Skip to content

Comments

build(deps): Bump oras.land/oras-go/v2 from 2.2.1 to 2.3.0#84

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/go_modules/oras.land/oras-go/v2-2.3.0
Open

build(deps): Bump oras.land/oras-go/v2 from 2.2.1 to 2.3.0#84
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/go_modules/oras.land/oras-go/v2-2.3.0

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Sep 4, 2023

Bumps oras.land/oras-go/v2 from 2.2.1 to 2.3.0.

Release notes

Sourced from oras.land/oras-go/v2's releases.

v2.3.0

New Features

  • Conform to image-spec v1.1.0-rc4 and distribution-spec v1.1.0-rc3, while remaining compatible with image-spec v1.1.0-rc2 and distribution-spec v1.1.0-rc1 (see #494 for more details)
    • Support handling Image Index with a subject
    • Add oras.PackManifest that supports packing Image Manifest version 1.0 and version 1.1.0-rc4, as well as media type validation
    • Add Repository.HandleWarning that can be used to handle warnings returned by the remote registry
    • Update the implementation of Referrers API to support the "OCI-Filters-Applied" response header
    • Update the implementation of pushing manifests with subject to support the "OCI-Subject" response header
  • Add Repository.SkipReferrersGC that allows skipping deleting dangling referrers index when referrers tag schema is utilized

Deprecation

  • oras.Pack is deprecated and not recommended for future use. Use oras.PackManifest instead.

Other Changes

  • Improve documentation and examples

Detailed Commits

Full Changelog: oras-project/oras-go@v2.2.1...v2.3.0

Commits
  • 47d028a feat: validate input media type for oras.PackManifest (#574)
  • 60da91b refactor: refactor unexported pack methods (#573)
  • e6d40b6 refactor: add PackManifest and deprecate Pack (#570)
  • ea07bf6 build(deps): bump apache/skywalking-eyes from 0.4.0 to 0.5.0 (#569)
  • bbe92af fix: pack should not set artifactType when config is specified (#565)
  • 933ae41 docs: display larger example (#564)
  • d5cefe9 docs: add e2e examples for oras-go (#561)
  • b59a33e feat: report warnings (#560)
  • 3a2e0c1 docs: update links (#563)
  • 6ec43e7 feat: update the implementation of deleting manifest for distribution-spec v1...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [oras.land/oras-go/v2](https://github.com/oras-project/oras-go) from 2.2.1 to 2.3.0.
- [Release notes](https://github.com/oras-project/oras-go/releases)
- [Commits](oras-project/oras-go@v2.2.1...v2.3.0)

---
updated-dependencies:
- dependency-name: oras.land/oras-go/v2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 4, 2023
@codecov-commenter
Copy link

Codecov Report

Merging #84 (a1b4ec9) into main (7574cea) will not change coverage.
The diff coverage is n/a.

❗ Your organization is not using the GitHub App Integration. As a result you may experience degraded service beginning May 15th. Please install the GitHub App Integration for your organization. Read more.

@@           Coverage Diff           @@
##             main      #84   +/-   ##
=======================================
  Coverage   63.98%   63.98%           
=======================================
  Files          40       40           
  Lines        2252     2252           
=======================================
  Hits         1441     1441           
  Misses        689      689           
  Partials      122      122           

📣 We’re building smart automated test selection to slash your CI/CD build times. Learn more

@github-actions
Copy link

This PR is stale because it has been opened for 45 days with no activity. Remove stale label or comment. Otherwise, it will be closed in 30 days.

@github-actions github-actions bot added the Stale label Feb 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code Stale

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant