chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azsecrets from 1.4.0 to 1.5.0#96
Conversation
…ault/azsecrets Bumps [github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azsecrets](https://github.com/Azure/azure-sdk-for-go) from 1.4.0 to 1.5.0. - [Release notes](https://github.com/Azure/azure-sdk-for-go/releases) - [Commits](Azure/azure-sdk-for-go@sdk/azcore/v1.4.0...sdk/azcore/v1.5.0) --- updated-dependencies: - dependency-name: github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azsecrets dependency-version: 1.5.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
PR SummaryMedium Risk Overview There are no application code changes; Azure Key Vault access in Reviewed by Cursor Bugbot for commit ba859a2. Bugbot is set up for automated code reviews on this repo. Configure here. |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
haasonsaas
left a comment
There was a problem hiding this comment.
🔒 Hermes automated security scan flagged this PR.
🔴 Secrets / credentials (please remove before merge):
go.sum— generic-api-key
Automated gitleaks + pattern scan. Dismiss this review if it's a false positive.
False positive — go.sum contains dependency hashes, not a secret. Hermes gate rule fixed to skip lock/sum files. Dismissing.
Bumps github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azsecrets from 1.4.0 to 1.5.0.
Release notes
Sourced from github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azsecrets's releases.
... (truncated)
Commits
f4ab3aaRemove arm/ClientOptions.AuxiliaryTenants (#20573)a554ef0Remove azcore multitenant auth API (#20572)0a42300PutBlobFromURL/UploadBlobFromURL API (#20558)be3f449Fix azcore changelog entry (#20569)380d05aFix regression - base name overrides in CI (#20563)4bdfb89Modified challenge policy test (#20554)5ab558fAdded support for copy source authorization to append block from url (#20557)d2534f7[Azquery][Readme] Edit pass (#20382)e9c77a5Bump credscan to 2.3.12.23 (#20562)dd74ea3Transaction Validation - Blob Client (#20550)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)