Skip to content

chore(deps): bump the minor-and-patch group with 7 updates - #750

Merged
mklos-kw merged 1 commit into
mainfrom
dependabot/go_modules/minor-and-patch-468aaea430
Sep 28, 2026
Merged

mklos-kw merged 1 commit into
mainfrom
dependabot/go_modules/minor-and-patch-468aaea430

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown

Bumps the minor-and-patch group with 7 updates:

Package From To
github.com/beevik/etree 1.8.0 1.8.1
github.com/go-playground/universal-translator 0.18.1 0.18.2
github.com/go-playground/validator/v10 10.30.4 10.30.5
github.com/huandu/xstrings 1.6.0 1.6.1
github.com/nats-io/nats.go 1.53.1 1.54.0
github.com/onsi/gomega 1.43.1 1.44.0
go.etcd.io/etcd/client/v3 3.7.1 3.7.2

Updates github.com/beevik/etree from 1.8.0 to 1.8.1

Release notes

Sourced from github.com/beevik/etree's releases.

Release v1.8.1

Fixes

  • Fixed a panic-causing bug in all Remove functions.
Changelog

Sourced from github.com/beevik/etree's changelog.

Release 1.8.1

Fixes

  • Fixed a panic-causing bug in all Remove functions.
Commits

Updates github.com/go-playground/universal-translator from 0.18.1 to 0.18.2

Release notes

Sourced from github.com/go-playground/universal-translator's releases.

Release 0.18.2

What's Changed

Full Changelog: go-playground/universal-translator@v0.18.1...v0.18.2

Commits

Updates github.com/go-playground/validator/v10 from 10.30.4 to 10.30.5

Release notes

Sourced from github.com/go-playground/validator/v10's releases.

Release 10.30.5

What's Changed

New Contributors

Full Changelog: go-playground/validator@v10.30.4...v10.30.5

Commits

Updates github.com/huandu/xstrings from 1.6.0 to 1.6.1

Commits
  • f835cc2 Merge pull request #68 from x0Lazarus/docs-scrub-replacement-character
  • affb8e6 Merge pull request #69 from jakezwang/fix/camelcase-trailing-initial
  • cedef93 fix: preserve trailing uppercase initials in camel case
  • 86af16d docs: clarify Scrub handling of replacement characters
  • See full diff in compare view

Updates github.com/nats-io/nats.go from 1.53.1 to 1.54.0

Release notes

Sourced from github.com/nats-io/nats.go's releases.

Release v1.54.0

Changelog

This release raises the minimum supported Go version to 1.26 and adds support for nats-server v2.15 stream and consumer info fields.

ADDED

  • Core NATS:
    • nats.MultipathTCP() option to enable or disable MPTCP for outbound connections (#2145)
    • Conn.ConnectedDomain() to read the JetStream domain advertised by the connected server (#2139)
  • JetStream:
    • ClusterInfo.Desired, PeerInfo.Peer, PeerInfo.Pending and StreamSourceInfo.Seq in stream and consumer info, reported by nats-server v2.15 (#2144)
    • Nats-Schedule-Rollup header const and WithScheduleRollup() publish option (#2142)

FIXED

  • Core NATS:
    • Panic in DecodeHeadersMsg on inline status tokens shorter than 3 characters. Thanks @​nikitha-m for the contribution (#2101)
    • Data race on Subscription.sid between applyNewSID and removeSub (#2122)
  • JetStream:
    • Messages() iterator going silent after a reconnect that completes between Next() calls. Thanks @​1995parham for the contribution (#2135)
    • Legacy ordered consumer silently losing messages when the subscription hits its pending limits (#2137)
    • Legacy ordered consumer reset resurrecting an unsubscribed or draining subscription (#2133)

IMPROVED

  • Core NATS:
    • Avoid allocation when parsing header message arguments with a fifth token. Thanks @​0xAozora for the contribution (#2130)
    • Preallocate reply subject buffers. Thanks @​0xAozora for the contribution (#2123)
  • JetStream:
    • Prevent doErr closure escaping to the heap in async publish reply handling. Thanks @​0xAozora for the contribution (#2127)
    • Fix typo in Publisher interface methods comment. Thanks @​sreeram77 for the contribution (#2120)
  • Minimum Go version is now 1.26 (#2146)
  • Bump klauspost/compress to v1.20.0 and nkeys to v0.4.16 (#2117, #2146)
  • Tests run locally without docker via an in-process ntf tester (#2131), and CI now runs against nats-server v2.15.0 (#2146)
  • Fix flaky cluster restart tests (#2141) and list consumers test against latest server (#2138)

Complete Changes

nats-io/nats.go@v1.53.1...v1.54.0

Commits
  • 7a8404a Release v1.54.0 (#2148)
  • 240fb1f [IMPROVED] Bump dependencies and update server version in CI (#2146)
  • 203d828 [FIXED] Panic in DecodeHeadersMsg on status tokens shorter than 3 characters ...
  • dc92fca [FIXED] Ordered consumer silently losing messages on slow consumer (#2137)
  • e18cea8 [IMPROVED] Prevent doErr closure escaping to heap (#2127)
  • d8d8c09 [ADDED] nats.MultipathTCP() for enabling or disabling MPTCP (#2145)
  • e95c424 [FIXED] Flaky cluster restart tests: waitForStream must see a stream leader (...
  • e3abbf4 [ADDED] Nats-Schedule-Rollup header const and publish options (#2142)
  • f1289db [ADDED] Desired state, peer ID/pending and source seq in stream and consumer ...
  • b84f783 Ignore Claude Code local files and .worktrees (#2140)
  • Additional commits viewable in compare view

Updates github.com/onsi/gomega from 1.43.1 to 1.44.0

Release notes

Sourced from github.com/onsi/gomega's releases.

v1.44.0

Fixes

  • BeNumerically compares signed and unsigned integers by value: -1 no longer equals uint64(math.MaxUint64) and uint(5) is now greater than -3 (#925) [26e3c6b]
  • BeNumerically("~") no longer overflows when computing the distance between extreme integers (#928) [1955764]
  • BeNumerically("==", x, threshold) now honors the threshold for floats, as it already did for integers (#927) [10e2aca]
  • HaveKeyWithValue succeeds if any key accepted by the key matcher has a matching value, rather than depending on map iteration order (#929) [ffc577a]
  • HaveKey and HaveKeyWithValue treat key and value matcher errors like ContainElement does: a match wins, and an error is only reported when nothing matches (#926) [dc91598]
  • MatchJSON no longer treats numbers too large for a float64 as equal to one another (#930) [9d619a5]
  • MatchJSON compares integers beyond ±2^53 exactly, so neighboring large integers (e.g. IDs) no longer match; all other numbers are still compared as float64s (#931) [8ef1aa7, 630fe12]
  • HaveExactElements reports missing or extra elements that start at index 0, and reports the first extra element's index rather than the last (#934) [af1b777]
  • MatchYAML compares every document in a multi-document stream rather than only the first; empty documents (e.g. a leading or trailing ---) are ignored (#933) [2773796]
  • MatchXML ignores namespace prefixes: elements and attributes are compared by namespace URI, and the URIs declared on each element must match whatever prefix they are bound to (#932) [c0dbd89, 2565350]
Changelog

Sourced from github.com/onsi/gomega's changelog.

1.44.0

Fixes

  • BeNumerically compares signed and unsigned integers by value: -1 no longer equals uint64(math.MaxUint64) and uint(5) is now greater than -3 (#925) [26e3c6b]
  • BeNumerically("~") no longer overflows when computing the distance between extreme integers (#928) [1955764]
  • BeNumerically("==", x, threshold) now honors the threshold for floats, as it already did for integers (#927) [10e2aca]
  • HaveKeyWithValue succeeds if any key accepted by the key matcher has a matching value, rather than depending on map iteration order (#929) [ffc577a]
  • HaveKey and HaveKeyWithValue treat key and value matcher errors like ContainElement does: a match wins, and an error is only reported when nothing matches (#926) [dc91598]
  • MatchJSON no longer treats numbers too large for a float64 as equal to one another (#930) [9d619a5]
  • MatchJSON compares integers beyond ±2^53 exactly, so neighboring large integers (e.g. IDs) no longer match; all other numbers are still compared as float64s (#931) [8ef1aa7, 630fe12]
  • HaveExactElements reports missing or extra elements that start at index 0, and reports the first extra element's index rather than the last (#934) [af1b777]
  • MatchYAML compares every document in a multi-document stream rather than only the first; empty documents (e.g. a leading or trailing ---) are ignored (#933) [2773796]
  • MatchXML ignores namespace prefixes: elements and attributes are compared by namespace URI, and the URIs declared on each element must match whatever prefix they are bound to (#932) [c0dbd89, 2565350]
Commits

Updates go.etcd.io/etcd/client/v3 from 3.7.1 to 3.7.2

Release notes

Sourced from go.etcd.io/etcd/client/v3's releases.

v3.7.2

Please check out CHANGELOG for a full list of changes. And make sure to read upgrade guide before upgrading etcd (there may be breaking changes).

For installation guides, please check out play.etcd.io and operating etcd. Latest support status for common architectures and operating systems can be found at supported platforms.

Linux
ETCD_VER=v3.7.2
choose either URL
GOOGLE_URL=https://storage.googleapis.com/etcd
GITHUB_URL=https://github.com/etcd-io/etcd/releases/download
DOWNLOAD_URL=${GOOGLE_URL}
rm -f /tmp/etcd-${ETCD_VER}-linux-amd64.tar.gz
rm -rf /tmp/etcd-download-test && mkdir -p /tmp/etcd-download-test
curl -L ${DOWNLOAD_URL}/${ETCD_VER}/etcd-${ETCD_VER}-linux-amd64.tar.gz -o /tmp/etcd-${ETCD_VER}-linux-amd64.tar.gz
tar xzvf /tmp/etcd-${ETCD_VER}-linux-amd64.tar.gz -C /tmp/etcd-download-test --strip-components=1 --no-same-owner
rm -f /tmp/etcd-${ETCD_VER}-linux-amd64.tar.gz
/tmp/etcd-download-test/etcd --version
/tmp/etcd-download-test/etcdctl version
/tmp/etcd-download-test/etcdutl version
start a local etcd server
/tmp/etcd-download-test/etcd
write,read to etcd
/tmp/etcd-download-test/etcdctl --endpoints=localhost:2379 put foo bar
/tmp/etcd-download-test/etcdctl --endpoints=localhost:2379 get foo

macOS (Darwin)
ETCD_VER=v3.7.2
choose either URL
GOOGLE_URL=https://storage.googleapis.com/etcd
GITHUB_URL=https://github.com/etcd-io/etcd/releases/download
DOWNLOAD_URL=${GOOGLE_URL}
rm -f /tmp/etcd-${ETCD_VER}-darwin-amd64.zip
rm -rf /tmp/etcd-download-test && mkdir -p /tmp/etcd-download-test
curl -L ${DOWNLOAD_URL}/${ETCD_VER}/etcd-${ETCD_VER}-darwin-amd64.zip -o /tmp/etcd-${ETCD_VER}-darwin-amd64.zip
unzip /tmp/etcd-${ETCD_VER}-darwin-amd64.zip -d /tmp && rm -f /tmp/etcd-${ETCD_VER}-darwin-amd64.zip
mv /tmp/etcd-${ETCD_VER}-darwin-amd64/* /tmp/etcd-download-test && rm -rf mv /tmp/etcd-${ETCD_VER}-darwin-amd64
</tr></table>

... (truncated)

Commits
  • 68c065e version: bump up to 3.7.2
  • b85cf4b dependency: bump google.golang.org/grpc to v1.83.2
  • 9e41c76 fileutil: close locked files when purging fails
  • c1c6e17 Delete bump-devcontainer-version GitHub action
  • ca26c7e Merge pull request #22413 from ivanvc/release-3.7-go-1.26.8
  • 9d58213 fix: deflake TestIssue20271
  • adb3646 Bump go to 1.26.8
  • 2632b79 Merge pull request #22404 from k8s-infra-cherrypick-robot/cherry-pick-22173-t...
  • 0c06cc3 Merge pull request #22378 from k8s-infra-cherrypick-robot/cherry-pick-22314-t...
  • 3d67b05 Deflake TestEtcdGrpcResolverRoundRobin: sleep 1s to allow all grpc sub channe...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [github.com/beevik/etree](https://github.com/beevik/etree) | `1.8.0` | `1.8.1` |
| [github.com/go-playground/universal-translator](https://github.com/go-playground/universal-translator) | `0.18.1` | `0.18.2` |
| [github.com/go-playground/validator/v10](https://github.com/go-playground/validator) | `10.30.4` | `10.30.5` |
| [github.com/huandu/xstrings](https://github.com/huandu/xstrings) | `1.6.0` | `1.6.1` |
| [github.com/nats-io/nats.go](https://github.com/nats-io/nats.go) | `1.53.1` | `1.54.0` |
| [github.com/onsi/gomega](https://github.com/onsi/gomega) | `1.43.1` | `1.44.0` |
| [go.etcd.io/etcd/client/v3](https://github.com/etcd-io/etcd) | `3.7.1` | `3.7.2` |


Updates `github.com/beevik/etree` from 1.8.0 to 1.8.1
- [Release notes](https://github.com/beevik/etree/releases)
- [Changelog](https://github.com/beevik/etree/blob/main/RELEASE_NOTES.md)
- [Commits](beevik/etree@v1.8.0...v1.8.1)

Updates `github.com/go-playground/universal-translator` from 0.18.1 to 0.18.2
- [Release notes](https://github.com/go-playground/universal-translator/releases)
- [Commits](go-playground/universal-translator@v0.18.1...v0.18.2)

Updates `github.com/go-playground/validator/v10` from 10.30.4 to 10.30.5
- [Release notes](https://github.com/go-playground/validator/releases)
- [Commits](go-playground/validator@v10.30.4...v10.30.5)

Updates `github.com/huandu/xstrings` from 1.6.0 to 1.6.1
- [Release notes](https://github.com/huandu/xstrings/releases)
- [Commits](huandu/xstrings@v1.6.0...v1.6.1)

Updates `github.com/nats-io/nats.go` from 1.53.1 to 1.54.0
- [Release notes](https://github.com/nats-io/nats.go/releases)
- [Commits](nats-io/nats.go@v1.53.1...v1.54.0)

Updates `github.com/onsi/gomega` from 1.43.1 to 1.44.0
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](onsi/gomega@v1.43.1...v1.44.0)

Updates `go.etcd.io/etcd/client/v3` from 3.7.1 to 3.7.2
- [Release notes](https://github.com/etcd-io/etcd/releases)
- [Commits](etcd-io/etcd@v3.7.1...v3.7.2)

---
updated-dependencies:
- dependency-name: github.com/beevik/etree
  dependency-version: 1.8.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: github.com/go-playground/universal-translator
  dependency-version: 0.18.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: github.com/go-playground/validator/v10
  dependency-version: 10.30.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: github.com/huandu/xstrings
  dependency-version: 1.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: github.com/nats-io/nats.go
  dependency-version: 1.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: go.etcd.io/etcd/client/v3
  dependency-version: 3.7.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 27, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 27, 2026 22:03
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 27, 2026
@kw-security

kw-security commented Sep 27, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@mklos-kw
mklos-kw merged commit cece6f6 into main Sep 28, 2026
16 checks passed
@mklos-kw
mklos-kw deleted the dependabot/go_modules/minor-and-patch-468aaea430 branch September 28, 2026 10:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants