build(deps): Bump github.com/open-policy-agent/opa from 1.4.2 to 1.18.2 in /authbridge/authlib#640
Conversation
22d68df to
d97e9b4
Compare
|
Holding this one — triaged as high-risk. Bumping opa
This is why the Dependency Review check fails ( Recommended options before merging:
Leaving open for now rather than merging. |
|
Superseded by #674, which applies option 2 above: the opa |
Bumps [github.com/open-policy-agent/opa](https://github.com/open-policy-agent/opa) from 1.4.2 to 1.18.2. - [Release notes](https://github.com/open-policy-agent/opa/releases) - [Changelog](https://github.com/open-policy-agent/opa/blob/main/CHANGELOG.md) - [Commits](open-policy-agent/opa@v1.4.2...v1.18.2) --- updated-dependencies: - dependency-name: github.com/open-policy-agent/opa dependency-version: 1.18.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
d97e9b4 to
11c6da2
Compare
Bundles Dependabot's opa 1.4.2 -> 1.18.2 bump (kagenti#640) with an explicit oras.land/oras-go/v2 v2.6.2 pin to avoid the high-severity transitive advisory GHSA-fxhp-mv3v-67qp (oras-go tar hardlink extraction escape), which opa 1.18.2 otherwise pulls in via oras-go 2.6.1 and which fails the Dependency Review check (fail-on-severity: moderate). Applies the bump in authlib and runs `go mod tidy` (GOWORK=off) in authlib and every module that `replace`s it (authbridge-envoy, authbridge-proxy, abctl) so their go.mod/go.sum stay in sync. Same pattern as kagenti#673. Verified locally (GOWORK=off): go vet, go build, and go test -race pass in authlib/envoy/proxy; the proxy lite variant (exclude_plugin_* tags) builds and tests; abctl vets clean. oras-go resolves to 2.6.2 in all modules with no residual 2.5.0/2.6.1. Supersedes and closes kagenti#640. Assisted-By: Claude (Anthropic AI) <noreply@anthropic.com> Signed-off-by: Paolo Dettori <dettori@us.ibm.com>
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps github.com/open-policy-agent/opa from 1.4.2 to 1.18.2.
Release notes
Sourced from github.com/open-policy-agent/opa's releases.
... (truncated)
Changelog
Sourced from github.com/open-policy-agent/opa's changelog.
... (truncated)
Commits
e695c9ePatch release v1.18.2d473969Fix regression in fix of #8557 (#8845)acc8bf9Release v1.18.1713dc6aast: fix AnnotationSet memory leak via runtime.AddCleanup cyclecc2c5c6Prepare v1.18 release (#8820)e72a98fformat: keep lonewithon the closing-bracket line of multi-line expression...03646ddtopdown: Fix PE not namespacing vars in comprehensions nested insideevery...bf2bb52benchmarks: split off script, emit markdown table02ce276version: fix ill-formed User-Agent header (#8796)1fdbb77build(deps): bump the dependencies group across 2 directories with 6 updates