Skip to content

fix(deps): update all#38

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/all
Open

fix(deps): update all#38
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Jun 16, 2021

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Age Confidence
actions/cache action minor v3.0.4v3.5.0 age confidence
actions/checkout action minor v2.4.0v2.7.0 age confidence
codfish/semantic-release-action action minor v1.9.0v1.10.0 age confidence
github.com/stretchr/testify require minor v1.8.0v1.11.1 age confidence
github.com/tailscale/depaware require digest 720c4b4835d31c age confidence
go uses-with minor 1.16.x1.26.x age confidence
go.uber.org/multierr require minor v1.7.0v1.11.0 age confidence
go.uber.org/zap require minor v1.17.0v1.28.0 age confidence
golangci/golangci-lint uses-with minor v1.31v1.64.8 age confidence
golangci/golangci-lint-action action minor v3.2.0v3.7.1 age confidence

Release Notes

actions/cache (actions/cache)

v3.5.0

Compare Source

  • Bump actions/cache to v4.1.0

Full Changelog: actions/cache@v3...v3.5.0

v3.4.3

Compare Source

What's Changed

Full Changelog: actions/cache@v3.4.2...v3.4.3

v3.4.2

Compare Source

What's Changed

[!IMPORTANT]
As a reminder, there were important backend changes to release v3.4.0, see those release notes and the announcement for more details.

Full Changelog: actions/cache@v3.4.0...v3.4.2

v3.4.1

Compare Source

[!WARNING]
This version was incorrectly released using a SHA pointing to a newer version for immutable actions only. Please use v3.4.2 (or v3) instead.

v3.4.0

Compare Source

⚠️ Important Changes

The cache backend service has been rewritten from the ground up for improved performance and reliability. actions/cache now integrates with the new cache service (v2) APIs.

The new service will gradually roll out as of February 1st, 2025. The legacy service will also be sunset on the same date. Changes in these release are fully backward compatible.

We are deprecating some versions of this action. We recommend upgrading to version v4 or v3 as soon as possible before February 1st, 2025. (Upgrade instructions below).

If you are using pinned SHAs, please use the SHAs of versions v4.2.0 or v3.4.0

If you do not upgrade, all workflow runs using any of the deprecated actions/cache will fail.

Upgrading to the recommended versions will not break your workflows.

Read more about the change & access the migration guide: reference to the announcement.

Minor changes

Minor and patch version updates for these dependencies:

Full Changelog: actions/cache@v3.3.3...v3.4.0

v3.3.3

Compare Source

What's Changed

New Contributors

Full Changelog: actions/cache@v3...v3.3.3

v3.3.2

Compare Source

What's Changed

New Contributors

Full Changelog: actions/cache@v3...v3.3.2

v3.3.1

Compare Source

What's Changed

Full Changelog: actions/cache@v3...v3.3.1

v3.3.0

Compare Source

What's Changed

New Contributors

Full Changelog: actions/cache@v3...v3.3.0

v3.2.6

Compare Source

What's Changed

Full Changelog: actions/cache@v3...v3.2.6

v3.2.5

Compare Source

What's Changed

New Contributors

Full Changelog: actions/cache@v3...v3.2.5

v3.2.4

Compare Source

What's Changed

New Contributors

Full Changelog: actions/cache@v3...v3.2.4

v3.2.3

Compare Source

What's Changed

New Contributors

Full Changelog: actions/cache@v3...v3.2.3

v3.2.2

Compare Source

What's Changed

New Contributors

Full Changelog: actions/cache@v3.2.1...v3.2.2

v3.2.1

Compare Source

What's Changed

Full Changelog: actions/cache@v3.2.0...v3.2.1

v3.2.0

Compare Source

What's Changed

New Contributors

Full Changelog: actions/cache@v3...v3.2.0

v3.0.11

Compare Source

What's Changed

New Contributors

Full Changelog: actions/cache@v3...v3.0.11

v3.0.10

Compare Source

  • Fix a bug with sorting inputs.
  • Update definition for restore-keys in README.md

v3.0.9

Compare Source

  • Enhanced the warning message for cache unavailability in case of GHES.

v3.0.8

Compare Source

What's Changed

  • Fix zstd not working for windows on gnu tar in issues.
  • Allow users to provide a custom timeout as input for aborting cache segment download using the environment variable SEGMENT_DOWNLOAD_TIMEOUT_MIN. Default is 60 minutes.

v3.0.7

Compare Source

What's Changed
  • Fix for the download stuck problem has been added in actions/cache for users who were intermittently facing the issue. As part of this fix, new timeout has been introduced in the download step to stop the download if it doesn't complete within an hour and run the rest of the workflow without erroring out.

v3.0.6

Compare Source

What's Changed
  • Add example for clojure lein project dependencies by @​shivamarora1 in PR #​835
  • Update toolkit's cache npm module to latest. Bump cache version to v3.0.6 by @​pdotl in PR #​887
  • Fix issue #​809 where cache save/restore was failing for Amazon Linux 2 runners due to older tar version
  • Fix issue #​833 where cache save was not working for caching github workspace directory
New Contributors

Full Changelog: actions/cache@v3...v3.0.6

v3.0.5

Compare Source

Removed error handling by consuming actions/cache 3.0 toolkit, Now cache server error handling will be done by toolkit.

actions/checkout (actions/checkout)

v2.7.0

Compare Source

What's Changed

Full Changelog: actions/checkout@v2.6.0...v2.7.0

v2.6.0

Compare Source

What's Changed

Full Changelog: actions/checkout@v2.5.0...v2.6.0

v2.5.0

Compare Source

What's Changed

Full Changelog: actions/checkout@v2...v2.5.0

v2.4.2

Compare Source

What's Changed

Full Changelog: actions/checkout@v2...v2.4.2

v2.4.1

Compare Source

  • Fixed an issue where checkout failed to run in container jobs due to the new git setting safe.directory
codfish/semantic-release-action (codfish/semantic-release-action)

v1.10.0

Compare Source

Features
stretchr/testify (github.com/stretchr/testify)

v1.11.1

Compare Source

This release fixes #​1785 introduced in v1.11.0 where expected argument values implementing the stringer interface (String() string) with a method which mutates their value, when passed to mock.Mock.On (m.On("Method", <expected>).Return()) or actual argument values passed to mock.Mock.Called may no longer match one another where they previously did match. The behaviour prior to v1.11.0 where the stringer is always called is restored. Future testify releases may not call the stringer method at all in this case.

What's Changed

Full Changelog: stretchr/testify@v1.11.0...v1.11.1

v1.11.0

Compare Source

What's Changed

Functional Changes

v1.11.0 Includes a number of performance improvements.

Fixes
Documentation, Build & CI

New Contributors

Full Changelog: stretchr/testify@v1.10.0...v1.11.0

v1.10.0

Compare Source

What's Changed
Functional Changes
Fixes
Documentation, Build & CI
New Contributors

Full Changelog: stretchr/testify@v1.9.0...v1.10.0

v1.9.0

Compare Source

What's Changed

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot requested a review from moul as a code owner June 16, 2021 12:16
@auto-add-label auto-add-label Bot added the bug Something isn't working label Jun 16, 2021
@codecov

codecov Bot commented Jun 16, 2021

Copy link
Copy Markdown

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 73.33%. Comparing base (519baed) to head (87667d7).

❗ Current head 87667d7 differs from pull request most recent head ccbfd12. Consider uploading reports for the commit ccbfd12 to get more accurate results

Additional details and impacted files
@@           Coverage Diff           @@
##           master      #38   +/-   ##
=======================================
  Coverage   73.33%   73.33%           
=======================================
  Files           2        2           
  Lines         120      120           
=======================================
  Hits           88       88           
  Misses         31       31           
  Partials        1        1           
Flag Coverage Δ
unittests 73.33% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@renovate renovate Bot changed the title fix(deps): update module moul.io/u to v1.25.0 fix(deps): update module moul.io/u to v1.25.0 - autoclosed Jun 21, 2021
@renovate renovate Bot closed this Jun 21, 2021
@trafico-bot trafico-bot Bot added the 🔍 Ready for Review Pull Request is not reviewed yet label Jun 21, 2021
@renovate renovate Bot deleted the renovate/all branch June 21, 2021 22:12
@renovate renovate Bot changed the title fix(deps): update module moul.io/u to v1.25.0 - autoclosed fix(deps): update module moul.io/u to v1.25.0 Jun 21, 2021
@renovate renovate Bot reopened this Jun 21, 2021
@renovate renovate Bot restored the renovate/all branch June 21, 2021 23:53
@renovate renovate Bot changed the title fix(deps): update module moul.io/u to v1.25.0 fix(deps): update all Jun 22, 2021
@renovate renovate Bot force-pushed the renovate/all branch 2 times, most recently from a9b6884 to b04c6e8 Compare June 28, 2021 19:36
@renovate renovate Bot force-pushed the renovate/all branch 2 times, most recently from d19b529 to 13eed18 Compare July 7, 2021 18:29
@renovate renovate Bot changed the title fix(deps): update all chore(deps): update all Oct 20, 2021
@auto-add-label auto-add-label Bot added dependencies and removed bug Something isn't working labels Oct 20, 2021
@renovate renovate Bot changed the title chore(deps): update all fix(deps): update module go.uber.org/zap to v1.19.1 Nov 19, 2021
@auto-add-label auto-add-label Bot added bug Something isn't working and removed dependencies labels Nov 19, 2021
@renovate renovate Bot changed the title fix(deps): update module go.uber.org/zap to v1.19.1 chore(deps): update all Nov 23, 2021
@auto-add-label auto-add-label Bot added dependencies and removed bug Something isn't working labels Nov 23, 2021
@renovate renovate Bot force-pushed the renovate/all branch 2 times, most recently from 6aab188 to 1ea308b Compare August 11, 2022 11:55
@renovate renovate Bot force-pushed the renovate/all branch 2 times, most recently from e478426 to 45e076c Compare August 24, 2022 17:01
@renovate renovate Bot force-pushed the renovate/all branch 2 times, most recently from cdf60be to 65b2343 Compare March 24, 2023 23:16
@renovate renovate Bot force-pushed the renovate/all branch 3 times, most recently from 8b497ff to 303769b Compare June 2, 2023 12:40
@renovate renovate Bot force-pushed the renovate/all branch 2 times, most recently from 1e2c09d to 172c148 Compare September 14, 2023 22:50
@renovate renovate Bot changed the title chore(deps): update all fix(deps): update all Dec 10, 2024
@socket-security

socket-security Bot commented Aug 13, 2025

Copy link
Copy Markdown

@renovate

renovate Bot commented Apr 26, 2026

Copy link
Copy Markdown
Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.13 -> 1.26

@socket-security

socket-security Bot commented Jun 7, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: golang golang.org/x/tools is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?golang/github.com/tailscale/depaware@v0.0.0-20260426051615-835d31c2ca68golang/golang.org/x/tools@v0.44.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/golang.org/x/tools@v0.44.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies 🔍 Ready for Review Pull Request is not reviewed yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants