-
Notifications
You must be signed in to change notification settings - Fork 4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
build(deps): bump the go_modules group across 1 directories with 2 updates #615
build(deps): bump the go_modules group across 1 directories with 2 updates #615
Conversation
…dates Bumps the go_modules group with 2 updates in the /. directory: [github.com/cloudflare/circl](https://github.com/cloudflare/circl) and [github.com/go-git/go-git/v5](https://github.com/go-git/go-git). Updates `github.com/cloudflare/circl` from 1.1.0 to 1.3.7 - [Release notes](https://github.com/cloudflare/circl/releases) - [Commits](cloudflare/circl@v1.1.0...v1.3.7) Updates `github.com/go-git/go-git/v5` from 5.5.2 to 5.11.0 - [Release notes](https://github.com/go-git/go-git/releases) - [Commits](go-git/go-git@v5.5.2...v5.11.0) --- updated-dependencies: - dependency-name: github.com/cloudflare/circl dependency-type: indirect dependency-group: go_modules-security-group - dependency-name: github.com/go-git/go-git/v5 dependency-type: indirect dependency-group: go_modules-security-group ... Signed-off-by: dependabot[bot] <[email protected]>
breaks go.sum?? |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I had to manually re-add oapi-codegen (probably because it's a devDependency, in npm terms ...). Code then compiled.
I then looked for a way to ensure oapi-codegen doesn't get removed in the future. Looks like tools.go
(added in this PR) is the recommended way.
github.com/go-git/gcfg v1.5.0 // indirect | ||
github.com/go-git/go-billy/v5 v5.4.0 // indirect | ||
github.com/go-git/go-git/v5 v5.5.2 // indirect | ||
github.com/getkin/kin-openapi v0.107.0 // indirect |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is one of the several new dependencies that go mod tidy
explicitly adds to go.sum now that we oapi-codegen is an explicit dependency via tools.go. Before that, they were only used implicitly, by being included in the precompiled oapi-codegen. I guess it's good for dependency awareness that we're tracking them more explicitly now.
Bumps the go_modules group with 2 updates in the /. directory: github.com/cloudflare/circl and github.com/go-git/go-git/v5.
Updates
github.com/cloudflare/circl
from 1.1.0 to 1.3.7Release notes
Sourced from github.com/cloudflare/circl's releases.
... (truncated)
Commits
c48866b
Releasing CIRCL v1.3.775ef91e
kyber: remove division by q in ciphertext compression899732a
build(deps): bump golang.org/x/crypto99f0f71
Releasing CIRCL v1.3.6e728d0d
Apply thibmeu code review suggestionsceb2d90
Updating blindrsa to be compliant with RFC9474.44133f7
spelling: trippedc2076d6
spelling: transposesdad2166
spelling: title171c418
spelling: thresholdUpdates
github.com/go-git/go-git/v5
from 5.5.2 to 5.11.0Release notes
Sourced from github.com/go-git/go-git/v5's releases.
... (truncated)
Commits
5d08d3b
Merge pull request #958 from pjbgf/workval5bd1d8f
build: Ensure checkout is the first operationb2c1982
git: worktree, Align validation with upstream rulescec7da6
Merge pull request #953 from pjbgf/alternates8b47ceb
storage: filesystem, Add option to set a specific FS for alternates4f61489
Merge pull request #941 from djmoch/filestats-renameae552ce
Merge pull request #939 from dhoizner/fix-pull-after-shallowcc1895b
Merge pull request #950 from aymanbagabas/validate-refde1d5a5
git: validate reference namesd87110b
Merge pull request #948 from go-git/dependabot/go_modules/cli/go-git/github.c...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.