-
Notifications
You must be signed in to change notification settings - Fork 5
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump metrics-exporter-statsd from 0.6.0 to 0.8.0 #337
Conversation
Hi there 👋, @DryRunSecurity here, below is a summary of our analysis and findings.
Note 🟢 Risk threshold not exceeded. Change Summary (click to expand)The following is a summary of changes in this pull request made by me, your security buddy 🤖. Note that this summary is auto-generated and not meant to be a definitive list of security issues but rather a helpful summary from a security perspective. Summary: The code changes in this pull request focus on updating the versions of two dependencies in the Rust project: While the version changes themselves do not introduce any obvious security concerns, it is important to review the changes in the new versions to ensure that there are no known security vulnerabilities. Additionally, it is a good practice to monitor the dependency versions and update them regularly to keep the application secure and up-to-date. Files Changed:
As an application security engineer, I would recommend reviewing the release notes or changelogs for the updated dependencies to understand the changes and any potential security implications. Additionally, running automated security scans or audits on the updated dependencies would be a good practice to ensure that there are no known vulnerabilities. Powered by DryRun Security |
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media? TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (invoked as PR comments)
Additionally, you can add CodeRabbit Configration File (
|
4210602
to
295fb9d
Compare
eae5215
to
4fff6de
Compare
Bumps [metrics-exporter-statsd](https://github.com/github/metrics-exporter-statsd) from 0.6.0 to 0.8.0. - [Changelog](https://github.com/github/metrics-exporter-statsd/blob/main/CHANGELOG.md) - [Commits](github/metrics-exporter-statsd@0.6.0...0.8.0) --- updated-dependencies: - dependency-name: metrics-exporter-statsd dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
4fff6de
to
db851a0
Compare
Already resolved in the |
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps metrics-exporter-statsd from 0.6.0 to 0.8.0.
Changelog
Sourced from metrics-exporter-statsd's changelog.
Commits
4b0e294
Merge pull request #62 from github/mbellani/fix-publish-script184fee6
Fix version extraction7a61717
Merge pull request #61 from github/mbellani/release-0.8a74fa08
Release 0.87b405d9
Merge pull request #60 from ijc/metrics-2301e93e8
Merge branch 'main' into metrics-23a782d7f
Merge pull request #58 from github/dependabot/cargo/cadence-1.4.0456bd46
Merge pull request #57 from github/dependabot/cargo/thiserror-1.0.596bf3bba
Bump to metrics 0.23b9be716
Bump cadence from 1.3.0 to 1.4.0You can trigger a rebase of this PR by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)