6675 Commits

Author SHA1 Message Date
dependabot[bot] c35f3171a0 build(deps): bump hono in /e2e/api/compile/prisma
Bumps [hono](https://github.com/honojs/hono) from 4.12.18 to 4.12.23.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](https://github.com/honojs/hono/compare/v4.12.18...v4.12.23)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.12.23
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-05 08:05:18 +02:00
Philip Conrad 850f198d09 bundle: improve determinism of file_rego_versions patterns with overlap. (#8733)
This commit makes the behavior of pattern selection for
determining `file_rego_versions` from a bundle manifest more
deterministic when the pattern have overlap.

The docs note that when overlapping patterns occur, the result
is undefined. In practice, this meant that the map of patterns
was iterated over in randomized order.

We now iterate over the `file_rego_version` patterns in
lexically-sorted order, which ensures a deterministic result,
even when user-authored glob patterns overlap with each other.

Signed-off-by: Philip Conrad <philip_conrad@apple.com>
2026-06-04 11:47:07 -04:00
Anders Eknert 511fe48b5b ast: Clean up code for value comparisons (#8737)
The `ast.Compare(any, any)` function is a beast better avoided, and the
`any` args type mean some AST values (like strings) escape to the heap
when boxed.

Previous work already ensured it wasn't called too often — this just
moves it further along by having all `ast.Value`s do their own
comparisons with the help of a new function to easily compare 2
different value types.

Also:
- topdown: slightly cheaper object.union_n implementation
- eval: remove unused expr field on evalNot
- eval: rename fmtVarTerm -> fmtVar
- term: remove unused termSlice type
- builtins: cheaper Builtin.Ref()

Signed-off-by: Anders Eknert <anders.eknert@apple.com>
2026-06-04 13:08:57 +00:00
Anders Eknert eb8166fb1c perf: avoid allocations in object.get (#8729)
This change removes the 1-2 heap allocations previously made per call to
the `object.get` built-in function.

Also:
- Slightly tweak `builtins.<Type>Operand` functions to have them pass
the inlining threshold score of 80 — they would previously all score at
81!

Signed-off-by: Anders Eknert <anders.eknert@apple.com>
2026-06-04 14:51:39 +02:00
Charlie Egan c3a407c5d2 website: Add support page disclaimer and sort by date added (#8736)
Signed-off-by: Charlie Egan <charlie_egan@apple.com>
2026-06-04 10:00:16 +00:00
Stephan Renatus 323fb241e9 nightly: use regal@main
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-06-04 11:51:09 +02:00
Johan Fylling 2a41f710e1 oracle: Fix find-definition on expressions inside ast.Not nodes (#8731)
`ast.Node.Location` wasn't properly copied during `ResolveRefs` compiler
stage

Signed-off-by: Johan Fylling <johan.dev@fylling.se>
2026-06-03 17:09:51 +02:00
Charlie Egan 9e103847d0 docs: Update regal docs for 0.41.1 release (#8730)
https://github.com/open-policy-agent/regal/releases/tag/v0.41.1

Signed-off-by: Charlie Egan <charlie_egan@apple.com>
2026-06-03 12:38:12 +00:00
Charlie Egan 27619ae0dc docs: Update built-in index page titles (#8728)
This is for search engine result headings and on-site search titles.

Signed-off-by: Charlie Egan <charlie_egan@apple.com>
2026-06-03 13:28:34 +01:00
Johan Fylling 353033c65c ast: Apply location to inner ast.Not expressions (#8727)
Also fixing locations of and/or expressions.

---------

Signed-off-by: Johan Fylling <johan.dev@fylling.se>
2026-06-03 12:37:20 +02:00
Stephan Renatus 299760c6ab build: bump go 1.26.3 -> 1.26.4
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-06-03 11:59:01 +02:00
dependabot[bot] 44c765e2b7 build(deps): bump pg in /e2e/api/compile/prisma in the e2e-prisma group
Bumps the e2e-prisma group in /e2e/api/compile/prisma with 1 update: [pg](https://github.com/brianc/node-postgres/tree/HEAD/packages/pg).


Updates `pg` from 8.20.0 to 8.21.0
- [Changelog](https://github.com/brianc/node-postgres/blob/master/CHANGELOG.md)
- [Commits](https://github.com/brianc/node-postgres/commits/pg@8.21.0/packages/pg)

---
updated-dependencies:
- dependency-name: pg
  dependency-version: 8.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: e2e-prisma
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-03 11:51:54 +02:00
Charlie Egan bcc13280a4 website: Add .md alternate content types for llms (#8725)
This makes the site's content easier to consume from chatbots and coding
harnesses.

This reuses the logic from the copy page content button implemented
previously.

E.g.
https://deploy-preview-8725--openpolicyagent.netlify.app/docs/policy-reference/keywords/contains.md

Signed-off-by: Charlie Egan <charlie_egan@apple.com>
2026-06-02 16:03:07 +01:00
dependabot[bot] c5f72447e5 build(deps): bump the dependencies group across 2 directories with 2 updates
Bumps the dependencies group with 1 update in the / directory: [google.golang.org/grpc](https://github.com/grpc/grpc-go).
Bumps the dependencies group with 1 update in the /e2e directory: [github.com/rogpeppe/go-internal](https://github.com/rogpeppe/go-internal).


Updates `google.golang.org/grpc` from 1.81.0 to 1.81.1
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](https://github.com/grpc/grpc-go/compare/v1.81.0...v1.81.1)

Updates `github.com/rogpeppe/go-internal` from 1.14.1 to 1.15.0
- [Release notes](https://github.com/rogpeppe/go-internal/releases)
- [Commits](https://github.com/rogpeppe/go-internal/compare/v1.14.1...v1.15.0)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.81.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: github.com/rogpeppe/go-internal
  dependency-version: 1.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-02 12:25:38 +02:00
dependabot[bot] a8d339aa32 build(deps): bump the gha-dependencies group with 3 updates
Bumps the gha-dependencies group with 3 updates: [github/codeql-action](https://github.com/github/codeql-action), [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) and [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action).


Updates `github/codeql-action` from 4.35.3 to 4.36.0
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/e46ed2cbd01164d986452f91f178727624ae40d7...7211b7c8077ea37d8641b6271f6a365a22a5fbfa)

Updates `docker/setup-buildx-action` from 4.0.0 to 4.1.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](https://github.com/docker/setup-buildx-action/compare/4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd...d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5)

Updates `zizmorcore/zizmor-action` from 0.5.3 to 0.5.6
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)
- [Commits](https://github.com/zizmorcore/zizmor-action/compare/b1d7e1fb5de872772f31590499237e7cce841e8e...5f14fd08f7cf1cb1609c1e344975f152c7ee938d)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gha-dependencies
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gha-dependencies
- dependency-name: zizmorcore/zizmor-action
  dependency-version: 0.5.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gha-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-02 12:18:36 +02:00
Stephan Renatus d04a62b63d workflow: remove tests from docker (edge) image build
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-06-02 11:37:22 +02:00
Charlie Egan 8ee9808acc download/oci: Set Accept headers (#8720)
The ociTarget.Resolve and ociTarget.Fetch methods introduced in the
containerd migration were not setting Accept headers on manifest
requests. Several registries, including ghcr.io, require a manifest
media type in the Accept header and return 404 Not Found without it.

The previous containerd-based implementation set this header
automatically via the docker resolver. The new oras-based custom target
did not replicate that behaviour.

Signed-off-by: Charlie Egan <charlie_egan@apple.com>
2026-06-02 09:20:37 +00:00
Stephan Renatus d474d70750 workflows: bring back docker edge tags for post-merge
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-06-02 11:05:16 +02:00
Philip Conrad 6308609195 internal/edittree: Add recursive tree node recycling. (#8693)
This commit greatly extends the sync.Pool usage within the
EditTree data structure, and adds Dispose calls to the
appropriate call sites within the JSON Patch builtins.

This has a higher cost than the original "just unlink the
nodes" approach, but reduces GC and allocation pressure
when there's lots of churn and deletion operations.

Benchmarks indicate a 5-15% CPU time cost increase, in
exchange for a 15-18%+ reduction in memory usage and allocs.

Signed-off-by: Philip Conrad <philip@chariot-chaser.net>
2026-06-01 15:42:59 -04:00
Charlie Egan 98944a4f44 docs/chore: Remove broken links (#8716)
Fixes https://github.com/open-policy-agent/opa/issues/8714

Signed-off-by: Charlie Egan <charlie_egan@apple.com>
2026-06-01 12:36:58 +00:00
Toby Aurelius f1612417a6 docs: clarify environment variable substitution behaviour (#8713)
Updates documentation to clarify behaviour of unset environment variables
following #7831 and #7786.


Signed-off-by: Toby Aurelius <22025115+taurelius@users.noreply.github.com>
2026-05-29 19:57:44 +02:00
Johan Fylling 48e0e96482 Prepare v1.18.0 development (#8711)
Signed-off-by: Johan Fylling <johan.dev@fylling.se>
2026-05-28 19:08:42 +02:00
Johan Fylling 64a3625d33 Release v1.17.0 (#8710)
Signed-off-by: Johan Fylling <johan.dev@fylling.se>
v1.17.0
2026-05-28 16:48:35 +02:00
Stephan Renatus 68c9de5da0 benchmarks: tweak per-PR benchmark regression check based on pr-check
We can't run them all. It's too much.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-05-28 12:09:19 +02:00
Stephan Renatus 7fe3066154 server: remove dead code (s.partials) (#8708)
Follow-up to #6300

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-05-28 10:59:54 +02:00
Anders Eknert 37830be801 ast,storage/inmem: Add inmem.NewFromASTObject and add missing string case to ast.InternedValue (#8707)
- Add `inmem.NewFromASTObject` to simplify creating store from AST value
- Add missing string case to `ast.InternedValue`, and some internal
improvements

Signed-off-by: Anders Eknert <anders.eknert@apple.com>
2026-05-28 10:57:37 +02:00
Stephan Renatus 1661f22ba3 ast: add some schema $ref tests
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-05-28 09:49:16 +02:00
Stephan Renatus 3e22f562f1 benchmarks: only run for go changes
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-05-28 09:47:50 +02:00
Stephan Renatus 13aaeabce2 benchmarks: move env vars, remove zizmor-ignore comment
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-05-28 09:47:50 +02:00
Stephan Renatus 93e170868a benchmarks: fix PR message, skip tests
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-05-28 09:47:10 +02:00
Stephan Renatus 4ce3991901 benchmarks: use go tool machinery, add benchstat
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-05-28 09:18:33 +02:00
Stephan Renatus 41df8df4a2 benchmarks: use benchlab for per-PR feedback
Hopefully makes stuff a little more robust.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-05-28 08:53:39 +02:00
Dionna Amalie Glaze 4e1f9e8100 jsonschema: allow $ref in allOf schemas. (#8698)
Resolve any RefSchema within an AllOf before attempting to merge
schemas. Disregards empty anyOfs as top type.

Fixes #6523.

Signed-off-by: Dionna Glaze <d_glaze@apple.com>
2026-05-27 08:39:51 +02:00
Anders Eknert e07e1ec860 rego: Allow per-eval GenerateJSON function (#8690)
The Rego API's `GenerateJSON` function allows clients to provide custom
logic for transforming an original AST result into whatever format they
may need. Previously this could only be set on the Rego object directly,
meaning that a single prepared query would have to use the same function
for all evaluations. This change adds the option to additionally set an
`EvalGenerateJSON function scoped to individual evaluations, making it
easier to reuse a single prepared query even when the shape of the
result is determined dynamically, by input data, in-policy routing, etc.

Signed-off-by: Anders Eknert <anders.eknert@apple.com>
2026-05-26 16:25:14 +02:00
Anders Eknert 12cad2a326 Remove automaxprocs dependency (#8696)
This is handled natively by Go since 1.25, so this dependency should no
longer be needed. See references below for more information. Only
notable difference seems to be that Go sets a minimum value of 2 while
the automaxprocs lib has a minimum value of 1. Go seems to account for
much more though, so I don't think that difference alone warrants the
inclusion of this dependency. Users who really want GOMAXPROCS=1 can
always set that themselves.

References:
- https://github.com/golang/go/issues/73193
- https://github.com/uber-go/automaxprocs/issues/98

Signed-off-by: Anders Eknert <anders.eknert@apple.com>
2026-05-26 12:37:43 +02:00
Johan Fylling c5cc2d6ca7 ast: and/or compilation (#8695)
Fixes: #8678

Signed-off-by: Johan Fylling <johan.dev@fylling.se>
2026-05-26 11:19:03 +02:00
dependabot[bot] 763aaaab5f build(deps): bump qs from 6.14.1 to 6.14.2 in /docs (#8694)
Bumps [qs](https://github.com/ljharb/qs) from 6.14.1 to 6.14.2.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/ljharb/qs/blob/main/CHANGELOG.md">qs's
changelog</a>.</em></p>
<blockquote>
<h2><strong>6.14.2</strong></h2>
<ul>
<li>[Fix] <code>parse</code>: mark overflow objects for indexed notation
exceeding <code>arrayLimit</code> (<a
href="https://redirect.github.com/ljharb/qs/issues/546">#546</a>)</li>
<li>[Fix] <code>arrayLimit</code> means max count, not max index, in
<code>combine</code>/<code>merge</code>/<code>parseArrayValue</code></li>
<li>[Fix] <code>parse</code>: throw on <code>arrayLimit</code> exceeded
with indexed notation when <code>throwOnLimitExceeded</code> is true (<a
href="https://redirect.github.com/ljharb/qs/issues/529">#529</a>)</li>
<li>[Fix] <code>parse</code>: enforce <code>arrayLimit</code> on
<code>comma</code>-parsed values</li>
<li>[Fix] <code>parse</code>: fix error message to reflect arrayLimit as
max index; remove extraneous comments (<a
href="https://redirect.github.com/ljharb/qs/issues/545">#545</a>)</li>
<li>[Robustness] avoid <code>.push</code>, use <code>void</code></li>
<li>[readme] document that <code>addQueryPrefix</code> does not add
<code>?</code> to empty output (<a
href="https://redirect.github.com/ljharb/qs/issues/418">#418</a>)</li>
<li>[readme] clarify <code>parseArrays</code> and
<code>arrayLimit</code> documentation (<a
href="https://redirect.github.com/ljharb/qs/issues/543">#543</a>)</li>
<li>[readme] replace runkit CI badge with shields.io check-runs
badge</li>
<li>[meta] fix changelog typo (<code>arrayLength</code> →
<code>arrayLimit</code>)</li>
<li>[actions] fix rebase workflow permissions</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/ljharb/qs/commit/bdcf0c7f82387c18ac8fabfccd2f440645cef47b"><code>bdcf0c7</code></a>
v6.14.2</li>
<li><a
href="https://github.com/ljharb/qs/commit/294db90c812ddbe7d7a35d5687c505fd21a2d6a2"><code>294db90</code></a>
[readme] document that <code>addQueryPrefix</code> does not add
<code>?</code> to empty output</li>
<li><a
href="https://github.com/ljharb/qs/commit/5c308e5516c270a78caa6f278465914090f91ec6"><code>5c308e5</code></a>
[readme] clarify <code>parseArrays</code> and <code>arrayLimit</code>
documentation</li>
<li><a
href="https://github.com/ljharb/qs/commit/6addf8cf738d529c54d91f6f3ffb6c1be91bbfdc"><code>6addf8c</code></a>
[Fix] <code>parse</code>: mark overflow objects for indexed notation
exceeding <code>arrayLimit</code></li>
<li><a
href="https://github.com/ljharb/qs/commit/cfc108f662326d6ab540f3545ef0b832baf83cdf"><code>cfc108f</code></a>
[Fix] <code>arrayLimit</code> means max count, not max index, in
<code>combine</code>/<code>merge</code>/`pars...</li>
<li><a
href="https://github.com/ljharb/qs/commit/febb64442a80e49200211fa38d3c96b58024ac77"><code>febb644</code></a>
[Fix] <code>parse</code>: throw on <code>arrayLimit</code> exceeded with
indexed notation when `thr...</li>
<li><a
href="https://github.com/ljharb/qs/commit/f6a7abff1f13d644db9b05fe4f2c98ada6bf8482"><code>f6a7abf</code></a>
[Fix] <code>parse</code>: enforce <code>arrayLimit</code> on
<code>comma</code>-parsed values</li>
<li><a
href="https://github.com/ljharb/qs/commit/fbc5206c25b4d1851cea683f02c10756c521d15a"><code>fbc5206</code></a>
[Fix] <code>parse</code>: fix error message to reflect arrayLimit as max
index; remove e...</li>
<li><a
href="https://github.com/ljharb/qs/commit/1b9a8b4e78c6aff4c22fa559107227f02fd0216a"><code>1b9a8b4</code></a>
[actions] fix rebase workflow permissions</li>
<li><a
href="https://github.com/ljharb/qs/commit/2a35775614e0fb46ac8a3060201a32a7c23a7fda"><code>2a35775</code></a>
[meta] fix changelog typo (<code>arrayLength</code> →
<code>arrayLimit</code>)</li>
<li>Additional commits viewable in <a
href="https://github.com/ljharb/qs/compare/v6.14.1...v6.14.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=qs&package-manager=npm_and_yarn&previous-version=6.14.1&new-version=6.14.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/open-policy-agent/opa/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-25 13:58:44 +02:00
Anders Eknert 7e9ab4ac8c Remove direct x/net dependency (#8697)
We don't need that for h2c anymore, and it was only used in a e2e test.
Still an indirect dependency, but oh well.

Signed-off-by: Anders Eknert <anders.eknert@apple.com>
2026-05-25 09:56:20 +02:00
Johan Fylling bd872b8fb4 ast: and/or parsing (#8687)
resolves: #8677

Signed-off-by: Johan Fylling <johan.dev@fylling.se>
2026-05-22 18:04:34 +02:00
Stephan Renatus 7d918f5718 workflows: fix cache-dependency-path warnings in nightly run
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-05-22 16:40:52 +02:00
Anders Eknert d425213923 perf: avoid allocating in binary and/or when possible (#8689)
Avoid allocation in `&` and `|` calls when either of the operands is an
empty set.

Signed-off-by: Anders Eknert <anders.eknert@apple.com>
2026-05-21 23:00:34 +02:00
Charlie Egan f9155842bc docs: Add explicit address binding to examples (#8688)
Add --addr=0.0.0.0:8181 flag to OPA server commands in Docker Compose
examples. This is needed for OPA >1.0.

Addresses Feedback:
<img width="1358" height="616" alt="Screenshot"
src="https://github.com/user-attachments/assets/8b116c1f-b362-427c-8eff-7888dbbe5c14"
/>

Signed-off-by: Charlie Egan <charlie_egan@apple.com>
2026-05-21 18:33:42 +01:00
Sebastian Spaink 5e04b0f93b Enable pattern validation in json.verify_schema and json.match_schema (#8686)
resolve: https://github.com/open-policy-agent/opa/issues/6089

As a side effect of #4429 `json.match_schema` and `json.verify_schema`
have been silently ignoring the "pattern" keyword.

Updated the internal/gojsonschema project to have pattern validation be
optional to keep it disabled for type checking but enabled for the
builtins. Patterns that RE2 can't compile will fail.

Signed-off-by: Sebastian Spaink <sebastianspaink@gmail.com>
2026-05-21 18:36:14 +02:00
Sebastian Spaink 9d2c957c8b Generate a JSON Schema for the bundle manifest (#8684)
resolve: https://github.com/open-policy-agent/opa/issues/8661

Similar to the [plan.schema.json
](https://github.com/open-policy-agent/opa/pull/8676)this manifest will
be published on the website under
https://openpolicyagent.org/schemas/bundle/v1/manifest.schema.json

---------

Signed-off-by: Sebastian Spaink <sebastianspaink@gmail.com>
Co-authored-by: Stephan Renatus <s_renatus@apple.com>
2026-05-21 10:39:17 -05:00
Stephan Renatus 53d981c70f server/types: generalize request/response metadata
This is less brittle, and less duplication, than before. We're reading
out the known fields from struct tags ONCE on init() for each of the
types we want to use like this.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-05-21 08:24:59 +02:00
Stephan Renatus 840c2b91af server: wire in response/request metadata for compile handler
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-05-21 08:24:59 +02:00
ORYGN eca948b161 docs(ecosystem): add OPA MCP (#8618)
Adds **OPA MCP** to the ecosystem listing.

- **Repo:** https://github.com/OrygnsCode/opa-mcp-server
- **npm:** https://www.npmjs.com/package/@orygn/opa-mcp
- **Docker Hub:** https://hub.docker.com/r/orygn/opa-mcp

OPA MCP is a Model Context Protocol server that gives MCP-compatible
clients (Claude Desktop, Cursor, VS Code, Zed, Windsurf, etc.) a
structured interface to Rego. It wraps the OPA CLI, the OPA REST API,
and the Regal linter behind 32 schema-validated tools, plus higher-level
helpers (`rego_explain_decision`, `rego_describe_policy`,
`rego_generate_test_skeleton`, `rego_suggest_fix`) that compose the
primitives into agent-friendly workflows.

## Files

- `docs/src/data/ecosystem/entries/opa-mcp.md` — entry following the
format of `vscode-opa.md` and `regal.md`.
- `docs/static/img/ecosystem-entry-logos/opa-mcp.png` — 256×256 logo,
~55 KB.

## Labels

- `category: tooling`
- `layer: editor`

## docs_features

`learning-rego`, `policy-testing`, `debugging-rego`, `editors` — all
chosen from the existing taxonomy used by other entries.

Signed-off-by: OrygnsCode <38231263+OrygnsCode@users.noreply.github.com>
2026-05-20 08:54:01 -05:00
Sebastian Spaink 796db6b8d2 Generate a JSON Schema for the IR plan (#8676)
resolve: https://github.com/open-policy-agent/opa/issues/8662 

Generate a schema for the IR plan and publish it to the website at schemas/ir/v1/plan.schema.json 

resolve: https://github.com/open-policy-agent/opa/issues/6266

Fix the upper case Index in MakeNumberRefStmt by supporting both, lower and upper case.

---------

Signed-off-by: Sebastian Spaink <sebastianspaink@gmail.com>
2026-05-19 15:16:25 -05:00
Toby Aurelius f55bfe882d docs: correct ocp ssh key docs
Update description of OCP `ssh_key` config item to clarify it is the key contents, not a path.

Signed-off-by: Toby Aurelius <22025115+taurelius@users.noreply.github.com>
2026-05-19 13:45:31 +02:00
dependabot[bot] 0911080ea6 build(deps): bump the dependencies group across 2 directories with 12 updates (#8674)
Bumps the dependencies group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/fsnotify/fsnotify](https://github.com/fsnotify/fsnotify) |
`1.9.0` | `1.10.1` |
|
[github.com/huandu/go-sqlbuilder](https://github.com/huandu/go-sqlbuilder)
| `1.40.2` | `1.41.0` |
| [github.com/lestrrat-go/jwx/v3](https://github.com/lestrrat-go/jwx) |
`3.1.0` | `3.1.1` |
|
[github.com/olekukonko/tablewriter](https://github.com/olekukonko/tablewriter)
| `1.1.0` | `1.1.4` |
| [github.com/vektah/gqlparser/v2](https://github.com/vektah/gqlparser)
| `2.5.32` | `2.5.33` |
| [golang.org/x/net](https://github.com/golang/net) | `0.53.0` |
`0.54.0` |
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.80.0` |
`1.81.0` |
| gopkg.in/ini.v1 | `1.67.1` | `1.67.2` |

Bumps the dependencies group with 11 updates in the /e2e directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/fsnotify/fsnotify](https://github.com/fsnotify/fsnotify) |
`1.9.0` | `1.10.1` |
|
[github.com/huandu/go-sqlbuilder](https://github.com/huandu/go-sqlbuilder)
| `1.40.2` | `1.41.0` |
| [github.com/lestrrat-go/jwx/v3](https://github.com/lestrrat-go/jwx) |
`3.1.0` | `3.1.1` |
|
[github.com/olekukonko/tablewriter](https://github.com/olekukonko/tablewriter)
| `1.1.0` | `1.1.4` |
| [github.com/vektah/gqlparser/v2](https://github.com/vektah/gqlparser)
| `2.5.32` | `2.5.33` |
| [golang.org/x/net](https://github.com/golang/net) | `0.53.0` |
`0.54.0` |
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.80.0` |
`1.81.0` |
| gopkg.in/ini.v1 | `1.67.1` | `1.67.2` |
|
[github.com/go-sql-driver/mysql](https://github.com/go-sql-driver/mysql)
| `1.9.3` | `1.10.0` |
|
[github.com/microsoft/go-mssqldb](https://github.com/microsoft/go-mssqldb)
| `1.9.8` | `1.10.0` |
| [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) | `1.49.1` |
`1.50.1` |


Updates `github.com/fsnotify/fsnotify` from 1.9.0 to 1.10.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/fsnotify/fsnotify/releases">github.com/fsnotify/fsnotify's
releases</a>.</em></p>
<blockquote>
<h2>v1.10.1</h2>
<h3>Changes and fixes</h3>
<ul>
<li>
<p>inotify: don't remove sibling watches sharing a path prefix (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>)</p>
</li>
<li>
<p>inotify, windows: don't rename sibling watches sharing a path prefix
(<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>)</p>
</li>
</ul>
<p><a
href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/754">fsnotify/fsnotify#754</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/755">fsnotify/fsnotify#755</a></p>
<h2>v1.10.0</h2>
<p>This version of fsnotify needs Go 1.23.</p>
<h3>Changes and fixes</h3>
<ul>
<li>
<p>inotify: improve initialization error message (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>)</p>
</li>
<li>
<p>inotify: send Rename event if recursive watch is renamed (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>)</p>
</li>
<li>
<p>inotify: avoid copying event buffers when reading names (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>)</p>
</li>
<li>
<p>kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a
bad entry no longer aborts Watcher.Add for the whole directory (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>)</p>
</li>
<li>
<p>kqueue: drop watches directly in Close() to fix a file descriptor
leak when recycling watchers (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>)</p>
</li>
<li>
<p>windows: fix nil pointer dereference in remWatch (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>)</p>
</li>
<li>
<p>windows: lock watch field updates against concurrent WatchList to fix
a race introduced in v1.9.0 (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>,
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>)</p>
</li>
</ul>
<p><a
href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/696">fsnotify/fsnotify#696</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/709">fsnotify/fsnotify#709</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/731">fsnotify/fsnotify#731</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/736">fsnotify/fsnotify#736</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/740">fsnotify/fsnotify#740</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/741">fsnotify/fsnotify#741</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/748">fsnotify/fsnotify#748</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/749">fsnotify/fsnotify#749</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/fsnotify/fsnotify/blob/main/CHANGELOG.md">github.com/fsnotify/fsnotify's
changelog</a>.</em></p>
<blockquote>
<h2>1.10.1 2026-05-04</h2>
<h3>Changes and fixes</h3>
<ul>
<li>
<p>inotify: don't remove sibling watches sharing a path prefix (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>)</p>
</li>
<li>
<p>inotify, windows: don't rename sibling watches sharing a path prefix
(<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>)</p>
</li>
</ul>
<p><a
href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/754">fsnotify/fsnotify#754</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/755">fsnotify/fsnotify#755</a></p>
<h2>1.10.0 2026-04-30</h2>
<p>This version of fsnotify needs Go 1.23.</p>
<h3>Changes and fixes</h3>
<ul>
<li>
<p>inotify: improve initialization error message (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>)</p>
</li>
<li>
<p>inotify: send Rename event if recursive watch is renamed (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>)</p>
</li>
<li>
<p>inotify: avoid copying event buffers when reading names (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>)</p>
</li>
<li>
<p>kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a
bad entry no longer aborts Watcher.Add for the whole directory (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>)</p>
</li>
<li>
<p>kqueue: drop watches directly in Close() to fix a file descriptor
leak
when recycling watchers (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>)</p>
</li>
<li>
<p>windows: fix nil pointer dereference in remWatch (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>)</p>
</li>
<li>
<p>windows: lock watch field updates against concurrent WatchList to fix
a race introduced in v1.9.0 (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>,
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>)</p>
</li>
</ul>
<p><a
href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/696">fsnotify/fsnotify#696</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/709">fsnotify/fsnotify#709</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/731">fsnotify/fsnotify#731</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/736">fsnotify/fsnotify#736</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/740">fsnotify/fsnotify#740</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/741">fsnotify/fsnotify#741</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/748">fsnotify/fsnotify#748</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/749">fsnotify/fsnotify#749</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/76b01a6e8f502187fecedea8b025e79e5a86085c"><code>76b01a6</code></a>
Release 1.10.1</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/fec150b807510e54e5b25def4b6e5fb001b4898c"><code>fec150b</code></a>
Update changelog</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/162b4216ab8f92ecd26425530bee198972c9b3cb"><code>162b421</code></a>
inotify, windows: don't rename sibling watches sharing a path prefix (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>)</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/224257f23b2f3a96509b316c5cead71dd4a9099a"><code>224257f</code></a>
inotify: don't remove sibling watches sharing a path prefix (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>)</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/e0c956c0ccaf51562fee30ef5c055c74e6ae2104"><code>e0c956c</code></a>
windows: document directory Write events and stabilize tests (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/745">#745</a>)</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/8d01d7b9cbe0199e4a1e60fbd965fb05dbb42123"><code>8d01d7b</code></a>
Release 1.10.0</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/602284e4a8cadd488d7a5fa07c48462dfac25108"><code>602284e</code></a>
Update changelog</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/7f03e59f9659552d8a084e03024cb9b983748ed7"><code>7f03e59</code></a>
kqueue: skip ENOENT entries in watchDirectoryFiles (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>)</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/dab9dde2fc9ba4d0c1076318f81cabcc8fdb2ec9"><code>dab9dde</code></a>
windows: lock watch field updates against concurrent WatchList (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>)
(<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>)</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/eadf267ce152b5e62d48cc2c13bb08bd4062b6c7"><code>eadf267</code></a>
kqueue: drop watches directly in Close() instead of going through
remove() (#...</li>
<li>Additional commits viewable in <a
href="https://github.com/fsnotify/fsnotify/compare/v1.9.0...v1.10.1">compare
view</a></li>
</ul>
</details>
<br />

Updates `github.com/huandu/go-sqlbuilder` from 1.40.2 to 1.41.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/huandu/go-sqlbuilder/releases">github.com/huandu/go-sqlbuilder's
releases</a>.</em></p>
<blockquote>
<h2>v1.41.0</h2>
<ul>
<li><code>[NEW]</code> Add an option <code>NoExpand</code> to change
default field &quot;expand&quot; behavior for backward compatibility.
See <a
href="https://redirect.github.com/huandu/go-sqlbuilder/issues/237">#237</a>
for details.</li>
</ul>
<p>NOTE: Starting from v1.40.0, the <code>Struct</code> utility type
defaults to expanding non-primitive struct fields. This change caused
unexpected behavior for some users. To address this without reverting
the features introduced in v1.40.0, we have introduced a <code>NoExpand
</code>configuration. When set to true, all fields will default to no
expansion (preserving legacy behavior). You can still opt-in to
expansion for specific fields by using the
<code>fieldopt:&quot;expand&quot;</code> tag.</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/huandu/go-sqlbuilder/compare/v1.40.0...v1.41.0">https://github.com/huandu/go-sqlbuilder/compare/v1.40.0...v1.41.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/huandu/go-sqlbuilder/commit/44837218602c8f96eac9f27411d5b93a20dc979d"><code>4483721</code></a>
fix <a
href="https://redirect.github.com/huandu/go-sqlbuilder/issues/237">#237</a>:
add option <code>NoExpand</code> to control default field
&quot;expand&quot; behavior</li>
<li>See full diff in <a
href="https://github.com/huandu/go-sqlbuilder/compare/v1.40.2...v1.41.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `github.com/lestrrat-go/jwx/v3` from 3.1.0 to 3.1.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lestrrat-go/jwx/releases">github.com/lestrrat-go/jwx/v3's
releases</a>.</em></p>
<blockquote>
<h2>v3.1.1</h2>
<p>For more detailed release notes, see <a
href="https://github.com/lestrrat-go/jwx/blob/v3.1.1/Changes">Changes</a>.</p>
<h2>What's Changed</h2>
<ul>
<li>build(deps): bump pozil/auto-assign-issue from 2.2.0 to 2.2.1 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2045">lestrrat-go/jwx#2045</a></li>
<li>guard ecdsa coordinates against oversized big.Int by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2050">lestrrat-go/jwx#2050</a></li>
<li>reject jwe with conflicting alg in protected vs per-recipient by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2052">lestrrat-go/jwx#2052</a></li>
<li>fix AddressClaim.MarshalJSON for non-printable bytes by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2056">lestrrat-go/jwx#2056</a></li>
<li>jwt: only call ParseForm when WithFormKey is supplied by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2058">lestrrat-go/jwx#2058</a></li>
<li>jws: jkuProvider rejects fetched keys marked use=enc by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2060">lestrrat-go/jwx#2060</a></li>
<li>jwa: unify SignatureAlgorithm/KeyEncryption/ContentEncryption into
one registry by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2066">lestrrat-go/jwx#2066</a></li>
<li>build(deps): bump pozil/auto-assign-issue from
f245a9119ba5cc2fed4aa7b8268d576d40acddf0 to
7bf9d82c77d45976224660b873fc83e60576c5aa by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2065">lestrrat-go/jwx#2065</a></li>
<li>cmd/jwx: warn on private-key-to-tty + reject keysize&lt;=0 for oct
by <a href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in
<a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2071">lestrrat-go/jwx#2071</a></li>
<li>jws: refuse &quot;b64&quot; header in VerifyCompactFast by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2081">lestrrat-go/jwx#2081</a></li>
<li>jws: VerifyCompactFast refusals match jws.VerifyError() class by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2083">lestrrat-go/jwx#2083</a></li>
<li>jws: name loose keySet options in fan-out verify error by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2085">lestrrat-go/jwx#2085</a></li>
<li>jws: honor RFC 7797 b64=false in Message.MarshalJSON by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2087">lestrrat-go/jwx#2087</a></li>
<li>jws: reject literal-JSON &quot;protected&quot; in general-form JWS
by <a href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in
<a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2089">lestrrat-go/jwx#2089</a></li>
<li>jwt: ParseRequest: don't skip form body on chunked transfer by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2091">lestrrat-go/jwx#2091</a></li>
<li>jwt: pedantic mode enforces cty=JWT nested-envelope shape by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2094">lestrrat-go/jwx#2094</a></li>
<li>jwt: defensively reject missing claims in MaxDeltaIs / MinDeltaIs by
<a href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2099">lestrrat-go/jwx#2099</a></li>
<li>jwt: ParseInsecure: parse loop-local payload, not original input by
<a href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2097">lestrrat-go/jwx#2097</a></li>
<li>jws: Verify rejects b64=false without &quot;b64&quot; listed in
&quot;crit&quot; by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2102">lestrrat-go/jwx#2102</a></li>
<li>jws: Sign auto-declares &quot;b64&quot; in &quot;crit&quot; when
emitting b64=false by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2104">lestrrat-go/jwx#2104</a></li>
<li>jws: declare &quot;b64&quot; as typed bool header field by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2106">lestrrat-go/jwx#2106</a></li>
<li>jws: reject general-form JWS with top-level &quot;header&quot;
sibling of &quot;signatures&quot; by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2108">lestrrat-go/jwx#2108</a></li>
<li>jws: typed sentinel for AlgorithmsForKey unclassifiable-key failures
by <a href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in
<a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2110">lestrrat-go/jwx#2110</a></li>
<li>jws: VerifyMessage observes ctx cancellation between loop iterations
by <a href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in
<a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2112">lestrrat-go/jwx#2112</a></li>
<li>jws: cleanup follow-ups from recent review (low-severity batch) by
<a href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2114">lestrrat-go/jwx#2114</a></li>
<li>jwe: DecryptMessage observes ctx cancellation between loop
iterations by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2117">lestrrat-go/jwx#2117</a></li>
<li>jwe: parse and bound-check PBES2 p2c in int64 space; name the
violated bound by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2119">lestrrat-go/jwx#2119</a></li>
<li>jwe: WithKey validates alg-vs-key shape at option-time by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2121">lestrrat-go/jwx#2121</a></li>
<li>jwe: compression cap error names &quot;decompressed&quot; payload,
the option, and the size by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2123">lestrrat-go/jwx#2123</a></li>
<li>jwe: bound joined-error count and drop redundant outer Decrypt
prefix by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2125">lestrrat-go/jwx#2125</a></li>
<li>jwe: keySetProvider surfaces per-key errors via errors.Join by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2127">lestrrat-go/jwx#2127</a></li>
<li>jwe: add WithDisabledKeyAlgorithms global policy hook by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2129">lestrrat-go/jwx#2129</a></li>
<li>jwe: document WithMaxDecompressBufferSize behavior at non-positive
values by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2131">lestrrat-go/jwx#2131</a></li>
<li>jwk: stop duplicating JWK fields at JWKS top level on parse by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2133">lestrrat-go/jwx#2133</a></li>
<li>jwk: wrap ParseKey errors with ParseError sentinel by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2135">lestrrat-go/jwx#2135</a></li>
<li>jwk: stream the keys array with cap-before-allocate by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2137">lestrrat-go/jwx#2137</a></li>
<li>jwk: treat nil key from custom KeyParser as continue, not success by
<a href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2140">lestrrat-go/jwx#2140</a></li>
<li>jwk: fix phantom ContinueParseError refs and unmarshaler typo in
docs by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2142">lestrrat-go/jwx#2142</a></li>
<li>Changes: draft v3.1.1 release notes by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2155">lestrrat-go/jwx#2155</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/lestrrat-go/jwx/compare/v3.1.0...v3.1.1">https://github.com/lestrrat-go/jwx/compare/v3.1.0...v3.1.1</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/lestrrat-go/jwx/blob/v3.1.1/Changes">github.com/lestrrat-go/jwx/v3's
changelog</a>.</em></p>
<blockquote>
<p>v3.1.1 7 May 2026</p>
<ul>
<li>
<p>[jws] Coordinated RFC 7797 <code>b64=false</code> handling pass:
<code>jws.Verify</code>
rejects payloads with <code>b64=false</code> unless <code>b64</code> is
also listed in
<code>crit</code>; <code>jws.Sign</code> auto-declares <code>b64</code>
in <code>crit</code> when emitting
<code>b64=false</code>; <code>Message.MarshalJSON</code> honors
<code>b64=false</code> instead of
silently re-encoding; <code>jws.VerifyCompactFast</code> refuses any
compact
JWS carrying <code>b64</code> (the fast path doesn't process extension
headers); and <code>b64</code> is now declared as a typed boolean header
field rather than handled ad-hoc.
(<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2081">#2081</a>,
<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2087">#2087</a>,
<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2102">#2102</a>,
<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2104">#2104</a>,
<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2106">#2106</a>)</p>
</li>
<li>
<p>[jws] Reject malformed general-form JSON-serialized JWS: inputs
with a top-level <code>header</code> member as a sibling of
<code>signatures</code> are
rejected (the spec only permits <code>header</code> inside per-signature
objects), as are inputs whose <code>protected</code> member is a literal
JSON object instead of a base64url-encoded string.
(<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2089">#2089</a>,
<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2108">#2108</a>)</p>
</li>
<li>
<p>[jws] <code>jws.AlgorithmsForKey</code> failures from unclassifiable
keys
are now wrapped in a typed sentinel so callers can branch on
&quot;couldn't categorize this key&quot; without string matching the
error
message. (<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2110">#2110</a>)</p>
</li>
<li>
<p>[jws] Verify error-shape consistency: <code>VerifyCompactFast</code>
refusals now match the <code>jws.VerifyError()</code> taxonomy used by
the
slow path, fan-out verify errors name the loose <code>WithKeySet</code>
options that were tried, multi-signature <code>b64</code> mismatches
name
the offending signature index and conflicting value, and the
compact <code>b64=false</code>+payload-contains-<code>.</code> error
references RFC
7797 §5.2 and points at <code>WithDetachedPayload</code>.
(<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2083">#2083</a>,
<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2085">#2085</a>,
<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2114">#2114</a>)</p>
</li>
<li>
<p>[jws] Keys fetched via the <code>jku</code> header are no longer
accepted
for signature verification when the JWK declares <code>use=enc</code>.
(<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2060">#2060</a>)</p>
</li>
<li>
<p>[jws][jwe] <code>jws.VerifyMessage</code> and
<code>jwe.DecryptMessage</code> observe
context cancellation between loop iterations rather than only at
boundaries. Long fan-out verify/decrypt loops now respond to a
cancelled context promptly. (<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2112">#2112</a>,
<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2117">#2117</a>)</p>
</li>
<li>
<p>[jwe] Reject PBES2 messages whose <code>p2c</code> (iteration count)
does
not parse cleanly into int64 or violates the configured bound.
The error now names the violated bound (min vs max) instead of
the generic &quot;out of range&quot;. (<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2119">#2119</a>)</p>
</li>
<li>
<p>[jwe] <code>jwe.WithKey()</code> validates the alg-vs-key shape at
option
construction time rather than during encryption, so misuse
surfaces at the call site instead of inside the encrypt loop.
(<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2121">#2121</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lestrrat-go/jwx/commit/59b8b1b4239be0b470e5d939f16759793bc4a203"><code>59b8b1b</code></a>
release v3.1.1</li>
<li><a
href="https://github.com/lestrrat-go/jwx/commit/4d4ab015bec294bcee30d83506def12906e9da2c"><code>4d4ab01</code></a>
Changes: draft v3.1.1 release notes (<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2155">#2155</a>)</li>
<li><a
href="https://github.com/lestrrat-go/jwx/commit/ad739f565db19d9d8fe805eb5db0b05d5441f971"><code>ad739f5</code></a>
jwk: fix phantom ContinueParseError refs and unmarshaler typo in docs
(<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2142">#2142</a>)</li>
<li><a
href="https://github.com/lestrrat-go/jwx/commit/3227cf9c3d8ddc2d9728d58db03f905b61972f69"><code>3227cf9</code></a>
jwk: treat nil key from custom KeyParser as continue, not success (<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2140">#2140</a>)</li>
<li><a
href="https://github.com/lestrrat-go/jwx/commit/82c067ed57cbcbf0aba072518ed928c96306e951"><code>82c067e</code></a>
jwk: stream the keys array with cap-before-allocate (<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2137">#2137</a>)</li>
<li><a
href="https://github.com/lestrrat-go/jwx/commit/931a815632dab9bb0e49c81aa701dbf9e9a77f04"><code>931a815</code></a>
jwk: wrap ParseKey errors with ParseError sentinel (<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2135">#2135</a>)</li>
<li><a
href="https://github.com/lestrrat-go/jwx/commit/53f62259012b1d934a1dc8c07ebbd8f516f7b919"><code>53f6225</code></a>
jwk: stop duplicating JWK fields at JWKS top level on parse (<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2133">#2133</a>)</li>
<li><a
href="https://github.com/lestrrat-go/jwx/commit/8943519997fa2fe4e7e0423baf9cd8e9bb45ddd9"><code>8943519</code></a>
jwe: document WithMaxDecompressBufferSize behavior at non-positive
values (<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2">#2</a>...</li>
<li><a
href="https://github.com/lestrrat-go/jwx/commit/4797307a63aa0dd6847ee64cbdacbb878226b4f8"><code>4797307</code></a>
jwe: add WithDisabledKeyAlgorithms global policy hook (<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2129">#2129</a>)</li>
<li><a
href="https://github.com/lestrrat-go/jwx/commit/de41d0ef9e0b8f6a9f844f5313abbc510dda78fb"><code>de41d0e</code></a>
jwe: keySetProvider surfaces per-key errors via errors.Join (<a
href="https://redirect.github.com/lestrrat-go/jwx/issues/2127">#2127</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/lestrrat-go/jwx/compare/v3.1.0...v3.1.1">compare
view</a></li>
</ul>
</details>
<br />

Updates `github.com/olekukonko/tablewriter` from 1.1.0 to 1.1.4
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/olekukonko/tablewriter/commit/a0dea8a90a8a0c7610afb5588d2f15a57f4aa9a2"><code>a0dea8a</code></a>
no need to disable twice</li>
<li><a
href="https://github.com/olekukonko/tablewriter/commit/a4fb40afbe367fd0733ce7b45223034febf7b0b4"><code>a4fb40a</code></a>
Merge pull request <a
href="https://redirect.github.com/olekukonko/tablewriter/issues/314">#314</a>
from sducamp/fix/rendition-debug-leak</li>
<li><a
href="https://github.com/olekukonko/tablewriter/commit/6bc4cb4866ab2a10340bf0d11c41e676b546e253"><code>6bc4cb4</code></a>
fix: prevent debug output leak from renderer during Options()
reconfiguration</li>
<li><a
href="https://github.com/olekukonko/tablewriter/commit/54408fee90b7a66a94d9d71f789d42e03f45109b"><code>54408fe</code></a>
update ll to v0.1.6</li>
<li><a
href="https://github.com/olekukonko/tablewriter/commit/5ea5f3c761e556def568d7e07df774c55ae66071"><code>5ea5f3c</code></a>
add mote tab test ans update go mod</li>
<li><a
href="https://github.com/olekukonko/tablewriter/commit/1455dd8dd79719f142013f59e300fcdf0144f3fd"><code>1455dd8</code></a>
Merge pull request <a
href="https://redirect.github.com/olekukonko/tablewriter/issues/311">#311</a>
from olekukonko/tabber</li>
<li><a
href="https://github.com/olekukonko/tablewriter/commit/d7b0a55c1f9c6bd55eceaa22dfb0123bac23f281"><code>d7b0a55</code></a>
improve tab and make test more predictable</li>
<li><a
href="https://github.com/olekukonko/tablewriter/commit/62117a2ca655057ba2e61f2d18896f619fc48230"><code>62117a2</code></a>
add space default <a
href="https://redirect.github.com/olekukonko/tablewriter/issues/312">#312</a>
for colorized renderer</li>
<li><a
href="https://github.com/olekukonko/tablewriter/commit/4958831ad1de62ec94567bf5d42a8a9b2c50e74d"><code>4958831</code></a>
ll v0.1.5 update enables logging by default hence disable</li>
<li><a
href="https://github.com/olekukonko/tablewriter/commit/1c68e06c65b87d5416aada2737b6683fadd1b25b"><code>1c68e06</code></a>
use space for padding as default <a
href="https://redirect.github.com/olekukonko/tablewriter/issues/312">#312</a></li>
<li>Additional commits viewable in <a
href="https://github.com/olekukonko/tablewriter/compare/v1.1.0...v1.1.4">compare
view</a></li>
</ul>
</details>
<br />

Updates `github.com/vektah/gqlparser/v2` from 2.5.32 to 2.5.33
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vektah/gqlparser/releases">github.com/vektah/gqlparser/v2's
releases</a>.</em></p>
<blockquote>
<h2>v2.5.33</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: allow repeatable directives on GraphQL document by <a
href="https://github.com/fredzqm"><code>@​fredzqm</code></a> in <a
href="https://redirect.github.com/vektah/gqlparser/pull/418">vektah/gqlparser#418</a></li>
<li>feat: create a new ScalarLeafsRuleWithoutSuggestions validator rule
by <a
href="https://github.com/XuankangLin"><code>@​XuankangLin</code></a> in
<a
href="https://redirect.github.com/vektah/gqlparser/pull/413">vektah/gqlparser#413</a></li>
<li>refactor: format lines in scalar_leafs.go by <a
href="https://github.com/XuankangLin"><code>@​XuankangLin</code></a> in
<a
href="https://redirect.github.com/vektah/gqlparser/pull/423">vektah/gqlparser#423</a></li>
<li>Fix negative Position.Column for definitions with block string
descriptions (<a
href="https://redirect.github.com/vektah/gqlparser/issues/254">#254</a>)
by <a href="https://github.com/riwal42c"><code>@​riwal42c</code></a> in
<a
href="https://redirect.github.com/vektah/gqlparser/pull/422">vektah/gqlparser#422</a></li>
<li>Update spec to 2023 version by <a
href="https://github.com/StevenACoffman"><code>@​StevenACoffman</code></a>
in <a
href="https://redirect.github.com/vektah/gqlparser/pull/401">vektah/gqlparser#401</a></li>
<li>Bump picomatch from 2.3.1 to 2.3.2 in /validator/imported by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/vektah/gqlparser/pull/420">vektah/gqlparser#420</a></li>
<li>Bump <code>@​babel/preset-env</code> from 7.29.0 to 7.29.2 in
/validator/imported in the actions-deps group by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/vektah/gqlparser/pull/419">vektah/gqlparser#419</a></li>
<li>Bump brace-expansion from 1.1.12 to 1.1.13 in /validator/imported by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/vektah/gqlparser/pull/421">vektah/gqlparser#421</a></li>
<li>Bump prettier from 3.8.1 to 3.8.2 in /validator/imported in the
actions-deps group by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/vektah/gqlparser/pull/424">vektah/gqlparser#424</a></li>
<li>Bump prettier from 3.8.2 to 3.8.3 in /validator/imported in the
actions-deps group by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/vektah/gqlparser/pull/425">vektah/gqlparser#425</a></li>
<li>Bump minimatch from 3.0.4 to 3.1.5 in /validator/imported by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/vektah/gqlparser/pull/417">vektah/gqlparser#417</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/XuankangLin"><code>@​XuankangLin</code></a>
made their first contribution in <a
href="https://redirect.github.com/vektah/gqlparser/pull/413">vektah/gqlparser#413</a></li>
<li><a href="https://github.com/riwal42c"><code>@​riwal42c</code></a>
made their first contribution in <a
href="https://redirect.github.com/vektah/gqlparser/pull/422">vektah/gqlparser#422</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/vektah/gqlparser/compare/v2.5.32...v2.5.33">https://github.com/vektah/gqlparser/compare/v2.5.32...v2.5.33</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vektah/gqlparser/commit/41b7913b390ac4278ca7fc766afd586c1e6df819"><code>41b7913</code></a>
Bump minimatch from 3.0.4 to 3.1.5 in /validator/imported (<a
href="https://redirect.github.com/vektah/gqlparser/issues/417">#417</a>)</li>
<li><a
href="https://github.com/vektah/gqlparser/commit/3c33bbeb81dd06c1dc5d5e56c97c2ac74e3a5e71"><code>3c33bbe</code></a>
Bump prettier in /validator/imported in the actions-deps group (<a
href="https://redirect.github.com/vektah/gqlparser/issues/425">#425</a>)</li>
<li><a
href="https://github.com/vektah/gqlparser/commit/f63b51fcf337b673ac06b593262f7ed72d11de24"><code>f63b51f</code></a>
Update spec to 2023 version (<a
href="https://redirect.github.com/vektah/gqlparser/issues/401">#401</a>)</li>
<li><a
href="https://github.com/vektah/gqlparser/commit/1f1383cb52d49c63919a791309a2c80e16a83c6f"><code>1f1383c</code></a>
Bump prettier in /validator/imported in the actions-deps group (<a
href="https://redirect.github.com/vektah/gqlparser/issues/424">#424</a>)</li>
<li><a
href="https://github.com/vektah/gqlparser/commit/021901042dbe56648020832ee88973acd389ea64"><code>0219010</code></a>
Fix negative Position.Column for definitions with block string
descriptions (...</li>
<li><a
href="https://github.com/vektah/gqlparser/commit/16bf3c4da15f2de0a8648e66f956ef9da2129d8e"><code>16bf3c4</code></a>
refactor: format lines in scalar_leafs.go (<a
href="https://redirect.github.com/vektah/gqlparser/issues/423">#423</a>)</li>
<li><a
href="https://github.com/vektah/gqlparser/commit/be677085400ffa5fd6e0ac86d98d1cf94db05efe"><code>be67708</code></a>
Bump brace-expansion from 1.1.12 to 1.1.13 in /validator/imported (<a
href="https://redirect.github.com/vektah/gqlparser/issues/421">#421</a>)</li>
<li><a
href="https://github.com/vektah/gqlparser/commit/61efb18da16d7f45f8050ecb576d27b85e6861da"><code>61efb18</code></a>
feat: create a new ScalarLeafsRuleWithoutSuggestions validator rule (<a
href="https://redirect.github.com/vektah/gqlparser/issues/413">#413</a>)</li>
<li><a
href="https://github.com/vektah/gqlparser/commit/a9bb4644d5911effae909bab06029df7f11c402c"><code>a9bb464</code></a>
feat(validator): handle repeatable directives correctly (<a
href="https://redirect.github.com/vektah/gqlparser/issues/418">#418</a>)</li>
<li><a
href="https://github.com/vektah/gqlparser/commit/b239ec3bfe15a44330f9752bd7fb56cc41cf1c2b"><code>b239ec3</code></a>
Bump <code>@​babel/preset-env</code> in /validator/imported in the
actions-deps group (<a
href="https://redirect.github.com/vektah/gqlparser/issues/419">#419</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vektah/gqlparser/compare/v2.5.32...v2.5.33">compare
view</a></li>
</ul>
</details>
<br />

Updates `golang.org/x/net` from 0.53.0 to 0.54.0
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/golang/net/commit/b138e06246cb323f2f380c2b7f7dd91f581dd56b"><code>b138e06</code></a>
go.mod: update golang.org/x dependencies</li>
<li><a
href="https://github.com/golang/net/commit/689f70a42abd350f3a1aaa70b0d13eb9543d927a"><code>689f70a</code></a>
quic: fix wrong final size being used for RESET_STREAM frame</li>
<li><a
href="https://github.com/golang/net/commit/208f306b2f0fd008b388bee2c2644be279778e94"><code>208f306</code></a>
http3: increase handshake timeout</li>
<li><a
href="https://github.com/golang/net/commit/49810da71b9026da9e0d028a6ad8c7730c52d9c4"><code>49810da</code></a>
http2: enable net/http wrapping when go &gt;= 1.27</li>
<li><a
href="https://github.com/golang/net/commit/5e11a5ab891c117eda83b4304d60dd13286c1c76"><code>5e11a5a</code></a>
quic: fix data race in streamForFrame</li>
<li><a
href="https://github.com/golang/net/commit/8c63081cd380ea768db5651941614b73472160ff"><code>8c63081</code></a>
http2: use empty Transport rather than DefaultTransport in
http2wrap</li>
<li><a
href="https://github.com/golang/net/commit/fc7b466ca49cb204039630533ece4fc557eb35cd"><code>fc7b466</code></a>
http2: add http2wrap test</li>
<li><a
href="https://github.com/golang/net/commit/15c2cb1875fd727313dc4de909b3ee149422fbe2"><code>15c2cb1</code></a>
http2: avoid overflowing 32-bit int when http2wrap enabled</li>
<li><a
href="https://github.com/golang/net/commit/64651885c2f2d745d77af2d7af2edbf568c179af"><code>6465188</code></a>
http2: add wrapped Server</li>
<li><a
href="https://github.com/golang/net/commit/72f419a894cb0597dd5b6bcf119086bf2af41231"><code>72f419a</code></a>
http2: add wrapped ClientConn</li>
<li>Additional commits viewable in <a
href="https://github.com/golang/net/compare/v0.53.0...v0.54.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `golang.org/x/text` from 0.36.0 to 0.37.0
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/golang/text/commit/3ef517e623a4bfc08d6457f87d73afda7af7d8e1"><code>3ef517e</code></a>
go.mod: update golang.org/x dependencies</li>
<li>See full diff in <a
href="https://github.com/golang/text/compare/v0.36.0...v0.37.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `google.golang.org/grpc` from 1.80.0 to 1.81.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/grpc/grpc-go/releases">google.golang.org/grpc's
releases</a>.</em></p>
<blockquote>
<h2>Release 1.81.0</h2>
<h1>Behavior Changes</h1>
<ul>
<li>balancer/rls: Switch gauge metrics to asynchronous emission (once
per collection cycle) to reduce telemetry noise and align with other
gRPC language implementations. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/8808">#8808</a>)</li>
</ul>
<h1>Dependencies</h1>
<ul>
<li>Minimum supported Go version is now 1.25. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/8969">#8969</a>)</li>
</ul>
<h1>Bug Fixes</h1>
<ul>
<li>xds: Use the leaf cluster's security config for the TLS handshake
instead of the aggregate cluster's config. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/8956">#8956</a>)</li>
<li>transport: Send a <code>RST_STREAM</code> when receiving an
<code>END_STREAM</code> when the stream is not already half-closed. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/8832">#8832</a>)</li>
<li>xds: Fix ADS resource name validation to prevent a panic. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/8970">#8970</a>)</li>
</ul>
<h1>New Features</h1>
<ul>
<li>grpc/stats: Add support for custom labels in per-call metrics (<a
href="https://github.com/grpc/proposal/blob/master/A108-otel-custom-per-call-label.md">gRFC
A108</a>). (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9008">#9008</a>)</li>
<li>xds: Add support for Server Name Indication (SNI) and SAN validation
(<a
href="https://github.com/grpc/proposal/blob/master/A101-SNI-setting-and-SNI-SAN-validation.md">gRFC
A101</a>). Disabled by default. To enable, set
<code>GRPC_EXPERIMENTAL_XDS_SNI=true</code> environment variable. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9016">#9016</a>)</li>
<li>xds: Add support to control which fields get propagated from ORCA
backend metric reports to LRS load reports (<a
href="https://github.com/grpc/proposal/blob/master/A85-lrs-custom-metrics-changes.md">gRFC
A85</a>). Disabled by default. To enable, set
<code>GRPC_EXPERIMENTAL_XDS_ORCA_LRS_PROPAGATION=true</code>. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9005">#9005</a>)</li>
<li>xds: Add metrics to track xDS client connectivity and cached
resource state (<a
href="https://github.com/grpc/proposal/blob/master/A78-grpc-metrics-wrr-pf-xds.md">gRFC
A78</a>). (<a
href="https://redirect.github.com/grpc/grpc-go/issues/8807">#8807</a>)</li>
<li>stats/otel: Enhance <code>grpc.subchannel.disconnections</code>
metric by adding disconnection reason to the
<code>grpc.disconnect_error</code> label (<a
href="https://github.com/grpc/proposal/blob/master/A94-subchannel-otel-metrics.md">gRFC
A94</a>). This provides granular insights into why subchannels are
closing. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/8973">#8973</a>)</li>
<li>mem: Add <code>mem.Buffer.Slice()</code> API to slice the buffer
like a slice. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/8977">#8977</a>)
<ul>
<li>Special Thanks: <a
href="https://github.com/ash2k"><code>@​ash2k</code></a></li>
</ul>
</li>
</ul>
<h1>Performance Improvements</h1>
<ul>
<li>alts: Pool read buffers to lower memory utilization when sockets are
unreadable. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/8964">#8964</a>)</li>
<li>transport: Pool HTTP/2 framer read buffers to reduce idle memory
consumption. Currently limited to Linux for ALTS and non-encrypted
transports (TCP, Unix). To disable, set
<code>GRPC_GO_EXPERIMENTAL_HTTP_FRAMER_READ_BUFFER_POOLING=false</code>
and report any issues. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9032">#9032</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/grpc/grpc-go/commit/cb18228317ff523e63d931b4058b0329585b7dcd"><code>cb18228</code></a>
Change version to 1.81.0 (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9062">#9062</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/96748f973e20bbfcafa19a8bdffc85ad5da138d1"><code>96748f9</code></a>
Cherry-pick <a
href="https://redirect.github.com/grpc/grpc-go/issues/9105">#9105</a> to
1.81.x (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9106">#9106</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/91832222f0144f76527b630ca55cfea6e1aa015a"><code>9183222</code></a>
Cherry pick <a
href="https://redirect.github.com/grpc/grpc-go/issues/9055">#9055</a>,
<a href="https://redirect.github.com/grpc/grpc-go/issues/9032">#9032</a>
to v1.81.x (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9095">#9095</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/5cba6da4211f3b130238c792937f5921741b616a"><code>5cba6da</code></a>
Revert &quot;deps: update dependencies for all modules (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9065">#9065</a>)&quot;
(<a
href="https://redirect.github.com/grpc/grpc-go/issues/9067">#9067</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/af8a9364aa7523ab24d214e9ef13e6ad64d5c5f9"><code>af8a936</code></a>
deps: update dependencies for all modules (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9065">#9065</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/cdc60dfaaadde45e16aa3c28237c0e655a722c1a"><code>cdc60df</code></a>
transport: optimize heap allocations in ready reader and update syscall
conne...</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/208d053e3204c806ba9e6205c26aa064c8b42852"><code>208d053</code></a>
xds/resolver: pass complete XDSConfig in RPC context for HTTP filters
(gRFC A...</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/50fe1cc7fd78b78ae638ed90ea78514c934167ac"><code>50fe1cc</code></a>
test: Fix flaky test
<code>TestServerStreaming_ClientCallRecvMsgTwice</code> in
`end2end...</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/d574bad188f25ba03d41a506e6f2ef93837ad10b"><code>d574bad</code></a>
build(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9050">#9050</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/b8bf4d0488a351c563d63797ffba321585d6bb24"><code>b8bf4d0</code></a>
build(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 in
/inte...</li>
<li>Additional commits viewable in <a
href="https://github.com/grpc/grpc-go/compare/v1.80.0...v1.81.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `gopkg.in/ini.v1` from 1.67.1 to 1.67.2

Updates `github.com/fsnotify/fsnotify` from 1.9.0 to 1.10.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/fsnotify/fsnotify/releases">github.com/fsnotify/fsnotify's
releases</a>.</em></p>
<blockquote>
<h2>v1.10.1</h2>
<h3>Changes and fixes</h3>
<ul>
<li>
<p>inotify: don't remove sibling watches sharing a path prefix (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>)</p>
</li>
<li>
<p>inotify, windows: don't rename sibling watches sharing a path prefix
(<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>)</p>
</li>
</ul>
<p><a
href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/754">fsnotify/fsnotify#754</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/755">fsnotify/fsnotify#755</a></p>
<h2>v1.10.0</h2>
<p>This version of fsnotify needs Go 1.23.</p>
<h3>Changes and fixes</h3>
<ul>
<li>
<p>inotify: improve initialization error message (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>)</p>
</li>
<li>
<p>inotify: send Rename event if recursive watch is renamed (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>)</p>
</li>
<li>
<p>inotify: avoid copying event buffers when reading names (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>)</p>
</li>
<li>
<p>kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a
bad entry no longer aborts Watcher.Add for the whole directory (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>)</p>
</li>
<li>
<p>kqueue: drop watches directly in Close() to fix a file descriptor
leak when recycling watchers (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>)</p>
</li>
<li>
<p>windows: fix nil pointer dereference in remWatch (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>)</p>
</li>
<li>
<p>windows: lock watch field updates against concurrent WatchList to fix
a race introduced in v1.9.0 (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>,
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>)</p>
</li>
</ul>
<p><a
href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/696">fsnotify/fsnotify#696</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/709">fsnotify/fsnotify#709</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/731">fsnotify/fsnotify#731</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/736">fsnotify/fsnotify#736</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/740">fsnotify/fsnotify#740</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/741">fsnotify/fsnotify#741</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/748">fsnotify/fsnotify#748</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/749">fsnotify/fsnotify#749</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/fsnotify/fsnotify/blob/main/CHANGELOG.md">github.com/fsnotify/fsnotify's
changelog</a>.</em></p>
<blockquote>
<h2>1.10.1 2026-05-04</h2>
<h3>Changes and fixes</h3>
<ul>
<li>
<p>inotify: don't remove sibling watches sharing a path prefix (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>)</p>
</li>
<li>
<p>inotify, windows: don't rename sibling watches sharing a path prefix
(<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>)</p>
</li>
</ul>
<p><a
href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/754">fsnotify/fsnotify#754</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/755">fsnotify/fsnotify#755</a></p>
<h2>1.10.0 2026-04-30</h2>
<p>This version of fsnotify needs Go 1.23.</p>
<h3>Changes and fixes</h3>
<ul>
<li>
<p>inotify: improve initialization error message (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>)</p>
</li>
<li>
<p>inotify: send Rename event if recursive watch is renamed (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>)</p>
</li>
<li>
<p>inotify: avoid copying event buffers when reading names (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>)</p>
</li>
<li>
<p>kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a
bad entry no longer aborts Watcher.Add for the whole directory (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>)</p>
</li>
<li>
<p>kqueue: drop watches directly in Close() to fix a file descriptor
leak
when recycling watchers (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>)</p>
</li>
<li>
<p>windows: fix nil pointer dereference in remWatch (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>)</p>
</li>
<li>
<p>windows: lock watch field updates against concurrent WatchList to fix
a race introduced in v1.9.0 (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>,
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>)</p>
</li>
</ul>
<p><a
href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/696">fsnotify/fsnotify#696</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/709">fsnotify/fsnotify#709</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/731">fsnotify/fsnotify#731</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/736">fsnotify/fsnotify#736</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/740">fsnotify/fsnotify#740</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/741">fsnotify/fsnotify#741</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/748">fsnotify/fsnotify#748</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/749">fsnotify/fsnotify#749</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/76b01a6e8f502187fecedea8b025e79e5a86085c"><code>76b01a6</code></a>
Release 1.10.1</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/fec150b807510e54e5b25def4b6e5fb001b4898c"><code>fec150b</code></a>
Update changelog</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/162b4216ab8f92ecd26425530bee198972c9b3cb"><code>162b421</code></a>
inotify, windows: don't rename sibling watches sharing a path prefix (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>)</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/224257f23b2f3a96509b316c5cead71dd4a9099a"><code>224257f</code></a>
inotify: don't remove sibling watches sharing a path prefix (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>)</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/e0c956c0ccaf51562fee30ef5c055c74e6ae2104"><code>e0c956c</code></a>
windows: document directory Write events and stabilize tests (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/745">#745</a>)</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/8d01d7b9cbe0199e4a1e60fbd965fb05dbb42123"><code>8d01d7b</code></a>
Release 1.10.0</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/602284e4a8cadd488d7a5fa07c48462dfac25108"><code>602284e</code></a>
Update changelog</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/7f03e59f9659552d8a084e03024cb9b983748ed7"><code>7f03e59</code></a>
kqueue: skip ENOENT entries in watchDirectoryFiles (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>)</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/dab9dde2fc9ba4d0c1076318f81cabcc8fdb2ec9"><code>dab9dde</code></a>
windows: lock watch field updates against concurrent WatchList (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>)
(<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>)</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/eadf267ce152b5e62d48cc2c13bb08bd4062b6c7"><code>eadf267</code></a>
kqueue: drop watches directly in Close() instead of going through
remove() (#...</li>
<li>Additional commits viewable in <a
href="https://github.com/fsnotify/fsnotify/compare/v1.9.0...v1.10.1">compare
view</a></li>
</ul>
</details>
<br />

Updates `github.com/huandu/go-sqlbuilder` from 1.40.2 to 1.41.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/huandu/go-sqlbuilder/releases">github.com/huandu/go-sqlbuilder's
releases</a>.</em></p>
<blockquote>
<h2>v1.41.0</h2>
<ul>
<li><code>[NEW]</code> Add an option <code>NoExpand</code> to change
default field &quot;expand&quot; behavior for backward compatibility.
See <a
href="https://redirect.github.com/huandu/go-sqlbuilder/issues/237">#237</a>
for details.</li>
</ul>
<p>NOTE: Starting from v1.40.0, the <code>Struct</code> utility type
defaults to expanding non-primitive struct fields. This change caused
unexpected behavior for some users. To address this without reverting
the features introduced in v1.40.0, we have introduced a <code>NoExpand
</code>configuration. When set to true, all fields will default to no
expansion (preserving legacy behavior). You can still opt-in to
expansion for specific fields by using the
<code>fieldopt:&quot;expand&quot;</code> tag.</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/huandu/go-sqlbuilder/compare/v1.40.0...v1.41.0">https://github.com/huandu/go-sqlbuilder/compare/v1.40.0...v1.41.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/huandu/go-sqlbuilder/commit/44837218602c8f96eac9f27411d5b93a20dc979d"><code>4483721</code></a>
fix <a
href="https://redirect.github.com/huandu/go-sqlbuilder/issues/237">#237</a>:
add option <code>NoExpand</code> to control default field
&quot;expand&quot; behavior</li>
<li>See full diff in <a
href="https://github.com/huandu/go-sqlbuilder/compare/v1.40.2...v1.41.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `github.com/lestrrat-go/jwx/v3` from 3.1.0 to 3.1.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lestrrat-go/jwx/releases">github.com/lestrrat-go/jwx/v3's
releases</a>.</em></p>
<blockquote>
<h2>v3.1.1</h2>
<p>For more detailed release notes, see <a
href="https://github.com/lestrrat-go/jwx/blob/v3.1.1/Changes">Changes</a>.</p>
<h2>What's Changed</h2>
<ul>
<li>build(deps): bump pozil/auto-assign-issue from 2.2.0 to 2.2.1 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2045">lestrrat-go/jwx#2045</a></li>
<li>guard ecdsa coordinates against oversized big.Int by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2050">lestrrat-go/jwx#2050</a></li>
<li>reject jwe with conflicting alg in protected vs per-recipient by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2052">lestrrat-go/jwx#2052</a></li>
<li>fix AddressClaim.MarshalJSON for non-printable bytes by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2056">lestrrat-go/jwx#2056</a></li>
<li>jwt: only call ParseForm when WithFormKey is supplied by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2058">lestrrat-go/jwx#2058</a></li>
<li>jws: jkuProvider rejects fetched keys marked use=enc by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2060">lestrrat-go/jwx#2060</a></li>
<li>jwa: unify SignatureAlgorithm/KeyEncryption/ContentEncryption into
one registry by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2066">lestrrat-go/jwx#2066</a></li>
<li>build(deps): bump pozil/auto-assign-issue from
f245a9119ba5cc2fed4aa7b8268d576d40acddf0 to
7bf9d82c77d45976224660b873fc83e60576c5aa by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2065">lestrrat-go/jwx#2065</a></li>
<li>cmd/jwx: warn on private-key-to-tty + reject keysize&lt;=0 for oct
by <a href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in
<a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2071">lestrrat-go/jwx#2071</a></li>
<li>jws: refuse &quot;b64&quot; header in VerifyCompactFast by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2081">lestrrat-go/jwx#2081</a></li>
<li>jws: VerifyCompactFast refusals match jws.VerifyError() class by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2083">lestrrat-go/jwx#2083</a></li>
<li>jws: name loose keySet options in fan-out verify error by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2085">lestrrat-go/jwx#2085</a></li>
<li>jws: honor RFC 7797 b64=false in Message.MarshalJSON by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2087">lestrrat-go/jwx#2087</a></li>
<li>jws: reject literal-JSON &quot;protected&quot; in general-form JWS
by <a href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in
<a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2089">lestrrat-go/jwx#2089</a></li>
<li>jwt: ParseRequest: don't skip form body on chunked transfer by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2091">lestrrat-go/jwx#2091</a></li>
<li>jwt: pedantic mode enforces cty=JWT nested-envelope shape by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2094">lestrrat-go/jwx#2094</a></li>
<li>jwt: defensively reject missing claims in MaxDeltaIs / MinDeltaIs by
<a href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2099">lestrrat-go/jwx#2099</a></li>
<li>jwt: ParseInsecure: parse loop-local payload, not original input by
<a href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2097">lestrrat-go/jwx#2097</a></li>
<li>jws: Verify rejects b64=false without &quot;b64&quot; listed in
&quot;crit&quot; by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2102">lestrrat-go/jwx#2102</a></li>
<li>jws: Sign auto-declares &quot;b64&quot; in &quot;crit&quot; when
emitting b64=false by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2104">lestrrat-go/jwx#2104</a></li>
<li>jws: declare &quot;b64&quot; as typed bool header field by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2106">lestrrat-go/jwx#2106</a></li>
<li>jws: reject general-form JWS with top-level &quot;header&quot;
sibling of &quot;signatures&quot; by <a
href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in <a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2108">lestrrat-go/jwx#2108</a></li>
<li>jws: typed sentinel for AlgorithmsForKey unclassifiable-key failures
by <a href="https://github.com/lestrrat"><code>@​lestrrat</code></a> in
<a
href="https://redirect.github.com/lestrrat-go/jwx/pull/2110">lestrrat-go/jwx#2110</a></li>
<li>jws: VerifyMessage observes ctx cancellation between loop iterations
by <a href="https://github.com/lestrrat"><code>@​lestrrat</code></a>
i...

_Description has been truncated_

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Johan Fylling <johan.dev@fylling.se>
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Johan Fylling <johan.dev@fylling.se>
Co-authored-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-05-19 10:13:47 +02:00