Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): Bump github.com/labstack/echo/v4 from 4.9.1 to 4.10.0 #88

Merged

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 30, 2023

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps github.com/labstack/echo/v4 from 4.9.1 to 4.10.0.

Release notes

Sourced from github.com/labstack/echo/v4's releases.

v4.10.0

Security

  • We are deprecating JWT middleware in this repository. Please use https://github.com/labstack/echo-jwt instead.

    JWT middleware is moved to separate repository to allow us to bump/upgrade version of JWT implementation (github.com/golang-jwt/jwt) we are using which we can not do in Echo core because this would break backwards compatibility guarantees we try to maintain.

  • This minor version bumps minimum Go version to 1.17 (from 1.16) due golang.org/x/ packages we depend on. There are several vulnerabilities fixed in these libraries.

    Echo still tries to support last 4 Go versions but there are occasions we can not guarantee this promise.

Enhancements

  • Bump x/text to 0.3.8 #2305
  • Bump dependencies and add notes about Go releases we support #2336
  • Add helper interface for ProxyBalancer interface #2316
  • Expose middleware.CreateExtractors function so we can use it from echo-contrib repository #2338
  • Refactor func(Context) error to HandlerFunc #2315
  • Improve function comments #2329
  • Add new method HTTPError.WithInternal #2340
  • Replace io/ioutil package usages #2342
  • Add staticcheck to CI flow #2343
  • Replace relative path determination from proprietary to std #2345
  • Remove square brackets from ipv6 addresses in XFF (X-Forwarded-For header) #2182
  • Add testcases for some BodyLimit middleware configuration options #2350
  • Additional configuration options for RequestLogger and Logger middleware #2341
  • Add route to request log #2162
  • GitHub Workflows security hardening #2358
  • Add govulncheck to CI and bump dependencies #2362
  • Fix rate limiter docs #2366
  • Refactor how e.Routes() work and introduce e.OnAddRouteHandler callback #2337
Changelog

Sourced from github.com/labstack/echo/v4's changelog.

v4.10.0 - 2022-12-27

Security

  • We are deprecating JWT middleware in this repository. Please use https://github.com/labstack/echo-jwt instead.

    JWT middleware is moved to separate repository to allow us to bump/upgrade version of JWT implementation (github.com/golang-jwt/jwt) we are using which we can not do in Echo core because this would break backwards compatibility guarantees we try to maintain.

  • This minor version bumps minimum Go version to 1.17 (from 1.16) due golang.org/x/ packages we depend on. There are several vulnerabilities fixed in these libraries.

    Echo still tries to support last 4 Go versions but there are occasions we can not guarantee this promise.

Enhancements

  • Bump x/text to 0.3.8 #2305
  • Bump dependencies and add notes about Go releases we support #2336
  • Add helper interface for ProxyBalancer interface #2316
  • Expose middleware.CreateExtractors function so we can use it from echo-contrib repository #2338
  • Refactor func(Context) error to HandlerFunc #2315
  • Improve function comments #2329
  • Add new method HTTPError.WithInternal #2340
  • Replace io/ioutil package usages #2342
  • Add staticcheck to CI flow #2343
  • Replace relative path determination from proprietary to std #2345
  • Remove square brackets from ipv6 addresses in XFF (X-Forwarded-For header) #2182
  • Add testcases for some BodyLimit middleware configuration options #2350
  • Additional configuration options for RequestLogger and Logger middleware #2341
  • Add route to request log #2162
  • GitHub Workflows security hardening #2358
  • Add govulncheck to CI and bump dependencies #2362
  • Fix rate limiter docs #2366
  • Refactor how e.Routes() work and introduce e.OnAddRouteHandler callback #2337
Commits
  • f36d566 Changelog for 4.10.0
  • a69727e Mark JWT middleware deprecated
  • 0056cc8 Improve comments wording
  • 45402bb Add echo.OnAddRouteHandler field. As name says - this handler is called when ...
  • f1cf1ec Fix adding route with host overwrites default host route with same method+pat...
  • 895121d Fix rate limiter docs (#2366)
  • abecadc Merge pull request #2362 from aldas/add_govulncheck_2_ci
  • bc75cc2 Add govulncheck to CI and bump dependencies. Refactor GitHub workflows.
  • 40eb889 build: harden echo.yml permissions
  • 135c511 Add request route with "route" tag to logger middleware (#2162)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jan 30, 2023
@dependabot dependabot bot changed the base branch from main to develop January 30, 2023 09:40
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/labstack/echo/v4-4.10.0 branch from 811a4e7 to c9da425 Compare January 30, 2023 09:40
@dependabot dependabot bot temporarily deployed to staging January 30, 2023 09:44 Inactive
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/labstack/echo/v4-4.10.0 branch from c9da425 to 12ea8d9 Compare February 15, 2023 13:44
@dependabot dependabot bot temporarily deployed to staging February 15, 2023 13:48 Inactive
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/labstack/echo/v4-4.10.0 branch from 12ea8d9 to 9185b9f Compare February 15, 2023 14:05
@dependabot dependabot bot temporarily deployed to staging February 15, 2023 14:09 Inactive
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/labstack/echo/v4-4.10.0 branch 2 times, most recently from 4630395 to fd1b6eb Compare February 15, 2023 14:15
@dependabot dependabot bot temporarily deployed to staging February 15, 2023 14:19 Inactive
Bumps [github.com/labstack/echo/v4](https://github.com/labstack/echo) from 4.9.1 to 4.10.0.
- [Release notes](https://github.com/labstack/echo/releases)
- [Changelog](https://github.com/labstack/echo/blob/master/CHANGELOG.md)
- [Commits](labstack/echo@v4.9.1...v4.10.0)

---
updated-dependencies:
- dependency-name: github.com/labstack/echo/v4
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/labstack/echo/v4-4.10.0 branch from fd1b6eb to 8da296e Compare February 15, 2023 14:24
@dependabot dependabot bot temporarily deployed to staging February 15, 2023 14:27 Inactive
@ankurdotb
Copy link
Contributor

@dependabot rebase

@ankurdotb ankurdotb temporarily deployed to staging February 15, 2023 14:54 — with GitHub Actions Inactive
@ankurdotb ankurdotb changed the title build(deps): Bump github.com/labstack/echo/v4 from 4.9.1 to 4.10.0 chore(deps): Bump github.com/labstack/echo/v4 from 4.9.1 to 4.10.0 Feb 15, 2023
@ankurdotb ankurdotb merged commit bada7b5 into develop Feb 15, 2023
@ankurdotb ankurdotb deleted the dependabot/go_modules/github.com/labstack/echo/v4-4.10.0 branch February 15, 2023 14:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file go Pull requests that update Go code
Development

Successfully merging this pull request may close these issues.

1 participant