Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump github.com/golangci/golangci-lint from 1.60.1 to 1.60.3 in /tools in the tools group #1715

Merged
merged 3 commits into from
Aug 28, 2024

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Aug 26, 2024

Bumps the tools group in /tools with 1 update: github.com/golangci/golangci-lint.

Updates github.com/golangci/golangci-lint from 1.60.1 to 1.60.3

Release notes

Sourced from github.com/golangci/golangci-lint's releases.

v1.60.3

golangci-lint is a free and open-source project built by volunteers.

If you value it, consider supporting us, the maintainers and linter authors.

We appreciate it! ❤️

For key updates, see the changelog.

Changelog

  • c2e095c022a97360f7fff5d49fbc11f273be929a build(deps): bump github.com/securego/gosec/v2 from 81cda2f91fbe to ab3f6c1c83a0 (#4943)
  • f0c190436343e51e6b4dc98a368cf7bae0e5f33a feat: check that Go version use to build is greater or equals to the Go version of the project (#4938)

v1.60.2

golangci-lint is a free and open-source project built by volunteers.

If you value it, consider supporting us, the maintainers and linter authors.

We appreciate it! ❤️

For key updates, see the changelog.

Changelog

  • f338f3ef33f0f7b641100aa1fd759549cc959a8b build(deps): bump github.com/securego/gosec/v2 from 5f0084eb01a9 to 81cda2f91fbe (#4927)
  • 132d81cb5a37a48b190b3fbb58eeb7fcc754f71a build(deps): bump github.com/tomarrell/wrapcheck/v2 from 2.8.3 to 2.9.0 (#4921)
  • 15529a9d74d8b6904d7da121c6f8c96e502c070c build(deps): bump honnef.co/go/tools from 0.5.0 to 0.5.1 (#4911)
  • e24ef74f8f63de3d1a31834c2754f31b32e571c3 build(deps): bump mvdan.cc/gofumpt from 0.6.0 to 0.7.0 (#4922)
  • 87dd8fe7552a8c8374ebde29db3bda8b28055962 exportloopref: deprecation (#4916)
  • ca0b09e5e3891abef239b7c14459c6fba90e796e gosec: add G602 analyzer (#4906)
  • adbdfdb288e939a175182b7a12b7555215ce98b2 staticcheck: propagate Go version (#4907)
Changelog

Sourced from github.com/golangci/golangci-lint's changelog.

v1.60.3

  1. Updated linters
    • gosec: from 81cda2f91fbe to ab3f6c1c83a0 (fix G115 false positives)
  2. Misc.
    • Check that the Go version use to build is greater or equals to the Go version of the project

v1.60.2

  1. Updated linters
  • gofmt: update to HEAD (go1.22)
  • gofumpt: from 0.6.0 to 0.7.0
  • gosec: fix G602 analyzer
  • gosec: from 5f0084eb01a9 to 81cda2f91fbe (adds G115, G405, G406, G506, G507)
  • staticcheck: from 0.5.0 to 0.5.1
  • staticcheck: propagate Go version
  • wrapcheck: from 2.8.3 to 2.9.0
  • ⚠️ exportloopref: deprecation
Commits
  • c2e095c build(deps): bump github.com/securego/gosec/v2 from 81cda2f91fbe to ab3f6c1c8...
  • f0c1904 feat: check that Go version use to build is greater or equals to the Go versi...
  • 2f53f2c docs: update documentation (#4931)
  • 1bdd38b docs: update documentation assets (#4930)
  • 561049d docs: update GitHub Action assets (#4929)
  • f338f3e build(deps): bump github.com/securego/gosec/v2 from 5f0084eb01a9 to 81cda2f91...
  • 741df1f dev: fix GO_VERSION in post release workflow (#4926)
  • 87dd8fe exportloopref: deprecation (#4916)
  • af298e1 chore: update gofmt (#4923)
  • 132d81c build(deps): bump github.com/tomarrell/wrapcheck/v2 from 2.8.3 to 2.9.0 (#4921)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

@dependabot dependabot bot requested a review from Oats87 as a code owner August 26, 2024 17:26
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Aug 26, 2024
@tpantelis tpantelis added the lint-projects Lint consuming projects label Aug 27, 2024
@tpantelis tpantelis force-pushed the dependabot/go_modules/tools/tools-57c78af44f branch from 8e5704b to ebe92c2 Compare August 27, 2024 15:52
@tpantelis
Copy link
Contributor

I've submitted PRs in other projects to address the linting errors. This needs to be submitted first.

Copy link
Member

@skitt skitt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The description in the last commit is incorrect.

As a general rule, I prefer to describe the change in the commit message, rather than say it’s a golangci-lint fix — the fix is valid whether or not it handles an issue identified by golangci-lint. So “Fix a number of overflowing integer conversions” for example for the first commit. The third commit is golangci-lint-specific 😉

@tpantelis
Copy link
Contributor

The description in the last commit is incorrect.

As a general rule, I prefer to describe the change in the commit message, rather than say it’s a golangci-lint fix — the fix is valid whether or not it handles an issue identified by golangci-lint. So “Fix a number of overflowing integer conversions” for example for the first commit. The third commit is golangci-lint-specific 😉

There actually shouldn't have been 2 commits - not sure how that happened. I'll just combine one and three. The third commit is technically a golangci-lint fix b/c the linter is deprecated.

dependabot bot and others added 3 commits August 28, 2024 07:39
Bumps the tools group in /tools with 1 update: [github.com/golangci/golangci-lint](https://github.com/golangci/golangci-lint).


Updates `github.com/golangci/golangci-lint` from 1.60.1 to 1.60.3
- [Release notes](https://github.com/golangci/golangci-lint/releases)
- [Changelog](https://github.com/golangci/golangci-lint/blob/master/CHANGELOG.md)
- [Commits](golangci/golangci-lint@v1.60.1...v1.60.3)

---
updated-dependencies:
- dependency-name: github.com/golangci/golangci-lint
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: tools
...

Signed-off-by: dependabot[bot] <[email protected]>
Specifically, gosec "integer overflow conversion" issues.

Signed-off-by: Tom Pantelis <[email protected]>
@tpantelis tpantelis force-pushed the dependabot/go_modules/tools/tools-57c78af44f branch from ebe92c2 to 59e4750 Compare August 28, 2024 11:43
@tpantelis tpantelis merged commit 3d3c231 into devel Aug 28, 2024
45 of 50 checks passed
@dependabot dependabot bot deleted the dependabot/go_modules/tools/tools-57c78af44f branch August 28, 2024 13:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file go Pull requests that update Go code lint-projects Lint consuming projects
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants