fix(deps): update go dependencies - #1477
Merged
Merged
Conversation
roborev: Combined Review (
|
renovate
Bot
force-pushed
the
renovate/go-dependencies
branch
from
August 21, 2026 02:36
adc64e3 to
b206694
Compare
Contributor
Author
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
roborev: Combined Review (
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v2.38.0→v2.39.1v2.10504.0→v2.10505.0v1.19.0→v1.19.2v0.0.24→v0.0.27v1.14.47→v1.14.49v1.6.1→v1.7.0v4.26.6→v4.26.7v0.43.0→v0.44.0v0.43.0→v0.44.0v0.11.0→v0.12.0v0.13.1→v0.21.1v1.53.0→v1.56.0Release Notes
danielgtaylor/huma (github.com/danielgtaylor/huma/v2)
v2.39.1Compare Source
v2.39.1
Overview
A patch release: correctness fixes for resolvers, validation, and response handling, plus a dependency refresh.
Response Status Visible to Middleware Again
WithContextcontext propagation in v2.39.0 copied the response status by value, so middleware that calledWithContextand then readStatus()afternext()always saw0instead of the status the handler set, breaking access logging and telemetry. The status is now shared by every context copy across all adapters, restoring the pre-2.39 invariant while keeping context propagation intact. (#1081)Resolvers & Defaults in Arrays and Maps
[2]Item), not just slices (#1076)type Coords [2]float64) no longer panics, and is no longer conflated with a resolver on its element type, which previously ran the element's resolver twice and the collection's never (#1082)reflect: reflect.Value.Set using unaddressable valueand resolver mutations are no longer silently discarded (#1082)Stricter
emailanduriFormatsValidation for two string formats is tighter, so payloads that previously passed may now return
422:email/idn-emailaccept an addr-spec only; full mailbox forms with a display name (Name <user@example.com>) are rejecteduri/irirequire an absolute URI with a non-empty scheme, while relative references remain valid underuri-reference/iri-reference(#1068)Validation Robustness
$refduringValidatenow reportsexpected schema $ref to resolve: ...instead of panicking on a nil dereference, covering discriminators andmap[string]any/map[any]anyvalues (#1065)type IDs []int64) are built with their declared element type and validated with item, length, and uniqueness constraints intact (#1074)Other Fixes
HeadersErrornow contribute their headers to the response, matching the handler error path (#1070)What's Changed
New Contributors
Full Changelog: danielgtaylor/huma@v2.39.0...v2.39.1
v2.39.0Compare Source
v2.39.0
Overview
This release adds a new framework adapter, a handful of developer-facing features, and a large batch of correctness fixes spanning SSE, the Fiber adapter, schema generation, and validation.
Echo v5 Support
The
humaechoadapter now supports Echo v5 alongside the existing versions. (#959)No More Faulty Duplicate-Schema Panics
Registering operations that use inline structs with differing field names (and an empty operation ID) previously panicked at startup on a false-positive duplicate-schema collision. Conflicting names are now auto-incremented deterministically (
Request,Request1,Request2, ...), so the app starts and the generated spec stays readable. (#893)Context Propagation to Adapters
WithContextnow propagates the context directly into the underlying adapter's own context wrapper (bun, chi, echo, fiber, gin, go, httprouter) instead of relying on a generic sub-context, so cancellation and context values flow correctly through the request lifecycle. (#867)SSE Streaming on Fiber / fasthttp
Server-Sent Events (and other streaming responses) previously failed on the Fiber adapters with
unable to flush, since fasthttp doesn't implementhttp.Flusher. SSE now streams correctly on Fiber v2 and v3 via an internal streaming hook, with no new public API andfasthttpremaining an indirect dependency. (#1059)More SSE Improvements
EventSource.onopenfires immediately rather than waiting for the first event (#1038)New Features
Schema.Constfor pinning a schema to a single allowed value (#1004)encoding.TextUnmarshalersupport for slice query parameters, matching the existing behavior for scalar params (#1021)contentType:"application/json"are now unmarshalled and validated (#1060)Validation & Schema Fixes
Application/Jsonno longer returns415(#1052)required: truein the generated spec, per the OpenAPI specification (#1011)uniqueItemsvalidation when array items are unhashable types, now returning422correctly (#1045)json:",inline"tag is now honored for embedding anonymous fields in schemas (#1006)Adapter & Robustness Fixes
EachHeaderiteration (it previously invoked the callback once per byte, breaking cookie reads) and switchedBodyReadertoBody()for automatic request-body decompression (#1058)GETsub-requests back into the generatedPATCHhandler and panicking (#1049)getAPIPrefixwhen server URLs contain template variables like{port}or{version}(#1027)Docs UI & Documentation
allow-downloadsto the Stoplight CSP so the Export button works (#1048)What's Changed
encoding.TextUnmarshalersupport for slice query parameters by @B94715 in #1021New Contributors
Full Changelog: danielgtaylor/huma@v2.38.0...v2.39.0
duckdb/duckdb-go (github.com/duckdb/duckdb-go/v2)
v2.10505.0Compare Source
What's Changed
Full Changelog: duckdb/duckdb-go@v2.10504.0...v2.10505.0
klauspost/compress (github.com/klauspost/compress)
v1.19.2Compare Source
What's Changed
New Contributors
Full Changelog: klauspost/compress@v1.19.1...v1.19.2
v1.19.1Compare Source
What's Changed
Peekinstead ofReadBytefor thebufio.Readerdecode path by @joechenrh in #1169New Contributors
Full Changelog: klauspost/compress@v1.19.0...v1.19.1
mattn/go-runewidth (github.com/mattn/go-runewidth)
v0.0.27Compare Source
v0.0.26Compare Source
v0.0.25Compare Source
mattn/go-sqlite3 (github.com/mattn/go-sqlite3)
v1.14.49: 1.14.49Compare Source
What's Changed
3053004by @mattn in #1442Full Changelog: mattn/go-sqlite3@v1.14.48...v1.14.49
v1.14.48: 1.14.48Compare Source
What's Changed
3051001by @mattn in #13663051002by @mattn in #13703051003by @mattn in #13753053000by @mattn in #13943053002by @mattn in #14043053003by @mattn in #1427New Contributors
Full Changelog: mattn/go-sqlite3@v1.14.16...v1.14.48
modelcontextprotocol/go-sdk (github.com/modelcontextprotocol/go-sdk)
v1.7.0Compare Source
This release brings full support for protocol version
2026-07-28.The wire protocol is largely rewritten: a stateless model with per-request
_meta, a newserver/discoverRPC replacing theinitializehandshake, multi-round-trip requests (MRTR) replacing server-initiated calls, a unifiedsubscriptions/listenstream replacing free-floating change notifications, standardised HTTP headers, and the formal deprecation of the roots, sampling, and logging features.The streamable HTTP transport accepts requests at protocol version
2026-07-28only whenStreamableHTTPOptions.Stateless = true. If you want to expose the new protocol over HTTP, setStateless = true; if you want to keep stateful sessions, your clients will negotiate down to2025-11-25.Backward compatibility with
2025-11-25and earlier is preserved on every endpoint. The SDK negotiates the highest mutually-supported version at connect time. The new protocol is enabled by default for new clients; existing legacy clients and servers continue to work unchanged.This release consolidates everything shipped in
v1.7.0-pre.1,v1.7.0-pre.2, andv1.7.0-pre.3. Thank you to everyone who exercised the pre-releases and filed feedback.v1.7.0-pre.3is already successfully used by GitHub, serving more than half a million users.Make MCP Stateless (SEP-2575) & Sessionless (SEP-2567)
The
initialize/notifications/initializedhandshake is removed in2026-07-28. Each request now carries_meta.io.modelcontextprotocol/{protocolVersion,clientInfo,clientCapabilities}so the server can validate the peer without state. A newserver/discoverRPC lets clients learn the server's supported versions and capabilities up front; the SDK falls back to legacyinitializeif discover fails. Resumability (Last-Event-ID, standalone GET) is removed;ping,logging/setLevel,resources/subscribe, andresources/unsubscribeare also removed on this revision and rejected withMethodNotFound.MissingRequiredClientCapabilityerror data by @guglielmo-san (#1005)UnsupportedProtocolVersionerror by @guglielmo-san (#989)Subscriptions listen (SEP-2575)
The legacy
tools/list_changed,prompts/list_changed,resources/list_changed, andresources/updatednotifications are replaced by a single long-livedsubscriptions/listenrequest whose response stream multiplexes every change notification the client opted into, each tagged withio.modelcontextprotocol/subscriptionId. The SDK opens this stream automatically onClient.Connectwhen the corresponding list-changed handler is set; servers route notifications only to subscribed sessions.subscriptions/listenrpc (SEP-2575) by @guglielmo-san (#1007)Multi Round-Trip Requests (SEP-2322)
Server-to-client requests for elicitation, sampling, and roots are no longer issued as fresh JSON-RPC requests. Instead a tool/prompt/resource handler returns an
InputRequiredResultwhoseinputRequestsfield carries the requests; the client fulfils each and retries the original call withinputResponsespopulated. The SDK ships client- and server-side middleware that handles this transparently in both directions, including a server-side compatibility shim that lets MRTR handlers also work against legacy clients.Cacheable list results (SEP-2549)
tools/list,prompts/list,resources/list,resources/templates/list,resources/read, andserver/discoverresults now carryttlMsandcacheScopefields. Clients honour them as freshness hints to reduce polling; shared intermediaries usecacheScopeto decide whether responses may be cached.DiscoverResultby @guglielmo-san (#1022)HTTP standardization (SEP-2243)
The streamable HTTP transport now mirrors selected fields from the JSON-RPC body into HTTP headers (
Mcp-Method,Mcp-Name,Mcp-Protocol-Version,Mcp-Param-*) so network intermediaries can route and observe MCP traffic without deep packet inspection. Tools can declare per-parameter passthrough viax-mcp-headerannotations on their input schema. Body↔header mismatches return-32020 HeaderMismatch.x-mcp-headerby @guglielmo-san (#915)Deprecation of roots, sampling, and logging (SEP-2577)
Roots, sampling, and logging are formally deprecated on the
2026-07-28revision. The SDK continues to expose the corresponding Go types for backward compatibility with older peers, but new servers should not rely on them.Behavior changes guarded by MCPGODEBUG
Seven escape-hatch flags are added in this release to restore behavior that changed as part of spec-compliance fixes. All will be removed in v1.9.0.
customresnotfounderrcode=1— restore the old-32002code forResourceNotFoundError.hintomitempty=1— restoreomitemptyonToolAnnotations.ReadOnlyHintandIdempotentHint. The default now always serializes these fields because the Go types are barebool(not*bool), so omittingfalsemade it indistinguishable from "unset".allowsessionsinstateless=1— restore session-id handling on stateless streamable HTTP servers (read/writeMcp-Session-Id, acceptDELETE). The default behavior is now what the spec requires: stateless servers ignore session IDs entirely and return405 Method Not AllowedforDELETE.nomethodnotfoundcodeinerror=1— restore the previous STDIO behavior where the JSON-RPCMethodNotFound(-32601) code is omitted from the error response for unhandled methods. The default now includes the code.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.