Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Sep 18, 2024

Bumps the go_modules group with 4 updates in the / directory: github.com/aws/aws-sdk-go, github.com/coredns/coredns, github.com/nats-io/nats-server/v2 and github.com/nats-io/nats-streaming-server.

Updates github.com/aws/aws-sdk-go from 1.20.21 to 1.34.0

Changelog

Sourced from github.com/aws/aws-sdk-go's changelog.

Release v1.34.0 (2020-08-07)

Service Client Updates

  • service/glue: Updates service API and documentation
    • AWS Glue now adds support for Network connection type enabling you to access resources inside your VPC using Glue crawlers and Glue ETL jobs.
  • service/organizations: Updates service API and documentation
    • Documentation updates for some new error reasons.
  • service/s3: Updates service documentation and examples
    • Updates Amazon S3 API reference documentation.
  • service/sms: Updates service API and documentation
    • In this release, AWS Server Migration Service (SMS) has added new features: 1. APIs to work with application and instance level validation 2. Import application catalog from AWS Application Discovery Service 3. For an application you can start on-demand replication

SDK Features

  • service/s3/s3crypto: Updates to the Amazon S3 Encryption Client - This change includes fixes for issues that were reported by Sophie Schmieg from the Google ISE team, and for issues that were discovered by AWS Cryptography.

Release v1.33.21 (2020-08-06)

Service Client Updates

  • service/ec2: Updates service API, documentation, and paginators
    • This release supports Wavelength resources, including carrier gateways, and carrier IP addresses.
  • service/lex-models: Updates service API and documentation
  • service/personalize: Updates service API and documentation
  • service/personalize-events: Updates service API and documentation
  • service/personalize-runtime: Updates service API and documentation
  • service/runtime.lex: Updates service API and documentation

Release v1.33.20 (2020-08-05)

Service Client Updates

  • service/appsync: Updates service API and documentation
  • service/fsx: Updates service documentation
  • service/resourcegroupstaggingapi: Updates service documentation
    • Documentation updates for the Resource Group Tagging API namespace.
  • service/sns: Updates service documentation
    • Documentation updates for SNS.
  • service/transcribe: Updates service API, documentation, and paginators

Release v1.33.19 (2020-08-04)

Service Client Updates

  • service/health: Updates service documentation
    • Documentation updates for health

Release v1.33.18 (2020-08-03)

... (truncated)

Commits
  • ae9b9fd Release v1.34.0 (2020-08-07)
  • 1e84382 Merge commit '12ff57a16373dda5a0c22eafdf0fa1c4c224f7c4' into release
  • b811ea8 Release v1.33.21 (2020-08-06) (#3462)
  • 12ff57a Updates to the Amazon S3 Encryption Client - This change includes fixes for i...
  • 2007a98 Release v1.33.20 (2020-08-05) (#3460)
  • 39b4438 Release v1.33.19 (2020-08-04) (#3458)
  • e14cc11 Merge pull request #3432 from diehlaws/common-files-standardization
  • 9a13de7 Release v1.33.18 (2020-08-03) (#3456)
  • 41f3140 Add reference links to readme
  • 29d57fc Implementing suggested changes
  • Additional commits viewable in compare view

Updates github.com/coredns/coredns from 1.4.0 to 1.11.2

Release notes

Sourced from github.com/coredns/coredns's releases.

v1.11.1

This release fixes a major performance regression introduced in 1.11.0 that affected DoT (TLS) forwarded connections. It also adds a new option to dnstap to add metadata to the dnstap extra field, and fixes a config parsing bug in cache.

Brought to You By

Chris O'Haver, P. Radha Krishna, Yong Tang, Yuheng, Zhizhen He

Noteworthy Changes

v1.11.0

Release Highlights

  • Adds support for accepting DNS connections over QUIC (doq).
  • Adds CNAME target rewrites to the rewrite plugin.
  • Plus many bug fixes, and some security improvements.

This release introduces the following backward incompatible changes:

  • In the kubernetes plugin, we have dropped support for watching Endpoint and Endpointslice v1beta, since all supported K8s versions now use Endpointslice.
  • The bufsize plugin changed its default size limit value to 1232
  • Some changes to forward plugin metrics.

Brought to You By

Amila Senadheera, Antony Chazapis, Ayato Tokubi, Ben Kochie, Catena cyber, Chris O'Haver, Dan Salmon, Dan Wilson, Denis MACHARD, Diogenes Pelisson, Eng Zer Jun, Fish-pro, Gabor Dozsa, Gary McDonald, João Henri, Justin, Lio李歐,

... (truncated)

Changelog

Sourced from github.com/coredns/coredns's changelog.

Makefile for releasing CoreDNS

The release is controlled from coremain/version.go. The version found there is

used to tag the git repo and to build the assets that are uploaded to GitHub.

The release should be accompanied by release notes in the notes/ subdirectory.

These are published on coredns.io. For example see: notes/coredns-1.5.1.md

Use make -f Makefile.release notes to create a skeleton notes document.

For this to work properly you must fetch the tag of the previous release.

Be sure to prune the PR list a bit, not everything is worthy!

As seen in notes/coredns-1.5.1.md we want to style the notes in the following manner:

* important changes at the top

* people who committed/review code (the latter is harder to get)

* Slightly abbreviated list of pull requests merged for this release.

Steps to release, first:

1. Up the version in coremain/version.go

2. Do a make -f Makefile.doc # This has been automated in GitHub, so you can probably skip this step

3. go generate

4. Send PR to get this merged.

Then:

1. Open an issue for this release

2. In an issue give the command: /release master VERSION

Where VERSION is the version of the release - the release script double checks this with the

actual CoreDNS version in coremain/version.go

3. (to test as release /release -t master VERSION can be used.

See https://github.com/coredns/release for documentation README on what needs to be setup for this to be

automated (can still be done by hand if needed). Especially what environment variables need to be

set! This further depends on Caddy being setup and dreck running as a plugin in Caddy.

To release we run, these target from the this Makefile.release ordered like:

* make release

* make github-push

Testing this is hard-ish as you don't want to accidentally release a coredns. If not executing the github-push target

you should be fine.

Docker image creation and upload are now separate steps, because it often failed before. See the Makefile.docker for

details.

ifeq (, $(shell which curl)) $(error "No curl in $$PATH, please install") endif

... (truncated)

Commits

Updates github.com/miekg/dns from 1.1.8 to 1.1.58

Commits

Updates github.com/nats-io/nats-server/v2 from 2.1.2 to 2.9.23

Release notes

Sourced from github.com/nats-io/nats-server/v2's releases.

Release v2.9.23

Changelog

Go Version

  • 1.20.10

Fixed

Accounts

  • Prevent bypassing authorization block when enabling system account access in accounts block (#4605). Backport from v2.10.2

Leafnodes

  • Prevent a leafnode cluster from receiving a message multiple times in a queue subscription (#4578). Backport from v2.10.2

JetStream

  • Hold lock when calculating the first message for subject in a message block (#4531). Backport from v2.10.0
  • Add self-healing mechanism to detect and delete orphaned Raft groups (#4647). Backport from v2.10.0
  • Prevent forward proposals in consumers after scaling down a stream (#4647). Backport from v2.10.0
  • Fix race condition during leader failover scenarios resulting in potential duplicate messages being sourced (#4592). Backport from v2.10.2

Complete Changes

nats-io/nats-server@v2.9.22...v2.9.23

Release v2.9.22

Changelog

Go Version

  • 1.20.8 (updated out-of-cycle since Go 1.19 is now EOL)

Dependencies

  • github.com/nats-io/jwt/v2 v2.5.0
  • golang.org/x/crypto v0.12.0
  • golang.org/x/sys v0.11.0

Improved

Monitoring

  • CORS Allow-Origin passthrough for monitoring server (#4423) Thanks to @​mdawar for the contribution!

JetStream

  • Improve consumer scaling reliability with filters and cluster restart (#4404)
  • Send event on lame duck mode (LDM) to avoid placing assets on shutting down nodes (#4405)
  • Skip filestore tombstones if downgrade from 2.10 occurs (#4452)
  • Adjust delivered and waiting count when consumer message delivery fails (#4472)

Fixed

Config

  • Allow empty configs and fix JSON compatibility (#4394, #4418)
  • Remove TLS OCSP debug log on reload (#4453)

... (truncated)

Commits
  • 45436e1 Release v2.9.23 (#4652)
  • 72ffa38 Release v2.9.23
  • 05fe77f Backport #4592 to 2.9 (#4651)
  • 6a73e68 [2.9.x] Bump Travis Go version to 1.20.10 (#4650)
  • 8b981a2 Backports from v2.10 for v2.9.23 release (#4647)
  • 28eb7c0 Only setup auto no-auth for $G account iff no authorization block was defined.
  • 9f16edd Make sure to not forward a message across a route for dq sub when we are a sp...
  • 0ac7895 Add in utility to detect and delete any NRG orphans.
  • 50722e9 When scaling a consumer down make sure to pop the loopAndForwardProposals go ...
  • 770cf2e Backport JetStream benchmarks improvements to 2.9.x (#4644)
  • Additional commits viewable in compare view

Updates github.com/nats-io/nats-streaming-server from 0.14.2 to 0.24.6

Release notes

Sourced from github.com/nats-io/nats-streaming-server's releases.

Release v0.24.6

Changelog

Note that we added a deprecation notice for this project. See note here

Go Version

  • 1.17.9: Both release executables and Docker images are built with this Go release.

Updated

  • Dependencies
    • github.com/hashicorp/raft v1.3.7 -> v1.3.9
    • NATS Go client v1.14.0 -> v1.15.0
    • NATS Server v2.8.1 -> v2.8.2 (#1249)

Complete Changes

nats-io/nats-streaming-server@v0.24.5...v0.24.6

Release v0.24.5

Changelog

Note that we added a deprecation notice for this project. See note here

Go Version

  • 1.17.9: Both release executables and Docker images are built with this Go release.

Updated

  • Dependencies
    • golang.org/x/crypto due to a CVE scan. However, since this affects crypto/ssh that the server is not using, the vulnerability does not impact the NATS Server. Thank you to @​pgvishnuram for the contribution (#1247)
    • NATS Server v2.8.0 -> v2.8.1 (#1249)

Complete Changes

nats-io/nats-streaming-server@v0.24.4...v0.24.5

Release v0.24.4

Changelog

Note that we added a deprecation notice for this project. See note here

Go Version

  • 1.17.9: Both release executables and Docker images are built with this Go release.

Updated

  • Dependencies (#1242)
    • NATS Server v2.7.4 -> v2.8.0

... (truncated)

Commits

Updates github.com/prometheus/client_golang from 0.9.3-0.20190127221311-3c4408c8b829 to 1.17.0

Release notes

Sourced from github.com/prometheus/client_golang's releases.

v1.17.0

What's Changed

  • [CHANGE] Minimum required go version is now 1.19 (we also test client_golang against new 1.21 version). #1325
  • [FEATURE] Add support for Created Timestamps in Counters, Summaries and Historams. #1313
  • [ENHANCEMENT] Enable detection of a native histogram without observations. #1314

New Contributors

... (truncated)

Changelog

Sourced from github.com/prometheus/client_golang's changelog.

1.17.0 / 2023-09-27

  • [CHANGE] Minimum required go version is now 1.19 (we also test client_golang against new 1.21 version). #1325
  • [FEATURE] Add support for Created Timestamps in Counters, Summaries and Historams. #1313
  • [ENHANCEMENT] Enable detection of a native histogram without observations. #1314

1.16.0 / 2023-06-15

  • [BUGFIX] api: Switch to POST for LabelNames, Series, and QueryExemplars. #1252
  • [BUGFIX] api: Fix undefined execution order in return statements. #1260
  • [BUGFIX] native histograms: Fix bug in bucket key calculation. #1279
  • [ENHANCEMENT] Reduce constrainLabels allocations for all metrics. #1272
  • [ENHANCEMENT] promhttp: Add process start time header for scrape efficiency. #1278
  • [ENHANCEMENT] promlint: Improve metricUnits runtime. #1286

1.15.1 / 2023-05-3

  • [BUGFIX] Fixed promhttp.Instrument* handlers wrongly trying to attach exemplar to unsupported metrics (e.g. summary),
    causing panics. #1253

1.15.0 / 2023-04-13

  • [BUGFIX] Fix issue with atomic variables on ppc64le. #1171
  • [BUGFIX] Support for multiple samples within same metric. #1181
  • [BUGFIX] Bump golang.org/x/text to v0.3.8 to mitigate CVE-2022-32149. #1187
  • [ENHANCEMENT] Add exemplars and middleware examples. #1173
  • [ENHANCEMENT] Add more context to "duplicate label names" error to enable debugging. #1177
  • [ENHANCEMENT] Add constrained labels and constrained variant for all MetricVecs. #1151
  • [ENHANCEMENT] Moved away from deprecated github.com/golang/protobuf package. #1183
  • [ENHANCEMENT] Add possibility to dynamically get label values for http instrumentation. #1066
  • [ENHANCEMENT] Add ability to Pusher to add custom headers. #1218
  • [ENHANCEMENT] api: Extend and improve efficiency of json-iterator usage. #1225
  • [ENHANCEMENT] Added (official) support for go 1.20. #1234
  • [ENHANCEMENT] timer: Added support for exemplars. #1233
  • [ENHANCEMENT] Filter expected metrics as well in CollectAndCompare. #1143
  • [ENHANCEMENT] ⚠️ Only set start/end if time is not Zero. This breaks compatibility in experimental api package. If you strictly depend on empty time.Time as actual value, the behavior is now changed. #1238

1.14.0 / 2022-11-08

  • [FEATURE] Add Support for Native Histograms. #1150
  • [CHANGE] Extend prometheus.Registry to implement prometheus.Collector interface. #1103

1.13.1 / 2022-11-01

  • [BUGFIX] Fix race condition with Exemplar in Counter. #1146
  • [BUGFIX] Fix CumulativeCount value of +Inf bucket created from exemplar. #1148
  • [BUGFIX] Fix double-counting bug in promhttp.InstrumentRoundTripperCounter. #1118

1.13.0 / 2022-08-05

... (truncated)

Commits

Updates golang.org/x/crypto from 0.0.0-20191117063200-497ca9f6d64f to 0.18.0

Commits

Updates golang.org/x/net from 0.0.0-20200324143707-d3edc9973b7e to 0.20.0

Commits

Updates golang.org/x/sys from 0.0.0-20200323222414-85ca7c5b95cd to 0.16.0

Commits

Updates gopkg.in/yaml.v2 from 2.2.4 to 2.4.0

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

…ates

Bumps the go_modules group with 4 updates in the / directory: [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go), [github.com/coredns/coredns](https://github.com/coredns/coredns), [github.com/nats-io/nats-server/v2](https://github.com/nats-io/nats-server) and [github.com/nats-io/nats-streaming-server](https://github.com/nats-io/nats-streaming-server).


Updates `github.com/aws/aws-sdk-go` from 1.20.21 to 1.34.0
- [Release notes](https://github.com/aws/aws-sdk-go/releases)
- [Changelog](https://github.com/aws/aws-sdk-go/blob/v1.34.0/CHANGELOG.md)
- [Commits](aws/aws-sdk-go@v1.20.21...v1.34.0)

Updates `github.com/coredns/coredns` from 1.4.0 to 1.11.2
- [Release notes](https://github.com/coredns/coredns/releases)
- [Changelog](https://github.com/coredns/coredns/blob/master/Makefile.release)
- [Commits](https://github.com/coredns/coredns/commits)

Updates `github.com/miekg/dns` from 1.1.8 to 1.1.58
- [Changelog](https://github.com/miekg/dns/blob/master/Makefile.release)
- [Commits](miekg/dns@v1.1.8...v1.1.58)

Updates `github.com/nats-io/nats-server/v2` from 2.1.2 to 2.9.23
- [Release notes](https://github.com/nats-io/nats-server/releases)
- [Changelog](https://github.com/nats-io/nats-server/blob/main/.goreleaser.yml)
- [Commits](nats-io/nats-server@v2.1.2...v2.9.23)

Updates `github.com/nats-io/nats-streaming-server` from 0.14.2 to 0.24.6
- [Release notes](https://github.com/nats-io/nats-streaming-server/releases)
- [Changelog](https://github.com/nats-io/nats-streaming-server/blob/main/.goreleaser.yml)
- [Commits](nats-io/nats-streaming-server@v0.14.2...v0.24.6)

Updates `github.com/prometheus/client_golang` from 0.9.3-0.20190127221311-3c4408c8b829 to 1.17.0
- [Release notes](https://github.com/prometheus/client_golang/releases)
- [Changelog](https://github.com/prometheus/client_golang/blob/main/CHANGELOG.md)
- [Commits](https://github.com/prometheus/client_golang/commits/v1.17.0)

Updates `golang.org/x/crypto` from 0.0.0-20191117063200-497ca9f6d64f to 0.18.0
- [Commits](https://github.com/golang/crypto/commits/v0.18.0)

Updates `golang.org/x/net` from 0.0.0-20200324143707-d3edc9973b7e to 0.20.0
- [Commits](https://github.com/golang/net/commits/v0.20.0)

Updates `golang.org/x/sys` from 0.0.0-20200323222414-85ca7c5b95cd to 0.16.0
- [Commits](https://github.com/golang/sys/commits/v0.16.0)

Updates `gopkg.in/yaml.v2` from 2.2.4 to 2.4.0

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go
  dependency-type: direct:production
  dependency-group: go_modules
- dependency-name: github.com/coredns/coredns
  dependency-type: direct:production
  dependency-group: go_modules
- dependency-name: github.com/miekg/dns
  dependency-type: direct:production
  dependency-group: go_modules
- dependency-name: github.com/nats-io/nats-server/v2
  dependency-type: direct:production
  dependency-group: go_modules
- dependency-name: github.com/nats-io/nats-streaming-server
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: github.com/prometheus/client_golang
  dependency-type: direct:production
  dependency-group: go_modules
- dependency-name: golang.org/x/crypto
  dependency-type: direct:production
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-type: direct:production
  dependency-group: go_modules
- dependency-name: golang.org/x/sys
  dependency-type: direct:production
  dependency-group: go_modules
- dependency-name: gopkg.in/yaml.v2
  dependency-type: direct:production
  dependency-group: go_modules
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 18, 2024
@sonarqubecloud
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant