-
Notifications
You must be signed in to change notification settings - Fork 32
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
build(deps): bump the all group with 7 updates #1806
Closed
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the all group with 7 updates: | Package | From | To | | --- | --- | --- | | [github.com/enterprise-contract/enterprise-contract-controller/api](https://github.com/enterprise-contract/enterprise-contract-controller) | `0.1.49` | `0.1.50` | | [github.com/gkampitakis/go-snaps](https://github.com/gkampitakis/go-snaps) | `0.5.5` | `0.5.6` | | [github.com/open-policy-agent/conftest](https://github.com/open-policy-agent/conftest) | `0.54.0` | `0.55.0` | | [github.com/open-policy-agent/opa](https://github.com/open-policy-agent/opa) | `0.66.0` | `0.67.0` | | [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) | `2.2.4` | `2.3.0` | | [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) | `1.8.4` | `1.8.7` | | [golang.org/x/exp](https://github.com/golang/exp) | `0.0.0-20231214170342-aacd6d4b4611` | `0.0.0-20240112132812-db7319d0e0e3` | Updates `github.com/enterprise-contract/enterprise-contract-controller/api` from 0.1.49 to 0.1.50 - [Release notes](https://github.com/enterprise-contract/enterprise-contract-controller/releases) - [Commits](enterprise-contract/enterprise-contract-controller@api/v0.1.49...api/v0.1.50) Updates `github.com/gkampitakis/go-snaps` from 0.5.5 to 0.5.6 - [Release notes](https://github.com/gkampitakis/go-snaps/releases) - [Commits](gkampitakis/go-snaps@v0.5.5...v0.5.6) Updates `github.com/open-policy-agent/conftest` from 0.54.0 to 0.55.0 - [Release notes](https://github.com/open-policy-agent/conftest/releases) - [Changelog](https://github.com/open-policy-agent/conftest/blob/master/.goreleaser.yml) - [Commits](open-policy-agent/conftest@v0.54.0...v0.55.0) Updates `github.com/open-policy-agent/opa` from 0.66.0 to 0.67.0 - [Release notes](https://github.com/open-policy-agent/opa/releases) - [Changelog](https://github.com/open-policy-agent/opa/blob/main/CHANGELOG.md) - [Commits](open-policy-agent/opa@v0.66.0...v0.67.0) Updates `github.com/sigstore/cosign/v2` from 2.2.4 to 2.3.0 - [Release notes](https://github.com/sigstore/cosign/releases) - [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md) - [Commits](sigstore/cosign@v2.2.4...v2.3.0) Updates `github.com/sigstore/sigstore` from 1.8.4 to 1.8.7 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.8.4...v1.8.7) Updates `golang.org/x/exp` from 0.0.0-20231214170342-aacd6d4b4611 to 0.0.0-20240112132812-db7319d0e0e3 - [Commits](https://github.com/golang/exp/commits) --- updated-dependencies: - dependency-name: github.com/enterprise-contract/enterprise-contract-controller/api dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/gkampitakis/go-snaps dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: github.com/open-policy-agent/conftest dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: github.com/open-policy-agent/opa dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: github.com/sigstore/cosign/v2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: github.com/sigstore/sigstore dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: golang.org/x/exp dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all ... Signed-off-by: dependabot[bot] <[email protected]>
dependabot
bot
added
dependencies
Pull requests that update a dependency file
go
Pull requests that update Go code
labels
Jul 29, 2024
@dependabot ignore github.com/sigstore/cosign/v2 major version |
OK, I won't notify you about version 2.x.x of github.com/sigstore/cosign/v2 again, unless you unignore it. |
github.com/sigstore/cosign/v2 is on golang 1.22 to which we can't upgrade right now. |
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the all group with 7 updates:
0.1.49
0.1.50
0.5.5
0.5.6
0.54.0
0.55.0
0.66.0
0.67.0
2.2.4
2.3.0
1.8.4
1.8.7
0.0.0-20231214170342-aacd6d4b4611
0.0.0-20240112132812-db7319d0e0e3
Updates
github.com/enterprise-contract/enterprise-contract-controller/api
from 0.1.49 to 0.1.50Release notes
Sourced from github.com/enterprise-contract/enterprise-contract-controller/api's releases.
Commits
c4e5c05
Merge pull request #369 from enterprise-contract/dependabot/github_actions/so...a96b8d8
Merge pull request #368 from enterprise-contract/dependabot/github_actions/st...c7f9eee
Merge pull request #367 from enterprise-contract/dependabot/github_actions/gi...5ed0b88
Merge pull request #363 from enterprise-contract/dependabot/go_modules/api/k8...988f770
Bump k8s.io/apiextensions-apiserver from 0.29.6 to 0.29.7 in /apiaeff6c0
Bump softprops/action-gh-release from 2.0.6 to 2.0.8c45b339
Bump step-security/harden-runner from 2.8.1 to 2.9.0d9430ab
Bump github/codeql-action from 3.25.12 to 3.25.138a7c6e7
Merge pull request #362 from enterprise-contract/dependabot/github_actions/gi...d89d6f5
Bump github/codeql-action from 3.25.11 to 3.25.12Updates
github.com/gkampitakis/go-snaps
from 0.5.5 to 0.5.6Release notes
Sourced from github.com/gkampitakis/go-snaps's releases.
Commits
2fadb85
feat: support matchStandaloneSnapshot (#102)Updates
github.com/open-policy-agent/conftest
from 0.54.0 to 0.55.0Release notes
Sourced from github.com/open-policy-agent/conftest's releases.
Commits
99d588f
build(deps): bump github.com/moby/buildkit from 0.14.1 to 0.15.1 (#976)2444462
build(deps): bump github.com/open-policy-agent/opa from 0.66.0 to 0.67.0 (#977)2f13857
fix: update regex to excape the dot in it (#975)daab0c9
ci: Bump golang-ci action to v6 (#974)2275d3f
build(deps): bump golang from 1.22.4-alpine to 1.22.5-alpine (#970)066d0f4
ci: Pin goreleaser to v1 (#969)3ca1e3a
ci: Bump Docker login to v3 (#968)Updates
github.com/open-policy-agent/opa
from 0.66.0 to 0.67.0Release notes
Sourced from github.com/open-policy-agent/opa's releases.
... (truncated)
Changelog
Sourced from github.com/open-policy-agent/opa's changelog.
... (truncated)
Commits
b62ae6b
Prepare v0.67.0 releasebec8e1a
build(deps): bump github/codeql-action from 3.25.13 to 3.25.14 (#6888)d48fdd9
server: Add missing handling forexplain=fails
to the REST API.959f9e5
docs: Add an example of a manifest with attributea793f27
repl: Add support for correctly loading bundle modulesc5706ee
server+util: Limit max request sizes, prealloc request buffers (#6868)0ca35e2
build(deps): bump docker/setup-buildx-action from 3.4.0 to 3.5.0 (#6880)f9ccb66
build(deps): bump github/codeql-action from 3.25.12 to 3.25.13 (#6881)0db1f8f
build(deps): bump docker/setup-qemu-action from 3.1.0 to 3.2.0 (#6882)ac3ddf9
docs: Update generated CLI docsUpdates
github.com/sigstore/cosign/v2
from 2.2.4 to 2.3.0Release notes
Sourced from github.com/sigstore/cosign/v2's releases.
Changelog
Sourced from github.com/sigstore/cosign/v2's changelog.
Commits
deed363
chore(deps): bump github.com/xanzy/go-gitlab from 0.106.0 to 0.107.0 (#3792)c6f89f8
chore(deps): bump github.com/buildkite/agent/v3 from 3.74.1 to 3.75.1 (#3793)aeba473
Add CHANGELOG for v2.3.0 (#3789)20d4724
chore(deps): bump github.com/google/go-containerregistry (#3790)4684fd6
chore(deps): bump the gomod group with 5 updates (#3780)3c6c5c9
chore(deps): bump github.com/sigstore/fulcio from 1.4.5 to 1.5.1 (#3784)05026ee
chore(deps): bump github.com/google/go-containerregistry (#3783)f9270c0
chore(deps): bump google.golang.org/api from 0.187.0 to 0.188.0 (#3782)4fd699c
chore(deps): bump go.step.sm/crypto from 0.48.1 to 0.50.0 (#3781)13d3a56
chore(deps): bump the actions group across 1 directory with 2 updates (#3785)Updates
github.com/sigstore/sigstore
from 1.8.4 to 1.8.7Release notes
Sourced from github.com/sigstore/sigstore's releases.
... (truncated)
Commits
cb8b4bb
sync go mod2506e5d
build(deps): Bump the all group across 1 directory with 4 updates9a70270
build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcpf6b4bb5
build(deps): Bump the all group in /pkg/signature/kms/gcp with 2 updatesaebd23d
build(deps): Bump actions/upload-artifact in the all groupec4bc1a
build(deps): Bump the all group across 1 directory with 2 updatesaeb9782
build(deps): Bump golang.org/x/crypto016e2e3
build(deps): Bump github.com/sigstore/sigstore8243831
build(deps): Bump hashicorp/vault in /test/e2e in the all group51d791e
build(deps): Bump the all group in /pkg/signature/kms/aws with 4 updatesUpdates
golang.org/x/exp
from 0.0.0-20231214170342-aacd6d4b4611 to 0.0.0-20240112132812-db7319d0e0e3Commits
Most Recent Ignore Conditions Applied to This Pull Request
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions