mirror of
https://github.com/open-policy-agent/opa.git
synced 2026-08-12 19:32:48 -06:00
23a4e6267688c948ef0217d8d3a808487f4137f9
434 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
2b18f03b2b |
topdown: fix "a", "a" in {"a"} not returning true (#8747)
It's mostly useless, but aren't we all. Also added benchmarks to make sure I didn't mess anything up. And one or two tiny but unrelated fixes. --------- Signed-off-by: Anders Eknert <anders.eknert@apple.com> Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com> Co-authored-by: Stephan Renatus <stephan.renatus@gmail.com> |
||
|
|
0911080ea6 |
build(deps): bump the dependencies group across 2 directories with 12 updates (#8674)
Bumps the dependencies group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github.com/fsnotify/fsnotify](https://github.com/fsnotify/fsnotify) | `1.9.0` | `1.10.1` | | [github.com/huandu/go-sqlbuilder](https://github.com/huandu/go-sqlbuilder) | `1.40.2` | `1.41.0` | | [github.com/lestrrat-go/jwx/v3](https://github.com/lestrrat-go/jwx) | `3.1.0` | `3.1.1` | | [github.com/olekukonko/tablewriter](https://github.com/olekukonko/tablewriter) | `1.1.0` | `1.1.4` | | [github.com/vektah/gqlparser/v2](https://github.com/vektah/gqlparser) | `2.5.32` | `2.5.33` | | [golang.org/x/net](https://github.com/golang/net) | `0.53.0` | `0.54.0` | | [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.80.0` | `1.81.0` | | gopkg.in/ini.v1 | `1.67.1` | `1.67.2` | Bumps the dependencies group with 11 updates in the /e2e directory: | Package | From | To | | --- | --- | --- | | [github.com/fsnotify/fsnotify](https://github.com/fsnotify/fsnotify) | `1.9.0` | `1.10.1` | | [github.com/huandu/go-sqlbuilder](https://github.com/huandu/go-sqlbuilder) | `1.40.2` | `1.41.0` | | [github.com/lestrrat-go/jwx/v3](https://github.com/lestrrat-go/jwx) | `3.1.0` | `3.1.1` | | [github.com/olekukonko/tablewriter](https://github.com/olekukonko/tablewriter) | `1.1.0` | `1.1.4` | | [github.com/vektah/gqlparser/v2](https://github.com/vektah/gqlparser) | `2.5.32` | `2.5.33` | | [golang.org/x/net](https://github.com/golang/net) | `0.53.0` | `0.54.0` | | [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.80.0` | `1.81.0` | | gopkg.in/ini.v1 | `1.67.1` | `1.67.2` | | [github.com/go-sql-driver/mysql](https://github.com/go-sql-driver/mysql) | `1.9.3` | `1.10.0` | | [github.com/microsoft/go-mssqldb](https://github.com/microsoft/go-mssqldb) | `1.9.8` | `1.10.0` | | [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) | `1.49.1` | `1.50.1` | Updates `github.com/fsnotify/fsnotify` from 1.9.0 to 1.10.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/fsnotify/fsnotify/releases">github.com/fsnotify/fsnotify's releases</a>.</em></p> <blockquote> <h2>v1.10.1</h2> <h3>Changes and fixes</h3> <ul> <li> <p>inotify: don't remove sibling watches sharing a path prefix (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>)</p> </li> <li> <p>inotify, windows: don't rename sibling watches sharing a path prefix (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>)</p> </li> </ul> <p><a href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/754">fsnotify/fsnotify#754</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/755">fsnotify/fsnotify#755</a></p> <h2>v1.10.0</h2> <p>This version of fsnotify needs Go 1.23.</p> <h3>Changes and fixes</h3> <ul> <li> <p>inotify: improve initialization error message (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>)</p> </li> <li> <p>inotify: send Rename event if recursive watch is renamed (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>)</p> </li> <li> <p>inotify: avoid copying event buffers when reading names (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>)</p> </li> <li> <p>kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a bad entry no longer aborts Watcher.Add for the whole directory (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>)</p> </li> <li> <p>kqueue: drop watches directly in Close() to fix a file descriptor leak when recycling watchers (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>)</p> </li> <li> <p>windows: fix nil pointer dereference in remWatch (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>)</p> </li> <li> <p>windows: lock watch field updates against concurrent WatchList to fix a race introduced in v1.9.0 (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>, <a href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>)</p> </li> </ul> <p><a href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/696">fsnotify/fsnotify#696</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/709">fsnotify/fsnotify#709</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/731">fsnotify/fsnotify#731</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/736">fsnotify/fsnotify#736</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/740">fsnotify/fsnotify#740</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/741">fsnotify/fsnotify#741</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/748">fsnotify/fsnotify#748</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/749">fsnotify/fsnotify#749</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/fsnotify/fsnotify/blob/main/CHANGELOG.md">github.com/fsnotify/fsnotify's changelog</a>.</em></p> <blockquote> <h2>1.10.1 2026-05-04</h2> <h3>Changes and fixes</h3> <ul> <li> <p>inotify: don't remove sibling watches sharing a path prefix (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>)</p> </li> <li> <p>inotify, windows: don't rename sibling watches sharing a path prefix (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>)</p> </li> </ul> <p><a href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/754">fsnotify/fsnotify#754</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/755">fsnotify/fsnotify#755</a></p> <h2>1.10.0 2026-04-30</h2> <p>This version of fsnotify needs Go 1.23.