Conversation
There was a problem hiding this comment.
Pull request overview
This PR updates sigstore-go dependency from an earlier version to v1.1.4, which involves removing numerous third-party dependency files and license files as part of the dependency update process.
Reviewed changes
Copilot reviewed 158 out of 1101 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| Multiple third-party LICENSE files | Removed license files for various dependencies including hashicorp/golang-lru, hashicorp/go-version, in-toto packages, and many others |
| Multiple third-party test files | Removed test files from hashicorp/golang-lru and hashicorp/go-version packages |
| Multiple third-party source files | Removed source code files from hashicorp packages including LRU cache implementations and version handling utilities |
| Multiple third-party configuration files | Removed go.mod files, CI configuration files, and other build/development configuration files |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
0eae7ef to
19b1b7b
Compare
|
Will this PR or #12299 be merged soon? |
|
IIRC we faced an issue with our |
Signed-off-by: Babak K. Shandiz <babakks@github.com>
Signed-off-by: Babak K. Shandiz <babakks@github.com>
03522e9 to
7925d73
Compare
Signed-off-by: Babak K. Shandiz <babakks@github.com>
Signed-off-by: Babak K. Shandiz <babakks@github.com>
|
Thanks for the fixes. I have not found info yet on how often a new version is released, do you know when a new version will appear or what determines when a new version is created? |
This MR contains the following updates: | Package | Update | Change | |---|---|---| | [cli/cli](https://github.com/cli/cli) | minor | `v2.83.2` → `v2.85.0` | MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot). **Proposed changes to behavior should be submitted there as MRs.** --- ### Release Notes <details> <summary>cli/cli (cli/cli)</summary> ### [`v2.85.0`](https://github.com/cli/cli/releases/tag/v2.85.0): GitHub CLI 2.85.0 [Compare Source](cli/cli@v2.83.2...v2.85.0) #### What's Changed ##### ✨ Features - Add gh browse --actions flag by [@​rneatherway](https://github.com/rneatherway) in [#​12091](cli/cli#12091) - feat: allow git remote names in gh repo set-default by [@​majiayu000](https://github.com/majiayu000) in [#​12377](cli/cli#12377) ##### 🐛 Fixes - Fix Debian CLI package link in installation guide by [@​andyfeller](https://github.com/andyfeller) in [#​12291](cli/cli#12291) - fix: prevent panic when processing null project items by [@​chrishenzie](https://github.com/chrishenzie) in [#​12324](cli/cli#12324) ##### 📚 Docs & Chores - chore: upgrade to `cli/oauth@v1.2.1` by [@​babakks](https://github.com/babakks) in [#​12337](cli/cli#12337) - ci: upgrade to GoReleaser `v2` by [@​babakks](https://github.com/babakks) in [#​12318](cli/cli#12318) - CI: Update Azure Code Signing client to 1.0.95 by [@​BagToad](https://github.com/BagToad) in [#​12424](cli/cli#12424) - CI: Update Azure Code Signing endpoint URL by [@​BagToad](https://github.com/BagToad) in [#​12425](cli/cli#12425) - ci: tag per build job by [@​babakks](https://github.com/babakks) in [#​12428](cli/cli#12428) - CI: Add shell specification for temporary tag creation on Windows by [@​BagToad](https://github.com/BagToad) in [#​12429](cli/cli#12429) - Bump sigstore-go to v1.1.4 by [@​williammartin](https://github.com/williammartin) in [#​12289](cli/cli#12289) - Update actions/checkout to v6 in extension workflow templates by [@​fchimpan](https://github.com/fchimpan) in [#​12393](cli/cli#12393) - ci: enable noop linters by [@​babakks](https://github.com/babakks) in [#​12440](cli/cli#12440) #####Dependencies - chore(deps): bump golang.org/x/sync from 0.18.0 to 0.19.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​12274](cli/cli#12274) - chore(deps): bump golang.org/x/text from 0.31.0 to 0.32.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​12281](cli/cli#12281) - chore(deps): bump golang.org/x/term from 0.37.0 to 0.38.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​12282](cli/cli#12282) - chore(deps): bump github.com/spf13/cobra from 1.10.1 to 1.10.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​12255](cli/cli#12255) - chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.1 to 2.13.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​12262](cli/cli#12262) - chore(deps): bump golangci/golangci-lint-action from 9.1.0 to 9.2.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​12252](cli/cli#12252) - chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.2 to 2.13.4 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​12302](cli/cli#12302) - chore(deps): bump golang.org/x/crypto from 0.45.0 to 0.46.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​12300](cli/cli#12300) - chore(deps): bump actions/attest-build-provenance from 3.0.0 to 3.1.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​12339](cli/cli#12339) - chore(deps): bump github.com/yuin/goldmark from 1.7.13 to 1.7.16 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​12452](cli/cli#12452) #### New Contributors - [@​chrishenzie](https://github.com/chrishenzie) made their first contribution in [#​12324](cli/cli#12324) - [@​fchimpan](https://github.com/fchimpan) made their first contribution in [#​12393](cli/cli#12393) - [@​majiayu000](https://github.com/majiayu000) made their first contribution in [#​12377](cli/cli#12377) **Full Changelog**: <cli/cli@v2.83.2...v2.85.0> </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this MR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box --- This MR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi44MS4yIiwidXBkYXRlZEluVmVyIjoiNDIuODEuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiUmVub3ZhdGUgQm90IiwiYXV0b21hdGlvbjpib3QtYXV0aG9yZWQiLCJkZXBlbmRlbmN5LXR5cGU6Om1pbm9yIl19-->
This PR bumps
sigstore-gotov1.1.4, and also upgrades thego-licensestool tov2.