Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security(tendermint): Bump github.com/tendermint/tendermint from 0.34.19 to 0.34.20 #367

Merged

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Aug 15, 2022

Bumps github.com/tendermint/tendermint from 0.34.19 to 0.34.20.

Release notes

Sourced from github.com/tendermint/tendermint's releases.

0.34.20 (WARNING: BETA SOFTWARE)

https://github.com/tendermint/tendermint/blob/v0.34.20/CHANGELOG.md#v0.34.20

Changelog

Sourced from github.com/tendermint/tendermint's changelog.

v0.34.20

Special thanks to external contributors on this release: @​joeabbey @​yihuang

This release introduces a prioritized mempool. Further notes can be found in UPGRADING.md.

NOTE: There's a known issue when combining the prioritized mempool with the ABCI socket client, that the team are curently working to resolve. Read more about the issue here.

BUG FIXES

FEATURES

IMPROVEMENTS

  • [logging] #8845 Add "Lazy" Stringers to defer Sprintf and Hash until logs print. (@​joeabbey)
Commits
  • d32df22 Prepare changelog for Release v0.34.20 (#9032)
  • 223ece9 mempool: ensure async requests are flushed to the server (#9010)
  • ba1711e mempool: ensure evicted transactions are removed from the cache (backport #90...
  • 8df725f build(deps): Bump google.golang.org/grpc from 1.47.0 to 1.48.0 (#8991)
  • 2b37373 config: remove obsolete mempool v1 warning (#8987)
  • bbb5f3b Prepare changelog for v0.34.20-rc1. (#8966)
  • d6b413f mempool: release lock during app connection flush (#8986)
  • 7b615f8 mempool: reduce lock contention during CheckTx (backport #8983) (#8985)
  • 7d94471 mempool: minor cleanup after backport from v0.35 (#8971)
  • 5276400 Update generated mocks after upgrade of Mockery v2. (#8974)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

ankurdotb and others added 9 commits August 13, 2022 01:29
Bumps github.com/spf13/viper from 1.10.1 to 1.12.0.

Release notes
Sourced from github.com/spf13/viper's releases.

v1.12.0
This release makes YAML v3 and TOML v2 the default versions used for encoding.
You can switch back to the old versions by adding viper_yaml2 and viper_toml1 to the build tags.
Please note that YAML v2 and TOML v1 are considered deprecated from this release and may be removed in a future release.
Please provide feedback in discussions and report bugs on the issue tracker. Thanks!

What's Changed
Exciting New Features 🎉

Add etcd3 support to remote by @​sagikazarmark in spf13/viper#1356
Make YAML 3 the default by @​sagikazarmark in spf13/viper#1357
Make TOML 2 the default by @​sagikazarmark in spf13/viper#1358

Enhancements 🚀

chore: fix Error log calls in mergeMaps by @​wwade in spf13/viper#1341
Add MustBindEnv by @​meowfaceman in spf13/viper#1301

Dependency Updates ⬆️

build(deps): bump github/codeql-action from 1 to 2 by @​dependabot in spf13/viper#1336
build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0-beta.8 to 2.0.0 by @​dependabot in spf13/viper#1339
build(deps): bump github.com/mitchellh/mapstructure from 1.4.3 to 1.5.0 by @​dependabot in spf13/viper#1332
build(deps): bump github.com/pelletier/go-toml from 1.9.4 to 1.9.5 by @​dependabot in spf13/viper#1335
build(deps): bump github.com/fsnotify/fsnotify from 1.5.1 to 1.5.4 by @​dependabot in spf13/viper#1338
build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0 by @​dependabot in spf13/viper#1344
build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1 by @​dependabot in spf13/viper#1343
build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0 by @​dependabot in spf13/viper#1349

New Contributors

@​meowfaceman made their first contribution in spf13/viper#1301
@​wwade made their first contribution in spf13/viper#1341

Full Changelog: spf13/[email protected]
v1.11.0

What's Changed
Exciting New Features 🎉

Experimental yaml v3 library support by @​sagikazarmark in spf13/viper#1273
Experimental toml v2 support by @​sagikazarmark in spf13/viper#1274
Experimental logger by @​sagikazarmark in spf13/viper#1275

Enhancements 🚀

Remove unnecessary operand by @​steviebps in spf13/viper#1213
Improve encoding layer by @​sagikazarmark in spf13/viper#1167
Allow merging configs with different types of leaf values by @​illarion in spf13/viper#1181

Bug Fixes 🐛

Disable race detector on windows by @​sagikazarmark in spf13/viper#1269



... (truncated)


Commits

4322cf2 feat: make toml2 the default
8d02999 feat: make yaml3 the default
7c35aa9 chore(deps): update yaml3
433821f feat: add etcd3 support to remote
2080d43 chore: update crypt
da55858 chore: fix Error log calls in mergeMaps
f50ce90 Add in MustBindEnv.
3b836e5 build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0
5d65186 build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1
9f85518 build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0
Additional commits viewable in compare view




Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Ankur Banerjee <[email protected]>
)

Bumps github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25.

Release notes
Sourced from github.com/lestrrat-go/jwx's releases.

v1.2.25
v1.2.25 23 May 2022
[Bug Fixes][Security]
  * [jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
    where the unpad operation might remove more bytes than necessary ([#744](lestrrat-go/jwx#744))
    This affects all jwx code that is available before v2.0.2 and v1.2.25.

v1.2.24
v1.2.24 05 May 2022
[Security]
  * Upgrade golang.org/x/crypto ([#724](lestrrat-go/jwx#724))

v1.2.23
v1.2.23 13 Apr 2022
[Bug fixes]
  * [jwk] jwk.AutoRefresh had a race condition when `Configure()` was
    called concurrently ([#686](lestrrat-go/jwx#686))
    (It has been patched correctly, but we may come back to revisit
     the design choices in the near future)

v1.2.22
v1.2.22 08 Apr 2022
[Bug fixes]
  * [jws] jws.Verify was ignoring the `b64` header when it was present
    in the protected headers ([#681](lestrrat-go/jwx#681)). Now the following should work:
  jws.Sign(..., jws.WithDetachedPayload(payload))
  // previously payload had to be base64 encoded
  jws.Verify(..., jws.WithDetachedPayload(payload))
(note: v2 branch was not affected)


v1.2.21
v1.2.21 30 Mar 2022
[Bug fixes]
  * [jwk] RSA keys without p and q can now be parsed.




Changelog
Sourced from github.com/lestrrat-go/jwx's changelog.

v1.2.25 23 May 2022
[Bug Fixes][Security]

[jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
where the unpad operation might remove more bytes than necessary (#744)
This affects all jwx code that is available before v2.0.2 and v1.2.25.

v1.2.24 05 May 2022
[Security]

Upgrade golang.org/x/crypto (#724)

v1.2.23 13 Apr 2022
[Bug fixes]

[jwk] jwk.AutoRefresh had a race condition when Configure() was
called concurrently (#686)
(It has been patched correctly, but we may come back to revisit
the design choices in the near future)

v1.2.22 08 Apr 2022
[Bug fixes]


[jws] jws.Verify was ignoring the b64 header when it was present
in the protected headers (#681). Now the following should work:
jws.Sign(..., jws.WithDetachedPayload(payload))
// previously payload had to be base64 encoded
jws.Verify(..., jws.WithDetachedPayload(payload))
(note: v2 branch was not affected)


v1.2.21 30 Mar 2022
[Bug fixes]

[jwk] RSA keys without p and q can now be parsed.




Commits

ad8c29d merge develop/v1 (#747)
e38f677 Merge develop/v1 (#727)
baba561 Merge branch 'develop/v1' into v1
8ff6c75 Update Changes
ea97e8c Fix race in jwk.AutoRefresh (#686)
f4701e1 Update Changes
e831228 Fix jws.Verify not respecting the b64 header in the protected headers (#683)
b66a2cb backport: Update golangci lint (#679) (#680)
4899c32 reword error
dd9e4c4 Bump github.com/lestrrat-go/httpcc from 1.0.0 to 1.0.1 (#675)
Additional commits viewable in compare view




Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Ankur Banerjee <[email protected]>
Bumps github.com/stretchr/testify from 1.7.1 to 1.8.0.

Commits

181cea6 impr: CallerInfo should print full paths to the terminal (#1201)
cf1284f Allow mock expectations to be ordered (#1106)
66eef0e fix: assert.MapSubset (or just support maps in assert.Subset) (#1178)
2fab6df Add WithinTimeRange method (#1188)
b5ce165 fixing panic in calls to assertion with nil m.mutex (#1212)
c206b2e Mock can be deadlocked by a panic (#1157)
1b73601 suite: correctly set stats on test panic (#1195)
ba1076d Add .Unset method to mock (#982)
c31ea03 Support comparing byte slice (#1202)
48391ba Fix panic in AssertExpectations for mocks without expectations (#1207)
Additional commits viewable in compare view




Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Ankur Banerjee <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Aug 15, 2022
Andrew Nikitin and others added 5 commits August 16, 2022 13:48
Signed-off-by: Andrew Nikitin <[email protected]>
Co-authored-by: Ankur Banerjee <[email protected]>
…0.1.1 (#371)

* chore(deps): Bump github.com/multiformats/go-multibase

Bumps [github.com/multiformats/go-multibase](https://github.com/multiformats/go-multibase) from 0.0.3 to 0.1.1.
- [Release notes](https://github.com/multiformats/go-multibase/releases)
- [Commits](multiformats/go-multibase@v0.0.3...v0.1.1)

---
updated-dependencies:
- dependency-name: github.com/multiformats/go-multibase
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>

* chore(deps): Bump github.com/multiformats/go-multibase

Bumps [github.com/multiformats/go-multibase](https://github.com/multiformats/go-multibase) from 0.0.3 to 0.1.1.
- [Release notes](https://github.com/multiformats/go-multibase/releases)
- [Commits](multiformats/go-multibase@v0.0.3...v0.1.1)

---
updated-dependencies:
- dependency-name: github.com/multiformats/go-multibase
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Ankur Banerjee <[email protected]>
…4.1 (#370)

Bumps [github.com/gabriel-vasile/mimetype](https://github.com/gabriel-vasile/mimetype) from 1.4.0 to 1.4.1.
- [Release notes](https://github.com/gabriel-vasile/mimetype/releases)
- [Commits](gabriel-vasile/mimetype@v1.4.0...v1.4.1)

---
updated-dependencies:
- dependency-name: github.com/gabriel-vasile/mimetype
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/tendermint/tendermint](https://github.com/tendermint/tendermint) from 0.34.19 to 0.34.20.
- [Release notes](https://github.com/tendermint/tendermint/releases)
- [Changelog](https://github.com/tendermint/tendermint/blob/main/CHANGELOG.md)
- [Commits](tendermint/tendermint@v0.34.19...v0.34.20)

---
updated-dependencies:
- dependency-name: github.com/tendermint/tendermint
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/tendermint/tendermint-0.34.20 branch from b3a1137 to 8b1c244 Compare August 16, 2022 21:11
@ankurdotb ankurdotb changed the base branch from main to develop August 16, 2022 21:22
@ankurdotb ankurdotb changed the title chore(deps): Bump github.com/tendermint/tendermint from 0.34.19 to 0.34.20 security(tendermint): Bump github.com/tendermint/tendermint from 0.34.19 to 0.34.20 Aug 16, 2022
@ankurdotb ankurdotb merged commit ab0cb89 into develop Aug 16, 2022
@ankurdotb ankurdotb deleted the dependabot/go_modules/github.com/tendermint/tendermint-0.34.20 branch August 16, 2022 23:34
ankurdotb added a commit that referenced this pull request Aug 16, 2022
commit ab0cb89
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Date:   Wed Aug 17 00:34:56 2022 +0100

    security(tendermint): Bump github.com/tendermint/tendermint from 0.34.19 to 0.34.20 (#367)

    * ci: Cleanup old workflow runs (#364)

    * ci: Make workflow cleanup choices easier

    * ci: Fix linting error

    * ci: Disable cleanup dry-run

    * ci: Add automated semantic release using Goreleaser (#357)

    Co-authored-by: Ankur Banerjee <[email protected]>

    * build: Optimise Docker build (#365)

    * chore(deps): Bump github.com/spf13/viper from 1.10.1 to 1.12.0 (#360)

    Bumps github.com/spf13/viper from 1.10.1 to 1.12.0.

    Release notes
    Sourced from github.com/spf13/viper's releases.

    v1.12.0
    This release makes YAML v3 and TOML v2 the default versions used for encoding.
    You can switch back to the old versions by adding viper_yaml2 and viper_toml1 to the build tags.
    Please note that YAML v2 and TOML v1 are considered deprecated from this release and may be removed in a future release.
    Please provide feedback in discussions and report bugs on the issue tracker. Thanks!

    What's Changed
    Exciting New Features 🎉

    Add etcd3 support to remote by @​sagikazarmark in spf13/viper#1356
    Make YAML 3 the default by @​sagikazarmark in spf13/viper#1357
    Make TOML 2 the default by @​sagikazarmark in spf13/viper#1358

    Enhancements 🚀

    chore: fix Error log calls in mergeMaps by @​wwade in spf13/viper#1341
    Add MustBindEnv by @​meowfaceman in spf13/viper#1301

    Dependency Updates ⬆️

    build(deps): bump github/codeql-action from 1 to 2 by @​dependabot in spf13/viper#1336
    build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0-beta.8 to 2.0.0 by @​dependabot in spf13/viper#1339
    build(deps): bump github.com/mitchellh/mapstructure from 1.4.3 to 1.5.0 by @​dependabot in spf13/viper#1332
    build(deps): bump github.com/pelletier/go-toml from 1.9.4 to 1.9.5 by @​dependabot in spf13/viper#1335
    build(deps): bump github.com/fsnotify/fsnotify from 1.5.1 to 1.5.4 by @​dependabot in spf13/viper#1338
    build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0 by @​dependabot in spf13/viper#1344
    build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1 by @​dependabot in spf13/viper#1343
    build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0 by @​dependabot in spf13/viper#1349

    New Contributors

    @​meowfaceman made their first contribution in spf13/viper#1301
    @​wwade made their first contribution in spf13/viper#1341

    Full Changelog: spf13/[email protected]
    v1.11.0

    What's Changed
    Exciting New Features 🎉

    Experimental yaml v3 library support by @​sagikazarmark in spf13/viper#1273
    Experimental toml v2 support by @​sagikazarmark in spf13/viper#1274
    Experimental logger by @​sagikazarmark in spf13/viper#1275

    Enhancements 🚀

    Remove unnecessary operand by @​steviebps in spf13/viper#1213
    Improve encoding layer by @​sagikazarmark in spf13/viper#1167
    Allow merging configs with different types of leaf values by @​illarion in spf13/viper#1181

    Bug Fixes 🐛

    Disable race detector on windows by @​sagikazarmark in spf13/viper#1269

    ... (truncated)

    Commits

    4322cf2 feat: make toml2 the default
    8d02999 feat: make yaml3 the default
    7c35aa9 chore(deps): update yaml3
    433821f feat: add etcd3 support to remote
    2080d43 chore: update crypt
    da55858 chore: fix Error log calls in mergeMaps
    f50ce90 Add in MustBindEnv.
    3b836e5 build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0
    5d65186 build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1
    9f85518 build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0
    Additional commits viewable in compare view

    Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

    Dependabot commands and options

    You can trigger Dependabot actions by commenting on this PR:

    @dependabot rebase will rebase this PR
    @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
    @dependabot merge will merge this PR after your CI passes on it
    @dependabot squash and merge will squash and merge this PR after your CI passes on it
    @dependabot cancel merge will cancel a previously requested merge and block automerging
    @dependabot reopen will reopen this PR if it is closed
    @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
    @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
    @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
    @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Ankur Banerjee <[email protected]>

    * chore(deps): Bump github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25 (#359)

    Bumps github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25.

    Release notes
    Sourced from github.com/lestrrat-go/jwx's releases.

    v1.2.25
    v1.2.25 23 May 2022
    [Bug Fixes][Security]
      * [jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
        where the unpad operation might remove more bytes than necessary ([#744](lestrrat-go/jwx#744))
        This affects all jwx code that is available before v2.0.2 and v1.2.25.

    v1.2.24
    v1.2.24 05 May 2022
    [Security]
      * Upgrade golang.org/x/crypto ([#724](lestrrat-go/jwx#724))

    v1.2.23
    v1.2.23 13 Apr 2022
    [Bug fixes]
      * [jwk] jwk.AutoRefresh had a race condition when `Configure()` was
        called concurrently ([#686](lestrrat-go/jwx#686))
        (It has been patched correctly, but we may come back to revisit
         the design choices in the near future)

    v1.2.22
    v1.2.22 08 Apr 2022
    [Bug fixes]
      * [jws] jws.Verify was ignoring the `b64` header when it was present
        in the protected headers ([#681](lestrrat-go/jwx#681)). Now the following should work:
      jws.Sign(..., jws.WithDetachedPayload(payload))
      // previously payload had to be base64 encoded
      jws.Verify(..., jws.WithDetachedPayload(payload))
    (note: v2 branch was not affected)

    v1.2.21
    v1.2.21 30 Mar 2022
    [Bug fixes]
      * [jwk] RSA keys without p and q can now be parsed.

    Changelog
    Sourced from github.com/lestrrat-go/jwx's changelog.

    v1.2.25 23 May 2022
    [Bug Fixes][Security]

    [jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
    where the unpad operation might remove more bytes than necessary (#744)
    This affects all jwx code that is available before v2.0.2 and v1.2.25.

    v1.2.24 05 May 2022
    [Security]

    Upgrade golang.org/x/crypto (#724)

    v1.2.23 13 Apr 2022
    [Bug fixes]

    [jwk] jwk.AutoRefresh had a race condition when Configure() was
    called concurrently (#686)
    (It has been patched correctly, but we may come back to revisit
    the design choices in the near future)

    v1.2.22 08 Apr 2022
    [Bug fixes]

    [jws] jws.Verify was ignoring the b64 header when it was present
    in the protected headers (#681). Now the following should work:
    jws.Sign(..., jws.WithDetachedPayload(payload))
    // previously payload had to be base64 encoded
    jws.Verify(..., jws.WithDetachedPayload(payload))
    (note: v2 branch was not affected)

    v1.2.21 30 Mar 2022
    [Bug fixes]

    [jwk] RSA keys without p and q can now be parsed.

    Commits

    ad8c29d merge develop/v1 (#747)
    e38f677 Merge develop/v1 (#727)
    baba561 Merge branch 'develop/v1' into v1
    8ff6c75 Update Changes
    ea97e8c Fix race in jwk.AutoRefresh (#686)
    f4701e1 Update Changes
    e831228 Fix jws.Verify not respecting the b64 header in the protected headers (#683)
    b66a2cb backport: Update golangci lint (#679) (#680)
    4899c32 reword error
    dd9e4c4 Bump github.com/lestrrat-go/httpcc from 1.0.0 to 1.0.1 (#675)
    Additional commits viewable in compare view

    Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

    Dependabot commands and options

    You can trigger Dependabot actions by commenting on this PR:

    @dependabot rebase will rebase this PR
    @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
    @dependabot merge will merge this PR after your CI passes on it
    @dependabot squash and merge will squash and merge this PR after your CI passes on it
    @dependabot cancel merge will cancel a previously requested merge and block automerging
    @dependabot reopen will reopen this PR if it is closed
    @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
    @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
    @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
    @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Ankur Banerjee <[email protected]>

    * chore(deps): Bump github.com/stretchr/testify from 1.7.1 to 1.8.0 (#362)

    Bumps github.com/stretchr/testify from 1.7.1 to 1.8.0.

    Commits

    181cea6 impr: CallerInfo should print full paths to the terminal (#1201)
    cf1284f Allow mock expectations to be ordered (#1106)
    66eef0e fix: assert.MapSubset (or just support maps in assert.Subset) (#1178)
    2fab6df Add WithinTimeRange method (#1188)
    b5ce165 fixing panic in calls to assertion with nil m.mutex (#1212)
    c206b2e Mock can be deadlocked by a panic (#1157)
    1b73601 suite: correctly set stats on test panic (#1195)
    ba1076d Add .Unset method to mock (#982)
    c31ea03 Support comparing byte slice (#1202)
    48391ba Fix panic in AssertExpectations for mocks without expectations (#1207)
    Additional commits viewable in compare view

    Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

    Dependabot commands and options

    You can trigger Dependabot actions by commenting on this PR:

    @dependabot rebase will rebase this PR
    @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
    @dependabot merge will merge this PR after your CI passes on it
    @dependabot squash and merge will squash and merge this PR after your CI passes on it
    @dependabot cancel merge will cancel a previously requested merge and block automerging
    @dependabot reopen will reopen this PR if it is closed
    @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
    @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
    @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
    @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Ankur Banerjee <[email protected]>

    * build: Multi-platform AMD64/ARM64 for Linux (#366)

    Signed-off-by: Andrew Nikitin <[email protected]>
    Co-authored-by: Ankur Banerjee <[email protected]>

    * ci: Fix CodeQL Golang version

    * chore(deps): Bump github.com/multiformats/go-multibase from 0.0.3 to 0.1.1 (#371)

    * chore(deps): Bump github.com/multiformats/go-multibase

    Bumps [github.com/multiformats/go-multibase](https://github.com/multiformats/go-multibase) from 0.0.3 to 0.1.1.
    - [Release notes](https://github.com/multiformats/go-multibase/releases)
    - [Commits](multiformats/go-multibase@v0.0.3...v0.1.1)

    ---
    updated-dependencies:
    - dependency-name: github.com/multiformats/go-multibase
      dependency-type: direct:production
      update-type: version-update:semver-minor
    ...

    Signed-off-by: dependabot[bot] <[email protected]>

    * chore(deps): Bump github.com/multiformats/go-multibase

    Bumps [github.com/multiformats/go-multibase](https://github.com/multiformats/go-multibase) from 0.0.3 to 0.1.1.
    - [Release notes](https://github.com/multiformats/go-multibase/releases)
    - [Commits](multiformats/go-multibase@v0.0.3...v0.1.1)

    ---
    updated-dependencies:
    - dependency-name: github.com/multiformats/go-multibase
      dependency-type: direct:production
      update-type: version-update:semver-minor
    ...

    Signed-off-by: dependabot[bot] <[email protected]>

    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Ankur Banerjee <[email protected]>

    * chore(deps): Bump github.com/gabriel-vasile/mimetype from 1.4.0 to 1.4.1 (#370)

    Bumps [github.com/gabriel-vasile/mimetype](https://github.com/gabriel-vasile/mimetype) from 1.4.0 to 1.4.1.
    - [Release notes](https://github.com/gabriel-vasile/mimetype/releases)
    - [Commits](gabriel-vasile/mimetype@v1.4.0...v1.4.1)

    ---
    updated-dependencies:
    - dependency-name: github.com/gabriel-vasile/mimetype
      dependency-type: direct:production
      update-type: version-update:semver-patch
    ...

    Signed-off-by: dependabot[bot] <[email protected]>

    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

    * chore(deps): Bump github.com/tendermint/tendermint

    Bumps [github.com/tendermint/tendermint](https://github.com/tendermint/tendermint) from 0.34.19 to 0.34.20.
    - [Release notes](https://github.com/tendermint/tendermint/releases)
    - [Changelog](https://github.com/tendermint/tendermint/blob/main/CHANGELOG.md)
    - [Commits](tendermint/tendermint@v0.34.19...v0.34.20)

    ---
    updated-dependencies:
    - dependency-name: github.com/tendermint/tendermint
      dependency-type: direct:production
      update-type: version-update:semver-patch
    ...

    Signed-off-by: dependabot[bot] <[email protected]>

    Signed-off-by: dependabot[bot] <[email protected]>
    Signed-off-by: Andrew Nikitin <[email protected]>
    Co-authored-by: Ankur Banerjee <[email protected]>
    Co-authored-by: Andrew Nikitin <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

commit f7b2d4f
Author: Ankur Banerjee <[email protected]>
Date:   Tue Aug 16 22:21:43 2022 +0100

    Squashed commit of the following:

    commit 48d1512
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Tue Aug 16 22:09:31 2022 +0100

        chore(deps): Bump github.com/gabriel-vasile/mimetype from 1.4.0 to 1.4.1 (#370)

        Bumps [github.com/gabriel-vasile/mimetype](https://github.com/gabriel-vasile/mimetype) from 1.4.0 to 1.4.1.
        - [Release notes](https://github.com/gabriel-vasile/mimetype/releases)
        - [Commits](gabriel-vasile/mimetype@v1.4.0...v1.4.1)

        ---
        updated-dependencies:
        - dependency-name: github.com/gabriel-vasile/mimetype
          dependency-type: direct:production
          update-type: version-update:semver-patch
        ...

        Signed-off-by: dependabot[bot] <[email protected]>

        Signed-off-by: dependabot[bot] <[email protected]>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

    commit 1bd0801
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Tue Aug 16 21:10:29 2022 +0100

        chore(deps): Bump github.com/multiformats/go-multibase from 0.0.3 to 0.1.1 (#371)

        * chore(deps): Bump github.com/multiformats/go-multibase

        Bumps [github.com/multiformats/go-multibase](https://github.com/multiformats/go-multibase) from 0.0.3 to 0.1.1.
        - [Release notes](https://github.com/multiformats/go-multibase/releases)
        - [Commits](multiformats/go-multibase@v0.0.3...v0.1.1)

        ---
        updated-dependencies:
        - dependency-name: github.com/multiformats/go-multibase
          dependency-type: direct:production
          update-type: version-update:semver-minor
        ...

        Signed-off-by: dependabot[bot] <[email protected]>

        * chore(deps): Bump github.com/multiformats/go-multibase

        Bumps [github.com/multiformats/go-multibase](https://github.com/multiformats/go-multibase) from 0.0.3 to 0.1.1.
        - [Release notes](https://github.com/multiformats/go-multibase/releases)
        - [Commits](multiformats/go-multibase@v0.0.3...v0.1.1)

        ---
        updated-dependencies:
        - dependency-name: github.com/multiformats/go-multibase
          dependency-type: direct:production
          update-type: version-update:semver-minor
        ...

        Signed-off-by: dependabot[bot] <[email protected]>

        Signed-off-by: dependabot[bot] <[email protected]>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
        Co-authored-by: Ankur Banerjee <[email protected]>

    commit 4b2da73
    Author: Ankur Banerjee <[email protected]>
    Date:   Tue Aug 16 17:06:51 2022 +0100

        ci: Fix CodeQL Golang version

    commit 2fc6ae5
    Author: Andrew Nikitin <[email protected]>
    Date:   Tue Aug 16 15:48:13 2022 +0300

        build: Multi-platform AMD64/ARM64 for Linux (#366)

        Signed-off-by: Andrew Nikitin <[email protected]>
        Co-authored-by: Ankur Banerjee <[email protected]>

    commit 7485eb2
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Mon Aug 15 15:37:31 2022 +0100

        chore(deps): Bump github.com/stretchr/testify from 1.7.1 to 1.8.0 (#362)

        Bumps github.com/stretchr/testify from 1.7.1 to 1.8.0.

        Commits

        181cea6 impr: CallerInfo should print full paths to the terminal (#1201)
        cf1284f Allow mock expectations to be ordered (#1106)
        66eef0e fix: assert.MapSubset (or just support maps in assert.Subset) (#1178)
        2fab6df Add WithinTimeRange method (#1188)
        b5ce165 fixing panic in calls to assertion with nil m.mutex (#1212)
        c206b2e Mock can be deadlocked by a panic (#1157)
        1b73601 suite: correctly set stats on test panic (#1195)
        ba1076d Add .Unset method to mock (#982)
        c31ea03 Support comparing byte slice (#1202)
        48391ba Fix panic in AssertExpectations for mocks without expectations (#1207)
        Additional commits viewable in compare view

        Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

        Dependabot commands and options

        You can trigger Dependabot actions by commenting on this PR:

        @dependabot rebase will rebase this PR
        @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
        @dependabot merge will merge this PR after your CI passes on it
        @dependabot squash and merge will squash and merge this PR after your CI passes on it
        @dependabot cancel merge will cancel a previously requested merge and block automerging
        @dependabot reopen will reopen this PR if it is closed
        @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
        @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

        Signed-off-by: dependabot[bot] <[email protected]>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
        Co-authored-by: Ankur Banerjee <[email protected]>

    commit 1e3e807
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Mon Aug 15 15:14:40 2022 +0100

        chore(deps): Bump github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25 (#359)

        Bumps github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25.

        Release notes
        Sourced from github.com/lestrrat-go/jwx's releases.

        v1.2.25
        v1.2.25 23 May 2022
        [Bug Fixes][Security]
          * [jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
            where the unpad operation might remove more bytes than necessary ([#744](lestrrat-go/jwx#744))
            This affects all jwx code that is available before v2.0.2 and v1.2.25.

        v1.2.24
        v1.2.24 05 May 2022
        [Security]
          * Upgrade golang.org/x/crypto ([#724](lestrrat-go/jwx#724))

        v1.2.23
        v1.2.23 13 Apr 2022
        [Bug fixes]
          * [jwk] jwk.AutoRefresh had a race condition when `Configure()` was
            called concurrently ([#686](lestrrat-go/jwx#686))
            (It has been patched correctly, but we may come back to revisit
             the design choices in the near future)

        v1.2.22
        v1.2.22 08 Apr 2022
        [Bug fixes]
          * [jws] jws.Verify was ignoring the `b64` header when it was present
            in the protected headers ([#681](lestrrat-go/jwx#681)). Now the following should work:
          jws.Sign(..., jws.WithDetachedPayload(payload))
          // previously payload had to be base64 encoded
          jws.Verify(..., jws.WithDetachedPayload(payload))
        (note: v2 branch was not affected)

        v1.2.21
        v1.2.21 30 Mar 2022
        [Bug fixes]
          * [jwk] RSA keys without p and q can now be parsed.

        Changelog
        Sourced from github.com/lestrrat-go/jwx's changelog.

        v1.2.25 23 May 2022
        [Bug Fixes][Security]

        [jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
        where the unpad operation might remove more bytes than necessary (#744)
        This affects all jwx code that is available before v2.0.2 and v1.2.25.

        v1.2.24 05 May 2022
        [Security]

        Upgrade golang.org/x/crypto (#724)

        v1.2.23 13 Apr 2022
        [Bug fixes]

        [jwk] jwk.AutoRefresh had a race condition when Configure() was
        called concurrently (#686)
        (It has been patched correctly, but we may come back to revisit
        the design choices in the near future)

        v1.2.22 08 Apr 2022
        [Bug fixes]

        [jws] jws.Verify was ignoring the b64 header when it was present
        in the protected headers (#681). Now the following should work:
        jws.Sign(..., jws.WithDetachedPayload(payload))
        // previously payload had to be base64 encoded
        jws.Verify(..., jws.WithDetachedPayload(payload))
        (note: v2 branch was not affected)

        v1.2.21 30 Mar 2022
        [Bug fixes]

        [jwk] RSA keys without p and q can now be parsed.

        Commits

        ad8c29d merge develop/v1 (#747)
        e38f677 Merge develop/v1 (#727)
        baba561 Merge branch 'develop/v1' into v1
        8ff6c75 Update Changes
        ea97e8c Fix race in jwk.AutoRefresh (#686)
        f4701e1 Update Changes
        e831228 Fix jws.Verify not respecting the b64 header in the protected headers (#683)
        b66a2cb backport: Update golangci lint (#679) (#680)
        4899c32 reword error
        dd9e4c4 Bump github.com/lestrrat-go/httpcc from 1.0.0 to 1.0.1 (#675)
        Additional commits viewable in compare view

        Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

        Dependabot commands and options

        You can trigger Dependabot actions by commenting on this PR:

        @dependabot rebase will rebase this PR
        @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
        @dependabot merge will merge this PR after your CI passes on it
        @dependabot squash and merge will squash and merge this PR after your CI passes on it
        @dependabot cancel merge will cancel a previously requested merge and block automerging
        @dependabot reopen will reopen this PR if it is closed
        @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
        @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

        Signed-off-by: dependabot[bot] <[email protected]>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
        Co-authored-by: Ankur Banerjee <[email protected]>

    commit a56cfeb
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Mon Aug 15 14:50:56 2022 +0100

        chore(deps): Bump github.com/spf13/viper from 1.10.1 to 1.12.0 (#360)

        Bumps github.com/spf13/viper from 1.10.1 to 1.12.0.

        Release notes
        Sourced from github.com/spf13/viper's releases.

        v1.12.0
        This release makes YAML v3 and TOML v2 the default versions used for encoding.
        You can switch back to the old versions by adding viper_yaml2 and viper_toml1 to the build tags.
        Please note that YAML v2 and TOML v1 are considered deprecated from this release and may be removed in a future release.
        Please provide feedback in discussions and report bugs on the issue tracker. Thanks!

        What's Changed
        Exciting New Features 🎉

        Add etcd3 support to remote by @​sagikazarmark in spf13/viper#1356
        Make YAML 3 the default by @​sagikazarmark in spf13/viper#1357
        Make TOML 2 the default by @​sagikazarmark in spf13/viper#1358

        Enhancements 🚀

        chore: fix Error log calls in mergeMaps by @​wwade in spf13/viper#1341
        Add MustBindEnv by @​meowfaceman in spf13/viper#1301

        Dependency Updates ⬆️

        build(deps): bump github/codeql-action from 1 to 2 by @​dependabot in spf13/viper#1336
        build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0-beta.8 to 2.0.0 by @​dependabot in spf13/viper#1339
        build(deps): bump github.com/mitchellh/mapstructure from 1.4.3 to 1.5.0 by @​dependabot in spf13/viper#1332
        build(deps): bump github.com/pelletier/go-toml from 1.9.4 to 1.9.5 by @​dependabot in spf13/viper#1335
        build(deps): bump github.com/fsnotify/fsnotify from 1.5.1 to 1.5.4 by @​dependabot in spf13/viper#1338
        build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0 by @​dependabot in spf13/viper#1344
        build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1 by @​dependabot in spf13/viper#1343
        build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0 by @​dependabot in spf13/viper#1349

        New Contributors

        @​meowfaceman made their first contribution in spf13/viper#1301
        @​wwade made their first contribution in spf13/viper#1341

        Full Changelog: spf13/[email protected]
        v1.11.0

        What's Changed
        Exciting New Features 🎉

        Experimental yaml v3 library support by @​sagikazarmark in spf13/viper#1273
        Experimental toml v2 support by @​sagikazarmark in spf13/viper#1274
        Experimental logger by @​sagikazarmark in spf13/viper#1275

        Enhancements 🚀

        Remove unnecessary operand by @​steviebps in spf13/viper#1213
        Improve encoding layer by @​sagikazarmark in spf13/viper#1167
        Allow merging configs with different types of leaf values by @​illarion in spf13/viper#1181

        Bug Fixes 🐛

        Disable race detector on windows by @​sagikazarmark in spf13/viper#1269

        ... (truncated)

        Commits

        4322cf2 feat: make toml2 the default
        8d02999 feat: make yaml3 the default
        7c35aa9 chore(deps): update yaml3
        433821f feat: add etcd3 support to remote
        2080d43 chore: update crypt
        da55858 chore: fix Error log calls in mergeMaps
        f50ce90 Add in MustBindEnv.
        3b836e5 build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0
        5d65186 build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1
        9f85518 build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0
        Additional commits viewable in compare view

        Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

        Dependabot commands and options

        You can trigger Dependabot actions by commenting on this PR:

        @dependabot rebase will rebase this PR
        @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
        @dependabot merge will merge this PR after your CI passes on it
        @dependabot squash and merge will squash and merge this PR after your CI passes on it
        @dependabot cancel merge will cancel a previously requested merge and block automerging
        @dependabot reopen will reopen this PR if it is closed
        @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
        @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

        Signed-off-by: dependabot[bot] <[email protected]>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
        Co-authored-by: Ankur Banerjee <[email protected]>

    commit a5aef25
    Author: Ankur Banerjee <[email protected]>
    Date:   Mon Aug 15 10:44:13 2022 +0100

        build: Optimise Docker build (#365)

    commit 4517a19
    Author: Andrew Nikitin <[email protected]>
    Date:   Sat Aug 13 03:55:47 2022 +0300

        ci: Add automated semantic release using Goreleaser (#357)

        Co-authored-by: Ankur Banerjee <[email protected]>

    commit 5a30740
    Author: Ankur Banerjee <[email protected]>
    Date:   Sat Aug 13 01:53:06 2022 +0100

        ci: Disable cleanup dry-run

    commit 3e8aea4
    Author: Ankur Banerjee <[email protected]>
    Date:   Sat Aug 13 01:42:43 2022 +0100

        ci: Fix linting error

    commit c335aba
    Author: Ankur Banerjee <[email protected]>
    Date:   Sat Aug 13 01:38:00 2022 +0100

        ci: Make workflow cleanup choices easier

    commit d89f496
    Author: Ankur Banerjee <[email protected]>
    Date:   Sat Aug 13 01:29:14 2022 +0100

        ci: Cleanup old workflow runs (#364)

commit ed9b26f
Author: Ankur Banerjee <[email protected]>
Date:   Tue Aug 16 17:02:09 2022 +0100

    Squashed commit of the following:

    commit 2fc6ae5
    Author: Andrew Nikitin <[email protected]>
    Date:   Tue Aug 16 15:48:13 2022 +0300

        build: Multi-platform AMD64/ARM64 for Linux (#366)

        Signed-off-by: Andrew Nikitin <[email protected]>
        Co-authored-by: Ankur Banerjee <[email protected]>

    commit 7485eb2
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Mon Aug 15 15:37:31 2022 +0100

        chore(deps): Bump github.com/stretchr/testify from 1.7.1 to 1.8.0 (#362)

        Bumps github.com/stretchr/testify from 1.7.1 to 1.8.0.

        Commits

        181cea6 impr: CallerInfo should print full paths to the terminal (#1201)
        cf1284f Allow mock expectations to be ordered (#1106)
        66eef0e fix: assert.MapSubset (or just support maps in assert.Subset) (#1178)
        2fab6df Add WithinTimeRange method (#1188)
        b5ce165 fixing panic in calls to assertion with nil m.mutex (#1212)
        c206b2e Mock can be deadlocked by a panic (#1157)
        1b73601 suite: correctly set stats on test panic (#1195)
        ba1076d Add .Unset method to mock (#982)
        c31ea03 Support comparing byte slice (#1202)
        48391ba Fix panic in AssertExpectations for mocks without expectations (#1207)
        Additional commits viewable in compare view

        Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

        Dependabot commands and options

        You can trigger Dependabot actions by commenting on this PR:

        @dependabot rebase will rebase this PR
        @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
        @dependabot merge will merge this PR after your CI passes on it
        @dependabot squash and merge will squash and merge this PR after your CI passes on it
        @dependabot cancel merge will cancel a previously requested merge and block automerging
        @dependabot reopen will reopen this PR if it is closed
        @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
        @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

        Signed-off-by: dependabot[bot] <[email protected]>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
        Co-authored-by: Ankur Banerjee <[email protected]>

    commit 1e3e807
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Mon Aug 15 15:14:40 2022 +0100

        chore(deps): Bump github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25 (#359)

        Bumps github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25.

        Release notes
        Sourced from github.com/lestrrat-go/jwx's releases.

        v1.2.25
        v1.2.25 23 May 2022
        [Bug Fixes][Security]
          * [jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
            where the unpad operation might remove more bytes than necessary ([#744](lestrrat-go/jwx#744))
            This affects all jwx code that is available before v2.0.2 and v1.2.25.

        v1.2.24
        v1.2.24 05 May 2022
        [Security]
          * Upgrade golang.org/x/crypto ([#724](lestrrat-go/jwx#724))

        v1.2.23
        v1.2.23 13 Apr 2022
        [Bug fixes]
          * [jwk] jwk.AutoRefresh had a race condition when `Configure()` was
            called concurrently ([#686](lestrrat-go/jwx#686))
            (It has been patched correctly, but we may come back to revisit
             the design choices in the near future)

        v1.2.22
        v1.2.22 08 Apr 2022
        [Bug fixes]
          * [jws] jws.Verify was ignoring the `b64` header when it was present
            in the protected headers ([#681](lestrrat-go/jwx#681)). Now the following should work:
          jws.Sign(..., jws.WithDetachedPayload(payload))
          // previously payload had to be base64 encoded
          jws.Verify(..., jws.WithDetachedPayload(payload))
        (note: v2 branch was not affected)

        v1.2.21
        v1.2.21 30 Mar 2022
        [Bug fixes]
          * [jwk] RSA keys without p and q can now be parsed.

        Changelog
        Sourced from github.com/lestrrat-go/jwx's changelog.

        v1.2.25 23 May 2022
        [Bug Fixes][Security]

        [jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
        where the unpad operation might remove more bytes than necessary (#744)
        This affects all jwx code that is available before v2.0.2 and v1.2.25.

        v1.2.24 05 May 2022
        [Security]

        Upgrade golang.org/x/crypto (#724)

        v1.2.23 13 Apr 2022
        [Bug fixes]

        [jwk] jwk.AutoRefresh had a race condition when Configure() was
        called concurrently (#686)
        (It has been patched correctly, but we may come back to revisit
        the design choices in the near future)

        v1.2.22 08 Apr 2022
        [Bug fixes]

        [jws] jws.Verify was ignoring the b64 header when it was present
        in the protected headers (#681). Now the following should work:
        jws.Sign(..., jws.WithDetachedPayload(payload))
        // previously payload had to be base64 encoded
        jws.Verify(..., jws.WithDetachedPayload(payload))
        (note: v2 branch was not affected)

        v1.2.21 30 Mar 2022
        [Bug fixes]

        [jwk] RSA keys without p and q can now be parsed.

        Commits

        ad8c29d merge develop/v1 (#747)
        e38f677 Merge develop/v1 (#727)
        baba561 Merge branch 'develop/v1' into v1
        8ff6c75 Update Changes
        ea97e8c Fix race in jwk.AutoRefresh (#686)
        f4701e1 Update Changes
        e831228 Fix jws.Verify not respecting the b64 header in the protected headers (#683)
        b66a2cb backport: Update golangci lint (#679) (#680)
        4899c32 reword error
        dd9e4c4 Bump github.com/lestrrat-go/httpcc from 1.0.0 to 1.0.1 (#675)
        Additional commits viewable in compare view

        Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

        Dependabot commands and options

        You can trigger Dependabot actions by commenting on this PR:

        @dependabot rebase will rebase this PR
        @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
        @dependabot merge will merge this PR after your CI passes on it
        @dependabot squash and merge will squash and merge this PR after your CI passes on it
        @dependabot cancel merge will cancel a previously requested merge and block automerging
        @dependabot reopen will reopen this PR if it is closed
        @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
        @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

        Signed-off-by: dependabot[bot] <[email protected]>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
        Co-authored-by: Ankur Banerjee <[email protected]>

    commit a56cfeb
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Mon Aug 15 14:50:56 2022 +0100

        chore(deps): Bump github.com/spf13/viper from 1.10.1 to 1.12.0 (#360)

        Bumps github.com/spf13/viper from 1.10.1 to 1.12.0.

        Release notes
        Sourced from github.com/spf13/viper's releases.

        v1.12.0
        This release makes YAML v3 and TOML v2 the default versions used for encoding.
        You can switch back to the old versions by adding viper_yaml2 and viper_toml1 to the build tags.
        Please note that YAML v2 and TOML v1 are considered deprecated from this release and may be removed in a future release.
        Please provide feedback in discussions and report bugs on the issue tracker. Thanks!

        What's Changed
        Exciting New Features 🎉

        Add etcd3 support to remote by @​sagikazarmark in spf13/viper#1356
        Make YAML 3 the default by @​sagikazarmark in spf13/viper#1357
        Make TOML 2 the default by @​sagikazarmark in spf13/viper#1358

        Enhancements 🚀

        chore: fix Error log calls in mergeMaps by @​wwade in spf13/viper#1341
        Add MustBindEnv by @​meowfaceman in spf13/viper#1301

        Dependency Updates ⬆️

        build(deps): bump github/codeql-action from 1 to 2 by @​dependabot in spf13/viper#1336
        build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0-beta.8 to 2.0.0 by @​dependabot in spf13/viper#1339
        build(deps): bump github.com/mitchellh/mapstructure from 1.4.3 to 1.5.0 by @​dependabot in spf13/viper#1332
        build(deps): bump github.com/pelletier/go-toml from 1.9.4 to 1.9.5 by @​dependabot in spf13/viper#1335
        build(deps): bump github.com/fsnotify/fsnotify from 1.5.1 to 1.5.4 by @​dependabot in spf13/viper#1338
        build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0 by @​dependabot in spf13/viper#1344
        build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1 by @​dependabot in spf13/viper#1343
        build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0 by @​dependabot in spf13/viper#1349

        New Contributors

        @​meowfaceman made their first contribution in spf13/viper#1301
        @​wwade made their first contribution in spf13/viper#1341

        Full Changelog: spf13/[email protected]
        v1.11.0

        What's Changed
        Exciting New Features 🎉

        Experimental yaml v3 library support by @​sagikazarmark in spf13/viper#1273
        Experimental toml v2 support by @​sagikazarmark in spf13/viper#1274
        Experimental logger by @​sagikazarmark in spf13/viper#1275

        Enhancements 🚀

        Remove unnecessary operand by @​steviebps in spf13/viper#1213
        Improve encoding layer by @​sagikazarmark in spf13/viper#1167
        Allow merging configs with different types of leaf values by @​illarion in spf13/viper#1181

        Bug Fixes 🐛

        Disable race detector on windows by @​sagikazarmark in spf13/viper#1269

        ... (truncated)

        Commits

        4322cf2 feat: make toml2 the default
        8d02999 feat: make yaml3 the default
        7c35aa9 chore(deps): update yaml3
        433821f feat: add etcd3 support to remote
        2080d43 chore: update crypt
        da55858 chore: fix Error log calls in mergeMaps
        f50ce90 Add in MustBindEnv.
        3b836e5 build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0
        5d65186 build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1
        9f85518 build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0
        Additional commits viewable in compare view

        Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

        Dependabot commands and options

        You can trigger Dependabot actions by commenting on this PR:

        @dependabot rebase will rebase this PR
        @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
        @dependabot merge will merge this PR after your CI passes on it
        @dependabot squash and merge will squash and merge this PR after your CI passes on it
        @dependabot cancel merge will cancel a previously requested merge and block automerging
        @dependabot reopen will reopen this PR if it is closed
        @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
        @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

        Signed-off-by: dependabot[bot] <[email protected]>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
        Co-authored-by: Ankur Banerjee <[email protected]>

    commit a5aef25
    Author: Ankur Banerjee <[email protected]>
    Date:   Mon Aug 15 10:44:13 2022 +0100

        build: Optimise Docker build (#365)

    commit 4517a19
    Author: Andrew Nikitin <[email protected]>
    Date:   Sat Aug 13 03:55:47 2022 +0300

        ci: Add automated semantic release using Goreleaser (#357)

        Co-authored-by: Ankur Banerjee <[email protected]>

    commit 5a30740
    Author: Ankur Banerjee <[email protected]>
    Date:   Sat Aug 13 01:53:06 2022 +0100

        ci: Disable cleanup dry-run

    commit 3e8aea4
    Author: Ankur Banerjee <[email protected]>
    Date:   Sat Aug 13 01:42:43 2022 +0100

        ci: Fix linting error

    commit c335aba
    Author: Ankur Banerjee <[email protected]>
    Date:   Sat Aug 13 01:38:00 2022 +0100

        ci: Make workflow cleanup choices easier

    commit d89f496
    Author: Ankur Banerjee <[email protected]>
    Date:   Sat Aug 13 01:29:14 2022 +0100

        ci: Cleanup old workflow runs (#364)
ankurdotb added a commit that referenced this pull request Oct 14, 2022
….19 to 0.34.20 (#367)

* ci: Cleanup old workflow runs (#364)

* ci: Make workflow cleanup choices easier

* ci: Fix linting error

* ci: Disable cleanup dry-run

* ci: Add automated semantic release using Goreleaser (#357)

Co-authored-by: Ankur Banerjee <[email protected]>

* build: Optimise Docker build (#365)

* chore(deps): Bump github.com/spf13/viper from 1.10.1 to 1.12.0 (#360)

Bumps github.com/spf13/viper from 1.10.1 to 1.12.0.

Release notes
Sourced from github.com/spf13/viper's releases.

v1.12.0
This release makes YAML v3 and TOML v2 the default versions used for encoding.
You can switch back to the old versions by adding viper_yaml2 and viper_toml1 to the build tags.
Please note that YAML v2 and TOML v1 are considered deprecated from this release and may be removed in a future release.
Please provide feedback in discussions and report bugs on the issue tracker. Thanks!

What's Changed
Exciting New Features 🎉

Add etcd3 support to remote by @​sagikazarmark in spf13/viper#1356
Make YAML 3 the default by @​sagikazarmark in spf13/viper#1357
Make TOML 2 the default by @​sagikazarmark in spf13/viper#1358

Enhancements 🚀

chore: fix Error log calls in mergeMaps by @​wwade in spf13/viper#1341
Add MustBindEnv by @​meowfaceman in spf13/viper#1301

Dependency Updates ⬆️

build(deps): bump github/codeql-action from 1 to 2 by @​dependabot in spf13/viper#1336
build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0-beta.8 to 2.0.0 by @​dependabot in spf13/viper#1339
build(deps): bump github.com/mitchellh/mapstructure from 1.4.3 to 1.5.0 by @​dependabot in spf13/viper#1332
build(deps): bump github.com/pelletier/go-toml from 1.9.4 to 1.9.5 by @​dependabot in spf13/viper#1335
build(deps): bump github.com/fsnotify/fsnotify from 1.5.1 to 1.5.4 by @​dependabot in spf13/viper#1338
build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0 by @​dependabot in spf13/viper#1344
build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1 by @​dependabot in spf13/viper#1343
build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0 by @​dependabot in spf13/viper#1349

New Contributors

@​meowfaceman made their first contribution in spf13/viper#1301
@​wwade made their first contribution in spf13/viper#1341

Full Changelog: spf13/[email protected]
v1.11.0

What's Changed
Exciting New Features 🎉

Experimental yaml v3 library support by @​sagikazarmark in spf13/viper#1273
Experimental toml v2 support by @​sagikazarmark in spf13/viper#1274
Experimental logger by @​sagikazarmark in spf13/viper#1275

Enhancements 🚀

Remove unnecessary operand by @​steviebps in spf13/viper#1213
Improve encoding layer by @​sagikazarmark in spf13/viper#1167
Allow merging configs with different types of leaf values by @​illarion in spf13/viper#1181

Bug Fixes 🐛

Disable race detector on windows by @​sagikazarmark in spf13/viper#1269



... (truncated)


Commits

4322cf2 feat: make toml2 the default
8d02999 feat: make yaml3 the default
7c35aa9 chore(deps): update yaml3
433821f feat: add etcd3 support to remote
2080d43 chore: update crypt
da55858 chore: fix Error log calls in mergeMaps
f50ce90 Add in MustBindEnv.
3b836e5 build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0
5d65186 build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1
9f85518 build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0
Additional commits viewable in compare view




Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Ankur Banerjee <[email protected]>

* chore(deps): Bump github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25 (#359)

Bumps github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25.

Release notes
Sourced from github.com/lestrrat-go/jwx's releases.

v1.2.25
v1.2.25 23 May 2022
[Bug Fixes][Security]
  * [jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
    where the unpad operation might remove more bytes than necessary ([#744](lestrrat-go/jwx#744))
    This affects all jwx code that is available before v2.0.2 and v1.2.25.

v1.2.24
v1.2.24 05 May 2022
[Security]
  * Upgrade golang.org/x/crypto ([#724](lestrrat-go/jwx#724))

v1.2.23
v1.2.23 13 Apr 2022
[Bug fixes]
  * [jwk] jwk.AutoRefresh had a race condition when `Configure()` was
    called concurrently ([#686](lestrrat-go/jwx#686))
    (It has been patched correctly, but we may come back to revisit
     the design choices in the near future)

v1.2.22
v1.2.22 08 Apr 2022
[Bug fixes]
  * [jws] jws.Verify was ignoring the `b64` header when it was present
    in the protected headers ([#681](lestrrat-go/jwx#681)). Now the following should work:
  jws.Sign(..., jws.WithDetachedPayload(payload))
  // previously payload had to be base64 encoded
  jws.Verify(..., jws.WithDetachedPayload(payload))
(note: v2 branch was not affected)


v1.2.21
v1.2.21 30 Mar 2022
[Bug fixes]
  * [jwk] RSA keys without p and q can now be parsed.




Changelog
Sourced from github.com/lestrrat-go/jwx's changelog.

v1.2.25 23 May 2022
[Bug Fixes][Security]

[jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
where the unpad operation might remove more bytes than necessary (#744)
This affects all jwx code that is available before v2.0.2 and v1.2.25.

v1.2.24 05 May 2022
[Security]

Upgrade golang.org/x/crypto (#724)

v1.2.23 13 Apr 2022
[Bug fixes]

[jwk] jwk.AutoRefresh had a race condition when Configure() was
called concurrently (#686)
(It has been patched correctly, but we may come back to revisit
the design choices in the near future)

v1.2.22 08 Apr 2022
[Bug fixes]


[jws] jws.Verify was ignoring the b64 header when it was present
in the protected headers (#681). Now the following should work:
jws.Sign(..., jws.WithDetachedPayload(payload))
// previously payload had to be base64 encoded
jws.Verify(..., jws.WithDetachedPayload(payload))
(note: v2 branch was not affected)


v1.2.21 30 Mar 2022
[Bug fixes]

[jwk] RSA keys without p and q can now be parsed.




Commits

ad8c29d merge develop/v1 (#747)
e38f677 Merge develop/v1 (#727)
baba561 Merge branch 'develop/v1' into v1
8ff6c75 Update Changes
ea97e8c Fix race in jwk.AutoRefresh (#686)
f4701e1 Update Changes
e831228 Fix jws.Verify not respecting the b64 header in the protected headers (#683)
b66a2cb backport: Update golangci lint (#679) (#680)
4899c32 reword error
dd9e4c4 Bump github.com/lestrrat-go/httpcc from 1.0.0 to 1.0.1 (#675)
Additional commits viewable in compare view




Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Ankur Banerjee <[email protected]>

* chore(deps): Bump github.com/stretchr/testify from 1.7.1 to 1.8.0 (#362)

Bumps github.com/stretchr/testify from 1.7.1 to 1.8.0.

Commits

181cea6 impr: CallerInfo should print full paths to the terminal (#1201)
cf1284f Allow mock expectations to be ordered (#1106)
66eef0e fix: assert.MapSubset (or just support maps in assert.Subset) (#1178)
2fab6df Add WithinTimeRange method (#1188)
b5ce165 fixing panic in calls to assertion with nil m.mutex (#1212)
c206b2e Mock can be deadlocked by a panic (#1157)
1b73601 suite: correctly set stats on test panic (#1195)
ba1076d Add .Unset method to mock (#982)
c31ea03 Support comparing byte slice (#1202)
48391ba Fix panic in AssertExpectations for mocks without expectations (#1207)
Additional commits viewable in compare view




Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Ankur Banerjee <[email protected]>

* build: Multi-platform AMD64/ARM64 for Linux (#366)

Signed-off-by: Andrew Nikitin <[email protected]>
Co-authored-by: Ankur Banerjee <[email protected]>

* ci: Fix CodeQL Golang version

* chore(deps): Bump github.com/multiformats/go-multibase from 0.0.3 to 0.1.1 (#371)

* chore(deps): Bump github.com/multiformats/go-multibase

Bumps [github.com/multiformats/go-multibase](https://github.com/multiformats/go-multibase) from 0.0.3 to 0.1.1.
- [Release notes](https://github.com/multiformats/go-multibase/releases)
- [Commits](multiformats/go-multibase@v0.0.3...v0.1.1)

---
updated-dependencies:
- dependency-name: github.com/multiformats/go-multibase
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>

* chore(deps): Bump github.com/multiformats/go-multibase

Bumps [github.com/multiformats/go-multibase](https://github.com/multiformats/go-multibase) from 0.0.3 to 0.1.1.
- [Release notes](https://github.com/multiformats/go-multibase/releases)
- [Commits](multiformats/go-multibase@v0.0.3...v0.1.1)

---
updated-dependencies:
- dependency-name: github.com/multiformats/go-multibase
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Ankur Banerjee <[email protected]>

* chore(deps): Bump github.com/gabriel-vasile/mimetype from 1.4.0 to 1.4.1 (#370)

Bumps [github.com/gabriel-vasile/mimetype](https://github.com/gabriel-vasile/mimetype) from 1.4.0 to 1.4.1.
- [Release notes](https://github.com/gabriel-vasile/mimetype/releases)
- [Commits](gabriel-vasile/mimetype@v1.4.0...v1.4.1)

---
updated-dependencies:
- dependency-name: github.com/gabriel-vasile/mimetype
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): Bump github.com/tendermint/tendermint

Bumps [github.com/tendermint/tendermint](https://github.com/tendermint/tendermint) from 0.34.19 to 0.34.20.
- [Release notes](https://github.com/tendermint/tendermint/releases)
- [Changelog](https://github.com/tendermint/tendermint/blob/main/CHANGELOG.md)
- [Commits](tendermint/tendermint@v0.34.19...v0.34.20)

---
updated-dependencies:
- dependency-name: github.com/tendermint/tendermint
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>

Signed-off-by: dependabot[bot] <[email protected]>
Signed-off-by: Andrew Nikitin <[email protected]>
Co-authored-by: Ankur Banerjee <[email protected]>
Co-authored-by: Andrew Nikitin <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file go Pull requests that update Go code
Development

Successfully merging this pull request may close these issues.

1 participant