chore(deps): bump github.com/go-git/go-git/v5 from 5.16.5 to 5.17.1 in /services/apps/git_integration/src/crowdgit/services/vulnerability_scanner#3980
Conversation
Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.16.5 to 5.17.1. - [Release notes](https://github.com/go-git/go-git/releases) - [Commits](go-git/go-git@v5.16.5...v5.17.1) --- updated-dependencies: - dependency-name: github.com/go-git/go-git/v5 dependency-version: 5.17.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
Your PR title doesn't contain a Jira issue key. Consider adding it for better traceability. Example:
Projects:
Please add a Jira issue key to your PR title. |
1 similar comment
|
Your PR title doesn't contain a Jira issue key. Consider adding it for better traceability. Example:
Projects:
Please add a Jira issue key to your PR title. |
|
|
|
Your PR title doesn't contain a Jira issue key. Consider adding it for better traceability. Example:
Projects:
Please add a Jira issue key to your PR title. |
Bumps github.com/go-git/go-git/v5 from 5.16.5 to 5.17.1.
Release notes
Sourced from github.com/go-git/go-git/v5's releases.
Commits
5e23dfdMerge pull request #1937 from pjbgf/idx-v56b38a32Merge pull request #1935 from pjbgf/index-v5cd757fcplumbing: format/idxfile, Fix version and fanout checks3ec0d70plumbing: format/index, Fix tree extension invalidated entry parsingdbe10b6plumbing: format/index, Align V2/V3 long name and V4 prefix encoding with Gite9b65dfplumbing: format/index, Improve v4 entry name validationadad18dMerge pull request #1930 from go-git/renovate/releases/v5.x-go-github.com-clo...29470bdbuild: Update module github.com/cloudflare/circl to v1.6.3 [SECURITY]bdf0688Merge pull request #1864 from pjbgf/v5-issue-555290e52storage: filesystem, Avoid overwriting loose obj files. Fixes #55Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Low Risk
Low risk dependency-only change limited to
go.mod/go.sum, though thego-gitbump could subtly affect repository parsing and scanning behavior.Overview
Updates the
vulnerability_scannerGo module dependencies, bumpinggithub.com/go-git/go-git/v5tov5.17.1(andgo-billyaccordingly) and refreshing checksums ingo.sum.Also upgrades transitive crypto dependency
github.com/cloudflare/circltov1.6.3and promotesgithub.com/ossf/osv-schema/bindings/gofrom indirect to a direct requirement.Written by Cursor Bugbot for commit dd5ce3f. This will update automatically on new commits. Configure here.