Skip to content

chore(deps): update go dependencies - #684

Open
red-hat-konflux[bot] wants to merge 1 commit into
release-1.4from
konflux/mintmaker/release-1.4/go-deps
Open

chore(deps): update go dependencies#684
red-hat-konflux[bot] wants to merge 1 commit into
release-1.4from
konflux/mintmaker/release-1.4/go-deps

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented May 12, 2026

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
cloud.google.com/go/auth indirect minor v0.20.0v0.22.0
cloud.google.com/go/iam indirect minor v1.11.0v1.12.0
cloud.google.com/go/longrunning indirect major v0.13.0v1.2.0
cloud.google.com/go/monitoring indirect minor v1.29.0v1.30.0
cloud.google.com/go/spanner require minor v1.91.0v1.94.0
cloud.google.com/go/storage indirect minor v1.62.1v1.64.0
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp indirect minor v1.32.0v1.35.0
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric indirect minor v0.56.0v0.59.0
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping indirect minor v0.56.0v0.59.0
github.com/apache/beam/sdks/v2 require minor v2.72.0v2.75.0
github.com/avast/retry-go/v4 indirect major v4.7.0v5.0.0
github.com/cenkalti/backoff/v5 indirect major v5.0.3v7.0.0
github.com/cheggaaa/pb/v3 indirect minor v3.1.6v3.2.0
github.com/clipperhouse/uax29/v2 indirect minor v2.2.0v2.7.0
github.com/docker/go-connections indirect minor v0.7.0v0.8.1
github.com/fxamacker/cbor/v2 indirect patch v2.9.1v2.9.2
github.com/go-logr/logr indirect patch v1.4.3v1.4.4
github.com/go-openapi/jsonpointer indirect major v0.23.1v1.0.0
github.com/go-openapi/jsonreference indirect major v0.21.5v1.0.0
github.com/go-openapi/swag indirect minor v0.26.0v0.28.0
github.com/go-openapi/swag/cmdutils indirect minor v0.26.0v0.28.0
github.com/go-openapi/swag/conv indirect minor v0.26.0v0.28.0
github.com/go-openapi/swag/fileutils indirect minor v0.26.0v0.28.0
github.com/go-openapi/swag/jsonname indirect minor v0.26.0v0.28.0
github.com/go-openapi/swag/jsonutils indirect minor v0.26.0v0.28.0
github.com/go-openapi/swag/loading indirect minor v0.26.0v0.28.0
github.com/go-openapi/swag/mangling indirect minor v0.26.0v0.28.0
github.com/go-openapi/swag/netutils indirect minor v0.26.0v0.28.0
github.com/go-openapi/swag/stringutils indirect minor v0.26.0v0.28.0
github.com/go-openapi/swag/typeutils indirect minor v0.26.0v0.28.0
github.com/go-openapi/swag/yamlutils indirect minor v0.26.0v0.28.0
github.com/golang-cz/devslog indirect patch v0.0.15v0.0.17
github.com/google/go-licenses/v2 require patch v2.0.0-alpha.1v2.0.1
github.com/googleapis/enterprise-certificate-proxy indirect patch v0.3.15v0.3.19
github.com/googleapis/gax-go/v2 indirect minor v2.22.0v2.23.0
github.com/grpc-ecosystem/go-grpc-middleware require major v1.4.0v2.3.3
github.com/imdario/mergo indirect major v0.3.16v1.0.2
github.com/jackc/pgx/v4 indirect major v4.18.3v5.10.0
github.com/jackc/pgx/v5 require minor v5.9.2v5.10.0
github.com/jhump/protoreflect/v2 indirect patch v2.0.0-beta.1v2.0.0-beta.2
github.com/klauspost/compress indirect minor v1.18.6v1.19.1
github.com/mattn/go-colorable indirect patch v0.1.14v0.1.15
github.com/mattn/go-isatty indirect patch v0.0.22v0.0.24
github.com/mattn/go-runewidth indirect patch v0.0.23v0.0.27
github.com/olekukonko/tablewriter indirect major v0.0.5v1.1.4
github.com/onsi/ginkgo indirect major v1.16.5v2.32.0
github.com/petermattis/goid indirect digest df67b19500c67a
github.com/planetscale/vtprotobuf indirect digest ba978878ae5a48
github.com/prometheus/client_golang require minor v1.23.2v1.24.1
github.com/prometheus/common indirect minor v0.67.5v0.70.1
github.com/prometheus/procfs indirect minor v0.20.1v0.21.1
github.com/prometheus/prometheus indirect minor v0.311.3v0.313.2
github.com/pseudomuto/protokit indirect minor v0.2.1v0.3.0
github.com/spiffe/go-spiffe/v2 indirect minor v2.6.0v2.8.1
go.etcd.io/bbolt indirect minor v1.4.3v1.5.0
go.etcd.io/etcd/api/v3 indirect minor v3.6.10v3.7.1
go.etcd.io/etcd/client/pkg/v3 indirect minor v3.6.10v3.7.1
go.etcd.io/etcd/client/v3 require minor v3.6.10v3.7.1
go.etcd.io/etcd/etcdctl/v3 require minor v3.6.10v3.7.1
go.etcd.io/etcd/etcdutl/v3 indirect minor v3.6.10v3.7.1
go.etcd.io/etcd/pkg/v3 indirect minor v3.6.10v3.7.1
go.etcd.io/etcd/server/v3 require minor v3.6.10v3.7.1
go.etcd.io/etcd/tests/v3 indirect minor v3.6.10v3.7.1
go.etcd.io/etcd/v3 require minor v3.6.10v3.7.1
go.etcd.io/raft/v3 indirect minor v3.6.0v3.7.0
go.opentelemetry.io/contrib/detectors/gcp indirect minor v1.43.0v1.44.0
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc indirect minor v0.68.0v0.69.0
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp indirect minor v0.68.0v0.69.0
go.opentelemetry.io/otel indirect minor v1.43.0v1.44.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace indirect minor v1.43.0v1.44.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc indirect minor v1.43.0v1.44.0
go.opentelemetry.io/otel/metric indirect minor v1.43.0v1.44.0
go.opentelemetry.io/otel/sdk indirect minor v1.43.0v1.44.0
go.opentelemetry.io/otel/sdk/metric indirect minor v1.43.0v1.44.0
go.opentelemetry.io/otel/trace indirect minor v1.43.0v1.44.0
go.opentelemetry.io/proto/otlp indirect minor v1.10.0v1.11.0
go.uber.org/zap indirect minor v1.27.1v1.28.0
go.yaml.in/yaml/v2 indirect major v2.4.4v3.0.5
go.yaml.in/yaml/v3 indirect patch v3.0.4v3.0.5
golang.org/x/crypto require minor v0.51.0v0.54.0
golang.org/x/exp indirect digest 74f9aabb88d891
golang.org/x/mod indirect minor v0.36.0v0.38.0
golang.org/x/net indirect minor v0.54.0v0.57.0
golang.org/x/sync require minor v0.20.0v0.22.0
golang.org/x/sys require minor v0.44.0v0.47.0
golang.org/x/term indirect minor v0.43.0v0.45.0
golang.org/x/text indirect minor v0.37.0v0.40.0
golang.org/x/tools require minor v0.45.0v0.48.0
google.golang.org/api require minor v0.278.0v0.291.0
google.golang.org/genproto require digest 3700d418efbd57
google.golang.org/genproto/googleapis/rpc require digest 3700d418efbd57
google.golang.org/grpc require minor v1.81.0v1.83.0
gopkg.in/evanphx/json-patch.v4 indirect major v4.13.0v5.9.11
gopkg.in/yaml.v2 require major v2.4.0v3.0.1
k8s.io/api require minor v0.35.4v0.36.3
k8s.io/apimachinery require minor v0.35.4v0.36.3
k8s.io/client-go require minor v0.35.4v0.36.3
k8s.io/kube-openapi indirect digest da4e56fd427ff9
k8s.io/utils require digest ff6756fcf1189d
sigs.k8s.io/structured-merge-diff/v6 indirect patch v6.4.0v6.4.2

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

googleapis/google-cloud-go (cloud.google.com/go/auth)

v0.22.0

Compare Source

  • bigtable:

    • cbt: Support cells per column limit for row read.
    • bttest: Correctly handle empty RowSet.
    • Fix ReadModifyWrite operation in emulator.
    • Fix API path in GetCluster.
  • bigquery:

    • BEHAVIOR CHANGE: Retry on 503 status code.
    • Add dataset.DeleteWithContents.
    • Add SchemaUpdateOptions for query jobs.
    • Add Timeline to QueryStatistics.
    • Add more stats to ExplainQueryStage.
    • Support Parquet data format.
  • datastore:

    • Support omitempty for times.
  • dlp:

    • BREAKING CHANGE: Remove v1beta1 client. Please migrate to the v2 client,
      which is now out of beta.
    • Add v2 client.
  • firestore:

    • BEHAVIOR CHANGE: Treat set({}, MergeAll) as valid.
  • iam:

    • Support JWT signing via SignJwt callopt.
  • profiler:

    • BEHAVIOR CHANGE: PollForSerialOutput returns an error when context.Done.
    • BEHAVIOR CHANGE: Increase the initial backoff to 1 minute.
    • Avoid returning empty serial port output.
  • pubsub:

    • BEHAVIOR CHANGE: Don't backoff during next retryable error once stream is healthy.
    • BEHAVIOR CHANGE: Don't backoff on EOF.
    • pstest: Support Acknowledge and ModifyAckDeadline RPCs.
  • redis:

    • Add v1 beta Redis client.
  • spanner:

    • Support SessionLabels.
  • speech:

    • Add api v1 beta1 client.
  • storage:

    • BEHAVIOR CHANGE: Retry reads when retryable error occurs.
    • Fix delete of object in requester-pays bucket.
    • Support KMS integration.

v0.21.0

Compare Source

  • bigquery:

    • Add OpenCensus tracing.
  • firestore:

    • BREAKING CHANGE: If a document does not exist, return a DocumentSnapshot
      whose Exists method returns false. DocumentRef.Get and Transaction.Get
      return the non-nil DocumentSnapshot in addition to a NotFound error.
      DocumentRef.GetAll and Transaction.GetAll return a non-nil
      DocumentSnapshot instead of nil.
    • Add DocumentIterator.Stop. Call Stop whenever you are done with a
      DocumentIterator.
    • Added Query.Snapshots and DocumentRef.Snapshots, which provide realtime
      notification of updates. See https://cloud.google.com/firestore/docs/query-data/listen.
    • Canceling an RPC now always returns a grpc.Status with codes.Canceled.
  • spanner:

    • Add CommitTimestamp, which supports inserting the commit timestamp of a
      transaction into a column.
GoogleCloudPlatform/opentelemetry-operations-go (github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric)

v0.59.0

Compare Source

What's Changed

New Contributors

Full Changelog: GoogleCloudPlatform/opentelemetry-operations-go@v0.58.0...v0.59.0

v0.58.0: v1.34.0/v0.58.0

Compare Source

What's Changed

Full Changelog: GoogleCloudPlatform/opentelemetry-operations-go@v0.57.0...v0.58.0

v0.57.0: v1.33.0/v0.57.0

Compare Source

What's Changed

New Contributors

Full Changelog: GoogleCloudPlatform/opentelemetry-operations-go@v0.56.0...v0.57.0

apache/beam (github.com/apache/beam/sdks/v2)

v2.75.0: Beam 2.75.0 release

Compare Source

We are happy to present the new 2.75.0 release of Beam.
This release includes both improvements and new functionality.
See the download page for this release.

For more information on changes in 2.75.0, check out the detailed release notes.

Highlights

  • Python SDK now supports memory profiling with Memray (#​38853).
  • (Python) Added Qdrant VectorDatabaseWriteConfig implementation (#​38141).
I/Os
  • Support for reading from Delta Lake added (Java) (#​38551).
  • ClickHouseIO: support writing DateTime64(precision[, 'timezone']) columns with sub-second precision (Java) (#​38466).
  • Upgraded IO Expansion Service to Java 17 (#​38974).
New Features / Improvements
  • Dataflow Runner v2 has been renamed to Dataflow Portable Runner. Please refer to Dataflow public documentation on when to enable Portable Runner.(#​39000).
  • (Java) Enabled state tag encoding v2 by default for new Dataflow Streaming Engine jobs. It can be disabled by passing --experiments=disable_streaming_engine_state_tag_encoding_v2 or --updateCompatibilityVersion=2.74.0 pipeline option. Note that the tag encoding version cannot change during a job update. Jobs using tag encoding v2 (enabled by default for new jobs on 2.75.0+) cannot be downgraded to Beam versions prior to 2.73.0, as only versions 2.73.0 and later support tag encoding v2. (#​38705).
  • (Python) Added instrumentation to support off-the-shelf profiling agents when launching Python SDK Harness (#​38853).
  • (Java) Added support to the FnApi Data stream protocol allowing runners to isolate bundles slowly processing input from other bundles. (#​39001).
  • (YAML) Switched js2py library to Quickjs (#​38473).
  • (YAML) Added HuggingFaceModelHandler for YAML usage (#​38696).
  • (YAML) Added WriteToMongoDB transform (#​38376).
  • (YAML) Added WriteToDatadog transform (#​38362).
  • (Java) Flink 2.1 and 2.2 support is added (#​38947) (#​38978); Flink 1.17 and 1.18 support is dropped.
  • (Python) MqttIO is now supported in Python via cross-language (#​21060).
Breaking Changes
  • (Python) Typehints of dataclass fields are honored during type inferences. To restore the behavior of fallback-to-any,
    use pipeline option --exclude_infer_dataclass_field_type (#​38797).
    However fixing forward is recommended.
Bugfixes
  • Fixed GCS filesystem glob matching to correctly handle / in object names and support ** for recursive matching (Go) (#​38059).
  • Fixed BigQueryEnrichmentHandler batch mode dropping earlier requests when multiple requests share the same enrichment key (Python) (#​38035).
  • Fixed IcebergIO writing manifest column bounds padded with trailing 0x00 bytes, which broke equality predicate pushdown in some query engines (Java) (#​38580).
Known Issues
  • (Java) Projects using the Flink runner with Flink 2.1 or later alongside libraries requiring org.lz4:lz4-java (e.g., Kafka clients) may encounter a Gradle capability conflict, because Flink 2.1+ ships at.yawk.lz4:lz4-java which declares the same capability. To resolve, add a capabilitiesResolution rule to your build.gradle that selects at.yawk.lz4:lz4-java (#​38947).

According to git shortlog, the following people contributed to the 2.75.0 release. Thank you to all contributors!

Abdelrahman Ibrahim, Ahmed Abualsaud, Akshat, Andrew Crites, Andrew Kabas, Anurag Pappula, Arpit Jain, Arun Pandian, Atharv, Chamikara Jayalath, Danny McCormick, Deji Ibrahim, Derrick Williams, Drew Stevens, Durgaprasad M L, Elia Liu, Enzo Maruffa Moreira, Ganesh Sivakumar, Goutam Adwant, HansMarcus01, Jack McCluskey, Joe Santos, Kenneth Knowles, Lalit Yadav, Liam Miller-Cushon, Maciej Szwaja, Manan Mangal, Michael Gruschke, Nikita Grover, Radek Stankiewicz, Radosław Stankiewicz, Reuven Lax, RuiLong J., Sachin Ranjalkar, Sagnik Ghosh, Sam Whittle, Shunping Huang, Subramanya V, Tarun Annapareddy, Tobias Kaymak, TongruiLi, Valentyn Tymofieiev, Vitaly Terentyev, XQ Hu, Yi Hu, aaaZayne, claudevdm, ddebowczyk92, innuendo, kellen, parveensania, tejasiyer-dev

v2.74.0: Beam 2.74.0 release

Compare Source

We are happy to present the new 2.74.0 release of Beam.
This release includes both improvements and new functionality.
See the download page for this release.

For more information on changes in 2.74.0, check out the detailed release notes.

Highlights

  • Spark 4 runner support for Java SDK (#​38255).
I/Os
  • IcebergIO: support declaring a table's sort order on dynamic table creation via the new sort_fields config (#​38269).
  • IcebergIO: support writing with hash distribution mode, and with autosharding (#​38061).
New Features / Improvements
  • Capability introduces an indicator for aggregations and timers firing during a pipeline drain, allowing users and sinks to recognize and appropriately handle potentially incomplete or partial data (#​36884).
  • Added support for setting disk provisioned IOPS and throughput in Dataflow runner via --diskProvisionedIops and --diskProvisionedThroughputMibps pipeline options (Java/Go/Python) (#​38349).
  • TriggerStateMachineRunner changes from BitSetCoder to SentinelBitSetCoder to
    encode finished bitset. SentinelBitSetCoder and BitSetCoder are state
    compatible. Both coders can decode encoded bytes from the other coder
    (#​38139).
  • (Python) Added type alias for with_exception_handling to be used for typehints. (#​38173).
  • (Java) BatchElements transform for Java SDK (#​38369)
  • Added plugin mechanism to support different Lineage implementations (Java) (#​36790).
  • (Python) Supported Python user type in Beam SQL. For example, SQL statements like SELECT some_field from PCOLLECTION can now operate a PCollection of Beam Row containing pickable Python user type (#​20738).
  • (Python) Introduced beam.coders.registry.register_row as preferred API to register a named tuple or dataclass with a Beam Row. At pipelne runtime, the original type associated with the registered row are preserved across the serialization boundary (#​38108).
Breaking Changes
  • (Python) Made Beartype the default fallback type checking tool. This can be disabled with the --disable_beartype pipeline option. (#​38275)
Deprecations
Bugfixes
  • Fixed BigQueryEnrichmentHandler batch mode dropping earlier requests when multiple requests share the same enrichment key (Python) (#​38035).
  • Added max_batch_duration_secs passthrough support in Python Enrichment BigQuery and CloudSQL handlers so batching duration can be forwarded to BatchElements (#​38243).

According to git shortlog, the following people contributed to the 2.74.0 release. Thank you to all contributors!

Abdelrahman Ibrahim, Ahmed Abualsaud, Andrew Crites, Andrew Kabas, Arran Cudbard-Bell, Arun Pandian, Asish Kumar, Bentsi Leviav, Blake Jones, Bruno Volpato, Chris Jordan, Danny McCormick, Deji Ibrahim, Derrick Williams, Elia LIU, Ganesh Sivakumar, Jack McCluskey, Kenneth Knowles, Lalit Yadav, M Junaid Shaukat, Matej Aleksandrov, Prabhnoor Singh, Radek Stankiewicz, Radosław Stankiewicz, Reuven Lax, RuiLong J., Sam Whittle, Shunping Huang, Subramanya V, Tarun Annapareddy, Tobias Kaymak, TongruiLi, Valentyn Tymofieiev, Vitaly Terentyev, XQ Hu, Yi Hu, ZIHAN DAI, apanich, bambadiouf1, chenxuesdu, claudevdm, harshadkhetpal, johnjcasey, parveensania, tianz101

v2.73.0: Beam 2.73.0 release

Compare Source

We are happy to present the new 2.73.0 release of Beam.
This release includes both improvements and new functionality.
See the download page for this release.

For more information on changes in 2.73.0, check out the detailed release notes.

Highlights

I/Os
  • DebeziumIO (Java): added OffsetRetainer interface and FileSystemOffsetRetainer implementation to persist and restore CDC offsets across pipeline restarts, and exposed withStartOffset / withOffsetRetainer on DebeziumIO.Read and the cross-language ReadBuilder (#​28248).
New Features / Improvements
  • (Python) Added BigQuery CDC streaming source (#​37724)
  • Added ADKAgentModelHandler for running Google Agent Development Kit (ADK) agents (Python) (#​37917).
  • (Python) Added exception chaining to preserve error context in CloudSQLEnrichmentHandler, processes utilities, and core transforms (#​37422).
  • (Python) Added a pipeline option --experiments=pip_no_build_isolation to disable build isolation when installing dependencies in the runtime environment (#​37331).
  • (Go) Added OrderedListState support to the Go SDK stateful DoFn API (#​37629).
  • Added support for large pipeline options via a file (Python) (#​37370).
  • Supported infer schema from dataclass (Python) (#​22085). Default coder for typehint-ed (or set with_output_type) for non-frozen dataclasses changed to RowCoder. To preserve the old behavior (fast primitive coder), explicitly register the type with FastPrimitiveCoder.
  • Updates minimum Go version to 1.26.1 (#​37897).
  • (Python) Added image embedding support in apache_beam.ml.rag package (#​37628).
  • (Python) Added support for Python version 3.14 (#​37247).
Breaking Changes
  • The Python SDK container's boot.go now passes pipeline options through a file instead of the PIPELINE_OPTIONS environment variable. If a user pairs a new Python SDK container with an older SDK version (which does not support the file-based approach), the pipeline options will not be recognized and the pipeline will fail. Users must ensure their SDK and container versions are synchronized (#​37370).
  • Python DoFn.with_exception_handling now respects user DoFn typehints. This can break update compatibility if coders change. It can also break pipeline compilation if existing typehints are incorrect. To update safely sepcify the pipeline option --update_compatibility_version=2.72.0. To fix typehints replace any incorrect typehints that were previously ignored (#​37590)
Bugfixes
  • Fixed ProcessManager not reaping child processes, causing zombie process accumulation on long-running Flink deployments (Java) (#​37930).
Security Fixes

List of Contributors

According to git shortlog, the following people contributed to the 2.73.0 release. Thank you to all contributors!

Abdelrahman Ibrahim, Ahmed Abualsaud, Alex Malao, Alexander Nieuwenhuijse, Andres Tiko, Andrew Crites, Arun Pandian, Bentsi Leviav, Bruno Volpato, Chamikara Jayalath, Chandra Kiran Bolla, Danny McCormick, Deji Ibrahim, Derrick Williams, Elia LIU, Esmelealem, Hannes Gustafsson, Jack McCluskey, Joey Tran, Kenneth Knowles, M Junaid Shaukat, Mansi Singh, Matej Aleksandrov, Mathijs Deelen, Mattie Fu, Praneet Nadella, Radek Stankiewicz, Radosław Stankiewicz, Reuven Lax, RuiLong J., S. Veyrié, Sakthivel Subramanian, Sam Whittle, Shubham Thakur, Shunping Huang, Subramanya V, Tarun Annapareddy, Tobias Kaymak, Valentyn Tymofieiev, Vitaly Terentyev, XQ Hu, Yi Hu, ZIHAN DAI, claudevdm, kishorepola, parveensania

avast/retry-go (github.com/avast/retry-go/v4)

v5.0.0

Compare Source

What's Changed

New Contributors

Full Changelog: avast/retry-go@4.7.0...v5.0.0

cenkalti/backoff (github.com/cenkalti/backoff/v5)

v7.0.0

Compare Source

v6.0.1

Compare Source

v6.0.0

Compare Source

cheggaaa/pb (github.com/cheggaaa/pb/v3)

v3.2.0

Compare Source

v3.1.7

Compare Source

clipperhouse/uax29 (github.com/clipperhouse/uax29/v2)

v2.7.0

Compare Source

v2.6.0

Compare Source

v2.5.0

Compare Source

What's Changed

Breaking change

The returned iterator type from FromString() and FromBytes() is now a pointer. This will not present a problem if you are just using it in the typical way, which is assigning to a local variable and iterating.

If you are embedding this iterator into another object, and therefore declaring its type, this change might break your compilation. You’ll need to change to a pointer type. Apologies if so — this seems like a small enough change that a v3 would be a bit much.

New Contributors

Full Changelog: clipperhouse/uax29@v2.4.0...v2.5.0

v2.4.0

Compare Source

Adds Unicode 16 support

What's Changed

Full Changelog: clipperhouse/uax29@v2.3.0...v2.4.0

v2.3.1

Compare Source

v2.3.0

Compare Source

docker/go-connections (github.com/docker/go-connections)

v0.8.1

Compare Source

v0.8.0

Compare Source

fxamacker/cbor (github.com/fxamacker/cbor/v2)

v2.9.2

Compare Source

This release refactors and hardens the streaming encoder by adding stricter checks for encoding CBOR indefinite-length data. Other changes include minor bugfixes, defensive checks, and more tests.

Projects that don't use CBOR indefinite-length data may also want to upgrade (summary of prior releases).

The stricter checks in the encoder prevent improper use of the library and bad inputs from producing malformed CBOR indefinite-length data that would be rejected by the decoder.

This release passed fuzz tests (billions of execs) and it is production quality.

What's Changed

  • Reject encoding indefinite-length map with odd item count by @​fxamacker in #​764
  • Reject encoding indefinite-length data item as a chunk inside indefinite-length byte string or text string by @​fxamacker in #​765
  • Make TagSet.Remove a no-op when contentType is nil by @​fxamacker in #​766
  • Refactor indefinite-length encoding and improve chunk validation during encoding by @​fxamacker in #​767
  • Add more tests, fix a nit in unreachable panic message, update docs & ci by @​fxamacker in #​768
CI / GitHub Actions and Docs
🔎 Details...

Full Changelog: fxamacker/cbor@v2.9.1...v2.9.2

go-logr/logr (github.com/go-logr/logr)

v1.4.4

Compare Source

What's Changed

New Contributors

Full Changelog: go-logr/logr@v1.4.3...v1.4.4

go-openapi/jsonpointer (github.com/go-openapi/jsonpointer)

v1.0.0

Compare Source

1.0.0 - 2026-07-07

Stable API pledge - no change from v0.24.0

Full Changelog: go-openapi/jsonpointer@v0.24.0...v1.0.0

2 commits in this release.


Documentation

People who contributed to this release

jsonpointer license terms

License

v0.24.0

Compare Source

0.24.0 - 2026-06-29

Full Changelog: go-openapi/jsonpointer@v0.23.2...v0.24.0

17 commits in this release.


Implemented enhancements
  • feat(jsonname): added new json name provider more respectful of go conventions for JSON (#​195) by @​fredbi ...
Refactor
  • refact: refactored the package into multiple specialized sub-packages by @​fredbi ...
  • refact loading, jsonutils, yamlutils utililities by @​fredbi ...
Documentation
Code quality
Testing
Miscellaneous tasks
  • chore: removed most remaining external dependencies by @​fredbi ...
Updates
  • build(deps): bump the go-openapi-dependencies group across 15 directories with 2 updates by @​dependabot[bot] ...
  • build(deps): bump the go-openapi-dependencies group across 15 directories with 2 updates by @​dependabot[bot] ...
Other (technical)

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/release-1.4/go-deps branch from 962162f to 2efd0c6 Compare May 13, 2026 02:57
@red-hat-konflux

red-hat-konflux Bot commented May 13, 2026

Copy link
Copy Markdown
Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 2 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.25.9 -> 1.26.4
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 -> v1.44.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 -> v1.44.0

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/release-1.4/go-deps branch 17 times, most recently from 68fd81e to 30b0338 Compare May 22, 2026 06:26
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/release-1.4/go-deps branch 10 times, most recently from 01893b3 to 3f52370 Compare May 28, 2026 02:54
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/release-1.4/go-deps branch 15 times, most recently from a5cc312 to e38fdd2 Compare June 5, 2026 14:22
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/release-1.4/go-deps branch 13 times, most recently from 97e43a3 to df4bcda Compare June 20, 2026 18:26
@red-hat-konflux

Copy link
Copy Markdown
Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: go.sum
Command failed: go get -t ./...
go: github.com/imdario/mergo@v1.0.2: parsing go.mod:
	module declares its path as: dario.cat/mergo
	        but was required as: github.com/imdario/mergo

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants