Skip to content

deps: bump google.golang.org/grpc from 1.83.1 to 1.83.2 in the grpc-protobuf group across 1 directory - #127

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/grpc-protobuf-a135cde889
Closed

deps: bump google.golang.org/grpc from 1.83.1 to 1.83.2 in the grpc-protobuf group across 1 directory#127
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/grpc-protobuf-a135cde889

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 31, 2026

Copy link
Copy Markdown
Contributor

Bumps the grpc-protobuf group with 1 update in the / directory: google.golang.org/grpc.

Updates google.golang.org/grpc from 1.83.1 to 1.83.2

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.83.2

Security

  • server: Reject requests missing both :authority and Host headers with HTTP 400 and status Internal. (grpc/grpc-go#9365)
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 31, 2026
Bumps the grpc-protobuf group with 1 update in the / directory: [google.golang.org/grpc](https://github.com/grpc/grpc-go).


Updates `google.golang.org/grpc` from 1.83.1 to 1.83.2
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.83.1...v1.83.2)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.83.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: grpc-protobuf
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title deps: bump google.golang.org/grpc from 1.83.1 to 1.83.2 in the grpc-protobuf group deps: bump google.golang.org/grpc from 1.83.1 to 1.83.2 in the grpc-protobuf group across 1 directory Sep 7, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/grpc-protobuf-a135cde889 branch from 039afef to f778d73 Compare September 7, 2026 13:46
sylvesterdamgaard added a commit that referenced this pull request Sep 7, 2026
Dependabot PRs #126-#128 and #138-#140 all fail the Supply chain check
for the same structural reason: they bump go.mod but cannot regenerate
sbom.json, so 'Check SBOM is current' rejects every one of them. Applied
together here with the SBOM regenerated:

- prometheus/client_model 0.6.2 -> 0.6.3 (#140)
- shirou/gopsutil/v4 4.26.7 -> 4.26.8 (#139)
- prometheus/common 0.70.1 -> 0.71.0 (#138)
- spf13/pflag 1.0.9 -> 1.0.10 (#128)
- google.golang.org/grpc 1.83.1 -> 1.83.2 (+genproto, protobuf) (#127)
- otel group -> 1.46.0 (otel, otlptracegrpc, stdouttrace, sdk, trace) (#126)

Full test suite, build, vet, gofmt and license-check green locally.
@sylvesterdamgaard

Copy link
Copy Markdown
Contributor

Superseded by #141 (merged) — all six updates applied there with the SBOM regenerated, which is what blocked the Supply chain check on the individual PRs.

@dependabot @github

dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@sylvesterdamgaard
sylvesterdamgaard deleted the dependabot/go_modules/grpc-protobuf-a135cde889 branch September 7, 2026 22:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant