Skip to content

fix(deps): update go dependencies - #1477

Merged
mariusvniekerk merged 1 commit into
mainfrom
renovate/go-dependencies
Aug 21, 2026
Merged

mariusvniekerk merged 1 commit into
mainfrom
renovate/go-dependencies

Conversation

@renovate

@renovate renovate Bot commented Aug 20, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
github.com/danielgtaylor/huma/v2 v2.38.0 → v2.39.1 age confidence
github.com/duckdb/duckdb-go/v2 v2.10504.0 → v2.10505.0 age confidence
github.com/klauspost/compress v1.19.0 → v1.19.2 age confidence
github.com/mattn/go-runewidth v0.0.24 → v0.0.27 age confidence
github.com/mattn/go-sqlite3 v1.14.47 → v1.14.49 age confidence
github.com/modelcontextprotocol/go-sdk v1.6.1 → v1.7.0 age confidence
github.com/shirou/gopsutil/v4 v4.26.6 → v4.26.7 age confidence
github.com/testcontainers/testcontainers-go v0.43.0 → v0.44.0 age confidence
github.com/testcontainers/testcontainers-go/modules/postgres v0.43.0 → v0.44.0 age confidence
go.kenn.io/docbank v0.11.0 → v0.12.0 age confidence
go.kenn.io/kit v0.13.1 → v0.21.1 age confidence
modernc.org/sqlite v1.53.0 → v1.56.0 age confidence

Release Notes

danielgtaylor/huma (github.com/danielgtaylor/huma/v2)

v2.39.1

Compare Source

v2.39.1
Overview

A patch release: correctness fixes for resolvers, validation, and response handling, plus a dependency refresh.

Response Status Visible to Middleware Again

WithContext context propagation in v2.39.0 copied the response status by value, so middleware that called WithContext and then read Status() after next() always saw 0 instead of the status the handler set, breaking access logging and telemetry. The status is now shared by every context copy across all adapters, restoring the pre-2.39 invariant while keeping context propagation intact. (#​1081)

Resolvers & Defaults in Arrays and Maps
  • Nested resolvers now run for fixed-size arrays ([2]Item), not just slices (#​1076)
  • A resolver on a named collection type (e.g. type Coords [2]float64) no longer panics, and is no longer conflated with a resolver on its element type, which previously ran the element's resolver twice and the collection's never (#​1082)
  • Values reached through a map are now written back after being walked, so applying a default no longer panics with reflect: reflect.Value.Set using unaddressable value and resolver mutations are no longer silently discarded (#​1082)
Stricter email and uri Formats

Validation for two string formats is tighter, so payloads that previously passed may now return 422:

  • email / idn-email accept an addr-spec only; full mailbox forms with a display name (Name <user@example.com>) are rejected
  • uri / iri require an absolute URI with a non-empty scheme, while relative references remain valid under uri-reference / iri-reference (#​1068)
Validation Robustness
  • An unresolvable schema $ref during Validate now reports expected schema $ref to resolve: ... instead of panicking on a nil dereference, covering discriminators and map[string]any / map[any]any values (#​1065)
  • Named numeric slice parameters (e.g. type IDs []int64) are built with their declared element type and validated with item, length, and uniqueness constraints intact (#​1074)
Other Fixes
  • Resolver errors that wrap a HeadersError now contribute their headers to the response, matching the handler error path (#​1070)
  • A nil interface response body no longer panics in the schema link transformer (#​1072)
  • Dependencies updated (#​1066)
What's Changed
New Contributors

Full Changelog: danielgtaylor/huma@v2.39.0...v2.39.1

v2.39.0

Compare Source

v2.39.0
Overview

This release adds a new framework adapter, a handful of developer-facing features, and a large batch of correctness fixes spanning SSE, the Fiber adapter, schema generation, and validation.

Echo v5 Support

The humaecho adapter now supports Echo v5 alongside the existing versions. (#​959)

No More Faulty Duplicate-Schema Panics

Registering operations that use inline structs with differing field names (and an empty operation ID) previously panicked at startup on a false-positive duplicate-schema collision. Conflicting names are now auto-incremented deterministically (Request, Request1, Request2, ...), so the app starts and the generated spec stays readable. (#​893)

Context Propagation to Adapters

WithContext now propagates the context directly into the underlying adapter's own context wrapper (bun, chi, echo, fiber, gin, go, httprouter) instead of relying on a generic sub-context, so cancellation and context values flow correctly through the request lifecycle. (#​867)

SSE Streaming on Fiber / fasthttp

Server-Sent Events (and other streaming responses) previously failed on the Fiber adapters with unable to flush, since fasthttp doesn't implement http.Flusher. SSE now streams correctly on Fiber v2 and v3 via an internal streaming hook, with no new public API and fasthttp remaining an indirect dependency. (#​1059)

More SSE Improvements
  • Response headers are now flushed before the user handler runs, so EventSource.onopen fires immediately rather than waiting for the first event (#​1038)
  • Comments can now be sent over SSE streams, a common way to keep connections alive (#​1054)
New Features
  • Schema.Const for pinning a schema to a single allowed value (#​1004)
  • Customizable docs renderer config for finer control over the documentation UI (#​1024)
  • encoding.TextUnmarshaler support for slice query parameters, matching the existing behavior for scalar params (#​1021)
  • Non-file JSON form-data fields: multipart form fields tagged contentType:"application/json" are now unmarshalled and validated (#​1060)
Validation & Schema Fixes
  • Integer enums no longer always fail validation on query/path parameters; numeric enum values are now compared numerically rather than by strict Go type (#​1050)
  • Content-Type validation is now case-insensitive per RFC 9110, so e.g. Application/Json no longer returns 415 (#​1052)
  • Path parameters are always marked required: true in the generated spec, per the OpenAPI specification (#​1011)
  • Prevented a panic (and dropped response) in uniqueItems validation when array items are unhashable types, now returning 422 correctly (#​1045)
  • The json:",inline" tag is now honored for embedding anonymous fields in schemas (#​1006)
  • Hidden route schemas are no longer leaked into the generated spec (#​1032)
Adapter & Robustness Fixes
  • humafiber (v2): corrected EachHeader iteration (it previously invoked the callback once per byte, breaking cookie reads) and switched BodyReader to Body() for automatic request-body decompression (#​1058)
  • autopatch: prevented chi route-context reuse from recursing internal GET sub-requests back into the generated PATCH handler and panicking (#​1049)
  • Fixed a URL parsing panic in getAPIPrefix when server URLs contain template variables like {port} or {version} (#​1027)
  • The read deadline is now cleared after the request body is read, so a slow handler can't cause a background read to time out and cancel the connection context (#​1028)
Docs UI & Documentation
  • Forms are now permitted in the docs UI CSP (#​1036)
  • Added allow-downloads to the Stoplight CSP so the Export button works (#​1048)
  • Updated Restish references to v2 (#​1041)
What's Changed
New Contributors

Full Changelog: danielgtaylor/huma@v2.38.0...v2.39.0

duckdb/duckdb-go (github.com/duckdb/duckdb-go/v2)

v2.10505.0

Compare Source

What's Changed

Full Changelog: duckdb/duckdb-go@v2.10504.0...v2.10505.0

klauspost/compress (github.com/klauspost/compress)

v1.19.2

Compare Source

What's Changed
New Contributors

Full Changelog: klauspost/compress@v1.19.1...v1.19.2

v1.19.1

Compare Source

What's Changed

New Contributors

Full Changelog: klauspost/compress@v1.19.0...v1.19.1

mattn/go-runewidth (github.com/mattn/go-runewidth)

v0.0.27

Compare Source

v0.0.26

Compare Source

v0.0.25

Compare Source

mattn/go-sqlite3 (github.com/mattn/go-sqlite3)

v1.14.49: 1.14.49

Compare Source

What's Changed

Full Changelog: mattn/go-sqlite3@v1.14.48...v1.14.49

v1.14.48: 1.14.48

Compare Source

What's Changed

New Contributors

Full Changelog: mattn/go-sqlite3@v1.14.16...v1.14.48

modelcontextprotocol/go-sdk (github.com/modelcontextprotocol/go-sdk)

v1.7.0

Compare Source

This release brings full support for protocol version 2026-07-28.
The wire protocol is largely rewritten: a stateless model with per-request _meta, a new server/discover RPC replacing the initialize handshake, multi-round-trip requests (MRTR) replacing server-initiated calls, a unified subscriptions/listen stream replacing free-floating change notifications, standardised HTTP headers, and the formal deprecation of the roots, sampling, and logging features.

The streamable HTTP transport accepts requests at protocol version 2026-07-28 only when StreamableHTTPOptions.Stateless = true. If you want to expose the new protocol over HTTP, set Stateless = true; if you want to keep stateful sessions, your clients will negotiate down to 2025-11-25.

Backward compatibility with 2025-11-25 and earlier is preserved on every endpoint. The SDK negotiates the highest mutually-supported version at connect time. The new protocol is enabled by default for new clients; existing legacy clients and servers continue to work unchanged.

This release consolidates everything shipped in v1.7.0-pre.1, v1.7.0-pre.2, and v1.7.0-pre.3. Thank you to everyone who exercised the pre-releases and filed feedback.

v1.7.0-pre.3 is already successfully used by GitHub, serving more than half a million users.

Make MCP Stateless (SEP-2575) & Sessionless (SEP-2567)

The initialize/notifications/initialized handshake is removed in 2026-07-28. Each request now carries _meta.io.modelcontextprotocol/{protocolVersion,clientInfo,clientCapabilities} so the server can validate the peer without state. A new server/discover RPC lets clients learn the server's supported versions and capabilities up front; the SDK falls back to legacy initialize if discover fails. Resumability (Last-Event-ID, standalone GET) is removed; ping, logging/setLevel, resources/subscribe, and resources/unsubscribe are also removed on this revision and rejected with MethodNotFound.

Subscriptions listen (SEP-2575)

The legacy tools/list_changed, prompts/list_changed, resources/list_changed, and resources/updated notifications are replaced by a single long-lived subscriptions/listen request whose response stream multiplexes every change notification the client opted into, each tagged with io.modelcontextprotocol/subscriptionId. The SDK opens this stream automatically on Client.Connect when the corresponding list-changed handler is set; servers route notifications only to subscribed sessions.

Multi Round-Trip Requests (SEP-2322)

Server-to-client requests for elicitation, sampling, and roots are no longer issued as fresh JSON-RPC requests. Instead a tool/prompt/resource handler returns an InputRequiredResult whose inputRequests field carries the requests; the client fulfils each and retries the original call with inputResponses populated. The SDK ships client- and server-side middleware that handles this transparently in both directions, including a server-side compatibility shim that lets MRTR handlers also work against legacy clients.

Cacheable list results (SEP-2549)

tools/list, prompts/list, resources/list, resources/templates/list, resources/read, and server/discover results now carry ttlMs and cacheScope fields. Clients honour them as freshness hints to reduce polling; shared intermediaries use cacheScope to decide whether responses may be cached.

HTTP standardization (SEP-2243)

The streamable HTTP transport now mirrors selected fields from the JSON-RPC body into HTTP headers (Mcp-Method, Mcp-Name, Mcp-Protocol-Version, Mcp-Param-*) so network intermediaries can route and observe MCP traffic without deep packet inspection. Tools can declare per-parameter passthrough via x-mcp-header annotations on their input schema. Body↔header mismatches return -32020 HeaderMismatch.

Deprecation of roots, sampling, and logging (SEP-2577)

Roots, sampling, and logging are formally deprecated on the 2026-07-28 revision. The SDK continues to expose the corresponding Go types for backward compatibility with older peers, but new servers should not rely on them.

Behavior changes guarded by MCPGODEBUG

Seven escape-hatch flags are added in this release to restore behavior that changed as part of spec-compliance fixes. All will be removed in v1.9.0.

  • customresnotfounderrcode=1 — restore the old -32002 code for ResourceNotFoundError.
  • hintomitempty=1 — restore omitempty on ToolAnnotations.ReadOnlyHint and IdempotentHint. The default now always serializes these fields because the Go types are bare bool (not *bool), so omitting false made it indistinguishable from "unset".
  • allowsessionsinstateless=1 — restore session-id handling on stateless streamable HTTP servers (read/write Mcp-Session-Id, accept DELETE). The default behavior is now what the spec requires: stateless servers ignore session IDs entirely and return 405 Method Not Allowed for DELETE.
  • nomethodnotfoundcodeinerror=1 — restore the previous STDIO behavior where the JSON-RPC MethodNotFound (-32601) code is omitted from the error response for unhandled methods. The default now includes the code.
  • **`noprotocoler

✂ Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@roborev-ci

roborev-ci Bot commented Aug 20, 2026

Copy link
Copy Markdown

roborev: Combined Review (adc64e3)

Dependency upgrades are security-clean, but the PR has incomplete Go module metadata.

Medium

  • go.mod:8 — The upgraded modules are missing corresponding checksums from go.sum, which still contains only the previous versions. This breaks reproducible or read-only dependency resolution. Run go mod tidy and commit the resulting go.mod transitive updates and go.sum checksums.

Reviewers: 2 done | Synthesis: codex, 24s | Total: 2m12s

@renovate
renovate Bot force-pushed the renovate/go-dependencies branch from adc64e3 to b206694 Compare August 21, 2026 02:36
@renovate

renovate Bot commented Aug 21, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 20 additional dependencies were updated

Details:

Package Change
github.com/docker/go-connections v0.6.0 -> v0.7.0
github.com/duckdb/duckdb-go-bindings v0.10504.0 -> v0.10505.0
github.com/duckdb/duckdb-go-bindings/lib/darwin-amd64 v0.10504.0 -> v0.10505.0
github.com/duckdb/duckdb-go-bindings/lib/darwin-arm64 v0.10504.0 -> v0.10505.0
github.com/duckdb/duckdb-go-bindings/lib/linux-amd64 v0.10504.0 -> v0.10505.0
github.com/duckdb/duckdb-go-bindings/lib/linux-arm64 v0.10504.0 -> v0.10505.0
github.com/duckdb/duckdb-go-bindings/lib/windows-amd64 v0.10504.0 -> v0.10505.0
github.com/ebitengine/purego v0.10.0 -> v0.10.2
github.com/felixge/httpsnoop v1.0.4 -> v1.1.0
github.com/go-ole/go-ole v1.2.6 -> v1.3.0
github.com/klauspost/cpuid/v2 v2.3.0 -> v2.4.0
github.com/lufia/plan9stats v0.0.0-20211012122336-39d0f177ccd0 -> v0.0.0-20260330125221-c963978e514e
github.com/mattn/go-isatty v0.0.21 -> v0.0.24
github.com/moby/moby/api v1.54.2 -> v1.55.0
github.com/moby/moby/client v0.4.0 -> v0.5.0
github.com/moby/sys/sequential v0.6.0 -> v0.7.0
github.com/tklauser/go-sysconf v0.3.16 -> v0.4.0
github.com/tklauser/numcpus v0.11.0 -> v0.12.0
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.60.0 -> v0.69.0
modernc.org/libc v1.73.4 -> v1.74.4

@roborev-ci

roborev-ci Bot commented Aug 21, 2026

Copy link
Copy Markdown

roborev: Combined Review (b206694)

No issues found.


Reviewers: 2 done | Synthesis: codex | Total: 6m52s

@mariusvniekerk
mariusvniekerk merged commit f2e020c into main Aug 21, 2026
21 checks passed
@mariusvniekerk
mariusvniekerk deleted the renovate/go-dependencies branch August 21, 2026 18:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant