Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump github.com/xmidt-org/webpa-common/v2 from 2.0.7 to 2.1.0 #87

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 12, 2023

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps github.com/xmidt-org/webpa-common/v2 from 2.0.7 to 2.1.0.

Release notes

Sourced from github.com/xmidt-org/webpa-common/v2's releases.

v2.1.0 2023-01-11

Changelog

Sourced from github.com/xmidt-org/webpa-common/v2's changelog.

[v2.1.0]

Commits
  • 8336f9b Merge pull request #720 from xmidt-org/denopink/release/v2.1.0
  • a47446f Merge branch 'main' into denopink/release/v2.1.0
  • 395febe Bump go.uber.org/fx from 1.19.0 to 1.19.1 (#766)
  • 28e6b33 Merge branch 'main' into denopink/release/v2.1.0
  • 34fef03 Merge pull request #708 from xmidt-org/denopink/refactoring/archive-webpa-com...
  • 5b1562f fix logging bug
  • eeb8937 reverting service/servicecfg packages back to use gokit log because of gokitz...
  • 576cf50 reverting service/consul packages back to use gokit log because of gokitzk.Ne...
  • 1aceb5c fix unit tests
  • 837c1e0 Merge branch 'main' into denopink/refactoring/archive-webpa-common/logging
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jan 12, 2023
@github-actions github-actions bot enabled auto-merge (squash) January 12, 2023 12:06
@guardrails
Copy link

guardrails bot commented Jan 12, 2023

⚠️ We detected 25 security issues in this pull request:

Vulnerable Libraries (25)
Severity Details
N/A pkg:golang/golang.org/x/net@v0.2.0@v0.2.0 upgrade to: 1.18.9,1.19.4,0.4.0
N/A pkg:golang/golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e@v0.0.0-20220624214902-1bab6f366d9e upgrade to: 1.18.9,1.19.4,0.4.0
N/A pkg:golang/golang.org/x/net@v0.0.0-20220725212005-46097bf591d3@v0.0.0-20220725212005-46097bf591d3 upgrade to: 1.18.6,1.19.1,0.0.0-20220906165146-f3363e06e74c
N/A pkg:golang/github.com/aws/aws-sdk-go@v1.44.177@v1.44.177 - no patch available
High pkg:golang/github.com/hashicorp/consul/api@v1.15.3@v1.15.3 - no patch available
N/A pkg:golang/github.com/hashicorp/consul/api@v1.4.0@v1.4.0 - no patch available
N/A pkg:golang/github.com/aws/aws-sdk-go@v1.44.176@v1.44.176 - no patch available
High pkg:golang/github.com/hashicorp/consul/sdk@v0.11.0@v0.11.0 - no patch available
N/A pkg:golang/golang.org/x/net@v0.3.0@v0.3.0 upgrade to: 1.18.9,1.19.4,0.4.0
N/A pkg:golang/golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b@v0.0.0-20221014081412-f15817d10f9b upgrade to: 1.18.9,1.19.4,0.4.0
N/A pkg:golang/golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9@v0.0.0-20220617184016-355a448f1bc9 upgrade to: 1.18.6,1.19.1,0.0.0-20220906165146-f3363e06e74c
N/A pkg:golang/golang.org/x/net@v0.1.0@v0.1.0 upgrade to: 1.18.9,1.19.4,0.4.0
High pkg:golang/github.com/hashicorp/consul/api@v1.3.0@v1.3.0 - no patch available
High pkg:golang/github.com/hashicorp/consul/sdk@v0.13.0@v0.13.0 - no patch available
N/A pkg:golang/golang.org/x/net@v0.0.0-20220927171203-f486391704dc@v0.0.0-20220927171203-f486391704dc upgrade to: 1.18.9,1.19.4,0.4.0
High pkg:golang/github.com/hashicorp/consul/api@v1.18.0@v1.18.0 - no patch available
N/A pkg:golang/golang.org/x/net@v0.0.0-20220909164309-bea034e7d591@v0.0.0-20220909164309-bea034e7d591 upgrade to: 1.18.9,1.19.4,0.4.0
N/A pkg:golang/golang.org/x/net@v0.0.0-20220607020251-c690dde0001d@v0.0.0-20220607020251-c690dde0001d upgrade to: 1.18.9,1.19.4,0.4.0
N/A pkg:golang/golang.org/x/net@v0.0.0-20221012135044-0b7e1fb9d458@v0.0.0-20221012135044-0b7e1fb9d458 upgrade to: 1.18.9,1.19.4,0.4.0
N/A pkg:golang/golang.org/x/net@v0.0.0-20221004154528-8021a29435af@v0.0.0-20221004154528-8021a29435af upgrade to: 1.18.9,1.19.4,0.4.0
N/A pkg:golang/github.com/hashicorp/consul/api@v1.4.0@v1.4.0 - no patch available
High pkg:golang/github.com/hashicorp/consul/api@v1.3.0@v1.3.0 - no patch available
High pkg:golang/github.com/nats-io/nats-server/v2@v2.5.0@v2.5.0 - no patch available
High pkg:golang/github.com/nats-io/nats-server/v2@v2.5.0@v2.5.0 - no patch available
High pkg:golang/github.com/nats-io/nats-server/v2@v2.5.0@v2.5.0 - no patch available

More info on how to fix Vulnerable Libraries in Go.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

@codecov
Copy link

codecov bot commented Jan 12, 2023

Codecov Report

Merging #87 (ecd766c) into main (129e46f) will not change coverage.
The diff coverage is n/a.

❗ Current head ecd766c differs from pull request most recent head f800cea. Consider uploading reports for the commit f800cea to get more accurate results

@@           Coverage Diff           @@
##             main      #87   +/-   ##
=======================================
  Coverage   68.42%   68.42%           
=======================================
  Files          12       12           
  Lines         361      361           
=======================================
  Hits          247      247           
  Misses        111      111           
  Partials        3        3           
Flag Coverage Δ
unittests 68.42% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

Bumps [github.com/xmidt-org/webpa-common/v2](https://github.com/xmidt-org/webpa-common) from 2.0.7 to 2.1.0.
- [Release notes](https://github.com/xmidt-org/webpa-common/releases)
- [Changelog](https://github.com/xmidt-org/webpa-common/blob/main/CHANGELOG.md)
- [Commits](xmidt-org/webpa-common@v2.0.7...v2.1.0)

---
updated-dependencies:
- dependency-name: github.com/xmidt-org/webpa-common/v2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/xmidt-org/webpa-common/v2-2.1.0 branch from ecd766c to f800cea Compare January 12, 2023 12:12
@github-actions github-actions bot merged commit 9f00390 into main Jan 12, 2023
@github-actions github-actions bot deleted the dependabot/go_modules/github.com/xmidt-org/webpa-common/v2-2.1.0 branch January 12, 2023 12:14
@sonarcloud
Copy link

sonarcloud bot commented Jan 12, 2023

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants