Repository navigation
fix(deps): update all dependencies - #1818
Open
red-hat-konflux[bot] wants to merge 1 commit into
Open
red-hat-konflux[bot] wants to merge 1 commit into
red-hat-konflux[bot] wants to merge 1 commit into
Conversation
Contributor
Author
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by Details:
|
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/master/all
branch
6 times, most recently
from
September 28, 2026 00:41
1908937 to
7cc499f
Compare
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/master/all
branch
9 times, most recently
from
October 5, 2026 00:43
e1a998f to
27b4a25
Compare
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/master/all
branch
2 times, most recently
from
October 6, 2026 06:57
26750dd to
c6aadd3
Compare
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/master/all
branch
from
October 7, 2026 00:55
c6aadd3 to
66d5e0b
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.23.3→v0.24.0v0.2.8→v0.3.0v0.9.1→v0.10.0v0.7.5→v1.0.0v2.11.4→v2.11.7v0.25.4→v0.25.6v0.1.5→v0.1.6v5.0.3→v7.0.1v1.1.0→v2.3.0v3.20.0→v3.21.0v1.6.2→v4.9.6v2.2007.4→v4.9.6v0.2.0→v2.4.2v3.0.5→v4.1.5v1.0.1→v1.0.2v1.0.2→v1.0.3v4.5.2→v5.3.1v0.28.1→v0.30.0v0.1.10→v0.1.11v2.24.1→v2.26.2v2.30.0→v2.31.0v1.6.0→v1.6.2v1.20.0→v1.20.1v3.1.6→v3.1.7v1.43.1→v1.44.0v0.62.0→v0.63.0v1.11.1→v1.11.2v1.6.4→v1.6.5v1.22.17→v3.14.0v0.71.0→v0.72.0v0.71.0→v0.72.0v0.71.0→v0.72.0v1.46.0→v1.47.0v0.22.0→v0.23.0v0.22.0→v0.23.0v1.46.0→v1.47.0v1.46.0→v1.47.0v1.46.0→v1.47.0v1.46.0→v1.47.0v1.46.0→v1.47.0v0.68.0→v0.69.0v0.22.0→v0.23.0v1.46.0→v1.47.0v1.46.0→v1.47.0v0.22.0→v1.47.0v1.46.0→v1.47.0v1.46.0→v1.47.0v0.22.0→v1.47.0v1.46.0→v1.47.0v1.46.0→v1.47.0v1.11.0→v1.11.1v2.4.4→v3.0.52824783→01e3d03v0.50.0→v0.51.0v2.5.0→v3.0.1v0.298.0→v0.300.0v0.301.0v1.83.2→v1.84.0v4.13.0→v5.9.11v2.4.0→v3.0.1v0.37.0→v0.37.19.8-1790074235→9.8-17912795639.8-1790074235→9.8-1791279563v0.21.1→v0.21.2v0.21.1→v0.21.2v0.21.1→v0.21.2v6.4.2→v7.0.0Release Notes
googleapis/google-cloud-go (cloud.google.com/go/auth)
v0.24.0KimMachineGun/automemlimit (github.com/KimMachineGun/automemlimit)
v1.0.0Compare Source
After four years of iteration through v0.x, automemlimit v1.0.0 is finally here! This release simplifies the public API and improves cgroup memory limit detection.
Key changes from v0.x:
memlimit.Setreplaces thememlimit.SetGoMemLimit*functionsmemlimit.Setreturns the previousGOMEMLIMITinstead of0when configuration is skipped or an error occursmemlimit.SetsetsGOMEMLIMITtomath.MaxInt64when the provider returnsmemlimit.ErrNoLimitmemlimit.FromCgroupreplaces the version-specific cgroup providersmemlimit.WithEnv,AUTOMEMLIMIT_EXPERIMENT, andAUTOMEMLIMIT_DEBUGwere removedmemlimit.FromSystemfor system memory fallbackmemlimit.WithRefreshIntervalnow takes acontext.Contextfor cancellationmemlimit.WithMinwas added to set a lower bound forGOMEMLIMITcaddyserver/caddy (github.com/caddyserver/caddy/v2)
v2.11.7Compare Source
This patch release fixes regressions from 2.11.6, including a crash when proxying over HTTP/2 and streams that were cut off after a minute. If you're on 2.11.6, we recommend upgrading. It also adds support for the brand new
Incrementalheader field (RFC 10036).Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.
Highlights
Fixed: crash and dropped streams caused by the new idle timeouts. 2.11.6 introduced default idle read/write timeouts, which caused some problems:
In 2.11.6, the request body's idle deadline could outlive the handler that set it:
POST, were cut off exactly 60 seconds after the body was read. (#8103)Both are fixed in #8107. Thanks @steadytao!
Over HTTP/2, streaming responses that paused between writes for longer than
write_idle(1 minute by default), like quiet SSE streams, were reset with a stream error. As documented, only a write that stalls should count. Thanks @WeidiDeng! (#8118, #8119)Fixed: placeholders for missing cookies are empty again. Since 2.11.6, places that keep unknown placeholders as written, like
respondheaders, would output{http.request.cookie.*}literally when the cookie wasn't in the request. The same happened to{http.request.tls.*}on plain HTTP requests. Both are empty again. Thanks @steadytao! (#8019)New: support for the
Incrementalheader field (RFC 10036). It's the standard replacement for NGINX's proprietaryX-Accel-Bufferingheader. If an upstream response hasIncremental: ?1,reverse_proxyforwards it immediately, the same asflush_interval -1, andencodestreams it instead of holding it back. Great for Mercure, SSE and other streaming apps.request_buffersorresponse_buffersoptions would prevent incremental forwarding, Caddy responds with501 Not Implementedinstead of silently buffering, as the RFC requires.proxy_status_nameoption adds aProxy-Statusheader to those responses, explaining why the message was refused.Thanks @dunglas! (#8020)
Faster TLS handshakes: When nothing subscribes to certificate events and debug logging is off, CertMagic no longer builds event data for every handshake. Certificate lookup per handshake is about twice as fast, with 10 allocations instead of 15. Thanks @u5surf! (#8010)
Unix sockets: When a reload moves a listener (or the admin endpoint) off a Unix socket, the old socket now closes right away and its file is removed. Before, clients connecting to the old path would hang until the next garbage collection, about 2 minutes later. Thanks @littfed! (#8061)
Headers handler: Multiple
Set-Cookievalues in a JSON config'ssetare now sent as separate header fields, instead of being joined with commas into one field that clients can't parse. Thanks @Indra55! (#8080)caddy fmtno longer deletes an opening brace at the very end of the input. Thanks @n0liu! (#8047)What's Changed
New Contributors
Full Changelog: caddyserver/caddy@v2.11.6...v2.11.7
v2.11.6Compare Source
This patch release contains a large number of minor and some noticeable enhancements and bug fixes. Thank you to everyone who contributed or spent their LLM tokens responsibly to help with this release!
We have much more in the pipeline still, as AI has made contributions of all quality levels cheap and easy. We will be trying to go through them as quickly and efficiently as we can.
Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.
Highlights
url_patternrequest matcher: Match requests with the URLPattern standard, the same syntax used by browsers (JS) and many web frameworks. It supports named groups, wildcards, and regexp components. Captured groups become placeholders ({http.url_pattern.<component>.<group>}), and there's a matchingurl_patternCEL function too. Thanks @dunglas! (#7787)timeoutshandler directive for per-route tuning. (#7913)tls_automate_namesglobal option: Manage certificates for names without serving them in a site block. (#8015)expected_underscore_headersserver option: If dropping header fields with underscores in 2.11.4 broke your app, you can now list the specific headers to keep. (#7809)versions 3upstreams now honortls_trust_pool(#8042)random_choosepolicy distributes correctly now (#7873)encodenow stream immediately instead of being buffered. (#7905)importnow works inside named routes (#7986), and quoted braces are treated as literal arguments (#7875).set_cookielog filter (#7888)roll_intervalaccepts days (d) (#7900){http.request.proto_name}placeholder (#7782)SERVER_ADDR(#7912)authenticationproviders no longer clobber each other's responses (#7904)431 Request Header Fields Too Large. If you need more, raise it with themax_header_sizeserver option.read_body_idleandwrite_idlein thetimeoutsserver option, or per-route with thetimeoutsdirective. (#7913).are now dropped, the same way underscores were in 2.11.4. PHP folds.to_, so these could be used to impersonate legitimate headers. If you need specific ones, allow them with the newexpected_dot_headersserver option.client_authno longer applies to more specific hostnames that have their own site blocks. For example,public.example.comno longer inherits mTLS from*.example.com. If you were counting on that inheritance, configureclient_authon the specific site explicitly. (#7920)named_routes(#7800)forward_authuri(#7814)weighted_round_robinweights (#7807)browsefile_limit(#7988)mapinputs (#8067)mapdestination placeholders (#8074)@version separators (#7974)/loadnow returns400with warnings inside a valid JSON body when a config is invalid. Before, it returned200with two concatenated JSON objects. (#7267)methodmatcher values are normalized to uppercase, somethod getnow matchesGETrequests. (#7832)Security fixes
Thank you to everyone who reported responsibly and helped with patches:
forward_authandreverse_proxy, a request could be sent on the wrong upstream connection. Reported by @carlt, fixed by @WeidiDeng. (GHSA-6365-7ppr-5r92, #7859)101 Switching Protocolsresponses too. Thanks @jirn073-76.handle_pathanduristrip_prefix/strip_suffixnow canonicalize the resulting path, so it can't bypass path-based authorization. Thanks @steadytao..(see above) to prevent bypassingforward_auth copy_headerswith PHP/FastCGI backends. Thanks @dunglas.path_regexpmatcher now normalizes Windows backslashes like thepathmatcher does. This completes the fix for CVE-2026-52844. Thanks @thientd. (#7858)Proxyheader is no longer passed to backends asHTTP_PROXY(HTTPoxy). Thanks @bzyy1024. (#7934)413. Thanks @hktitof. (#7969)🚨 Notice for Caddy plugin maintainers: Dependabot will probably alert you to the security fixes in Caddy and urge you to upgrade it in your
go.modfile. Please ONLY upgrade the Caddy dependency if there's a change to an exported API your plugin uses. Note that doing so now also requires Go 1.26.Thank you to everyone who was involved this release, especially our 40 new contributors! 🎉
What's Changed
d(day) inroll_intervaldirective by @mohammed90 in #7900Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.