Bump the go_modules group across 1 directory with 5 updates
Bumps the go_modules group with 2 updates in the / directory: github.com/cloudflare/circl and github.com/gin-gonic/gin.
Updates github.com/cloudflare/circl from 1.1.0 to 1.3.7
Release notes
Sourced from github.com/cloudflare/circl's releases.
CIRCL v1.3.7
What's Changed
- build(deps): bump golang.org/x/crypto from 0.3.1-0.20221117191849-2c476679df9a to 0.17.0 by
@dependabotin cloudflare/circl#467- kyber: remove division by q in ciphertext compression by
@bwesterbin cloudflare/circl#468- Releasing CIRCL v1.3.7 by
@armfazhin cloudflare/circl#469New Contributors
@dependabotmade their first contribution in cloudflare/circl#467Full Changelog: https://github.com/cloudflare/circl/compare/v1.3.6...v1.3.7
CIRCL v1.3.6
What's Changed
- internal: add TurboShake{128,256} by
@bwesterbin cloudflare/circl#430- Kangaroo12 draft -10 by
@bwesterbin cloudflare/circl#431- Add K12 as XOF by
@bwesterbin cloudflare/circl#437- xof/k12: Fix a typo in the package documentation by
@cjpattonin cloudflare/circl#438- Set CIRCL version for generated assembler code. by
@armfazhin cloudflare/circl#440- Add tkn20 benchmarks by
@tanyav2in cloudflare/circl#442- Add partially blind RSA implementation by
@chris-woodin cloudflare/circl#445- Update doc.go by
@nadimkobeissiin cloudflare/circl#447- tss/rsa: key generation for threshold RSA (safe primes) by
@armfazhin cloudflare/circl#450- Bumping Go version for CI jobs. by
@armfazhin cloudflare/circl#457- Spelling by
@jsorefin cloudflare/circl#456- blindrsa: updating blindrsa to be compliant with RFC9474 by
@armfazhin cloudflare/circl#464- Releasing CIRCL v1.3.6 by
@armfazhin cloudflare/circl#465New Contributors
@nadimkobeissimade their first contribution in cloudflare/circl#447@jsorefmade their first contribution in cloudflare/circl#456Full Changelog: https://github.com/cloudflare/circl/compare/v1.3.3...v1.3.6
CIRCL v1.3.3
New Features
- ASCON light-weight authenticated encryption.
- Hybrid KEM for HPKE based on Kyber and X25519.
- CIRCL can be compiled both as static and dynamic linking modes.
Security
- Fixes error-handling on rand readers.
What's Changed
- Use untyped consts for Kyber params by
@tmthrgdin cloudflare/circl#398- zk/dl: adds prefixed labels and updates nomenclature. by
@armfazhin cloudflare/circl#396- Bumping Go version. by
@armfazhin cloudflare/circl#399- kem: add P-256 + Kyber768Draft00 hybrid by
@bwesterbin cloudflare/circl#402
... (truncated)
Commits
c48866bReleasing CIRCL v1.3.775ef91ekyber: remove division by q in ciphertext compression899732abuild(deps): bump golang.org/x/crypto99f0f71Releasing CIRCL v1.3.6e728d0dApply thibmeu code review suggestionsceb2d90Updating blindrsa to be compliant with RFC9474.44133f7spelling: trippedc2076d6spelling: transposesdad2166spelling: title171c418spelling: threshold- Additional commits viewable in compare view
Updates github.com/gin-gonic/gin from 1.9.0 to 1.9.1
Release notes
Sourced from github.com/gin-gonic/gin's releases.
v1.9.1
Changelog
BUG FIXES
- fix Request.Context() checks #3512
SECURITY
- fix lack of escaping of filename in Content-Disposition #3556
ENHANCEMENTS
- refactor: use bytes.ReplaceAll directly #3455
- convert strings and slices using the officially recommended way #3344
- improve render code coverage #3525
DOCS
Changelog
Sourced from github.com/gin-gonic/gin's changelog.
Gin v1.9.1
BUG FIXES
- fix Request.Context() checks #3512
SECURITY
- fix lack of escaping of filename in Content-Disposition #3556
ENHANCEMENTS
- refactor: use bytes.ReplaceAll directly #3455
- convert strings and slices using the officially recommended way #3344
- improve render code coverage #3525
DOCS
Commits
4ea0e64Ready release gin 1.9.1 (by: thinkerou) (#3630)bb1fc2efix Request.Context() checks (#3512)2d4bbecfix lack of escaping of filename in Content-Disposition (#3556)9f5ecd4chore(deps): bump actions/setup-go from 3 to 4 (#3543)20cd6bcchore(deps): bump github.com/go-playground/validator/v10 (#3610)6bdc725Fix typos in ISSUE_TEMPLATE.md (#3616)1ab2689chore(deps): bump golang.org/x/net from 0.9.0 to 0.10.0 (#3599)6a0556eimprove render code coverage (#3525)eac2daachore: update dependencies for various packages and libraries (#3585)757a638chore: improve linting, testing, and GitHub Actions setup (#3583)- Additional commits viewable in compare view
Updates golang.org/x/crypto from 0.7.0 to 0.17.0
Commits
9d2ee97ssh: implement strict KEX protocol changes4e5a261ssh: close net.Conn on all NewServerConn errors152cdb1x509roots/fallback: update bundlefdfe1f8ssh: defer channel window adjustmentb8ffc16blake2b: drop Go 1.6, Go 1.8 compatibility7e6fbd8ssh: wrap errors from client handshakebda2f3fargon2: avoid clobbering BP325b735ssh/test: skip TestSSHCLIAuth on Windows1eadac5go.mod: update golang.org/x dependenciesb2d7c26ssh: add (*Client).DialContext method- Additional commits viewable in compare view
Updates golang.org/x/net from 0.9.0 to 0.10.0
Commits
daac0cego.mod: update golang.org/x dependencies82780d6http2: don't reuse connections that are experiencing errors0bfab66ipv4, ipv6: drop redundant skip checks based on GOOS938ff15ipv4, ipv6, nettest: skip unsupported tests on wasip1eb1572chtml: another shot at security doc9001ca7nettest: re-enable unixpacket tests on netbsd/3863d5a8eeinternal/socks: permit authenticating with an empty password- See full diff in compare view
Updates google.golang.org/protobuf from 1.28.1 to 1.30.0
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) -
@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) -
@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) -
@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency -
@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the Security Alerts page.