Skip to content

Update go version, bump direct deps to latest minor/patch, address supply chain security alert, remove unused pipeline yml, configure dependabot#158

Draft
gerrytan wants to merge 7 commits into
mainfrom
dependabot-and-cve-fixes
Draft

Update go version, bump direct deps to latest minor/patch, address supply chain security alert, remove unused pipeline yml, configure dependabot#158
gerrytan wants to merge 7 commits into
mainfrom
dependabot-and-cve-fixes

Conversation

@gerrytan
Copy link
Copy Markdown
Member

@gerrytan gerrytan commented May 26, 2026

Summary

  • Bump the module to Go 1.25.10 and bump all direct dependencies to latest minor/patch semver
  • Remove the unused Azure Pipelines YAML, update the schema pipeline to read the Go version from go.mod, and move the build pool to Ubuntu 24.04, Ubuntu 22 is no longer supported.
  • Add Dependabot version update configuration so dependency updates can be kept current automatically.
  • Update the Linux packaging Docker image base to Azure Linux to satisfy the supply chain security scanner.

Testing

@gerrytan gerrytan marked this pull request as draft May 26, 2026 06:55
@gerrytan gerrytan changed the title chore: refresh Go toolchain, dependencies, and CI images Update go version, bump direct deps to latest minor/patch, address supply chain security alert May 26, 2026
@gerrytan gerrytan changed the title Update go version, bump direct deps to latest minor/patch, address supply chain security alert Update go version, bump direct deps to latest minor/patch, address supply chain security alert, remove unused pipeline yml May 26, 2026
@gerrytan gerrytan changed the title Update go version, bump direct deps to latest minor/patch, address supply chain security alert, remove unused pipeline yml Update go version, bump direct deps to latest minor/patch, address supply chain security alert, remove unused pipeline yml, configure dependabot May 26, 2026
@gerrytan gerrytan requested a review from Copilot May 26, 2026 07:20
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review this pull request because it exceeds the maximum number of files (300). Try reducing the number of changed files and requesting a review from Copilot again.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants