更新数据#1
Open
yinchongbing wants to merge 4588 commits into
Open
Conversation
Bumps software.amazon.awssdk:sts from 2.42.9 to 2.42.11. --- updated-dependencies: - dependency-name: software.amazon.awssdk:sts dependency-version: 2.42.11 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…mockito-mockito-junit-jupiter-5.23.0 build(deps): bump org.mockito:mockito-junit-jupiter from 5.22.0 to 5.23.0
…ware.amazon.awssdk-sts-2.42.11 build(deps): bump software.amazon.awssdk:sts from 2.42.9 to 2.42.11
Fix release failure after maven central plugin migration
Bumps [org.apache.maven.plugins:maven-javadoc-plugin](https://github.com/apache/maven-javadoc-plugin) from 3.11.3 to 3.12.0. - [Release notes](https://github.com/apache/maven-javadoc-plugin/releases) - [Commits](apache/maven-javadoc-plugin@maven-javadoc-plugin-3.11.3...maven-javadoc-plugin-3.12.0) --- updated-dependencies: - dependency-name: org.apache.maven.plugins:maven-javadoc-plugin dependency-version: 3.12.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps software.amazon.awssdk:sts from 2.42.11 to 2.42.13. --- updated-dependencies: - dependency-name: software.amazon.awssdk:sts dependency-version: 2.42.13 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…apache.maven.plugins-maven-javadoc-plugin-3.12.0 build(deps): bump org.apache.maven.plugins:maven-javadoc-plugin from 3.11.3 to 3.12.0
…ware.amazon.awssdk-sts-2.42.13 build(deps): bump software.amazon.awssdk:sts from 2.42.11 to 2.42.13
Bumps software.amazon.awssdk:sts from 2.42.13 to 2.42.14. --- updated-dependencies: - dependency-name: software.amazon.awssdk:sts dependency-version: 2.42.14 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…ware.amazon.awssdk-sts-2.42.14 build(deps): bump software.amazon.awssdk:sts from 2.42.13 to 2.42.14
Bumps software.amazon.awssdk:sts from 2.42.14 to 2.42.15. --- updated-dependencies: - dependency-name: software.amazon.awssdk:sts dependency-version: 2.42.15 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…ware.amazon.awssdk-sts-2.42.15 build(deps): bump software.amazon.awssdk:sts from 2.42.14 to 2.42.15
Bumps [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) from 3.3.0 to 3.4.0. - [Release notes](https://github.com/diffplug/spotless/releases) - [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md) - [Commits](diffplug/spotless@lib/3.3.0...maven/3.4.0) --- updated-dependencies: - dependency-name: com.diffplug.spotless:spotless-maven-plugin dependency-version: 3.4.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps software.amazon.awssdk:sts from 2.42.15 to 2.42.16. --- updated-dependencies: - dependency-name: software.amazon.awssdk:sts dependency-version: 2.42.16 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…diffplug.spotless-spotless-maven-plugin-3.4.0 build(deps): bump com.diffplug.spotless:spotless-maven-plugin from 3.3.0 to 3.4.0
…ware.amazon.awssdk-sts-2.42.16 build(deps): bump software.amazon.awssdk:sts from 2.42.15 to 2.42.16
Bumps `spring.boot.version` from 4.0.3 to 4.0.4. Updates `org.springframework.boot:spring-boot` from 4.0.3 to 4.0.4 - [Release notes](https://github.com/spring-projects/spring-boot/releases) - [Commits](spring-projects/spring-boot@v4.0.3...v4.0.4) Updates `org.springframework.boot:spring-boot-autoconfigure` from 4.0.3 to 4.0.4 - [Release notes](https://github.com/spring-projects/spring-boot/releases) - [Commits](spring-projects/spring-boot@v4.0.3...v4.0.4) Updates `org.springframework.boot:spring-boot-actuator` from 4.0.3 to 4.0.4 - [Release notes](https://github.com/spring-projects/spring-boot/releases) - [Commits](spring-projects/spring-boot@v4.0.3...v4.0.4) Updates `org.springframework.boot:spring-boot-test` from 4.0.3 to 4.0.4 - [Release notes](https://github.com/spring-projects/spring-boot/releases) - [Commits](spring-projects/spring-boot@v4.0.3...v4.0.4) --- updated-dependencies: - dependency-name: org.springframework.boot:spring-boot dependency-version: 4.0.4 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: org.springframework.boot:spring-boot-autoconfigure dependency-version: 4.0.4 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: org.springframework.boot:spring-boot-actuator dependency-version: 4.0.4 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: org.springframework.boot:spring-boot-test dependency-version: 4.0.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps software.amazon.awssdk:sts from 2.42.16 to 2.42.18. --- updated-dependencies: - dependency-name: software.amazon.awssdk:sts dependency-version: 2.42.18 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps [com.google.protobuf:protobuf-java](https://github.com/protocolbuffers/protobuf) from 4.34.0 to 4.34.1. - [Release notes](https://github.com/protocolbuffers/protobuf/releases) - [Commits](https://github.com/protocolbuffers/protobuf/commits) --- updated-dependencies: - dependency-name: com.google.protobuf:protobuf-java dependency-version: 4.34.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps `jackson.version` from 2.21.1 to 2.21.2. Updates `com.fasterxml.jackson.core:jackson-databind` from 2.21.1 to 2.21.2 - [Commits](https://github.com/FasterXML/jackson/commits) Updates `com.fasterxml.jackson.core:jackson-core` from 2.21.1 to 2.21.2 - [Commits](FasterXML/jackson-core@jackson-core-2.21.1...jackson-core-2.21.2) --- updated-dependencies: - dependency-name: com.fasterxml.jackson.core:jackson-databind dependency-version: 2.21.2 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: com.fasterxml.jackson.core:jackson-core dependency-version: 2.21.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…ng.boot.version-4.0.4 build(deps): bump spring.boot.version from 4.0.3 to 4.0.4
…ware.amazon.awssdk-sts-2.42.18 build(deps): bump software.amazon.awssdk:sts from 2.42.16 to 2.42.18
…google.protobuf-protobuf-java-4.34.1 build(deps): bump com.google.protobuf:protobuf-java from 4.34.0 to 4.34.1
…son.version-2.21.2 build(deps): bump jackson.version from 2.21.1 to 2.21.2
Bumps software.amazon.awssdk:sts from 2.42.18 to 2.42.19. --- updated-dependencies: - dependency-name: software.amazon.awssdk:sts dependency-version: 2.42.19 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…ware.amazon.awssdk-sts-2.42.19 build(deps): bump software.amazon.awssdk:sts from 2.42.18 to 2.42.19
Bumps software.amazon.awssdk:sts from 2.42.19 to 2.42.20. --- updated-dependencies: - dependency-name: software.amazon.awssdk:sts dependency-version: 2.42.20 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…ware.amazon.awssdk-sts-2.42.20 build(deps): bump software.amazon.awssdk:sts from 2.42.19 to 2.42.20
Bumps software.amazon.awssdk:sts from 2.42.20 to 2.42.21. --- updated-dependencies: - dependency-name: software.amazon.awssdk:sts dependency-version: 2.42.21 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…ware.amazon.awssdk-sts-2.42.21 build(deps): bump software.amazon.awssdk:sts from 2.42.20 to 2.42.21
Bumps `spring.version` from 6.2.8 to 7.0.7. Updates `org.springframework:spring-core` from 6.2.8 to 7.0.7 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v6.2.8...v7.0.7) Updates `org.springframework:spring-aop` from 6.2.8 to 7.0.7 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v6.2.8...v7.0.7) Updates `org.springframework:spring-beans` from 6.2.8 to 7.0.7 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v6.2.8...v7.0.7) Updates `org.springframework:spring-context` from 6.2.8 to 7.0.7 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v6.2.8...v7.0.7) Updates `org.springframework:spring-expression` from 6.2.8 to 7.0.7 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v6.2.8...v7.0.7) Updates `org.springframework:spring-test` from 6.2.8 to 7.0.7 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v6.2.8...v7.0.7) --- updated-dependencies: - dependency-name: org.springframework:spring-aop dependency-version: 7.0.7 dependency-type: direct:production update-type: version-update:semver-major - dependency-name: org.springframework:spring-beans dependency-version: 7.0.7 dependency-type: direct:production update-type: version-update:semver-major - dependency-name: org.springframework:spring-context dependency-version: 7.0.7 dependency-type: direct:production update-type: version-update:semver-major - dependency-name: org.springframework:spring-core dependency-version: 7.0.7 dependency-type: direct:production update-type: version-update:semver-major - dependency-name: org.springframework:spring-expression dependency-version: 7.0.7 dependency-type: direct:production update-type: version-update:semver-major - dependency-name: org.springframework:spring-test dependency-version: 7.0.7 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]>
…dependencies Add Dependabot Bazel sync automation with manual backfill for existing PRs
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.35.5 to 4.36.0. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@9e0d7b8...7211b7c) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.36.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
…ions/github/codeql-action-4.36.0 build(deps): bump github/codeql-action from 4.35.5 to 4.36.0
fix: refresh EKS authentication token per request
…-dependabot-prs Fix failing GitHub Actions job sync-open-dependabot-prs
fix: generate valid EKS authentication token payload
…ng.version-7.0.7 build(deps): bump spring.version from 6.2.8 to 7.0.7
Bumps [com.google.protobuf:protobuf-java](https://github.com/protocolbuffers/protobuf) from 4.34.1 to 4.35.0. - [Release notes](https://github.com/protocolbuffers/protobuf/releases) - [Commits](https://github.com/protocolbuffers/protobuf/commits) --- updated-dependencies: - dependency-name: com.google.protobuf:protobuf-java dependency-version: 4.35.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@de0fac2...df4cb1c) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 6.0.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.0 to 4.36.1. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@7211b7c...87557b9) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.36.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…google.protobuf-protobuf-java-4.35.0 build(deps): bump com.google.protobuf:protobuf-java from 4.34.1 to 4.35.0
…ions/actions/checkout-6.0.3 build(deps): bump actions/checkout from 6.0.2 to 6.0.3
…ions/github/codeql-action-4.36.1 build(deps): bump github/codeql-action from 4.36.0 to 4.36.1
Bumps [graalvm/setup-graalvm](https://github.com/graalvm/setup-graalvm) from 1.5.3 to 1.5.4. - [Release notes](https://github.com/graalvm/setup-graalvm/releases) - [Commits](graalvm/setup-graalvm@bef4b0e...329c42c) --- updated-dependencies: - dependency-name: graalvm/setup-graalvm dependency-version: 1.5.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps [org.codehaus.gmavenplus:gmavenplus-plugin](https://github.com/groovy/GMavenPlus) from 4.3.1 to 5.0.0. - [Release notes](https://github.com/groovy/GMavenPlus/releases) - [Commits](groovy/GMavenPlus@4.3.1...5.0.0) --- updated-dependencies: - dependency-name: org.codehaus.gmavenplus:gmavenplus-plugin dependency-version: 5.0.0 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]>
…ions/graalvm/setup-graalvm-1.5.4 build(deps): bump graalvm/setup-graalvm from 1.5.3 to 1.5.4
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.1 to 4.36.2. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@87557b9...8aad20d) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.36.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
Harden Copy non-tar directory copy against path traversal from pod-controlled ls -F output by sanitizing entry names and enforcing destination path containment. Add regression test for traversal and positive test for safe entries.
…traversal fix(util): prevent non-tar copy path traversal
…codehaus.gmavenplus-gmavenplus-plugin-5.0.0 build(deps-dev): bump org.codehaus.gmavenplus:gmavenplus-plugin from 4.3.1 to 5.0.0
…ions/github/codeql-action-4.36.2 build(deps): bump github/codeql-action from 4.36.1 to 4.36.2
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
更新数据