Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 11, 2023

Bumps google.golang.org/grpc from 1.44.0 to 1.52.0.

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.52.0

New Features

  • xdsclient: log node ID with verbosity INFO (#5860)
  • ringhash: impose cap on max_ring_size to reduce possibility of OOMs (#5801)

Behavior Changes

  • client: return an error from Dial if an empty target is passed and no custom dialer is present; the ClientConn would otherwise be unable to connect and perform RPCs (#5732)

Bug Fixes

  • transport (net/http server handler): respond to bad HTTP requests with status 400 (Bad Request) instead of 500 (Internal Server Error). (#5804)
  • transport: Fixed closing a closed channel panic in handlePing (#5854)
  • server: fix ChainUnaryInterceptor and ChainStreamInterceptor to allow retrying handlers (#5666)
  • transport: ensure value of :authority header matches server name used in TLS handshake when the latter is overridden by the name resolver (#5748)

Documentation

  • examples: add an example to illustrate the usage of stats handler (#5657)
  • examples: add new example to show updating metadata in interceptors (#5788)

Release 1.51.0

Behavior Changes

  • xds: NACK EDS resources with duplicate addresses in accordance with a recent spec change (#5715)
  • grpc: restrict status codes that can be generated by the control plane (gRFC A54) (#5653)

New Features

  • client: set grpc-accept-encoding header with all registered compressors (#5541)
  • xds/weightedtarget: return a more meaningful error when all child policies are in TRANSIENT_FAILURE (#5711)
  • gcp/observability: add "started rpcs" metric (#5768)
  • xds: de-experimentalize the google-c2p-resolver (#5707)
  • balancer: add experimental Producer types and methods (#5669)
  • orca: provide a way for LB policies to receive OOB load reports (#5669)

Bug Fixes

  • go.mod: upgrade x/text dependency to address CVE 2022-32149 (#5769)
  • client: fix race that could lead to an incorrect connection state if it was closed immediately after the server's HTTP/2 preface was received (#5714)

... (truncated)

Commits
  • ce56cef Change version to 1.52.0 (#5870)
  • a0e8eb9 test: rename race.go to race_test.go (#5869)
  • ae86ff4 benchmark: fix typo in ClientReadBufferSize feature name (#5867)
  • e53d28f xdsclient: log node ID with verbosity INFO (#5860)
  • 9373e5c transport: Fix closing a closed channel panic in handlePing (#5854)
  • 2f413c4 transport/http2: use HTTP 400 for bad requests instead of 500 (#5804)
  • 5003029 testutils: do a better job of verifying pick_first in tests (#5850)
  • 3e27f89 binarylog: Account for key in metadata truncation (#5851)
  • f54bba9 test/xds: minor cleanup in xDS e2e test (#5843)
  • a9709c3 Added logs for reasons causing connection and transport close (#5840)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.44.0 to 1.52.0.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.44.0...v1.52.0)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot requested a review from a team as a code owner January 11, 2023 14:07
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jan 11, 2023
@trafico-bot trafico-bot bot added the 🔍 Ready for Review Pull Request is not reviewed yet label Jan 11, 2023
@guardrails
Copy link

guardrails bot commented Jan 11, 2023

⚠️ We detected 35 security issues in this pull request:

Vulnerable Libraries (35)
Severity Details
N/A pkg:golang/golang.org/x/sys@v0.0.0-20211124211545-fe61309f8881@v0.0.0-20211124211545-fe61309f8881 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/golang.org/x/net@v0.0.0-20220225172249-27dd8689420f@v0.0.0-20220225172249-27dd8689420f - no patch available
N/A pkg:golang/golang.org/x/sys@v0.0.0-20211210111614-af8b64212486@v0.0.0-20211210111614-af8b64212486 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210603125802-9665404d3644@v0.0.0-20210603125802-9665404d3644 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22@v0.0.0-20210616094352-59db8d763f22 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210220050731-9a76102bfb43@v0.0.0-20210220050731-9a76102bfb43 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20220209214540-3681064d5158@v0.0.0-20220209214540-3681064d5158 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20200905004654-be1d3432aa8f@v0.0.0-20200905004654-be1d3432aa8f upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210104204734-6f8348627aad@v0.0.0-20210104204734-6f8348627aad upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210320140829-1e4c9ba3b0c4@v0.0.0-20210320140829-1e4c9ba3b0c4 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210806184541-e5e7981a1069@v0.0.0-20210806184541-e5e7981a1069 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/golang.org/x/net@v0.0.0-20220412020605-290c469a71a5@v0.0.0-20220412020605-290c469a71a5 - no patch available
N/A pkg:golang/golang.org/x/sys@v0.0.0-20220227234510-4e6760a101f9@v0.0.0-20220227234510-4e6760a101f9 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/golang.org/x/net@v0.0.0-20201031054903-ff519b6c9102@v0.0.0-20201031054903-ff519b6c9102 - no patch available
High pkg:golang/github.com/hashicorp/consul/api@v1.3.0@v1.3.0 - no patch available
High pkg:golang/github.com/hashicorp/consul/api@v1.3.0@v1.3.0 - no patch available
N/A pkg:golang/golang.org/x/net@v0.0.0-20220909164309-bea034e7d591@v0.0.0-20220909164309-bea034e7d591 upgrade to: 1.18.9,1.19.4,0.4.0
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210908233432-aa78b53d3365@v0.0.0-20210908233432-aa78b53d3365 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210305230114-8fe3ee5dd75b@v0.0.0-20210305230114-8fe3ee5dd75b upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4@v0.0.0-20220425223048-2871e0cb64e4 - no patch available
High pkg:golang/golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420@v0.0.0-20210503060351-7fd8e65b6420 - no patch available
High pkg:golang/golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd@v0.0.0-20220127200216-cd36cc0744dd - no patch available
N/A pkg:golang/golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e@v0.0.0-20220624214902-1bab6f366d9e upgrade to: 1.18.9,1.19.4,0.4.0
Medium pkg:golang/golang.org/x/text@v0.3.5@v0.3.5 - no patch available
N/A pkg:golang/golang.org/x/sys@v0.0.0-20201201145000-ef89a241ccb3@v0.0.0-20201201145000-ef89a241ccb3 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b@v0.0.0-20221014081412-f15817d10f9b upgrade to: 1.18.9,1.19.4,0.4.0
N/A pkg:golang/golang.org/x/sys@v0.0.0-20210823070655-63515b42dcdf@v0.0.0-20210823070655-63515b42dcdf upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
High pkg:golang/golang.org/x/text@v0.3.4@v0.3.4 - no patch available
N/A pkg:golang/golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9@v0.0.0-20220617184016-355a448f1bc9 upgrade to: 1.18.9,1.19.4,0.4.0
High pkg:golang/golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11@v0.0.0-20201209123823-ac852fbbde11 - no patch available
N/A pkg:golang/golang.org/x/net@v0.0.0-20220607020251-c690dde0001d@v0.0.0-20220607020251-c690dde0001d upgrade to: 1.18.9,1.19.4,0.4.0
N/A pkg:golang/golang.org/x/net@v0.0.0-20220722155237-a158d28d115b@v0.0.0-20220722155237-a158d28d115b upgrade to: 1.18.9,1.19.4,0.4.0
N/A pkg:golang/golang.org/x/sys@v0.0.0-20220328115105-d36c6a25d886@v0.0.0-20220328115105-d36c6a25d886 upgrade to: 1.17.10,1.18.2,0.0.0-20220412211240-33da011f77ad
N/A pkg:golang/golang.org/x/net@v0.0.0-20221012135044-0b7e1fb9d458@v0.0.0-20221012135044-0b7e1fb9d458 upgrade to: 1.18.9,1.19.4,0.4.0
High pkg:golang/golang.org/x/net@v0.0.0-20220325170049-de3da57026de@v0.0.0-20220325170049-de3da57026de - no patch available

More info on how to fix Vulnerable Libraries in Go.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jan 25, 2023

Superseded by #257.

@dependabot dependabot bot closed this Jan 25, 2023
@dependabot dependabot bot deleted the dependabot/go_modules/google.golang.org/grpc-1.52.0 branch January 25, 2023 14:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code 🔍 Ready for Review Pull Request is not reviewed yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants