Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: Update dependencies #219

Merged
merged 2 commits into from
Jun 11, 2024
Merged

chore: Update dependencies #219

merged 2 commits into from
Jun 11, 2024

Conversation

abhisek
Copy link
Member

@abhisek abhisek commented Jun 11, 2024

No description provided.

Signed-off-by: abhisek <abhisek.datta@gmail.com>
Copy link

cloudflare-workers-and-pages bot commented Jun 11, 2024

Deploying safedep-vet with  Cloudflare Pages  Cloudflare Pages

Latest commit: c4d4cb3
Status: ✅  Deploy successful!
Preview URL: https://abc60e72.safedep-vet.pages.dev
Branch Preview URL: https://chore-update-deps-06-2024.safedep-vet.pages.dev

View logs

Copy link

github-actions bot commented Jun 11, 2024

vet Summary Report

This report is generated by vet

Policy Checks

  • ✅ Vulnerability
  • ✅ Malware
  • ❌ License
  • ❌ Popularity
  • ❌ Maintenance
  • ❌ Security Posture
  • ✅ Threats

New Packages

  • ✅ [Go] golang.org/x/term@0.21.0
  • ✅ [Go] github.com/go-playground/validator/v10@10.21.0
  • ✅ [Go] github.com/klauspost/compress@1.17.8
  • ✅ [Go] stdlib@1.22
  • ✅ [Go] golang.org/x/sys@0.21.0
  • ⚠️ [Go] google.golang.org/genproto/googleapis/rpc@0.0.0-20240610135401-a8a62080eff3
  • ✅ [Go] github.com/google/osv-scanner@1.7.4
  • ✅ [Go] github.com/kataras/golog@0.1.12
  • ✅ [Go] github.com/package-url/packageurl-go@0.1.3
  • ⚠️ [Go] github.com/klauspost/cpuid/v2@2.2.8
  • ✅ [Go] golang.org/x/arch@0.8.0
  • ✅ [Go] golang.org/x/crypto@0.24.0
  • ✅ [Go] github.com/gomarkdown/markdown@0.0.0-20240419095408-642f0ee99ae2
  • ✅ [Go] github.com/gin-gonic/gin@1.10.0
  • ⚠️ [Go] github.com/safedep/dry@0.0.0-20240405050202-3b26d9386e57
  • ✅ [Go] github.com/smacker/go-tree-sitter@0.0.0-20240514083259-c5d1f3f5f99e
  • ✅ [Go] golang.org/x/oauth2@0.21.0
  • ✅ [Go] golang.org/x/net@0.26.0
  • ✅ [Go] github.com/bytedance/sonic/loader@0.1.1
  • ✅ [Go] github.com/CycloneDX/cyclonedx-go@0.9.0
  • ✅ [Go] github.com/deepmap/oapi-codegen@1.16.3
  • ✅ [Go] github.com/antlr4-go/antlr/v4@4.13.1
  • ✅ [Go] golang.org/x/mod@0.18.0
  • ✅ [Go] github.com/BurntSushi/toml@1.4.0
  • ✅ [Go] github.com/gabriel-vasile/mimetype@1.4.4
  • ✅ [Go] github.com/tdewolff/minify/v2@2.20.33
  • ⚠️ [Go] github.com/cloudwego/base64x@0.1.4
  • ⚠️ [Go] google.golang.org/genproto/googleapis/api@0.0.0-20240610135401-a8a62080eff3
  • ✅ [Go] github.com/goccy/go-json@0.10.3
  • ✅ [Go] github.com/jedib0t/go-pretty/v6@6.5.9
  • ✅ [Go] github.com/cloudflare/circl@1.3.8
  • ✅ [Go] github.com/labstack/echo/v4@4.12.0
  • ✅ [Go] k8s.io/utils@0.0.0-20240502163921-fe8a2dddb1d0
  • ✅ [Go] google.golang.org/protobuf@1.34.1
  • ⚠️ [Go] github.com/spdx/tools-golang@0.5.4
  • ✅ [Go] github.com/tdewolff/parse/v2@2.7.14
  • ✅ [Go] golang.org/x/exp@0.0.0-20240604190554-fc45aab8b7f8
  • ✅ [Go] github.com/bytedance/sonic@1.11.8
  • ✅ [Go] github.com/pelletier/go-toml/v2@2.2.2
  • ⚠️ [Go] github.com/cloudwego/iasm@0.2.0
  • ✅ [Go] golang.org/x/text@0.16.0
  • ✅ [Go] github.com/kataras/iris/v12@12.2.11

Packages Violating Policy

[Go] google.golang.org/genproto/googleapis/rpc@0.0.0-20240610135401-a8a62080eff3 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component release pipeline appear to use dangerous workflows

[Go] github.com/klauspost/cpuid/v2@2.2.8 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/safedep/dry@0.0.0-20240405050202-3b26d9386e57 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] github.com/cloudwego/base64x@0.1.4 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] google.golang.org/genproto/googleapis/api@0.0.0-20240610135401-a8a62080eff3 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component release pipeline appear to use dangerous workflows

[Go] github.com/spdx/tools-golang@0.5.4 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Risky OSS license was detected

[Go] github.com/cloudwego/iasm@0.2.0 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

Signed-off-by: abhisek <abhisek.datta@gmail.com>
@abhisek abhisek merged commit c2175fe into main Jun 11, 2024
9 of 10 checks passed
@abhisek abhisek deleted the chore/update-deps-06-2024 branch June 11, 2024 09:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant