Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bumping dependencies and go version #209

Merged
merged 2 commits into from
Feb 16, 2023

Conversation

marcsanmi
Copy link
Contributor

@marcsanmi marcsanmi commented Feb 14, 2023

Bump sarama package to update golang.org/x/net indirect dependency high vulnerability. The vuln was triggered in this pipeline's PR.

Screenshot 2023-02-14 at 17 21 49

As long assarama, I also bumped gojmx and sync and go version.

Note: I needed to regenerate the mocks since the interface changed.

@marcsanmi marcsanmi requested a review from a team February 14, 2023 16:25
@marcsanmi marcsanmi changed the title Bumping dependencies Bumping dependencies and go version Feb 14, 2023
@marcsanmi marcsanmi force-pushed the msanmiquel/fix-sarama-indirect-dependency-vuln branch from 484d735 to 312af02 Compare February 15, 2023 08:31
@marcsanmi marcsanmi force-pushed the msanmiquel/fix-sarama-indirect-dependency-vuln branch from c33c822 to 467f8de Compare February 15, 2023 12:49
@marcsanmi marcsanmi requested review from kilokang and a team February 15, 2023 12:57
Copy link
Contributor

@alvarocabanas alvarocabanas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@marcsanmi marcsanmi merged commit 28c2070 into master Feb 16, 2023
@marcsanmi marcsanmi deleted the msanmiquel/fix-sarama-indirect-dependency-vuln branch February 16, 2023 10:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants