fix(deps): vuln unstable upgrades — 5 packages (unstable: 1 · minor: 4) #46
Conversation
Release Notesgoogle.golang.org/protobuf (v1.28.1 → v1.36.11) — GitHub Releasev1.36.11Full Changelog: protocolbuffers/protobuf-go@v1.36.10...v1.36.11 User-visible changes: Bug fixes: Maintenance: v1.36.10Full Changelog: protocolbuffers/protobuf-go@v1.36.9...v1.36.10 Bug fixes: Maintenance: v1.36.9Full Changelog: protocolbuffers/protobuf-go@v1.36.8...v1.36.9 User-visible changes: v1.36.8Maintenance: CL/696316: all: set Go language version to Go 1.23 v1.36.7Maintenance / optimizations: CL/683955: encoding/protowire: micro-optimize SizeVarint (-20% on Intel) v1.36.6Full Changelog: protocolbuffers/protobuf-go@v1.36.5...v1.36.6 User-visible changes: Maintenance: v1.36.5Full Changelog: protocolbuffers/protobuf-go@v1.36.4...v1.36.5 Bug fixes: Maintenance: v1.36.4Full Changelog: protocolbuffers/protobuf-go@v1.36.3...v1.36.4 Bug fixes: Maintenance: v1.36.3Full Changelog: protocolbuffers/protobuf-go@v1.36.2...v1.36.3 Bug fixes: User-visible changes: Maintenance: (and 14 more releases — view all) k8s.io/apimachinery (v0.26.2 → v0.35.4) — Commit comparison
... and 85 more commits k8s.io/klog/v2 (v2.80.1 → v2.140.0) — GitHub Releasev2.140.0What's Changed
New Contributors
Full Changelog: kubernetes/klog@v2.130.1...v2.140.0 v2.130.1What's Changed
Full Changelog: kubernetes/klog@v2.130.0...v2.130.1 v2.130.0What's Changed
New Contributors
Full Changelog: kubernetes/klog@v2.120.1...v2.130.0 v2.120.1What's Changed
Full Changelog: kubernetes/klog@v2.120.0...v2.120.1 v2.120.0What's Changed
New Contributors
Full Changelog: kubernetes/klog@v2.110.1...v2.120.0 v2.110.1What's Changed
New Contributors
Full Changelog: kubernetes/klog@v2.100.1...v2.110.1 v2.100.1What's Changed
New Contributors
Full Changelog: kubernetes/klog@v2.90.1...v2.100.1 v2.90.1What's Changed
Full Changelog: kubernetes/klog@v2.90.0...v2.90.1 v2.90.0What's Changed
Full Changelog: kubernetes/klog@v2.80.1...v2.90.0 There are some API differences from previous versionGenerated by ADMS Sources: 2 GitHub Releases, 1 Commit comparison, 2 not available. |
|
#46 (comment) pings all upstream contributors. Please stop that by quoting the PR authors or disabling this bot! |
|
@pohly this was a bug in the changelog. We have turned it off now |
|
Hey, sorry for the noise. This was caused by a bug in our automated dependency update system that incorrectly included upstream changelog content in PR comments, triggering notifications to external contributors. The feature flag has been turned off and we're working on a fix. Sorry about that again. |
Summary: Security update — 5 packages upgraded (UNSTABLE changes included)
Manifests changed:
.(go)✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.
Updates
Packages marked with "-" are updated due to dependency constraints.
Security Details
ℹ️ Other Vulnerabilities (2)
v1.2.3v1.4.3go.modv1.28.1v1.36.11go.modv0.26.2v0.35.4go.modv2.80.1v2.140.0go.modv1.3.0v1.6.0go.modReview Checklist
Standard review:
Update Mode: Vulnerability Remediation
🤖 Generated by DataDog Automated Dependency Management System