Skip to content

fix(deps): update go modules (minor/patch) - #31

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-modules-(minorpatch)
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-modules-(minorpatch)

Conversation

@renovate

@renovate renovate Bot commented Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
entgo.io/ent v0.14.5 → v0.14.6 age confidence require patch
github.com/getkin/kin-openapi v0.144.0 → v0.149.0 age confidence require minor
github.com/go-chi/chi/v5 v5.2.4 → v5.3.2 age confidence require minor
github.com/mattn/go-sqlite3 v1.14.17 → v1.14.52 age confidence require patch
github.com/openchami/fabrica v0.4.3 → v0.4.11 age confidence require patch
github.com/spf13/viper v1.16.0 → v1.21.0 age confidence require minor
github.com/stretchr/testify v1.11.1 → v1.12.1 age confidence require minor
go (source) 1.26.2 → 1.27.1 age confidence golang minor

Release Notes

ent/ent (entgo.io/ent)

v0.14.6

Compare Source

getkin/kin-openapi (github.com/getkin/kin-openapi)

v0.149.0

Compare Source

What's Changed

Full Changelog: getkin/kin-openapi@v0.148.0...v0.149.0

v0.148.0

Compare Source

What's Changed

New Contributors

Full Changelog: getkin/kin-openapi@v0.147.0...v0.148.0

v0.147.0

Compare Source

What's Changed

New Contributors

Full Changelog: getkin/kin-openapi@v0.146.0...v0.147.0

v0.146.0

Compare Source

What's Changed

Full Changelog: getkin/kin-openapi@v0.145.0...v0.146.0

v0.145.0

Compare Source

What's Changed

Full Changelog: getkin/kin-openapi@v0.144.0...v0.145.0

go-chi/chi (github.com/go-chi/chi/v5)

v5.3.2

Compare Source

What's Changed

  • feat(middleware): add text/markdown, text/csv, text/vtt to default compressible types by @​VojtechVitek in #​1151
  • docs: deployment recipe for middleware.ClientIPFromXFFTrustedProxies() by @​VojtechVitek in #​1111
  • fix: don't drop handlers that collide with a Mount()/Route() pattern by @​VojtechVitek in #​1148
  • Don't duplicate methods in Allow: header for 405 responses by @​flimzy in #​1029
  • fix(middleware): reject catch-all compress wildcards by @​VojtechVitek in #​1156
    • middleware.NewCompressor(level, "/*") never worked and silently compressed nothing. Instead of turning it into a compress-everything catch-all (as proposed in #​868 and #​1121), we decided to reject both "/" and "/*" at construction and panic. Compressing every response wastes CPU on already-compressed types (zip, jpeg, png), which is why the middleware keeps a curated default list. Users should pass explicit content types.

Full Changelog: go-chi/chi@v5.3.1...v5.3.2

v5.3.1

Compare Source

What's Changed

New Contributors

Full Changelog: go-chi/chi@v5.3.0...v5.3.1

v5.3.0

Compare Source

What's Changed

New Contributors

SECURITY: middleware.ClientIP, a replacement for middleware.RealIP

PR #​967 introduced middleware.ClientIP, a replacement for middleware.RealIP that closes the three open spoofing advisories:

It also addresses issues outlined at:

middleware.RealIP is deprecated in this PR with pointers to the new API.

The deprecation only adds a // Deprecated: doc comment; the function keeps working for backward compatibility.

Why a new middleware (not "fix RealIP in place")

RealIP has two unfixable design choices: it mutates r.RemoteAddr, and it tries to be a one-size-fits-all default by walking a hard-coded list of headers any client can supply. Per adam-p's "The perils of the 'real' client IP" (which calls chi out by name on this), there is no safe default — the user must pick their trust source explicitly.

The new API

Four middlewares, two accessors. Pick exactly one middleware based on your
infrastructure, read the result with one of the two accessors:

// One of the four. There is no safe default — pick exactly one.
func ClientIPFromHeader(trustedHeader string) func(http.Handler) http.Handler
func ClientIPFromXFF(trustedIPPrefixes ...string) func(http.Handler) http.Handler
func ClientIPFromXFFTrustedProxies(numTrustedProxies int) func(http.Handler) http.Handler
func ClientIPFromRemoteAddr(h http.Handler) http.Handler

// Read the result.
func GetClientIP(ctx context.Context) string         // for logs, rate-limit keys
func GetClientIPAddr(ctx context.Context) netip.Addr // for typed work

Example usage:

// Pick a single ClientIP middleware based on your deployment
  
// Cloudflare.
r.Use(middleware.ClientIPFromHeader("CF-Connecting-IP"))

// Nginx with ngx_http_realip_module.
r.Use(middleware.ClientIPFromHeader("X-Real-IP"))

// Apache with mod_remoteip.
r.Use(middleware.ClientIPFromHeader("X-Client-IP"))

// AWS CloudFront, or any proxy fleet with known CIDRs.
r.Use(middleware.ClientIPFromXFF(
    "13.32.0.0/15",   // CloudFront IPv4
    "52.46.0.0/18",   // CloudFront IPv4
    "2600:9000::/28", // CloudFront IPv6
))

// Behind exactly 2 trusted proxies with dynamic IPs (autoscaling pools,
// ephemeral containers, dynamic CDN edges).
r.Use(middleware.ClientIPFromXFFTrustedProxies(2))

// Server directly on the public internet, no proxy in front.
r.Use(middleware.ClientIPFromRemoteAddr)

And in your handler or downstream middleware:

clientIP := middleware.GetClientIP(r.Context())
// log it, use it as a rate-limit key, etc.

Thanks to @​adam-p, @​c2h5oh, @​rezmoss, @​Saku0512, @​convto, @​Dirbaio, @​jawnsy, @​lrstanley, @​mfridman, @​n33pm, @​pkieltyka for the prior discussions, detailed reviews, advisory reports, and test contributions that shaped this PR.

Full Changelog: go-chi/chi@v5.2.5...v5.3.0

v5.2.5

Compare Source

What's Changed

New Contributors

Full Changelog: go-chi/chi@v5.2.3...v5.2.5

mattn/go-sqlite3 (github.com/mattn/go-sqlite3)

v1.14.52: 1.14.52

Compare Source

What's Changed

  • Replace schema probe with eager first step for cached statements by @​mattn in #​1454

Full Changelog: mattn/go-sqlite3@v1.14.51...v1.14.52

v1.14.51: 1.14.51

Compare Source

What's Changed

New Contributors

Full Changelog: mattn/go-sqlite3@v1.14.50...v1.14.51

v1.14.50: 1.14.50

Compare Source

What's Changed

New Contributors

Full Changelog: mattn/go-sqlite3@v1.14.49...v1.14.50

v1.14.49: 1.14.49

Compare Source

What's Changed

Full Changelog: mattn/go-sqlite3@v1.14.48...v1.14.49

v1.14.48: 1.14.48

Compare Source

What's Changed

New Contributors

Full Changelog: mattn/go-sqlite3@v1.14.16...v1.14.48

v1.14.47

Compare Source

v1.14.46

Compare Source

v1.14.45

Compare Source

v1.14.44

Compare Source

v1.14.43

Compare Source

v1.14.42

Compare Source

v1.14.41

Compare Source

v1.14.40

Compare Source

v1.14.39

Compare Source

v1.14.38

Compare Source

v1.14.37

Compare Source

v1.14.36

Compare Source

v1.14.35

Compare Source

v1.14.34

Compare Source

v1.14.33

Compare Source

v1.14.32

Compare Source

v1.14.31

Compare Source

v1.14.30

Compare Source

v1.14.29

Compare Source

v1.14.28

Compare Source

v1.14.27

Compare Source

v1.14.26

Compare Source

v1.14.25

Compare Source

v1.14.24

Compare Source

v1.14.23

Compare Source

v1.14.22

Compare Source

v1.14.21

Compare Source

v1.14.20

Compare Source

v1.14.19

Compare Source

v1.14.18

Compare Source

openchami/fabrica (github.com/openchami/fabrica)

v0.4.11

Compare Source

Fabrica 0.4.11

Release Date: 2026-09-24T19:07:57Z

Installation
Installer (Linux and macOS)
curl -fsSL https://github.com/openchami/fabrica/releases/latest/download/install.sh | sh
Binaries

Download the appropriate binary for your platform from the assets below.

Docker
docker pull ghcr.io/openchami/fabrica:0.4.11
Go Install
go install github.com/openchami/fabrica/cmd/fabrica@v0.4.11

Changelog

  • f068837 chore(deps): update actions/setup-go action to v7 (#​108)
  • 18e67fe chore(deps): update github-actions (minor/patch) (#​88)
  • 0cfffe3 chore(reuse): fix copyright (#​113)
  • 809a6ed feat(annotations): define dedicated storage annotation contract (#​98)
  • e045ede feat(codegen): add optional resource emitter extension (#​104)
  • 53b0071 feat(codegen): emit dedicated Ent schema annotations (#​99)
  • 9306bbc feat(codegen): map Go fields to Ent field types (#​100)
  • aa38d7c feat(codegen): support project-owned custom storage (#​106)
  • 08af6ad fix(annotations): make resource parsing order-independent and complete (#​97)
  • 29b6028 fix(codegen): hash by column name, and register Ent's runtime (#​103)
  • a4bd044 fix(deps): update go modules (minor/patch) (#​89)
  • 73e4934 test(codegen): cover generic Ent schemas and adapter (#​102)
  • 7f9592b test(codegen): preserve supplemental Ent schemas (#​105)
  • a9702d9 test(codegen): prove generated dedicated Ent schemas compile (#​101)

Full Changelog: OpenCHAMI/fabrica@v0.4.10...v0.4.11

v0.4.10

Compare Source

Fabrica 0.4.10

Release Date: 2026-08-13T23:13:48Z

Installation
Installer (Linux and macOS)
curl -fsSL https://github.com/openchami/fabrica/releases/latest/download/install.sh | sh
Binaries

Download the appropriate binary for your platform from the assets below.

Docker
docker pull ghcr.io/openchami/fabrica:0.4.10
Go Install
go install github.com/openchami/fabrica/cmd/fabrica@v0.4.10

Changelog

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/Denver)

  • Branch creation
    • "before 5am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file renovate labels Jul 27, 2026
@renovate

renovate Bot commented Jul 27, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 11 additional dependencies were updated

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=3 days

Details:

Package Change
ariga.io/atlas v0.32.1-0.20250325101103-175b25e1c1b9 -> v0.36.2-0.20250730182955-2c6300d0a3e1
github.com/fsnotify/fsnotify v1.6.0 -> v1.9.0
github.com/go-playground/validator/v10 v10.30.2 -> v10.30.3
github.com/pelletier/go-toml/v2 v2.0.8 -> v2.2.4
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 -> v6.0.3
github.com/subosito/gotenv v1.4.2 -> v1.6.0
go.uber.org/zap v1.27.1 -> v1.28.0
golang.org/x/crypto v0.52.0 -> v0.53.0
golang.org/x/mod v0.35.0 -> v0.38.0
golang.org/x/sys v0.45.0 -> v0.46.0
golang.org/x/text v0.37.0 -> v0.41.0

@renovate renovate Bot added the renovate label Jul 27, 2026
@renovate
renovate Bot force-pushed the renovate/go-modules-(minorpatch) branch 2 times, most recently from 488331c to d8da03f Compare August 1, 2026 10:10
@renovate
renovate Bot force-pushed the renovate/go-modules-(minorpatch) branch 4 times, most recently from b7d6fd7 to 145b60b Compare August 17, 2026 10:50
@renovate
renovate Bot force-pushed the renovate/go-modules-(minorpatch) branch 6 times, most recently from 9fff328 to 574d0db Compare August 29, 2026 16:46
@renovate
renovate Bot force-pushed the renovate/go-modules-(minorpatch) branch 13 times, most recently from 7b3a0ec to 09c5167 Compare September 2, 2026 23:04
@renovate
renovate Bot force-pushed the renovate/go-modules-(minorpatch) branch 6 times, most recently from b0988f4 to df82979 Compare September 8, 2026 11:34
@renovate
renovate Bot force-pushed the renovate/go-modules-(minorpatch) branch from df82979 to 667535e Compare September 27, 2026 22:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file renovate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants