chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.2 in /policy/slsa - #90
dependabot[bot] wants to merge 1 commit into
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Bumps [oras.land/oras-go/v2](https://github.com/oras-project/oras-go) from 2.6.0 to 2.6.2. - [Release notes](https://github.com/oras-project/oras-go/releases) - [Changelog](https://github.com/oras-project/oras-go/blob/main/RELEASES.md) - [Commits](oras-project/oras-go@v2.6.0...v2.6.2) --- updated-dependencies: - dependency-name: oras.land/oras-go/v2 dependency-version: 2.6.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
49e8e08 to
3ffac3d
Compare
|
Superseded by #101, which refreshed all six Go modules to equal or newer dependency versions and passed the full local and hosted CI suites. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps oras.land/oras-go/v2 from 2.6.0 to 2.6.2.
Release notes
Sourced from oras.land/oras-go/v2's releases.
Commits
105715erelease: v2.6.2 (#1235)31da196Merge commit from forkadab2f2Merge commit from fork948a1dcbuild(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 (#1242)c463c65fix: prevent hardlink path traversal via process CWD (GHSA-fxhp-mv3v-67qp) (#...91c04abfix(content): bound ReadAll allocation by content, not descriptor size (#1223)314e836fix: bound tag and referrer list pagination to prevent unbounded requests (#1...122e88fbuild(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 (#1208)47b7c80release: v2.6.1 (#1195)3c2e884Merge commit from fork