Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 30, 2025

Bumps golang.org/x/crypto from 0.23.0 to 0.31.0.

Commits
  • b4f1988 ssh: make the public key cache a 1-entry FIFO cache
  • 7042ebc openpgp/clearsign: just use rand.Reader in tests
  • 3e90321 go.mod: update golang.org/x dependencies
  • 8c4e668 x509roots/fallback: update bundle
  • 6018723 go.mod: update golang.org/x dependencies
  • 71ed71b README: don't recommend go get
  • 750a45f sha3: add MarshalBinary, AppendBinary, and UnmarshalBinary
  • 36b1725 sha3: avoid trailing permutation
  • 80ea76e sha3: fix padding for long cSHAKE parameters
  • c17aa50 sha3: avoid buffer copy
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jan 30, 2025
@dependabot dependabot bot requested a review from metachris January 30, 2025 21:34
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/crypto-0.31.0 branch from f345701 to 405ef74 Compare January 31, 2025 13:44
@jtraglia
Copy link
Collaborator

Hmm /x/crypto 0.32.0 exists now. Let's use that one. I'm going to ask dependabot to recreate this PR.

@dependabot recreate

Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.23.0 to 0.31.0.
- [Commits](golang/crypto@v0.23.0...v0.31.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/crypto-0.31.0 branch from 405ef74 to 7abbc70 Compare January 31, 2025 14:08
@jtraglia
Copy link
Collaborator

Well that didn't work. Whatever. This is to resolve a security alert.

@jtraglia jtraglia merged commit 245de7f into develop Jan 31, 2025
3 checks passed
@jtraglia jtraglia deleted the dependabot/go_modules/golang.org/x/crypto-0.31.0 branch January 31, 2025 14:13
jtraglia added a commit that referenced this pull request Apr 22, 2025
* v1.8.2-dev

* fix CONTRIBUTING lint path (#683)

* Update linters and fix issues (#707)

* Update main.go (#706)

* chore: add `.env.example` (#696)

* chore(git): add *.env, !.env.example to .gitignore

* chore: .env.example

* docs: fix invalid link in the document (#690)

* Release the RISC-V binary. (#682)

Part of #681.

* Add support for Electra (#651)

* Replace go-*-client deps with electra forks

* Add processElectraPayload

* Run make fmt

* Replace Exits with WithdrawRequests

* Rename WithdrawRequest to WithdrawalRequest

* Run go mod tidy

* Use go-*-client@electra

* Upgrade go-eth2-client

* update deps

* Add t.Helper() call

* Add back nolint comment

* Replace attestantio/go-*-client deps

* Fix accidental change

* Update go-boost-utils

* Update go-eth2-client for alpha.7 support

* Fix mistake

* Update & reverse payload decoding order

* Revert decoding order & add replacements

* Update go-eth2-client

* Update go-builder-client

* Modify processElectraPayload to use a channel (#704)

* server: refactor processElectraPayload (#703)

* Update go-eth2-client to latest electra commit

* Remove nolint:canonicalheader comments

* Disable canonicalheader linter

---------

Co-authored-by: avalonche <avalonche@protonmail.com>
Co-authored-by: Tyler <122291810+0xTylerHolmes@users.noreply.github.com>

* Update golang to 1.23 (#717)

* Update linter tools (#718)

* Update dependencies (#716)

* Update go-ethereum to v1.14.13

* Update go-utils to v0.8.3

* Update uint256 to v1.3.2

* Update testify to v1.10.0

* Update urfave/cli/v3 to v3.0.0-beta1

* Update go-bitfield to v0.0.0-20240618144021-706c95b2dd15

* Bump golang.org/x/crypto from 0.23.0 to 0.31.0 (#714)

Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.23.0 to 0.31.0.
- [Commits](golang/crypto@v0.23.0...v0.31.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Minor cleanup (#715)

* server: refactor bidRespKey

* server: split http handling and functionality

* Fix versionFlag to output to stdout (#710)

* Fix versionFlag to output to stdout

* Write version with fmt.Fprintf(cmd.Writer, ...)

---------

Co-authored-by: Justin Traglia <95511699+jtraglia@users.noreply.github.com>
Co-authored-by: Justin Traglia <jtraglia@pm.me>

* server: split http handling and functionality (part2) (#721)

* server: split out logger preparation (#722)

* server: make processPayload generic (#723)

* server: re-add capella types (#724)

* server: re-add capella types

* Remove unnecessary type arguments

* Add missing verifyBlockhash for electra

---------

Co-authored-by: Justin Traglia <jtraglia@pm.me>

* server: re-add bellatrix support (#725)

* server: re-add bellatrix support

* Remove unnecessary type arguments

* server: refactor TestGetPayloadFork tests (#726)

* server: refactor getPayloadForks tests

* server: remove old tests

* server: add nolint directive

* server: remove duplicate tests

* server: tiny refactor

* server: tiny refactor

* server: tiny refactor

* server: refactor tests again

* Rename denebHeader & add comment

---------

Co-authored-by: Justin Traglia <jtraglia@pm.me>

* Fix various nits (#728)

* Make error message better

* Use phase0.Slot type for slots

* Do a little clean up in service

* Rename "_slot" to "slot"

* Clean up getHeader function

* Do some clean up in functionality

* Split functionality.go into get_{header,payload}.go (#730)

* Use consistent capitalization for log messages (#732)

* Add fixes to SendHTTPRequest (#735)

* add missing error check

* move error check and use the same format for header comments

* Bump github.com/ethereum/go-ethereum from 1.14.13 to 1.15.0 (#737)

Bumps [github.com/ethereum/go-ethereum](https://github.com/ethereum/go-ethereum) from 1.14.13 to 1.15.0.
- [Release notes](https://github.com/ethereum/go-ethereum/releases)
- [Commits](ethereum/go-ethereum@v1.14.13...v1.15.0)

---
updated-dependencies:
- dependency-name: github.com/ethereum/go-ethereum
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Forward validator registrations without decoding (#733)

* Bump github.com/ethereum/go-ethereum from 1.15.0 to 1.15.1 (#740)

Bumps [github.com/ethereum/go-ethereum](https://github.com/ethereum/go-ethereum) from 1.15.0 to 1.15.1.
- [Release notes](https://github.com/ethereum/go-ethereum/releases)
- [Commits](ethereum/go-ethereum@v1.15.0...v1.15.1)

---
updated-dependencies:
- dependency-name: github.com/ethereum/go-ethereum
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Add SSZ tests for registerValidator (#741)

* Add SSZ tests for registerValidator

* Simplify conditional

* Fix a flakey test

* Remove support for relay monitors (#739)

* Remove support for relay monitors

* Remove blocknative relay from example

* Add getHeader SSZ support (#734)

* docs: fix Rémy Roy's guide link in README.md (#744)

* docs: fix Rémy Roy's guide link in README.md

* Update README.md

Co-authored-by: Marius van der Wijden <m.vanderwijden@live.de>

---------

Co-authored-by: Marius van der Wijden <m.vanderwijden@live.de>

* Bump github.com/ethereum/go-ethereum from 1.15.1 to 1.15.2 (#743)

Bumps [github.com/ethereum/go-ethereum](https://github.com/ethereum/go-ethereum) from 1.15.1 to 1.15.2.
- [Release notes](https://github.com/ethereum/go-ethereum/releases)
- [Commits](ethereum/go-ethereum@v1.15.1...v1.15.2)

---
updated-dependencies:
- dependency-name: github.com/ethereum/go-ethereum
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump github.com/attestantio/go-builder-client (#745)

* Add HeaderDateMilliseconds for improved request timing tracking (#748)

- Introduce new HeaderDateMilliseconds constant in constants.go
- Add HeaderDateMilliseconds to getHeader and processPayload methods
- Mark HeaderStartTimeUnixMS as deprecated with a comment

* Update dependencies (#755)

* Upgrade to go 1.24

* Update dependencies

* Update linters & fix complaints

* Update go versions elsewhere

* Add Hoodi testnet flag (#758)

* Add hoodi flag to the CLI

* Update docs

* Add getPayload SSZ support  (#742)

* Start to add getPayload SSZ support

* Add log for failed content parsing

* Update go-builder-client

* Properly parse getPayload response content type

* s/relaysToRequestFrom/relays

* Do a single SSZ to JSON conversion if necessary

* Only use JSON if necessary

* Simplify

* Only do conversion if necessary

* Bump version to v1.9-rc3 (#759)

* Remove deprecated HeaderStartTimeUnixMS (#749)

- Remove HeaderStartTimeUnixMS constant from constants.go
- Remove HeaderStartTimeUnixMS from getHeader and processPayload methods
- Fully transition to using HeaderDateMilliseconds for request timing

Co-authored-by: Justin Traglia <95511699+jtraglia@users.noreply.github.com>

* Add more logging to registerValidator (#768)

* fix: JSON Content-Type for relay get payload w/o SSZ support (#769)

* Update linters (#772)

* Update linters & migrate golangci-lint config

* Fix linter errors

* Update all dependencies (#771)

* Update version to v1.9 (#775)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Chris Hager <chris@linuxuser.at>
Co-authored-by: Jonas Warlike <mikmillarog@gmail.com>
Co-authored-by: Tyler <122291810+0xTylerHolmes@users.noreply.github.com>
Co-authored-by: richard <ohko4711@163.com>
Co-authored-by: Lorenzo <lorenzo.feroleto.dev@gmail.com>
Co-authored-by: guckool <yingzhengcrypto@gmail.com>
Co-authored-by: Leonardo Arias <leo@flashbots.net>
Co-authored-by: avalonche <avalonche@protonmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Marius van der Wijden <m.vanderwijden@live.de>
Co-authored-by: coincashew <62976495+coincashew@users.noreply.github.com>
Co-authored-by: Alexey Shekhirin <5773434+shekhirin@users.noreply.github.com>
Co-authored-by: Alexander Tesfamichael <alex.tesfamichael@gmail.com>
Co-authored-by: Jacob Kaufmann <jacobkaufmann18@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant