fix(deps): vuln minor upgrades — 15 packages (minor: 3 · patch: 12) [sticker-award]#257
Conversation
Release Notesgo.opentelemetry.io/otel/sdk (v1.38.0 → v1.43.0) — GitHub Releasev1.43.0Added
Changed
(truncated) v1.42.0Added
Changed
Fixed
(truncated — see source for full notes) github.com/gin-gonic/gin (v1.11.0 → v1.12.0) — GitHub Releasev1.12.0ChangelogFeatures
Bug fixes
(truncated) github.com/golang-jwt/jwt/v5 (v5.2.3 → v5.3.1) — GitHub Releasev5.3.1What's Changed🔐 Features
👒 Dependencies
(truncated) v5.3.0This release is almost identical to to What's Changed
Full Changelog: golang-jwt/jwt@v5.2.3...v5.3.0 github.com/DataDog/dd-trace-go/contrib/IBM/sarama/v2 (v2.6.0 → v2.6.1) — GitHub ReleaseWhat's ChangedApplication Performance Monitoring (APM)
Full Changelog: DataDog/dd-trace-go@v2.6.0...v2.6.1 github.com/DataDog/dd-trace-go/contrib/gin-gonic/gin/v2 (v2.6.0 → v2.6.1) — GitHub ReleaseWhat's ChangedApplication Performance Monitoring (APM)
Full Changelog: DataDog/dd-trace-go@v2.6.0...v2.6.1 github.com/DataDog/dd-trace-go/contrib/gorm.io/gorm.v1/v2 (v2.6.0 → v2.6.1) — GitHub ReleaseWhat's ChangedApplication Performance Monitoring (APM)
Full Changelog: DataDog/dd-trace-go@v2.6.0...v2.6.1 github.com/DataDog/dd-trace-go/contrib/net/http/v2 (v2.6.0 → v2.6.1) — GitHub ReleaseWhat's ChangedApplication Performance Monitoring (APM)
Full Changelog: DataDog/dd-trace-go@v2.6.0...v2.6.1 github.com/DataDog/dd-trace-go/contrib/sirupsen/logrus/v2 (v2.6.0 → v2.6.1) — GitHub ReleaseWhat's ChangedApplication Performance Monitoring (APM)
Full Changelog: DataDog/dd-trace-go@v2.6.0...v2.6.1 github.com/DataDog/dd-trace-go/v2 (v2.6.0 → v2.6.1) — GitHub ReleaseWhat's ChangedApplication Performance Monitoring (APM)
Full Changelog: DataDog/dd-trace-go@v2.6.0...v2.6.1 github.com/aws/aws-sdk-go-v2 (v1.41.2 → v1.41.6) — Changeloghttps://github.com/aws/aws-sdk-go-v2/blob/main/CHANGELOG.md github.com/aws/aws-sdk-go-v2/config (v1.32.10 → v1.32.16) — Changeloghttps://github.com/aws/aws-sdk-go-v2/blob/main/CHANGELOG.md github.com/aws/aws-sdk-go-v2/service/eventbridge (v1.45.19 → v1.45.24) — Changeloghttps://github.com/aws/aws-sdk-go-v2/blob/main/CHANGELOG.md github.com/aws/aws-sdk-go-v2/service/sqs (v1.42.22 → v1.42.26) — Changeloghttps://github.com/aws/aws-sdk-go-v2/blob/main/CHANGELOG.md github.com/go-playground/validator/v10 (v10.30.1 → v10.30.2) — GitHub ReleaseWhat's Changed
New Contributors
Full Changelog: go-playground/validator@v10.30.1...v10.30.2 github.com/sirupsen/logrus (v1.9.3 → v1.9.4) — GitHub ReleaseNotable changes
Full Changelog: sirupsen/logrus@v1.9.3...v1.9.4 Generated by ADMS Sources: 11 GitHub Releases, 4 Changelogs. |
|
Hey, sorry for the noise. This was caused by a bug in our automated dependency update system that incorrectly included upstream changelog content in PR comments, triggering notifications to external contributors. The feature flag has been turned off and we're working on a fix. Sorry about that again. |
Summary: High-severity security update — 15 packages upgraded (MINOR changes included)
Manifests changed:
sticker-award(go)✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.
Updates
Packages marked with "-" are updated due to dependency constraints.
Security Details
🚨 Critical & High Severity (4 fixed)
Review Checklist
Standard review:
Update Mode: Vulnerability Remediation (High)
🤖 Generated by DataDog Automated Dependency Management System