Skip to content

fix(deps): update go dependencies - #494

Open
red-hat-konflux[bot] wants to merge 1 commit into
masterfrom
konflux/mintmaker/master/go-deps
Open

red-hat-konflux[bot] wants to merge 1 commit into
masterfrom
konflux/mintmaker/master/go-deps

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
cel.dev/expr v0.25.2v0.25.3 age confidence
cloud.google.com/go/auth v0.20.0v0.23.2 age confidence
github.com/DeRuina/timberjack v1.4.5v1.4.7 age confidence
github.com/alecthomas/chroma/v2 v2.26.1v2.27.0 age confidence
github.com/buger/jsonparser v1.2.0v1.6.1 age confidence
github.com/caddyserver/caddy/v2 v2.11.3v2.11.4 age confidence
github.com/caddyserver/certmagic v0.25.3v0.25.4 age confidence
github.com/cloudflare/circl v1.6.3v1.6.5 age confidence
github.com/coreos/go-oidc/v3 v3.18.0v3.21.0 age confidence
github.com/darkweak/souin v1.7.8v1.7.9 age confidence
github.com/darkweak/storages/core v0.0.19v0.0.20 age confidence
github.com/dlclark/regexp2/v2 v2.1.1v2.8.0 age confidence
github.com/felixge/httpsnoop v1.0.4v1.1.0 age confidence
github.com/fxamacker/cbor/v2 v2.9.2v2.9.4 age confidence
github.com/go-chi/chi/v5 v5.3.0v5.3.2 age confidence
github.com/go-jose/go-jose/v4 v4.1.4v4.1.5 age confidence
github.com/go-logr/logr v1.4.3v1.4.4 age confidence
github.com/go-sql-driver/mysql v1.10.0v1.10.1 age confidence
github.com/google/cel-go v0.28.1v0.30.0 age confidence
github.com/google/s2a-go v0.1.9v0.1.10 age confidence
github.com/googleapis/enterprise-certificate-proxy v0.3.16v0.3.22 age confidence
github.com/googleapis/gax-go/v2 v2.22.0v2.24.1 age confidence
github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0v2.30.0 age confidence
github.com/huandu/xstrings v1.5.0v1.6.0 age confidence
github.com/jackc/pgx/v5 v5.9.2v5.11.0 age confidence
github.com/klauspost/compress v1.18.6v1.20.0 age confidence
github.com/klauspost/cpuid/v2 v2.3.0v2.4.0 age confidence
github.com/mattn/go-isatty v0.0.22v0.0.24 age confidence
github.com/miekg/dns v1.1.72v1.1.73 age confidence
github.com/pierrec/lz4/v4 v4.1.27v4.1.30 age confidence
github.com/pires/go-proxyproto v0.12.0v0.15.0 age confidence
github.com/prometheus/client_golang v1.23.2v1.24.1 age confidence
github.com/prometheus/client_model v0.6.2v0.6.3 age confidence
github.com/prometheus/common v0.70.1v0.71.0 age confidence
github.com/prometheus/common v0.68.0v0.71.0 age confidence
github.com/prometheus/procfs v0.21.1v0.22.0 age confidence
github.com/prometheus/procfs v0.20.1v0.22.0 age confidence
github.com/quic-go/quic-go v0.59.1v0.62.0 age confidence
github.com/sirupsen/logrus v1.9.4v1.10.2 age confidence
github.com/slackhq/nebula v1.10.3v1.11.1 age confidence
github.com/smallstep/linkedca v0.25.0v0.26.0 age confidence
github.com/smallstep/pkcs7 v0.2.1v0.2.3 age confidence
github.com/yuin/goldmark v1.8.2v1.8.6 age confidence
go.etcd.io/bbolt v1.4.3v1.5.0 age confidence
go.opentelemetry.io/contrib/bridges/prometheus v0.69.0v0.71.0 age confidence
go.opentelemetry.io/contrib/exporters/autoexport v0.69.0v0.71.0 age confidence
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0v0.71.0 age confidence
go.opentelemetry.io/contrib/propagators/autoprop v0.69.0v0.71.0 age confidence
go.opentelemetry.io/contrib/propagators/aws v1.44.0v1.46.0 age confidence
go.opentelemetry.io/contrib/propagators/b3 v1.44.0v1.46.0 age confidence
go.opentelemetry.io/contrib/propagators/jaeger v1.44.0v1.46.0 age confidence
go.opentelemetry.io/contrib/propagators/ot v1.44.0v1.46.0 age confidence
go.opentelemetry.io/otel v1.44.0v1.46.0 age confidence
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.20.0v0.22.0 age confidence
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp v0.20.0v0.22.0 age confidence
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.44.0v1.46.0 age confidence
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp v1.44.0v1.46.0 age confidence
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0v1.46.0 age confidence
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.44.0v1.46.0 age confidence
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.44.0v1.46.0 age confidence
go.opentelemetry.io/otel/exporters/prometheus v0.66.0v0.68.0 age confidence
go.opentelemetry.io/otel/exporters/stdout/stdoutlog v0.20.0v0.22.0 age confidence
go.opentelemetry.io/otel/exporters/stdout/stdoutmetric v1.44.0v1.46.0 age confidence
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.44.0v1.46.0 age confidence
go.opentelemetry.io/otel/log v0.20.0v0.22.0 age confidence
go.opentelemetry.io/otel/metric v1.44.0v1.46.0 age confidence
go.opentelemetry.io/otel/sdk v1.44.0v1.46.0 age confidence
go.opentelemetry.io/otel/sdk/log v0.20.0v0.22.0 age confidence
go.opentelemetry.io/otel/sdk/metric v1.44.0v1.46.0 age confidence
go.opentelemetry.io/otel/trace v1.44.0v1.46.0 age confidence
go.opentelemetry.io/proto/otlp v1.10.0v1.11.0 age confidence
go.step.sm/crypto v0.81.1v0.91.0 age confidence
go.yaml.in/yaml/v3 v3.0.4v3.0.5 age confidence
golang.org/x/crypto v0.53.0v0.57.0 age confidence
golang.org/x/mod v0.36.0v0.41.0 age confidence
golang.org/x/net v0.58.0v0.59.0 age confidence
golang.org/x/net v0.56.0v0.59.0 age confidence
golang.org/x/oauth2 v0.36.0v0.37.0 age confidence
golang.org/x/sync v0.21.0v0.23.0 age confidence
golang.org/x/sys v0.47.0v0.48.0 age confidence
golang.org/x/sys v0.46.0v0.48.0 age confidence
golang.org/x/term v0.44.0v0.46.0 age confidence
golang.org/x/text v0.41.0v0.42.0 age confidence
golang.org/x/text v0.38.0v0.42.0 age confidence
golang.org/x/time v0.15.0v0.16.0 age confidence
golang.org/x/tools v0.45.0v0.50.0 age confidence
google.golang.org/api v0.285.0v0.298.0 age confidence
google.golang.org/grpc v1.81.1v1.83.2 age confidence
google.golang.org/protobuf v1.36.11v1.36.12 age confidence

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

cel-expr/cel-spec (cel.dev/expr)

v0.25.3

Compare Source

What's Changed

New Contributors

Full Changelog: cel-expr/cel-spec@v0.25.2...v0.25.3

googleapis/google-cloud-go (cloud.google.com/go/auth)

v0.23.0

Compare Source

  • bigquery: Add DDL stats to query statistics.
  • bigtable:
    • cbt: Add cells-per-column limit for row lookup.
    • cbt: Make it possible to combine read filters.
  • dlp: v2beta2 client removed. Use the v2 client instead.
  • firestore, spanner: Fix compilation errors due to protobuf changes.

v0.22.0

Compare Source

  • bigtable:

    • cbt: Support cells per column limit for row read.
    • bttest: Correctly handle empty RowSet.
    • Fix ReadModifyWrite operation in emulator.
    • Fix API path in GetCluster.
  • bigquery:

    • BEHAVIOR CHANGE: Retry on 503 status code.
    • Add dataset.DeleteWithContents.
    • Add SchemaUpdateOptions for query jobs.
    • Add Timeline to QueryStatistics.
    • Add more stats to ExplainQueryStage.
    • Support Parquet data format.
  • datastore:

    • Support omitempty for times.
  • dlp:

    • BREAKING CHANGE: Remove v1beta1 client. Please migrate to the v2 client,
      which is now out of beta.
    • Add v2 client.
  • firestore:

    • BEHAVIOR CHANGE: Treat set({}, MergeAll) as valid.
  • iam:

    • Support JWT signing via SignJwt callopt.
  • profiler:

    • BEHAVIOR CHANGE: PollForSerialOutput returns an error when context.Done.
    • BEHAVIOR CHANGE: Increase the initial backoff to 1 minute.
    • Avoid returning empty serial port output.
  • pubsub:

    • BEHAVIOR CHANGE: Don't backoff during next retryable error once stream is healthy.
    • BEHAVIOR CHANGE: Don't backoff on EOF.
    • pstest: Support Acknowledge and ModifyAckDeadline RPCs.
  • redis:

    • Add v1 beta Redis client.
  • spanner:

    • Support SessionLabels.
  • speech:

    • Add api v1 beta1 client.
  • storage:

    • BEHAVIOR CHANGE: Retry reads when retryable error occurs.
    • Fix delete of object in requester-pays bucket.
    • Support KMS integration.

v0.21.0

Compare Source

  • bigquery:

    • Add OpenCensus tracing.
  • firestore:

    • BREAKING CHANGE: If a document does not exist, return a DocumentSnapshot
      whose Exists method returns false. DocumentRef.Get and Transaction.Get
      return the non-nil DocumentSnapshot in addition to a NotFound error.
      DocumentRef.GetAll and Transaction.GetAll return a non-nil
      DocumentSnapshot instead of nil.
    • Add DocumentIterator.Stop. Call Stop whenever you are done with a
      DocumentIterator.
    • Added Query.Snapshots and DocumentRef.Snapshots, which provide realtime
      notification of updates. See https://cloud.google.com/firestore/docs/query-data/listen.
    • Canceling an RPC now always returns a grpc.Status with codes.Canceled.
  • spanner:

    • Add CommitTimestamp, which supports inserting the commit timestamp of a
      transaction into a column.
DeRuina/timberjack (github.com/DeRuina/timberjack)

v1.4.7

Compare Source

Bug Fixes
  • bump klauspost/compress to v1.18.7 to resolve GO-2026-5841 govulncheck noise (#​122) (aa922ff)

Note: this release raises the minimum required Go version from 1.21 to 1.24, as all fixed versions of klauspost/compress require go >= 1.24. Consumers on Go 1.21–1.23 with the default GOTOOLCHAIN=auto will transparently download the newer toolchain; consumers who cannot upgrade can stay on v1.4.6.

v1.4.6

Compare Source

Performance
  • avoid a stat syscall per directory entry in oldLogFiles (#​121) (0e8d599)
alecthomas/chroma (github.com/alecthomas/chroma/v2)

v2.27.0

Compare Source

Changelog

buger/jsonparser (github.com/buger/jsonparser)

v1.6.1

Compare Source

Covered by ReqProof — L3 Assurance (123 requirements, 0 errors, 0 warnings)
Performance — gjson-style fast-skip in hot loops

Ported gjson's >'\\' fast-skip trick to three inner loops in parser.go:
stringEndConfig tail, blockEndConfig, and searchKeysConfig. The trick
uses a single unsigned comparison (byte > 0x5C) to skip all non-structural
bytes in bulk, reducing per-byte branch overhead.

Payload Before After Improvement
Small (190B) 382 ns 339 ns -11.3%
Medium (2.4kB) 3,899 ns 3,141 ns -19.4%
Large (24kB) 20,788 ns 20,114 ns -3.2%

Zero allocations maintained on all paths.

Benchmarks — now includes gjson and sonic

Added tidwall/gjson (15.5k⭐, path-based
parser like jsonparser) and bytedance/sonic
(9.6k⭐, SIMD-accelerated deserializer) to the benchmark suite.

Final leaderboard (large payload):

Library time/op bytes/op allocs/op
buger/jsonparser 20,114 0 0
tidwall/gjson 22,756 28,672 2
mailru/easyjson 33,771 4,016 134
bytedance/sonic 41,053 31,368 71
pquerna/ffjson 59,063 4,822 144
encoding/json 130,565 4,432 147

jsonparser is the fastest across all payload sizes and the only zero-allocation parser.


v1.6.0

Compare Source

Covered by ReqProof — L3 Assurance (123 requirements, 0 errors, 0 warnings)
New API — Append
// Append to an array without knowing its length
data, _ = jsonparser.Append(data, []byte(`"new_item"`), "items")
  • Append(data, value, keys...) — appends value to the end of the JSON array addressed by keys. Addresses the top-level value when keys is empty; auto-vivifies a missing keyed path as a single-element array. Returns MalformedArrayError when the addressed value is not an array. Traced to SYS-REQ-009, SYS-REQ-110.
Known issues — all resolved (zero open)
  • KI-2 fixedParseInt("-") now returns an error instead of (0, nil). One-line sign-only guard in bytes.go:parseInt (after stripping the sign byte, an empty remainder returns (0, false, false)).
  • KI-3 fixedSet with an array-index path component under an object parent (and vice-versa) now auto-coerces the container type instead of emitting malformed JSON. (Disposition already set to fixed in v1.5.x.)
  • KI-4 fixedSet on a top-level array-index beyond length now appends at the array's end (matching nested-array behavior under SYS-REQ-110) instead of returning KeyPathNotFoundError. Also cleans up trailing commas in malformed arrays.

Zero open known issues. Every previously shipped known issue is now resolved and covered by ReqProof L3 Assurance.


v1.5.1

Compare Source

Covered by ReqProof — L3 Assurance (123 requirements, 0 errors, 0 warnings)
Performance — 6.1x large-payload speedup
  • Fix stringEnd unbounded backslash scanstringEndConfig was scanning the ENTIRE remaining parent document for backslashes (bytes.IndexByte(data, '\\')) instead of just the string body. On a 24kb large payload this walked tens of KB per string. Now bounded to data[:firstQuote] (the string body only). 128µs → 22µs (5.8x).
  • SWAR string scan — replaced two separate bytes.IndexByte calls (quote + backslash) with a single inline 8-byte SWAR (SIMD-Within-A-Register) loop that checks for both characters simultaneously. 22µs → 21µs (additional 8%).
  • Benchmark suite updated — all comparison libraries (gabs, easyjson, ffjson, etc.) updated to latest versions. Benchmark methodology documented (Apple M4 Max, Go 1.26.3, median of 5 runs). The encoding/json benchmark no longer uses ffjson-generated methods (the #​126 ffjson measurement bug was fixed in v1.3.1).
  • README benchmarks refreshed — all numbers now reflect real measurements on modern hardware with current library versions.
Updated benchmark results (Apple M4 Max, Go 1.26.3, median of 5 runs)
Payload jsonparser encoding/json easyjson Speedup vs encoding/json
Small (190B, Get) 382 ns 1,335 ns 312 ns 3.5x
Small (190B, EachKey) 241 ns 5.5x
Medium (2.4kB, Get) 3,894 ns 10,564 ns 2,444 ns 2.7x
Medium (2.4kB, EachKey) 1,923 ns 5.5x
Large (24kB) 20,788 ns 134,123 ns 32,765 ns 6.4x

All jsonparser results: 0 bytes allocated, 0 allocations.


v1.5.0

Compare Source

Covered by ReqProof — L3 Assurance

v1.5.0 extends the formal-verification coverage to 123 requirements (0 errors, 0 warnings) across all new APIs. Every new function is traced via source annotations, tested with MC/DC witnesses, and covered by the structure-aware fuzzer.

Config struct — opt-in lenient parsing (#​160, #​115)
var Lenient = jsonparser.Config{AllowSingleQuotes: true, AllowUnknownEscapes: true}
Lenient.Get(data, "key")  // parses {'key':'value'} and unknown escapes
  • AllowSingleQuotes — accept 'key':'value' alongside "key":"value" (JavaScript/Python-style). The same escape rules apply inside single-quoted strings.
  • AllowUnknownEscapes — pass through unknown escape sequences (\`, \x) literally instead of erroring.
  • The default Config is strict (RFC 8259 only). Package-level functions are unchanged.
  • Config methods mirror the full API: Get, GetString, Set, Delete, ArrayEach, ObjectEach.
Streaming ReaderParser (#​132, #​257)
rp := jsonparser.NewReaderParser(file)  // any io.Reader
rp.Get("users", "[0]", "name")          // path-based access from a stream
  • Path-based access to JSON data from an io.Readerno need to load the entire document into memory.
  • Buffers data incrementally in 64KB chunks; memory is bounded by the largest value, not the document size.
  • Enables parsing 10GB+ JSON files without OOM.
  • Methods: Get, GetString, ArrayEach.
Name aliases (#​66)

Canonical EachXxx pattern added alongside existing XxxEach names:

New (canonical) Old (kept for compat)
EachArray ArrayEach
EachObject ObjectEach
EachArrayErr ArrayEachErr
EachArrayWildcard ArrayEachWildcard

EachKey, EachKeyErr, EachKeyWildcard already matched the pattern. All old names remain functional.

Proof
  • 2 new SYS-REQs: 115 (Config/lenient parsing), 116 (streaming ReaderParser)
  • 123 requirements, 0 errors, 0 warnings, 279/279 functions traced

v1.4.0

Compare Source

Covered by ReqProof — L3 Assurance

v1.4.0 adds 9 new backward-compatible APIs, each traced to a formal requirement and verified with MC/DC coverage. 121 requirements, 0 errors, 0 warnings.

New APIs

Iteration with error/break control — resolves #​53, #​129, #​176, #​230, #​255, #​262

  • ArrayEachErr — callback returns error to stop early (io.EOF = graceful stop)
  • EachKeyErr — same pattern for EachKey

Safe string handling — resolves #​144, #​158, #​218, #​270

  • Escape(s string) []byte — RFC 8259 string escaping (inverse of Unescape)
  • SetString(data, val, keys...) — Set with auto-quoted value

Container accessors — resolves #​175, #​261, #​271

  • GetArrayLen / GetObjectLen — count elements without a callback
  • GetUint64 — uint64 variant of GetInt

Delete found signal — resolves #​229

  • DeleteFound(data, keys...) ([]byte, bool) — returns whether the key was found

Wildcard paths — resolves #​112

  • EachKeyWildcard, ArrayEachWildcard, SetWildcard[*] path component

JSONPath compiled paths — resolves #​234, #​251

  • ParsePath("$.users[0].name")[]string path
  • CompilePath + CompiledPath — pre-compile and reuse with Get/Set/Delete
Fixes
  • EachKey no longer panics with >64 key components (#​56)
  • Set pre-allocates output buffer, reducing allocations from 6 to 1 (#​107)
Proof
  • 3 new SYS-REQs: 112 (container length), 113 (wildcard paths), 114 (compiled paths)
  • 121 requirements, 384 MC/DC witness rows, 0 uncovered

v1.3.1

Compare Source

Covered by ReqProof — L3 Assurance

v1.3.1 fixes 3 bugs that escaped the initial proof review, with new proof gates to prevent recurrence.

Bug fixes
  • Fix Set/Delete input-buffer aliasing (#​209, #​141) — Set and Delete no longer corrupt the caller's input []byte when the slice has spare capacity. All mutation paths now allocate a fresh buffer.
  • Fix EachKey array-index inconsistency (#​232) — EachKey now descends into terminal array-index paths consistently with Get.
  • Fix benchmark measuring ffjson, not encoding/json (#​126) — benchmark payload types stripped of generated methods.
Proof strengthening
Bug Proof gap New gate
#​209/#​141 Set aliasing No obligation said "Set must not mutate the input buffer" New obligation no_input_mutation + assertInputUnchanged gate
#​232 EachKey ≠ Get No cross-API consistency obligation New obligation api_consistency + differential gate
#​126 benchmark ffjson Proof didn't cover benchmarks Benchmark honesty lint

v1.3.0

Compare Source

Formally verified by ReqProof

jsonparser v1.3.0 is the first Go library proven to L3 assurance by ReqProof, a git-native requirements-engineering and formal-verification platform. The entire codebase is now covered by:

  • 118 formal requirements (7 stakeholder + 111 system-level), each traced to code via source annotations and verified with FRETish formalization.
  • 100% Modified Condition/Decision Coverage (MC/DC) — both code-level (every decision/condition branch exercised) and requirement-side (377/377 truth-table rows witnessed).
  • A custom structure-aware JSON fuzzer (github.com/probelabs/json-fuzz) generating grammar-valid mutations at 250k inputs/sec, plus path-mutation and encoding/json differential harnesses.

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot enabled auto-merge (squash) September 10, 2026 01:12
@red-hat-konflux red-hat-konflux Bot changed the title fix(deps): update go dependencies fix(deps): update go dependencies - autoclosed Sep 15, 2026
@red-hat-konflux red-hat-konflux Bot closed this Sep 15, 2026
auto-merge was automatically disabled September 15, 2026 00:52

Pull request was closed

@red-hat-konflux red-hat-konflux Bot changed the title fix(deps): update go dependencies - autoclosed fix(deps): update go dependencies Sep 17, 2026
@red-hat-konflux red-hat-konflux Bot reopened this Sep 17, 2026
@red-hat-konflux

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: dev-proxy/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 2 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.25.14 -> 1.26.0
google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa -> v0.0.0-20260825221802-da73d73af1c5
google.golang.org/genproto/googleapis/rpc v0.0.0-20260610212136-7ab31c22f7ad -> v0.0.0-20260825221802-da73d73af1c5
File name: proxy/executor/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.25.14 -> 1.26.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants