Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump the all group across 1 directory with 3 updates #2037

Closed

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Sep 30, 2024

Bumps the all group with 3 updates in the /acceptance directory: github.com/enterprise-contract/enterprise-contract-controller/api, github.com/wiremock/go-wiremock and sigs.k8s.io/kustomize/kyaml.

Updates github.com/enterprise-contract/enterprise-contract-controller/api from 0.1.57 to 0.1.59

Release notes

Sourced from github.com/enterprise-contract/enterprise-contract-controller/api's releases.

API Release api/v0.1.59

What's Changed

Full Changelog: enterprise-contract/enterprise-contract-controller@api/v0.1.58...api/v0.1.59

API Release api/v0.1.58

What's Changed

Full Changelog: enterprise-contract/enterprise-contract-controller@api/v0.1.57...api/v0.1.58

Commits
  • cec5c56 Merge pull request #407 from enterprise-contract/dependabot/github_actions/gi...
  • 7dcf54c Merge pull request #406 from enterprise-contract/dependabot/github_actions/ac...
  • 37ac6aa Bump github/codeql-action from 3.26.8 to 3.26.10
  • 26fe4ce Bump actions/checkout from 4.1.7 to 4.2.0
  • 54cded6 Merge pull request #405 from enterprise-contract/dependabot/github_actions/gi...
  • 4af750a Bump github/codeql-action from 3.26.7 to 3.26.8
  • See full diff in compare view

Updates github.com/wiremock/go-wiremock from 1.9.0 to 1.10.0

Release notes

Sourced from github.com/wiremock/go-wiremock's releases.

1.10.0

🚀 New features and improvements

  • Add the MustEqualtoJson matcher which simplifies working with JSON. It accepts a value of any type and marshals it into a JSON string (#31) @​walkerus

🐛 Bug fixes

  • Fix WithAuthToken and WithDigestAuth stub rules
Commits

Updates sigs.k8s.io/kustomize/kyaml from 0.17.2 to 0.18.0

Release notes

Sourced from sigs.k8s.io/kustomize/kyaml's releases.

api/v0.17.3

chore

#5506: fix some comments #5693: fix: always show accumulation errors #5699: chore: add deprecation comment to commonLabels #5698: fix(namereference): add configuration for new admission API

Dependencies

#5734: Update kyaml to v0.17.2

Commits
  • 2cd9a2e Merge pull request #5768 from dims/remove-starlark-support
  • d32eacf Remove starlark support
  • 88f19bf Merge pull request #5763 from koba1t/update_go_1.22.7
  • a3c0b4a disable for a step to skip test when that is docs PR
  • b67ce5b go work sync && ./hack/doGoMod.sh tidy
  • 5ba8523 update go 1.22.7
  • 4034e36 Add --helm-debug Flag to Kustomize for Enhanced Helm Debugging (#5751)
  • c3872ce Merge pull request #5745 from isarns/master
  • d35d21c Merge pull request #5760 from Kavinjsir/patch-docs
  • a5f43ec style: linting
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all group with 3 updates in the /acceptance directory: [github.com/enterprise-contract/enterprise-contract-controller/api](https://github.com/enterprise-contract/enterprise-contract-controller), [github.com/wiremock/go-wiremock](https://github.com/wiremock/go-wiremock) and [sigs.k8s.io/kustomize/kyaml](https://github.com/kubernetes-sigs/kustomize).


Updates `github.com/enterprise-contract/enterprise-contract-controller/api` from 0.1.57 to 0.1.59
- [Release notes](https://github.com/enterprise-contract/enterprise-contract-controller/releases)
- [Commits](enterprise-contract/enterprise-contract-controller@api/v0.1.57...api/v0.1.59)

Updates `github.com/wiremock/go-wiremock` from 1.9.0 to 1.10.0
- [Release notes](https://github.com/wiremock/go-wiremock/releases)
- [Commits](wiremock/go-wiremock@v1.9.0...v1.10.0)

Updates `sigs.k8s.io/kustomize/kyaml` from 0.17.2 to 0.18.0
- [Release notes](https://github.com/kubernetes-sigs/kustomize/releases)
- [Commits](kubernetes-sigs/kustomize@api/v0.17.2...kyaml/v0.18.0)

---
updated-dependencies:
- dependency-name: github.com/enterprise-contract/enterprise-contract-controller/api
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github.com/wiremock/go-wiremock
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: sigs.k8s.io/kustomize/kyaml
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 30, 2024
@lcarva
Copy link
Member

lcarva commented Sep 30, 2024

go: sigs.k8s.io/kustomize/kyaml@v0.18.0 requires go >= 1.22.7 (running go 1.22.5)

I really dislike that a min patch version is being required.

@simonbaird
Copy link
Member

Saw this one:

level=error msg="Running error: can't run linter goanalysis_metalinter\nbuildir: failed to load package fnplugin: could not load export data: no export data for \"sigs.k8s.io/kustomize/api/internal/plugins/fnplugin\""

@simonbaird
Copy link
Member

Oh, I guess the go version dep is hard blocker at this stage.

@zregvart
Copy link
Member

zregvart commented Oct 3, 2024

We can't update sigs.k8s.io/kustomize/kyaml because it contains a change not released in other kustomize modules. We might want to update golang to pickup a fix for CVE-2024-34156, though I don't see an updated rh-osbs/openshift-golang-builder image.
I have a commit with these fixes. We can go on that route or we can ignore the sigs.k8s.io/kustomize/kyaml 0.18.0 and wait for other kustomize modules to be released.

Copy link
Contributor Author

dependabot bot commented on behalf of github Oct 7, 2024

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot bot closed this Oct 7, 2024
auto-merge was automatically disabled October 7, 2024 15:59

Pull request was closed

@dependabot dependabot bot deleted the dependabot/go_modules/acceptance/all-e27b51a613 branch October 7, 2024 15:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file go Pull requests that update Go code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants