fix(deps): update go deps - #675
renovate[bot] wants to merge 1 commit into
Conversation
ℹ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
cfe5463 to
1d00451
Compare
3a3cde4 to
454732b
Compare
7414232 to
9d84f67
Compare
d203676 to
2a00a77
Compare
73f7ae5 to
a28c63b
Compare
a2927db to
2a88f28
Compare
6b5bc0a to
76c4580
Compare
b02c775 to
48f2fa8
Compare
48f2fa8 to
7b45b9d
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the
Comment |
350aeb8 to
3af717d
Compare
34294f2 to
f28d9eb
Compare
5e18c33 to
1c89754
Compare
7feeab4 to
8ec32e9
Compare
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by Details:
|
Generated by renovateBot
This PR contains the following updates:
v3.51.1→v3.53.1v0.21.7→v0.22.1v0.0.22→v0.0.24v0.4.1→v0.6.0v1.6.1→v1.8.0v1.4.2→v1.7.0v3.9.0→v3.12.0v1.11.0→v1.12.0v0.22.0→v0.23.0v0.15.0→v0.16.0v0.36.1→v0.37.0Release Notes
go-task/task (github.com/go-task/task/v3)
v3.53.1Compare Source
🚀 Features
experimental feature for 3 years, but is now enabled by default. Massive
thanks to all those that contributed and gave feedback (too many to list
here). We've also given the
Remote Taskfiles documentation a
bit of a polish (#1317, #2906 by @pd93).
timeoutthat terminates a command once it exceeds thegiven duration (Go duration syntax). It covers shell commands, task calls,
deferred commands,
depsand theifcondition, obeysignore_error, andreports exit code
124. Callers that join arun: onceorwhen_changedtask already running now honor their own
timeout, and inherit that task'sfailure instead of being told it succeeded (#1569, #2898 by @vmaerten).
(monorepos). Fingerprinting is up to 86% faster and make up to 70% fewer
memory allocations on the more advanced scenarios. Benchmarks were added as
well. We're basically skipping work when not needed. (#2853, #2883 by
@Napolitain, #2884 by @Napolitain).
source files now reuses a single buffer, reducing memory allocations by ~98%
and wall-clock time by ~7% (#2925 by @vmaerten).
includes.excludescan now exclude a whole namespace: append:*to thenamespace name, e.g.
excludes: ['debug:*']. Bare entries still match asingle task name exactly (#2300, #2959 by @xmxxc).
enum.refin--interactiveprompts. Required vars usingenum.refnow show the selection list like static enums, instead of fallingback to free-form input (#2817 by @vmaerten).
task --completion nu. They completetask names and aliases, every flag with its description, and the values of
--completion,--outputand--sort(#2966 by @vmaerten).--verbosemode, a task whosecommand exits non-zero now reports
task: "<name>" failed: <error>instead ofstopping without a trace (#2240 by @Drino).
🐛 Fixes
checksum:not being verified when a remote Taskfile came fromthe cache (#2980 by @vmaerten).
{{.CHECKSUM}}/{{.TIMESTAMP}}) ignoring amethod:set at the Taskfile level: the variable now follows the same methodresolution as the up-to-date check. Only the variable matching the effective
method is injected, so a task inheriting a Taskfile-level
method: timestampgets
{{.TIMESTAMP}}and no longer a{{.CHECKSUM}}(which now renders as anempty string), and neither variable is injected when the effective method is
none(#2924 by @vmaerten).ref:infor: matrix:andenum:only accepting literal lists. Refscomputed with template functions like
keysorsplitListno longer failwith "must resolve to a list" (#2544, #2956 by @no-hup).
Escat an interactive variable prompt not cancelling the run(#2942 by @anilnatha).
joinUrlcollapsing the//in a URL scheme (e.g. producinghttp:/localhostinstead ofhttp://localhost) (#2915 by @vsaraikin).ignore_erroron a command inside aforloop. Editors no longer flag a Taskfile that Task runs perfectly fine (#2044
by @gokeefe-atb).
ignore_erroron atask:call, andif,setandshopton a commandinside a
forloop (#2967 by @vmaerten).📚 Documentation & Website
(#2184 by @jubr).
and its frontmatter on the website (#2981 by @pd93).
v3.53.0Compare Source
v3.52.0Compare Source
order. Prompts now follow the order the vars are declared in the Taskfile.
(#2871 by @caproven)
Fish's
vendor_completions.ddirectory instead ofcompletions(#2850, #2859by @Legimity).
taskcommand, not justthe
taskbinary itself (#2852 by @kojiishi).show-aliaseszstyle can turn this off (#2865, #2864 by @vmaerten).\,_,^) leakinginto checksum/timestamp filenames, breaking
sources:/generates:up-to-datedetection (#2886 by @s3onghyun).
for: matrix:loops usingref:rows producing wrong values when thesame task was run concurrently (e.g. by parallel
deps) with different vars(#2890, #2894 by @amitmishra11).
secret: trueflag for variables that masks their value in logs,task --summary, and command output (#2514 by @vmaerten).use_gitignoresetting (global or per-task) to skip files matchedby your
.gitignorewhen fingerprintingsources/generatesand whenwatching (#2773 by @vmaerten).
--output,--output-group-begin,--output-group-end,--output-group-error-only) viathe
TASK_OUTPUT*environment variables (#2873 by @liiight).--temp-dirflag (withTASK_TEMP_DIRenv var andtemp-dirtaskrcconfig) to customise the directory where Task stores temporary files such as
checksums. Relative paths are resolved against the root Taskfile (#2891 by
@kjasn).
@vmaerten).
a
/_git/path segment rather than a.gitsuffix (#2904 by @pd93).taskfile.dev/Taskfile.yml (#2905 by
@pd93).
includes:entries (missingtaskfile/dir) reporting amisleading "include cycle detected" error instead of a clear configuration
error (#1881, #2892 by @Lewin671).
google/go-containerregistry (github.com/google/go-containerregistry)
v0.22.1Compare Source
What's Changed
New Contributors
Full Changelog: google/go-containerregistry@v0.22.0...v0.22.1
v0.22.0Compare Source
What's Changed
New Contributors
Full Changelog: google/go-containerregistry@v0.21.9...v0.21.10
v0.21.9Compare Source
What's Changed
Full Changelog: google/go-containerregistry@v0.21.8...v0.21.9
v0.21.8Compare Source
The artifacts attached to this release are missing SLSA provenance, see #2390.
What's Changed
New Contributors
Full Changelog: google/go-containerregistry@v0.21.7...v0.21.8
mattn/go-isatty (github.com/mattn/go-isatty)
v0.0.24Compare Source
v0.0.23Compare Source
moby/moby (github.com/moby/moby/client)
v0.6.0Compare Source
0.6.0
Changelog
v0.5.1Compare Source
v0.5.0Compare Source
modelcontextprotocol/go-sdk (github.com/modelcontextprotocol/go-sdk)
v1.8.0Compare Source
This release is equivalent to v1.8.0-pre.2. Thank you to those who tested the pre-release.
In this release we introduce several fixes and improvements on top of v1.7.0. It adds no new protocol revision: the supported set is unchanged, and
2026-07-28remains the newest version the SDK negotiates.The bulk of the work is hardening the transports against resource exhaustion, closing session leaks, deadlocks and teardown hangs found by users running the new protocol at scale, and giving servers explicit control over which protocol versions they advertise.
Two behavior changes are guarded by new
MCPGODEBUGflags; see the section below.Hardening against resource exhaustion
Every decoding path that buffers incoming input is now bounded. JSON payloads are rejected past 1000 levels of nesting, before the parser recurses. Both SSE readers cap the bytes buffered for a single event via
MaxEventSizeonSSEClientTransportandStreamableClientTransport, and the stdio transport caps a single JSON-RPC frame viaStdioTransport.MaxLineLength.On the OAuth side, dynamic client registration responses are bounded to 1 MB, and the discovery code now validates metadata documents rather than trusting them.
Restricting the protocol versions a server supports
ServerOptions.SupportedProtocolVersionslets a server narrow the set of versions it advertises and negotiates. The list can only narrow, never widen; naming a version the SDK does not implement panics at construction.Relatedly, a stateful streamable handler receiving a
2026-07-28request now returns that same JSON-RPC error instead of a plain-text 400, so the client can renegotiate down instead of losing the connection.Per-request cache control
ServerOptions.SetCacheableis a new hook that decides thettlMsandcacheScopefields of every result carrying them:server/discover, the four list methods, andresources/read. It runs once per result, after the handler returns, with the values that handler produced, so it can set a policy globally while still letting an individual handler override it. Anything left unset falls back to the protocol default ofpublic.Behavior changes guarded by MCPGODEBUG
Two new escape-hatch flags restore the previous behavior of the changes above. Both will be removed in v1.9.0.
plaintextstatefulrejection=1— restore the plain-texthttp.Error400 body a statefulStreamableHTTPHandlerpreviously returned for a request carrying per-request metadata. The default is now a JSON-RPC-32022 CodeUnsupportedProtocolVersionerror with anUnsupportedProtocolVersionDatapayload advertising the legacy versions the server supports. Introduced by #1143.blockingcancelnotify=1— restore the previous behavior where a cancelled call waits synchronously fornotifications/cancelledto be delivered (up to 5s) before returning, joining any delivery error into the caller's error. The default now retires the call immediately and sends the notification asynchronously. Introduced by #1151.Options below were removed, according to plan:
seterroroverwriteenableoriginverificationdisablecontenttypecheckdisablelocalhostprotectionOther Changes to the SDK
go getleaves the module unbuildable by @tonydzi (#1148)actions/setup-nodefrom 6.0.0 to 7.0.0 by @dependabot (#1123)actions/setup-pythonfrom 6.3.0 to 7.0.0 by @dependabot (#1124)actions/setup-gofrom 6.5.0 to 7.0.0 by @dependabot (#1125)actions/checkoutfrom 7.0.0 to 7.0.1 by @dependabot (#1126)golang/govulncheck-actionfrom 1.0.4 to 1.1.0 by @dependabot (#1218)ossf/scorecard-actionfrom 2.4.3 to 2.4.4 by @dependabot (#1217)New Contributors
Full Changelog: modelcontextprotocol/go-sdk@v1.7.0...v1.8.0-pre.1
v1.7.0Compare Source
This release brings full support for protocol version
2026-07-28.The wire protocol is largely rewritten: a stateless model with per-request
_meta, a newserver/discoverRPC replacing theinitializehandshake, multi-round-trip requests (MRTR) replacing server-initiated calls, a unifiedsubscriptions/listenstream replacing free-floating change notifications, standardised HTTP headers, and the formal deprecation of the roots, sampling, and logging features.The streamable HTTP transport accepts requests at protocol version
2026-07-28only whenStreamableHTTPOptions.Stateless = true. If you want to expose the new protocol over HTTP, setStateless = true; if you want to keep stateful sessions, your clients will negotiate down to2025-11-25.Backward compatibility with
2025-11-25and earlier is preserved on every endpoint. The SDK negotiates the highest mutually-supported version at connect time. The new protocol is enabled by default for new clients; existing legacy clients and servers continue to work unchanged.This release consolidates everything shipped in
v1.7.0-pre.1,v1.7.0-pre.2, andv1.7.0-pre.3. Thank you to everyone who exercised the pre-releases and filed feedback.v1.7.0-pre.3is already successfully used by GitHub, serving more than half a million users.Make MCP Stateless (SEP-2575) & Sessionless (SEP-2567)
The
initialize/notifications/initializedhandshake is removed in2026-07-28. Each request now carries_meta.io.modelcontextprotocol/{protocolVersion,clientInfo,clientCapabilities}so the server can validate the peer without state. A newserver/discoverRPC lets clients learn the server's supported versions and capabilities up front; the SDK falls back to legacyinitializeif discover fails. Resumability (Last-Event-ID, standalone GET) is removed;ping,logging/setLevel,resources/subscribe, andresources/unsubscribeare also removed on this revision and rejected withMethodNotFound.MissingRequiredClientCapabilityerror data by @guglielmo-san (#1005)UnsupportedProtocolVersionerror by @guglielmo-san (#989)Subscriptions listen (SEP-2575)
The legacy
tools/list_changed,prompts/list_changed,resources/list_changed, andresources/updatednotifications are replaced by a single long-livedsubscriptions/listenrequest whose response stream multiplexes every change notification the client opted into, each tagged withio.modelcontextprotocol/subscriptionId. The SDK opens this stream automatically onClient.Connectwhen the corresponding list-changed handler is set; servers route notifications only to subscribed sessions.subscriptions/listenrpc (SEP-2575) by @guglielmo-san (#1007)Multi Round-Trip Requests (SEP-2322)
Server-to-client requests for elicitation, sampling, and roots are no longer issued as fresh JSON-RPC requests. Instead a tool/prompt/resource handler returns an
InputRequiredResultwhoseinputRequestsfield carries the requests; the client fulfils each and retries the original call withinputResponsespopulated. The SDK ships client- and server-side middleware that handles this transparently in both directions, including a server-side compatibility shim that lets MRTR handlers also work against legacy clients.Cacheable list results (SEP-2549)
tools/list,prompts/list,resources/list,resources/templates/list,resources/read, andserver/discoverresults now carryttlMsandcacheScopefields. Clients honour them as freshness hints to reduce polling; shared intermediaries usecacheScopeto decide whether responses may be cached.DiscoverResultby @guglielmo-san (#1022)HTTP standardization (SEP-2243)
The streamable HTTP transport now mirrors selected fields from the JSON-RPC body into HTTP headers (
Mcp-Method,Mcp-Name,Mcp-Protocol-Version,Mcp-Param-*) so network intermediaries can route and observe MCP traffic without deep packet inspection. Tools can declare per-parameter passthroughConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.