Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump the minor group with 5 updates #3428

Open
wants to merge 1 commit into
base: release-4.2
Choose a base branch
from

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 13, 2024

Bumps the minor group with 5 updates:

Package From To
github.com/sylabs/scs-build-client 0.9.13 0.9.14
github.com/sylabs/sif/v2 2.19.1 2.20.0
github.com/sylabs/squashfs 1.0.0 1.0.4
golang.org/x/crypto 0.30.0 0.31.0
google.golang.org/grpc 1.67.2 1.69.0

Updates github.com/sylabs/scs-build-client from 0.9.13 to 0.9.14

Release notes

Sourced from github.com/sylabs/scs-build-client's releases.

v0.9.14

What's Changed

Full Changelog: sylabs/scs-build-client@v0.9.13...v0.9.14

Commits
  • 23f1379 build(deps): bump golang.org/x/crypto from 0.28.0 to 0.31.0 (#267)
  • c339e78 Merge pull request #266 from sylabs/dependabot/go_modules/golang.org/x/term-0...
  • b14f666 build(deps): bump golang.org/x/term from 0.26.0 to 0.27.0
  • 7c8a9dd Merge pull request #265 from sylabs/dependabot/go_modules/github.com/ProtonMa...
  • dff698e build(deps): bump github.com/ProtonMail/go-crypto from 1.1.2 to 1.1.3
  • 97aad71 Merge pull request #264 from sylabs/dependabot/go_modules/github.com/stretchr...
  • dc3b1f5 build(deps): bump github.com/stretchr/testify from 1.9.0 to 1.10.0
  • 25caa17 Merge pull request #263 from sylabs/dependabot/go_modules/github.com/sylabs/s...
  • 8f35f70 build(deps): bump github.com/sylabs/sif/v2 from 2.19.2 to 2.20.0
  • a098bcc Merge pull request #262 from sylabs/dependabot/go_modules/github.com/ProtonMa...
  • Additional commits viewable in compare view

Updates github.com/sylabs/sif/v2 from 2.19.1 to 2.20.0

Release notes

Sourced from github.com/sylabs/sif/v2's releases.

v2.20.0

What's Changed

Full Changelog: sylabs/sif@v2.19.2...v2.20.0

v2.19.2

What's Changed

Full Changelog: sylabs/sif@v2.19.1...v2.19.2

Commits
  • e458cb9 Merge pull request #391 from sylabs/dependabot/go_modules/main/github.com/Pro...
  • 071c3a8 fix: corpus image generation
  • 869cab3 build(deps): bump github.com/ProtonMail/go-crypto from 1.0.0 to 1.1.2
  • faccf54 build(deps): bump github.com/sigstore/sigstore from 1.8.9 to 1.8.10 (#387)
  • d08b6c1 Merge pull request #386 from tri-adam/golangci-lint-v1.61
  • 0d09c53 ci: bump golangci-lint to v1.61
  • a270847 build(deps): bump github.com/sigstore/sigstore from 1.8.8 to 1.8.9 (#385)
  • See full diff in compare view

Updates github.com/sylabs/squashfs from 1.0.0 to 1.0.4

Commits

Updates golang.org/x/crypto from 0.30.0 to 0.31.0

Commits

Updates google.golang.org/grpc from 1.67.2 to 1.69.0

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.69.0

Known Issues

  • The recently added grpc.NewClient function is incompatible with forward proxies, because it resolves the target hostname on the client instead of passing the hostname to the proxy. A fix is expected to be a part of grpc-go v1.70. (#7556)

New Features

  • stats/opentelemetry: Introduce new APIs to enable OpenTelemetry instrumentation for metrics on servers and clients (#7874)
  • xdsclient: add support to fallback to lower priority servers when higher priority ones are down (#7701)
  • dns: Add support for link local IPv6 addresses (#7889)
  • The new experimental pickfirst LB policy (disabled by default) supports Happy Eyeballs, interleaving IPv4 and IPv6 address as described in RFC-8305 section 4, to attempt connections to multiple backends concurrently. The experimental pickfirst policy can be enabled by setting the environment variable GRPC_EXPERIMENTAL_ENABLE_NEW_PICK_FIRST to true. (#7725, #7742)
  • balancer/pickfirst: Emit metrics from the pick_first load balancing policy (#7839)
  • grpc: export MethodHandler, which is the type of an already-exported field in MethodDesc (#7796)

Bug Fixes

  • credentials/google: set scope for application default credentials (#7887)
  • xds: fix edge-case issues where some clients or servers would not initialize correctly or would not receive errors when resources are invalid or unavailable if another channel or server with the same target was already in use . (#7851, #7853)
  • examples: fix the debugging example, which was broken by a recent change (#7833)

Behavior Changes

  • client: update retry attempt backoff to apply jitter per updates to gRFC A6. (#7869)
  • balancer/weightedroundrobin: use the pick_first LB policy to manage connections (#7826)

API Changes

  • balancer: An internal method is added to the balancer.SubConn interface to force implementors to embed a delegate implementation. This requirement is present in the interface documentation, but wasn't enforced earlier. (#7840)

Performance Improvements

  • mem: implement a ReadAll() method for more efficient io.Reader consumption (#7653)
  • mem: use slice capacity instead of length to determine whether to pool buffers or directly allocate them (#7702)

Documentation

  • examples/csm_observability: Add xDS Credentials and switch server to be xDS enabled (#7875)

Release 1.68.1

Bug Fixes

  • credentials/alts: avoid SRV and TXT lookups for handshaker service to work around hangs caused by buggy versions of systemd-resolved. (#7861)

Dependencies

... (truncated)

Commits
  • 317271b pickfirst: Register a health listener when used as a leaf policy (#7832)
  • 5565631 balancer/pickfirst: replace grpc.Dial with grpc.NewClient in tests (#7879)
  • 634497b test: Split import paths for generated message and service code (#7891)
  • 78aa51b pickfirst: Stop test servers without closing listeners (#7872)
  • 00272e8 dns: Support link local IPv6 addresses (#7889)
  • 17d08f7 scripts/gen-deps: filter out grpc modules (#7890)
  • ab189b0 examples/features/csm_observability: Add xDS Credentials (#7875)
  • 3ce87dd credentials/google: Add cloud-platform scope for ADC (#7887)
  • 3c0586a stats/opentelemetry: Cleanup OpenTelemetry API's before stabilization (#7874)
  • 4c07bca stream: add jitter to retry backoff in accordance with gRFC A6 (#7869)
  • Additional commits viewable in compare view

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
github.com/sylabs/sif/v2 [< 2.20, > 2.19.1]
google.golang.org/grpc [>= 1.68.a, < 1.69]
github.com/sylabs/sif/v2 [>= 2.20.a, < 2.21]

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [github.com/sylabs/scs-build-client](https://github.com/sylabs/scs-build-client) | `0.9.13` | `0.9.14` |
| [github.com/sylabs/sif/v2](https://github.com/sylabs/sif) | `2.19.1` | `2.20.0` |
| [github.com/sylabs/squashfs](https://github.com/sylabs/squashfs) | `1.0.0` | `1.0.4` |
| [golang.org/x/crypto](https://github.com/golang/crypto) | `0.30.0` | `0.31.0` |
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.67.2` | `1.69.0` |


Updates `github.com/sylabs/scs-build-client` from 0.9.13 to 0.9.14
- [Release notes](https://github.com/sylabs/scs-build-client/releases)
- [Changelog](https://github.com/sylabs/scs-build-client/blob/main/.goreleaser.yml)
- [Commits](sylabs/scs-build-client@v0.9.13...v0.9.14)

Updates `github.com/sylabs/sif/v2` from 2.19.1 to 2.20.0
- [Release notes](https://github.com/sylabs/sif/releases)
- [Changelog](https://github.com/sylabs/sif/blob/main/.goreleaser.yml)
- [Commits](sylabs/sif@v2.19.1...v2.20.0)

Updates `github.com/sylabs/squashfs` from 1.0.0 to 1.0.4
- [Release notes](https://github.com/sylabs/squashfs/releases)
- [Commits](sylabs/squashfs@v1.0.0...v1.0.4)

Updates `golang.org/x/crypto` from 0.30.0 to 0.31.0
- [Commits](golang/crypto@v0.30.0...v0.31.0)

Updates `google.golang.org/grpc` from 1.67.2 to 1.69.0
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.67.2...v1.69.0)

---
updated-dependencies:
- dependency-name: github.com/sylabs/scs-build-client
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor
- dependency-name: github.com/sylabs/sif/v2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor
- dependency-name: github.com/sylabs/squashfs
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor
- dependency-name: golang.org/x/crypto
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor
- dependency-name: google.golang.org/grpc
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Dec 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants