Skip to content

fix(deps): update all dependencies - #1818

Open
red-hat-konflux[bot] wants to merge 1 commit into
masterfrom
konflux/mintmaker/master/all
Open

red-hat-konflux[bot] wants to merge 1 commit into
masterfrom
konflux/mintmaker/master/all

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
cloud.google.com/go/auth v0.23.3 → v0.24.0 age confidence indirect minor
cloud.google.com/go/auth/oauth2adapt v0.2.8 → v0.3.0 age confidence indirect minor
cloud.google.com/go/compute/metadata v0.9.1 → v0.10.0 age confidence indirect minor
github.com/KimMachineGun/automemlimit v0.7.5 → v1.0.0 age confidence indirect major
github.com/caddyserver/caddy/v2 v2.11.4 → v2.11.7 age confidence require patch
github.com/caddyserver/certmagic v0.25.4 → v0.25.6 age confidence indirect patch
github.com/caddyserver/zerossl v0.1.5 → v0.1.6 age confidence indirect patch
github.com/cenkalti/backoff/v5 v5.0.3 → v7.0.1 age confidence indirect major
github.com/cespare/xxhash v1.1.0 → v2.3.0 age confidence indirect major
github.com/coreos/go-oidc/v3 v3.20.0 → v3.21.0 age confidence indirect minor
github.com/dgraph-io/badger v1.6.2 → v4.9.6 age confidence indirect major
github.com/dgraph-io/badger/v2 v2.2007.4 → v4.9.6 age confidence indirect major
github.com/dgraph-io/ristretto v0.2.0 → v2.4.2 age confidence indirect major
github.com/go-jose/go-jose/v3 v3.0.5 → v4.1.5 age confidence indirect major
github.com/go-openapi/jsonpointer v1.0.1 → v1.0.2 age confidence indirect patch
github.com/go-openapi/jsonreference v1.0.2 → v1.0.3 age confidence indirect patch
github.com/golang-jwt/jwt/v4 v4.5.2 → v5.3.1 age confidence indirect major
github.com/google/cel-go v0.28.1 → v0.30.0 age confidence replace minor
github.com/google/s2a-go v0.1.10 → v0.1.11 age confidence indirect patch
github.com/googleapis/gax-go/v2 v2.24.1 → v2.26.2 age confidence indirect minor
github.com/grpc-ecosystem/grpc-gateway/v2 v2.30.0 → v2.31.0 age confidence indirect minor
github.com/huandu/xstrings v1.6.0 → v1.6.2 age confidence indirect patch
github.com/klauspost/compress v1.20.0 → v1.20.1 age confidence indirect patch
github.com/mholt/acmez/v3 v3.1.6 → v3.1.7 age confidence indirect patch
github.com/onsi/gomega v1.43.1 → v1.44.0 age confidence require minor
github.com/quic-go/quic-go v0.62.0 → v0.63.0 age confidence indirect minor
github.com/slackhq/nebula v1.11.1 → v1.11.2 age confidence indirect patch
github.com/tinylib/msgp v1.6.4 → v1.6.5 age confidence indirect patch
github.com/urfave/cli v1.22.17 → v3.14.0 age confidence indirect major
go.opentelemetry.io/contrib/bridges/prometheus v0.71.0 → v0.72.0 age confidence indirect minor
go.opentelemetry.io/contrib/exporters/autoexport v0.71.0 → v0.72.0 age confidence indirect minor
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.71.0 → v0.72.0 age confidence indirect minor
go.opentelemetry.io/otel v1.46.0 → v1.47.0 age confidence indirect minor
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.22.0 → v0.23.0 age confidence indirect minor
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp v0.22.0 → v0.23.0 age confidence indirect minor
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.46.0 → v1.47.0 age confidence indirect minor
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp v1.46.0 → v1.47.0 age confidence indirect minor
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.46.0 → v1.47.0 age confidence indirect minor
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.46.0 → v1.47.0 age confidence indirect minor
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.46.0 → v1.47.0 age confidence indirect minor
go.opentelemetry.io/otel/exporters/prometheus v0.68.0 → v0.69.0 age confidence indirect minor
go.opentelemetry.io/otel/exporters/stdout/stdoutlog v0.22.0 → v0.23.0 age confidence indirect minor
go.opentelemetry.io/otel/exporters/stdout/stdoutmetric v1.46.0 → v1.47.0 age confidence indirect minor
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.46.0 → v1.47.0 age confidence indirect minor
go.opentelemetry.io/otel/log v0.22.0 → v1.47.0 age confidence indirect major
go.opentelemetry.io/otel/metric v1.46.0 → v1.47.0 age confidence indirect minor
go.opentelemetry.io/otel/sdk v1.46.0 → v1.47.0 age confidence indirect minor
go.opentelemetry.io/otel/sdk/log v0.22.0 → v1.47.0 age confidence indirect major
go.opentelemetry.io/otel/sdk/metric v1.46.0 → v1.47.0 age confidence indirect minor
go.opentelemetry.io/otel/trace v1.46.0 → v1.47.0 age confidence indirect minor
go.opentelemetry.io/proto/otlp v1.11.0 → v1.11.1 age confidence indirect patch
go.yaml.in/yaml/v2 v2.4.4 → v3.0.5 age confidence indirect major
golang.org/x/net 2824783 → 01e3d03 indirect digest
golang.org/x/tools v0.50.0 → v0.51.0 age confidence indirect minor
gomodules.xyz/jsonpatch/v2 v2.5.0 → v3.0.1 age confidence indirect major
google.golang.org/api v0.298.0 → v0.300.0 age confidence indirect minor v0.301.0
google.golang.org/grpc v1.83.2 → v1.84.0 age confidence indirect minor
gopkg.in/evanphx/json-patch.v4 v4.13.0 → v5.9.11 age confidence indirect major
gopkg.in/yaml.v2 v2.4.0 → v3.0.1 age confidence indirect major
k8s.io/code-generator v0.37.0 → v0.37.1 age confidence indirect patch
registry.access.redhat.com/ubi9-minimal 9.8-1790074235 → 9.8-1791279563 age confidence final patch
registry.access.redhat.com/ubi9/ubi-minimal 9.8-1790074235 → 9.8-1791279563 age confidence final patch
sigs.k8s.io/kustomize/api v0.21.1 → v0.21.2 age confidence indirect patch
sigs.k8s.io/kustomize/cmd/config v0.21.1 → v0.21.2 age confidence indirect patch
sigs.k8s.io/kustomize/kyaml v0.21.1 → v0.21.2 age confidence indirect patch
sigs.k8s.io/structured-merge-diff/v6 v6.4.2 → v7.0.0 age confidence indirect major

Release Notes

googleapis/google-cloud-go (cloud.google.com/go/auth)

v0.24.0

  • bigquery: Support for the NUMERIC type.
  • bigtable:
    • cbt: Optionally specify columns for read/lookup
    • Support instance-level administration.
  • oslogin: New client for the OS Login API.
  • pubsub:
    • The package is now stable. There will be no further breaking changes.
    • Internal changes to improve Subscription.Receive behavior.
  • storage: Support updating bucket lifecycle config.
  • spanner: Support struct-typed parameter bindings.
  • texttospeech: New client for the Text-to-Speech API.
KimMachineGun/automemlimit (github.com/KimMachineGun/automemlimit)

v1.0.0

Compare Source

After four years of iteration through v0.x, automemlimit v1.0.0 is finally here! This release simplifies the public API and improves cgroup memory limit detection.

Key changes from v0.x:

  • memlimit.Set replaces the memlimit.SetGoMemLimit* functions
  • memlimit.Set returns the previous GOMEMLIMIT instead of 0 when configuration is skipped or an error occurs
  • memlimit.Set sets GOMEMLIMIT to math.MaxInt64 when the provider returns memlimit.ErrNoLimit
  • memlimit.FromCgroup replaces the version-specific cgroup providers
  • memlimit.WithEnv, AUTOMEMLIMIT_EXPERIMENT, and AUTOMEMLIMIT_DEBUG were removed
    • Use memlimit.FromSystem for system memory fallback
  • memlimit.WithRefreshInterval now takes a context.Context for cancellation
  • memlimit.WithMin was added to set a lower bound for GOMEMLIMIT
caddyserver/caddy (github.com/caddyserver/caddy/v2)

v2.11.7

Compare Source

This patch release fixes regressions from 2.11.6, including a crash when proxying over HTTP/2 and streams that were cut off after a minute. If you're on 2.11.6, we recommend upgrading. It also adds support for the brand new Incremental header field (RFC 10036).

Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.

Highlights

  • Fixed: crash and dropped streams caused by the new idle timeouts. 2.11.6 introduced default idle read/write timeouts, which caused some problems:

    • In 2.11.6, the request body's idle deadline could outlive the handler that set it:

      • Over HTTP/2, Caddy could panic with a nil pointer dereference when the reverse proxy was still reading a request body after the handler had returned. (#​8101)
      • Over HTTP/1.1, streaming responses to requests with a body, such as SSE clients that open the stream with a POST, were cut off exactly 60 seconds after the body was read. (#​8103)

      Both are fixed in #​8107. Thanks @​steadytao!

    • Over HTTP/2, streaming responses that paused between writes for longer than write_idle (1 minute by default), like quiet SSE streams, were reset with a stream error. As documented, only a write that stalls should count. Thanks @​WeidiDeng! (#​8118, #​8119)

  • Fixed: placeholders for missing cookies are empty again. Since 2.11.6, places that keep unknown placeholders as written, like respond headers, would output {http.request.cookie.*} literally when the cookie wasn't in the request. The same happened to {http.request.tls.*} on plain HTTP requests. Both are empty again. Thanks @​steadytao! (#​8019)

  • New: support for the Incremental header field (RFC 10036). It's the standard replacement for NGINX's proprietary X-Accel-Buffering header. If an upstream response has Incremental: ?1, reverse_proxy forwards it immediately, the same as flush_interval -1, and encode streams it instead of holding it back. Great for Mercure, SSE and other streaming apps.

    • If the request_buffers or response_buffers options would prevent incremental forwarding, Caddy responds with 501 Not Implemented instead of silently buffering, as the RFC requires.
    • The new proxy_status_name option adds a Proxy-Status header to those responses, explaining why the message was refused.

    Thanks @​dunglas! (#​8020)

  • Faster TLS handshakes: When nothing subscribes to certificate events and debug logging is off, CertMagic no longer builds event data for every handshake. Certificate lookup per handshake is about twice as fast, with 10 allocations instead of 15. Thanks @​u5surf! (#​8010)

  • Unix sockets: When a reload moves a listener (or the admin endpoint) off a Unix socket, the old socket now closes right away and its file is removed. Before, clients connecting to the old path would hang until the next garbage collection, about 2 minutes later. Thanks @​littfed! (#​8061)

  • Headers handler: Multiple Set-Cookie values in a JSON config's set are now sent as separate header fields, instead of being joined with commas into one field that clients can't parse. Thanks @​Indra55! (#​8080)

  • caddy fmt no longer deletes an opening brace at the very end of the input. Thanks @​n0liu! (#​8047)

What's Changed

New Contributors

Full Changelog: caddyserver/caddy@v2.11.6...v2.11.7

v2.11.6

Compare Source

This patch release contains a large number of minor and some noticeable enhancements and bug fixes. Thank you to everyone who contributed or spent their LLM tokens responsibly to help with this release!

We have much more in the pipeline still, as AI has made contributions of all quality levels cheap and easy. We will be trying to go through them as quickly and efficiently as we can.

Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.

⚠️ Please read the breaking changes below before upgrading. Most of them come from security hardening, and most configs won't notice. If you were relying on one of the old behaviors, though, you'll want to know about it.

Highlights

  • New url_pattern request matcher: Match requests with the URLPattern standard, the same syntax used by browsers (JS) and many web frameworks. It supports named groups, wildcards, and regexp components. Captured groups become placeholders ({http.url_pattern.<component>.<group>}), and there's a matching url_pattern CEL function too. Thanks @​dunglas! (#​7787)
  • Slowloris mitigation: New idle read/write timeouts reset on every successful read or write. A stalled connection gets cut off, and a slow one that's still making progress is left alone. You can also set optional minimum transfer rates, and there's a new timeouts handler directive for per-route tuning. (#​7913)
  • New tls_automate_names global option: Manage certificates for names without serving them in a site block. (#​8015)
  • New expected_underscore_headers server option: If dropping header fields with underscores in 2.11.4 broke your app, you can now list the specific headers to keep. (#​7809)
  • HTTP/3 over Tailscale and other low-MTU links now works, because the initial QUIC packet size is smaller. (#​7886)
  • Reverse proxy got more love:
    • partial responses are flushed to clients properly (#​7849)
    • TCP half-close is propagated on upgraded streams (#​8027)
    • versions 3 upstreams now honor tls_trust_pool (#​8042)
    • active health check state is kept separate per check config, so one handler's failing probes don't mark the upstream down for everyone else (#​7916)
    • the random_choose policy distributes correctly now (#​7873)
  • Server-sent events behind encode now stream immediately instead of being buffered. (#​7905)
  • Graceful shutdown now waits for servers left over from previous configs, so long-lived responses that started before a reload aren't cut off at exit. (#​8009)
  • Caddyfile: import now works inside named routes (#​7986), and quoted braces are treated as literal arguments (#​7875).
  • Logging:
  • Performance: fewer allocations in request hot paths, encoding negotiation, and the reverse proxy, from @​jvoisin and @​dunglas. Directory browsing is much faster for large directories. (#​7847, #​7903, #​7911, #​7925, #​7926, #​7936)
  • Other new stuff:
    • {http.request.proto_name} placeholder (#​7782)
    • FastCGI populates SERVER_ADDR (#​7912)
    • multiple authentication providers no longer clobber each other's responses (#​7904)

⚠️ Breaking changes

  • Go 1.26 is now the minimum version for building Caddy and plugins. (#​8056)
  • Request headers are limited to 16 KiB by default. Before, we used Go's 1 MB default. Requests with larger headers (giant cookies, oversized tokens, etc.) will now get 431 Request Header Fields Too Large. If you need more, raise it with the max_header_size server option.
  • New 1-minute idle read/write timeouts by default. If a request body read or a response write stalls (makes no progress at all) for longer than that, the connection is aborted. Pauses between writes, like with SSE, don't count. Some long-lived streams where the client goes quiet mid-body may be affected. You can tune these with read_body_idle and write_idle in the timeouts server option, or per-route with the timeouts directive. (#​7913)
  • Request header fields containing . are now dropped, the same way underscores were in 2.11.4. PHP folds . to _, so these could be used to impersonate legitimate headers. If you need specific ones, allow them with the new expected_dot_headers server option.
  • A wildcard site's client_auth no longer applies to more specific hostnames that have their own site blocks. For example, public.example.com no longer inherits mTLS from *.example.com. If you were counting on that inheritance, configure client_auth on the specific site explicitly. (#​7920)
  • Stricter config validation. Some configs that used to be silently accepted (and probably didn't do what you expected) are now errors:
    • duplicate named_routes (#​7800)
    • duplicate forward_auth uri (#​7814)
    • invalid weighted_round_robin weights (#​7807)
    • a non-integer browse file_limit (#​7988)
    • duplicate or ambiguous map inputs (#​8067)
    • malformed map destination placeholders (#​8074)
    • module paths with ambiguous @ version separators (#​7974)
  • Admin API /load now returns 400 with warnings inside a valid JSON body when a config is invalid. Before, it returned 200 with two concatenated JSON objects. (#​7267)
  • method matcher values are normalized to uppercase, so method get now matches GET requests. (#​7832)

Security fixes

Thank you to everyone who reported responsibly and helped with patches:

  • reverseproxy: When a route used both forward_auth and reverse_proxy, a request could be sent on the wrong upstream connection. Reported by @​carlt, fixed by @​WeidiDeng. (GHSA-6365-7ppr-5r92, #​7859)
  • reverseproxy: Hop-by-hop headers from upstreams are now stripped from 101 Switching Protocols responses too. Thanks @​jirn073-76.
  • caddyhttp: handle_path and uri strip_prefix/strip_suffix now canonicalize the resulting path, so it can't bypass path-based authorization. Thanks @​steadytao.
  • caddyhttp: Extended the 2.11.4 header-alias filter to . (see above) to prevent bypassing forward_auth copy_headers with PHP/FastCGI backends. Thanks @​dunglas.
  • caddyhttp: The path_regexp matcher now normalizes Windows backslashes like the path matcher does. This completes the fix for CVE-2026-52844. Thanks @​thientd. (#​7858)
  • fileserver: Windows 8.3 short names are rejected in every path component, not just the last one. Thanks @​DavidCarliez. (#​7952)
  • fileserver: Fixed ETag collisions between files with different modification times and sizes. Thanks @​dunglas.
  • fastcgi: The client's Proxy header is no longer passed to backends as HTTP_PROXY (HTTPoxy). Thanks @​bzyy1024. (#​7934)
  • reverseproxy: Sticky session cookie hashes are compared in constant time. Thanks @​alhudz. (#​7853)
  • admin: Request paths are normalized in the remote admin access check, and origin/host allow-lists compare case-insensitively (defense-in-depth). Thanks @​AmariahAK, @​mohammed90, and @​hktitof. (#​7910, #​7973, #​7993)
  • caddyhttp: Oversized request bodies used through placeholders now correctly return 413. Thanks @​hktitof. (#​7969)

⚠️ These security patches may be breaking if your application relies on the buggy behaviors.

🚨 Notice for Caddy plugin maintainers: Dependabot will probably alert you to the security fixes in Caddy and urge you to upgrade it in your go.mod file. Please ONLY upgrade the Caddy dependency if there's a change to an exported API your plugin uses. Note that doing so now also requires Go 1.26.

Thank you to everyone who was involved this release, especially our 40 new contributors! 🎉

What's Changed

✂ Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux

red-hat-konflux Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 4 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=3 days

Details:

Package Change
go 1.26.7 -> 1.27
k8s.io/apimachinery v0.37.0 -> v0.37.1
golang.org/x/crypto/x509roots/fallback v0.0.0-20260908180501-3f62bf119e84 -> v0.0.0-20260929172509-b39ff6d641ec
google.golang.org/genproto/googleapis/api v0.0.0-20260825221802-da73d73af1c5 -> v0.0.0-20260928230214-8a89bd6388cc
google.golang.org/genproto/googleapis/rpc v0.0.0-20260825221802-da73d73af1c5 -> v0.0.0-20260928230214-8a89bd6388cc

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/all branch 6 times, most recently from 1908937 to 7cc499f Compare September 28, 2026 00:41
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update all dependencies fix(deps): update all dependencies Sep 28, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/all branch 9 times, most recently from e1a998f to 27b4a25 Compare October 5, 2026 00:43
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/all branch 2 times, most recently from 26750dd to c6aadd3 Compare October 6, 2026 06:57
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/all branch from c6aadd3 to 66d5e0b Compare October 7, 2026 00:55

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants