chore(deps): fix dependabot security alerts#2773
Draft
Baoyuantop wants to merge 1 commit into
Draft
Conversation
8739232 to
ab28f42
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR updates Go module dependencies to resolve the current open Dependabot security alerts for:
google.golang.org/grpcgo.opentelemetry.io/otelandgo.opentelemetry.io/otel/sdkgithub.com/jackc/pgx/v5github.com/moby/spdystreamfilippo.io/edwards25519It also raises the project Go version, toolchain, and GitHub Actions setup-go version from Go 1.24 to Go 1.25 because
github.com/jackc/pgx/v5@v5.9.2requires Go 1.25 or newer.Validation
go mod tidygo list -m google.golang.org/grpc go.opentelemetry.io/otel go.opentelemetry.io/otel/sdk github.com/jackc/pgx/v5 github.com/moby/spdystream filippo.io/edwards25519 github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream github.com/aws/aws-sdk-go-v2/service/s3 github.com/aws/aws-sdk-go-v2/service/lambda github.com/aws/aws-sdk-go-v2/service/cloudwatchlogsgo vet ./api/... ./cmd/... ./internal/... ./pkg/...go test ./api/... ./cmd/... ./internal/... ./pkg/...make buildmake testwas also attempted locally, but the local run could not complete becausesetup-envtestfailed to fetchkubebuilder-tools-1.30.0-darwin-arm64.tar.gzfrom GCS with401 Unauthorized; the Go 1.25 downloaded toolchain in this environment also failed the-coverprofilepath withgo: no such tool "covdata". The non-coverage test suite and build target completed successfully.