chore(deps): bump github.com/ulikunitz/xz from 0.5.12 to 0.5.14
Bumps github.com/ulikunitz/xz from 0.5.12 to 0.5.14.
Commits
7184815Preparation of release v0.5.1488ddf1dAddress Security Issue GHSA-jc7w-c686-c4v9c8314b8Add new package xio with WriteCloserStack- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.
Benchmark Test Results
Benchmark results from the latest changes vs base branch
make .tool/task
make[1]: Entering directory '/home/runner/work/stereoscope/stereoscope'
make[1]: Leaving directory '/home/runner/work/stereoscope/stereoscope'
.tool/task show-benchstat
? github.com/anchore/stereoscope [no test files]
? github.com/anchore/stereoscope/examples [no test files]
PASS
ok github.com/anchore/stereoscope/internal 0.003s
? github.com/anchore/stereoscope/internal/bus [no test files]
PASS
ok github.com/anchore/stereoscope/internal/containerd 0.008s
PASS
ok github.com/anchore/stereoscope/internal/docker 0.004s
? github.com/anchore/stereoscope/internal/log [no test files]
PASS
ok github.com/anchore/stereoscope/internal/podman 0.005s
? github.com/anchore/stereoscope/pkg/event [no test files]
? github.com/anchore/stereoscope/pkg/event/parsers [no test files]
goos: linux
goarch: amd64
pkg: github.com/anchore/stereoscope/pkg/file
cpu: AMD EPYC 7763 64-Core Processor
BenchmarkTarIndex-4 34885 33723 ns/op 5700 B/op 93 allocs/op
BenchmarkTarIndex-4 34240 34198 ns/op 5699 B/op 93 allocs/op
BenchmarkTarIndex-4 35376 33958 ns/op 5698 B/op 93 allocs/op
BenchmarkTarIndex-4 35211 33966 ns/op 5700 B/op 93 allocs/op
BenchmarkTarIndex-4 35206 33873 ns/op 5700 B/op 93 allocs/op
BenchmarkTarIndex-4 35422 34428 ns/op 5702 B/op 93 allocs/op
BenchmarkTarIndex-4 34665 34427 ns/op 5701 B/op 93 allocs/op
PASS
ok github.com/anchore/stereoscope/pkg/file 10.795s
PASS
ok github.com/anchore/stereoscope/pkg/filetree 0.005s
? github.com/anchore/stereoscope/pkg/filetree/filenode [no test files]
PASS
ok github.com/anchore/stereoscope/pkg/image 0.005s
PASS
ok github.com/anchore/stereoscope/pkg/image/containerd 0.009s
PASS
ok github.com/anchore/stereoscope/pkg/image/docker 0.005s
PASS
ok github.com/anchore/stereoscope/pkg/image/oci 0.005s
PASS
ok github.com/anchore/stereoscope/pkg/image/oci/credhelpers 0.005s
? github.com/anchore/stereoscope/pkg/image/podman [no test files]
PASS
ok github.com/anchore/stereoscope/pkg/image/sif 0.004s
? github.com/anchore/stereoscope/pkg/imagetest [no test files]
PASS
ok github.com/anchore/stereoscope/pkg/tree 0.003s
PASS
ok github.com/anchore/stereoscope/pkg/tree/node 0.003s
goos: linux
goarch: amd64
pkg: github.com/anchore/stereoscope/test/integration
cpu: AMD EPYC 7763 64-Core Processor
BenchmarkSimpleImage_GetImage/docker-archive-4 1059 1188427 ns/op 282748 B/op 2440 allocs/op
BenchmarkSimpleImage_GetImage/docker-archive-4 921 1173353 ns/op 282360 B/op 2439 allocs/op
BenchmarkSimpleImage_GetImage/docker-archive-4 1062 1112599 ns/op 282153 B/op 2439 allocs/op
BenchmarkSimpleImage_GetImage/docker-archive-4 1075 1113426 ns/op 281955 B/op 2438 allocs/op
BenchmarkSimpleImage_GetImage/docker-archive-4 1075 1105525 ns/op 281922 B/op 2438 allocs/op
BenchmarkSimpleImage_GetImage/docker-archive-4 1070 1121625 ns/op 281724 B/op 2438 allocs/op
BenchmarkSimpleImage_GetImage/docker-archive-4 1076 1098621 ns/op 281719 B/op 2438 allocs/op
--- FAIL: BenchmarkSimpleImage_GetImage/podman
fixture_image_simple_test.go:175: could not get fixture image: unable to detect input for 'stereoscope-fixture-image-simple:04e16e44161c8888a1a963720fd0443cbf7eef8101434c431de8725cd98cc9f7', errs: podman not available: no host address
#0 building with "default" instance using docker driver
#1 [internal] load build definition from Dockerfile
#1 transferring dockerfile: 345B done
#1 DONE 0.0s
#2 [internal] load .dockerignore
#2 transferring context: 2B done
#2 DONE 0.0s
#3 [internal] load build context
#3 transferring context: 209B done
#3 DONE 0.0s
#4 [2/3] ADD file-2.txt /somefile-2.txt
#4 CACHED
#5 [1/3] ADD file-1.txt /somefile-1.txt
#5 CACHED
#6 [3/3] ADD target /
#6 CACHED
#7 exporting to image
#7 exporting layers done
#7 writing image sha256:6f2d057bb2e6203142074841bf5b61f7468e595e9d94ff0c3fa171ad43fad3da done
#7 naming to docker.io/library/stereoscope-fixture-image-simple:04e16e44161c8888a1a963720fd0443cbf7eef8101434c431de8725cd98cc9f7 done
#7 naming to docker.io/library/stereoscope-fixture-image-simple:latest done
#7 DONE 0.0s
ctr: failed to dial "/run/containerd/containerd.sock": connection error: desc = "transport: error while dialing: dial unix /run/containerd/containerd.sock: connect: permission denied"
--- FAIL: BenchmarkSimpleImage_GetImage
image_fixtures.go:193: using existing image tar: 'test-fixtures/cache/stereoscope-fixture-image-simple-04e16e44161c8888a1a963720fd0443cbf7eef8101434c431de8725cd98cc9f7.tar' (size: 22528, modified: 2025-09-08 16:54:33.047723125 +0000 UTC, mode: -rw-r--r--)
image_fixtures.go:241: Build docker image: name="stereoscope-fixture-image-simple" tag="04e16e44161c8888a1a963720fd0443cbf7eef8101434c431de8725cd98cc9f7"
image_fixtures.go:291: saveImage running: docker image save stereoscope-fixture-image-simple:04e16e44161c8888a1a963720fd0443cbf7eef8101434c431de8725cd98cc9f7
image_fixtures.go:286:
Error Trace: /home/runner/work/stereoscope/stereoscope/pkg/imagetest/image_fixtures.go:286
/home/runner/work/stereoscope/stereoscope/pkg/imagetest/image_fixtures.go:162
/home/runner/work/stereoscope/stereoscope/pkg/imagetest/image_fixtures.go:152
/home/runner/work/stereoscope/stereoscope/pkg/imagetest/image_fixtures.go:33
/home/runner/work/stereoscope/stereoscope/test/integration/fixture_image_simple_test.go:163
/opt/hostedtoolcache/go/1.24.6/x64/src/testing/benchmark.go:245
/opt/hostedtoolcache/go/1.24.6/x64/src/runtime/asm_amd64.s:1700
Error: Received unexpected error:
exit status 1
Test: BenchmarkSimpleImage_GetImage
Messages: could not import docker image to containerd (shell out)
BenchmarkSimpleImage_FetchSquashedContents/docker-archive-4 61257 19397 ns/op 2616 B/op 18 allocs/op
BenchmarkSimpleImage_FetchSquashedContents/docker-archive-4 61704 19741 ns/op 2616 B/op 18 allocs/op
BenchmarkSimpleImage_FetchSquashedContents/docker-archive-4 61905 19470 ns/op 2616 B/op 18 allocs/op
BenchmarkSimpleImage_FetchSquashedContents/docker-archive-4 61843 19410 ns/op 2616 B/op 18 allocs/op
BenchmarkSimpleImage_FetchSquashedContents/docker-archive-4 61506 19388 ns/op 2616 B/op 18 allocs/op
BenchmarkSimpleImage_FetchSquashedContents/docker-archive-4 61038 19403 ns/op 2616 B/op 18 allocs/op
BenchmarkSimpleImage_FetchSquashedContents/docker-archive-4 61010 19391 ns/op 2616 B/op 18 allocs/op
--- FAIL: BenchmarkSimpleImage_FetchSquashedContents
image_fixtures.go:193: using existing image tar: 'test-fixtures/cache/stereoscope-fixture-image-simple-04e16e44161c8888a1a963720fd0443cbf7eef8101434c431de8725cd98cc9f7.tar' (size: 22528, modified: 2025-09-08 16:54:33.047723125 +0000 UTC, mode: -rw-r--r--)
image_fixtures.go:75: error getting fixture image: 'podman' 'image-simple' with request 'podman:stereoscope-fixture-image-simple:04e16e44161c8888a1a963720fd0443cbf7eef8101434c431de8725cd98cc9f7': unable to detect input for 'stereoscope-fixture-image-simple:04e16e44161c8888a1a963720fd0443cbf7eef8101434c431de8725cd98cc9f7', errs: podman not available: no host address
FAIL
exit status 1
FAIL github.com/anchore/stereoscope/test/integration 19.723s
? github.com/anchore/stereoscope/test/integration/test-fixtures/registry [no test files]
FAIL
goos: linux
goarch: amd64
pkg: github.com/anchore/stereoscope/pkg/file
cpu: AMD EPYC 7763 64-Core Processor
ctr:
│ .tmp/benchmark-19be940.txt │
│ sec/op │
TarIndex-4 33.97µ ± 1%
│ .tmp/benchmark-19be940.txt │
│ B/op │
TarIndex-4 5.566Ki ± 0%
│ .tmp/benchmark-19be940.txt │
│ allocs/op │
TarIndex-4 93.00 ± 0%
pkg: github.com/anchore/stereoscope/test/integration
│ .tmp/benchmark-19be940.txt │
│ sec/op │
SimpleImage_GetImage/docker-archive-4 1.113m ± 7%
│ .tmp/benchmark-19be940.txt │
│ B/op │
SimpleImage_GetImage/docker-archive-4 275.3Ki ± 0%
│ .tmp/benchmark-19be940.txt │
│ allocs/op │
SimpleImage_GetImage/docker-archive-4 2.438k ± 0%
ctr: failed to dial "/run/containerd/containerd.sock": connection error: desc = "transport: error while dialing: dial unix /run/containerd/containerd.sock: connect: permission denied"
│ .tmp/benchmark-19be940.txt │
│ sec/op │
SimpleImage_FetchSquashedContents/docker-archive-4 19.40µ ± 2%
│ .tmp/benchmark-19be940.txt │
│ B/op │
SimpleImage_FetchSquashedContents/docker-archive-4 2.555Ki ± 0%
│ .tmp/benchmark-19be940.txt │
│ allocs/op │
SimpleImage_FetchSquashedContents/docker-archive-4 18.00 ± 0%
goos: linux
goarch: amd64
pkg: github.com/anchore/stereoscope/pkg/file
cpu: AMD EPYC 7763 64-Core Processor
ctr:
│ .tmp/benchmark-19be940.txt │
│ sec/op │
TarIndex-4 33.97µ ± 1%
│ .tmp/benchmark-19be940.txt │
│ B/op │
TarIndex-4 5.566Ki ± 0%
│ .tmp/benchmark-19be940.txt │
│ allocs/op │
TarIndex-4 93.00 ± 0%
pkg: github.com/anchore/stereoscope/test/integration
│ .tmp/benchmark-19be940.txt │
│ sec/op │
SimpleImage_GetImage/docker-archive-4 1.113m ± 7%
│ .tmp/benchmark-19be940.txt │
│ B/op │
SimpleImage_GetImage/docker-archive-4 275.3Ki ± 0%
│ .tmp/benchmark-19be940.txt │
│ allocs/op │
SimpleImage_GetImage/docker-archive-4 2.438k ± 0%
ctr: failed to dial "/run/containerd/containerd.sock": connection error: desc = "transport: error while dialing: dial unix /run/containerd/containerd.sock: connect: permission denied"
│ .tmp/benchmark-19be940.txt │
│ sec/op │
SimpleImage_FetchSquashedContents/docker-archive-4 19.40µ ± 2%
│ .tmp/benchmark-19be940.txt │
│ B/op │
SimpleImage_FetchSquashedContents/docker-archive-4 2.555Ki ± 0%
│ .tmp/benchmark-19be940.txt │
│ allocs/op │
SimpleImage_FetchSquashedContents/docker-archive-4 18.00 ± 0%
@dependabot rebase
@dependabot ignore this minor version (seems to have build errors, and a new one is already released)
OK, I won't notify you about version 0.5.x again, unless you re-open this PR.
Should have ignore patch version, not minor version.