Skip to content

chore(deps): bump the go group across 1 directory with 11 updates - #271

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-1c452ccad8
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-1c452ccad8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the go group with 11 updates in the / directory:

Package From To
github.com/coreos/go-oidc/v3 3.20.0 3.21.0
github.com/knadh/koanf/v2 2.3.6 2.3.7
github.com/labstack/echo/v5 5.3.1 5.4.0
github.com/modelcontextprotocol/go-sdk 1.7.0 1.8.0
github.com/prometheus/client_model 0.6.2 0.6.3
golang.org/x/oauth2 0.36.0 0.37.0
golang.org/x/sync 0.22.0 0.23.0
golang.org/x/sys 0.47.0 0.48.0
golang.org/x/time 0.15.0 0.16.0
google.golang.org/grpc 1.83.2 1.84.0
modernc.org/sqlite 1.57.0 1.59.0

Updates github.com/coreos/go-oidc/v3 from 3.20.0 to 3.21.0

Release notes

Sourced from github.com/coreos/go-oidc/v3's releases.

v3.21.0

What's Changed

New Contributors

Full Changelog: coreos/go-oidc@v3.20.0...v3.21.0

Commits
  • c914bd3 oidc: ignore JWKs with unsupported key types rather than failing
  • See full diff in compare view

Updates github.com/knadh/koanf/v2 from 2.3.6 to 2.3.7

Release notes

Sourced from github.com/knadh/koanf/v2's releases.

v2.3.7

What's Changed

New Contributors

Full Changelog: knadh/koanf@v2.3.6...v2.3.7

Commits
  • f3b40fa Fix typed map getter funcs returning empty results (#450)
  • c69572c Fix Slices silently dropping a natively-typed []map[string]any (#448)
  • 83a6751 Bump google.golang.org/grpc from 1.82.1 to 1.83.1 in /examples (#446)
  • c316bd1 Fix empty slices resulting in removed keys in StringsMap() (#449)
  • 6ad56fe Fix key collission on 'Unflatten' by making insertions deterministic. Closes ...
  • eb15bf7 fix: panic when Config.Transport is not supplied (#439)
  • defde9b Fix azurevault throwing 403 incorrectly fetching disabled keys. Closes #436.
  • fb45026 Skip env entries without '=' in env provider avoid panicking.
  • See full diff in compare view

Updates github.com/labstack/echo/v5 from 5.3.1 to 5.4.0

Release notes

Sourced from github.com/labstack/echo/v5's releases.

v5.4.0

Security

This release fixes several security issues. Upgrading is recommended. Some fixes change behavior; read "Behavior changes to check before upgrading" below.

  • Request scheme: Context.Scheme() now uses the X-Forwarded-Proto, X-Forwarded-Protocol, X-Forwarded-Ssl and X-Url-Scheme headers only when the request comes directly from a loopback, link-local or private network address or a unix socket. Before this, any client could send X-Forwarded-Proto: https over plain HTTP and skip HTTPSRedirect. When X-Forwarded-Proto is present, only it is used (its last value), and the scheme is returned in lowercase. Echo#SchemeExtractor (and Config.SchemeExtractor) selects the strategy: ExtractSchemeFromHeaders(...TrustOption) (default), ExtractSchemeDirect() or LegacySchemeExtractor(). The Secure middleware now sets HSTS based on Context.Scheme(). The Proxy middleware always sets X-Forwarded-Proto from Context.Scheme() and removes X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme before forwarding. GHSA-2ffq-g2xg-c22p
  • Proxy middleware: always sets X-Real-IP from Context.RealIP(), so a client can no longer pass a spoofed X-Real-IP to the upstream. GHSA-99jh-6h7p-pp36
  • JSONP: Context.JSONP and Context.JSONPBlob accept only a callback that is empty, a JavaScript identifier or a dot-separated path of identifiers (ASCII letters, digits, _ and $). Any other callback returns a 400 Bad Request error that wraps the new ErrInvalidJSONPCallback, and nothing is written. JSONP responses now carry X-Content-Type-Options: nosniff. JSONP lets any website read the response with the user's cookies, so do not use it for data that needs authentication. GHSA-h9g5-28mm-hx3g
  • MethodOverride: a POST can no longer be overridden to GET, HEAD, OPTIONS, TRACE or CONNECT. Before this, with the MethodFromForm or MethodFromQuery getter and MethodOverride registered with Use before the CSRF middleware, _method=GET skipped the CSRF check. Register MethodOverride with Echo#Pre. GHSA-r7w9-592q-9vg4
  • Redirects: the trailing slash middlewares and the static directory redirect percent-encode control characters in the redirect path. Before this, /%09/evil.example/ redirected browsers to evil.example. GHSA-v753-g4cw-jm48
  • Static files: with the default settings, the Static middleware resolves files from the same form of the path that the router matched, so /admin%2Fsecret.txt or /%61dmin/secret.txt can no longer reach a file under a guarded /admin/* route. GHSA-375p-5qhx-8wq4 The Static middleware and StaticDirectoryHandler (used by Echo.Static, Echo.StaticFS, Group.Static and Group.StaticFS) no longer serve paths with a ., .. or empty segment, such as /assets/../admin/secret.txt, also after path unescaping. GHSA-3pmx-cf9f-34xr

Behavior changes to check before upgrading

  • Proxies or load balancers with public IP addresses. If a proxy connects to your app from a public (or 100.64.0.0/10) address, its X-Forwarded-Proto is now ignored: HTTPSRedirect redirects in a loop and the Secure middleware stops sending HSTS. This affects, for example, Cloudflare, CloudFront and Azure Front Door connecting to a public origin, the GCP external HTTP(S) load balancer including GKE Ingress (35.191.0.0/16, 130.211.0.0/22), and networks that use 100.64.0.0/10 (such as Alibaba Cloud SLB or EKS custom networking). Trust the proxy's address ranges:
    _, gclb1, _ := net.ParseCIDR("35.191.0.0/16")
    _, gclb2, _ := net.ParseCIDR("130.211.0.0/22")
    e.SchemeExtractor = echo.ExtractSchemeFromHeaders(echo.TrustIPRange(gclb1), echo.TrustIPRange(gclb2))
    Proxies on the same host, in a private network (AWS ALB, in-cluster ingress controllers such as ingress-nginx or Traefik, most PaaS routers) or on a unix socket keep working without changes. echo.LegacySchemeExtractor() restores the old behavior but is not safe unless every request passes through a proxy that sets these headers. Serverless adapters or middleware that set RemoteAddr to the client's address also make X-Forwarded-Proto ignored (or, if they take it from a header, spoofable).
  • Trusted proxies must set X-Forwarded-Proto. A proxy on a trusted address that passes the client's X-Forwarded-Proto through (for example nginx without proxy_set_header X-Forwarded-Proto $scheme;) still lets the client choose the scheme. An invalid X-Forwarded-Proto value now results in http instead of falling back to the other scheme headers.
  • Your own tests. httptest.NewRequest sets RemoteAddr to 192.0.2.1:1234, which is not trusted, so tests that set X-Forwarded-Proto now see http. Set req.RemoteAddr = "10.0.0.1:1234" or use e.SchemeExtractor = echo.LegacySchemeExtractor() in such tests.
  • Proxy middleware headers. X-Real-IP sent to the upstream is now always Context.RealIP(). In a chain like nginx → Echo Proxy → upstream, configure Echo#IPExtractor (for example echo.ExtractIPFromRealIPHeader()) to pass the client address on. X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme are no longer forwarded; X-Forwarded-Proto carries the scheme.
  • MethodOverride. Overriding a POST to GET (for example with X-HTTP-Method-Override: GET to send a long query in a POST body) is no longer done; such requests keep the POST method.
  • Static files. Paths with a double slash or dot segment (for example /assets//app.js) now return 404; in HTML5 mode the index is still served. The Static middleware no longer finds file names that the client sends with non-default escaping (for example %2C, %40 or lowercase hex like %c3%a9) unless StaticConfig.EnablePathUnescaping is set; Echo.Static has behaved this way since v5.2.1. With StaticConfig.EnablePathUnescaping or Config.EnablePathUnescapingStaticFiles, encoded dots (%2e%2e) no longer traverse directories, but encoded slashes are still decoded, so do not combine these options with route-based access control.
  • JSONP. Context.JSONP returns an error for callbacks that are not JavaScript identifiers.

Documentation

  • IPExtractor docs: corrected the description of the default (the direct peer address has been used since v5.1.0).
  • Static middleware: when registered with Echo#Use it runs before route and group middleware, so route guards do not protect the files it serves.
Changelog

Sourced from github.com/labstack/echo/v5's changelog.

v5.4.0 - 2026-09-27

Security

This release fixes several security issues. Upgrading is recommended. Some fixes change behavior; read "Behavior changes to check before upgrading" below.

  • Request scheme: Context.Scheme() now uses the X-Forwarded-Proto, X-Forwarded-Protocol, X-Forwarded-Ssl and X-Url-Scheme headers only when the request comes directly from a loopback, link-local or private network address or a unix socket. Before this, any client could send X-Forwarded-Proto: https over plain HTTP and skip HTTPSRedirect. When X-Forwarded-Proto is present, only it is used (its last value), and the scheme is returned in lowercase. Echo#SchemeExtractor (and Config.SchemeExtractor) selects the strategy: ExtractSchemeFromHeaders(...TrustOption) (default), ExtractSchemeDirect() or LegacySchemeExtractor(). The Secure middleware now sets HSTS based on Context.Scheme(). The Proxy middleware always sets X-Forwarded-Proto from Context.Scheme() and removes X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme before forwarding. GHSA-2ffq-g2xg-c22p
  • Proxy middleware: always sets X-Real-IP from Context.RealIP(), so a client can no longer pass a spoofed X-Real-IP to the upstream. GHSA-99jh-6h7p-pp36
  • JSONP: Context.JSONP and Context.JSONPBlob accept only a callback that is empty, a JavaScript identifier or a dot-separated path of identifiers (ASCII letters, digits, _ and $). Any other callback returns a 400 Bad Request error that wraps the new ErrInvalidJSONPCallback, and nothing is written. JSONP responses now carry X-Content-Type-Options: nosniff. JSONP lets any website read the response with the user's cookies, so do not use it for data that needs authentication. GHSA-h9g5-28mm-hx3g
  • MethodOverride: a POST can no longer be overridden to GET, HEAD, OPTIONS, TRACE or CONNECT. Before this, with the MethodFromForm or MethodFromQuery getter and MethodOverride registered with Use before the CSRF middleware, _method=GET skipped the CSRF check. Register MethodOverride with Echo#Pre. GHSA-r7w9-592q-9vg4
  • Redirects: the trailing slash middlewares and the static directory redirect percent-encode control characters in the redirect path. Before this, /%09/evil.example/ redirected browsers to evil.example. GHSA-v753-g4cw-jm48
  • Static files: with the default settings, the Static middleware resolves files from the same form of the path that the router matched, so /admin%2Fsecret.txt or /%61dmin/secret.txt can no longer reach a file under a guarded /admin/* route. GHSA-375p-5qhx-8wq4 The Static middleware and StaticDirectoryHandler (used by Echo.Static, Echo.StaticFS, Group.Static and Group.StaticFS) no longer serve paths with a ., .. or empty segment, such as /assets/../admin/secret.txt, also after path unescaping. GHSA-3pmx-cf9f-34xr

Behavior changes to check before upgrading

  • Proxies or load balancers with public IP addresses. If a proxy connects to your app from a public (or 100.64.0.0/10) address, its X-Forwarded-Proto is now ignored: HTTPSRedirect redirects in a loop and the Secure middleware stops sending HSTS. This affects, for example, Cloudflare, CloudFront and Azure Front Door connecting to a public origin, the GCP external HTTP(S) load balancer including GKE Ingress (35.191.0.0/16, 130.211.0.0/22), and networks that use 100.64.0.0/10 (such as Alibaba Cloud SLB or EKS custom networking). Trust the proxy's address ranges:
    _, gclb1, _ := net.ParseCIDR("35.191.0.0/16")
    _, gclb2, _ := net.ParseCIDR("130.211.0.0/22")
    e.SchemeExtractor = echo.ExtractSchemeFromHeaders(echo.TrustIPRange(gclb1), echo.TrustIPRange(gclb2))
    Proxies on the same host, in a private network (AWS ALB, in-cluster ingress controllers such as ingress-nginx or Traefik, most PaaS routers) or on a unix socket keep working without changes. echo.LegacySchemeExtractor() restores the old behavior but is not safe unless every request passes through a proxy that sets these headers. Serverless adapters or middleware that set RemoteAddr to the client's address also make X-Forwarded-Proto ignored (or, if they take it from a header, spoofable).
  • Trusted proxies must set X-Forwarded-Proto. A proxy on a trusted address that passes the client's X-Forwarded-Proto through (for example nginx without proxy_set_header X-Forwarded-Proto $scheme;) still lets the client choose the scheme. An invalid X-Forwarded-Proto value now results in http instead of falling back to the other scheme headers.
  • Your own tests. httptest.NewRequest sets RemoteAddr to 192.0.2.1:1234, which is not trusted, so tests that set X-Forwarded-Proto now see http. Set req.RemoteAddr = "10.0.0.1:1234" or use e.SchemeExtractor = echo.LegacySchemeExtractor() in such tests.
  • Proxy middleware headers. X-Real-IP sent to the upstream is now always Context.RealIP(). In a chain like nginx → Echo Proxy → upstream, configure Echo#IPExtractor (for example echo.ExtractIPFromRealIPHeader()) to pass the client address on. X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme are no longer forwarded; X-Forwarded-Proto carries the scheme.
  • MethodOverride. Overriding a POST to GET (for example with X-HTTP-Method-Override: GET to send a long query in a POST body) is no longer done; such requests keep the POST method.
  • Static files. Paths with a double slash or dot segment (for example /assets//app.js) now return 404; in HTML5 mode the index is still served. The Static middleware no longer finds file names that the client sends with non-default escaping (for example %2C, %40 or lowercase hex like %c3%a9) unless StaticConfig.EnablePathUnescaping is set; Echo.Static has behaved this way since v5.2.1. With StaticConfig.EnablePathUnescaping or Config.EnablePathUnescapingStaticFiles, encoded dots (%2e%2e) no longer traverse directories, but encoded slashes are still decoded, so do not combine these options with route-based access control.
  • JSONP. Context.JSONP returns an error for callbacks that are not JavaScript identifiers.

Documentation

  • IPExtractor docs: corrected the description of the default (the direct peer address has been used since v5.1.0).
  • Static middleware: when registered with Echo#Use it runs before route and group middleware, so route guards do not protect the files it serves.
Commits
  • fc41009 Merge commit from fork
  • e804f42 revert: keep documentation examples in echox
  • b790a02 chore: update maintainer credits, security reporting, and remove unused stale...
  • 68ac4cf docs: add source-aligned examples and compatibility workflow
  • 3d084be docs(readme): fix extra asterisk in v4 security support note
  • 9ce228d docs: clarify group prefix concatenation
  • df5edd9 fix(rfc9457): do not mutate a shared ProblemError (#3094)
  • 90702e7 docs: update CLAUDE.md for v5 (module path and Context type)
  • 07b3c4a refactor(middleware): clamp remaining tokens with max
  • e552b4d CI: add Go 1.27 to CI
  • Additional commits viewable in compare view

Updates github.com/modelcontextprotocol/go-sdk from 1.7.0 to 1.8.0

Release notes

Sourced from github.com/modelcontextprotocol/go-sdk's releases.

v1.8.0

This release is equivalent to v1.8.0-pre.2. Thank you to those who tested the pre-release.

In this release we introduce several fixes and improvements on top of v1.7.0. It adds no new protocol revision: the supported set is unchanged, and 2026-07-28 remains the newest version the SDK negotiates.

The bulk of the work is hardening the transports against resource exhaustion, closing session leaks, deadlocks and teardown hangs found by users running the new protocol at scale, and giving servers explicit control over which protocol versions they advertise.

Two behavior changes are guarded by new MCPGODEBUG flags; see the section below.

Hardening against resource exhaustion

Every decoding path that buffers incoming input is now bounded. JSON payloads are rejected past 1000 levels of nesting, before the parser recurses. Both SSE readers cap the bytes buffered for a single event via MaxEventSize on SSEClientTransport and StreamableClientTransport, and the stdio transport caps a single JSON-RPC frame via StdioTransport.MaxLineLength.

On the OAuth side, dynamic client registration responses are bounded to 1 MB, and the discovery code now validates metadata documents rather than trusting them.

Restricting the protocol versions a server supports

ServerOptions.SupportedProtocolVersions lets a server narrow the set of versions it advertises and negotiates. The list can only narrow, never widen; naming a version the SDK does not implement panics at construction. Relatedly, a stateful streamable handler receiving a 2026-07-28 request now returns that same JSON-RPC error instead of a plain-text 400, so the client can renegotiate down instead of losing the connection.

Per-request cache control

ServerOptions.SetCacheable is a new hook that decides the ttlMs and cacheScope fields of every result carrying them: server/discover, the four list methods, and resources/read. It runs once per result, after the handler returns, with the values that handler produced, so it can set a policy globally while still letting an individual handler override it. Anything left unset falls back to the protocol default of public.

Behavior changes guarded by MCPGODEBUG

Two new escape-hatch flags restore the previous behavior of the changes above. Both will be removed in v1.9.0.

  • plaintextstatefulrejection=1 — restore the plain-text http.Error 400 body a stateful StreamableHTTPHandler previously returned for a request carrying per-request metadata. The default is now a JSON-RPC -32022 CodeUnsupportedProtocolVersion error with an UnsupportedProtocolVersionData payload advertising the legacy versions the server supports. Introduced by #1143.
  • blockingcancelnotify=1 — restore the previous behavior where a cancelled call waits synchronously for notifications/cancelled to be delivered (up to 5s) before returning, joining any delivery error into the caller's error. The default now retires the call immediately and sends the notification asynchronously. Introduced by #1151.

Options below were removed, according to plan:

  • seterroroverwrite
  • enableoriginverification
  • disablecontenttypecheck

... (truncated)

Commits
  • 3f3b699 refactor: remove legacy MCPGODEBUG compatibility for new protocol release (#1...
  • 830f0b7 mcp: update conformance tests (#1231)
  • 12cbafe oauthex: oauth discovery checks (#1220)
  • 3632967 mcp: add an sse event size cap (#1205)
  • 0d3036f mcp: allow per request Cacheable customization (#1203)
  • cb0de64 mcp: add a max request body size of the old transport (#1224)
  • 2fdabde mcp: do not check metatada on notifications (#1215)
  • 59185e6 build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 (#1217)
  • a6764cf build(deps): bump golang/govulncheck-action from 1.0.4 to 1.1.0 (#1218)
  • 8227246 fix: only subscribe when server advertises capability (#1221)
  • Additional commits viewable in compare view

Updates github.com/prometheus/client_model from 0.6.2 to 0.6.3

Release notes

Sourced from github.com/prometheus/client_model's releases.

v0.6.3

What's Changed

New Contributors

Full Changelog: prometheus/client_model@v0.6.2...v0.6.3

What's Changed

... (truncated)

Commits

Updates golang.org/x/oauth2 from 0.36.0 to 0.37.0

Commits
  • c624b89 google: change the snake case endpoint to kebab-case
  • 09a82f6 all: upgrade go directive to at least 1.26.0 [generated]
  • See full diff in compare view

Updates golang.org/x/sync from 0.22.0 to 0.23.0

Commits
  • f75267d semaphore: panic on negative capacity
  • 3ffd83c all: upgrade go directive to at least 1.26.0 [generated]
  • See full diff in compare view

Updates golang.org/x/sys from 0.47.0 to 0.48.0

Commits
  • 613e257 cpu: add riscv64 hwprobe drift test
  • 6f7b10f unix: add MLOCK_ONFAULT constant
  • 663e7c8 cpu: add basic support for GOARCH=sparc64
  • de5f12f cpu: add ppc64le POWER10 detection
  • 80e8acf unix: run go fix
  • 1e3c182 unix: add IPMI interface
  • d429e20 unix: stop generating sparc termbits from the generic header
  • bd3bddf unix: add missing HWTSTAMP_* constants
  • e812f53 windows: add SO_SNDTIMEO constant for socket options
  • f6989c5 unix: align Ifreq so its union accessors cannot fault
  • Additional commits viewable in compare view

Updates golang.org/x/time from 0.15.0 to 0.16.0

Commits
  • fb013b3 all: upgrade go directive to at least 1.26.0 [generated]
  • See full diff in compare view

Updates google.golang.org/grpc from 1.83.2 to 1.84.0

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.84.0

Behavior Changes

  • stats/otel: The grpc.lb.pick_first.* metrics have been removed and replaced with grpc.subchannel.* metrics. See gRFC A94 for more details. (#9215)

New Features

  • xds: Add support for contains_match in route header matchers. (#9223)

Bug Fixes

  • client: Fix a bug where a ClientConn could get permanently stuck in IDLE when an RPC was canceled during stream creation. Previously, such cancellations triggered stream cleanup twice, corrupting the channel's idleness state and causing subsequent RPCs to fail with deadline exceeded errors. (#9191)
  • client: Fix a bug where non-gRPC HTTP responses ending with an empty DATA frame failed the RPC with status code Internal instead of preserving the HTTP-mapped status code and response body. (#9217)
  • credentials: Validate metadata returned by per-RPC credentials, failing the RPC with status code Internal if invalid keys or values are found. Previously, invalid metadata from credentials was sent to the server in outgoing HTTP/2 requests. (#9202)
  • credentials/sts: Prevent potential token leakage by disallowing HTTP redirects during STS token exchange. Previously, 3xx redirects were followed automatically, replaying the request body containing authentication tokens to the redirect destination. (#9299)
  • randomsubsetting: Ignore endpoints that contain no addresses. Previously, this could cause the policy to panic while computing hashes. (#9259)
  • stats/otel: Ensure method names are populated in trace spans when metrics are disabled. Previously, running with tracing enabled and metrics disabled resulted in server trace spans lacking the RPC method name (recording only "Recv."). (#9262)
  • transport: Return io.ErrUnexpectedEOF when EOF is encountered after partial header or message body reads. Previously, partial reads could return a plain io.EOF, failing to distinguish truncated data from a clean end of stream. (#9204)
  • transport: Validate metadata supplied by balancers (in PickResult.Metadata) and resolver addresses, failing the RPC with status code Internal if invalid keys or values are found. Previously, invalid metadata from these sources was sent to the server in outgoing HTTP/2 requests. (#9203)
  • xds: Fix a rare corner case that could prevent a cluster from being removed when it is no longer in use. (#9140)
  • xds: Fix panic during route matching for routes containing header matchers with empty exact_match strings. (#9223)
  • xds: Reject routes containing header matchers with empty prefix_match or suffix_match strings. Previously, this caused a panic during route matching. (#9223)
  • xds: Fix EDS drop policies being applied at a much lower rate than configured due to an integer overflow. (#9257)
  • xds: Reject EDS resources containing drop policies with unsupported denominators. Previously, such resources caused the client to panic when calculating drop rates. (#9218)
  • xds/rbac: Reject RBAC configurations containing nested Principal or Permission rules with :scheme or grpc- prefixed header matchers. Previously, such configurations could cause DENY policies to fail open. (#9258)
  • xds/rbac: Rewrite host header matchers to :authority in nested Principal and Permission rules. Previously, this rewrite only applied to top-level rules, causing nested host matchers to never match incoming requests and DENY policies to fail open. (#9258)
  • xds/rbac: Reject CidrRanges with an unset prefix length. Previously, an omitted prefix_len field caused a panic during RBAC configuration parsing. (#9250)

Performance Improvements

  • transport: Avoid a heap allocation when flushing shared write buffers. (#9233)
  • credentials/alts: Support dynamic frame size negotiation and add the GRPC_GO_EXPERIMENTAL_ALTS_MAX_FRAME_SIZE environment variable (default 4KiB, max 512KiB) to configure the maximum ALTS record frame size. (#9268)
Commits

Updates modernc.org/sqlite from 1.57.0 to 1.59.0

Changelog

Sourced from modernc.org/sqlite's changelog.

Changelog

Entries for v1.38.1 through v1.44.1 and for v1.49.1 were added on 2026-09-05, reconstructed from the git history and the merge requests they cite; they were missing at release time.

  • 2026-09-30 v1.61.0:

  • 2026-09-29 v1.60.1:

    • Binding arguments to a statement is no longer quadratic in the number of its parameters, which made multi-row INSERTs with thousands of ? parameters slow. Resolves [GitHub issue #8](modernc-org/sqlite#8), thanks wencycool!
  • 2026-09-28 v1.60.0:

    • A fault while reading the memory-mapped -shm file of a WAL database no longer crashes the ...

      Description has been truncated

Bumps the go group with 11 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/coreos/go-oidc/v3](https://github.com/coreos/go-oidc) | `3.20.0` | `3.21.0` |
| [github.com/knadh/koanf/v2](https://github.com/knadh/koanf) | `2.3.6` | `2.3.7` |
| [github.com/labstack/echo/v5](https://github.com/labstack/echo) | `5.3.1` | `5.4.0` |
| [github.com/modelcontextprotocol/go-sdk](https://github.com/modelcontextprotocol/go-sdk) | `1.7.0` | `1.8.0` |
| [github.com/prometheus/client_model](https://github.com/prometheus/client_model) | `0.6.2` | `0.6.3` |
| [golang.org/x/oauth2](https://github.com/golang/oauth2) | `0.36.0` | `0.37.0` |
| [golang.org/x/sync](https://github.com/golang/sync) | `0.22.0` | `0.23.0` |
| [golang.org/x/sys](https://github.com/golang/sys) | `0.47.0` | `0.48.0` |
| [golang.org/x/time](https://github.com/golang/time) | `0.15.0` | `0.16.0` |
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.83.2` | `1.84.0` |
| [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) | `1.57.0` | `1.59.0` |



Updates `github.com/coreos/go-oidc/v3` from 3.20.0 to 3.21.0
- [Release notes](https://github.com/coreos/go-oidc/releases)
- [Commits](coreos/go-oidc@v3.20.0...v3.21.0)

Updates `github.com/knadh/koanf/v2` from 2.3.6 to 2.3.7
- [Release notes](https://github.com/knadh/koanf/releases)
- [Commits](knadh/koanf@v2.3.6...v2.3.7)

Updates `github.com/labstack/echo/v5` from 5.3.1 to 5.4.0
- [Release notes](https://github.com/labstack/echo/releases)
- [Changelog](https://github.com/labstack/echo/blob/master/CHANGELOG.md)
- [Commits](labstack/echo@v5.3.1...v5.4.0)

Updates `github.com/modelcontextprotocol/go-sdk` from 1.7.0 to 1.8.0
- [Release notes](https://github.com/modelcontextprotocol/go-sdk/releases)
- [Commits](modelcontextprotocol/go-sdk@v1.7.0...v1.8.0)

Updates `github.com/prometheus/client_model` from 0.6.2 to 0.6.3
- [Release notes](https://github.com/prometheus/client_model/releases)
- [Commits](prometheus/client_model@v0.6.2...v0.6.3)

Updates `golang.org/x/oauth2` from 0.36.0 to 0.37.0
- [Commits](golang/oauth2@v0.36.0...v0.37.0)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](golang/sync@v0.22.0...v0.23.0)

Updates `golang.org/x/sys` from 0.47.0 to 0.48.0
- [Commits](golang/sys@v0.47.0...v0.48.0)

Updates `golang.org/x/time` from 0.15.0 to 0.16.0
- [Commits](golang/time@v0.15.0...v0.16.0)

Updates `google.golang.org/grpc` from 1.83.2 to 1.84.0
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.83.2...v1.84.0)

Updates `modernc.org/sqlite` from 1.57.0 to 1.59.0
- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)
- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.57.0...v1.59.0)

---
updated-dependencies:
- dependency-name: github.com/coreos/go-oidc/v3
  dependency-version: 3.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/knadh/koanf/v2
  dependency-version: 2.3.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/labstack/echo/v5
  dependency-version: 5.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/modelcontextprotocol/go-sdk
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/prometheus/client_model
  dependency-version: 0.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: golang.org/x/oauth2
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: golang.org/x/sys
  dependency-version: 0.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: golang.org/x/time
  dependency-version: 0.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: google.golang.org/grpc
  dependency-version: 1.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: modernc.org/sqlite
  dependency-version: 1.59.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 1, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 1, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/go-1c452ccad8 branch October 1, 2026 23:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants