Backport security fix for v0.25.1 patch release#321
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## release-0.25 #321 +/- ##
=============================================
Coverage 57.20% 57.20%
=============================================
Files 13 13
Lines 1458 1458
=============================================
Hits 834 834
Misses 529 529
Partials 95 95
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
maleck13
left a comment
There was a problem hiding this comment.
changes look ok but not sure why builds are failing
The scripts in release branch do no respect versions set in build.yml. The generated bundle is not the committed one and the bundle validation task report failure. I believe it's been fixed in #324. I am going to rebase and see |
Bumps golang.org/x/net from v0.52.0 to v0.55.0. Signed-off-by: Thomas Maas <thomas@webtypes.com>
313fba0 to
da5daf2
Compare
The rebase did it |
Summary
Cherry-picked security fix for the v0.25.1 patch release.
Changes
Semver Classification
All changes are patch-safe:
idnapackageVerification
// indirectin go.mod)Related
Generated via
/kdt:patch-releaseworkflow