dce
dce copied to clipboard
Bump github.com/gorilla/schema from 1.2.0 to 1.4.1
Bumps github.com/gorilla/schema from 1.2.0 to 1.4.1.
Release notes
Sourced from github.com/gorilla/schema's releases.
v1.4.1
Security Release
Fixes an issue where sparse slice deserialization can cause memory exhaustion CVE-2024-37298
Thanks to
@AlexVasilutafor the report and following responsible disclosure.Full Changelog: https://github.com/gorilla/schema/compare/v1.4.0...v1.4.1
v1.4.0
What's Changed
- feat: if a different type in slice, raise error by
@lll-lll-lll-lllin gorilla/schema#212- fixed panic: reflect: indirection through nil pointer to embedded struct by
@morus12in gorilla/schema#211New Contributors
@lll-lll-lll-lllmade their first contribution in gorilla/schema#212Full Changelog: https://github.com/gorilla/schema/compare/v1.3.0...v1.3.1
v1.3.0
What's Changed
- Remove log.Fatal() usage in encoder.go by
@h2570suin gorilla/schema#207- Add default tag by
@zak905in gorilla/schema#183- update readme: add informations about the default tag option usage by
@zak905in gorilla/schema#209New Contributors
@h2570sumade their first contribution in gorilla/schema#207@zak905made their first contribution in gorilla/schema#183Full Changelog: https://github.com/gorilla/schema/compare/v1.2.1...v1.3.0
Release v1.2.1
What's Changed
- build: use build matrix; drop Go <= 1.10 by
@elithrarin gorilla/schema#147- doc: Update README CI badge by
@elithrarin gorilla/schema#148- docs: remove travis badge by
@elithrarin gorilla/schema#149- build: fix config.yml by
@elithrarin gorilla/schema#150- [bug] Registered encoder doesn't work for struct pointer types by
@tkhametovin gorilla/schema#174- Update README.md by
@coreydaleyin gorilla/schema#197- [GPT-98] Update go version & add verification/testing tools by
@apoorvajagtapin gorilla/schema#200- fix misspell by
@YuyaAboin gorilla/schema#192- Update issues.yml by
@coreydaleyin gorilla/schema#201- update GitHub workflows by
@coreydaleyin gorilla/schema#205New Contributors
@tkhametovmade their first contribution in gorilla/schema#174@coreydaleymade their first contribution in gorilla/schema#197@apoorvajagtapmade their first contribution in gorilla/schema#200@YuyaAbomade their first contribution in gorilla/schema#192Full Changelog: https://github.com/gorilla/schema/compare/v1.2.0...v1.2.1
Commits
cd59f2fMerge pull request from GHSA-3669-72x9-r9p3180f71efix: indirection through nil pointer to embedded struct (#211)a377fd6fix: fix assertion testbe699f4fix delete pointer slice test50924fffix:test: fix commentc44c90dfix:test: add assertion7d1c58efix: decode error message4548527fix: test data993e5b1fix: add test7487651fix: if default element type of value are setted in slice , raise error- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.