Skip to content
This repository was archived by the owner on Sep 27, 2025. It is now read-only.

⬆️ Bump @bufbuild/buf from 1.50.0 to 1.54.0 - #90

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/bufbuild/buf-1.54.0
Open

⬆️ Bump @bufbuild/buf from 1.50.0 to 1.54.0#90
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/bufbuild/buf-1.54.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 19, 2025

Copy link
Copy Markdown
Contributor

Bumps @bufbuild/buf from 1.50.0 to 1.54.0.

Release notes

Sourced from @​bufbuild/buf's releases.

v1.54.0

  • Add CSR category to breaking rules.
  • Add support for local bufplugins for protoc-gen-buf-breaking and protoc-gen-buf-lint.
  • Add RISC-V (64-bit) binaries for Linux to releases.
  • Fix type filtering on buf generate for empty files, files with no declared types.
  • Fix CEL check on buf lint for predefined rules variables.
  • Fix buf config migrate to filter out removed rules.
  • Allow users to set examples without constraints in PROTOVALIDATE lint rule.
  • Add ppc64le binaries for Linux to releases.

v1.53.0

  • Fix buf breaking annotations for JSON format.

v1.52.1

  • Fix language version for pre-commit hooks.

v1.52.0

  • Fix exclude_type on a non imported package.
  • Fix --exclude-type flag for buf generate when an input is specified.
  • Fix type filter import filtering for options.
  • Add OS environment when invoking local buf plugins.
  • Add file path to buf lint and buf breaking output even when source code info is not available. This allows buf lint and buf breaking to respect ignore and ignore_only configurations when source code info is not available.

v1.51.0

  • Fix buf convert to allow for zero length for binpb, txtpb, and yaml formats.
  • Fix use of deprecated flag --include-types for buf generate.
  • Add --against-registry flag to buf breaking that runs breaking checks against the latest commit on the default branch of the corresponding module in the registry.
  • Fix type filter with unused image dependencies for buf generate.
  • Improve type filtering for buf generate. Adds the ability to exclude types with the parameter exclude_types in buf.gen.yaml and a flag --exclude-types in the CLI. Type filters may now also be specified as plugin parameters in buf.gen.yaml.

v1.50.1

  • Security: Improved input validation to prevent unsafe command execution when running buf registry login. (Reported by Matt Austin)
Changelog

Sourced from @​bufbuild/buf's changelog.

[v1.54.0] - 2025-05-12

  • Add CSR category to breaking rules.
  • Add support for local bufplugins for protoc-gen-buf-breaking and protoc-gen-buf-lint.
  • Add RISC-V (64-bit) binaries for Linux to releases.
  • Fix type filtering on buf generate for empty files, files with no declared types.
  • Fix CEL check on buf lint for predefined rules variables.
  • Fix buf config migrate to filter out removed rules.
  • Allow users to set examples without constraints in PROTOVALIDATE lint rule.
  • Add ppc64le binaries for Linux to releases.

[v1.53.0] - 2025-04-21

  • Fix buf breaking annotations for JSON format.

[v1.52.1] - 2025-04-08

  • Fix language version for pre-commit hooks.

[v1.52.0] - 2025-04-07

  • Fix exclude_type on a non imported package.
  • Fix --exclude-type flag for buf generate when an input is specified.
  • Fix type filter import filtering for options.
  • Add OS environment when invoking local buf plugins.
  • Add file path to buf lint and buf breaking output even when source code info is not available. This allows buf lint and buf breaking to respect ignore and ignore_only configurations when source code info is not available.

[v1.51.0] - 2025-03-28

  • Fix buf convert to allow for zero length for binpb, txtpb, and yaml formats.
  • Fix use of deprecated flag --include-types for buf generate.
  • Add --against-registry flag to buf breaking that runs breaking checks against the latest commit on the default branch of the corresponding module in the registry.
  • Fix type filter with unused image dependencies for buf generate.
  • Improve type filtering for buf generate. Adds the ability to exclude types with the parameter exclude_types in buf.gen.yaml and a flag --exclude-types in the CLI. Type filters may now also be specified as plugin parameters in buf.gen.yaml.

[v1.50.1] - 2025-03-10

  • Minor fixes and dependency updates.
Commits
  • e399520 Release v1.54.0 (#3842)
  • cbdbf63 Allow users to set examples without constraints in PROTOVALIDATE lint rule ...
  • de92461 Add CHANGELOG entry for ppc64le Linux binary (#3841)
  • 40c0fd3 Add ppc64le Linux binary to releases and README update (#3840)
  • 0080105 Move to buf.build/go/standard (#3839)
  • 3fbc038 Move first batch of ext-suffixed packages to standard with x prefix (#3838)
  • 878a477 Fix check failure message on partial images (#3826)
  • c544d37 Make upgrade (#3837)
  • 91e71ac Remove private/pkg/app in favor of buf.build/go/app (#3829)
  • d8f7c30 Remove interrupt package and make app not depend on other private/pkg package...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Résumé par Sourcery

Mise à jour de @bufbuild/buf de la version 1.50.0 à la version 1.54.0 dans les dépendances et le fichier de verrouillage du projet pour bénéficier des derniers correctifs et améliorations en amont.

Build :

  • Mise à jour du spécificateur de version de @bufbuild/buf dans package.json vers ^1.54.0
  • Régénération des entrées pnpm-lock.yaml pour @bufbuild/buf et ses binaires de plateforme à la version 1.54.0
Original summary in English

Summary by Sourcery

Bump @bufbuild/buf from 1.50.0 to 1.54.0 in the project’s dependencies and lockfile to pick up the latest upstream fixes and enhancements.

Build:

  • Update @bufbuild/buf version specifier in package.json to ^1.54.0
  • Regenerate pnpm-lock.yaml entries for @bufbuild/buf and its platform binaries at version 1.54.0

Bumps [@bufbuild/buf](https://github.com/bufbuild/buf) from 1.50.0 to 1.54.0.
- [Release notes](https://github.com/bufbuild/buf/releases)
- [Changelog](https://github.com/bufbuild/buf/blob/main/CHANGELOG.md)
- [Commits](bufbuild/buf@v1.50.0...v1.54.0)

---
updated-dependencies:
- dependency-name: "@bufbuild/buf"
  dependency-version: 1.54.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 19, 2025
@vercel

vercel Bot commented May 19, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
spotify-mobile-lyrics-api ✅ Ready (Inspect) Visit Preview 💬 Add feedback May 19, 2025 6:22am

@sourcery-ai

sourcery-ai Bot commented May 19, 2025

Copy link
Copy Markdown

Guide du relecteur

Cette PR met à niveau la dépendance @bufbuild/buf de la version v1.50.0 à la version v1.54.0 en mettant à jour les spécificateurs de version et en synchronisant les entrées du fichier de verrouillage (y compris les binaires spécifiques à la plateforme) pour refléter la nouvelle version.

Modifications au niveau des fichiers

Modification Détails Fichiers
Augmenter le spécificateur de version de @bufbuild/buf
  • Mettre à jour l'entrée devDependencies pour @bufbuild/buf dans package.json vers ^1.54.0
  • Ajuster les champs specifier et version pour @bufbuild/buf dans la section importers de pnpm-lock.yaml
package.json
pnpm-lock.yaml
Synchroniser les résolutions et les instantanés de pnpm-lock.yaml
  • Mettre à jour les entrées de résolution pour tous les binaires @bufbuild/buf spécifiques à la plateforme vers la version 1.54.0 avec de nouveaux hachages d'intégrité
  • Actualiser les entrées d'instantané optionnelles pour chaque package @bufbuild/buf afin qu'elles correspondent à la version augmentée
pnpm-lock.yaml

Conseils et commandes

Interagir avec Sourcery

  • Déclencher une nouvelle revue : Commentez @sourcery-ai review sur la pull request.
  • Continuer les discussions : Répondez directement aux commentaires de revue de Sourcery.
  • Générer un problème GitHub à partir d'un commentaire de revue : Demandez à Sourcery de créer un problème à partir d'un commentaire de revue en y répondant. Vous pouvez également répondre à un commentaire de revue avec @sourcery-ai issue pour créer un problème à partir de celui-ci.
  • Générer un titre de pull request : Écrivez @sourcery-ai n'importe où dans le titre de la pull request pour générer un titre à tout moment. Vous pouvez également commenter @sourcery-ai title sur la pull request pour (re)générer le titre à tout moment.
  • Générer un résumé de pull request : Écrivez @sourcery-ai summary n'importe où dans le corps de la pull request pour générer un résumé de PR à tout moment, exactement où vous le souhaitez. Vous pouvez également commenter @sourcery-ai summary sur la pull request pour (re)générer le résumé à tout moment.
  • Générer un guide du relecteur : Commentez @sourcery-ai guide sur la pull request pour (re)générer le guide du relecteur à tout moment.
  • Résoudre tous les commentaires de Sourcery : Commentez @sourcery-ai resolve sur la pull request pour résoudre tous les commentaires de Sourcery. Utile si vous avez déjà traité tous les commentaires et que vous ne voulez plus les voir.
  • Rejeter toutes les revues de Sourcery : Commentez @sourcery-ai dismiss sur la pull request pour rejeter toutes les revues Sourcery existantes. Particulièrement utile si vous voulez repartir à zéro avec une nouvelle revue - n'oubliez pas de commenter @sourcery-ai review pour déclencher une nouvelle revue !

Personnaliser votre expérience

Accédez à votre tableau de bord pour :

  • Activer ou désactiver les fonctionnalités de revue telles que le résumé de pull request généré par Sourcery, le guide du relecteur et autres.
  • Changer la langue de la revue.
  • Ajouter, supprimer ou modifier des instructions de revue personnalisées.
  • Ajuster d'autres paramètres de revue.

Obtenir de l'aide

Original review guide in English

Reviewer's Guide

This PR upgrades the @bufbuild/buf dependency from v1.50.0 to v1.54.0 by updating version specifiers and synchronizing the lockfile entries (including platform-specific binaries) to reflect the new release.

File-Level Changes

Change Details Files
Bump @bufbuild/buf version specifier
  • Update the devDependencies entry for @bufbuild/buf in package.json to ^1.54.0
  • Adjust the specifier and version fields for @bufbuild/buf in the pnpm-lock.yaml importers section
package.json
pnpm-lock.yaml
Synchronize pnpm-lock.yaml resolutions and snapshots
  • Update resolution entries for all platform-specific @bufbuild/buf binaries to version 1.54.0 with new integrity hashes
  • Refresh optional snapshot entries for each @bufbuild/buf package to match the bumped version
pnpm-lock.yaml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​bufbuild/​buf@​1.50.0 ⏵ 1.54.09110010099 +3100

View full report

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants