Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

deps: bump golang.org/x/net from 0.15.0 to 0.17.0 #2293

Merged
merged 1 commit into from
Nov 1, 2023

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 14, 2023

Bumps golang.org/x/net from 0.15.0 to 0.17.0.

Commits
  • b225e7c http2: limit maximum handler goroutines to MaxConcurrentStreams
  • 88194ad go.mod: update golang.org/x dependencies
  • 2b60a61 quic: fix several bugs in flow control accounting
  • 73d82ef quic: handle DATA_BLOCKED frames
  • 5d5a036 quic: handle streams moving from the data queue to the meta queue
  • 350aad2 quic: correctly extend peer's flow control window after MAX_DATA
  • 21814e7 quic: validate connection id transport parameters
  • a600b35 quic: avoid redundant MAX_DATA updates
  • ea63359 http2: check stream body is present on read timeout
  • ddd8598 quic: version negotiation
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

Dependabot will merge this PR once it's up-to-date and CI passes on it, as requested by @rbtr.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

@dependabot dependabot bot requested a review from a team as a code owner October 14, 2023 00:24
@dependabot dependabot bot added the dependencies Dependencies only. label Oct 14, 2023
@dependabot dependabot bot added the go Pull requests that update Go code label Oct 14, 2023
@dependabot dependabot bot assigned matmerr and rbtr Oct 14, 2023
@nddq nddq force-pushed the a615dependabot/go_modules/golang.org/x/net-0.17.0 branch from 59acda6 to f98c198 Compare October 27, 2023 06:32
@rbtr
Copy link
Contributor

rbtr commented Oct 27, 2023

/azp run

Copy link
Contributor

@rbtr rbtr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dependabot squash and merge

@azure-pipelines
Copy link

Azure Pipelines successfully started running 2 pipeline(s).

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Oct 27, 2023

One of your CI runs failed on this pull request, so Dependabot won't merge it.

Dependabot will still automatically merge this pull request if you amend it and your tests pass.

@rbtr rbtr force-pushed the a615dependabot/go_modules/golang.org/x/net-0.17.0 branch from f98c198 to d8367a8 Compare October 30, 2023 15:55
@rbtr
Copy link
Contributor

rbtr commented Oct 30, 2023

/azp run

@azure-pipelines
Copy link

Azure Pipelines successfully started running 2 pipeline(s).

@rbtr rbtr enabled auto-merge (squash) October 30, 2023 16:36
@nddq nddq force-pushed the a615dependabot/go_modules/golang.org/x/net-0.17.0 branch from d8367a8 to ec8992b Compare October 31, 2023 19:20
@rbtr rbtr disabled auto-merge October 31, 2023 20:02
@rbtr
Copy link
Contributor

rbtr commented Oct 31, 2023

/azp run

Copy link
Contributor

@rbtr rbtr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dependabot squash and merge

Copy link

Azure Pipelines successfully started running 2 pipeline(s).

@rbtr rbtr added release/1.4 Change affects v1.4 release train needs-backport Change needs to be backported to previous release trains release/latest Change affects latest release train labels Oct 31, 2023
Bumps [golang.org/x/net](https://github.com/golang/net) from 0.15.0 to 0.17.0.
- [Commits](golang/net@v0.15.0...v0.17.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@rbtr rbtr force-pushed the a615dependabot/go_modules/golang.org/x/net-0.17.0 branch from ec8992b to 5dd7fb2 Compare October 31, 2023 21:47
@rbtr rbtr merged commit a540544 into master Nov 1, 2023
77 of 79 checks passed
@rbtr rbtr deleted the a615dependabot/go_modules/golang.org/x/net-0.17.0 branch November 1, 2023 15:01
@rbtr rbtr removed the needs-backport Change needs to be backported to previous release trains label Nov 3, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Dependencies only. go Pull requests that update Go code release/latest Change affects latest release train release/1.4 Change affects v1.4 release train
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants