Skip to content

chore: fix dependabot alerts - #4441

Merged
rchincha merged 4 commits into
project-zot:mainfrom
rchincha:fix-deps
Sep 19, 2026
Merged

rchincha merged 4 commits into
project-zot:mainfrom
rchincha:fix-deps

Conversation

@rchincha

Copy link
Copy Markdown
Contributor

What type of PR is this?

Which issue does this PR fix:

What does this PR do / Why do we need it:

If an issue # is not available please add repro steps and logs showing the issue:

Testing done on this change:

Automation added to e2e:

Will this break upgrades or downgrades?

Does this PR introduce any user-facing change?:


By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@rchincha
rchincha requested a review from andaaron as a code owner September 18, 2026 08:24
@codecov

codecov Bot commented Sep 18, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 94.59%. Comparing base (0529845) to head (da7d7c1).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #4441      +/-   ##
==========================================
+ Coverage   92.01%   94.59%   +2.58%     
==========================================
  Files         215      215              
  Lines       33058    29839    -3219     
==========================================
- Hits        30419    28227    -2192     
+ Misses       1682     1612      -70     
+ Partials      957        0     -957     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Signed-off-by: Ramkumar Chinchani <rchincha.dev@gmail.com>
@andaaron

Copy link
Copy Markdown
Contributor

Please fix lint issues.

Signed-off-by: Ramkumar Chinchani <rchincha.dev@gmail.com>
@rchincha
rchincha requested a review from vrajashkr as a code owner September 18, 2026 16:26
Replace errors.As(err, &x) with the generic errors.AsType[T](err), and
flatten embedded-field composite literals now that Go 1.27 allows
initializing promoted fields directly, closing out the modernize
findings golangci-lint's max-same-issues cap was hiding.

Signed-off-by: Ramkumar Chinchani <rchincha.dev@gmail.com>
Signed-off-by: Ramkumar Chinchani <rchincha.dev@gmail.com>

@vrajashkr vrajashkr left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Left one question.

Comment thread pkg/storage/gc/gc.go
func getSubjectFromCosignTag(tag string) godigest.Digest {
alg := strings.Split(tag, "-")[0]
encoded := strings.Split(tag, "-")[1]
alg, encoded, _ := strings.Cut(tag, "-")

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it guaranteed that the tag that will come here is validated to be in the right format?
strings.Cut returns before, after, and found. In case the tag has 2 hyphens in it, the "after" will be invalid.

If the tag is validated/always generated by code, then no problems here.

@rchincha
rchincha merged commit 715fde5 into project-zot:main Sep 19, 2026
62 of 64 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants