Skip to content

build(deps): bump github.com/danielgtaylor/huma/v2 from 2.38.0 to 2.39.0 - #1474

Closed
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/go_modules/github.com/danielgtaylor/huma/v2-2.39.0
Closed

build(deps): bump github.com/danielgtaylor/huma/v2 from 2.38.0 to 2.39.0#1474
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/go_modules/github.com/danielgtaylor/huma/v2-2.39.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 22, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/danielgtaylor/huma/v2 from 2.38.0 to 2.39.0.

Release notes

Sourced from github.com/danielgtaylor/huma/v2's releases.

v2.39.0

Overview

This release adds a new framework adapter, a handful of developer-facing features, and a large batch of correctness fixes spanning SSE, the Fiber adapter, schema generation, and validation.

Echo v5 Support

The humaecho adapter now supports Echo v5 alongside the existing versions. (#959)

No More Faulty Duplicate-Schema Panics

Registering operations that use inline structs with differing field names (and an empty operation ID) previously panicked at startup on a false-positive duplicate-schema collision. Conflicting names are now auto-incremented deterministically (Request, Request1, Request2, ...), so the app starts and the generated spec stays readable. (#893)

Context Propagation to Adapters

WithContext now propagates the context directly into the underlying adapter's own context wrapper (bun, chi, echo, fiber, gin, go, httprouter) instead of relying on a generic sub-context, so cancellation and context values flow correctly through the request lifecycle. (#867)

SSE Streaming on Fiber / fasthttp

Server-Sent Events (and other streaming responses) previously failed on the Fiber adapters with unable to flush, since fasthttp doesn't implement http.Flusher. SSE now streams correctly on Fiber v2 and v3 via an internal streaming hook, with no new public API and fasthttp remaining an indirect dependency. (#1059)

More SSE Improvements

  • Response headers are now flushed before the user handler runs, so EventSource.onopen fires immediately rather than waiting for the first event (#1038)
  • Comments can now be sent over SSE streams, a common way to keep connections alive (#1054)

New Features

  • Schema.Const for pinning a schema to a single allowed value (#1004)
  • Customizable docs renderer config for finer control over the documentation UI (#1024)
  • encoding.TextUnmarshaler support for slice query parameters, matching the existing behavior for scalar params (#1021)
  • Non-file JSON form-data fields: multipart form fields tagged contentType:"application/json" are now unmarshalled and validated (#1060)

Validation & Schema Fixes

  • Integer enums no longer always fail validation on query/path parameters; numeric enum values are now compared numerically rather than by strict Go type (#1050)
  • Content-Type validation is now case-insensitive per RFC 9110, so e.g. Application/Json no longer returns 415 (#1052)
  • Path parameters are always marked required: true in the generated spec, per the OpenAPI specification (#1011)
  • Prevented a panic (and dropped response) in uniqueItems validation when array items are unhashable types, now returning 422 correctly (#1045)
  • The json:",inline" tag is now honored for embedding anonymous fields in schemas (#1006)
  • Hidden route schemas are no longer leaked into the generated spec (#1032)

Adapter & Robustness Fixes

  • humafiber (v2): corrected EachHeader iteration (it previously invoked the callback once per byte, breaking cookie reads) and switched BodyReader to Body() for automatic request-body decompression (#1058)
  • autopatch: prevented chi route-context reuse from recursing internal GET sub-requests back into the generated PATCH handler and panicking (#1049)
  • Fixed a URL parsing panic in getAPIPrefix when server URLs contain template variables like {port} or {version} (#1027)
  • The read deadline is now cleared after the request body is read, so a slow handler can't cause a background read to time out and cancel the connection context (#1028)

Docs UI & Documentation

  • Forms are now permitted in the docs UI CSP (#1036)
  • Added allow-downloads to the Stoplight CSP so the Export button works (#1048)
  • Updated Restish references to v2 (#1041)

What's Changed

... (truncated)

Commits
  • d6f2a37 feat(form-data): handle unmarshalling and validation of non-file JSON form da...
  • 214a18c fix: avoid faulty duplicate detection (#893)
  • 4e53fef fix: prevent panic in uniqueItems validation for unhashable types (#1042) (#1...
  • a8a668c fix(sse): support streaming responses on Fiber/fasthttp adapters (#1059)
  • 6cc787b Support sending comments with SSE (#1054)
  • da460b9 feat: propagate context to adapters on WithContext (#867)
  • fcd9058 fix(humafiber): correct Fiber v2 EachHeader iteration and body decompression ...
  • 770e618 fix: content type validation should be case insensitive (#1052)
  • fd8148e fix: compare numeric enum values numerically (#1050)
  • 93b5a32 fix: support json inline tag for embedding anonymous fields in schema (#1006)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Jul 22, 2026
Bumps [github.com/danielgtaylor/huma/v2](https://github.com/danielgtaylor/huma) from 2.38.0 to 2.39.0.
- [Release notes](https://github.com/danielgtaylor/huma/releases)
- [Commits](danielgtaylor/huma@v2.38.0...v2.39.0)

---
updated-dependencies:
- dependency-name: github.com/danielgtaylor/huma/v2
  dependency-version: 2.39.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/github.com/danielgtaylor/huma/v2-2.39.0 branch 2 times, most recently from f98002e to fd823a5 Compare July 27, 2026 09:58
rdimitrov added a commit that referenced this pull request Jul 27, 2026
## Problem

The **Build, Lint, and Validate** CI job is failing on every open PR
(#1480, #1474, #1449) and on `main`. The failing step is `govulncheck`:

```
Vulnerability #1: GO-2026-5970
    Infinite loop on invalid input in golang.org/x/text
    Found in: golang.org/x/text@v0.38.0
    Fixed in: golang.org/x/text@v0.39.0
```

This is **not** caused by any of those PRs' changes —
`govulncheck-action` fetches the live vulnerability database at runtime,
so when GO-2026-5970 was published, every branch based on the current
`main` started failing. The vulnerable symbol is reachable via:

- `auth.DefaultHTTPKeyFetcher.FetchKey` → `http.Client.Do`
- `database.NewTestDB` → `pgx.Connect`

so the scan exits with code 3.

## Fix

Bump the (indirect) `golang.org/x/text` dependency from `v0.38.0` to the
fixed `v0.39.0` and `go mod tidy`.

## Verification

- `govulncheck ./...` no longer reports GO-2026-5970 (confirmed
locally).
- `go build ./...` passes.

## Note

The `deploy/` module pins `golang.org/x/text@v0.37.0`, which is also <
v0.39.0. It is a separate module and is **not** scanned by this CI job
(govulncheck runs `./...` in the root module only), so it does not block
CI. Worth a follow-up bump for hygiene, but out of scope here.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
rdimitrov added a commit that referenced this pull request Jul 27, 2026
Consolidates the five open dependabot PRs into a single change so they
can be reviewed and merged together. Each bump was reproduced against
current `main` (`go get` + `go mod tidy` for Go modules; the exact SHA
pins applied for the actions group), rather than merging the individual
branches, to avoid stale `go.sum` conflicts.

## Root module (`go.mod`)
| Dependency | From | To | Supersedes |
|---|---|---|---|
| `google.golang.org/grpc` | 1.82.0 | 1.82.1 | #1479 |
| `github.com/prometheus/client_golang` | 1.23.2 | 1.24.1 | #1475 |
| `github.com/danielgtaylor/huma/v2` | 2.38.0 | 2.39.0 | #1474 |

## Deploy module (`deploy/go.mod`)
| Dependency | From | To | Supersedes |
|---|---|---|---|
| `github.com/pulumi/pulumi-kubernetes/sdk/v4` | 4.32.0 | 4.33.0 | #1449
|

## GitHub Actions (#1476)
- `actions/setup-go` SHA bumped across `ci.yml`, `release.yml`,
`deploy-production.yml`, `deploy-staging.yml`
- `actions/download-artifact` v4 → v8.0.1 in
`close-invalid-publish-prs.yml`

`go mod tidy` re-resolved transitive dependencies in both modules
accordingly.

## Verification
- `go build ./...` passes (root + deploy)
- `go vet ./...` passes
- `govulncheck ./...` reports no `golang.org/x/text` finding (the
GO-2026-5970 fix from #1481 is preserved; tidy pulled x/text to v0.40.0)

## Follow-up
Once this merges, the five superseded PRs (#1479, #1475, #1474, #1449,
#1476) can be closed.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
@rdimitrov

Copy link
Copy Markdown
Member

Superseded by #1482, which consolidated the open dependabot updates and has now been merged. Closing this one as its bump is already on main.

@rdimitrov rdimitrov closed this Jul 27, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/go_modules/github.com/danielgtaylor/huma/v2-2.39.0 branch July 27, 2026 10:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant