bump go, bump deps for cve, bump opencost and move to opencost/core #177
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Signed-off-by: Cliff Colvin [email protected]
What does this PR change?
Bump deps for cve resolution, bump go to 1.22, bump opencost dependency and switch to opencost/core
Closes #166 and Closes #174
This was a targetted update for opencost, https://github.com/kubecost/kubectl-cost/security/dependabot/8 https://github.com/kubecost/kubectl-cost/security/dependabot/7 and https://github.com/kubecost/kubectl-cost/security/dependabot/5
all the rest of the dependencies that changed were transitive to these.
Does this PR rely on any other PRs?
How does this PR impact users? (This is the kind of thing that goes in release notes!)
NA just have less vulnerabilities
Links to Issues or ZD tickets this PR addresses or fixes
How was this PR tested?
Build locally and test against nightly using ./test/integration.sh
Have you made an update to documentation?
NA