chore(deps): bump go.ketch.com/lib/orlop/v2 from 2.19.3 to 2.25.10 - #159
chore(deps): bump go.ketch.com/lib/orlop/v2 from 2.19.3 to 2.25.10#159dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [go.ketch.com/lib/orlop/v2](https://github.com/ketch-com/orlop) from 2.19.3 to 2.25.10. - [Release notes](https://github.com/ketch-com/orlop/releases) - [Commits](ketch-com/orlop@v2.19.3...v2.25.10) --- updated-dependencies: - dependency-name: go.ketch.com/lib/orlop/v2 dependency-version: 2.25.10 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Bumps go.ketch.com/lib/orlop/v2 from 2.19.3 to 2.25.10.
Release notes
Sourced from go.ketch.com/lib/orlop/v2's releases.
... (truncated)
Commits
a20b2fcfix: upgrade conventional-actions to node24 (#329)647802cchore: SHA-pin conventional-actions to latest hardened versions (#328)ebf399bchore(deps): bump github.com/stretchr/testify from 1.8.4 to 1.9.0 (#320)56956e6chore(deps): bump actions/checkout from 3 to 4 (#306)b75cbe8chore(deps): bump actions/setup-go from 4 to 5 (#318)218b159chore(bump): Bump dependencies (#319)49c8b62fix: header (#317)21548bdchore: upgrade dependencies (#316)9da548afix: add maps for compatibility (#315)c33c286fix(orlop): update connection key name (#314)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Note
Medium Risk
Orlop is wired into CLI entrypoint, config, login, and transponder; a multi-minor jump with gRPC/protobuf churn could change runtime behavior even though no first-party code changed.
Overview
Bumps
go.ketch.com/lib/orlop/v2from 2.19.3 to 2.25.10 with no application source changes—onlygo.mod/go.sum.The update also refreshes related direct deps (cobra, logrus, godotenv) and transitive stacks (uber/fx, gRPC, protobuf, golang.org/x/sys).
github.com/golang/protobufandgo.uber.org/atomicdrop out of the module graph;github.com/google/uuidappears as a new indirect dependency.Reviewed by Cursor Bugbot for commit 8df7682. Configure here.