-
Notifications
You must be signed in to change notification settings - Fork 89
Bump the go group with 13 updates #1439
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Bumps the go group with 13 updates: | Package | From | To | | --- | --- | --- | | [github.com/c-bata/go-prompt](https://github.com/c-bata/go-prompt) | `0.2.5` | `0.2.6` | | [github.com/apache/camel-k/v2](https://github.com/apache/camel-k) | `2.5.0` | `2.7.0` | | [github.com/forPelevin/gomoji](https://github.com/forPelevin/gomoji) | `1.3.0` | `1.3.1` | | [github.com/gookit/color](https://github.com/gookit/color) | `1.5.4` | `1.6.0` | | [github.com/jedib0t/go-pretty/v6](https://github.com/jedib0t/go-pretty) | `6.6.5` | `6.6.8` | | [github.com/magiconair/properties](https://github.com/magiconair/properties) | `1.8.9` | `1.8.10` | | [github.com/spf13/viper](https://github.com/spf13/viper) | `1.19.0` | `1.20.1` | | [github.com/stretchr/testify](https://github.com/stretchr/testify) | `1.10.0` | `1.11.1` | | [github.com/urfave/cli](https://github.com/urfave/cli) | `1.22.16` | `1.22.17` | | [github.com/vbauerster/mpb/v8](https://github.com/vbauerster/mpb) | `8.9.1` | `8.10.2` | | [golang.org/x/sync](https://github.com/golang/sync) | `0.12.0` | `0.15.0` | | [golang.org/x/term](https://github.com/golang/term) | `0.30.0` | `0.32.0` | | [golang.org/x/text](https://github.com/golang/text) | `0.23.0` | `0.26.0` | Updates `github.com/c-bata/go-prompt` from 0.2.5 to 0.2.6 - [Changelog](https://github.com/c-bata/go-prompt/blob/master/CHANGELOG.md) - [Commits](c-bata/go-prompt@v0.2.5...v0.2.6) Updates `github.com/apache/camel-k/v2` from 2.5.0 to 2.7.0 - [Release notes](https://github.com/apache/camel-k/releases) - [Changelog](https://github.com/apache/camel-k/blob/main/release.adoc) - [Commits](apache/camel-k@v2.5.0...v2.7.0) Updates `github.com/forPelevin/gomoji` from 1.3.0 to 1.3.1 - [Release notes](https://github.com/forPelevin/gomoji/releases) - [Commits](forPelevin/gomoji@v1.3.0...v1.3.1) Updates `github.com/gookit/color` from 1.5.4 to 1.6.0 - [Release notes](https://github.com/gookit/color/releases) - [Commits](gookit/color@v1.5.4...v1.6.0) Updates `github.com/jedib0t/go-pretty/v6` from 6.6.5 to 6.6.8 - [Release notes](https://github.com/jedib0t/go-pretty/releases) - [Commits](jedib0t/go-pretty@v6.6.5...v6.6.8) Updates `github.com/magiconair/properties` from 1.8.9 to 1.8.10 - [Release notes](https://github.com/magiconair/properties/releases) - [Commits](magiconair/properties@v1.8.9...v1.8.10) Updates `github.com/spf13/viper` from 1.19.0 to 1.20.1 - [Release notes](https://github.com/spf13/viper/releases) - [Commits](spf13/viper@v1.19.0...v1.20.1) Updates `github.com/stretchr/testify` from 1.10.0 to 1.11.1 - [Release notes](https://github.com/stretchr/testify/releases) - [Commits](stretchr/testify@v1.10.0...v1.11.1) Updates `github.com/urfave/cli` from 1.22.16 to 1.22.17 - [Release notes](https://github.com/urfave/cli/releases) - [Changelog](https://github.com/urfave/cli/blob/main/docs/CHANGELOG.md) - [Commits](urfave/cli@v1.22.16...v1.22.17) Updates `github.com/vbauerster/mpb/v8` from 8.9.1 to 8.10.2 - [Release notes](https://github.com/vbauerster/mpb/releases) - [Commits](vbauerster/mpb@v8.9.1...v8.10.2) Updates `golang.org/x/sync` from 0.12.0 to 0.15.0 - [Commits](golang/sync@v0.12.0...v0.15.0) Updates `golang.org/x/term` from 0.30.0 to 0.32.0 - [Commits](golang/term@v0.30.0...v0.32.0) Updates `golang.org/x/text` from 0.23.0 to 0.26.0 - [Release notes](https://github.com/golang/text/releases) - [Commits](golang/text@v0.23.0...v0.26.0) --- updated-dependencies: - dependency-name: github.com/c-bata/go-prompt dependency-version: 0.2.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go - dependency-name: github.com/apache/camel-k/v2 dependency-version: 2.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go - dependency-name: github.com/forPelevin/gomoji dependency-version: 1.3.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go - dependency-name: github.com/gookit/color dependency-version: 1.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go - dependency-name: github.com/jedib0t/go-pretty/v6 dependency-version: 6.6.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go - dependency-name: github.com/magiconair/properties dependency-version: 1.8.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go - dependency-name: github.com/spf13/viper dependency-version: 1.20.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go - dependency-name: github.com/stretchr/testify dependency-version: 1.11.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go - dependency-name: github.com/urfave/cli dependency-version: 1.22.17 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go - dependency-name: github.com/vbauerster/mpb/v8 dependency-version: 8.10.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go - dependency-name: golang.org/x/sync dependency-version: 0.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go - dependency-name: golang.org/x/term dependency-version: 0.32.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go - dependency-name: golang.org/x/text dependency-version: 0.26.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go ... Signed-off-by: dependabot[bot] <[email protected]>
at 🎯 Static Application Security Testing (SAST) VulnerabilityFull descriptionVulnerability Details
OverviewUsing insecure protocols—such as HTTP, FTP, or LDAP—can expose sensitive Vulnerable exampleIn this example, the application uses insecure protocols to communicate, package main
import (
"fmt"
)
type SwampService struct {
InsecureHttpProtocol string
InsecureFtpProtocol string
}
func NewSwampService() *SwampService {
return &SwampService{
InsecureHttpProtocol: "http://", // Insecure protocol
InsecureFtpProtocol: "ftp://", // Insecure protocol
}
}
func (s *SwampService) ConnectToFrogService(server string) {
url := s.InsecureHttpProtocol + server + "/frogEndpoint"
s.connect(url)
url = s.InsecureFtpProtocol + server + "/frogFile"
s.connect(url)
}
func (s *SwampService) connect(url string) {
fmt.Printf("Connecting to %s\n", url)
// Logic to connect to the service
}
func main() {
service := NewSwampService()
service.ConnectToFrogService("example.com")
}In this vulnerable example, the RemediationTo mitigate the use of insecure protocols, replace them with secure alternatives package main
import (
"fmt"
)
type SwampService struct {
InsecureHttpProtocol string
InsecureFtpProtocol string
}
func NewSwampService() *SwampService {
return &SwampService{
InsecureHttpProtocol: "http://", // Insecure protocol
InsecureFtpProtocol: "ftp://", // Insecure protocol
}
}
func (s *SwampService) ConnectToFrogService(server string) {
url := s.InsecureHttpProtocol + server + "/frogEndpoint"
s.connect(url)
url = s.InsecureFtpProtocol + server + "/frogFile"
s.connect(url)
}
func (s *SwampService) connect(url string) {
fmt.Printf("Connecting to %s\n", url)
// Logic to connect to the service
}
func main() {
service := NewSwampService()
service.ConnectToFrogService("example.com")
}In this remediated example, the |
at 🎯 Static Application Security Testing (SAST) VulnerabilityFull descriptionVulnerability Details
OverviewUsing insecure protocols—such as HTTP, FTP, or LDAP—can expose sensitive Vulnerable exampleIn this example, the application uses insecure protocols to communicate, package main
import (
"fmt"
)
type SwampService struct {
InsecureHttpProtocol string
InsecureFtpProtocol string
}
func NewSwampService() *SwampService {
return &SwampService{
InsecureHttpProtocol: "http://", // Insecure protocol
InsecureFtpProtocol: "ftp://", // Insecure protocol
}
}
func (s *SwampService) ConnectToFrogService(server string) {
url := s.InsecureHttpProtocol + server + "/frogEndpoint"
s.connect(url)
url = s.InsecureFtpProtocol + server + "/frogFile"
s.connect(url)
}
func (s *SwampService) connect(url string) {
fmt.Printf("Connecting to %s\n", url)
// Logic to connect to the service
}
func main() {
service := NewSwampService()
service.ConnectToFrogService("example.com")
}In this vulnerable example, the RemediationTo mitigate the use of insecure protocols, replace them with secure alternatives package main
import (
"fmt"
)
type SwampService struct {
InsecureHttpProtocol string
InsecureFtpProtocol string
}
func NewSwampService() *SwampService {
return &SwampService{
InsecureHttpProtocol: "http://", // Insecure protocol
InsecureFtpProtocol: "ftp://", // Insecure protocol
}
}
func (s *SwampService) ConnectToFrogService(server string) {
url := s.InsecureHttpProtocol + server + "/frogEndpoint"
s.connect(url)
url = s.InsecureFtpProtocol + server + "/frogFile"
s.connect(url)
}
func (s *SwampService) connect(url string) {
fmt.Printf("Connecting to %s\n", url)
// Logic to connect to the service
}
func main() {
service := NewSwampService()
service.ConnectToFrogService("example.com")
}In this remediated example, the |
at 🎯 Static Application Security Testing (SAST) VulnerabilityFull descriptionVulnerability Details
OverviewUsing insecure protocols—such as HTTP, FTP, or LDAP—can expose sensitive Vulnerable exampleIn this example, the application uses insecure protocols to communicate, package main
import (
"fmt"
)
type SwampService struct {
InsecureHttpProtocol string
InsecureFtpProtocol string
}
func NewSwampService() *SwampService {
return &SwampService{
InsecureHttpProtocol: "http://", // Insecure protocol
InsecureFtpProtocol: "ftp://", // Insecure protocol
}
}
func (s *SwampService) ConnectToFrogService(server string) {
url := s.InsecureHttpProtocol + server + "/frogEndpoint"
s.connect(url)
url = s.InsecureFtpProtocol + server + "/frogFile"
s.connect(url)
}
func (s *SwampService) connect(url string) {
fmt.Printf("Connecting to %s\n", url)
// Logic to connect to the service
}
func main() {
service := NewSwampService()
service.ConnectToFrogService("example.com")
}In this vulnerable example, the RemediationTo mitigate the use of insecure protocols, replace them with secure alternatives package main
import (
"fmt"
)
type SwampService struct {
InsecureHttpProtocol string
InsecureFtpProtocol string
}
func NewSwampService() *SwampService {
return &SwampService{
InsecureHttpProtocol: "http://", // Insecure protocol
InsecureFtpProtocol: "ftp://", // Insecure protocol
}
}
func (s *SwampService) ConnectToFrogService(server string) {
url := s.InsecureHttpProtocol + server + "/frogEndpoint"
s.connect(url)
url = s.InsecureFtpProtocol + server + "/frogFile"
s.connect(url)
}
func (s *SwampService) connect(url string) {
fmt.Printf("Connecting to %s\n", url)
// Logic to connect to the service
}
func main() {
service := NewSwampService()
service.ConnectToFrogService("example.com")
}In this remediated example, the |
at 🎯 Static Application Security Testing (SAST) VulnerabilityFull descriptionVulnerability Details
OverviewUsing insecure protocols—such as HTTP, FTP, or LDAP—can expose sensitive Vulnerable exampleIn this example, the application uses insecure protocols to communicate, package main
import (
"fmt"
)
type SwampService struct {
InsecureHttpProtocol string
InsecureFtpProtocol string
}
func NewSwampService() *SwampService {
return &SwampService{
InsecureHttpProtocol: "http://", // Insecure protocol
InsecureFtpProtocol: "ftp://", // Insecure protocol
}
}
func (s *SwampService) ConnectToFrogService(server string) {
url := s.InsecureHttpProtocol + server + "/frogEndpoint"
s.connect(url)
url = s.InsecureFtpProtocol + server + "/frogFile"
s.connect(url)
}
func (s *SwampService) connect(url string) {
fmt.Printf("Connecting to %s\n", url)
// Logic to connect to the service
}
func main() {
service := NewSwampService()
service.ConnectToFrogService("example.com")
}In this vulnerable example, the RemediationTo mitigate the use of insecure protocols, replace them with secure alternatives package main
import (
"fmt"
)
type SwampService struct {
InsecureHttpProtocol string
InsecureFtpProtocol string
}
func NewSwampService() *SwampService {
return &SwampService{
InsecureHttpProtocol: "http://", // Insecure protocol
InsecureFtpProtocol: "ftp://", // Insecure protocol
}
}
func (s *SwampService) ConnectToFrogService(server string) {
url := s.InsecureHttpProtocol + server + "/frogEndpoint"
s.connect(url)
url = s.InsecureFtpProtocol + server + "/frogFile"
s.connect(url)
}
func (s *SwampService) connect(url string) {
fmt.Printf("Connecting to %s\n", url)
// Logic to connect to the service
}
func main() {
service := NewSwampService()
service.ConnectToFrogService("example.com")
}In this remediated example, the |



Bumps the go group with 13 updates:
0.2.50.2.62.5.02.7.01.3.01.3.11.5.41.6.06.6.56.6.81.8.91.8.101.19.01.20.11.10.01.11.11.22.161.22.178.9.18.10.20.12.00.15.00.30.00.32.00.23.00.26.0Updates
github.com/c-bata/go-promptfrom 0.2.5 to 0.2.6Commits
82a9122Merge pull request #224 from zaynetro/upgrade-term-pkg20e0658Update pkg/term to 1.2.08aae7fbMerge pull request #222 from c-bata/go-1-16d527d12Use go 1.168e6eb48Add Bit as a project using go-prompt.327dcaaAdd topicctl as a project using go-prompt.Updates
github.com/apache/camel-k/v2from 2.5.0 to 2.7.0Release notes
Sourced from github.com/apache/camel-k/v2's releases.
... (truncated)
Changelog
Sourced from github.com/apache/camel-k/v2's changelog.
... (truncated)
Commits
c61820dchore(release): preparing for tag v2.7.052595bechore(release): Helm chart for 2.7.0033c3a2chore: starting release branch for release-2.7.xc598645chore(runtime): default ck runtime 3.15.30b46667fix(ctrl): use caSecrets parameters for kamelet downloade5b8eeafeat(trait): use sensible timeout for Quarkus native builderb5ffc2fchore(deps): bump github.com/stoewer/go-strcase from 1.3.0 to 1.3.164dc4fcfix(trait): cron replace only related componentsf53e6a7fix(install): remove unneded rbacs43a6caefix(e2e): cron test time reductionUpdates
github.com/forPelevin/gomojifrom 1.3.0 to 1.3.1Release notes
Sourced from github.com/forPelevin/gomoji's releases.
Commits
e6aacc4Fix emoji removal with accented chars (#27)Updates
github.com/gookit/colorfrom 1.5.4 to 1.6.0Release notes
Sourced from github.com/gookit/color's releases.
... (truncated)
Commits
0b1dc4c✅ demo: update the examples deps and some codesfa47891⬆️ dep: upgrade gookit/assert to v0.1.1, update some testsd95f213✨ feat: add new convert func: HSVToRGB, RGBToHSV173325a👔 up: update detect env, use internal Level* instead of the terminfo....c5db0d0👔 up: remove deprecated var isLikeInCmd, update some testsf46f52e🔥 chore: remove any.go, merge printer.go to quickstart.gocc45966🎨 chore: update some go file code stylee532935Optimize RenderCode performance with fast paths for string arguments (#110)f14a7b8📝 chore: update some code style and some tests6de7584Fix race condition in Theme.Tips method when called concurrently (#109)Updates
github.com/jedib0t/go-pretty/v6from 6.6.5 to 6.6.8Release notes
Sourced from github.com/jedib0t/go-pretty/v6's releases.
Commits
3c86af8progress demo tweaks (#371)2ac3ff0progress: option to override tracker rendering logic (#369)c802c02Add pac-man classic chomp and colored dominoes indeterminate indicators (#370)18e8a01OSC 8 hiperlink support (#364)b14745ctable: support vertical merge in HTML rendering; fixes #348 (#361)5a8fa5ftext: support NO_COLOR/FORCE_COLOR env directives; fixes #352 (#360)be73dfaREADME.md: fix ci status badge (#355)51030bdupdate dependencies; other minor fixes (#354)2b859b4table: fix rebalancing of long merged columns; fixes #350 (#353)Updates
github.com/magiconair/propertiesfrom 1.8.9 to 1.8.10Release notes
Sourced from github.com/magiconair/properties's releases.
Commits
281f515Merge pull request #81 from magiconair/issue-806b7aa68test with go1.2406f3133escape leading whitespace on value in Write()3dfc3b5Merge pull request #77 from magiconair/get32bitb148584Add 32bit numeric getters which do not panicUpdates
github.com/spf13/viperfrom 1.19.0 to 1.20.1Release notes
Sourced from github.com/spf13/viper's releases.
... (truncated)
Commits
9568cfcfix: config type check when loading any configfd05140fix(config): get config type from v.configType or config file extc038295docs: add update instructions for 1.209c07e0fbuild: disable unused linters48112d6ci: add Go 1.24 to the test matrix66e3e28build(deps): bump github.com/spf13/pflag from 1.0.5 to 1.0.617b96acNew Logo8b223a4build(deps): bump github.com/spf13/cast from 1.7.0 to 1.7.191fd363chore: update aferoe75c48fFix issues reported by testifylintUpdates
github.com/stretchr/testifyfrom 1.10.0 to 1.11.1Release notes
Sourced from github.com/stretchr/testify's releases.
... (truncated)
Commits
2a57335Merge pull request #1788 from brackendawson/1785-backport-1.11af8c912Backport #1786 to release/1.11b7801fbMerge pull request #1778 from stretchr/dependabot/github_actions/actions/chec...69831f3build(deps): bump actions/checkout from 4 to 5a53be35Improve captureTestingT helperaafb604mock: improve formatting of error message7218e03improve error msg929a212Merge pull request #1758 from stretchr/dolmen/suite-faster-method-filteringbc7459esuite: faster filtering of methods (-testify.m)7d37b5csuite: refactor methodFilterUpdates
github.com/urfave/clifrom 1.22.16 to 1.22.17Release notes
Sourced from github.com/urfave/cli's releases.
Commits
992e53dMerge pull request #2158 from urfave/v1-deps-upb37456cUpdate dependencies in v1 series394fbd8Merge pull request #2156 from urfave/v1-not-dependabot2a5bdc7Dependabot does not work like this77bb234Merge pull request #2153 from urfave/v1-dependabot-maybe5d6ed14Is this file needed on each release branch?Updates
github.com/vbauerster/mpb/v8from 8.9.1 to 8.10.2Release notes
Sourced from github.com/vbauerster/mpb/v8's releases.
Commits
d30b560v8.10.27efde3cmake [][]io.Reader with capacity0675e6bprefer builtin min (needs Go 1.21)db1c068no need to capture loop var since Go 1.22