chore(deps): bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.1#292
chore(deps): bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.1#292dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.18.0 to 5.19.1. - [Release notes](https://github.com/go-git/go-git/releases) - [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md) - [Commits](go-git/go-git@v5.18.0...v5.19.1) --- updated-dependencies: - dependency-name: github.com/go-git/go-git/v5 dependency-version: 5.19.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Duplication | 0 |
AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.
TIP This summary will be updated as you push new changes.
There was a problem hiding this comment.
Pull Request Overview
This PR updates 'github.com/go-git/go-git/v5' to v5.19.1, incorporating security hardening and bug fixes. The primary blocker for this change is the omission of 'go.sum' updates, which are necessary for checksum verification and build reproducibility. While the codebase is otherwise up to standards according to quality analysis, the lack of evidence for build verification or basic Git operation smoke tests increases the risk of regressions in the dependency tree.
About this PR
- The PR modifies 'go.mod' but does not include the corresponding updates to 'go.sum'. This is required for dependency integrity and reproducible builds. Please run 'go mod tidy' and include the updated 'go.sum' file in this PR.
Test suggestions
- Verify the project compiles and builds successfully with the updated dependency tree.
- Perform smoke tests on Git operations (clone, pull, submodule init) to ensure compatibility with the new library version.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify the project compiles and builds successfully with the updated dependency tree.
2. Perform smoke tests on Git operations (clone, pull, submodule init) to ensure compatibility with the new library version.
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
Bumps github.com/go-git/go-git/v5 from 5.18.0 to 5.19.1.
Release notes
Sourced from github.com/go-git/go-git/v5's releases.
Commits
3c3be60Merge pull request #2137 from go-git/validate-v53fba897plumbing: format/packfile, cap delta chain depth in parsera97d660Merge pull request #2125 from hiddeco/v5/format-input-boundsaeaa125plumbing: format/objfile, require Header before Read1f38e17plumbing: format/packfile, bound inflate sizef7545a0plumbing: format/idxfile, bound nr by file size170b881Merge pull request #2116 from pjbgf/symlink-v57b6d994Merge pull request #2117 from hiddeco/v5/worktree-fs-mkdirall-root-noopf0709b3git: Stop validating symlink target paths776d00fgit: Allow MkdirAll on worktree-root pathsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.