Skip to content
This repository was archived by the owner on Jun 11, 2025. It is now read-only.

chore(deps): bump google.golang.org/grpc from 1.57.0 to 1.57.1#56

Merged
karthik1729 merged 1 commit into
release-1.0.5from
dependabot/go_modules/google.golang.org/grpc-1.57.1
Dec 16, 2023
Merged

chore(deps): bump google.golang.org/grpc from 1.57.0 to 1.57.1#56
karthik1729 merged 1 commit into
release-1.0.5from
dependabot/go_modules/google.golang.org/grpc-1.57.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Dec 16, 2023

Bumps google.golang.org/grpc from 1.57.0 to 1.57.1.

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.57.1

Security

  • server: prohibit more than MaxConcurrentStreams handlers from running at once (CVE-2023-44487)

    In addition to this change, applications should ensure they do not leave running tasks behind related to the RPC before returning from method handlers, or should enforce appropriate limits on any such work.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.57.0 to 1.57.1.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.57.0...v1.57.1)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the DEPENDENCY Pull requests that update a dependency file label Dec 16, 2023
@karthik1729 karthik1729 merged commit 217b15d into release-1.0.5 Dec 16, 2023
@dependabot dependabot Bot deleted the dependabot/go_modules/google.golang.org/grpc-1.57.1 branch December 16, 2023 11:02
karthik1729 pushed a commit that referenced this pull request Dec 16, 2023
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.57.0 to 1.57.1.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.57.0...v1.57.1)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
karthik1729 added a commit that referenced this pull request Dec 16, 2023
* removing pinned k8s deps

* upgrading to go version 1.21.1

* fixes mutating webhook validation type

* fix(resources-watcher): controllers updated for controller-runtime
0.16.0

* Refactoring: updating to new controller runtime. - Work in progress

* Rfactoring mongo operator

* fix(resource-watcher): platform resource watcher uses grpc connect now

- removes kafka message sender

* fix(mongo/database): fixes standalone database

- updates to standalone CRD, to have output credentials and helm secret
  name in spec

* feat(platform-operator): includes remaining operators

* fix(msvc-influx): refactorings for controllers

* Feature/ci updates (#58)

* Cleanup: deleted depricated cluster-setup operator

* CI: added workflows to build binaries and push images to container registry

* CI: changed CI matrix strategy

* Refactor: fixed compilation issues and removed depricated operators

* CI: added UPX compression before container building

* CI: added upx compression before container build

* CI: added platform and agent operators to the build flow

---------

Co-authored-by: Karthik Thirumalasetti <karthik@kloudlite.io>

* chore(deps): bump github.com/docker/docker (#57)

Bumps [github.com/docker/docker](https://github.com/docker/docker) from 20.10.21+incompatible to 24.0.7+incompatible.
- [Release notes](https://github.com/docker/docker/releases)
- [Commits](moby/moby@v20.10.21...v24.0.7)

---
updated-dependencies:
- dependency-name: github.com/docker/docker
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump google.golang.org/grpc from 1.57.0 to 1.57.1 (#56)

Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.57.0 to 1.57.1.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.57.0...v1.57.1)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump golang.org/x/net from 0.15.0 to 0.17.0 (#55)

Bumps [golang.org/x/net](https://github.com/golang/net) from 0.15.0 to 0.17.0.
- [Commits](golang/net@v0.15.0...v0.17.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github.com/cyphar/filepath-securejoin (#53)

Bumps [github.com/cyphar/filepath-securejoin](https://github.com/cyphar/filepath-securejoin) from 0.2.3 to 0.2.4.
- [Release notes](https://github.com/cyphar/filepath-securejoin/releases)
- [Commits](cyphar/filepath-securejoin@v0.2.3...v0.2.4)

---
updated-dependencies:
- dependency-name: github.com/cyphar/filepath-securejoin
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bug/build path fix (#60)

* Cleanup: deleted depricated cluster-setup operator

* CI: added workflows to build binaries and push images to container registry

---------

Signed-off-by: Karthik Thirumalasetti <karthik@kloudlite.io>

* CI: added workflows to build binaries and push images to container registry (#61)

* Bug/build path fix (#62)

* CI: added workflows to build binaries and push images to container registry

* Path fix

* chore(deps): bump github.com/docker/distribution (#54)

Bumps [github.com/docker/distribution](https://github.com/docker/distribution) from 2.8.1+incompatible to 2.8.2+incompatible.
- [Release notes](https://github.com/docker/distribution/releases)
- [Commits](distribution/distribution@v2.8.1...v2.8.2)

---
updated-dependencies:
- dependency-name: github.com/docker/distribution
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Added Security policy

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Karthik Thirumalasetti <karthik@kloudlite.io>
Co-authored-by: nxtcoder17 <nxtcoder17@gmail.com>
Co-authored-by: Piyush Kumar <piyush@Piyushs-MacBook-Air.local>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
abdheshnayak pushed a commit that referenced this pull request Nov 5, 2024
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.57.0 to 1.57.1.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.57.0...v1.57.1)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
abdheshnayak pushed a commit that referenced this pull request Nov 5, 2024
* removing pinned k8s deps

* upgrading to go version 1.21.1

* fixes mutating webhook validation type

* fix(resources-watcher): controllers updated for controller-runtime
0.16.0

* Refactoring: updating to new controller runtime. - Work in progress

* Rfactoring mongo operator

* fix(resource-watcher): platform resource watcher uses grpc connect now

- removes kafka message sender

* fix(mongo/database): fixes standalone database

- updates to standalone CRD, to have output credentials and helm secret
  name in spec

* feat(platform-operator): includes remaining operators

* fix(msvc-influx): refactorings for controllers

* Feature/ci updates (#58)

* Cleanup: deleted depricated cluster-setup operator

* CI: added workflows to build binaries and push images to container registry

* CI: changed CI matrix strategy

* Refactor: fixed compilation issues and removed depricated operators

* CI: added UPX compression before container building

* CI: added upx compression before container build

* CI: added platform and agent operators to the build flow

---------

Co-authored-by: Karthik Thirumalasetti <karthik@kloudlite.io>

* chore(deps): bump github.com/docker/docker (#57)

Bumps [github.com/docker/docker](https://github.com/docker/docker) from 20.10.21+incompatible to 24.0.7+incompatible.
- [Release notes](https://github.com/docker/docker/releases)
- [Commits](moby/moby@v20.10.21...v24.0.7)

---
updated-dependencies:
- dependency-name: github.com/docker/docker
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump google.golang.org/grpc from 1.57.0 to 1.57.1 (#56)

Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.57.0 to 1.57.1.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.57.0...v1.57.1)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump golang.org/x/net from 0.15.0 to 0.17.0 (#55)

Bumps [golang.org/x/net](https://github.com/golang/net) from 0.15.0 to 0.17.0.
- [Commits](golang/net@v0.15.0...v0.17.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github.com/cyphar/filepath-securejoin (#53)

Bumps [github.com/cyphar/filepath-securejoin](https://github.com/cyphar/filepath-securejoin) from 0.2.3 to 0.2.4.
- [Release notes](https://github.com/cyphar/filepath-securejoin/releases)
- [Commits](cyphar/filepath-securejoin@v0.2.3...v0.2.4)

---
updated-dependencies:
- dependency-name: github.com/cyphar/filepath-securejoin
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bug/build path fix (#60)

* Cleanup: deleted depricated cluster-setup operator

* CI: added workflows to build binaries and push images to container registry

---------

Signed-off-by: Karthik Thirumalasetti <karthik@kloudlite.io>

* CI: added workflows to build binaries and push images to container registry (#61)

* Bug/build path fix (#62)

* CI: added workflows to build binaries and push images to container registry

* Path fix

* chore(deps): bump github.com/docker/distribution (#54)

Bumps [github.com/docker/distribution](https://github.com/docker/distribution) from 2.8.1+incompatible to 2.8.2+incompatible.
- [Release notes](https://github.com/docker/distribution/releases)
- [Commits](distribution/distribution@v2.8.1...v2.8.2)

---
updated-dependencies:
- dependency-name: github.com/docker/distribution
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Added Security policy

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Karthik Thirumalasetti <karthik@kloudlite.io>
Co-authored-by: nxtcoder17 <nxtcoder17@gmail.com>
Co-authored-by: Piyush Kumar <piyush@Piyushs-MacBook-Air.local>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
nxtcoder17 added a commit that referenced this pull request Jan 2, 2025
- [Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto #56 ](https://github.com/kloudlite/operator/security/dependabot/56)
- [ Non-linear parsing of case-insensitive content in golang.org/x/net/html #57](https://github.com/kloudlite/operator/security/dependabot/57)
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

DEPENDENCY Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant