Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
build(deps): bump github.com/go-git/go-git/v5 from 5.13.2 to 5.14.0 (#…
…1548) Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.13.2 to 5.14.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/go-git/go-git/releases">github.com/go-git/go-git/v5's releases</a>.</em></p> <blockquote> <h2>v5.14.0</h2> <h2>What's Changed</h2> <ul> <li>v5: Bump Go and dependencies to mitigate <a href="https://pkg.go.dev/vuln/GO-2025-3487">GO-2025-3487</a> by <a href="https://github.com/pjbgf"><code>@pjbgf</code></a> in <a href="https://redirect.github.com/go-git/go-git/pull/1436">go-git/go-git#1436</a></li> </ul> <p>:warning: Note that this version requires Go 1.23, due to the bump to <code>golang.org/x/crypto@v0.35.0</code> which mitigates the CVE above. User's that can't bump to Go 1.23 will need to remain on the previous v5.13.x release.</p> <p><strong>Full Changelog</strong>: <a href="https://github.com/go-git/go-git/compare/v5.13.2...v5.14.0">https://github.com/go-git/go-git/compare/v5.13.2...v5.14.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/go-git/go-git/commit/863c621c8bed1fef118c564ac79e4b025f3f3c98"><code>863c621</code></a> Merge pull request <a href="https://redirect.github.com/go-git/go-git/issues/1436">#1436</a> from pjbgf/v5-bumps</li> <li><a href="https://github.com/go-git/go-git/commit/2e69e817ab29ca0734987c4d283a5797e1be7d03"><code>2e69e81</code></a> build: Bump dependencies</li> <li><a href="https://github.com/go-git/go-git/commit/b2c1ec98af0b932b760f993ab2ad25abfc890bac"><code>b2c1ec9</code></a> build: Bump Go versions</li> <li>See full diff in <a href="https://github.com/go-git/go-git/compare/v5.13.2...v5.14.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- Loading branch information