Skip to content

Bump the go-deps group across 1 directory with 4 updates - #1982

Closed
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/go_modules/go-deps-bcac6e2f11
Closed

dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/go_modules/go-deps-bcac6e2f11

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the go-deps group with 4 updates in the / directory: github.com/google/trillian, google.golang.org/genproto, google.golang.org/grpc and github.com/sigstore/sigstore.

Updates github.com/google/trillian from 1.7.3 to 1.8.0

Release notes

Sourced from github.com/google/trillian's releases.

v1.8.0

API

Features

Claimant Model

Fixes

What's Changed

New Contributors

... (truncated)

Changelog

Sourced from github.com/google/trillian's changelog.

v1.8.0

  • Recommended go version for development: 1.26
  • Bump golang to 1.26, golangci-lint to v2.10.1.
  • Filter mastership election event watching by lease name
  • Remove OpenCensus tracing support and associated instrumentation hooks by @​phb
    • Removed internal tracing packages (monitoring/trace.go and monitoring/opencensus/), command-line --tracing flags, and spanFor / StartSpan instrumentation across server, tree, and storage entrypoints.
  • Allow unencrypted PEM private key files by @​JasonPowr
    • ReadPrivateKeyFile and FromProto (via PEMKeyFile) now accept an empty password, treating the key as unencrypted. Previously, an empty password was rejected with an error.
  • Replace deprecated golang.org/x/crypto/ed25519 with stdlib crypto/ed25519 by @​JasonPowr
Commits
  • 0362d55 CHANGELOG.md update ahead of v1.8 (#3933)
  • 0d6fa8f Bump the go-deps group across 1 directory with 20 updates AND bump go to 1.26...
  • 5061cfc Bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc (#3927)
  • 999a06b Remove tracing support, which drops aws SDK and prometheus deps. (#3912)
  • e9b1644 Bump google.golang.org/grpc from 1.83.1 to 1.83.2 (#3923)
  • 70e3cce Bump the docker-deps group across 6 directories with 5 updates (#3918)
  • 87ef5b5 Bump the github-actions-deps group with 4 updates (#3921)
  • c537cd6 Bump google.golang.org/grpc from 1.82.1 to 1.83.1 (#3922)
  • 02b853b Bump the github-actions-deps group across 1 directory with 7 updates (#3910)
  • 416e64c offer batching for mysql quota provider (#3917)
  • Additional commits viewable in compare view

Updates google.golang.org/genproto from 0.0.0-20260622175928-b703f567277d to 0.0.0-20260715232425-e75dac1f907d

Commits

Updates google.golang.org/grpc from 1.83.2 to 1.84.0

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.84.0

Behavior Changes

  • stats/otel: The grpc.lb.pick_first.* metrics have been removed and replaced with grpc.subchannel.* metrics. See gRFC A94 for more details. (#9215)

New Features

  • xds: Add support for contains_match in route header matchers. (#9223)

Bug Fixes

  • client: Fix a bug where a ClientConn could get permanently stuck in IDLE when an RPC was canceled during stream creation. Previously, such cancellations triggered stream cleanup twice, corrupting the channel's idleness state and causing subsequent RPCs to fail with deadline exceeded errors. (#9191)
  • client: Fix a bug where non-gRPC HTTP responses ending with an empty DATA frame failed the RPC with status code Internal instead of preserving the HTTP-mapped status code and response body. (#9217)
  • credentials: Validate metadata returned by per-RPC credentials, failing the RPC with status code Internal if invalid keys or values are found. Previously, invalid metadata from credentials was sent to the server in outgoing HTTP/2 requests. (#9202)
  • credentials/sts: Prevent potential token leakage by disallowing HTTP redirects during STS token exchange. Previously, 3xx redirects were followed automatically, replaying the request body containing authentication tokens to the redirect destination. (#9299)
  • randomsubsetting: Ignore endpoints that contain no addresses. Previously, this could cause the policy to panic while computing hashes. (#9259)
  • stats/otel: Ensure method names are populated in trace spans when metrics are disabled. Previously, running with tracing enabled and metrics disabled resulted in server trace spans lacking the RPC method name (recording only "Recv."). (#9262)
  • transport: Return io.ErrUnexpectedEOF when EOF is encountered after partial header or message body reads. Previously, partial reads could return a plain io.EOF, failing to distinguish truncated data from a clean end of stream. (#9204)
  • transport: Validate metadata supplied by balancers (in PickResult.Metadata) and resolver addresses, failing the RPC with status code Internal if invalid keys or values are found. Previously, invalid metadata from these sources was sent to the server in outgoing HTTP/2 requests. (#9203)
  • xds: Fix a rare corner case that could prevent a cluster from being removed when it is no longer in use. (#9140)
  • xds: Fix panic during route matching for routes containing header matchers with empty exact_match strings. (#9223)
  • xds: Reject routes containing header matchers with empty prefix_match or suffix_match strings. Previously, this caused a panic during route matching. (#9223)
  • xds: Fix EDS drop policies being applied at a much lower rate than configured due to an integer overflow. (#9257)
  • xds: Reject EDS resources containing drop policies with unsupported denominators. Previously, such resources caused the client to panic when calculating drop rates. (#9218)
  • xds/rbac: Reject RBAC configurations containing nested Principal or Permission rules with :scheme or grpc- prefixed header matchers. Previously, such configurations could cause DENY policies to fail open. (#9258)
  • xds/rbac: Rewrite host header matchers to :authority in nested Principal and Permission rules. Previously, this rewrite only applied to top-level rules, causing nested host matchers to never match incoming requests and DENY policies to fail open. (#9258)
  • xds/rbac: Reject CidrRanges with an unset prefix length. Previously, an omitted prefix_len field caused a panic during RBAC configuration parsing. (#9250)

Performance Improvements

  • transport: Avoid a heap allocation when flushing shared write buffers. (#9233)
  • credentials/alts: Support dynamic frame size negotiation and add the GRPC_GO_EXPERIMENTAL_ALTS_MAX_FRAME_SIZE environment variable (default 4KiB, max 512KiB) to configure the maximum ALTS record frame size. (#9268)
Commits

Updates github.com/sigstore/sigstore from 1.10.9 to 1.11.0

Release notes

Sourced from github.com/sigstore/sigstore's releases.

v1.11.0

What's Changed

v1.11.0 and v1.10.10 are identical releases tagged for the same commit. Since the minimum Go version has been bumped to 1.27.0, we are releasing this change as a minor version bump. Dependencies that do not want to update to 1.27 yet can use v1.10.11, and we'll backport any security fixes to v1.10.x for the next 6 months while Go 1.26 is still supported.

Full Changelog: sigstore/sigstore@v1.10.9...v1.11.0

v1.10.11 rolls back the release to a previous commit where the minimum Go version is 1.25.0. An upcoming v1.11.0 will require 1.27.0.

v1.10.10

What's Changed

New Contributors

Full Changelog: sigstore/sigstore@v1.10.9...v1.10.10

Commits
  • 4f4c3f8 Add release instructions (#2418)
  • 49e21e5 build(deps): Bump github.com/google/go-containerregistry from 0.21.9 to 0.22....
  • eda3b60 build(deps): Bump the gomod group across 4 directories with 4 updates (#2413)
  • b3e2728 Adjust mldsa error handling (#2417)
  • bfbf63e Support for ML-DSA keys (#2416)
  • 538e3fa Bump go to 1.27 and fix linter and api issues (#2415)
  • e8841f5 build(deps): Bump hashicorp/vault in /test/e2e in the all group (#2412)
  • 5b3d739 Fix Azure KMS ECDSA signature verification (r||s ordering + padding) (#2410)
  • ba4de68 build(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2406)
  • 1abcedd build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#2407)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-deps group with 4 updates in the / directory: [github.com/google/trillian](https://github.com/google/trillian), [google.golang.org/genproto](https://github.com/googleapis/go-genproto), [google.golang.org/grpc](https://github.com/grpc/grpc-go) and [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore).


Updates `github.com/google/trillian` from 1.7.3 to 1.8.0
- [Release notes](https://github.com/google/trillian/releases)
- [Changelog](https://github.com/google/trillian/blob/master/CHANGELOG.md)
- [Commits](google/trillian@v1.7.3...v1.8.0)

Updates `google.golang.org/genproto` from 0.0.0-20260622175928-b703f567277d to 0.0.0-20260715232425-e75dac1f907d
- [Commits](https://github.com/googleapis/go-genproto/commits)

Updates `google.golang.org/grpc` from 1.83.2 to 1.84.0
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.83.2...v1.84.0)

Updates `github.com/sigstore/sigstore` from 1.10.9 to 1.11.0
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.10.9...v1.11.0)

---
updated-dependencies:
- dependency-name: github.com/google/trillian
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: google.golang.org/genproto
  dependency-version: 0.0.0-20260715232425-e75dac1f907d
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: google.golang.org/grpc
  dependency-version: 1.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/sigstore/sigstore
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 25, 2026
@dependabot
dependabot Bot requested review from a team as code owners September 25, 2026 02:44
@dependabot dependabot Bot added the go Pull requests that update Go code label Sep 25, 2026
Signed-off-by: Bob Callaway <bcallaway@google.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 2, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/go-deps-bcac6e2f11 branch October 2, 2026 02:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant