Skip to content

Commit

Permalink
Squashed commit of the following:
Browse files Browse the repository at this point in the history
commit ab0cb89
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Date:   Wed Aug 17 00:34:56 2022 +0100

    security(tendermint): Bump github.com/tendermint/tendermint from 0.34.19 to 0.34.20 (#367)

    * ci: Cleanup old workflow runs (#364)

    * ci: Make workflow cleanup choices easier

    * ci: Fix linting error

    * ci: Disable cleanup dry-run

    * ci: Add automated semantic release using Goreleaser (#357)

    Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    * build: Optimise Docker build (#365)

    * chore(deps): Bump github.com/spf13/viper from 1.10.1 to 1.12.0 (#360)

    Bumps github.com/spf13/viper from 1.10.1 to 1.12.0.

    Release notes
    Sourced from github.com/spf13/viper's releases.

    v1.12.0
    This release makes YAML v3 and TOML v2 the default versions used for encoding.
    You can switch back to the old versions by adding viper_yaml2 and viper_toml1 to the build tags.
    Please note that YAML v2 and TOML v1 are considered deprecated from this release and may be removed in a future release.
    Please provide feedback in discussions and report bugs on the issue tracker. Thanks!

    What's Changed
    Exciting New Features 🎉

    Add etcd3 support to remote by @​sagikazarmark in spf13/viper#1356
    Make YAML 3 the default by @​sagikazarmark in spf13/viper#1357
    Make TOML 2 the default by @​sagikazarmark in spf13/viper#1358

    Enhancements 🚀

    chore: fix Error log calls in mergeMaps by @​wwade in spf13/viper#1341
    Add MustBindEnv by @​meowfaceman in spf13/viper#1301

    Dependency Updates ⬆️

    build(deps): bump github/codeql-action from 1 to 2 by @​dependabot in spf13/viper#1336
    build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0-beta.8 to 2.0.0 by @​dependabot in spf13/viper#1339
    build(deps): bump github.com/mitchellh/mapstructure from 1.4.3 to 1.5.0 by @​dependabot in spf13/viper#1332
    build(deps): bump github.com/pelletier/go-toml from 1.9.4 to 1.9.5 by @​dependabot in spf13/viper#1335
    build(deps): bump github.com/fsnotify/fsnotify from 1.5.1 to 1.5.4 by @​dependabot in spf13/viper#1338
    build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0 by @​dependabot in spf13/viper#1344
    build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1 by @​dependabot in spf13/viper#1343
    build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0 by @​dependabot in spf13/viper#1349

    New Contributors

    @​meowfaceman made their first contribution in spf13/viper#1301
    @​wwade made their first contribution in spf13/viper#1341

    Full Changelog: spf13/viper@v1.11.0...v1.12.0
    v1.11.0

    What's Changed
    Exciting New Features 🎉

    Experimental yaml v3 library support by @​sagikazarmark in spf13/viper#1273
    Experimental toml v2 support by @​sagikazarmark in spf13/viper#1274
    Experimental logger by @​sagikazarmark in spf13/viper#1275

    Enhancements 🚀

    Remove unnecessary operand by @​steviebps in spf13/viper#1213
    Improve encoding layer by @​sagikazarmark in spf13/viper#1167
    Allow merging configs with different types of leaf values by @​illarion in spf13/viper#1181

    Bug Fixes 🐛

    Disable race detector on windows by @​sagikazarmark in spf13/viper#1269

    ... (truncated)

    Commits

    4322cf2 feat: make toml2 the default
    8d02999 feat: make yaml3 the default
    7c35aa9 chore(deps): update yaml3
    433821f feat: add etcd3 support to remote
    2080d43 chore: update crypt
    da55858 chore: fix Error log calls in mergeMaps
    f50ce90 Add in MustBindEnv.
    3b836e5 build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0
    5d65186 build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1
    9f85518 build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0
    Additional commits viewable in compare view

    Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

    Dependabot commands and options

    You can trigger Dependabot actions by commenting on this PR:

    @dependabot rebase will rebase this PR
    @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
    @dependabot merge will merge this PR after your CI passes on it
    @dependabot squash and merge will squash and merge this PR after your CI passes on it
    @dependabot cancel merge will cancel a previously requested merge and block automerging
    @dependabot reopen will reopen this PR if it is closed
    @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
    @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
    @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
    @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    * chore(deps): Bump github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25 (#359)

    Bumps github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25.

    Release notes
    Sourced from github.com/lestrrat-go/jwx's releases.

    v1.2.25
    v1.2.25 23 May 2022
    [Bug Fixes][Security]
      * [jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
        where the unpad operation might remove more bytes than necessary ([#744](lestrrat-go/jwx#744))
        This affects all jwx code that is available before v2.0.2 and v1.2.25.

    v1.2.24
    v1.2.24 05 May 2022
    [Security]
      * Upgrade golang.org/x/crypto ([#724](lestrrat-go/jwx#724))

    v1.2.23
    v1.2.23 13 Apr 2022
    [Bug fixes]
      * [jwk] jwk.AutoRefresh had a race condition when `Configure()` was
        called concurrently ([#686](lestrrat-go/jwx#686))
        (It has been patched correctly, but we may come back to revisit
         the design choices in the near future)

    v1.2.22
    v1.2.22 08 Apr 2022
    [Bug fixes]
      * [jws] jws.Verify was ignoring the `b64` header when it was present
        in the protected headers ([#681](lestrrat-go/jwx#681)). Now the following should work:
      jws.Sign(..., jws.WithDetachedPayload(payload))
      // previously payload had to be base64 encoded
      jws.Verify(..., jws.WithDetachedPayload(payload))
    (note: v2 branch was not affected)

    v1.2.21
    v1.2.21 30 Mar 2022
    [Bug fixes]
      * [jwk] RSA keys without p and q can now be parsed.

    Changelog
    Sourced from github.com/lestrrat-go/jwx's changelog.

    v1.2.25 23 May 2022
    [Bug Fixes][Security]

    [jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
    where the unpad operation might remove more bytes than necessary (#744)
    This affects all jwx code that is available before v2.0.2 and v1.2.25.

    v1.2.24 05 May 2022
    [Security]

    Upgrade golang.org/x/crypto (#724)

    v1.2.23 13 Apr 2022
    [Bug fixes]

    [jwk] jwk.AutoRefresh had a race condition when Configure() was
    called concurrently (#686)
    (It has been patched correctly, but we may come back to revisit
    the design choices in the near future)

    v1.2.22 08 Apr 2022
    [Bug fixes]

    [jws] jws.Verify was ignoring the b64 header when it was present
    in the protected headers (#681). Now the following should work:
    jws.Sign(..., jws.WithDetachedPayload(payload))
    // previously payload had to be base64 encoded
    jws.Verify(..., jws.WithDetachedPayload(payload))
    (note: v2 branch was not affected)

    v1.2.21 30 Mar 2022
    [Bug fixes]

    [jwk] RSA keys without p and q can now be parsed.

    Commits

    ad8c29d merge develop/v1 (#747)
    e38f677 Merge develop/v1 (#727)
    baba561 Merge branch 'develop/v1' into v1
    8ff6c75 Update Changes
    ea97e8c Fix race in jwk.AutoRefresh (#686)
    f4701e1 Update Changes
    e831228 Fix jws.Verify not respecting the b64 header in the protected headers (#683)
    b66a2cb backport: Update golangci lint (#679) (#680)
    4899c32 reword error
    dd9e4c4 Bump github.com/lestrrat-go/httpcc from 1.0.0 to 1.0.1 (#675)
    Additional commits viewable in compare view

    Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

    Dependabot commands and options

    You can trigger Dependabot actions by commenting on this PR:

    @dependabot rebase will rebase this PR
    @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
    @dependabot merge will merge this PR after your CI passes on it
    @dependabot squash and merge will squash and merge this PR after your CI passes on it
    @dependabot cancel merge will cancel a previously requested merge and block automerging
    @dependabot reopen will reopen this PR if it is closed
    @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
    @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
    @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
    @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    * chore(deps): Bump github.com/stretchr/testify from 1.7.1 to 1.8.0 (#362)

    Bumps github.com/stretchr/testify from 1.7.1 to 1.8.0.

    Commits

    181cea6 impr: CallerInfo should print full paths to the terminal (#1201)
    cf1284f Allow mock expectations to be ordered (#1106)
    66eef0e fix: assert.MapSubset (or just support maps in assert.Subset) (#1178)
    2fab6df Add WithinTimeRange method (#1188)
    b5ce165 fixing panic in calls to assertion with nil m.mutex (#1212)
    c206b2e Mock can be deadlocked by a panic (#1157)
    1b73601 suite: correctly set stats on test panic (#1195)
    ba1076d Add .Unset method to mock (#982)
    c31ea03 Support comparing byte slice (#1202)
    48391ba Fix panic in AssertExpectations for mocks without expectations (#1207)
    Additional commits viewable in compare view

    Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

    Dependabot commands and options

    You can trigger Dependabot actions by commenting on this PR:

    @dependabot rebase will rebase this PR
    @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
    @dependabot merge will merge this PR after your CI passes on it
    @dependabot squash and merge will squash and merge this PR after your CI passes on it
    @dependabot cancel merge will cancel a previously requested merge and block automerging
    @dependabot reopen will reopen this PR if it is closed
    @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
    @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
    @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
    @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    * build: Multi-platform AMD64/ARM64 for Linux (#366)

    Signed-off-by: Andrew Nikitin <andrew.nikitin@evernym.com>
    Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    * ci: Fix CodeQL Golang version

    * chore(deps): Bump github.com/multiformats/go-multibase from 0.0.3 to 0.1.1 (#371)

    * chore(deps): Bump github.com/multiformats/go-multibase

    Bumps [github.com/multiformats/go-multibase](https://github.com/multiformats/go-multibase) from 0.0.3 to 0.1.1.
    - [Release notes](https://github.com/multiformats/go-multibase/releases)
    - [Commits](multiformats/go-multibase@v0.0.3...v0.1.1)

    ---
    updated-dependencies:
    - dependency-name: github.com/multiformats/go-multibase
      dependency-type: direct:production
      update-type: version-update:semver-minor
    ...

    Signed-off-by: dependabot[bot] <support@github.com>

    * chore(deps): Bump github.com/multiformats/go-multibase

    Bumps [github.com/multiformats/go-multibase](https://github.com/multiformats/go-multibase) from 0.0.3 to 0.1.1.
    - [Release notes](https://github.com/multiformats/go-multibase/releases)
    - [Commits](multiformats/go-multibase@v0.0.3...v0.1.1)

    ---
    updated-dependencies:
    - dependency-name: github.com/multiformats/go-multibase
      dependency-type: direct:production
      update-type: version-update:semver-minor
    ...

    Signed-off-by: dependabot[bot] <support@github.com>

    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    * chore(deps): Bump github.com/gabriel-vasile/mimetype from 1.4.0 to 1.4.1 (#370)

    Bumps [github.com/gabriel-vasile/mimetype](https://github.com/gabriel-vasile/mimetype) from 1.4.0 to 1.4.1.
    - [Release notes](https://github.com/gabriel-vasile/mimetype/releases)
    - [Commits](gabriel-vasile/mimetype@v1.4.0...v1.4.1)

    ---
    updated-dependencies:
    - dependency-name: github.com/gabriel-vasile/mimetype
      dependency-type: direct:production
      update-type: version-update:semver-patch
    ...

    Signed-off-by: dependabot[bot] <support@github.com>

    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

    * chore(deps): Bump github.com/tendermint/tendermint

    Bumps [github.com/tendermint/tendermint](https://github.com/tendermint/tendermint) from 0.34.19 to 0.34.20.
    - [Release notes](https://github.com/tendermint/tendermint/releases)
    - [Changelog](https://github.com/tendermint/tendermint/blob/main/CHANGELOG.md)
    - [Commits](tendermint/tendermint@v0.34.19...v0.34.20)

    ---
    updated-dependencies:
    - dependency-name: github.com/tendermint/tendermint
      dependency-type: direct:production
      update-type: version-update:semver-patch
    ...

