chore(deps): update build tools#491
Merged
ttosta-google merged 2 commits intoGoogleCloudPlatform:mainfrom Jan 24, 2024
Merged
Conversation
b57480f to
a12887e
Compare
a12887e to
e203646
Compare
e203646 to
fab7570
Compare
fab7570 to
0571f54
Compare
0571f54 to
3d61606
Compare
3d61606 to
11e308a
Compare
11e308a to
14b2ca5
Compare
14b2ca5 to
db1d196
Compare
db1d196 to
9fde056
Compare
dccbdc0 to
82b2a1c
Compare
82b2a1c to
df97a2c
Compare
df97a2c to
705a77c
Compare
705a77c to
a4d34b9
Compare
a4d34b9 to
144c84d
Compare
144c84d to
d598491
Compare
d598491 to
b444da1
Compare
b444da1 to
29976ff
Compare
ttosta-google
approved these changes
Jan 24, 2024
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.13.2->v1.13.3v1.1.1->v1.3.0v1.6.3->v1.7.1Release Notes
cert-manager/cert-manager (cert-manager/cert-manager)
v1.13.3Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This patch release contains fixes for the following security vulnerabilities in the cert-manager-controller:
GO-2023-2334: Decryption of malicious PBES2 JWE objects can consume unbounded system resources.If you use ArtifactHub Security report or trivy, this patch will also silence the following warning about a vulnerability in code which is imported but not used by the cert-manager-controller:
CVE-2023-47108: DoS vulnerability inotelgrpcdue to unbound cardinality metrics.An ongoing security audit of cert-manager suggested some changes to the webhook code to mitigate DoS attacks, and these are included in this patch release.
Changes
Bug or Regression
>= 3MiB. This is to mitigate DoS attacks that attempt to crash the webhook process by sending large requests that exceed the available memory. (#6507, @inteon)ReadHeaderTimeoutin allhttp.Serverinstances. (#6538, @wallrj)otel,docker, andjoseto fix CVE alerts. See GHSA-8pgv-569h-w5rw, GHSA-jq35-85cj-fj4p, and GHSA-2c7c-3mj9-8fqh. (#6514, @inteon)Dependencies
Added
Nothing has changed.
Changed
cloud.google.com/go/firestore:v1.11.0 → v1.12.0cloud.google.com/go:v0.110.6 → v0.110.7github.com/felixge/httpsnoop:v1.0.3 → v1.0.4github.com/go-jose/go-jose/v3:v3.0.0 → v3.0.1github.com/go-logr/logr:v1.2.4 → v1.3.0github.com/golang/glog:v1.1.0 → v1.1.2github.com/google/go-cmp:v0.5.9 → v0.6.0go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc:v0.45.0 → v0.46.0go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp:v0.44.0 → v0.46.0go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc:v1.19.0 → v1.20.0go.opentelemetry.io/otel/exporters/otlp/otlptrace:v1.19.0 → v1.20.0go.opentelemetry.io/otel/metric:v1.19.0 → v1.20.0go.opentelemetry.io/otel/sdk:v1.19.0 → v1.20.0go.opentelemetry.io/otel/trace:v1.19.0 → v1.20.0go.opentelemetry.io/otel:v1.19.0 → v1.20.0go.uber.org/goleak:v1.2.1 → v1.3.0golang.org/x/sys:v0.13.0 → v0.14.0google.golang.org/genproto/googleapis/api:f966b18 → b8732ecgoogle.golang.org/genproto:f966b18 → b8732ecgoogle.golang.org/grpc:v1.58.3 → v1.59.0Removed
Nothing has changed.
google-github-actions/auth (google-github-actions/auth)
v1.3.0Compare Source
What's Changed
Full Changelog: google-github-actions/auth@v1...v1.3.0
v1.2.0Compare Source
What's Changed
New Contributors
Full Changelog: google-github-actions/auth@v1...v1.2.0
hashicorp/terraform (hashicorp/terraform)
v1.7.1Compare Source
1.7.1 (January 24, 2024)
BUG FIXES:
terraform test: Fix crash when referencing variables or functions within the file levelvariablesblock. (#34531)terraform test: Fix crash whenoverride_moduleblock was missing theoutputsattribute. (#34563)v1.7.0Compare Source
1.7.0 (January 17, 2024)
UPGRADE NOTES:
Input validations are being restored to the state file in this version of Terraform. Due to a state interoperability issue (#33770) in earlier versions, users that require interaction between different minor series should ensure they have upgraded to the following patches:
This is important for users with
terraform_remote_statedata sources reading remote state across different versions of Terraform.nonsensitivefunction no longer raises an error when applied to a value that is already non-sensitive. (#33856)terraform graphnow produces a simplified graph describing only relationships between resources by default, for consistency with the granularity of information returned by other commands that emphasize resources as the main interesting object type and de-emphasize the other "glue" objects that connect them.The type of graph that earlier versions of Terraform produced by default is still available with explicit use of the
-type=planoption, producing an approximation of the real dependency graph Terraform Core would use to construct a plan.terraform test: Simplify the ordering of destroy operations during test cleanup to simple reverse run block order. (#34293)backend/s3: The
use_legacy_workflowargument now defaults tofalse. The backend will now search for credentials in the same order as the default provider chain in the AWS SDKs and AWS CLI. To revert to the legacy credential provider chain ordering, set this value totrue. This argument, and the ability to use the legacy workflow, is deprecated. To encourage consistency with the AWS SDKs, this argument will be removed in a future minor version.NEW FEATURES:
terraform test: Providers, modules, resources, and data sources can now be mocked during executions ofterraform test. The following new blocks have been introduced within.tftest.hclfiles:mock_provider: Can replace provider instances with mocked providers, allowing tests to execute incommand = applymode without requiring a configured cloud provider account and credentials. Terraform will create fake resources for mocked providers and maintain them in state for the lifecycle of the given test file.override_resource: Specific resources can be overridden so Terraform will create a fake resource with custom values instead of creating infrastructure for the overridden resource.override_data: Specific data sources can be overridden so data can be imported into tests without requiring real infrastructure to be created externally first.override_module: Specific modules can be overridden in their entirety to give greater control over the returned outputs without requiring in-depth knowledge of the module itself.removedblock for refactoring modules: Module authors can now record in source code when a resource or module call has been removed from configuration, and can inform Terraform whether the corresponding object should be deleted or simply removed from state.This effectively provides a configuration-driven workflow to replace
terraform state rm. Removing an object from state is a new type of action which is planned and applied like any other. Theterraform state rmcommand will remain available for scenarios in which directly modifying the state file is appropriate.BUG FIXES:
cdfailure. (#34128)terraform test: Stop attempting to destroy run blocks that have no actual infrastructure to destroy. This fixes an issue where attempts to destroy "verification" run blocks that load only data sources would fail if the underlying infrastructure referenced by the run blocks had already been destroyed. (#34331)terraform test: Improve error message for invalid run block names. (#34469)terraform test: Fix bug where outputs in "empty" modules were not available to the assertions from Terraform test files. (#34482)local-execandfileprovisioners connecting to remote hosts using SSH. (#34426)ENHANCEMENTS:
terraform test: Providers defined within test files can now reference variables from their configuration that are defined within the test file. (#34069)terraform test: Providers defined within test files can now reference outputs from run blocks. (#34118)terraform test: Terraform functions are now available within variables and provider blocks within test files. (#34204)terraform test: Terraform will now load variables from anyterraform.tfvarswithin the testing directory, and apply the variable values to tests within the same directory. (#34341)terraform graph: Now produces a simplified resources-only graph by default. (#34288)terraform console: Now supports a-planoption which allows evaluating expressions against the planned new state, rather than against the prior state. This provides a more complete set of values for use in console expressions, at the expense of a slower startup time due first calculating the plan. (#34342)import:for_eachcan now be used to expand theimportblock to handle multiple resource instances (#33932)postconditionblock or aprevent_destroysetting, Terraform will now include that proposed change in the plan output alongside the relevant error, whereas before the error would replace the proposed change in the output. (#34312).terraformignore: improve performance when ignoring large directories (#34400)Previous Releases
For information on prior major and minor releases, see their changelogs:
v1.6.6Compare Source
1.6.6 (December 13, 2023)
BUG FIXES:
terraform test: Stop attempting to destroy run blocks that have no actual infrastructure to destroy. This fixes an issue where attempts to destroy "verification" run blocks that load only data sources would fail if the underlying infrastructure referenced by the run blocks had already been destroyed. (#34331)v1.6.5Compare Source
1.6.5 (November 29, 2023)
BUG FIXES:
v1.6.4Compare Source
1.6.4 (November 15, 2023)
ENHANCEMENTS:
endpoints.ssoto allow overriding the AWS SSO API endpoint. (#34195)BUG FIXES:
terraform test: Fix bug preventing passing sensitive output values from previous run blocks as inputs to future run blocks. (#34190)https_proxyandno_proxyparameters to allow fully specifying proxy configuration (#34243)Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate. View repository job log here.