terraform-provider-graphql
terraform-provider-graphql copied to clipboard
chore(deps): bump github.com/hashicorp/go-getter from 1.5.3 to 1.7.0
Bumps github.com/hashicorp/go-getter from 1.5.3 to 1.7.0.
Release notes
Sourced from github.com/hashicorp/go-getter's releases.
v1.7.0
What's Changed
- docs: provide logging recommendations by
@mickael-hc
in hashicorp/go-getter#371- Update aws sdk version by
@Jukie
in hashicorp/go-getter#384- Update S3 URL in README by
@twelvelabs
in hashicorp/go-getter#378- Migrate to GHA by
@claire-labry
in hashicorp/go-getter#379- [COMPLIANCE] Update MPL 2.0 LICENSE by
@hashicorp-copywrite
in hashicorp/go-getter#386- remove codesign entirely from go-getter by
@claire-labry
in hashicorp/go-getter#408- Add decompression bomb mitigation options for v1 by
@picatz
in hashicorp/go-getter#412- v1: decompressors: add LimitedDecompressors helper by
@shoenig
in hashicorp/go-getter#413New Contributors
@mickael-hc
made their first contribution in hashicorp/go-getter#371@Jukie
made their first contribution in hashicorp/go-getter#384@twelvelabs
made their first contribution in hashicorp/go-getter#378@hashicorp-copywrite
made their first contribution in hashicorp/go-getter#386Full Changelog: https://github.com/hashicorp/go-getter/compare/v1.6.2...v1.7.0
v1.6.2
What's Changed
- Fix
no getter available for X-Terraform-Get source protocol
when using bare github or bitbucket hostnames: #370v1.6.1
No release notes provided.
v1.5.11
What's Changed
- Redact SSH key from URL query parameter by
@macedogm
in hashicorp/go-getter#348- gcs: only run oauth test if env var is set by
@schmichael
in hashicorp/go-getter#349New Contributors
@macedogm
made their first contribution in hashicorp/go-getter#348Full Changelog: https://github.com/hashicorp/go-getter/compare/v1.5.10...v1.5.11
v1.5.10
- When fetching files from Google Cloud Storage, go-getter will now consider the
GOOGLE_OAUTH_ACCESS_TOKEN
environment variable as a potential source of a Google Cloud Platform access token. (#302)- Fixed a regression from v1.5.9 where
git::
sources would no longer accept direct commit ids in the optionalref
argument, and would instead only allow named refs from the remote. As a compromise, go-getter will now accept forref
anything thatgit checkout
would accept as a valid tree selector, unless you also setdepth
to activate shallow clone mode in which caseref
must be a named ref due to requirements of the Git protocol in that case. (#345)v1.5.9
Fix git shallow clone (
depth
parameter) for any ref. See #266v1.5.8
No release notes provided.
v1.5.7
In 1.5.7, we moved to using signore, an internal tool, for GPG signing.
v1.5.5
... (truncated)
Commits
0edab85
Merge pull request #413 from hashicorp/limited-decompressors-helperb38771f
decompressors: add LimitedDecompressors helper78e6721
Merge pull request #412 from hashicorp/mitigate-decompression-bombcf15d84
Add decompression bomb mitigation optionsd229395
Merge pull request #408 from hashicorp/remove-codesignb55f8f7
remove codesign entirely from go-getter611343a
Merge pull request #386 from hashicorp/compliance/add-license7220a3d
Merge pull request #379 from hashicorp/migrate-to-gha2daac52
Update get_gcs_test.go95c5f2d
Update get_s3_test.go- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.
Codecov Report
Base: 73.66% // Head: 73.66% // No change to project coverage :thumbsup:
Coverage data is based on head (
3f3002b
) compared to base (362e61c
). Patch has no changes to coverable lines.
:mega: This organization is not using Codecov’s GitHub App Integration. We recommend you install it so Codecov can continue to function properly for your repositories. Learn more
Additional details and impacted files
@@ Coverage Diff @@
## master #83 +/- ##
=======================================
Coverage 73.66% 73.66%
=======================================
Files 7 7
Lines 505 505
=======================================
Hits 372 372
Misses 92 92
Partials 41 41
Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.
:umbrella: View full report at Codecov.
:loudspeaker: Do you have feedback about the report comment? Let us know in this issue.
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version
or @dependabot ignore this minor version
.
If you change your mind, just re-open this PR and I'll resolve any conflicts on it.