Skip to content

Commit 410969b

Browse files
committed
chore: Update dependencies
1 parent 67de24f commit 410969b

22 files changed

+79
-77
lines changed

.github/workflows/ci.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -127,7 +127,7 @@ jobs:
127127
id: buf-setup
128128
uses: bufbuild/buf-action@8f4a1456a0ab6a1eb80ba68e53832e6fcfacc16c # v1.3.0
129129
with:
130-
version: 1.59.0
130+
version: 1.62.1
131131
lint: true
132132
format: true
133133
breaking: ${{ !contains(env.commit_msg, '[skip buf-breaking]') }}

.github/workflows/codeql.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ jobs:
5252

5353
# Initializes the CodeQL tools for scanning.
5454
- name: Initialize CodeQL
55-
uses: github/codeql-action/init@1b168cd39490f61582a9beae412bb7057a6b2c4e # v4.31.8
55+
uses: github/codeql-action/init@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
5656
with:
5757
languages: ${{ matrix.language }}
5858
# If you wish to specify custom queries, you can do so here or in a config file.
@@ -62,7 +62,7 @@ jobs:
6262

6363
# Auto build attempts to build any compiled languages (C/C++, C#, or Java).
6464
- name: Auto build
65-
uses: github/codeql-action/autobuild@1b168cd39490f61582a9beae412bb7057a6b2c4e # v4.31.8
65+
uses: github/codeql-action/autobuild@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
6666

6767
# Run manual build only if auto-build fails
6868
- name: Manual build
@@ -75,4 +75,4 @@ jobs:
7575
# Can be excluded if the commit message contains: [skip codeql]
7676
- name: Perform CodeQL analysis
7777
if: ${{ !contains(env.commit_msg, '[skip codeql]') }}
78-
uses: github/codeql-action/analyze@1b168cd39490f61582a9beae412bb7057a6b2c4e # v4.31.8
78+
uses: github/codeql-action/analyze@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9

.github/workflows/dependency-review.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,4 +26,4 @@ jobs:
2626
# Scan dependencies
2727
# https://github.com/actions/dependency-review-action
2828
- name: Dependency review
29-
uses: actions/dependency-review-action@40c09b7dc99638e5ddb0bfd91c1673effc064d8a # v4.8.1
29+
uses: actions/dependency-review-action@3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261 # v4.8.2

.github/workflows/maintenance.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
egress-policy: audit
1919

2020
- name: Tag stale issues and PRs
21-
uses: actions/stale@5f858e3efba33a5ca4407a664cc011ad407f2008 # v10.1.0
21+
uses: actions/stale@997185467fa4f803885201cee163a9f38240193d # v10.1.1
2222
with:
2323
# On the 'debug' mode the action will not perform any operation.
2424
# Add the secret ACTIONS_STEP_DEBUG with a value of 'true' in the repository.

.github/workflows/ossf-scorecard.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -59,6 +59,6 @@ jobs:
5959

6060
# Upload the results to GitHub's code scanning dashboard.
6161
- name: Upload results to code-scanning
62-
uses: github/codeql-action/upload-sarif@1b168cd39490f61582a9beae412bb7057a6b2c4e # v4.31.8
62+
uses: github/codeql-action/upload-sarif@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
6363
with:
6464
sarif_file: results.sarif

.gitignore

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,9 @@
66
# Deps
77
vendor/**
88

9+
# Buf dependencies; updated with: `buf export --all -o .buf-deps`
10+
.buf-deps
11+
912
# NodeJS
1013
node_modules
1114
package-lock.json

.gitleaksignore

Lines changed: 13 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,13 @@
1-
4b14aa74b3347c928b8bd70114dfe362a6ba0353:net/drpc/testdata/server.sample_key:private-key:1
2-
4b14aa74b3347c928b8bd70114dfe362a6ba0353:net/drpc/testdata/ca.sample_key:private-key:1
3-
4b14aa74b3347c928b8bd70114dfe362a6ba0353:net/drpc/testdata/bad.sample_key:private-key:1
4-
0cda6a8918625e28ce256d15572c36588eaab413:did/key_type.go:generic-api-key:28
5-
97f3b9cf16c95dd95126df996450f3bbd5a226fb:net/rpc/testdata/server.sample_key:private-key:1
6-
97f3b9cf16c95dd95126df996450f3bbd5a226fb:net/rpc/testdata/ca.sample_key:private-key:1
7-
97f3b9cf16c95dd95126df996450f3bbd5a226fb:net/rpc/testdata/bad.sample_key:private-key:1
8-
4213b06c2ecb968182d8d13343be82ca9e5a365c:net/http/testdata/ca.sample_key:private-key:1
9-
4213b06c2ecb968182d8d13343be82ca9e5a365c:net/http/testdata/server.sample_key:private-key:1
10-
2096763359dba6025823f5676a0eb092f8caebee:net/loader/testdata/server.sample_key:private-key:1
11-
2096763359dba6025823f5676a0eb092f8caebee:net/loader/testdata/ca.sample_key:private-key:1
12-
73c3f9b6f09f1bf8361ef60719791364eec14b87:buf.yaml:generic-api-key:17
1+
buf.yaml:generic-api-key:5
2+
buf.yaml:generic-api-key:17
3+
net/loader/testdata/ca.sample_key:private-key:1
4+
net/loader/testdata/server.sample_key:private-key:1
5+
net/http/testdata/ca.sample_key:private-key:1
6+
net/http/testdata/server.sample_key:private-key:1
7+
net/rpc/testdata/bad.sample_key:private-key:1
8+
net/rpc/testdata/ca.sample_key:private-key:1
9+
net/rpc/testdata/server.sample_key:private-key:1
10+
did/key_type.go:generic-api-key:28
11+
net/drpc/testdata/bad.sample_key:private-key:1
12+
net/drpc/testdata/ca.sample_key:private-key:1
13+
net/drpc/testdata/server.sample_key:private-key:1

Makefile

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,6 @@ fuzz:
4545
lint:
4646
# Go code
4747
golangci-lint run -v ./$(pkg)
48-
semgrep --config "p/trailofbits"
4948

5049
## protos: Compile all protobuf definitions and RPC services
5150
protos:
@@ -63,9 +62,11 @@ scan-ci:
6362
# https://go.googlesource.com/vuln
6463
scan-deps:
6564
govulncheck -mode source -scan package ./...
65+
semgrep --config "p/trailofbits"
6666

6767
## scan-secrets: Scan project code for accidentally leaked secrets
6868
# https://gitleaks.io
69+
# gitleaks dir --no-banner -f json -r - | jq -r '.[].Fingerprint' > .gitleaksignore
6970
scan-secrets:
7071
gitleaks git -v
7172

buf.gen.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -20,16 +20,16 @@ plugins:
2020
out: .
2121
opt:
2222
- paths=source_relative
23-
- remote: buf.build/grpc/go:v1.5.1
23+
- remote: buf.build/grpc/go:v1.6.0
2424
out: .
2525
opt:
2626
- paths=source_relative
2727
- require_unimplemented_servers=true
28-
- remote: buf.build/grpc-ecosystem/openapiv2:v2.27.3
28+
- remote: buf.build/grpc-ecosystem/openapiv2:v2.27.4
2929
out: .
3030
opt:
3131
- logtostderr=true
32-
- remote: buf.build/grpc-ecosystem/gateway:v2.27.3
32+
- remote: buf.build/grpc-ecosystem/gateway:v2.27.4
3333
out: .
3434
opt:
3535
- paths=source_relative

buf.lock

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,5 +8,5 @@ deps:
88
commit: 61b203b9a9164be9a834f58c37be6f62
99
digest: b5:7811a98b35bd2e4ae5c3ac73c8b3d9ae429f3a790da15de188dc98fc2b77d6bb10e45711f14903af9553fa9821dff256054f2e4b7795789265bc476bec2f088c
1010
- name: buf.build/grpc-ecosystem/grpc-gateway
11-
commit: 4c5ba75caaf84e928b7137ae5c18c26a
12-
digest: b5:c113e62fb3b29289af785866cae062b55ec8ae19ab3f08f3004098928fbca657730a06810b2012951294326b95669547194fa84476b9e9b688d4f8bf77a0691d
11+
commit: 6467306b4f624747aaf6266762ee7a1c
12+
digest: b5:c2caa61467d992749812c909f93c07e9a667da33c758a7c1973d63136c23b3cafcc079985b12cdf54a10049ed3297418f1eda42cdffdcf34113792dcc3a990af

0 commit comments

Comments
 (0)