Skip to content

chore(deps): bump the all-dependencies group across 1 directory with 13 updates - #1879

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/go_modules/develop/all-dependencies-9c7d647404
Closed

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/go_modules/develop/all-dependencies-9c7d647404

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the all-dependencies group with 13 updates in the / directory:

Package From To
github.com/ethereum/go-ethereum 1.17.4 1.17.7
github.com/knadh/koanf/parsers/json 1.0.0 1.0.1
github.com/knadh/koanf/providers/rawbytes 1.0.0 1.0.1
github.com/knadh/koanf/v2 2.3.5 2.3.7
github.com/mattn/go-sqlite3 1.14.48 1.14.52
github.com/prometheus/client_golang 1.24.0 1.24.1
github.com/prometheus/client_model 0.6.2 0.6.3
github.com/rs/cors 1.11.0 1.11.1
github.com/stretchr/testify 1.11.1 1.12.1
golang.org/x/sync 0.22.0 0.23.0
google.golang.org/genproto/googleapis/rpc 0.0.0-20260526163538-3dc84a4a5aaa 0.0.0-20260819154853-08b0e4226688
google.golang.org/grpc 1.83.2 1.84.0
google.golang.org/protobuf 1.36.11 1.36.12

Updates github.com/ethereum/go-ethereum from 1.17.4 to 1.17.7

Release notes

Sourced from github.com/ethereum/go-ethereum's releases.

Intact Neuro-Coil (v1.17.7)

This is a quick release, cut mainly because publishing v1.17.6 to the Ubuntu PPA failed. It also carries a few fixes merged since then. Both v1.17.6 and v1.17.7 are ready for the Amsterdam fork on Sepolia (Oct 6, 2026), so Sepolia validators can run either version.

Users can now also choose their own history pruning point with --history.chain <block number>:<block hash>. It works both for pruning an existing node with geth prune-history and for snap sync, which then skips downloading the chain history before that block.

Changes

  • Add postosaka and custom <block number>:<block hash> history pruning points (#35792)
  • Account for both the execution and state gas (EIP-8037) when selecting transactions in the miner (#35773)
  • Fix a memory leak by waiting for the block prefetcher when stopping the chain (#35821)
  • Release the pathdb clean caches when the database is disabled (#35789)
  • Encode and hash the block-level access list once, in a dedicated pipeline (#35772)
  • Keep the snap sync v2 pivot moving by applying block-level access lists after the state sync (#35749)
  • Only fetch block-level access lists close to the chain head (#35780)
  • Skip peers whose announced block range doesn't cover the request (#35723)
  • Restore the txpool empty-state fallback during snap sync, fixing the regression introduced in v1.17.3 (#35582)
  • Allow restarting an interrupted snap sync when a history cutoff is configured (#35837, #35844)
  • Update execution-spec-tests fixtures to v21 (#35835)
  • Add five new multi-cloud bootnodes operated by NodeOps alongside the existing bootnodes (#35682)

For a full rundown of the changes please consult the Geth 1.17.7 release milestone.


As with all our previous releases, you can find the:

Inorganic Lubricant (v1.17.6)

This is a maintenance release with a number of performance improvements to block processing and initial sync, and is recommended for all users.

A few things worth highlighting:

  • The Amsterdam hardfork is scheduled on the Sepolia testnet at timestamp 1791294816 (Oct 6, 2026, 13:53:36 UTC). Sepolia node operators must upgrade before that time.
  • The Holesky testnet has been removed, as the network reached end-of-life.
  • Go 1.24 is no longer supported. Release binaries and Docker images are now built with Go 1.27.

Fork Implementation

  • Schedule the Amsterdam fork on Sepolia (#35734)
  • Remove the EIP-7610 implementation (#35581)
  • Update EIP-2780 and EIP-8038 gas parameters (#35454, #35497)
  • Update EIP-7997 deterministic factory contract (#35458)

... (truncated)

Commits
  • 3d858f8 version: release 1.17.7 (#35847)
  • e6a82f8 core: handle the sync restarting after unclean shutdown (#35844)
  • fa8fe67 cmd/devp2p: make blobCount in makeBlobTxs per transaction (#35818)
  • 3793989 triedb/pathdb: fix flaky TestHistoricalStateReader (#35839)
  • 5dcdd05 params: replace EF bootnodes with NodeOps fleet (#35682)
  • bbedffe tests: update test fixture to v21 (#35835)
  • f8f9bc5 core/txpool: restore empty state fallback during snap sync (#35582)
  • 5d8fd6b core: allow restarting a snap sync before the history cutoff (#35837)
  • 1a916a8 .github: group dependabot security updates (#35807)
  • 81dbc8b core/filtermaps: fix intermittent hang in TestIndexerRandomRange (#35823)
  • Additional commits viewable in compare view

Updates github.com/knadh/koanf/parsers/json from 1.0.0 to 1.0.1

Commits
  • 75e13d9 Fix multiple large int64 handling issues.
  • b133504 skip disabled secret on azure kv read (#437)
  • 1aba4ed deps: upgrade go-toml to v2.4.3 (#419)
  • d2ffdaa Bump golang.org/x/crypto from 0.45.0 to 0.52.0 in /providers/kiln (#427)
  • 4f7edbb Bump google.golang.org/grpc from 1.56.3 to 1.82.1 in /examples (#430)
  • 31dd449 fix: error on scalar/map type mismatch in MergeStrict regardless of order (#424)
  • e09e4c8 fix: report full key var in MergeStrict type-mismatch error message (#418)
  • 7a28d59 Exclude nats, vault providers from global workspace and fix CI test commands.
  • d511690 Fix test action to use local Go toolchain for different versions.
  • 308274c Fix async file provider Watch() test that would race and fail randomly.
  • Additional commits viewable in compare view

Updates github.com/knadh/koanf/providers/rawbytes from 1.0.0 to 1.0.1

Commits
  • 75e13d9 Fix multiple large int64 handling issues.
  • b133504 skip disabled secret on azure kv read (#437)
  • 1aba4ed deps: upgrade go-toml to v2.4.3 (#419)
  • d2ffdaa Bump golang.org/x/crypto from 0.45.0 to 0.52.0 in /providers/kiln (#427)
  • 4f7edbb Bump google.golang.org/grpc from 1.56.3 to 1.82.1 in /examples (#430)
  • 31dd449 fix: error on scalar/map type mismatch in MergeStrict regardless of order (#424)
  • e09e4c8 fix: report full key var in MergeStrict type-mismatch error message (#418)
  • 7a28d59 Exclude nats, vault providers from global workspace and fix CI test commands.
  • d511690 Fix test action to use local Go toolchain for different versions.
  • 308274c Fix async file provider Watch() test that would race and fail randomly.
  • Additional commits viewable in compare view

Updates github.com/knadh/koanf/v2 from 2.3.5 to 2.3.7

Release notes

Sourced from github.com/knadh/koanf/v2's releases.

v2.3.7

What's Changed

New Contributors

Full Changelog: knadh/koanf@v2.3.6...v2.3.7

v2.3.6

What's Changed

New Contributors

Full Changelog: knadh/koanf@v2.3.5...v2.3.6

Commits
  • f3b40fa Fix typed map getter funcs returning empty results (#450)
  • c69572c Fix Slices silently dropping a natively-typed []map[string]any (#448)
  • 83a6751 Bump google.golang.org/grpc from 1.82.1 to 1.83.1 in /examples (#446)
  • c316bd1 Fix empty slices resulting in removed keys in StringsMap() (#449)
  • 6ad56fe Fix key collission on 'Unflatten' by making insertions deterministic. Closes ...
  • eb15bf7 fix: panic when Config.Transport is not supplied (#439)
  • defde9b Fix azurevault throwing 403 incorrectly fetching disabled keys. Closes #436.
  • fb45026 Skip env entries without '=' in env provider avoid panicking.
  • 75e13d9 Fix multiple large int64 handling issues.
  • b133504 skip disabled secret on azure kv read (#437)
  • Additional commits viewable in compare view

Updates github.com/mattn/go-sqlite3 from 1.14.48 to 1.14.52

Release notes

Sourced from github.com/mattn/go-sqlite3's releases.

1.14.52

What's Changed

Full Changelog: mattn/go-sqlite3@v1.14.51...v1.14.52

1.14.51

What's Changed

New Contributors

Full Changelog: mattn/go-sqlite3@v1.14.50...v1.14.51

1.14.50

What's Changed

New Contributors

Full Changelog: mattn/go-sqlite3@v1.14.49...v1.14.50

1.14.49

What's Changed

... (truncated)

Commits
  • b0be46f Merge pull request #1454 from mattn/fix-stmt-cache-probe-cost
  • c8212b8 Replace schema probe with eager first step for cached statements
  • d7f5da7 Merge pull request #1452 from mattn/fix-stmt-cache-schema-change
  • 6428cad Merge pull request #1444 from bradengroom/codex/efficient-query-cancellation
  • be93f7a Merge pull request #1453 from mattn/fix-handle-map-quadratic
  • 5b285a1 Merge branch 'master' into codex/efficient-query-cancellation
  • 2294cd9 Replace copy-on-write handle map with sync.Map
  • 5341cee Gate cache on runtime version and skip probing in transactions
  • c7ed68d Flush statement cache when the schema changes
  • 6507893 Merge pull request #1367 from kberov/typos
  • Additional commits viewable in compare view

Updates github.com/prometheus/client_golang from 1.24.0 to 1.24.1

Release notes

Sourced from github.com/prometheus/client_golang's releases.

v1.24.1 / 2026-07-23

Small bugfix release for promhttp.

What's Changed

[BUGFIX] promhttp: Fix panic on requests with nil URL. #2065

Full Changelog: prometheus/client_golang@v1.24.0...v1.24.1

Changelog

Sourced from github.com/prometheus/client_golang's changelog.

1.24.1 / 2026-07-23

  • [BUGFIX] promhttp: Fix panic on requests with nil URL. #2065
Commits

Updates github.com/prometheus/client_model from 0.6.2 to 0.6.3

Release notes

Sourced from github.com/prometheus/client_model's releases.

v0.6.3

What's Changed

New Contributors

Full Changelog: prometheus/client_model@v0.6.2...v0.6.3

What's Changed

... (truncated)

Commits

Updates github.com/rs/cors from 1.11.0 to 1.11.1

Commits
  • a814d79 Re-add support for multiple Access-Control-Request-Headers field (fixes #184)...
  • 1562b17 Removed redundant log nil checks (#178)
  • 3d336ea Update all dependencies to latest in examples (#175)
  • 85fc0ca Make Gin wrapper's status configurable and use 204 as default (fixes #145) (#...
  • See full diff in compare view

Updates github.com/stretchr/testify from 1.11.1 to 1.12.1

Release notes

Sourced from github.com/stretchr/testify's releases.

v1.12.1

This is the first release which has the minimum dependencies practical in testify v1. The last remaining dependencies are github.com/stretchr/objx which itself has no dependencies, and go.yaml.in/yaml/v3. Removing objx would require v2, it cannot be vendored. Removing YAML would require vendoring the yaml library, which would do more harm than good. It's better to become aware of vulnerabilities in the official yaml package than to attempt to maintain our own.

What's Changed

New Contributors

Full Changelog: stretchr/testify@v1.12.0...v1.12.1

What's Changed

New Contributors

Full Changelog: stretchr/testify@v1.12.0...v1.12.1

v1.12.0

What's Changed

Functional Changes

Fixes

Documentation, Build & CI

... (truncated)

Commits
  • 959dbda Merge pull request #1935 from harryzcy/yaml-update
  • 9bb7176 Update go.yaml.in/yaml/v3 to v3.0.5
  • 001eb79 Merge pull request #1905 from Kentzo/patch-1
  • ad40f38 Merge pull request #1906 from stretchr/dependabot/github_actions/actions/chec...
  • 3bae017 build(deps): bump actions/checkout from 6.0.2 to 6.0.3
  • f8c01f3 mock: Mock.Return does not exist anymore
  • 12f8b56 Merge pull request #1563 from stretchr/make-AssertionFunc-types-aliases
  • a11649e assert: make *AssertionFunc type just aliases
  • dc20f41 Merge pull request #1890 from stretchr/dolmen/codegen-modernize
  • 098f8d7 _codegen: use strings.Builder
  • Additional commits viewable in compare view

Updates golang.org/x/sync from 0.22.0 to 0.23.0

Commits
  • f75267d semaphore: panic on negative capacity
  • 3ffd83c all: upgrade go directive to at least 1.26.0 [generated]
  • See full diff in compare view

Updates google.golang.org/genproto/googleapis/rpc from 0.0.0-20260526163538-3dc84a4a5aaa to 0.0.0-20260819154853-08b0e4226688

Commits

Updates google.golang.org/grpc from 1.83.2 to 1.84.0

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.84.0

Behavior Changes

  • stats/otel: The grpc.lb.pick_first.* metrics have been removed and replaced with grpc.subchannel.* metrics. See gRFC A94 for more details. (#9215)

New Features

  • xds: Add support for contains_match in route header matchers. (#9223)

Bug Fixes

  • client: Fix a bug where a ClientConn could get permanently stuck in IDLE when an RPC was canceled during stream creation. Previously, such cancellations triggered stream cleanup twice, corrupting the channel's idleness state and causing subsequent RPCs to fail with deadline exceeded errors. (#9191)
  • client: Fix a bug where non-gRPC HTTP responses ending with an empty DATA frame failed the RPC with status code Internal instead of preserving the HTTP-mapped status code and response body. (#9217)
  • credentials: Validate metadata returned by per-RPC credentials, failing the RPC with status code Internal if invalid keys or values are found. Previously, invalid metadata from credentials was sent to the server in outgoing HTTP/2 requests. (#9202)
  • credentials/sts: Prevent potential token leakage by disallowing HTTP redirects during STS token exchange. Previously, 3xx redirects were followed automatically, replaying the request body containing authentication tokens to the redirect destination. (#9299)
  • randomsubsetting: Ignore endpoints that contain no addresses. Previously, this could cause the policy to panic while computing hashes. (#9259)
  • stats/otel: Ensure method names are populated in trace spans when metrics are disabled. Previously, running with tracing enabled and metrics disabled resulted in server trace spans lacking the RPC method name (recording only "Recv."). (#9262)
  • transport: Return io.ErrUnexpectedEOF when EOF is encountered after partial header or message body reads. Previously, partial reads could return a plain io.EOF, failing to distinguish truncated data from a clean end of stream. (#9204)
  • transport: Validate metadata supplied by balancers (in PickResult.Metadata) and resolver addresses, failing the RPC with status code Internal if invalid keys or values are found. Previously, invalid metadata from these sources was sent to the server in outgoing HTTP/2 requests. (#9203)
  • xds: Fix a rare corner case that could prevent a cluster from being removed when it is no longer in use. (#9140)
  • xds: Fix panic during route matching for routes containing header matchers with empty exact_match strings. (#9223)
  • xds: Reject routes containing header matchers with empty prefix_match or suffix_match strings. Previously, this caused a panic during route matching. (#9223)
  • xds: Fix EDS drop policies being applied at a much lower rate than configured due to an integer overflow. (#9257)
  • xds: Reject EDS resources containing drop policies with unsupported denominators. Previously, such resources caused the client to panic when calculating drop rates. (#9218)
  • xds/rbac: Reject RBAC configurations containing nested Principal or Permission rules with :scheme or grpc- prefixed header matchers. Previously, such configurations could cause DENY policies to fail open. (#9258)
  • xds/rbac: Rewrite host header matchers to :authority in nested Principal and Permission rules. Previously, this rewrite only applied to top-level rules, causing nested host matchers to never match incoming requests and DENY policies to fail open. (#9258)
  • xds/rbac: Reject CidrRanges with an unset prefix length. Previously, an omitted prefix_len field caused a panic during RBAC configuration parsing. (#9250)

Performance Improvements

  • transport: Avoid a heap allocation when flushing shared write buffers. (#9233)
  • credentials/alts: Support dynamic frame size negotiation and add the GRPC_GO_EXPERIMENTAL_ALTS_MAX_FRAME_SIZE environment variable (default 4KiB, max 512KiB) to configure the maximum ALTS record frame size. (#9268)
Details Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 29, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/develop/all-dependencies-9c7d647404 branch from 6350c60 to eeaca23 Compare October 6, 2026 12:04
…13 updates

Bumps the all-dependencies group with 13 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/ethereum/go-ethereum](https://github.com/ethereum/go-ethereum) | `1.17.4` | `1.17.7` |
| [github.com/knadh/koanf/parsers/json](https://github.com/knadh/koanf) | `1.0.0` | `1.0.1` |
| [github.com/knadh/koanf/providers/rawbytes](https://github.com/knadh/koanf) | `1.0.0` | `1.0.1` |
| [github.com/knadh/koanf/v2](https://github.com/knadh/koanf) | `2.3.5` | `2.3.7` |
| [github.com/mattn/go-sqlite3](https://github.com/mattn/go-sqlite3) | `1.14.48` | `1.14.52` |
| [github.com/prometheus/client_golang](https://github.com/prometheus/client_golang) | `1.24.0` | `1.24.1` |
| [github.com/prometheus/client_model](https://github.com/prometheus/client_model) | `0.6.2` | `0.6.3` |
| [github.com/rs/cors](https://github.com/rs/cors) | `1.11.0` | `1.11.1` |
| [github.com/stretchr/testify](https://github.com/stretchr/testify) | `1.11.1` | `1.12.1` |
| [golang.org/x/sync](https://github.com/golang/sync) | `0.22.0` | `0.23.0` |
| [google.golang.org/genproto/googleapis/rpc](https://github.com/googleapis/go-genproto) | `0.0.0-20260526163538-3dc84a4a5aaa` | `0.0.0-20260819154853-08b0e4226688` |
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.83.2` | `1.84.0` |
| google.golang.org/protobuf | `1.36.11` | `1.36.12` |



Updates `github.com/ethereum/go-ethereum` from 1.17.4 to 1.17.7
- [Release notes](https://github.com/ethereum/go-ethereum/releases)
- [Commits](ethereum/go-ethereum@v1.17.4...v1.17.7)

Updates `github.com/knadh/koanf/parsers/json` from 1.0.0 to 1.0.1
- [Release notes](https://github.com/knadh/koanf/releases)
- [Commits](knadh/koanf@v1.0.0...parsers/hcl/v1.0.1)

Updates `github.com/knadh/koanf/providers/rawbytes` from 1.0.0 to 1.0.1
- [Release notes](https://github.com/knadh/koanf/releases)
- [Commits](knadh/koanf@v1.0.0...parsers/hcl/v1.0.1)

Updates `github.com/knadh/koanf/v2` from 2.3.5 to 2.3.7
- [Release notes](https://github.com/knadh/koanf/releases)
- [Commits](knadh/koanf@v2.3.5...v2.3.7)

Updates `github.com/mattn/go-sqlite3` from 1.14.48 to 1.14.52
- [Release notes](https://github.com/mattn/go-sqlite3/releases)
- [Commits](mattn/go-sqlite3@v1.14.48...v1.14.52)

Updates `github.com/prometheus/client_golang` from 1.24.0 to 1.24.1
- [Release notes](https://github.com/prometheus/client_golang/releases)
- [Changelog](https://github.com/prometheus/client_golang/blob/main/CHANGELOG.md)
- [Commits](prometheus/client_golang@v1.24.0...v1.24.1)

Updates `github.com/prometheus/client_model` from 0.6.2 to 0.6.3
- [Release notes](https://github.com/prometheus/client_model/releases)
- [Commits](prometheus/client_model@v0.6.2...v0.6.3)

Updates `github.com/rs/cors` from 1.11.0 to 1.11.1
- [Commits](rs/cors@v1.11.0...v1.11.1)

Updates `github.com/stretchr/testify` from 1.11.1 to 1.12.1
- [Release notes](https://github.com/stretchr/testify/releases)
- [Commits](stretchr/testify@v1.11.1...v1.12.1)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](golang/sync@v0.22.0...v0.23.0)

Updates `google.golang.org/genproto/googleapis/rpc` from 0.0.0-20260526163538-3dc84a4a5aaa to 0.0.0-20260819154853-08b0e4226688
- [Commits](https://github.com/googleapis/go-genproto/commits)

Updates `google.golang.org/grpc` from 1.83.2 to 1.84.0
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.83.2...v1.84.0)

Updates `google.golang.org/protobuf` from 1.36.11 to 1.36.12

---
updated-dependencies:
- dependency-name: github.com/ethereum/go-ethereum
  dependency-version: 1.17.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: github.com/knadh/koanf/parsers/json
  dependency-version: 1.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: github.com/knadh/koanf/providers/rawbytes
  dependency-version: 1.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: github.com/knadh/koanf/v2
  dependency-version: 2.3.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: github.com/mattn/go-sqlite3
  dependency-version: 1.14.52
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: github.com/prometheus/client_golang
  dependency-version: 1.24.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: github.com/prometheus/client_model
  dependency-version: 0.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: github.com/rs/cors
  dependency-version: 1.11.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: github.com/stretchr/testify
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: google.golang.org/genproto/googleapis/rpc
  dependency-version: 0.0.0-20260819154853-08b0e4226688
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: google.golang.org/grpc
  dependency-version: 1.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: google.golang.org/protobuf
  dependency-version: 1.36.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/develop/all-dependencies-9c7d647404 branch from eeaca23 to 06c14df Compare October 6, 2026 12:07
@dependabot @github

dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 7, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/develop/all-dependencies-9c7d647404 branch October 7, 2026 11:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants