Skip to content

Update go indirect modules - #12

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-indirect-modules
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-indirect-modules

Conversation

@renovate

@renovate renovate Bot commented Sep 27, 2026

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
github.com/fsnotify/fsnotify v1.9.0 → v1.10.1 age confidence indirect minor
github.com/fxamacker/cbor/v2 v2.9.1 → v2.9.4 age confidence indirect patch
github.com/go-openapi/jsonpointer v1.0.0 → v1.0.2 age confidence indirect patch
github.com/go-openapi/jsonreference v1.0.0 → v1.0.3 age confidence indirect patch
github.com/go-openapi/swag v0.28.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/cmdutils v0.28.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/conv v0.28.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/fileutils v0.28.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/jsonutils v0.28.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/loading v0.28.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/mangling v0.28.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/netutils v0.28.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/pools v0.28.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/stringutils v0.28.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/typeutils v0.28.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/yamlutils v0.28.0 → v0.29.2 age confidence indirect minor
github.com/google/gnostic-models v0.7.0 → v0.7.1 age confidence indirect patch
github.com/grpc-ecosystem/grpc-gateway/v2 v2.30.0 → v2.31.0 age confidence indirect minor
github.com/prometheus/client_model v0.6.2 → v0.6.3 age confidence indirect patch
github.com/prometheus/common v0.70.1 → v0.71.0 age confidence indirect minor
github.com/prometheus/procfs v0.21.1 → v0.22.0 age confidence indirect minor
go.uber.org/zap v1.27.1 → v1.28.0 age confidence indirect minor
golang.org/x/net v0.58.0 → v0.59.0 age confidence indirect minor
golang.org/x/oauth2 v0.36.0 → v0.37.0 age confidence indirect minor
golang.org/x/sync v0.22.0 → v0.23.0 age confidence indirect minor
golang.org/x/sys v0.47.0 → v0.48.0 age confidence indirect minor
golang.org/x/term v0.45.0 → v0.46.0 age confidence indirect minor
golang.org/x/text v0.41.0 → v0.42.0 age confidence indirect minor
golang.org/x/time v0.15.0 → v0.16.0 age confidence indirect minor
gomodules.xyz/jsonpatch/v2 v2.4.0 → v2.5.0 age confidence indirect minor
google.golang.org/genproto/googleapis/api 08b0e42 → b142276 age confidence indirect digest
google.golang.org/genproto/googleapis/rpc 08b0e42 → b142276 age confidence indirect digest
google.golang.org/grpc v1.83.1 → v1.84.0 age confidence indirect minor
sigs.k8s.io/json 2d32026 → 11ed52e age confidence indirect digest

Release Notes

fsnotify/fsnotify (github.com/fsnotify/fsnotify)

v1.10.1

Compare Source

Changes and fixes
  • inotify: don't remove sibling watches sharing a path prefix (#​754)

  • inotify, windows: don't rename sibling watches sharing a path prefix
    (#​755)

v1.10.0

Compare Source

This version of fsnotify needs Go 1.23.

Changes and fixes
  • inotify: improve initialization error message (#​731)

  • inotify: send Rename event if recursive watch is renamed (#​696)

  • inotify: avoid copying event buffers when reading names (#​741)

  • kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a bad entry no longer aborts Watcher.Add for the whole directory (#​748)

  • kqueue: drop watches directly in Close() to fix a file descriptor leak when recycling watchers (#​740)

  • windows: fix nil pointer dereference in remWatch (#​736)

  • windows: lock watch field updates against concurrent WatchList to fix a race introduced in v1.9.0 (#​709, #​749)

fxamacker/cbor (github.com/fxamacker/cbor/v2)

v2.9.4

Compare Source

This release fixes potential panics when decoding a CBOR map whose key decodes to an uncomparable Go value under certain conditions.

Not affected: user apps that don't register tag types and don't use map key types that are either named empty interfaces (e.g. type MyAny any) or contain interfaces.

These potential panics can be encountered when one of these two conditions is met:

  • user application registers a tag type (via TagSet interface) that is an array or struct with uncomparable or interface{} element or field type, or
  • user application specifies a destination Go map whose key type is a named empty interface type or a type containing an interface.

This was identified while improving tests and reviewing code for an upcoming release.

Tests and fuzz tests were extended to cover this bug.

Upgrading to v2.9.4 is recommended.

What's Changed

Full Changelog: fxamacker/cbor@v2.9.3...v2.9.4

v2.9.3

Compare Source

This release fixes a potential panic when decoding into a time.Time from a CBOR byte string, map, or array under certain conditions.

Not affected: standard CBOR time data (RFC 8949 tag 0 or tag 1), and decoders configured with timeTag = DecTagRequired.

Upgrading to v2.9.3 is recommended.

The panic stack trace was publicly reported on 2026-08-17, and the fix was released the same day. Fuzz testing was extended to cover this class of bug, and fuzzing of v2.9.3 is ongoing.

What's Changed

  • Skip data item when decoding to time.Time fails under certain conditions by @​fxamacker in #​803

Full Changelog: fxamacker/cbor@v2.9.2...v2.9.3

v2.9.2

Compare Source

This release refactors and hardens the streaming encoder by adding stricter checks for encoding CBOR indefinite-length data. Other changes include minor bugfixes, defensive checks, and more tests.

Projects that don't use CBOR indefinite-length data may also want to upgrade (summary of prior releases).

The stricter checks in the encoder prevent improper use of the library and bad inputs from producing malformed CBOR indefinite-length data that would be rejected by the decoder.

This release passed fuzz tests (billions of execs) and it is production quality.

What's Changed

  • Reject encoding indefinite-length map with odd item count by @​fxamacker in #​764
  • Reject encoding indefinite-length data item as a chunk inside indefinite-length byte string or text string by @​fxamacker in #​765
  • Make TagSet.Remove a no-op when contentType is nil by @​fxamacker in #​766
  • Refactor indefinite-length encoding and improve chunk validation during encoding by @​fxamacker in #​767
  • Add more tests, fix a nit in unreachable panic message, update docs & ci by @​fxamacker in #​768
CI / GitHub Actions and Docs
🔎 Details...

Full Changelog: fxamacker/cbor@v2.9.1...v2.9.2

go-openapi/jsonpointer (github.com/go-openapi/jsonpointer)

v1.0.2

Compare Source

1.0.2 - 2026-09-24

Full Changelog: go-openapi/jsonpointer@v1.0.1...v1.0.2

7 commits in this release.


Fixed bugs
  • fix: panics in Pointer.Get, Pointer.Set and json name resolution by @​fredbi ...
Documentation
Code quality
Updates
Other (technical)

People who contributed to this release

jsonpointer license terms

License

v1.0.1

Compare Source

1.0.1 - 2026-09-04

Full Changelog: go-openapi/jsonpointer@v1.0.0...v1.0.1

14 commits in this release.


Documentation
Miscellaneous tasks
Updates

People who contributed to this release

jsonpointer license terms

License

go-openapi/jsonreference (github.com/go-openapi/jsonreference)

v1.0.3

Compare Source

1.0.3 - 2026-09-25

Full Changelog: go-openapi/jsonreference@v1.0.2...v1.0.3

4 commits in this release.


Fixed bugs
Security
  • chore(security): upgraded go-openapi/jsonpointer by @​fredbi ...
Updates

People who contributed to this release

jsonreference license terms

License

v1.0.2

Compare Source

1.0.2 - 2026-09-04

Full Changelog: go-openapi/jsonreference@v1.0.1...v1.0.2

4 commits in this release.


Refactor
Documentation
Updates

People who contributed to this release

jsonreference license terms

License

v1.0.1

Compare Source

1.0.1 - 2026-08-25

Full Changelog: go-openapi/jsonreference@v1.0.0...v1.0.1

12 commits in this release.


Fixed bugs
  • fix: keep NormalizeURL's output parseable when dropping a default port by @​fredbi ...
Documentation
Performance
  • perf: replace the duplicate-slash regexp in NormalizeURL with a scan by @​fredbi ...
Miscellaneous tasks
Updates
Other (technical)

People who contributed to this release

jsonreference license terms

License

go-openapi/swag (github.com/go-openapi/swag)

v0.29.2

Compare Source

0.29.2 - 2026-09-04

Full Changelog: go-openapi/swag@v0.29.1...v0.29.2

8 commits in this release.


Documentation
Miscellaneous tasks
Updates

People who contributed to this release

swag license terms

License

Per-module changes


cmdutils (0.29.2)

Miscellaneous tasks

conv (0.29.2)

Miscellaneous tasks
Updates

fileutils (0.29.2)

Miscellaneous tasks
Updates

jsonname (0.29.2)

Miscellaneous tasks
Updates

jsonutils/adapters/easyjson (0.29.2)

Miscellaneous tasks
Updates

jsonutils/adapters/testintegration/benchmarks (0.29.2)

Miscellaneous tasks
Updates

jsonutils/adapters/testintegration (0.29.2)

Miscellaneous tasks
Updates

jsonutils/fixtures_test (0.29.2)

Miscellaneous tasks
Updates

jsonutils (0.29.2)

Miscellaneous tasks
Updates

loading (0.29.2)

Miscellaneous tasks
Updates

mangling (0.29.2)

Miscellaneous tasks
Updates

netutils (0.29.2)

Miscellaneous tasks
Updates

pools (0.29.2)

Miscellaneous tasks
Updates

stringutils (0.29.2)

Miscellaneous tasks
Updates

typeutils (0.29.2)

Miscellaneous tasks
Updates

yamlutils (0.29.2)

Miscellaneous tasks
Updates

v0.29.1

Compare Source

0.29.1 - 2026-08-21

Full Changelog: go-openapi/swag@v0.29.0...v0.29.1

4 commits in this release.


Testing
Miscellaneous tasks
Updates

People who contributed to this release

swag license terms

License

Per-module changes


conv (0.29.1)

Miscellaneous tasks

jsonname (0.29.1)

Miscellaneous tasks

jsonutils/adapters/easyjson (0.29.1)

Miscellaneous tasks

jsonutils/adapters/testintegration/benchmarks (0.29.1)

Miscellaneous tasks

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants