Skip to content

fix(deps): update go dependencies - #585

Merged
privateip merged 1 commit into
mainfrom
renovate/go-deps
Sep 21, 2026
Merged

privateip merged 1 commit into
mainfrom
renovate/go-deps

Conversation

@renovate

@renovate renovate Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/mdlayher/netlink v1.9.0v1.11.2 age confidence
google.golang.org/grpc v1.83.2v1.84.0 age confidence

Release Notes

mdlayher/netlink (github.com/mdlayher/netlink)

v1.11.2

Compare Source

  • [Bug Fix]: #​291 fixed a bug
    where netlink.Conn.Receive would block concurrent calls to
    netlink.Conn.Send when blocking in recvmsg.
  • [Improvement]: #​289 updated
    golang.org/x/net and golang.org/x/sys dependencies.

v1.11.1

Compare Source

  • [Bug Fix]: #​283 fixed a bug
    where netlink.Conn.Receive would reject valid netlink messages whose header
    length is not aligned. This is common with nfqueue, nflog and conntrack events.
  • [Bug Fix]: #​284 fixed a bug
    where netlink.Message.Data could be silently overwritten by subsequent
    netlink.Conn.Receive calls when netlink.Config.MessageBufferSize is enabled,
    due to pooled buffer reuse.
  • [Improvement]: #​282 improved
    error handling by usage of errors package.

v1.11.0

Compare Source

This is the first release of package netlink that only supports Go 1.25+.

  • [Bug Fix]: #​280 fixed a
    critical bug where netlink.Conn.Receive and netlink.Conn.ReceiveIter would
    panic if the received message was unaligned.
  • [Improvement]: #​277 added
    big-endian test fixtures for nlenc and deprecated endian helpers in favor of
    binary.NativeEndian.
  • [Improvement]: #​276 fixed
    skipping of tests on big-endian hosts.
  • [Improvement]: #​273 added
    golangci-lint to the CI pipeline and fixed all existing lint issues.
  • [Improvement]: #​272 updated
    dependencies and Go version to 1.25.

v1.10.0

Compare Source

Users of this version should upgrade to v1.11.0 as this version contains a
critical bug.

  • [New API]: #​270 added
    MessageBufferSize option to netlink.Config for configuring the size of the
    copy buffer used for receiving messages. This can improve performance in
    high-throughput applications by reducing the number of syscalls needed to
    receive messages.
  • [Improvement]: #​219 added
    debug logging inspired by libmnl. This is now the new default when setting
    NLDEBUG in the environment.
  • [New API]: #​258 added
    netlink.Conn.ReceiveIter for iterating over responses without collecting
    them into a slice. It also optimized netlink.Conn.Receive to use this new
    API internally so that less memory is used.
  • [Improvement]: #​269 made it so
    nltest.Conn.Receive can be used to test that multi-part messages are drained
    properly.
  • [Improvement]: #​266 optimized
    the initial parsing of netlink messages in netlink.Socket.Receive by adding
    an iterator for parsing messages directly from the receive buffer.
  • [Improvement]: #​267 added
    integration test benchmarks for multi-part dumps.
  • [Improvement]: #​215 optimized
    the internal peek/allocate logic in netlink.Socket.Receive. Messages are
    no longer being copied during peeking and the buffer is allocated to the exact
    size of the upcoming message.
  • [Bug Fix]: #​265 fixed a bug
    where concurrent calls to netlink.Conn.Receive could race with each other
    when handling multi-part messages. Calls to Receive are now serialized.
  • [Improvement]: #​264 added
    handling for truncated messages in netlink.Socket.Receive.
grpc/grpc-go (google.golang.org/grpc)

v1.84.0: Release 1.84.0

Compare Source

Behavior Changes

  • stats/otel: The grpc.lb.pick_first.* metrics have been removed and replaced with grpc.subchannel.* metrics. See gRFC A94 for more details. (#​9215)

New Features

  • xds: Add support for contains_match in route header matchers. (#​9223)

Bug Fixes

  • client: Fix a bug where a ClientConn could get permanently stuck in IDLE when an RPC was canceled during stream creation. Previously, such cancellations triggered stream cleanup twice, corrupting the channel's idleness state and causing subsequent RPCs to fail with deadline exceeded errors. (#​9191)
  • client: Fix a bug where non-gRPC HTTP responses ending with an empty DATA frame failed the RPC with status code Internal instead of preserving the HTTP-mapped status code and response body. (#​9217)
  • credentials: Validate metadata returned by per-RPC credentials, failing the RPC with status code Internal if invalid keys or values are found. Previously, invalid metadata from credentials was sent to the server in outgoing HTTP/2 requests. (#​9202)
  • credentials/sts: Prevent potential token leakage by disallowing HTTP redirects during STS token exchange. Previously, 3xx redirects were followed automatically, replaying the request body containing authentication tokens to the redirect destination. (#​9299)
  • randomsubsetting: Ignore endpoints that contain no addresses. Previously, this could cause the policy to panic while computing hashes. (#​9259)
  • stats/otel: Ensure method names are populated in trace spans when metrics are disabled. Previously, running with tracing enabled and metrics disabled resulted in server trace spans lacking the RPC method name (recording only "Recv."). (#​9262)
  • transport: Return io.ErrUnexpectedEOF when EOF is encountered after partial header or message body reads. Previously, partial reads could return a plain io.EOF, failing to distinguish truncated data from a clean end of stream. (#​9204)
  • transport: Validate metadata supplied by balancers (in PickResult.Metadata) and resolver addresses, failing the RPC with status code Internal if invalid keys or values are found. Previously, invalid metadata from these sources was sent to the server in outgoing HTTP/2 requests. (#​9203)
  • xds: Fix a rare corner case that could prevent a cluster from being removed when it is no longer in use. (#​9140)
  • xds: Fix panic during route matching for routes containing header matchers with empty exact_match strings. (#​9223)
  • xds: Reject routes containing header matchers with empty prefix_match or suffix_match strings. Previously, this caused a panic during route matching. (#​9223)
  • xds: Fix EDS drop policies being applied at a much lower rate than configured due to an integer overflow. (#​9257)
  • xds: Reject EDS resources containing drop policies with unsupported denominators. Previously, such resources caused the client to panic when calculating drop rates. (#​9218)
  • xds/rbac: Reject RBAC configurations containing nested Principal or Permission rules with :scheme or grpc- prefixed header matchers. Previously, such configurations could cause DENY policies to fail open. (#​9258)
  • xds/rbac: Rewrite host header matchers to :authority in nested Principal and Permission rules. Previously, this rewrite only applied to top-level rules, causing nested host matchers to never match incoming requests and DENY policies to fail open. (#​9258)
  • xds/rbac: Reject CidrRanges with an unset prefix length. Previously, an omitted prefix_len field caused a panic during RBAC configuration parsing. (#​9250)

Performance Improvements

  • transport: Avoid a heap allocation when flushing shared write buffers. (#​9233)
  • credentials/alts: Support dynamic frame size negotiation and add the GRPC_GO_EXPERIMENTAL_ALTS_MAX_FRAME_SIZE environment variable (default 4KiB, max 512KiB) to configure the maximum ALTS record frame size. (#​9268)

Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • "before 6am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner September 21, 2026 04:27
@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Sep 21, 2026
@renovate

renovate Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated

Details:

Package Change
google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa -> v0.0.0-20260706201446-f0a921348800

@renovate
renovate Bot force-pushed the renovate/go-deps branch from 602aa03 to b382b14 Compare September 21, 2026 16:11
@renovate renovate Bot changed the title fix(deps): update module google.golang.org/grpc to v1.84.0 fix(deps): update go dependencies Sep 21, 2026
@privateip
privateip merged commit 2ee49fd into main Sep 21, 2026
13 checks passed
@privateip
privateip deleted the renovate/go-deps branch September 21, 2026 16:26
@privateip privateip mentioned this pull request Sep 21, 2026
1 task
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant