Skip to content

chore(deps): bump the dependencies group with 4 updates - #1470

Merged
k1LoW merged 1 commit into
mainfrom
dependabot/go_modules/dependencies-b00ce86ebf
May 11, 2026
Merged

k1LoW merged 1 commit into
mainfrom
dependabot/go_modules/dependencies-b00ce86ebf

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 4 updates: github.com/lestrrat-go/jwx/v3, golang.org/x/crypto, golang.org/x/mod and google.golang.org/grpc.

Updates github.com/lestrrat-go/jwx/v3 from 3.1.0 to 3.1.1

Release notes

Sourced from github.com/lestrrat-go/jwx/v3's releases.

v3.1.1

For more detailed release notes, see Changes.

What's Changed

Full Changelog: lestrrat-go/jwx@v3.1.0...v3.1.1

Changelog

Sourced from github.com/lestrrat-go/jwx/v3's changelog.

v3.1.1 7 May 2026

  • [jws] Coordinated RFC 7797 b64=false handling pass: jws.Verify rejects payloads with b64=false unless b64 is also listed in crit; jws.Sign auto-declares b64 in crit when emitting b64=false; Message.MarshalJSON honors b64=false instead of silently re-encoding; jws.VerifyCompactFast refuses any compact JWS carrying b64 (the fast path doesn't process extension headers); and b64 is now declared as a typed boolean header field rather than handled ad-hoc. (#2081, #2087, #2102, #2104, #2106)

  • [jws] Reject malformed general-form JSON-serialized JWS: inputs with a top-level header member as a sibling of signatures are rejected (the spec only permits header inside per-signature objects), as are inputs whose protected member is a literal JSON object instead of a base64url-encoded string. (#2089, #2108)

  • [jws] jws.AlgorithmsForKey failures from unclassifiable keys are now wrapped in a typed sentinel so callers can branch on "couldn't categorize this key" without string matching the error message. (#2110)

  • [jws] Verify error-shape consistency: VerifyCompactFast refusals now match the jws.VerifyError() taxonomy used by the slow path, fan-out verify errors name the loose WithKeySet options that were tried, multi-signature b64 mismatches name the offending signature index and conflicting value, and the compact b64=false+payload-contains-. error references RFC 7797 §5.2 and points at WithDetachedPayload. (#2083, #2085, #2114)

  • [jws] Keys fetched via the jku header are no longer accepted for signature verification when the JWK declares use=enc. (#2060)

  • [jws][jwe] jws.VerifyMessage and jwe.DecryptMessage observe context cancellation between loop iterations rather than only at boundaries. Long fan-out verify/decrypt loops now respond to a cancelled context promptly. (#2112, #2117)

  • [jwe] Reject PBES2 messages whose p2c (iteration count) does not parse cleanly into int64 or violates the configured bound. The error now names the violated bound (min vs max) instead of the generic "out of range". (#2119)

  • [jwe] jwe.WithKey() validates the alg-vs-key shape at option construction time rather than during encryption, so misuse surfaces at the call site instead of inside the encrypt loop. (#2121)

... (truncated)

Commits
  • 59b8b1b release v3.1.1
  • 4d4ab01 Changes: draft v3.1.1 release notes (#2155)
  • ad739f5 jwk: fix phantom ContinueParseError refs and unmarshaler typo in docs (#2142)
  • 3227cf9 jwk: treat nil key from custom KeyParser as continue, not success (#2140)
  • 82c067e jwk: stream the keys array with cap-before-allocate (#2137)
  • 931a815 jwk: wrap ParseKey errors with ParseError sentinel (#2135)
  • 53f6225 jwk: stop duplicating JWK fields at JWKS top level on parse (#2133)
  • 8943519 jwe: document WithMaxDecompressBufferSize behavior at non-positive values (#2...
  • 4797307 jwe: add WithDisabledKeyAlgorithms global policy hook (#2129)
  • de41d0e jwe: keySetProvider surfaces per-key errors via errors.Join (#2127)
  • Additional commits viewable in compare view

Updates golang.org/x/crypto from 0.50.0 to 0.51.0

Commits
  • b8a14a8 go.mod: update golang.org/x dependencies
  • 9d9d507 x509roots/fallback/bundle: fix bundle test with Go 1.27+
  • fd0b90d acme: include Problem in OrderError.Error
  • b9e5359 pbkdf2: turn into a wrapper for crypto/pbkdf2
  • cc0e4fc hkdf: forward Extract to the standard library
  • a8e9237 x509roots/fallback: update bundle
  • See full diff in compare view

Updates golang.org/x/mod from 0.35.0 to 0.36.0

Commits
  • 643da9b go.mod: update golang.org/x dependencies
  • ccc3cdf zip: include 'but content has correct sum' note in TestVCS
  • ab30318 zip: update zip hashes for new flate compression
  • See full diff in compare view

Updates google.golang.org/grpc from 1.80.0 to 1.81.0

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.81.0

Behavior Changes

  • balancer/rls: Switch gauge metrics to asynchronous emission (once per collection cycle) to reduce telemetry noise and align with other gRPC language implementations. (#8808)

Dependencies

  • Minimum supported Go version is now 1.25. (#8969)

Bug Fixes

  • xds: Use the leaf cluster's security config for the TLS handshake instead of the aggregate cluster's config. (#8956)
  • transport: Send a RST_STREAM when receiving an END_STREAM when the stream is not already half-closed. (#8832)
  • xds: Fix ADS resource name validation to prevent a panic. (#8970)

New Features

  • grpc/stats: Add support for custom labels in per-call metrics (gRFC A108). (#9008)
  • xds: Add support for Server Name Indication (SNI) and SAN validation (gRFC A101). Disabled by default. To enable, set GRPC_EXPERIMENTAL_XDS_SNI=true environment variable. (#9016)
  • xds: Add support to control which fields get propagated from ORCA backend metric reports to LRS load reports (gRFC A85). Disabled by default. To enable, set GRPC_EXPERIMENTAL_XDS_ORCA_LRS_PROPAGATION=true. (#9005)
  • xds: Add metrics to track xDS client connectivity and cached resource state (gRFC A78). (#8807)
  • stats/otel: Enhance grpc.subchannel.disconnections metric by adding disconnection reason to the grpc.disconnect_error label (gRFC A94). This provides granular insights into why subchannels are closing. (#8973)
  • mem: Add mem.Buffer.Slice() API to slice the buffer like a slice. (#8977)

Performance Improvements

  • alts: Pool read buffers to lower memory utilization when sockets are unreadable. (#8964)
  • transport: Pool HTTP/2 framer read buffers to reduce idle memory consumption. Currently limited to Linux for ALTS and non-encrypted transports (TCP, Unix). To disable, set GRPC_GO_EXPERIMENTAL_HTTP_FRAMER_READ_BUFFER_POOLING=false and report any issues. (#9032)
Commits
  • cb18228 Change version to 1.81.0 (#9062)
  • 96748f9 Cherry-pick #9105 to 1.81.x (#9106)
  • 9183222 Cherry pick #9055, #9032 to v1.81.x (#9095)
  • 5cba6da Revert "deps: update dependencies for all modules (#9065)" (#9067)
  • af8a936 deps: update dependencies for all modules (#9065)
  • cdc60df transport: optimize heap allocations in ready reader and update syscall conne...
  • 208d053 xds/resolver: pass complete XDSConfig in RPC context for HTTP filters (gRFC A...
  • 50fe1cc test: Fix flaky test TestServerStreaming_ClientCallRecvMsgTwice in `end2end...
  • d574bad build(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 (#9050)
  • b8bf4d0 build(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 in /inte...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dependencies group with 4 updates: [github.com/lestrrat-go/jwx/v3](https://github.com/lestrrat-go/jwx), [golang.org/x/crypto](https://github.com/golang/crypto), [golang.org/x/mod](https://github.com/golang/mod) and [google.golang.org/grpc](https://github.com/grpc/grpc-go).


Updates `github.com/lestrrat-go/jwx/v3` from 3.1.0 to 3.1.1
- [Release notes](https://github.com/lestrrat-go/jwx/releases)
- [Changelog](https://github.com/lestrrat-go/jwx/blob/v3.1.1/Changes)
- [Commits](lestrrat-go/jwx@v3.1.0...v3.1.1)

Updates `golang.org/x/crypto` from 0.50.0 to 0.51.0
- [Commits](golang/crypto@v0.50.0...v0.51.0)

Updates `golang.org/x/mod` from 0.35.0 to 0.36.0
- [Commits](golang/mod@v0.35.0...v0.36.0)

Updates `google.golang.org/grpc` from 1.80.0 to 1.81.0
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.80.0...v1.81.0)

---
updated-dependencies:
- dependency-name: github.com/lestrrat-go/jwx/v3
  dependency-version: 3.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: golang.org/x/crypto
  dependency-version: 0.51.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: golang.org/x/mod
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: google.golang.org/grpc
  dependency-version: 1.81.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] 
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code minor labels May 8, 2026
@k1LoW
k1LoW merged commit ce621de into main May 11, 2026
7 checks passed
@k1LoW
k1LoW deleted the dependabot/go_modules/dependencies-b00ce86ebf branch May 11, 2026 01:13
@github-actions github-actions Bot mentioned this pull request May 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code minor

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant