Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Jan 25, 2022

Bumps github.com/containers/image/v5 from 5.12.0 to 5.19.0.

Release notes

Sourced from github.com/containers/image/v5's releases.

v5.19.0

What's Changed

New Contributors

Full Changelog: containers/image@v5.18.0...v5.19.0

v5.18.0

  • Add copy.Options.PreserveDigests
  • Link the two variants of cannotModifyManifest*Reason together.
  • shortnames: mechanism to enforce resolving to Docker Hub
  • manifest.GuessMIMEType(): recognize self-described OCI manifests
  • Add a comment about only looking up credential helpers by registry
  • Reorganize the success case in getCredentialsWithHomeDir
  • Introduce a string key in getCredentialsWithHomeDir
  • Modify findAuthentication to use a string key instead of a reference.Named
  • Allow using namespaced keys in GetCredentials and GetAuthentication
  • Rename useLegacyAPI to useLegacyFormat
  • Fix GetAllCredentials
  • Reject invalid keys in GetCredentials/GetAuthentication
  • Make validateKey a bit more strict
  • Don't include full manifest contents in error messages
  • Log if a manifest upload doesn't contain a Docker-Content-Digest header
  • docker/config: handle credentials not found errors
  • docker: less bears :(
  • Remove unused filler argument to customPartialBlobCounter
  • Inline decor.Any into the caller
  • Inline sstyle into the only user
  • Simplify a check for missing credentials
  • Fix handling of missing data in GetAllCredentials
  • Fix the pseudo-version of github.com/opencontainers/image-spec
  • Update golang.org/x/crypto, and silence warnings about openpgp

v5.17.0

Includes a fix for CVE-2021-41190 / GHSA-77vh-xpmg-72qh .

  • [CI:DOCS] Misc manpage fixups

... (truncated)

Commits
  • 7bdefff v5.19.0
  • bd97b58 Merge pull request #1446 from vrothberg/passphrase
  • 2773109 GPGME: support passphrase for prompt-less signing
  • beb2d5d use github.com/proglottis/gpgme
  • 1485258 Merge pull request #1450 from containers/dependabot/go_modules/github.com/vba...
  • e3fe472 build(deps): bump github.com/vbauerster/mpb/v7 from 7.3.1 to 7.3.2
  • c23e79e Merge pull request #1449 from rhatdan/codespell
  • 968e9a5 Run codespell on code
  • 5cb6ee2 Merge pull request #1447 from containers/dependabot/go_modules/github.com/con...
  • 2747440 build(deps): bump github.com/containers/storage from 1.37.0 to 1.38.0
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/containers/image/v5](https://github.com/containers/image) from 5.12.0 to 5.19.0.
- [Release notes](https://github.com/containers/image/releases)
- [Commits](containers/image@v5.12.0...v5.19.0)

---
updated-dependencies:
- dependency-name: github.com/containers/image/v5
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jan 25, 2022
@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Feb 2, 2022

Superseded by #37.

@dependabot dependabot bot closed this Feb 2, 2022
@dependabot dependabot bot deleted the dependabot/go_modules/github.com/containers/image/v5-5.19.0 branch February 2, 2022 21:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants