-
Notifications
You must be signed in to change notification settings - Fork 28
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump the minor-patch group across 2 directories with 2 updates #410
Conversation
@kommendorkapten Due to decisions made in #384, we intend to continue supporting go 1.22 until sigstore-go 1.0. We need to decline the upgrade to go-containerregistry until google/go-containerregistry#2047 is merged. |
@codysoyland Oh, nice. I missed that. |
We also discussed going back to that contributor and discussing this. Trying to fight dependabot up to and past 1.0 is not a great use of maintainer time unfortunately. |
@dependabot ignore github.com/google/go-containerregistry 0.20.3 |
I think the chat command I just sent should prevent dependabot from reopening this specific update for go-containerregistry again. Hopefully this will save us some time. |
@dependabot recreate |
Bumps the minor-patch group with 2 updates in the / directory: [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) and [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry). Bumps the minor-patch group with 2 updates in the /examples/oci-image-verification directory: [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) and [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry). Updates `github.com/sigstore/sigstore` from 1.8.12 to 1.8.14 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.8.12...v1.8.14) Updates `github.com/google/go-containerregistry` from 0.20.2 to 0.20.3 - [Release notes](https://github.com/google/go-containerregistry/releases) - [Changelog](https://github.com/google/go-containerregistry/blob/main/.goreleaser.yml) - [Commits](google/go-containerregistry@v0.20.2...v0.20.3) Updates `github.com/sigstore/sigstore` from 1.8.12 to 1.8.14 - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.8.12...v1.8.14) Updates `github.com/google/go-containerregistry` from 0.20.2 to 0.20.3 - [Release notes](https://github.com/google/go-containerregistry/releases) - [Changelog](https://github.com/google/go-containerregistry/blob/main/.goreleaser.yml) - [Commits](google/go-containerregistry@v0.20.2...v0.20.3) --- updated-dependencies: - dependency-name: github.com/sigstore/sigstore dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/google/go-containerregistry dependency-type: indirect update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/sigstore/sigstore dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github.com/google/go-containerregistry dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch ... Signed-off-by: dependabot[bot] <[email protected]>
c71c3de
to
e122e46
Compare
Signed-off-by: Cody Soyland <[email protected]>
@dependabot ignore github.com/google/go-containerregistry patch version |
OK, I won't notify you about version 0.20.3 of github.com/google/go-containerregistry again, unless you unignore it. |
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Pull request was closed
Bumps the minor-patch group with 2 updates in the / directory: github.com/sigstore/sigstore and github.com/google/go-containerregistry.
Bumps the minor-patch group with 2 updates in the /examples/oci-image-verification directory: github.com/sigstore/sigstore and github.com/google/go-containerregistry.
Updates
github.com/sigstore/sigstore
from 1.8.12 to 1.8.14Release notes
Sourced from github.com/sigstore/sigstore's releases.
Commits
351b102
export variable (#1978)0a1ec6f
build(deps): Bump golang.org/x/oauth2 in /pkg/signature/kms/gcp (#1973)a806b7e
build(deps): Bump github.com/hashicorp/vault/api (#1974)a235f11
build(deps): Bump localstack/localstack in /test/e2e in the all group (#1965)a883eaf
cliplugin: convert module to package only (#1956)4f6e90c
zizmor fixes (#1960)cb6fcc5
run lint across all submodules (#1959)750295f
cliplugin: lint fixes (#1958)67bd820
cliplugin: semver, add tests for hash func encoding (#1948)c5b7d21
cliplugin: use caller contexts (#1947)Updates
github.com/google/go-containerregistry
from 0.20.2 to 0.20.3Release notes
Sourced from github.com/google/go-containerregistry's releases.
Commits
c4dd792
bump deps using hack/bump-deps.sh (#2042)6bce25e
Detect zstd in crane append (#2023)06dcd85
mutate: Create a defensive annotations copy (#2030)a9a53a8
check for 406 status code when handling referrers endpoint response (#2026)4630c40
don't pin chainguard-dev/actions (#2025)808e354
bump actions to latest (#2011)a07d1ca
fix: redact.URL uses (*URL).Redacted to omit basic-auth password (#1947)00f182b
Expose compare package (#2001)b8e87ed
remote/transport: Make bearer transport go-routine-safe (#1806)Updates
github.com/sigstore/sigstore
from 1.8.12 to 1.8.14Release notes
Sourced from github.com/sigstore/sigstore's releases.
Commits
351b102
export variable (#1978)0a1ec6f
build(deps): Bump golang.org/x/oauth2 in /pkg/signature/kms/gcp (#1973)a806b7e
build(deps): Bump github.com/hashicorp/vault/api (#1974)a235f11
build(deps): Bump localstack/localstack in /test/e2e in the all group (#1965)a883eaf
cliplugin: convert module to package only (#1956)4f6e90c
zizmor fixes (#1960)cb6fcc5
run lint across all submodules (#1959)750295f
cliplugin: lint fixes (#1958)67bd820
cliplugin: semver, add tests for hash func encoding (#1948)c5b7d21
cliplugin: use caller contexts (#1947)Updates
github.com/google/go-containerregistry
from 0.20.2 to 0.20.3Release notes
Sourced from github.com/google/go-containerregistry's releases.
Commits
c4dd792
bump deps using hack/bump-deps.sh (#2042)6bce25e
Detect zstd in crane append (#2023)06dcd85
mutate: Create a defensive annotations copy (#2030)a9a53a8
check for 406 status code when handling referrers endpoint response (#2026)4630c40
don't pin chainguard-dev/actions (#2025)808e354
bump actions to latest (#2011)a07d1ca
fix: redact.URL uses (*URL).Redacted to omit basic-auth password (#1947)00f182b
Expose compare package (#2001)b8e87ed
remote/transport: Make bearer transport go-routine-safe (#1806)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions