update dependencies to fix critical security vulnerabilities - #122
update dependencies to fix critical security vulnerabilities#122anthony-telljohann wants to merge 2 commits into
Conversation
|
Working with my employer to get the CLA signed. |
|
Thank you for the contrib @anthony-telljohann , the vendoring needs to be updated too: https://github.com/microsoft/terraform-provider-msgraph/actions/runs/27553853996/job/82275422996?pr=122 |
8ed260c to
09c58c4
Compare
Thanks for the catch. I have updated the vendoring. Now that I'm back from my long vacation, I'm going to circle back with my executive team about getting this CLA signed. |
|
If all goes well, I should able to sign CLA on Monday, July 27th. |
|
My executive team will be discussing this tomorrow, Wednesday, July 29. So, if that goes well, should be able to sign the CLA then. |
gerrytan
left a comment
There was a problem hiding this comment.
Thx for the contrib @anthony-telljohann . There's a linting error here: https://github.com/microsoft/terraform-provider-msgraph/actions/runs/29925757192/job/90436149252?pr=122 , I think the GitHub workflow need to be updated to accomodate the go version upgrade.
Good catch, I'll get that fixed shortly. |
|
@gerrytan I was able to test on my local machine that golangci-lint version 2.12.2 works but I don't have a way of running the workflow without your approval to test that the lint workflow works with golangci-lint version 2.12.2. It could be valuable to update the lint workflow to be triggered on |
|
@anthony-telljohann please read the following Contributor License Agreement(CLA). If you agree with the CLA, please reply with the following information.
Contributor License AgreementContribution License AgreementThis Contribution License Agreement (“Agreement”) is agreed to by the party signing below (“You”),
|
Some of the dependencies used by the msgraph terraform provider have critical security vulnerabilities. This pull request updates those vulnerable dependencies to versions without critical vulnerabilities.