togithub.com/go-git/go-git/pull/835) - plumbing: transport, handle IPv6 while parsing endpoint. Fixes [#​740](https://togithub.com/go-git/go-git/issues/740) by [@​ninedraft](https://togithub.com/ninedraft) in [https://github.com/go-git/go-git/pull/820](https://togithub.com/go-git/go-git/pull/820) - \*: update goproxy dependency to fix CVE-2023-37788 vulnerability by [@​svghadi](https://togithub.com/svghadi) in [https://github.com/go-git/go-git/pull/832](https://togithub.com/go-git/go-git/pull/832) - \*: bump dependencies and Go to 1.19 by [@​pjbgf](https://togithub.com/pjbgf) in [https://github.com/go-git/go-git/pull/837](https://togithub.com/go-git/go-git/pull/837) #### New Contributors - [@​svghadi](https://togithub.com/svghadi) made their first contribution in [https://github.com/go-git/go-git/pull/832](https://togithub.com/go-git/go-git/pull/832) - [@​daolis](https://togithub.com/daolis) made their first contribution in [https://github.com/go-git/go-git/pull/821](https://togithub.com/go-git/go-git/pull/821) **Full Changelog**: go-git/go-git@v5.8.1...v5.9.0 </details> <details> <summary>owenrumney/go-sarif (github.com/owenrumney/go-sarif/v2)</summary> ### [`v2.2.2`](https://togithub.com/owenrumney/go-sarif/releases/tag/v2.2.2) [Compare Source](https://togithub.com/owenrumney/go-sarif/compare/v2.2.1...v2.2.2) #### What's Changed - fix: add omitempty annotation to messageStrings by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/owenrumney/go-sarif/pull/68](https://togithub.com/owenrumney/go-sarif/pull/68) **Full Changelog**: owenrumney/go-sarif@v2.2.1...v2.2.2 ### [`v2.2.1`](https://togithub.com/owenrumney/go-sarif/releases/tag/v2.2.1) [Compare Source](https://togithub.com/owenrumney/go-sarif/compare/v2.2.0...v2.2.1) #### What's Changed - Bump github.com/stretchr/testify from 1.8.2 to 1.8.4 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/owenrumney/go-sarif/pull/62](https://togithub.com/owenrumney/go-sarif/pull/62) - Bump github.com/zclconf/go-cty from 1.13.1 to 1.13.2 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/owenrumney/go-sarif/pull/61](https://togithub.com/owenrumney/go-sarif/pull/61) - support messageStrings property by [@​masakura](https://togithub.com/masakura) in [https://github.com/owenrumney/go-sarif/pull/63](https://togithub.com/owenrumney/go-sarif/pull/63) - Bump github.com/zclconf/go-cty from 1.13.2 to 1.14.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/owenrumney/go-sarif/pull/65](https://togithub.com/owenrumney/go-sarif/pull/65) #### New Contributors - [@​masakura](https://togithub.com/masakura) made their first contribution in [https://github.com/owenrumney/go-sarif/pull/63](https://togithub.com/owenrumney/go-sarif/pull/63) **Full Changelog**: owenrumney/go-sarif@v2.2.0...v2.2.1 </details> --- ### Configuration 📅 **Schedule**: Branch creation - "before 6am on monday" in timezone Australia/Sydney, Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://togithub.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/google/osv-scanner). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNi44My4wIiwidXBkYXRlZEluVmVyIjoiMzYuODMuMCIsInRhcmdldEJyYW5jaCI6Im1haW4ifQ==-->
- Loading branch information