    Signed-off-by: dependabot[bot] <support@github.com>

    Signed-off-by: dependabot[bot] <support@github.com>
    Signed-off-by: Andrew Nikitin <andrew.nikitin@evernym.com>
    Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>
    Co-authored-by: Andrew Nikitin <andrew.nikitin@cheqd.io>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

commit f7b2d4f
Author: Ankur Banerjee <ankurdotb@users.noreply.github.com>
Date:   Tue Aug 16 22:21:43 2022 +0100

    Squashed commit of the following:

    commit 48d1512
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Tue Aug 16 22:09:31 2022 +0100

        chore(deps): Bump github.com/gabriel-vasile/mimetype from 1.4.0 to 1.4.1 (#370)

        Bumps [github.com/gabriel-vasile/mimetype](https://github.com/gabriel-vasile/mimetype) from 1.4.0 to 1.4.1.
        - [Release notes](https://github.com/gabriel-vasile/mimetype/releases)
        - [Commits](gabriel-vasile/mimetype@v1.4.0...v1.4.1)

        ---
        updated-dependencies:
        - dependency-name: github.com/gabriel-vasile/mimetype
          dependency-type: direct:production
          update-type: version-update:semver-patch
        ...

        Signed-off-by: dependabot[bot] <support@github.com>

        Signed-off-by: dependabot[bot] <support@github.com>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

    commit 1bd0801
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Tue Aug 16 21:10:29 2022 +0100

        chore(deps): Bump github.com/multiformats/go-multibase from 0.0.3 to 0.1.1 (#371)

        * chore(deps): Bump github.com/multiformats/go-multibase

        Bumps [github.com/multiformats/go-multibase](https://github.com/multiformats/go-multibase) from 0.0.3 to 0.1.1.
        - [Release notes](https://github.com/multiformats/go-multibase/releases)
        - [Commits](multiformats/go-multibase@v0.0.3...v0.1.1)

        ---
        updated-dependencies:
        - dependency-name: github.com/multiformats/go-multibase
          dependency-type: direct:production
          update-type: version-update:semver-minor
        ...

        Signed-off-by: dependabot[bot] <support@github.com>

        * chore(deps): Bump github.com/multiformats/go-multibase

        Bumps [github.com/multiformats/go-multibase](https://github.com/multiformats/go-multibase) from 0.0.3 to 0.1.1.
        - [Release notes](https://github.com/multiformats/go-multibase/releases)
        - [Commits](multiformats/go-multibase@v0.0.3...v0.1.1)

        ---
        updated-dependencies:
        - dependency-name: github.com/multiformats/go-multibase
          dependency-type: direct:production
          update-type: version-update:semver-minor
        ...

        Signed-off-by: dependabot[bot] <support@github.com>

        Signed-off-by: dependabot[bot] <support@github.com>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
        Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    commit 4b2da73
    Author: Ankur Banerjee <ankurdotb@users.noreply.github.com>
    Date:   Tue Aug 16 17:06:51 2022 +0100

        ci: Fix CodeQL Golang version

    commit 2fc6ae5
    Author: Andrew Nikitin <andrew.nikitin@cheqd.io>
    Date:   Tue Aug 16 15:48:13 2022 +0300

        build: Multi-platform AMD64/ARM64 for Linux (#366)

        Signed-off-by: Andrew Nikitin <andrew.nikitin@evernym.com>
        Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    commit 7485eb2
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Mon Aug 15 15:37:31 2022 +0100

        chore(deps): Bump github.com/stretchr/testify from 1.7.1 to 1.8.0 (#362)

        Bumps github.com/stretchr/testify from 1.7.1 to 1.8.0.

        Commits

        181cea6 impr: CallerInfo should print full paths to the terminal (#1201)
        cf1284f Allow mock expectations to be ordered (#1106)
        66eef0e fix: assert.MapSubset (or just support maps in assert.Subset) (#1178)
        2fab6df Add WithinTimeRange method (#1188)
        b5ce165 fixing panic in calls to assertion with nil m.mutex (#1212)
        c206b2e Mock can be deadlocked by a panic (#1157)
        1b73601 suite: correctly set stats on test panic (#1195)
        ba1076d Add .Unset method to mock (#982)
        c31ea03 Support comparing byte slice (#1202)
        48391ba Fix panic in AssertExpectations for mocks without expectations (#1207)
        Additional commits viewable in compare view

        Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

        Dependabot commands and options

        You can trigger Dependabot actions by commenting on this PR:

        @dependabot rebase will rebase this PR
        @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
        @dependabot merge will merge this PR after your CI passes on it
        @dependabot squash and merge will squash and merge this PR after your CI passes on it
        @dependabot cancel merge will cancel a previously requested merge and block automerging
        @dependabot reopen will reopen this PR if it is closed
        @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
        @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

        Signed-off-by: dependabot[bot] <support@github.com>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
        Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    commit 1e3e807
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Mon Aug 15 15:14:40 2022 +0100

        chore(deps): Bump github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25 (#359)

        Bumps github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25.

        Release notes
        Sourced from github.com/lestrrat-go/jwx's releases.

        v1.2.25
        v1.2.25 23 May 2022
        [Bug Fixes][Security]
          * [jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
            where the unpad operation might remove more bytes than necessary ([#744](lestrrat-go/jwx#744))
            This affects all jwx code that is available before v2.0.2 and v1.2.25.

        v1.2.24
        v1.2.24 05 May 2022
        [Security]
          * Upgrade golang.org/x/crypto ([#724](lestrrat-go/jwx#724))

        v1.2.23
        v1.2.23 13 Apr 2022
        [Bug fixes]
          * [jwk] jwk.AutoRefresh had a race condition when `Configure()` was
            called concurrently ([#686](lestrrat-go/jwx#686))
            (It has been patched correctly, but we may come back to revisit
             the design choices in the near future)

        v1.2.22
        v1.2.22 08 Apr 2022
        [Bug fixes]
          * [jws] jws.Verify was ignoring the `b64` header when it was present
            in the protected headers ([#681](lestrrat-go/jwx#681)). Now the following should work:
          jws.Sign(..., jws.WithDetachedPayload(payload))
          // previously payload had to be base64 encoded
          jws.Verify(..., jws.WithDetachedPayload(payload))
        (note: v2 branch was not affected)

        v1.2.21
        v1.2.21 30 Mar 2022
        [Bug fixes]
          * [jwk] RSA keys without p and q can now be parsed.

        Changelog
        Sourced from github.com/lestrrat-go/jwx's changelog.

        v1.2.25 23 May 2022
        [Bug Fixes][Security]

        [jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
        where the unpad operation might remove more bytes than necessary (#744)
        This affects all jwx code that is available before v2.0.2 and v1.2.25.

        v1.2.24 05 May 2022
        [Security]

        Upgrade golang.org/x/crypto (#724)

        v1.2.23 13 Apr 2022
        [Bug fixes]

        [jwk] jwk.AutoRefresh had a race condition when Configure() was
        called concurrently (#686)
        (It has been patched correctly, but we may come back to revisit
        the design choices in the near future)

        v1.2.22 08 Apr 2022
        [Bug fixes]

        [jws] jws.Verify was ignoring the b64 header when it was present
        in the protected headers (#681). Now the following should work:
        jws.Sign(..., jws.WithDetachedPayload(payload))
        // previously payload had to be base64 encoded
        jws.Verify(..., jws.WithDetachedPayload(payload))
        (note: v2 branch was not affected)

        v1.2.21 30 Mar 2022
        [Bug fixes]

        [jwk] RSA keys without p and q can now be parsed.

        Commits

        ad8c29d merge develop/v1 (#747)
        e38f677 Merge develop/v1 (#727)
        baba561 Merge branch 'develop/v1' into v1
        8ff6c75 Update Changes
        ea97e8c Fix race in jwk.AutoRefresh (#686)
        f4701e1 Update Changes
        e831228 Fix jws.Verify not respecting the b64 header in the protected headers (#683)
        b66a2cb backport: Update golangci lint (#679) (#680)
        4899c32 reword error
        dd9e4c4 Bump github.com/lestrrat-go/httpcc from 1.0.0 to 1.0.1 (#675)
        Additional commits viewable in compare view

        Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

        Dependabot commands and options

        You can trigger Dependabot actions by commenting on this PR:

        @dependabot rebase will rebase this PR
        @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
        @dependabot merge will merge this PR after your CI passes on it
        @dependabot squash and merge will squash and merge this PR after your CI passes on it
        @dependabot cancel merge will cancel a previously requested merge and block automerging
        @dependabot reopen will reopen this PR if it is closed
        @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
        @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

        Signed-off-by: dependabot[bot] <support@github.com>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
        Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    commit a56cfeb
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Mon Aug 15 14:50:56 2022 +0100

        chore(deps): Bump github.com/spf13/viper from 1.10.1 to 1.12.0 (#360)

        Bumps github.com/spf13/viper from 1.10.1 to 1.12.0.

        Release notes
        Sourced from github.com/spf13/viper's releases.

        v1.12.0
        This release makes YAML v3 and TOML v2 the default versions used for encoding.
        You can switch back to the old versions by adding viper_yaml2 and viper_toml1 to the build tags.
        Please note that YAML v2 and TOML v1 are considered deprecated from this release and may be removed in a future release.
        Please provide feedback in discussions and report bugs on the issue tracker. Thanks!

        What's Changed
        Exciting New Features 🎉

        Add etcd3 support to remote by @​sagikazarmark in spf13/viper#1356
        Make YAML 3 the default by @​sagikazarmark in spf13/viper#1357
        Make TOML 2 the default by @​sagikazarmark in spf13/viper#1358

        Enhancements 🚀

        chore: fix Error log calls in mergeMaps by @​wwade in spf13/viper#1341
        Add MustBindEnv by @​meowfaceman in spf13/viper#1301

        Dependency Updates ⬆️

        build(deps): bump github/codeql-action from 1 to 2 by @​dependabot in spf13/viper#1336
        build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0-beta.8 to 2.0.0 by @​dependabot in spf13/viper#1339
        build(deps): bump github.com/mitchellh/mapstructure from 1.4.3 to 1.5.0 by @​dependabot in spf13/viper#1332
        build(deps): bump github.com/pelletier/go-toml from 1.9.4 to 1.9.5 by @​dependabot in spf13/viper#1335
        build(deps): bump github.com/fsnotify/fsnotify from 1.5.1 to 1.5.4 by @​dependabot in spf13/viper#1338
        build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0 by @​dependabot in spf13/viper#1344
        build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1 by @​dependabot in spf13/viper#1343
        build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0 by @​dependabot in spf13/viper#1349

        New Contributors

        @​meowfaceman made their first contribution in spf13/viper#1301
        @​wwade made their first contribution in spf13/viper#1341

        Full Changelog: spf13/viper@v1.11.0...v1.12.0
        v1.11.0

        What's Changed
        Exciting New Features 🎉

        Experimental yaml v3 library support by @​sagikazarmark in spf13/viper#1273
        Experimental toml v2 support by @​sagikazarmark in spf13/viper#1274
        Experimental logger by @​sagikazarmark in spf13/viper#1275

        Enhancements 🚀

        Remove unnecessary operand by @​steviebps in spf13/viper#1213
        Improve encoding layer by @​sagikazarmark in spf13/viper#1167
        Allow merging configs with different types of leaf values by @​illarion in spf13/viper#1181

        Bug Fixes 🐛

        Disable race detector on windows by @​sagikazarmark in spf13/viper#1269

        ... (truncated)

        Commits

        4322cf2 feat: make toml2 the default
        8d02999 feat: make yaml3 the default
        7c35aa9 chore(deps): update yaml3
        433821f feat: add etcd3 support to remote
        2080d43 chore: update crypt
        da55858 chore: fix Error log calls in mergeMaps
        f50ce90 Add in MustBindEnv.
        3b836e5 build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0
        5d65186 build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1
        9f85518 build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0
        Additional commits viewable in compare view

        Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

        Dependabot commands and options

        You can trigger Dependabot actions by commenting on this PR:

        @dependabot rebase will rebase this PR
        @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
        @dependabot merge will merge this PR after your CI passes on it
        @dependabot squash and merge will squash and merge this PR after your CI passes on it
        @dependabot cancel merge will cancel a previously requested merge and block automerging
        @dependabot reopen will reopen this PR if it is closed
        @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
        @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

        Signed-off-by: dependabot[bot] <support@github.com>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
        Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    commit a5aef25
    Author: Ankur Banerjee <ankurdotb@users.noreply.github.com>
    Date:   Mon Aug 15 10:44:13 2022 +0100

        build: Optimise Docker build (#365)

    commit 4517a19
    Author: Andrew Nikitin <andrew.nikitin@cheqd.io>
    Date:   Sat Aug 13 03:55:47 2022 +0300

        ci: Add automated semantic release using Goreleaser (#357)

        Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    commit 5a30740
    Author: Ankur Banerjee <ankurdotb@users.noreply.github.com>
    Date:   Sat Aug 13 01:53:06 2022 +0100

        ci: Disable cleanup dry-run

    commit 3e8aea4
    Author: Ankur Banerjee <ankurdotb@users.noreply.github.com>
    Date:   Sat Aug 13 01:42:43 2022 +0100

        ci: Fix linting error

    commit c335aba
    Author: Ankur Banerjee <ankurdotb@users.noreply.github.com>
    Date:   Sat Aug 13 01:38:00 2022 +0100

        ci: Make workflow cleanup choices easier

    commit d89f496
    Author: Ankur Banerjee <ankurdotb@users.noreply.github.com>
    Date:   Sat Aug 13 01:29:14 2022 +0100

        ci: Cleanup old workflow runs (#364)

commit ed9b26f
Author: Ankur Banerjee <ankurdotb@users.noreply.github.com>
Date:   Tue Aug 16 17:02:09 2022 +0100

    Squashed commit of the following:

    commit 2fc6ae5
    Author: Andrew Nikitin <andrew.nikitin@cheqd.io>
    Date:   Tue Aug 16 15:48:13 2022 +0300

        build: Multi-platform AMD64/ARM64 for Linux (#366)

        Signed-off-by: Andrew Nikitin <andrew.nikitin@evernym.com>
        Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    commit 7485eb2
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Mon Aug 15 15:37:31 2022 +0100

        chore(deps): Bump github.com/stretchr/testify from 1.7.1 to 1.8.0 (#362)

        Bumps github.com/stretchr/testify from 1.7.1 to 1.8.0.

        Commits

        181cea6 impr: CallerInfo should print full paths to the terminal (#1201)
        cf1284f Allow mock expectations to be ordered (#1106)
        66eef0e fix: assert.MapSubset (or just support maps in assert.Subset) (#1178)
        2fab6df Add WithinTimeRange method (#1188)
        b5ce165 fixing panic in calls to assertion with nil m.mutex (#1212)
        c206b2e Mock can be deadlocked by a panic (#1157)
        1b73601 suite: correctly set stats on test panic (#1195)
        ba1076d Add .Unset method to mock (#982)
        c31ea03 Support comparing byte slice (#1202)
        48391ba Fix panic in AssertExpectations for mocks without expectations (#1207)
        Additional commits viewable in compare view

        Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

        Dependabot commands and options

        You can trigger Dependabot actions by commenting on this PR:

        @dependabot rebase will rebase this PR
        @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
        @dependabot merge will merge this PR after your CI passes on it
        @dependabot squash and merge will squash and merge this PR after your CI passes on it
        @dependabot cancel merge will cancel a previously requested merge and block automerging
        @dependabot reopen will reopen this PR if it is closed
        @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
        @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

        Signed-off-by: dependabot[bot] <support@github.com>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
        Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    commit 1e3e807
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Mon Aug 15 15:14:40 2022 +0100

        chore(deps): Bump github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25 (#359)

        Bumps github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25.

        Release notes
        Sourced from github.com/lestrrat-go/jwx's releases.

        v1.2.25
        v1.2.25 23 May 2022
        [Bug Fixes][Security]
          * [jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
            where the unpad operation might remove more bytes than necessary ([#744](lestrrat-go/jwx#744))
            This affects all jwx code that is available before v2.0.2 and v1.2.25.

        v1.2.24
        v1.2.24 05 May 2022
        [Security]
          * Upgrade golang.org/x/crypto ([#724](lestrrat-go/jwx#724))

        v1.2.23
        v1.2.23 13 Apr 2022
        [Bug fixes]
          * [jwk] jwk.AutoRefresh had a race condition when `Configure()` was
            called concurrently ([#686](lestrrat-go/jwx#686))
            (It has been patched correctly, but we may come back to revisit
             the design choices in the near future)

        v1.2.22
        v1.2.22 08 Apr 2022
        [Bug fixes]
          * [jws] jws.Verify was ignoring the `b64` header when it was present
            in the protected headers ([#681](lestrrat-go/jwx#681)). Now the following should work:
          jws.Sign(..., jws.WithDetachedPayload(payload))
          // previously payload had to be base64 encoded
          jws.Verify(..., jws.WithDetachedPayload(payload))
        (note: v2 branch was not affected)

        v1.2.21
        v1.2.21 30 Mar 2022
        [Bug fixes]
          * [jwk] RSA keys without p and q can now be parsed.

        Changelog
        Sourced from github.com/lestrrat-go/jwx's changelog.

        v1.2.25 23 May 2022
        [Bug Fixes][Security]

        [jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
        where the unpad operation might remove more bytes than necessary (#744)
        This affects all jwx code that is available before v2.0.2 and v1.2.25.

        v1.2.24 05 May 2022
        [Security]

        Upgrade golang.org/x/crypto (#724)

        v1.2.23 13 Apr 2022
        [Bug fixes]

        [jwk] jwk.AutoRefresh had a race condition when Configure() was
        called concurrently (#686)
        (It has been patched correctly, but we may come back to revisit
        the design choices in the near future)

        v1.2.22 08 Apr 2022
        [Bug fixes]

        [jws] jws.Verify was ignoring the b64 header when it was present
        in the protected headers (#681). Now the following should work:
        jws.Sign(..., jws.WithDetachedPayload(payload))
        // previously payload had to be base64 encoded
        jws.Verify(..., jws.WithDetachedPayload(payload))
        (note: v2 branch was not affected)

        v1.2.21 30 Mar 2022
        [Bug fixes]

        [jwk] RSA keys without p and q can now be parsed.

        Commits

        ad8c29d merge develop/v1 (#747)
        e38f677 Merge develop/v1 (#727)
        baba561 Merge branch 'develop/v1' into v1
        8ff6c75 Update Changes
        ea97e8c Fix race in jwk.AutoRefresh (#686)
        f4701e1 Update Changes
        e831228 Fix jws.Verify not respecting the b64 header in the protected headers (#683)
        b66a2cb backport: Update golangci lint (#679) (#680)
        4899c32 reword error
        dd9e4c4 Bump github.com/lestrrat-go/httpcc from 1.0.0 to 1.0.1 (#675)
        Additional commits viewable in compare view

        Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

        Dependabot commands and options

        You can trigger Dependabot actions by commenting on this PR:

        @dependabot rebase will rebase this PR
        @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
        @dependabot merge will merge this PR after your CI passes on it
        @dependabot squash and merge will squash and merge this PR after your CI passes on it
        @dependabot cancel merge will cancel a previously requested merge and block automerging
        @dependabot reopen will reopen this PR if it is closed
        @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
        @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

        Signed-off-by: dependabot[bot] <support@github.com>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
        Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    commit a56cfeb
    Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Date:   Mon Aug 15 14:50:56 2022 +0100

        chore(deps): Bump github.com/spf13/viper from 1.10.1 to 1.12.0 (#360)

        Bumps github.com/spf13/viper from 1.10.1 to 1.12.0.

        Release notes
        Sourced from github.com/spf13/viper's releases.

        v1.12.0
        This release makes YAML v3 and TOML v2 the default versions used for encoding.
        You can switch back to the old versions by adding viper_yaml2 and viper_toml1 to the build tags.
        Please note that YAML v2 and TOML v1 are considered deprecated from this release and may be removed in a future release.
        Please provide feedback in discussions and report bugs on the issue tracker. Thanks!

        What's Changed
        Exciting New Features 🎉

        Add etcd3 support to remote by @​sagikazarmark in spf13/viper#1356
        Make YAML 3 the default by @​sagikazarmark in spf13/viper#1357
        Make TOML 2 the default by @​sagikazarmark in spf13/viper#1358

        Enhancements 🚀

        chore: fix Error log calls in mergeMaps by @​wwade in spf13/viper#1341
        Add MustBindEnv by @​meowfaceman in spf13/viper#1301

        Dependency Updates ⬆️

        build(deps): bump github/codeql-action from 1 to 2 by @​dependabot in spf13/viper#1336
        build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0-beta.8 to 2.0.0 by @​dependabot in spf13/viper#1339
        build(deps): bump github.com/mitchellh/mapstructure from 1.4.3 to 1.5.0 by @​dependabot in spf13/viper#1332
        build(deps): bump github.com/pelletier/go-toml from 1.9.4 to 1.9.5 by @​dependabot in spf13/viper#1335
        build(deps): bump github.com/fsnotify/fsnotify from 1.5.1 to 1.5.4 by @​dependabot in spf13/viper#1338
        build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0 by @​dependabot in spf13/viper#1344
        build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1 by @​dependabot in spf13/viper#1343
        build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0 by @​dependabot in spf13/viper#1349

        New Contributors

        @​meowfaceman made their first contribution in spf13/viper#1301
        @​wwade made their first contribution in spf13/viper#1341

        Full Changelog: spf13/viper@v1.11.0...v1.12.0
        v1.11.0

        What's Changed
        Exciting New Features 🎉

        Experimental yaml v3 library support by @​sagikazarmark in spf13/viper#1273
        Experimental toml v2 support by @​sagikazarmark in spf13/viper#1274
        Experimental logger by @​sagikazarmark in spf13/viper#1275

        Enhancements 🚀

        Remove unnecessary operand by @​steviebps in spf13/viper#1213
        Improve encoding layer by @​sagikazarmark in spf13/viper#1167
        Allow merging configs with different types of leaf values by @​illarion in spf13/viper#1181

        Bug Fixes 🐛

        Disable race detector on windows by @​sagikazarmark in spf13/viper#1269

        ... (truncated)

        Commits

        4322cf2 feat: make toml2 the default
        8d02999 feat: make yaml3 the default
        7c35aa9 chore(deps): update yaml3
        433821f feat: add etcd3 support to remote
        2080d43 chore: update crypt
        da55858 chore: fix Error log calls in mergeMaps
        f50ce90 Add in MustBindEnv.
        3b836e5 build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0
        5d65186 build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1
        9f85518 build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0
        Additional commits viewable in compare view

        Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

        Dependabot commands and options

        You can trigger Dependabot actions by commenting on this PR:

        @dependabot rebase will rebase this PR
        @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
        @dependabot merge will merge this PR after your CI passes on it
        @dependabot squash and merge will squash and merge this PR after your CI passes on it
        @dependabot cancel merge will cancel a previously requested merge and block automerging
        @dependabot reopen will reopen this PR if it is closed
        @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
        @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
        @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

        Signed-off-by: dependabot[bot] <support@github.com>
        Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
        Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    commit a5aef25
    Author: Ankur Banerjee <ankurdotb@users.noreply.github.com>
    Date:   Mon Aug 15 10:44:13 2022 +0100

        build: Optimise Docker build (#365)

    commit 4517a19
    Author: Andrew Nikitin <andrew.nikitin@cheqd.io>
    Date:   Sat Aug 13 03:55:47 2022 +0300

        ci: Add automated semantic release using Goreleaser (#357)

        Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

    commit 5a30740
    Author: Ankur Banerjee <ankurdotb@users.noreply.github.com>
    Date:   Sat Aug 13 01:53:06 2022 +0100

        ci: Disable cleanup dry-run

    commit 3e8aea4
    Author: Ankur Banerjee <ankurdotb@users.noreply.github.com>
    Date:   Sat Aug 13 01:42:43 2022 +0100

        ci: Fix linting error

    commit c335aba
    Author: Ankur Banerjee <ankurdotb@users.noreply.github.com>
    Date:   Sat Aug 13 01:38:00 2022 +0100

        ci: Make workflow cleanup choices easier

    commit d89f496
    Author: Ankur Banerjee <ankurdotb@users.noreply.github.com>
    Date:   Sat Aug 13 01:29:14 2022 +0100

        ci: Cleanup old workflow runs (#364)
  • Loading branch information
ankurdotb committed Aug 16, 2022
1 parent fe65baf commit 9e24671
Show file tree
Hide file tree
Showing 7 changed files with 499 additions and 70 deletions.
3 changes: 2 additions & 1 deletion .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,13 +20,14 @@ jobs:
- uses: actions/setup-go@v3
with:
go-version-file: ./go.mod
cache: true

- name: Run GoReleaser
uses: goreleaser/goreleaser-action@v3
with:
distribution: goreleaser
version: latest
args: build --rm-dist --snapshot --single-target
args: build --rm-dist --snapshot --id ubuntu-latest-amd64

- name: Store artifact
uses: actions/upload-artifact@v3
Expand Down
5 changes: 2 additions & 3 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,15 +31,14 @@ jobs:

- uses: actions/setup-go@v3
with:
go-version-file: ./go.mod
go-version: 1.17

- uses: actions/checkout@v3
with:
fetch-depth: 0 # Required to fetch version

- name: Build
run: |
make proto-gen build
run: make proto-gen build

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v2
3 changes: 0 additions & 3 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -112,9 +112,6 @@ jobs:
tags: |
type=semver,pattern={{version}},value=${{ needs.release-binary.outputs.RELEASE_VERSION }}
labels: |
org.opencontainers.image.title="cheqd Node Docker Image"
org.opencontainers.image.description="Node for cheqd network"
org.opencontainers.image.source="https://github.com/cheqd/cheqd-node"
org.opencontainers.image.vendor="Cheqd Foundation Limited"
org.opencontainers.image.created={{date 'dddd, MMMM Do YYYY, h:mm:ss a'}}
org.opencontainers.image.documentation="https://docs.cheqd.io/node"
Expand Down
36 changes: 24 additions & 12 deletions .goreleaser.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,17 +10,36 @@ before:
- make clean
- go mod tidy
- go mod download
- make proto-gen

builds:
- id: cheqd-linux
- id: ubuntu-latest-amd64
main: ./cmd/cheqd-noded
binary: cheqd-noded
targets:
- "linux_amd64"
env:
- CGO_ENABLED=1
flags:
- -mod=readonly
- -tags="netgo ledger"
- -trimpath
ldflags:
- -s -w
- -X github.com/cosmos/cosmos-sdk/version.Name=cheqd-noded
- -X github.com/cosmos/cosmos-sdk/version.AppName=cheqd-noded
- -X github.com/cosmos/cosmos-sdk/version.Version={{ .Version }}
- -X github.com/cosmos/cosmos-sdk/version.Commit={{ .Commit }}
- -X github.com/cosmos/cosmos-sdk/version.BuildTags=netgo,ledger,goleveldb

- id: ubuntu-latest-arm64
main: ./cmd/cheqd-noded
binary: cheqd-noded
targets:
- linux_amd64
- "linux_arm64"
hooks:
pre: make proto-gen
pre:
- sudo apt update && sudo apt install clang gcc-multilib g++-multilib -y
flags:
- -mod=readonly
- -tags="netgo ledger"
Expand All @@ -33,6 +52,7 @@ builds:
- -X github.com/cosmos/cosmos-sdk/version.Commit={{ .Commit }}
- -X github.com/cosmos/cosmos-sdk/version.BuildTags=netgo,ledger,goleveldb


archives:
- id: release-archives
replacements:
Expand All @@ -51,7 +71,6 @@ checksum:

changelog:
use: github-native
sort: asc
groups:
- title: Features
regexp: "^.*feat[(\\w)]*:+.*$"
Expand All @@ -70,14 +89,7 @@ changelog:
order: 4
- title: 'Other changes'
order: 999
filters:
exclude:
- '^docs'
- '^test'
- '^ci'
- '^refactor'
- '^revert'
- '^style'


release:
github:
Expand Down
41 changes: 21 additions & 20 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -3,29 +3,29 @@ module github.com/cheqd/cheqd-node
go 1.17

require (
filippo.io/edwards25519 v1.0.0
filippo.io/edwards25519 v1.0.0-beta.2
github.com/btcsuite/btcutil v1.0.3-0.20201208143702-a53e38424cce
github.com/cosmos/cosmos-sdk v0.45.5
github.com/cosmos/ibc-go/v3 v3.1.0
github.com/gabriel-vasile/mimetype v1.4.0
github.com/gabriel-vasile/mimetype v1.4.1
github.com/go-ozzo/ozzo-validation/v4 v4.3.0
github.com/gogo/protobuf v1.3.3
github.com/golang/protobuf v1.5.2
github.com/google/uuid v1.3.0
github.com/gorilla/mux v1.8.0
github.com/grpc-ecosystem/grpc-gateway v1.16.0
github.com/lestrrat-go/jwx v1.2.25
github.com/multiformats/go-multibase v0.0.3
github.com/multiformats/go-multibase v0.1.1
github.com/rakyll/statik v0.1.7
github.com/spf13/cast v1.5.0
github.com/spf13/cobra v1.5.0
github.com/spf13/pflag v1.0.5
github.com/spf13/viper v1.12.0
github.com/stretchr/testify v1.8.0
github.com/tendermint/tendermint v0.34.19
github.com/tendermint/tendermint v0.34.20
github.com/tendermint/tm-db v0.6.6
google.golang.org/genproto v0.0.0-20220519153652-3a47de7e79bd
google.golang.org/grpc v1.46.2
google.golang.org/grpc v1.48.0
)

require (
Expand All @@ -37,7 +37,7 @@ require (
github.com/asaskevich/govalidator v0.0.0-20200108200545-475eaeb16496 // indirect
github.com/beorn7/perks v1.0.1 // indirect
github.com/bgentry/speakeasy v0.1.0 // indirect
github.com/btcsuite/btcd v0.22.0-beta // indirect
github.com/btcsuite/btcd v0.22.1 // indirect
github.com/cespare/xxhash v1.1.0 // indirect
github.com/cespare/xxhash/v2 v2.1.2 // indirect
github.com/coinbase/rosetta-sdk-go v0.7.0 // indirect
Expand All @@ -59,7 +59,7 @@ require (
github.com/felixge/httpsnoop v1.0.1 // indirect
github.com/fsnotify/fsnotify v1.5.4 // indirect
github.com/go-kit/kit v0.12.0 // indirect
github.com/go-kit/log v0.2.0 // indirect
github.com/go-kit/log v0.2.1 // indirect
github.com/go-logfmt/logfmt v0.5.1 // indirect
github.com/go-playground/universal-translator v0.18.0 // indirect
github.com/goccy/go-json v0.9.7 // indirect
Expand All @@ -82,16 +82,17 @@ require (
github.com/inconshreveable/mousetrap v1.0.0 // indirect
github.com/jmhodges/levigo v1.0.0 // indirect
github.com/keybase/go-keychain v0.0.0-20190712205309-48d3d31d256d // indirect
github.com/klauspost/compress v1.13.6 // indirect
github.com/klauspost/compress v1.15.1 // indirect
github.com/leodido/go-urn v1.2.1 // indirect
github.com/lestrrat-go/backoff/v2 v2.0.8 // indirect
github.com/lestrrat-go/blackmagic v1.0.0 // indirect
github.com/lestrrat-go/httpcc v1.0.1 // indirect
github.com/lestrrat-go/iter v1.0.1 // indirect
github.com/lestrrat-go/option v1.0.0 // indirect
github.com/lib/pq v1.10.4 // indirect
github.com/libp2p/go-buffer-pool v0.0.2 // indirect
github.com/lib/pq v1.10.6 // indirect
github.com/libp2p/go-buffer-pool v0.1.0 // indirect
github.com/magiconair/properties v1.8.6 // indirect
github.com/mattn/go-colorable v0.1.12 // indirect
github.com/mattn/go-isatty v0.0.14 // indirect
github.com/matttproud/golang_protobuf_extensions v1.0.1 // indirect
github.com/mimoo/StrobeGo v0.0.0-20181016162300-f8f6d4d2b643 // indirect
Expand All @@ -103,36 +104,36 @@ require (
github.com/multiformats/go-base32 v0.0.3 // indirect
github.com/multiformats/go-base36 v0.1.0 // indirect
github.com/pelletier/go-toml v1.9.5 // indirect
github.com/pelletier/go-toml/v2 v2.0.1 // indirect
github.com/pelletier/go-toml/v2 v2.0.2 // indirect
github.com/petermattis/goid v0.0.0-20180202154549-b0b1615b78e5 // indirect
github.com/pkg/errors v0.9.1 // indirect
github.com/pmezard/go-difflib v1.0.0 // indirect
github.com/prometheus/client_golang v1.12.1 // indirect
github.com/prometheus/client_golang v1.12.2 // indirect
github.com/prometheus/client_model v0.2.0 // indirect
github.com/prometheus/common v0.32.1 // indirect
github.com/prometheus/common v0.34.0 // indirect
github.com/prometheus/procfs v0.7.3 // indirect
github.com/rcrowley/go-metrics v0.0.0-20200313005456-10cdbea86bc0 // indirect
github.com/regen-network/cosmos-proto v0.3.1 // indirect
github.com/rs/cors v1.8.2 // indirect
github.com/rs/zerolog v1.23.0 // indirect
github.com/rs/zerolog v1.27.0 // indirect
github.com/sasha-s/go-deadlock v0.2.1-0.20190427202633-1595213edefa // indirect
github.com/spf13/afero v1.8.2 // indirect
github.com/spf13/jwalterweatherman v1.1.0 // indirect
github.com/subosito/gotenv v1.3.0 // indirect
github.com/subosito/gotenv v1.4.0 // indirect
github.com/syndtr/goleveldb v1.0.1-0.20200815110645-5c35d600f0ca // indirect
github.com/tecbot/gorocksdb v0.0.0-20191217155057-f0fad39f321c // indirect
github.com/tendermint/btcd v0.1.1 // indirect
github.com/tendermint/crypto v0.0.0-20191022145703-50d29ede1e15 // indirect
github.com/tendermint/go-amino v0.16.0 // indirect
github.com/zondax/hid v0.9.0 // indirect
go.etcd.io/bbolt v1.3.6 // indirect
golang.org/x/crypto v0.0.0-20220427172511-eb4f295cb31f // indirect
golang.org/x/net v0.0.0-20220520000938-2e3eb7b945c2 // indirect
golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a // indirect
golang.org/x/term v0.0.0-20210927222741-03fcf44c2211 // indirect
golang.org/x/crypto v0.0.0-20220525230936-793ad666bf5e // indirect
golang.org/x/net v0.0.0-20220624214902-1bab6f366d9e // indirect
golang.org/x/sys v0.0.0-20220615213510-4f61da869c0c // indirect
golang.org/x/term v0.0.0-20220526004731-065cf7ba2467 // indirect
golang.org/x/text v0.3.7 // indirect
google.golang.org/protobuf v1.28.0 // indirect
gopkg.in/ini.v1 v1.66.4 // indirect
gopkg.in/ini.v1 v1.66.6 // indirect
gopkg.in/yaml.v2 v2.4.0 // indirect
gopkg.in/yaml.v3 v3.0.1 // indirect
nhooyr.io/websocket v1.8.6 // indirect
Expand Down
Loading

0 comments on commit 9e24671

Please sign in to comment.