Skip to content

Bump golang.org/x/oauth2 from 0.9.0 to 0.12.0#674

Closed
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/go_modules/golang.org/x/oauth2-0.12.0
Closed

Bump golang.org/x/oauth2 from 0.9.0 to 0.12.0#674
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/go_modules/golang.org/x/oauth2-0.12.0

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Sep 5, 2023

Bumps golang.org/x/oauth2 from 0.9.0 to 0.12.0.

Commits
  • 0708528 go.mod: update golang.org/x dependencies
  • a835fc4 oauth2: move global auth style cache to be per-Config
  • 2e4a4e2 go.mod: update golang.org/x dependencies
  • ac6658e all: update go version to 1.18
  • ec5679f go.mod: update golang.org/x dependencies
  • 989acb1 all: update dependencies to their latest versions
  • See full diff in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Sep 5, 2023
@github-actions github-actions bot enabled auto-merge (squash) September 5, 2023 17:52
@guardrails
Copy link

guardrails bot commented Sep 5, 2023

⚠️ We detected 11 security issues in this pull request:

Vulnerable Libraries (11)
Severity Details
High pkg:golang/github.com/gogo/protobuf@v1.1.1 upgrade to: 1.3.2
N/A pkg:golang/golang.org/x/sys@v0.0.0-20200106162015-b016eb3dc98e upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/github.com/aws/aws-sdk-go@v1.44.264 - no patch available
N/A pkg:golang/golang.org/x/net@v0.0.0-20220725212005-46097bf591d3 upgrade to: 0.7.0
N/A pkg:golang/golang.org/x/sys@v0.0.0-20200615200032-f1bc736245b1 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/github.com/prometheus/client_golang@v1.7.1 upgrade to: 1.11.1
High pkg:golang/github.com/prometheus/client_golang@v0.9.1 upgrade to: 1.11.1
High pkg:golang/github.com/prometheus/client_golang@v1.0.0 upgrade to: 1.11.1
N/A pkg:golang/go.opentelemetry.io/otel/sdk@v1.0.0-RC3 - no patch available
N/A pkg:golang/golang.org/x/net@v0.0.0-20181114220301-adae6a3d119a upgrade to: 1.15.12,1.16.4,0.0.0-20210428140749-89ef3d95e781
N/A pkg:golang/golang.org/x/crypto@v0.0.0-20180904163835-0709b304e793 upgrade to: 1.12.16,1.13.7,0.0.0-20200124225646-8b5121be2f68

More info on how to fix Vulnerable Libraries in Go.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 56e7200 to 90e3ba5 Compare September 5, 2023 18:45
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 90e3ba5 to 0e874d6 Compare September 5, 2023 18:48
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 0e874d6 to eb9530d Compare September 7, 2023 17:52
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from eb9530d to aded1b8 Compare September 7, 2023 18:00
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from aded1b8 to 07b4742 Compare September 8, 2023 17:55
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 07b4742 to 01db79a Compare September 8, 2023 18:04
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 01db79a to 769ebfe Compare September 11, 2023 17:34
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 769ebfe to 90de9ad Compare September 12, 2023 18:08
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 90de9ad to c69f81e Compare September 13, 2023 17:33
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from c69f81e to 966548f Compare September 14, 2023 17:57
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 966548f to 0ddd0d2 Compare September 15, 2023 17:13
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 0ddd0d2 to c6ec31f Compare September 18, 2023 17:41
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from c6ec31f to 36596d6 Compare September 19, 2023 17:53
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 36596d6 to e04c22f Compare September 20, 2023 17:37
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from e04c22f to 9b62468 Compare September 21, 2023 17:54
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 9b62468 to 65f70a7 Compare September 25, 2023 17:48
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 65f70a7 to fadf6e4 Compare September 25, 2023 17:57
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from fadf6e4 to 7588881 Compare September 26, 2023 18:01
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 7588881 to a6b7f99 Compare September 27, 2023 17:37
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from a6b7f99 to 17b6c14 Compare September 28, 2023 17:25
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 17b6c14 to 2e3e921 Compare September 28, 2023 17:33
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 2e3e921 to 01ef516 Compare September 29, 2023 17:55
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 01ef516 to 8cef01b Compare October 3, 2023 17:44
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2) from 0.9.0 to 0.12.0.
- [Commits](golang/oauth2@v0.9.0...v0.12.0)

---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch from 8cef01b to a1685be Compare October 4, 2023 18:04
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Oct 6, 2023

Superseded by #720.

@dependabot dependabot bot closed this Oct 6, 2023
auto-merge was automatically disabled October 6, 2023 17:13

Pull request was closed

@dependabot dependabot bot deleted the dependabot/go_modules/golang.org/x/oauth2-0.12.0 branch October 6, 2023 17:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants