-
-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
build(deps): bump github.com/securego/gosec/v2 from 2.20.0 to 5f0084eb01a9 #4748
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
ldez
added
dependencies
Relates to an upstream dependency
linter: update version
Update version of linter
go
Pull requests that update Go code
labels
May 25, 2024
bombsimon
approved these changes
May 25, 2024
This was referenced Jun 14, 2024
codeboten
pushed a commit
to open-telemetry/opentelemetry-collector-contrib
that referenced
this pull request
Jun 14, 2024
**Description:** <Describe what has changed.> <!--Ex. Fixing a bug - Describe the bug and how this fixes the issue. Ex. Adding a feature - Explain what this achieves.--> The upstream issue was fixed by golangci/golangci-lint#4748, which was included in release [`v1.59.0`](https://github.com/golangci/golangci-lint/releases/tag/v1.59.0) of `golangci-lint`. From local testing, we're pulling version `v1.59.1` of `golangci-lint`, so the issue should be resolved. Local runtime with excludes: ``` $ .tools/golangci-lint run -v --enable-only gosec ... INFO Execution took 10.927544867s INFO Execution took 8.011302204s INFO Execution took 7.716441258s INFO Execution took 7.441336833s ``` Local runtime without excludes: ``` $ .tools/golangci-lint run -v --enable-only gosec ... INFO Execution took 9.780250262s INFO Execution took 8.175492516s INFO Execution took 7.550060974s INFO Execution took 7.526585686s ``` Note: I ran `.tools/golangci-lint cache clean` between each test to clean the cache and keep results as consistent as possible. I admit that I don't know why the values keep going down with every run, the cache cleaning command may not entirely be working. **Link to tracking Issue:** <Issue number if applicable> These excludes were introduced in #33192 I've opened a PR in core for this issue as well: open-telemetry/opentelemetry-collector#10411
codeboten
pushed a commit
to open-telemetry/opentelemetry-collector
that referenced
this pull request
Jun 14, 2024
#### Description The upstream issue was fixed by golangci/golangci-lint#4748, which was included in release [`v1.59.0`](https://github.com/golangci/golangci-lint/releases/tag/v1.59.0) of `golangci-lint`. From local testing, we're pulling version `v1.59.0` of `golangci-lint`, so the issue should be resolved. Local runtime with excludes: ``` $ .tools/golangci-lint run -v --enable-only gosec ... INFO Execution took 1.866075148s INFO Execution took 1.218805785s INFO Execution took 1.09527985s ``` Local runtime without excludes: ``` $ .tools/golangci-lint run -v --enable-only gosec ... INFO Execution took 2.244716429s INFO Execution took 1.539717296s INFO Execution took 1.530163777s ``` Note: I ran `.tools/golangci-lint cache clean` between each test to clean the cache and keep results as consistent as possible. <!-- Issue number if applicable --> #### Link to tracking issue Fixes #10213
This was referenced Aug 20, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
dependencies
Relates to an upstream dependency
go
Pull requests that update Go code
linter: update version
Update version of linter
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The update is done by hand because gosec is not released yet, and this is an important performance issue.
This update is safe because it only contains the Go version fix.
securego/gosec@v2.20.0...5f0084e
Comparison with v1.58.1:
Comparison with v1.58.2:
Those benchmarks are done with a
golangci-lint cache clean
before each benchmark.Fixes #4735