Bump the go_modules group across 12 directories with 5 updates#21830
Conversation
Bumps the go_modules group with 1 update in the /go/ql/integration-tests/bazel-sample-1/src directory: [golang.org/x/net](https://github.com/golang/net). Bumps the go_modules group with 1 update in the /go/ql/integration-tests/bazel-sample-2/src directory: [golang.org/x/net](https://github.com/golang/net). Bumps the go_modules group with 1 update in the /go/ql/integration-tests/go-mod-sample/src directory: [golang.org/x/net](https://github.com/golang/net). Bumps the go_modules group with 1 update in the /go/ql/integration-tests/go-mod-without-version/src directory: [golang.org/x/net](https://github.com/golang/net). Bumps the go_modules group with 1 update in the /go/ql/integration-tests/make-sample/src directory: [golang.org/x/net](https://github.com/golang/net). Bumps the go_modules group with 1 update in the /go/ql/integration-tests/ninja-sample/src directory: [golang.org/x/net](https://github.com/golang/net). Bumps the go_modules group with 1 update in the /go/ql/integration-tests/single-go-mod-in-root/src directory: [golang.org/x/net](https://github.com/golang/net). Bumps the go_modules group with 1 update in the /go/ql/integration-tests/two-go-mods-nested-one-in-root/src directory: [golang.org/x/net](https://github.com/golang/net). Bumps the go_modules group with 2 updates in the /go/ql/test/experimental/CWE-321-V2 directory: [github.com/go-jose/go-jose/v3](https://github.com/go-jose/go-jose) and [github.com/golang-jwt/jwt/v5](https://github.com/golang-jwt/jwt). Bumps the go_modules group with 1 update in the /go/ql/test/experimental/CWE-522-DecompressionBombs directory: [github.com/ulikunitz/xz](https://github.com/ulikunitz/xz). Bumps the go_modules group with 1 update in the /go/ql/test/library-tests/semmle/go/frameworks/Fasthttp directory: [golang.org/x/net](https://github.com/golang/net). Bumps the go_modules group with 1 update in the /go/ql/test/library-tests/semmle/go/frameworks/StdlibTaintFlow directory: [golang.org/x/net](https://github.com/golang/net). Updates `golang.org/x/net` from 0.23.0 to 0.38.0 - [Commits](golang/net@v0.23.0...v0.38.0) Updates `golang.org/x/net` from 0.23.0 to 0.38.0 - [Commits](golang/net@v0.23.0...v0.38.0) Updates `golang.org/x/net` from 0.23.0 to 0.38.0 - [Commits](golang/net@v0.23.0...v0.38.0) Updates `golang.org/x/net` from 0.23.0 to 0.38.0 - [Commits](golang/net@v0.23.0...v0.38.0) Updates `golang.org/x/net` from 0.23.0 to 0.38.0 - [Commits](golang/net@v0.23.0...v0.38.0) Updates `golang.org/x/net` from 0.23.0 to 0.38.0 - [Commits](golang/net@v0.23.0...v0.38.0) Updates `golang.org/x/net` from 0.23.0 to 0.38.0 - [Commits](golang/net@v0.23.0...v0.38.0) Updates `golang.org/x/net` from 0.23.0 to 0.38.0 - [Commits](golang/net@v0.23.0...v0.38.0) Updates `github.com/go-jose/go-jose/v3` from 3.0.0 to 3.0.5 - [Release notes](https://github.com/go-jose/go-jose/releases) - [Commits](go-jose/go-jose@v3.0.0...v3.0.5) Updates `github.com/golang-jwt/jwt/v5` from 5.0.0 to 5.2.2 - [Release notes](https://github.com/golang-jwt/jwt/releases) - [Commits](golang-jwt/jwt@v5.0.0...v5.2.2) Updates `golang.org/x/crypto` from 0.12.0 to 0.19.0 - [Commits](golang/crypto@v0.12.0...v0.19.0) Updates `github.com/ulikunitz/xz` from 0.5.11 to 0.5.14 - [Commits](ulikunitz/xz@v0.5.11...v0.5.14) Updates `golang.org/x/net` from 0.8.0 to 0.38.0 - [Commits](golang/net@v0.23.0...v0.38.0) Updates `golang.org/x/net` from 0.0.0-20201010224723-4f7140c49acb to 0.38.0 - [Commits](golang/net@v0.23.0...v0.38.0) --- updated-dependencies: - dependency-name: golang.org/x/net dependency-version: 0.38.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.38.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.38.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.38.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.38.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.38.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.38.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.38.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/go-jose/go-jose/v3 dependency-version: 3.0.5 dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/golang-jwt/jwt/v5 dependency-version: 5.2.2 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/crypto dependency-version: 0.19.0 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/ulikunitz/xz dependency-version: 0.5.14 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.38.0 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.38.0 dependency-type: direct:production dependency-group: go_modules ... Signed-off-by: dependabot[bot] <support@github.com>
|
@dependabot ignore golang.org/x/net github.com/ulikunitz/xz golang.org/x/crypto github.com/golang-jwt/jwt/v5 github.com/go-jose/go-jose/v3 |
|
@dependabot ignore golang.org/x/net |
|
OK, I won't notify you about golang.org/x/net again, unless you unignore it. |
|
@dependabot ignore github.com/ulikunitz/xz |
|
OK, I won't notify you about github.com/ulikunitz/xz again, unless you unignore it. |
|
@dependabot ignore golang.org/x/crypto |
|
OK, I won't notify you about golang.org/x/crypto again, unless you unignore it. |
|
@dependabot ignore github.com/golang-jwt/jwt/v5 |
|
OK, I won't notify you about github.com/golang-jwt/jwt/v5 again, unless you unignore it. |
|
@dependabot ignore github.com/go-jose/go-jose/v3 |
|
OK, I won't notify you about github.com/go-jose/go-jose/v3 again, unless you unignore it. |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps the go_modules group with 1 update in the /go/ql/integration-tests/bazel-sample-1/src directory: golang.org/x/net.
Bumps the go_modules group with 1 update in the /go/ql/integration-tests/bazel-sample-2/src directory: golang.org/x/net.
Bumps the go_modules group with 1 update in the /go/ql/integration-tests/go-mod-sample/src directory: golang.org/x/net.
Bumps the go_modules group with 1 update in the /go/ql/integration-tests/go-mod-without-version/src directory: golang.org/x/net.
Bumps the go_modules group with 1 update in the /go/ql/integration-tests/make-sample/src directory: golang.org/x/net.
Bumps the go_modules group with 1 update in the /go/ql/integration-tests/ninja-sample/src directory: golang.org/x/net.
Bumps the go_modules group with 1 update in the /go/ql/integration-tests/single-go-mod-in-root/src directory: golang.org/x/net.
Bumps the go_modules group with 1 update in the /go/ql/integration-tests/two-go-mods-nested-one-in-root/src directory: golang.org/x/net.
Bumps the go_modules group with 2 updates in the /go/ql/test/experimental/CWE-321-V2 directory: github.com/go-jose/go-jose/v3 and github.com/golang-jwt/jwt/v5.
Bumps the go_modules group with 1 update in the /go/ql/test/experimental/CWE-522-DecompressionBombs directory: github.com/ulikunitz/xz.
Bumps the go_modules group with 1 update in the /go/ql/test/library-tests/semmle/go/frameworks/Fasthttp directory: golang.org/x/net.
Bumps the go_modules group with 1 update in the /go/ql/test/library-tests/semmle/go/frameworks/StdlibTaintFlow directory: golang.org/x/net.
Updates
golang.org/x/netfrom 0.23.0 to 0.38.0Commits
e1fcd82html: properly handle trailing solidus in unquoted attribute value in foreign...ebed060internal/http3: fix build of tests with GOEXPERIMENT=nosynctest1f1fa29publicsuffix: regenerate table1215081http2: improve error when server sends HTTP/1312450ehtml: ensure <search> tag closes <p> and update tests09731f9http2: improve handling of lost PING in Server55989e2http2/h2c: use ResponseController for hijacking connections2914f46websocket: re-recommend gorilla/websocket99b3ae0go.mod: update golang.org/x dependencies85d1d54go.mod: update golang.org/x dependenciesUpdates
golang.org/x/netfrom 0.23.0 to 0.38.0Commits
e1fcd82html: properly handle trailing solidus in unquoted attribute value in foreign...ebed060internal/http3: fix build of tests with GOEXPERIMENT=nosynctest1f1fa29publicsuffix: regenerate table1215081http2: improve error when server sends HTTP/1312450ehtml: ensure <search> tag closes <p> and update tests09731f9http2: improve handling of lost PING in Server55989e2http2/h2c: use ResponseController for hijacking connections2914f46websocket: re-recommend gorilla/websocket99b3ae0go.mod: update golang.org/x dependencies85d1d54go.mod: update golang.org/x dependenciesUpdates
golang.org/x/netfrom 0.23.0 to 0.38.0Commits
e1fcd82html: properly handle trailing solidus in unquoted attribute value in foreign...ebed060internal/http3: fix build of tests with GOEXPERIMENT=nosynctest1f1fa29publicsuffix: regenerate table1215081http2: improve error when server sends HTTP/1312450ehtml: ensure <search> tag closes <p> and update tests09731f9http2: improve handling of lost PING in Server55989e2http2/h2c: use ResponseController for hijacking connections2914f46websocket: re-recommend gorilla/websocket99b3ae0go.mod: update golang.org/x dependencies85d1d54go.mod: update golang.org/x dependenciesUpdates
golang.org/x/netfrom 0.23.0 to 0.38.0Commits
e1fcd82html: properly handle trailing solidus in unquoted attribute value in foreign...ebed060internal/http3: fix build of tests with GOEXPERIMENT=nosynctest1f1fa29publicsuffix: regenerate table1215081http2: improve error when server sends HTTP/1312450ehtml: ensure <search> tag closes <p> and update tests09731f9http2: improve handling of lost PING in Server55989e2http2/h2c: use ResponseController for hijacking connections2914f46websocket: re-recommend gorilla/websocket99b3ae0go.mod: update golang.org/x dependencies85d1d54go.mod: update golang.org/x dependenciesUpdates
golang.org/x/netfrom 0.23.0 to 0.38.0Commits
e1fcd82html: properly handle trailing solidus in unquoted attribute value in foreign...ebed060internal/http3: fix build of tests with GOEXPERIMENT=nosynctest1f1fa29publicsuffix: regenerate table1215081http2: improve error when server sends HTTP/1312450ehtml: ensure <search> tag closes <p> and update tests09731f9http2: improve handling of lost PING in Server55989e2http2/h2c: use ResponseController for hijacking connections2914f46websocket: re-recommend gorilla/websocket99b3ae0go.mod: update golang.org/x dependencies85d1d54go.mod: update golang.org/x dependenciesUpdates
golang.org/x/netfrom 0.23.0 to 0.38.0Commits
e1fcd82html: properly handle trailing solidus in unquoted attribute value in foreign...ebed060internal/http3: fix build of tests with GOEXPERIMENT=nosynctest1f1fa29publicsuffix: regenerate table1215081http2: improve error when server sends HTTP/1312450ehtml: ensure <search> tag closes <p> and update tests09731f9http2: improve handling of lost PING in Server55989e2http2/h2c: use ResponseController for hijacking connections2914f46websocket: re-recommend gorilla/websocket99b3ae0go.mod: update golang.org/x dependencies85d1d54go.mod: update golang.org/x dependenciesUpdates
golang.org/x/netfrom 0.23.0 to 0.38.0Commits
e1fcd82html: properly handle trailing solidus in unquoted attribute value in foreign...ebed060internal/http3: fix build of tests with GOEXPERIMENT=nosynctest1f1fa29publicsuffix: regenerate table1215081http2: improve error when server sends HTTP/1312450ehtml: ensure <search> tag closes <p> and update tests09731f9http2: improve handling of lost PING in Server55989e2http2/h2c: use ResponseController for hijacking connections2914f46websocket: re-recommend gorilla/websocket99b3ae0go.mod: update golang.org/x dependencies85d1d54go.mod: update golang.org/x dependenciesUpdates
golang.org/x/netfrom 0.23.0 to 0.38.0Commits
e1fcd82html: properly handle trailing solidus in unquoted attribute value in foreign...ebed060internal/http3: fix build of tests with GOEXPERIMENT=nosynctest1f1fa29publicsuffix: regenerate table1215081http2: improve error when server sends HTTP/1312450ehtml: ensure <search> tag closes <p> and update tests09731f9http2: improve handling of lost PING in Server55989e2http2/h2c: use ResponseController for hijacking connections2914f46websocket: re-recommend gorilla/websocket99b3ae0go.mod: update golang.org/x dependencies85d1d54go.mod: update golang.org/x dependenciesUpdates
github.com/go-jose/go-jose/v3from 3.0.0 to 3.0.5Release notes
Sourced from github.com/go-jose/go-jose/v3's releases.
Commits
be2f654ci: update Go versions for GHA workflows (#221)0246416Merge commit from fork5253038Backport fix 167 to v3 (#174)047dc99CI: Update github actions and go version (#173)0f017e9Revert #26 (ignore unsupported JWKs in Sets) (#131)3e2bbefUnmarshal jwk keys with unsupported key type or algorithm into empty … (#26)add6a28v3: backport decompression limit fix (#107)11bb4e7doc: in v3 branch's README, point to v4 as latest (#101)863f73bv3.0.2: Update changelog (#95)bdbc794Update golang.org/x/crypto to v0.19 (backport) (#94)Updates
github.com/golang-jwt/jwt/v5from 5.0.0 to 5.2.2Release notes
Sourced from github.com/golang-jwt/jwt/v5's releases.
... (truncated)
Commits
0951d18Merge commit from forkc035977Update Parse example to use WithValidMethods (#425)bc8bdcaUpdate SECURITY.md (#416)5ec246cdocs: typo (#407)0123f1aFix jwt -show (#406)f961c72chore: bump ci tests to include go1.23 (#405)62e504cBump golangci/golangci-lint-action from 5 to 6 (#389)1a56dcfBump golangci/golangci-lint-action from 4 to 5 (#387)c8043eabuild: add go1.22 to ci workflows (#383)7c3f6dcUpdate README.md (#382)Updates
golang.org/x/cryptofrom 0.12.0 to 0.19.0Commits
405cb3bgo.mod: update golang.org/x dependencies913d3aex509roots/fallback: update bundledbb6ec1ssh/test: skip tests on darwin that fail on the darwin-amd64-longtest LUCI bu...403f699ssh/test: avoid leaking a net.UnixConn in server.TryDialWithAddr055043dgo.mod: update golang.org/x dependencies08396bbinternal/poly1305: drop Go 1.12 compatibility9d2ee97ssh: implement strict KEX protocol changes4e5a261ssh: close net.Conn on all NewServerConn errors152cdb1x509roots/fallback: update bundlefdfe1f8ssh: defer channel window adjustmentUpdates
github.com/ulikunitz/xzfrom 0.5.11 to 0.5.14Commits
7184815Preparation of release v0.5.1488ddf1dAddress Security Issue GHSA-jc7w-c686-c4v9c8314b8Add new package xio with WriteCloserStack4f11dceUpdate README.md and SECURITY.md to address security questionsf56ebbfTODO.md: fix a typoUpdates
golang.org/x/netfrom 0.8.0 to 0.38.0Commits
e1fcd82html: properly handle trailing solidus in unquoted attribute value in foreign...ebed060internal/http3: fix build of tests with GOEXPERIMENT=nosynctest1f1fa29publicsuffix: regenerate table1215081http2: improve error when server sends HTTP/1312450ehtml: ensure <search> tag closes <p> and update tests09731f9http2: improve handling of lost PING in Server55989e2http2/h2c: use ResponseController for hijacking connections2914f46websocket: re-recommend gorilla/websocket99b3ae0go.mod: update golang.org/x dependencies85d1d54go.mod: update golang.org/x dependenciesUpdates
golang.org/x/netfrom 0.0.0-20201010224723-4f7140c49acb to 0.38.0Commits
e1fcd82html: properly handle trailing solidus in unquoted attribute value in foreign...ebed060internal/http3: fix build of tests with GOEXPERIMENT=nosynctest1f1fa29publicsuffix: regenerate table1215081http2: improve error when server sends HTTP/1312450ehtml: ensure <search> tag closes <p> and update tests09731f9http2: improve handling of lost PING in Server55989e2http2/h2c: use ResponseController for hijacking connections2914f46websocket: re-recommend gorilla/websocket99b3ae0go.mod: update golang.org/x dependencies85d1d54go.mod: update golang.org/x dependenciesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.