Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Update module github.com/labstack/echo/v4 to v4.13.3 #74

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Dec 20, 2023

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
github.com/labstack/echo/v4 v4.11.3 -> v4.13.3 age adoption passing confidence

Release Notes

labstack/echo (github.com/labstack/echo/v4)

v4.13.3

Compare Source

Security

v4.13.2

Compare Source

Security

v4.13.1

Compare Source

Fixes

v4.13.0

Compare Source

BREAKING CHANGE JWT Middleware Removed from Core use labstack/echo-jwt instead

The JWT middleware has been removed from Echo core due to another security vulnerability, CVE-2024-51744. For more details, refer to issue #​2699. A drop-in replacement is available in the labstack/echo-jwt repository.

Important: Direct assignments like token := c.Get("user").(*jwt.Token) will now cause a panic due to an invalid cast. Update your code accordingly. Replace the current imports from "github.com/golang-jwt/jwt" in your handlers to the new middleware version using "github.com/golang-jwt/jwt/v5".

Background:

The version of golang-jwt/jwt (v3.2.2) previously used in Echo core has been in an unmaintained state for some time. This is not the first vulnerability affecting this library; earlier issues were addressed in PR #​1946.
JWT middleware was marked as deprecated in Echo core as of v4.10.0 on 2022-12-27. If you did not notice that, consider leveraging tools like Staticcheck to catch such deprecations earlier in you dev/CI flow. For bonus points - check out gosec.

We sincerely apologize for any inconvenience caused by this change. While we strive to maintain backward compatibility within Echo core, recurring security issues with third-party dependencies have forced this decision.

Enhancements

v4.12.0

Compare Source

Security

Enhancements

v4.11.4

Compare Source

Security

  • Upgrade golang.org/x/crypto to v0.17.0 to fix vulnerability issue #​2562

Enhancements


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested review from a team as code owners December 20, 2023 16:54
@renovate renovate bot force-pushed the renovate/github.heygears.com-labstack-echo-v4-4.x branch from 4b4a8b1 to d047608 Compare April 15, 2024 19:40
@renovate renovate bot changed the title Update module github.com/labstack/echo/v4 to v4.11.4 Update module github.com/labstack/echo/v4 to v4.12.0 Apr 15, 2024
@renovate renovate bot changed the title Update module github.com/labstack/echo/v4 to v4.12.0 Update module github.com/labstack/echo/v4 to v4.13.0 Dec 4, 2024
@renovate renovate bot force-pushed the renovate/github.heygears.com-labstack-echo-v4-4.x branch from d047608 to df45045 Compare December 4, 2024 22:49
Copy link
Contributor Author

renovate bot commented Dec 4, 2024

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 12 additional dependencies were updated

Details:

Package Change
github.com/stretchr/testify v1.8.4 -> v1.10.0
github.com/google/go-cmp v0.5.9 -> v0.6.0
github.com/labstack/gommon v0.4.0 -> v0.4.2
github.com/mattn/go-isatty v0.0.19 -> v0.0.20
github.com/stretchr/objx v0.5.0 -> v0.5.2
golang.org/x/crypto v0.14.0 -> v0.31.0
golang.org/x/mod v0.12.0 -> v0.17.0
golang.org/x/net v0.17.0 -> v0.33.0
golang.org/x/sys v0.13.0 -> v0.28.0
golang.org/x/text v0.13.0 -> v0.21.0
golang.org/x/time v0.3.0 -> v0.8.0
golang.org/x/tools v0.13.0 -> v0.21.1-0.20240508182429-e35e4ccd0d2d

@renovate renovate bot changed the title Update module github.com/labstack/echo/v4 to v4.13.0 Update module github.com/labstack/echo/v4 to v4.13.1 Dec 11, 2024
@renovate renovate bot force-pushed the renovate/github.heygears.com-labstack-echo-v4-4.x branch from df45045 to ed4fd08 Compare December 11, 2024 11:04
@renovate renovate bot changed the title Update module github.com/labstack/echo/v4 to v4.13.1 Update module github.com/labstack/echo/v4 to v4.13.2 Dec 12, 2024
@renovate renovate bot force-pushed the renovate/github.heygears.com-labstack-echo-v4-4.x branch from ed4fd08 to 4a29d81 Compare December 12, 2024 11:52
@renovate renovate bot changed the title Update module github.com/labstack/echo/v4 to v4.13.2 Update module github.com/labstack/echo/v4 to v4.13.3 Dec 19, 2024
@renovate renovate bot force-pushed the renovate/github.heygears.com-labstack-echo-v4-4.x branch from 4a29d81 to 375480c Compare December 19, 2024 08:05
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants