Skip to content

dependabot: Updates#16896

Merged
htuch merged 4 commits intoenvoyproxy:mainfrom
phlax:dependabot-updates
Jun 11, 2021
Merged

dependabot: Updates#16896
htuch merged 4 commits intoenvoyproxy:mainfrom
phlax:dependabot-updates

Conversation

@phlax
Copy link
Member

@phlax phlax commented Jun 9, 2021

Commit Message: dependabot: Updates
Additional Description:
Risk Level:
Testing:
Docs Changes:
Release Notes:
Platform Specific Features:
[Optional Runtime guard:]
[Optional Fixes #Issue]
[Optional Deprecated:]
[Optional API Considerations:]

@repokitteh-read-only
Copy link

CC @envoyproxy/dependency-shepherds: Your approval is needed for changes made to (bazel/.*repos.*\.bzl)|(bazel/dependency_imports\.bzl)|(api/bazel/.*\.bzl)|(.*/requirements\.txt)|(.*\.patch).

🐱

Caused by: #16896 was opened by phlax.

see: more, trace.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We are behind on protobuf in the core dependency space. Should this version align with https://github.com/envoyproxy/envoy/blob/main/bazel/repository_locations.bzl#L597-L608 ?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

perhaps, altho im not sure if it matters that much for this client example

do you want me to downgrade it to 3.16.0 ?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

or perhaps we bump the bazel version for it instead

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ive bumped the protobuf version pulled in by bazel

Copy link
Member Author

@phlax phlax Jun 10, 2021

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

actually im reverting the bazel bump - it requires more than a simple update to the bazel files

also - afaict the protos in this example are built using

these are more than 3 years old and use v3.6.0

imho we probably still want to bump the client library

@phlax
Copy link
Member Author

phlax commented Jun 9, 2021

seems like there is another update for codeql/action ill update tomorrow

/wait

dependabot bot and others added 4 commits June 10, 2021 09:53
Bumps [protobuf](https://github.com/protocolbuffers/protobuf) from 3.17.2 to 3.17.3.
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Changelog](https://github.com/protocolbuffers/protobuf/blob/master/generate_changelog.py)
- [Commits](protocolbuffers/protobuf@v3.17.2...v3.17.3)

---
updated-dependencies:
- dependency-name: protobuf
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Ryan Northey <ryan@synca.io>
Bumps [actions/stale](https://github.com/actions/stale) from 3.0.14 to 3.0.19.
- [Release notes](https://github.com/actions/stale/releases)
- [Commits](actions/stale@v3.0.14...v3.0.19)

---
updated-dependencies:
- dependency-name: actions/stale
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Ryan Northey <ryan@synca.io>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from cb5810848de15b695cd9ef3b559dd178c43c7df3 to 1.0.2. This release includes the previously tagged commit.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@cb58108...a66b44a)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Ryan Northey <ryan@synca.io>
Signed-off-by: Ryan Northey <ryan@synca.io>
@htuch
Copy link
Member

htuch commented Jun 11, 2021

/lgtm deps

@repokitteh-read-only repokitteh-read-only bot removed the deps Approval required for changes to Envoy's external dependencies label Jun 11, 2021
@htuch htuch merged commit fc3763f into envoyproxy:main Jun 11, 2021
leyao-daily pushed a commit to leyao-daily/envoy that referenced this pull request Sep 30, 2021
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Ryan Northey <ryan@synca.io>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants