Skip to content

Commit 009b790

Browse files
authored
Merge pull request #284 from grafana/283-update-go-module-and-docker-dependencies
Update Go Module and Docker Dependencies
2 parents 234f8a5 + c8de72b commit 009b790

File tree

7 files changed

+109
-12
lines changed

7 files changed

+109
-12
lines changed

Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
1-
ARG GO_VERSION=1.24.7
1+
ARG GO_VERSION=1.24.8
22
ARG VARIANT=alpine3.22
3-
ARG GOSEC_VERSION=2.22.8
3+
ARG GOSEC_VERSION=2.22.9
44

55
FROM securego/gosec:${GOSEC_VERSION} AS gosec
66

Dockerfile.goreleaser

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
1-
ARG GO_VERSION=1.24.7
1+
ARG GO_VERSION=1.24.8
22
ARG VARIANT=alpine3.22
3-
ARG GOSEC_VERSION=2.22.8
3+
ARG GOSEC_VERSION=2.22.9
44

55
FROM securego/gosec:${GOSEC_VERSION} AS gosec
66

go.mod

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ require (
77
github.com/chainguard-dev/git-urls v1.0.2
88
github.com/fatih/color v1.18.0
99
github.com/go-enry/go-license-detector/v4 v4.3.1
10-
github.com/go-git/go-git/v5 v5.16.2
10+
github.com/go-git/go-git/v5 v5.16.3
1111
github.com/grafana/k6foundry v0.4.7
1212
github.com/lmittmann/tint v1.1.2
1313
github.com/mattn/go-colorable v0.1.14
@@ -16,7 +16,7 @@ require (
1616
github.com/spf13/pflag v1.0.10
1717
github.com/szkiba/docsme v0.2.0
1818
github.com/szkiba/efa v0.1.0
19-
golang.org/x/mod v0.28.0
19+
golang.org/x/mod v0.29.0
2020
)
2121

2222
require (

go.sum

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -47,8 +47,8 @@ github.com/go-git/go-billy/v5 v5.6.2 h1:6Q86EsPXMa7c3YZ3aLAQsMA0VlWmy43r6FHqa/UN
4747
github.com/go-git/go-billy/v5 v5.6.2/go.mod h1:rcFC2rAsp/erv7CMz9GczHcuD0D32fWzH+MJAU+jaUU=
4848
github.com/go-git/go-git-fixtures/v4 v4.3.2-0.20231010084843-55a94097c399 h1:eMje31YglSBqCdIqdhKBW8lokaMrL3uTkpGYlE2OOT4=
4949
github.com/go-git/go-git-fixtures/v4 v4.3.2-0.20231010084843-55a94097c399/go.mod h1:1OCfN199q1Jm3HZlxleg+Dw/mwps2Wbk9frAWm+4FII=
50-
github.com/go-git/go-git/v5 v5.16.2 h1:fT6ZIOjE5iEnkzKyxTHK1W4HGAsPhqEqiSAssSO77hM=
51-
github.com/go-git/go-git/v5 v5.16.2/go.mod h1:4Ge4alE/5gPs30F2H1esi2gPd69R0C39lolkucHBOp8=
50+
github.com/go-git/go-git/v5 v5.16.3 h1:Z8BtvxZ09bYm/yYNgPKCzgWtaRqDTgIKRgIRHBfU6Z8=
51+
github.com/go-git/go-git/v5 v5.16.3/go.mod h1:4Ge4alE/5gPs30F2H1esi2gPd69R0C39lolkucHBOp8=
5252
github.com/golang/freetype v0.0.0-20170609003504-e2365dfdc4a0/go.mod h1:E/TSTwGwJL78qG/PmXZO1EjYhfJinVAhrmmHX6Z8B9k=
5353
github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 h1:f+oWsMOmNPc8JmEHVZIycC7hBoQxHH9pNKQORJNozsQ=
5454
github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8/go.mod h1:wcDNUvekVysuuOpQKo3191zZyTpiI6se1N1ULghS0sw=
@@ -131,8 +131,8 @@ golang.org/x/exp v0.0.0-20190125153040-c74c464bbbf2/go.mod h1:CJ0aWSM057203Lf6IL
131131
golang.org/x/exp v0.0.0-20240719175910-8a7402abbf56 h1:2dVuKD2vS7b0QIHQbpyTISPd0LeHDbnYEryqj5Q1ug8=
132132
golang.org/x/exp v0.0.0-20240719175910-8a7402abbf56/go.mod h1:M4RDyNAINzryxdtnbRXRL/OHtkFuWGRjvuhBJpk2IlY=
133133
golang.org/x/image v0.0.0-20180708004352-c73c2afc3b81/go.mod h1:ux5Hcp/YLpHSI86hEcLt0YII63i6oz57MZXIpbrjZUs=
134-
golang.org/x/mod v0.28.0 h1:gQBtGhjxykdjY9YhZpSlZIsbnaE2+PgjfLWUQTnoZ1U=
135-
golang.org/x/mod v0.28.0/go.mod h1:yfB/L0NOf/kmEbXjzCPOx1iK1fRutOydrCMsqRhEBxI=
134+
golang.org/x/mod v0.29.0 h1:HV8lRxZC4l2cr3Zq1LvtOsi/ThTgWnUk/y64QSs8GwA=
135+
golang.org/x/mod v0.29.0/go.mod h1:NyhrlYXJ2H4eJiRy/WDBO6HMqZQ6q9nk4JzS3NuCK+w=
136136
golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y=
137137
golang.org/x/net v0.39.0 h1:ZCu7HMWDxpXpaiKdhzIfaltL9Lp31x/3fCP11bc6/fY=
138138
golang.org/x/net v0.39.0/go.mod h1:X7NRbYVEA+ewNkCNyJ513WmMdQ3BineSwVtN2zD/d+E=

releases/v1.1.6.md

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
Grafana **xk6** `v1.1.6` is here! 🎉
2+
3+
This release focuses on essential updates to core Go modules and Docker images to enhance security, stability, and maintain compatibility.
4+
5+
### Security and Maintenance Updates
6+
7+
Several dependencies have been updated to their latest patch versions, which includes critical security fixes and stability improvements.
8+
9+
#### Go Module Updates
10+
11+
The following Go module dependencies are updated:
12+
13+
* `github.com/go-git/go-git/v5`: Updated to `v5.16.3`.
14+
* `golang.org/x/mod`: Updated to `v0.29.0`.
15+
16+
#### Docker and CI Tooling Updates
17+
18+
The Docker images used in the build and security processes are updated:
19+
20+
* **Build Base Image**: Updated to `golang:1.24.8-alpine3.22`.
21+
* **Security Scanner**: Updated `securego/gosec` to `2.22.9`.
22+
23+
### Rationale
24+
25+
These dependency updates are crucial for maintaining the security posture of `xk6`. Applying these updates was prioritized before the **planned refactoring** of the `xk6 lint` subcommand to ensure a stable and secure foundation for future development efforts.

vendor/github.com/go-git/go-git/v5/plumbing/object/commit.go

Lines changed: 72 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/modules.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -97,7 +97,7 @@ github.com/go-git/go-billy/v5/helper/polyfill
9797
github.com/go-git/go-billy/v5/memfs
9898
github.com/go-git/go-billy/v5/osfs
9999
github.com/go-git/go-billy/v5/util
100-
# github.com/go-git/go-git/v5 v5.16.2
100+
# github.com/go-git/go-git/v5 v5.16.3
101101
## explicit; go 1.23.0
102102
github.com/go-git/go-git/v5
103103
github.com/go-git/go-git/v5/config
@@ -238,7 +238,7 @@ golang.org/x/crypto/ssh/knownhosts
238238
# golang.org/x/exp v0.0.0-20240719175910-8a7402abbf56
239239
## explicit; go 1.20
240240
golang.org/x/exp/rand
241-
# golang.org/x/mod v0.28.0
241+
# golang.org/x/mod v0.29.0
242242
## explicit; go 1.24.0
243243
golang.org/x/mod/internal/lazyregexp
244244
golang.org/x/mod/modfile

0 commit comments

Comments
 (0)