fix(deps): update go deps - #675
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
Contributor
Author
ℹ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
renovate
Bot
force-pushed
the
renovate/go-deps
branch
5 times, most recently
from
September 15, 2025 05:46
cfe5463 to
1d00451
Compare
renovate
Bot
force-pushed
the
renovate/go-deps
branch
3 times, most recently
from
September 22, 2025 09:47
3a3cde4 to
454732b
Compare
renovate
Bot
force-pushed
the
renovate/go-deps
branch
4 times, most recently
from
September 29, 2025 09:59
7414232 to
9d84f67
Compare
renovate
Bot
force-pushed
the
renovate/go-deps
branch
9 times, most recently
from
October 5, 2025 16:42
d203676 to
2a00a77
Compare
renovate
Bot
force-pushed
the
renovate/go-deps
branch
5 times, most recently
from
October 14, 2025 11:07
73f7ae5 to
a28c63b
Compare
renovate
Bot
force-pushed
the
renovate/go-deps
branch
3 times, most recently
from
October 21, 2025 19:12
a2927db to
2a88f28
Compare
renovate
Bot
force-pushed
the
renovate/go-deps
branch
3 times, most recently
from
December 15, 2025 02:34
6b5bc0a to
76c4580
Compare
renovate
Bot
force-pushed
the
renovate/go-deps
branch
7 times, most recently
from
December 25, 2025 02:08
b02c775 to
48f2fa8
Compare
renovate
Bot
force-pushed
the
renovate/go-deps
branch
from
January 17, 2026 06:25
48f2fa8 to
7b45b9d
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the
Comment |
renovate
Bot
force-pushed
the
renovate/go-deps
branch
6 times, most recently
from
January 23, 2026 14:40
350aeb8 to
3af717d
Compare
renovate
Bot
force-pushed
the
renovate/go-deps
branch
2 times, most recently
from
January 26, 2026 14:00
34294f2 to
f28d9eb
Compare
renovate
Bot
force-pushed
the
renovate/go-deps
branch
4 times, most recently
from
February 9, 2026 10:04
5e18c33 to
1c89754
Compare
renovate
Bot
force-pushed
the
renovate/go-deps
branch
4 times, most recently
from
February 16, 2026 13:11
7feeab4 to
8ec32e9
Compare
Contributor
Author
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
Generated by renovateBot
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.4.3→v1.4.4v3.51.1→v3.52.0v1.18.6→v1.19.1v0.0.22→v0.0.24v0.4.1→v0.5.0v1.6.1→v1.7.0v3.9.0→v3.10.1v0.21.0→v0.22.0v0.36.1→v0.36.3Release Notes
go-logr/logr (github.com/go-logr/logr)
v1.4.4Compare Source
What's Changed
New Contributors
Full Changelog: go-logr/logr@v1.4.3...v1.4.4
go-task/task (github.com/go-task/task/v3)
v3.52.0Compare Source
order. Prompts now follow the order the vars are declared in the Taskfile.
(#2871 by @caproven)
Fish's
vendor_completions.ddirectory instead ofcompletions(#2850, #2859by @Legimity).
taskcommand, not justthe
taskbinary itself (#2852 by @kojiishi).show-aliaseszstyle can turn this off (#2865, #2864 by @vmaerten).\,_,^) leakinginto checksum/timestamp filenames, breaking
sources:/generates:up-to-datedetection (#2886 by @s3onghyun).
for: matrix:loops usingref:rows producing wrong values when thesame task was run concurrently (e.g. by parallel
deps) with different vars(#2890, #2894 by @amitmishra11).
secret: trueflag for variables that masks their value in logs,task --summary, and command output (#2514 by @vmaerten).use_gitignoresetting (global or per-task) to skip files matchedby your
.gitignorewhen fingerprintingsources/generatesand whenwatching (#2773 by @vmaerten).
--output,--output-group-begin,--output-group-end,--output-group-error-only) viathe
TASK_OUTPUT*environment variables (#2873 by @liiight).--temp-dirflag (withTASK_TEMP_DIRenv var andtemp-dirtaskrcconfig) to customise the directory where Task stores temporary files such as
checksums. Relative paths are resolved against the root Taskfile (#2891 by
@kjasn).
@vmaerten).
a
/_git/path segment rather than a.gitsuffix (#2904 by @pd93).taskfile.dev/Taskfile.yml (#2905 by
@pd93).
includes:entries (missingtaskfile/dir) reporting amisleading "include cycle detected" error instead of a clear configuration
error (#1881, #2892 by @Lewin671).
klauspost/compress (github.com/klauspost/compress)
v1.19.1Compare Source
What's Changed
Peekinstead ofReadBytefor thebufio.Readerdecode path by @joechenrh in #1169New Contributors
Full Changelog: klauspost/compress@v1.19.0...v1.19.1
v1.19.0Compare Source
What's Changed
decodedLenby @eustas in #1148New Contributors
Full Changelog: klauspost/compress@v1.18.6...v1.19.0
v1.18.7Compare Source
Security release without other changes.
Full Changelog: klauspost/compress@v1.18.6...v1.18.7
mattn/go-isatty (github.com/mattn/go-isatty)
v0.0.24Compare Source
v0.0.23Compare Source
moby/moby (github.com/moby/moby/client)
v0.5.0Compare Source
modelcontextprotocol/go-sdk (github.com/modelcontextprotocol/go-sdk)
v1.7.0Compare Source
This release brings full support for protocol version
2026-07-28.The wire protocol is largely rewritten: a stateless model with per-request
_meta, a newserver/discoverRPC replacing theinitializehandshake, multi-round-trip requests (MRTR) replacing server-initiated calls, a unifiedsubscriptions/listenstream replacing free-floating change notifications, standardised HTTP headers, and the formal deprecation of the roots, sampling, and logging features.The streamable HTTP transport accepts requests at protocol version
2026-07-28only whenStreamableHTTPOptions.Stateless = true. If you want to expose the new protocol over HTTP, setStateless = true; if you want to keep stateful sessions, your clients will negotiate down to2025-11-25.Backward compatibility with
2025-11-25and earlier is preserved on every endpoint. The SDK negotiates the highest mutually-supported version at connect time. The new protocol is enabled by default for new clients; existing legacy clients and servers continue to work unchanged.This release consolidates everything shipped in
v1.7.0-pre.1,v1.7.0-pre.2, andv1.7.0-pre.3. Thank you to everyone who exercised the pre-releases and filed feedback.v1.7.0-pre.3is already successfully used by GitHub, serving more than half a million users.Make MCP Stateless (SEP-2575) & Sessionless (SEP-2567)
The
initialize/notifications/initializedhandshake is removed in2026-07-28. Each request now carries_meta.io.modelcontextprotocol/{protocolVersion,clientInfo,clientCapabilities}so the server can validate the peer without state. A newserver/discoverRPC lets clients learn the server's supported versions and capabilities up front; the SDK falls back to legacyinitializeif discover fails. Resumability (Last-Event-ID, standalone GET) is removed;ping,logging/setLevel,resources/subscribe, andresources/unsubscribeare also removed on this revision and rejected withMethodNotFound.MissingRequiredClientCapabilityerror data by @guglielmo-san (#1005)UnsupportedProtocolVersionerror by @guglielmo-san (#989)Subscriptions listen (SEP-2575)
The legacy
tools/list_changed,prompts/list_changed,resources/list_changed, andresources/updatednotifications are replaced by a single long-livedsubscriptions/listenrequest whose response stream multiplexes every change notification the client opted into, each tagged withio.modelcontextprotocol/subscriptionId. The SDK opens this stream automatically onClient.Connectwhen the corresponding list-changed handler is set; servers route notifications only to subscribed sessions.subscriptions/listenrpc (SEP-2575) by @guglielmo-san (#1007)Multi Round-Trip Requests (SEP-2322)
Server-to-client requests for elicitation, sampling, and roots are no longer issued as fresh JSON-RPC requests. Instead a tool/prompt/resource handler returns an
InputRequiredResultwhoseinputRequestsfield carries the requests; the client fulfils each and retries the original call withinputResponsespopulated. The SDK ships client- and server-side middleware that handles this transparently in both directions, including a server-side compatibility shim that lets MRTR handlers also work against legacy clients.Cacheable list results (SEP-2549)
tools/list,prompts/list,resources/list,resources/templates/list,resources/read, andserver/discoverresults now carryttlMsandcacheScopefields. Clients honour them as freshness hints to reduce polling; shared intermediaries usecacheScopeto decide whether responses may be cached.DiscoverResultby @guglielmo-san (#1022)HTTP standardization (SEP-2243)
The streamable HTTP transport now mirrors selected fields from the JSON-RPC body into HTTP headers (
Mcp-Method,Mcp-Name,Mcp-Protocol-Version,Mcp-Param-*) so network intermediaries can route and observe MCP traffic without deep packet inspection. Tools can declare per-parameter passthrough viax-mcp-headerannotations on their input schema. Body↔header mismatches return-32020 HeaderMismatch.x-mcp-headerby @guglielmo-san (#915)Deprecation of roots, sampling, and logging (SEP-2577)
Roots, sampling, and logging are formally deprecated on the
2026-07-28revision. The SDK continues to expose the corresponding Go types for backward compatibility with older peers, but new servers should not rely on them.Behavior changes guarded by MCPGODEBUG
Seven escape-hatch flags are added in this release to restore behavior that changed as part of spec-compliance fixes. All will be removed in v1.9.0.
customresnotfounderrcode=1— restore the old-32002code forResourceNotFoundError.hintomitempty=1— restoreomitemptyonToolAnnotations.ReadOnlyHintandIdempotentHint. The default now always serializes these fields because the Go types are barebool(not*bool), so omittingfalsemade it indistinguishable from "unset".allowsessionsinstateless=1— restore session-id handling on stateless streamable HTTP servers (read/writeMcp-Session-Id, acceptDELETE). The default behavior is now what the spec requires: stateless servers ignore session IDs entirely and return405 Method Not AllowedforDELETE.nomethodnotfoundcodeinerror=1— restore the previous STDIO behavior where the JSON-RPCMethodNotFound(-32601) code is omitted from the error response for unhandled methods. The default now includes the code.noprotocolerrorbody=1— restore the previous streamable HTTP client behavior of not decoding the JSON-RPC error body of a non-2xx HTTP response. The default now surfaces the underlying JSON-RPC error.nowrapinvalidparams=1— restore the previous behavior of returning rawunmarshalParamserrors from receiving handlers instead of wrapping them as a JSON-RPC-32602 Invalid paramserror. Introduced by #1087.disablecompleteparamsvalidation=1— restore the previous behavior of acceptingcompletion/completeresponses without validating the presence of thecompletionparams object. Introduced by #1080.Other Changes to the SDK
Streamable HTTP transport:
streamableClientConn.Closeby @blackwell-systems (#929)Custom methods and MCPGODEBUG-guarded fixes:
unmarshalParamswith jsonrpc error by @guglielmo-san (#1087)CompleteResultby @guglielmo-san (#1080)Additional spec-compliance fixes:
DiscoverResult(SEP-2575) by @guglielmo-san (#1097)subscriptions/listenby @guglielmo-san (#1088)server/discoverfor<2026-07-28requests by @guglielmo-san (#1084)resultTypeon new-protocol responses by @ychampion (#1060)ElicitParamsby @guglielmo-san (#1078)ApplyDefaultwhenres.Content == nilby @guglielmo-san (#1069)InitializeParamsin Meta by @guglielmo-san (#1049)protocolVersionin legacy initialize toprotocolVersion20251125by @guglielmo-san (#1051)NotificationSubscriptionsa mandatory field by @guglielmo-san (#1050)omitemptyReadOnlyHintinToolAnnotationsby @pvlbzn (#908)AddToolwhen schema is nil by @wucm667 (#918)tool.InputSchemaandtool.OutputSchemavalidation (SEP-2106) by @guglielmo-san (#1009)2026-06-30to2026-07-28by @guglielmo-san (#1015)2026-07-28to the supported protocol versions by @guglielmo-san (#1020)Auth and OAuth:
ClockSkewoption toRequireBearerTokenOptionsby @BorisTyshkevich (#969)AllowMissingExpirationoption toRequireBearerTokenOptionsby @BorisTyshkevich (#971)MatchesResourcehelper (RFC 9728/8707 audience comparison) by @BorisTyshkevich (#970)oauth2.RetrieveErrorduring token refresh by @smlx (#917)Session, keepalive and misc:
golang.org/x/time/rateforLoggingHandlerrate limiting by @wucm667 (#927)Conformance tests, documentation and CI:
troubleshoot.mdto includeresultTypeby @guglielmo-san (#1081)github/codeql-actionfrom 4.35.1 to 4.35.2 by @dependabot (#922)github/codeql-actionfrom 4.35.2 to 4.36.0 by @dependabot (#986)actions/cachefrom 5.0.4 to 5.0.5 by @dependabot (#923)actions/cachefrom 5.0.5 to 6.1.0 by @dependabot (#1065)actions/setup-nodefrom 6.3.0 to 6.4.0 by @dependabot (#921)actions/upload-artifactfrom 7.0.0 to 7.0.1 by @dependabot (#920)actions/checkoutfrom 6.0.2 to 7.0.0 by @dependabot (#1040)actions/setup-pythonfrom 6.2.0 to 6.3.0 by @dependabot (#1038)actions/setup-gofrom 6.4.0 to 6.5.0 by @dependabot (#1066)github/codeql-action/upload-sariffrom 4.36.0 to 4.36.2 by @dependabot (#1039)New Contributors
Full Changelog: modelcontextprotocol/go-sdk@v1.6.0...v1.7.0
urfave/cli (github.com/urfave/cli/v3)
v3.10.1Compare Source
What's Changed
New Contributors
Full Changelog: urfave/cli@v3.10.0...v3.10.1
v3.10.0Compare Source
What's Changed
Full Changelog: urfave/cli@v3.9.1...v3.10.0
v3.9.1Compare Source
What's Changed
Full Changelog: urfave/cli@v3.9.0...v3.9.1
kubernetes/apimachinery (k8s.io/apimachinery)
v0.36.3Compare Source
v0.36.2Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.