-
Notifications
You must be signed in to change notification settings - Fork 240
build(deps): Bump the all-go group across 5 directories with 6 updates #2881
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Bumps the all-go group with 1 update in the / directory: [github.com/celestiaorg/go-header](https://github.com/celestiaorg/go-header). Bumps the all-go group with 1 update in the /execution/evm directory: [github.com/ethereum/go-ethereum](https://github.com/ethereum/go-ethereum). Bumps the all-go group with 2 updates in the /execution/grpc directory: [golang.org/x/net](https://github.com/golang/net) and [github.com/evstack/ev-node](https://github.com/evstack/ev-node). Bumps the all-go group with 2 updates in the /test/docker-e2e directory: [github.com/ethereum/go-ethereum](https://github.com/ethereum/go-ethereum) and [github.com/docker/docker](https://github.com/docker/docker). Bumps the all-go group with 2 updates in the /test/e2e directory: [github.com/ethereum/go-ethereum](https://github.com/ethereum/go-ethereum) and [github.com/celestiaorg/tastora](https://github.com/celestiaorg/tastora). Updates `github.com/celestiaorg/go-header` from 0.7.3 to 0.7.4 - [Release notes](https://github.com/celestiaorg/go-header/releases) - [Commits](celestiaorg/go-header@v0.7.3...v0.7.4) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `golang.org/x/net` from 0.46.0 to 0.47.0 - [Commits](golang/net@v0.46.0...v0.47.0) Updates `github.com/evstack/ev-node` from 1.0.0-beta.9 to 1.0.0-beta.10 - [Release notes](https://github.com/evstack/ev-node/releases) - [Changelog](https://github.com/evstack/ev-node/blob/main/CHANGELOG.md) - [Commits](v1.0.0-beta.9...v1.0.0-beta.10) Updates `golang.org/x/net` from 0.46.0 to 0.47.0 - [Commits](golang/net@v0.46.0...v0.47.0) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `github.com/docker/docker` from 28.5.1+incompatible to 28.5.2+incompatible - [Release notes](https://github.com/docker/docker/releases) - [Commits](moby/moby@v28.5.1...v28.5.2) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `github.com/celestiaorg/tastora` from 0.7.5 to 0.8.0 - [Release notes](https://github.com/celestiaorg/tastora/releases) - [Commits](celestiaorg/tastora@v0.7.5...v0.8.0) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `github.com/celestiaorg/tastora` from 0.7.5 to 0.8.0 - [Release notes](https://github.com/celestiaorg/tastora/releases) - [Commits](celestiaorg/tastora@v0.7.5...v0.8.0) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) --- updated-dependencies: - dependency-name: github.com/celestiaorg/go-header dependency-version: 0.7.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: golang.org/x/net dependency-version: 0.47.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-go - dependency-name: github.com/evstack/ev-node dependency-version: 1.0.0-beta.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: golang.org/x/net dependency-version: 0.47.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/docker/docker dependency-version: 28.5.2+incompatible dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/celestiaorg/tastora dependency-version: 0.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/celestiaorg/tastora dependency-version: 0.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest Buf updates on your PR. Results from workflow CI / buf-check (pull_request).
|
|
Claude finished @dependabot[bot]'s task —— View job Comprehensive Code ReviewTasks
SummaryThis Dependabot PR updates 6 Go dependencies across 5 directories. The changes include one critical security fix in go-ethereum and several important bug fixes. All changes appear safe to merge. Critical Security Finding✅ APPROVED - Critical Security Fix Includedgo-ethereum v1.16.6 → v1.16.7 contains a critical KZG cryptography vulnerability fix (CVE related to c-kzg-4844):
Dependency Updates Analysis1. github.com/celestiaorg/go-header (0.7.3 → 0.7.4)Type: Bug fixes (race condition fixes)
Assessment: ✅ Safe - These are defensive bug fixes that improve concurrency safety. 2. github.com/ethereum/go-ethereum (1.16.6 → 1.16.7)Type: Security fix + hardfork enablement
Assessment: ✅ Must merge - Contains critical security fix and required hardfork enablement. 3. golang.org/x/net (0.46.0 → 0.47.0)Type: Bug fixes and improvements
Assessment: ✅ Safe - Routine maintenance updates with bug fixes. 4. github.com/evstack/ev-node (1.0.0-beta.9 → 1.0.0-beta.10)Type: Feature additions and improvements
Breaking Changes:
Assessment: ✅ Safe - This is an internal dependency update that brings improvements to the project's own modules. 5. github.com/docker/docker (28.5.1 → 28.5.2)Type: Security fixes
Assessment: ✅ Should merge - Critical security fixes for container runtime used in tests. 6. github.com/celestiaorg/tastora (0.7.5 → 0.8.0)Type: Bug fixes and improvements
Assessment: ✅ Safe - Bug fixes and improvements to test framework. Code Changes Reviewexecution/evm/test/test_helpers.goChanges Made: - dockerClients = make(map[string]*dockerclient.Client)
+ dockerClients = make(map[string]types.TastoraDockerClient)
- func getTestScopedDockerSetup(t *testing.T) (*dockerclient.Client, string)
+ func getTestScopedDockerSetup(t *testing.T) (types.TastoraDockerClient, string)
- cli, netID := docker.DockerSetup(t)
+ cli, netID := docker.Setup(t)Assessment: ✅ Excellent
Strengths:
Module Consistency CheckAll go.mod files have been updated consistently:
Architecture & Code QualityStrengths:
No Issues Found:
Testing & CI
Security AssessmentPositive Findings:
No Security Concerns:
Performance & Resource EfficiencyExpected Impact:
DocumentationNote: The project's CLAUDE.md and CHANGELOG.md are well-maintained and document recent changes including the EVM execution client improvements from PR #2863. Recommendations1. MERGE IMMEDIATELY ✅This PR should be merged promptly due to:
2. Post-Merge ActionsAfter merging, consider:
3. Future Considerations
Final Verdict✅ APPROVED - RECOMMEND IMMEDIATE MERGE This PR contains critical security fixes and required hardfork enablement with no breaking changes to the codebase. All dependency updates are safe, well-tested, and improve the project's security posture. The single code change in Risk Level: Low |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2881 +/- ##
==========================================
- Coverage 64.81% 64.70% -0.11%
==========================================
Files 81 81
Lines 7347 7347
==========================================
- Hits 4762 4754 -8
- Misses 2043 2052 +9
+ Partials 542 541 -1
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
Bumps the all-go group with 1 update in the / directory: github.com/celestiaorg/go-header.
Bumps the all-go group with 1 update in the /execution/evm directory: github.com/ethereum/go-ethereum.
Bumps the all-go group with 2 updates in the /execution/grpc directory: golang.org/x/net and github.com/evstack/ev-node.
Bumps the all-go group with 2 updates in the /test/docker-e2e directory: github.com/ethereum/go-ethereum and github.com/docker/docker.
Bumps the all-go group with 2 updates in the /test/e2e directory: github.com/ethereum/go-ethereum and github.com/celestiaorg/tastora.
Updates
github.com/celestiaorg/go-headerfrom 0.7.3 to 0.7.4Release notes
Sourced from github.com/celestiaorg/go-header's releases.
Commits
425f0dcfix(headertest): add locking to header test suite for concurrent use (#356)62199e0fix(store): fixes rare race condition where 2 workers attempt to close errCh ...Updates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
golang.org/x/netfrom 0.46.0 to 0.47.0Commits
9a29643go.mod: update golang.org/x dependencies07cefd8context: deprecate5ac9dacpublicsuffix: don't treat ip addresses as domain namesd1f64ccquic: use testing/synctestfff0469http2: document that RFC 7540 prioritization does not work with small payloadsf35e3a4http2: fix weight overflow in RFC 7540 write scheduler89adc90http2: fix typo referring to RFC 9218 as RFC 9128 instead8d76a2cquic: don't defer MAX_STREAMS frames indefinitely027f8b7quic: fix expected ACK Delay in client's ACK after HANDSHAKE_DONEdec9fe7dns/dnsmessage: update SVCB packing to prohibit name compressionUpdates
github.com/evstack/ev-nodefrom 1.0.0-beta.9 to 1.0.0-beta.10Changelog
Sourced from github.com/evstack/ev-node's changelog.
Commits
d7eda60refactor(syncer,cache): use compare and swap loop and add comments (#2873)9a5eba1refactor: use state da height as well (#2872)faabb32refactor: retrieve highest da height in cache (#2870)6badca1chore: change from event count to start and end height (#2871)12b9559chore: bump da (#2866)d8d1709chore: bump core (#2865)e5aa2c3chore: reduce log noise (#2864)9d4c64cfix: sync service for non zero height starts with empty store (#2834)3ad84b8build(deps): Bump golang.org/x/crypto from 0.43.0 to 0.45.0 in /execution/evm...2b45d45chore: minor improvement for docs (#2862)Updates
golang.org/x/netfrom 0.46.0 to 0.47.0Commits
9a29643go.mod: update golang.org/x dependencies07cefd8context: deprecate5ac9dacpublicsuffix: don't treat ip addresses as domain namesd1f64ccquic: use testing/synctestfff0469http2: document that RFC 7540 prioritization does not work with small payloadsf35e3a4http2: fix weight overflow in RFC 7540 write scheduler89adc90http2: fix typo referring to RFC 9218 as RFC 9128 instead8d76a2cquic: don't defer MAX_STREAMS frames indefinitely027f8b7quic: fix expected ACK Delay in client's ACK after HANDSHAKE_DONEdec9fe7dns/dnsmessage: update SVCB packing to prohibit name compressionUpdates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
github.com/docker/dockerfrom 28.5.1+incompatible to 28.5.2+incompatibleRelease notes
Sourced from github.com/docker/docker's releases.
Commits
89c5e8fMerge pull request #51396 from thaJeztah/28.x_backport_api_docs9b93878Merge pull request #51395 from thaJeztah/28.x_backport_rootless_reject6178456Merge pull request #51398 from vvoland/51397-28.x0cae4e5vendor: github.com/moby/buildkit v0.25.233cc06fMerge pull request #51394 from vvoland/51393-28.xd525277api/docs: remove BuildCache.Parent field for API v1.42 and up2fbc51bdockerd-rootless.sh: reject DOCKERD_ROOTLESS_ROOTLESSKIT_NET=hostbd98008integration-cli: Adjust nofile limits1967515Dockerfile: update runc binary to v1.3.34489660Merge pull request #51387 from thaJeztah/28.x_bump_goUpdates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
github.com/celestiaorg/tastorafrom 0.7.5 to 0.8.0Release notes
Sourced from github.com/celestiaorg/tastora's releases.
Commits
ef34bd5chore: fix jwt secret flag (#150)7defa8bchore: add labeled client and update volume cleanup (#145)97525e3chore(deps): bump github.com/consensys/gnark-crypto (#147)Updates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
github.com/celestiaorg/tastorafrom 0.7.5 to 0.8.0Release notes
Sourced from github.com/celestiaorg/tastora's releases.
Commits
ef34bd5chore: fix jwt secret flag (#150)