</p> <h3>Changes and fixes</h3> <ul> <li> <p>inotify: improve initialization error message (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>)</p> </li> <li> <p>inotify: send Rename event if recursive watch is renamed (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>)</p> </li> <li> <p>inotify: avoid copying event buffers when reading names (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>)</p> </li> <li> <p>kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a bad entry no longer aborts Watcher.Add for the whole directory (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>)</p> </li> <li> <p>kqueue: drop watches directly in Close() to fix a file descriptor leak when recycling watchers (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>)</p> </li> <li> <p>windows: fix nil pointer dereference in remWatch (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>)</p> </li> <li> <p>windows: lock watch field updates against concurrent WatchList to fix a race introduced in v1.9.0 (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>, <a href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>)</p> </li> </ul> <p><a href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/696">fsnotify/fsnotify#696</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/709">fsnotify/fsnotify#709</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/731">fsnotify/fsnotify#731</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/736">fsnotify/fsnotify#736</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/740">fsnotify/fsnotify#740</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/741">fsnotify/fsnotify#741</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/748">fsnotify/fsnotify#748</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/749">fsnotify/fsnotify#749</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/fsnotify/fsnotify/commit/76b01a6e8f502187fecedea8b025e79e5a86085c"><code>76b01a6</code></a> Release 1.10.1</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/fec150b807510e54e5b25def4b6e5fb001b4898c"><code>fec150b</code></a> Update changelog</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/162b4216ab8f92ecd26425530bee198972c9b3cb"><code>162b421</code></a> inotify, windows: don't rename sibling watches sharing a path prefix (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>)</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/224257f23b2f3a96509b316c5cead71dd4a9099a"><code>224257f</code></a> inotify: don't remove sibling watches sharing a path prefix (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>)</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/e0c956c0ccaf51562fee30ef5c055c74e6ae2104"><code>e0c956c</code></a> windows: document directory Write events and stabilize tests (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/745">#745</a>)</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/8d01d7b9cbe0199e4a1e60fbd965fb05dbb42123"><code>8d01d7b</code></a> Release 1.10.0</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/602284e4a8cadd488d7a5fa07c48462dfac25108"><code>602284e</code></a> Update changelog</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/7f03e59f9659552d8a084e03024cb9b983748ed7"><code>7f03e59</code></a> kqueue: skip ENOENT entries in watchDirectoryFiles (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>)</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/dab9dde2fc9ba4d0c1076318f81cabcc8fdb2ec9"><code>dab9dde</code></a> windows: lock watch field updates against concurrent WatchList (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>) (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>)</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/eadf267ce152b5e62d48cc2c13bb08bd4062b6c7"><code>eadf267</code></a> kqueue: drop watches directly in Close() instead of going through remove() (#...</li> <li>Additional commits viewable in <a href="https://github.com/fsnotify/fsnotify/compare/v1.9.0...v1.10.1">compare view</a></li> </ul> </details> <br /> Updates `github.com/huandu/go-sqlbuilder` from 1.40.2 to 1.41.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/huandu/go-sqlbuilder/releases">github.com/huandu/go-sqlbuilder's releases</a>.</em></p> <blockquote> <h2>v1.41.0</h2> <ul> <li><code>[NEW]</code> Add an option <code>NoExpand</code> to change default field "expand" behavior for backward compatibility. See <a href="https://redirect.github.com/huandu/go-sqlbuilder/issues/237">#237</a> for details.</li> </ul> <p>NOTE: Starting from v1.40.0, the <code>Struct</code> utility type defaults to expanding non-primitive struct fields. This change caused unexpected behavior for some users. To address this without reverting the features introduced in v1.40.0, we have introduced a <code>NoExpand </code>configuration. When set to true, all fields will default to no expansion (preserving legacy behavior). You can still opt-in to expansion for specific fields by using the <code>fieldopt:"expand"</code> tag.</p> <p><strong>Full Changelog</strong>: <a href="https://github.com/huandu/go-sqlbuilder/compare/v1.40.0...v1.41.0">https://github.com/huandu/go-sqlbuilder/compare/v1.40.0...v1.41.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/huandu/go-sqlbuilder/commit/44837218602c8f96eac9f27411d5b93a20dc979d"><code>4483721</code></a> fix <a href="https://redirect.github.com/huandu/go-sqlbuilder/issues/237">#237</a>: add option <code>NoExpand</code> to control default field "expand" behavior</li> <li>See full diff in <a href="https://github.com/huandu/go-sqlbuilder/compare/v1.40.2...v1.41.0">compare view</a></li> </ul> </details> <br /> Updates `github.com/lestrrat-go/jwx/v3` from 3.1.0 to 3.1.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/lestrrat-go/jwx/releases">github.com/lestrrat-go/jwx/v3's releases</a>.</em></p> <blockquote> <h2>v3.1.1</h2> <p>For more detailed release notes, see <a href="https://github.com/lestrrat-go/jwx/blob/v3.1.1/Changes">Changes</a>.</p> <h2>What's Changed</h2> <ul> <li>build(deps): bump pozil/auto-assign-issue from 2.2.0 to 2.2.1 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2045">lestrrat-go/jwx#2045</a></li> <li>guard ecdsa coordinates against oversized big.Int by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2050">lestrrat-go/jwx#2050</a></li> <li>reject jwe with conflicting alg in protected vs per-recipient by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2052">lestrrat-go/jwx#2052</a></li> <li>fix AddressClaim.MarshalJSON for non-printable bytes by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2056">lestrrat-go/jwx#2056</a></li> <li>jwt: only call ParseForm when WithFormKey is supplied by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2058">lestrrat-go/jwx#2058</a></li> <li>jws: jkuProvider rejects fetched keys marked use=enc by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2060">lestrrat-go/jwx#2060</a></li> <li>jwa: unify SignatureAlgorithm/KeyEncryption/ContentEncryption into one registry by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2066">lestrrat-go/jwx#2066</a></li> <li>build(deps): bump pozil/auto-assign-issue from f245a9119ba5cc2fed4aa7b8268d576d40acddf0 to 7bf9d82c77d45976224660b873fc83e60576c5aa by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2065">lestrrat-go/jwx#2065</a></li> <li>cmd/jwx: warn on private-key-to-tty + reject keysize<=0 for oct by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2071">lestrrat-go/jwx#2071</a></li> <li>jws: refuse "b64" header in VerifyCompactFast by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2081">lestrrat-go/jwx#2081</a></li> <li>jws: VerifyCompactFast refusals match jws.VerifyError() class by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2083">lestrrat-go/jwx#2083</a></li> <li>jws: name loose keySet options in fan-out verify error by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2085">lestrrat-go/jwx#2085</a></li> <li>jws: honor RFC 7797 b64=false in Message.MarshalJSON by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2087">lestrrat-go/jwx#2087</a></li> <li>jws: reject literal-JSON "protected" in general-form JWS by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2089">lestrrat-go/jwx#2089</a></li> <li>jwt: ParseRequest: don't skip form body on chunked transfer by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2091">lestrrat-go/jwx#2091</a></li> <li>jwt: pedantic mode enforces cty=JWT nested-envelope shape by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2094">lestrrat-go/jwx#2094</a></li> <li>jwt: defensively reject missing claims in MaxDeltaIs / MinDeltaIs by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2099">lestrrat-go/jwx#2099</a></li> <li>jwt: ParseInsecure: parse loop-local payload, not original input by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2097">lestrrat-go/jwx#2097</a></li> <li>jws: Verify rejects b64=false without "b64" listed in "crit" by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2102">lestrrat-go/jwx#2102</a></li> <li>jws: Sign auto-declares "b64" in "crit" when emitting b64=false by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2104">lestrrat-go/jwx#2104</a></li> <li>jws: declare "b64" as typed bool header field by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2106">lestrrat-go/jwx#2106</a></li> <li>jws: reject general-form JWS with top-level "header" sibling of "signatures" by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2108">lestrrat-go/jwx#2108</a></li> <li>jws: typed sentinel for AlgorithmsForKey unclassifiable-key failures by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2110">lestrrat-go/jwx#2110</a></li> <li>jws: VerifyMessage observes ctx cancellation between loop iterations by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2112">lestrrat-go/jwx#2112</a></li> <li>jws: cleanup follow-ups from recent review (low-severity batch) by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2114">lestrrat-go/jwx#2114</a></li> <li>jwe: DecryptMessage observes ctx cancellation between loop iterations by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2117">lestrrat-go/jwx#2117</a></li> <li>jwe: parse and bound-check PBES2 p2c in int64 space; name the violated bound by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2119">lestrrat-go/jwx#2119</a></li> <li>jwe: WithKey validates alg-vs-key shape at option-time by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2121">lestrrat-go/jwx#2121</a></li> <li>jwe: compression cap error names "decompressed" payload, the option, and the size by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2123">lestrrat-go/jwx#2123</a></li> <li>jwe: bound joined-error count and drop redundant outer Decrypt prefix by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2125">lestrrat-go/jwx#2125</a></li> <li>jwe: keySetProvider surfaces per-key errors via errors.Join by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2127">lestrrat-go/jwx#2127</a></li> <li>jwe: add WithDisabledKeyAlgorithms global policy hook by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2129">lestrrat-go/jwx#2129</a></li> <li>jwe: document WithMaxDecompressBufferSize behavior at non-positive values by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2131">lestrrat-go/jwx#2131</a></li> <li>jwk: stop duplicating JWK fields at JWKS top level on parse by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2133">lestrrat-go/jwx#2133</a></li> <li>jwk: wrap ParseKey errors with ParseError sentinel by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2135">lestrrat-go/jwx#2135</a></li> <li>jwk: stream the keys array with cap-before-allocate by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2137">lestrrat-go/jwx#2137</a></li> <li>jwk: treat nil key from custom KeyParser as continue, not success by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2140">lestrrat-go/jwx#2140</a></li> <li>jwk: fix phantom ContinueParseError refs and unmarshaler typo in docs by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2142">lestrrat-go/jwx#2142</a></li> <li>Changes: draft v3.1.1 release notes by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2155">lestrrat-go/jwx#2155</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/lestrrat-go/jwx/compare/v3.1.0...v3.1.1">https://github.com/lestrrat-go/jwx/compare/v3.1.0...v3.1.1</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/lestrrat-go/jwx/blob/v3.1.1/Changes">github.com/lestrrat-go/jwx/v3's changelog</a>.</em></p> <blockquote> <p>v3.1.1 7 May 2026</p> <ul> <li> <p>[jws] Coordinated RFC 7797 <code>b64=false</code> handling pass: <code>jws.Verify</code> rejects payloads with <code>b64=false</code> unless <code>b64</code> is also listed in <code>crit</code>; <code>jws.Sign</code> auto-declares <code>b64</code> in <code>crit</code> when emitting <code>b64=false</code>; <code>Message.MarshalJSON</code> honors <code>b64=false</code> instead of silently re-encoding; <code>jws.VerifyCompactFast</code> refuses any compact JWS carrying <code>b64</code> (the fast path doesn't process extension headers); and <code>b64</code> is now declared as a typed boolean header field rather than handled ad-hoc. (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2081">#2081</a>, <a href="https://redirect.github.com/lestrrat-go/jwx/issues/2087">#2087</a>, <a href="https://redirect.github.com/lestrrat-go/jwx/issues/2102">#2102</a>, <a href="https://redirect.github.com/lestrrat-go/jwx/issues/2104">#2104</a>, <a href="https://redirect.github.com/lestrrat-go/jwx/issues/2106">#2106</a>)</p> </li> <li> <p>[jws] Reject malformed general-form JSON-serialized JWS: inputs with a top-level <code>header</code> member as a sibling of <code>signatures</code> are rejected (the spec only permits <code>header</code> inside per-signature objects), as are inputs whose <code>protected</code> member is a literal JSON object instead of a base64url-encoded string. (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2089">#2089</a>, <a href="https://redirect.github.com/lestrrat-go/jwx/issues/2108">#2108</a>)</p> </li> <li> <p>[jws] <code>jws.AlgorithmsForKey</code> failures from unclassifiable keys are now wrapped in a typed sentinel so callers can branch on "couldn't categorize this key" without string matching the error message. (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2110">#2110</a>)</p> </li> <li> <p>[jws] Verify error-shape consistency: <code>VerifyCompactFast</code> refusals now match the <code>jws.VerifyError()</code> taxonomy used by the slow path, fan-out verify errors name the loose <code>WithKeySet</code> options that were tried, multi-signature <code>b64</code> mismatches name the offending signature index and conflicting value, and the compact <code>b64=false</code>+payload-contains-<code>.</code> error references RFC 7797 §5.2 and points at <code>WithDetachedPayload</code>. (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2083">#2083</a>, <a href="https://redirect.github.com/lestrrat-go/jwx/issues/2085">#2085</a>, <a href="https://redirect.github.com/lestrrat-go/jwx/issues/2114">#2114</a>)</p> </li> <li> <p>[jws] Keys fetched via the <code>jku</code> header are no longer accepted for signature verification when the JWK declares <code>use=enc</code>. (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2060">#2060</a>)</p> </li> <li> <p>[jws][jwe] <code>jws.VerifyMessage</code> and <code>jwe.DecryptMessage</code> observe context cancellation between loop iterations rather than only at boundaries. Long fan-out verify/decrypt loops now respond to a cancelled context promptly. (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2112">#2112</a>, <a href="https://redirect.github.com/lestrrat-go/jwx/issues/2117">#2117</a>)</p> </li> <li> <p>[jwe] Reject PBES2 messages whose <code>p2c</code> (iteration count) does not parse cleanly into int64 or violates the configured bound. The error now names the violated bound (min vs max) instead of the generic "out of range". (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2119">#2119</a>)</p> </li> <li> <p>[jwe] <code>jwe.WithKey()</code> validates the alg-vs-key shape at option construction time rather than during encryption, so misuse surfaces at the call site instead of inside the encrypt loop. (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2121">#2121</a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/lestrrat-go/jwx/commit/59b8b1b4239be0b470e5d939f16759793bc4a203"><code>59b8b1b</code></a> release v3.1.1</li> <li><a href="https://github.com/lestrrat-go/jwx/commit/4d4ab015bec294bcee30d83506def12906e9da2c"><code>4d4ab01</code></a> Changes: draft v3.1.1 release notes (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2155">#2155</a>)</li> <li><a href="https://github.com/lestrrat-go/jwx/commit/ad739f565db19d9d8fe805eb5db0b05d5441f971"><code>ad739f5</code></a> jwk: fix phantom ContinueParseError refs and unmarshaler typo in docs (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2142">#2142</a>)</li> <li><a href="https://github.com/lestrrat-go/jwx/commit/3227cf9c3d8ddc2d9728d58db03f905b61972f69"><code>3227cf9</code></a> jwk: treat nil key from custom KeyParser as continue, not success (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2140">#2140</a>)</li> <li><a href="https://github.com/lestrrat-go/jwx/commit/82c067ed57cbcbf0aba072518ed928c96306e951"><code>82c067e</code></a> jwk: stream the keys array with cap-before-allocate (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2137">#2137</a>)</li> <li><a href="https://github.com/lestrrat-go/jwx/commit/931a815632dab9bb0e49c81aa701dbf9e9a77f04"><code>931a815</code></a> jwk: wrap ParseKey errors with ParseError sentinel (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2135">#2135</a>)</li> <li><a href="https://github.com/lestrrat-go/jwx/commit/53f62259012b1d934a1dc8c07ebbd8f516f7b919"><code>53f6225</code></a> jwk: stop duplicating JWK fields at JWKS top level on parse (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2133">#2133</a>)</li> <li><a href="https://github.com/lestrrat-go/jwx/commit/8943519997fa2fe4e7e0423baf9cd8e9bb45ddd9"><code>8943519</code></a> jwe: document WithMaxDecompressBufferSize behavior at non-positive values (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2">#2</a>...</li> <li><a href="https://github.com/lestrrat-go/jwx/commit/4797307a63aa0dd6847ee64cbdacbb878226b4f8"><code>4797307</code></a> jwe: add WithDisabledKeyAlgorithms global policy hook (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2129">#2129</a>)</li> <li><a href="https://github.com/lestrrat-go/jwx/commit/de41d0ef9e0b8f6a9f844f5313abbc510dda78fb"><code>de41d0e</code></a> jwe: keySetProvider surfaces per-key errors via errors.Join (<a href="https://redirect.github.com/lestrrat-go/jwx/issues/2127">#2127</a>)</li> <li>Additional commits viewable in <a href="https://github.com/lestrrat-go/jwx/compare/v3.1.0...v3.1.1">compare view</a></li> </ul> </details> <br /> Updates `github.com/olekukonko/tablewriter` from 1.1.0 to 1.1.4 <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/olekukonko/tablewriter/commit/a0dea8a90a8a0c7610afb5588d2f15a57f4aa9a2"><code>a0dea8a</code></a> no need to disable twice</li> <li><a href="https://github.com/olekukonko/tablewriter/commit/a4fb40afbe367fd0733ce7b45223034febf7b0b4"><code>a4fb40a</code></a> Merge pull request <a href="https://redirect.github.com/olekukonko/tablewriter/issues/314">#314</a> from sducamp/fix/rendition-debug-leak</li> <li><a href="https://github.com/olekukonko/tablewriter/commit/6bc4cb4866ab2a10340bf0d11c41e676b546e253"><code>6bc4cb4</code></a> fix: prevent debug output leak from renderer during Options() reconfiguration</li> <li><a href="https://github.com/olekukonko/tablewriter/commit/54408fee90b7a66a94d9d71f789d42e03f45109b"><code>54408fe</code></a> update ll to v0.1.6</li> <li><a href="https://github.com/olekukonko/tablewriter/commit/5ea5f3c761e556def568d7e07df774c55ae66071"><code>5ea5f3c</code></a> add mote tab test ans update go mod</li> <li><a href="https://github.com/olekukonko/tablewriter/commit/1455dd8dd79719f142013f59e300fcdf0144f3fd"><code>1455dd8</code></a> Merge pull request <a href="https://redirect.github.com/olekukonko/tablewriter/issues/311">#311</a> from olekukonko/tabber</li> <li><a href="https://github.com/olekukonko/tablewriter/commit/d7b0a55c1f9c6bd55eceaa22dfb0123bac23f281"><code>d7b0a55</code></a> improve tab and make test more predictable</li> <li><a href="https://github.com/olekukonko/tablewriter/commit/62117a2ca655057ba2e61f2d18896f619fc48230"><code>62117a2</code></a> add space default <a href="https://redirect.github.com/olekukonko/tablewriter/issues/312">#312</a> for colorized renderer</li> <li><a href="https://github.com/olekukonko/tablewriter/commit/4958831ad1de62ec94567bf5d42a8a9b2c50e74d"><code>4958831</code></a> ll v0.1.5 update enables logging by default hence disable</li> <li><a href="https://github.com/olekukonko/tablewriter/commit/1c68e06c65b87d5416aada2737b6683fadd1b25b"><code>1c68e06</code></a> use space for padding as default <a href="https://redirect.github.com/olekukonko/tablewriter/issues/312">#312</a></li> <li>Additional commits viewable in <a href="https://github.com/olekukonko/tablewriter/compare/v1.1.0...v1.1.4">compare view</a></li> </ul> </details> <br /> Updates `github.com/vektah/gqlparser/v2` from 2.5.32 to 2.5.33 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vektah/gqlparser/releases">github.com/vektah/gqlparser/v2's releases</a>.</em></p> <blockquote> <h2>v2.5.33</h2> <h2>What's Changed</h2> <ul> <li>fix: allow repeatable directives on GraphQL document by <a href="https://github.com/fredzqm"><code>@fredzqm</code></a> in <a href="https://redirect.github.com/vektah/gqlparser/pull/418">vektah/gqlparser#418</a></li> <li>feat: create a new ScalarLeafsRuleWithoutSuggestions validator rule by <a href="https://github.com/XuankangLin"><code>@XuankangLin</code></a> in <a href="https://redirect.github.com/vektah/gqlparser/pull/413">vektah/gqlparser#413</a></li> <li>refactor: format lines in scalar_leafs.go by <a href="https://github.com/XuankangLin"><code>@XuankangLin</code></a> in <a href="https://redirect.github.com/vektah/gqlparser/pull/423">vektah/gqlparser#423</a></li> <li>Fix negative Position.Column for definitions with block string descriptions (<a href="https://redirect.github.com/vektah/gqlparser/issues/254">#254</a>) by <a href="https://github.com/riwal42c"><code>@riwal42c</code></a> in <a href="https://redirect.github.com/vektah/gqlparser/pull/422">vektah/gqlparser#422</a></li> <li>Update spec to 2023 version by <a href="https://github.com/StevenACoffman"><code>@StevenACoffman</code></a> in <a href="https://redirect.github.com/vektah/gqlparser/pull/401">vektah/gqlparser#401</a></li> <li>Bump picomatch from 2.3.1 to 2.3.2 in /validator/imported by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/vektah/gqlparser/pull/420">vektah/gqlparser#420</a></li> <li>Bump <code>@babel/preset-env</code> from 7.29.0 to 7.29.2 in /validator/imported in the actions-deps group by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/vektah/gqlparser/pull/419">vektah/gqlparser#419</a></li> <li>Bump brace-expansion from 1.1.12 to 1.1.13 in /validator/imported by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/vektah/gqlparser/pull/421">vektah/gqlparser#421</a></li> <li>Bump prettier from 3.8.1 to 3.8.2 in /validator/imported in the actions-deps group by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/vektah/gqlparser/pull/424">vektah/gqlparser#424</a></li> <li>Bump prettier from 3.8.2 to 3.8.3 in /validator/imported in the actions-deps group by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/vektah/gqlparser/pull/425">vektah/gqlparser#425</a></li> <li>Bump minimatch from 3.0.4 to 3.1.5 in /validator/imported by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/vektah/gqlparser/pull/417">vektah/gqlparser#417</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/XuankangLin"><code>@XuankangLin</code></a> made their first contribution in <a href="https://redirect.github.com/vektah/gqlparser/pull/413">vektah/gqlparser#413</a></li> <li><a href="https://github.com/riwal42c"><code>@riwal42c</code></a> made their first contribution in <a href="https://redirect.github.com/vektah/gqlparser/pull/422">vektah/gqlparser#422</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/vektah/gqlparser/compare/v2.5.32...v2.5.33">https://github.com/vektah/gqlparser/compare/v2.5.32...v2.5.33</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vektah/gqlparser/commit/41b7913b390ac4278ca7fc766afd586c1e6df819"><code>41b7913</code></a> Bump minimatch from 3.0.4 to 3.1.5 in /validator/imported (<a href="https://redirect.github.com/vektah/gqlparser/issues/417">#417</a>)</li> <li><a href="https://github.com/vektah/gqlparser/commit/3c33bbeb81dd06c1dc5d5e56c97c2ac74e3a5e71"><code>3c33bbe</code></a> Bump prettier in /validator/imported in the actions-deps group (<a href="https://redirect.github.com/vektah/gqlparser/issues/425">#425</a>)</li> <li><a href="https://github.com/vektah/gqlparser/commit/f63b51fcf337b673ac06b593262f7ed72d11de24"><code>f63b51f</code></a> Update spec to 2023 version (<a href="https://redirect.github.com/vektah/gqlparser/issues/401">#401</a>)</li> <li><a href="https://github.com/vektah/gqlparser/commit/1f1383cb52d49c63919a791309a2c80e16a83c6f"><code>1f1383c</code></a> Bump prettier in /validator/imported in the actions-deps group (<a href="https://redirect.github.com/vektah/gqlparser/issues/424">#424</a>)</li> <li><a href="https://github.com/vektah/gqlparser/commit/021901042dbe56648020832ee88973acd389ea64"><code>0219010</code></a> Fix negative Position.Column for definitions with block string descriptions (...</li> <li><a href="https://github.com/vektah/gqlparser/commit/16bf3c4da15f2de0a8648e66f956ef9da2129d8e"><code>16bf3c4</code></a> refactor: format lines in scalar_leafs.go (<a href="https://redirect.github.com/vektah/gqlparser/issues/423">#423</a>)</li> <li><a href="https://github.com/vektah/gqlparser/commit/be677085400ffa5fd6e0ac86d98d1cf94db05efe"><code>be67708</code></a> Bump brace-expansion from 1.1.12 to 1.1.13 in /validator/imported (<a href="https://redirect.github.com/vektah/gqlparser/issues/421">#421</a>)</li> <li><a href="https://github.com/vektah/gqlparser/commit/61efb18da16d7f45f8050ecb576d27b85e6861da"><code>61efb18</code></a> feat: create a new ScalarLeafsRuleWithoutSuggestions validator rule (<a href="https://redirect.github.com/vektah/gqlparser/issues/413">#413</a>)</li> <li><a href="https://github.com/vektah/gqlparser/commit/a9bb4644d5911effae909bab06029df7f11c402c"><code>a9bb464</code></a> feat(validator): handle repeatable directives correctly (<a href="https://redirect.github.com/vektah/gqlparser/issues/418">#418</a>)</li> <li><a href="https://github.com/vektah/gqlparser/commit/b239ec3bfe15a44330f9752bd7fb56cc41cf1c2b"><code>b239ec3</code></a> Bump <code>@babel/preset-env</code> in /validator/imported in the actions-deps group (<a href="https://redirect.github.com/vektah/gqlparser/issues/419">#419</a>)</li> <li>Additional commits viewable in <a href="https://github.com/vektah/gqlparser/compare/v2.5.32...v2.5.33">compare view</a></li> </ul> </details> <br /> Updates `golang.org/x/net` from 0.53.0 to 0.54.0 <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/golang/net/commit/b138e06246cb323f2f380c2b7f7dd91f581dd56b"><code>b138e06</code></a> go.mod: update golang.org/x dependencies</li> <li><a href="https://github.com/golang/net/commit/689f70a42abd350f3a1aaa70b0d13eb9543d927a"><code>689f70a</code></a> quic: fix wrong final size being used for RESET_STREAM frame</li> <li><a href="https://github.com/golang/net/commit/208f306b2f0fd008b388bee2c2644be279778e94"><code>208f306</code></a> http3: increase handshake timeout</li> <li><a href="https://github.com/golang/net/commit/49810da71b9026da9e0d028a6ad8c7730c52d9c4"><code>49810da</code></a> http2: enable net/http wrapping when go >= 1.27</li> <li><a href="https://github.com/golang/net/commit/5e11a5ab891c117eda83b4304d60dd13286c1c76"><code>5e11a5a</code></a> quic: fix data race in streamForFrame</li> <li><a href="https://github.com/golang/net/commit/8c63081cd380ea768db5651941614b73472160ff"><code>8c63081</code></a> http2: use empty Transport rather than DefaultTransport in http2wrap</li> <li><a href="https://github.com/golang/net/commit/fc7b466ca49cb204039630533ece4fc557eb35cd"><code>fc7b466</code></a> http2: add http2wrap test</li> <li><a href="https://github.com/golang/net/commit/15c2cb1875fd727313dc4de909b3ee149422fbe2"><code>15c2cb1</code></a> http2: avoid overflowing 32-bit int when http2wrap enabled</li> <li><a href="https://github.com/golang/net/commit/64651885c2f2d745d77af2d7af2edbf568c179af"><code>6465188</code></a> http2: add wrapped Server</li> <li><a href="https://github.com/golang/net/commit/72f419a894cb0597dd5b6bcf119086bf2af41231"><code>72f419a</code></a> http2: add wrapped ClientConn</li> <li>Additional commits viewable in <a href="https://github.com/golang/net/compare/v0.53.0...v0.54.0">compare view</a></li> </ul> </details> <br /> Updates `golang.org/x/text` from 0.36.0 to 0.37.0 <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/golang/text/commit/3ef517e623a4bfc08d6457f87d73afda7af7d8e1"><code>3ef517e</code></a> go.mod: update golang.org/x dependencies</li> <li>See full diff in <a href="https://github.com/golang/text/compare/v0.36.0...v0.37.0">compare view</a></li> </ul> </details> <br /> Updates `google.golang.org/grpc` from 1.80.0 to 1.81.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/grpc/grpc-go/releases">google.golang.org/grpc's releases</a>.</em></p> <blockquote> <h2>Release 1.81.0</h2> <h1>Behavior Changes</h1> <ul> <li>balancer/rls: Switch gauge metrics to asynchronous emission (once per collection cycle) to reduce telemetry noise and align with other gRPC language implementations. (<a href="https://redirect.github.com/grpc/grpc-go/issues/8808">#8808</a>)</li> </ul> <h1>Dependencies</h1> <ul> <li>Minimum supported Go version is now 1.25. (<a href="https://redirect.github.com/grpc/grpc-go/issues/8969">#8969</a>)</li> </ul> <h1>Bug Fixes</h1> <ul> <li>xds: Use the leaf cluster's security config for the TLS handshake instead of the aggregate cluster's config. (<a href="https://redirect.github.com/grpc/grpc-go/issues/8956">#8956</a>)</li> <li>transport: Send a <code>RST_STREAM</code> when receiving an <code>END_STREAM</code> when the stream is not already half-closed. (<a href="https://redirect.github.com/grpc/grpc-go/issues/8832">#8832</a>)</li> <li>xds: Fix ADS resource name validation to prevent a panic. (<a href="https://redirect.github.com/grpc/grpc-go/issues/8970">#8970</a>)</li> </ul> <h1>New Features</h1> <ul> <li>grpc/stats: Add support for custom labels in per-call metrics (<a href="https://github.com/grpc/proposal/blob/master/A108-otel-custom-per-call-label.md">gRFC A108</a>). (<a href="https://redirect.github.com/grpc/grpc-go/issues/9008">#9008</a>)</li> <li>xds: Add support for Server Name Indication (SNI) and SAN validation (<a href="https://github.com/grpc/proposal/blob/master/A101-SNI-setting-and-SNI-SAN-validation.md">gRFC A101</a>). Disabled by default. To enable, set <code>GRPC_EXPERIMENTAL_XDS_SNI=true</code> environment variable. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9016">#9016</a>)</li> <li>xds: Add support to control which fields get propagated from ORCA backend metric reports to LRS load reports (<a href="https://github.com/grpc/proposal/blob/master/A85-lrs-custom-metrics-changes.md">gRFC A85</a>). Disabled by default. To enable, set <code>GRPC_EXPERIMENTAL_XDS_ORCA_LRS_PROPAGATION=true</code>. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9005">#9005</a>)</li> <li>xds: Add metrics to track xDS client connectivity and cached resource state (<a href="https://github.com/grpc/proposal/blob/master/A78-grpc-metrics-wrr-pf-xds.md">gRFC A78</a>). (<a href="https://redirect.github.com/grpc/grpc-go/issues/8807">#8807</a>)</li> <li>stats/otel: Enhance <code>grpc.subchannel.disconnections</code> metric by adding disconnection reason to the <code>grpc.disconnect_error</code> label (<a href="https://github.com/grpc/proposal/blob/master/A94-subchannel-otel-metrics.md">gRFC A94</a>). This provides granular insights into why subchannels are closing. (<a href="https://redirect.github.com/grpc/grpc-go/issues/8973">#8973</a>)</li> <li>mem: Add <code>mem.Buffer.Slice()</code> API to slice the buffer like a slice. (<a href="https://redirect.github.com/grpc/grpc-go/issues/8977">#8977</a>) <ul> <li>Special Thanks: <a href="https://github.com/ash2k"><code>@ash2k</code></a></li> </ul> </li> </ul> <h1>Performance Improvements</h1> <ul> <li>alts: Pool read buffers to lower memory utilization when sockets are unreadable. (<a href="https://redirect.github.com/grpc/grpc-go/issues/8964">#8964</a>)</li> <li>transport: Pool HTTP/2 framer read buffers to reduce idle memory consumption. Currently limited to Linux for ALTS and non-encrypted transports (TCP, Unix). To disable, set <code>GRPC_GO_EXPERIMENTAL_HTTP_FRAMER_READ_BUFFER_POOLING=false</code> and report any issues. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9032">#9032</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/grpc/grpc-go/commit/cb18228317ff523e63d931b4058b0329585b7dcd"><code>cb18228</code></a> Change version to 1.81.0 (<a href="https://redirect.github.com/grpc/grpc-go/issues/9062">#9062</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/96748f973e20bbfcafa19a8bdffc85ad5da138d1"><code>96748f9</code></a> Cherry-pick <a href="https://redirect.github.com/grpc/grpc-go/issues/9105">#9105</a> to 1.81.x (<a href="https://redirect.github.com/grpc/grpc-go/issues/9106">#9106</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/91832222f0144f76527b630ca55cfea6e1aa015a"><code>9183222</code></a> Cherry pick <a href="https://redirect.github.com/grpc/grpc-go/issues/9055">#9055</a>, <a href="https://redirect.github.com/grpc/grpc-go/issues/9032">#9032</a> to v1.81.x (<a href="https://redirect.github.com/grpc/grpc-go/issues/9095">#9095</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/5cba6da4211f3b130238c792937f5921741b616a"><code>5cba6da</code></a> Revert "deps: update dependencies for all modules (<a href="https://redirect.github.com/grpc/grpc-go/issues/9065">#9065</a>)" (<a href="https://redirect.github.com/grpc/grpc-go/issues/9067">#9067</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/af8a9364aa7523ab24d214e9ef13e6ad64d5c5f9"><code>af8a936</code></a> deps: update dependencies for all modules (<a href="https://redirect.github.com/grpc/grpc-go/issues/9065">#9065</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/cdc60dfaaadde45e16aa3c28237c0e655a722c1a"><code>cdc60df</code></a> transport: optimize heap allocations in ready reader and update syscall conne...</li> <li><a href="https://github.com/grpc/grpc-go/commit/208d053e3204c806ba9e6205c26aa064c8b42852"><code>208d053</code></a> xds/resolver: pass complete XDSConfig in RPC context for HTTP filters (gRFC A...</li> <li><a href="https://github.com/grpc/grpc-go/commit/50fe1cc7fd78b78ae638ed90ea78514c934167ac"><code>50fe1cc</code></a> test: Fix flaky test <code>TestServerStreaming_ClientCallRecvMsgTwice</code> in `end2end...</li> <li><a href="https://github.com/grpc/grpc-go/commit/d574bad188f25ba03d41a506e6f2ef93837ad10b"><code>d574bad</code></a> build(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 (<a href="https://redirect.github.com/grpc/grpc-go/issues/9050">#9050</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/b8bf4d0488a351c563d63797ffba321585d6bb24"><code>b8bf4d0</code></a> build(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 in /inte...</li> <li>Additional commits viewable in <a href="https://github.com/grpc/grpc-go/compare/v1.80.0...v1.81.0">compare view</a></li> </ul> </details> <br /> Updates `gopkg.in/ini.v1` from 1.67.1 to 1.67.2 Updates `github.com/fsnotify/fsnotify` from 1.9.0 to 1.10.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/fsnotify/fsnotify/releases">github.com/fsnotify/fsnotify's releases</a>.</em></p> <blockquote> <h2>v1.10.1</h2> <h3>Changes and fixes</h3> <ul> <li> <p>inotify: don't remove sibling watches sharing a path prefix (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>)</p> </li> <li> <p>inotify, windows: don't rename sibling watches sharing a path prefix (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>)</p> </li> </ul> <p><a href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/754">fsnotify/fsnotify#754</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/755">fsnotify/fsnotify#755</a></p> <h2>v1.10.0</h2> <p>This version of fsnotify needs Go 1.23.</p> <h3>Changes and fixes</h3> <ul> <li> <p>inotify: improve initialization error message (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>)</p> </li> <li> <p>inotify: send Rename event if recursive watch is renamed (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>)</p> </li> <li> <p>inotify: avoid copying event buffers when reading names (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>)</p> </li> <li> <p>kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a bad entry no longer aborts Watcher.Add for the whole directory (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>)</p> </li> <li> <p>kqueue: drop watches directly in Close() to fix a file descriptor leak when recycling watchers (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>)</p> </li> <li> <p>windows: fix nil pointer dereference in remWatch (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>)</p> </li> <li> <p>windows: lock watch field updates against concurrent WatchList to fix a race introduced in v1.9.0 (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>, <a href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>)</p> </li> </ul> <p><a href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/696">fsnotify/fsnotify#696</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/709">fsnotify/fsnotify#709</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/731">fsnotify/fsnotify#731</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/736">fsnotify/fsnotify#736</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/740">fsnotify/fsnotify#740</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/741">fsnotify/fsnotify#741</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/748">fsnotify/fsnotify#748</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/749">fsnotify/fsnotify#749</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/fsnotify/fsnotify/blob/main/CHANGELOG.md">github.com/fsnotify/fsnotify's changelog</a>.</em></p> <blockquote> <h2>1.10.1 2026-05-04</h2> <h3>Changes and fixes</h3> <ul> <li> <p>inotify: don't remove sibling watches sharing a path prefix (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>)</p> </li> <li> <p>inotify, windows: don't rename sibling watches sharing a path prefix (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>)</p> </li> </ul> <p><a href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/754">fsnotify/fsnotify#754</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/755">fsnotify/fsnotify#755</a></p> <h2>1.10.0 2026-04-30</h2> <p>This version of fsnotify needs Go 1.23.</p> <h3>Changes and fixes</h3> <ul> <li> <p>inotify: improve initialization error message (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>)</p> </li> <li> <p>inotify: send Rename event if recursive watch is renamed (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>)</p> </li> <li> <p>inotify: avoid copying event buffers when reading names (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>)</p> </li> <li> <p>kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a bad entry no longer aborts Watcher.Add for the whole directory (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>)</p> </li> <li> <p>kqueue: drop watches directly in Close() to fix a file descriptor leak when recycling watchers (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>)</p> </li> <li> <p>windows: fix nil pointer dereference in remWatch (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>)</p> </li> <li> <p>windows: lock watch field updates against concurrent WatchList to fix a race introduced in v1.9.0 (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>, <a href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>)</p> </li> </ul> <p><a href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/696">fsnotify/fsnotify#696</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/709">fsnotify/fsnotify#709</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/731">fsnotify/fsnotify#731</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/736">fsnotify/fsnotify#736</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/740">fsnotify/fsnotify#740</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/741">fsnotify/fsnotify#741</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/748">fsnotify/fsnotify#748</a> <a href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>: <a href="https://redirect.github.com/fsnotify/fsnotify/pull/749">fsnotify/fsnotify#749</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/fsnotify/fsnotify/commit/76b01a6e8f502187fecedea8b025e79e5a86085c"><code>76b01a6</code></a> Release 1.10.1</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/fec150b807510e54e5b25def4b6e5fb001b4898c"><code>fec150b</code></a> Update changelog</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/162b4216ab8f92ecd26425530bee198972c9b3cb"><code>162b421</code></a> inotify, windows: don't rename sibling watches sharing a path prefix (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>)</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/224257f23b2f3a96509b316c5cead71dd4a9099a"><code>224257f</code></a> inotify: don't remove sibling watches sharing a path prefix (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>)</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/e0c956c0ccaf51562fee30ef5c055c74e6ae2104"><code>e0c956c</code></a> windows: document directory Write events and stabilize tests (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/745">#745</a>)</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/8d01d7b9cbe0199e4a1e60fbd965fb05dbb42123"><code>8d01d7b</code></a> Release 1.10.0</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/602284e4a8cadd488d7a5fa07c48462dfac25108"><code>602284e</code></a> Update changelog</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/7f03e59f9659552d8a084e03024cb9b983748ed7"><code>7f03e59</code></a> kqueue: skip ENOENT entries in watchDirectoryFiles (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>)</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/dab9dde2fc9ba4d0c1076318f81cabcc8fdb2ec9"><code>dab9dde</code></a> windows: lock watch field updates against concurrent WatchList (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>) (<a href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>)</li> <li><a href="https://github.com/fsnotify/fsnotify/commit/eadf267ce152b5e62d48cc2c13bb08bd4062b6c7"><code>eadf267</code></a> kqueue: drop watches directly in Close() instead of going through remove() (#...</li> <li>Additional commits viewable in <a href="https://github.com/fsnotify/fsnotify/compare/v1.9.0...v1.10.1">compare view</a></li> </ul> </details> <br /> Updates `github.com/huandu/go-sqlbuilder` from 1.40.2 to 1.41.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/huandu/go-sqlbuilder/releases">github.com/huandu/go-sqlbuilder's releases</a>.</em></p> <blockquote> <h2>v1.41.0</h2> <ul> <li><code>[NEW]</code> Add an option <code>NoExpand</code> to change default field "expand" behavior for backward compatibility. See <a href="https://redirect.github.com/huandu/go-sqlbuilder/issues/237">#237</a> for details.</li> </ul> <p>NOTE: Starting from v1.40.0, the <code>Struct</code> utility type defaults to expanding non-primitive struct fields. This change caused unexpected behavior for some users. To address this without reverting the features introduced in v1.40.0, we have introduced a <code>NoExpand </code>configuration. When set to true, all fields will default to no expansion (preserving legacy behavior). You can still opt-in to expansion for specific fields by using the <code>fieldopt:"expand"</code> tag.</p> <p><strong>Full Changelog</strong>: <a href="https://github.com/huandu/go-sqlbuilder/compare/v1.40.0...v1.41.0">https://github.com/huandu/go-sqlbuilder/compare/v1.40.0...v1.41.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/huandu/go-sqlbuilder/commit/44837218602c8f96eac9f27411d5b93a20dc979d"><code>4483721</code></a> fix <a href="https://redirect.github.com/huandu/go-sqlbuilder/issues/237">#237</a>: add option <code>NoExpand</code> to control default field "expand" behavior</li> <li>See full diff in <a href="https://github.com/huandu/go-sqlbuilder/compare/v1.40.2...v1.41.0">compare view</a></li> </ul> </details> <br /> Updates `github.com/lestrrat-go/jwx/v3` from 3.1.0 to 3.1.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/lestrrat-go/jwx/releases">github.com/lestrrat-go/jwx/v3's releases</a>.</em></p> <blockquote> <h2>v3.1.1</h2> <p>For more detailed release notes, see <a href="https://github.com/lestrrat-go/jwx/blob/v3.1.1/Changes">Changes</a>.</p> <h2>What's Changed</h2> <ul> <li>build(deps): bump pozil/auto-assign-issue from 2.2.0 to 2.2.1 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2045">lestrrat-go/jwx#2045</a></li> <li>guard ecdsa coordinates against oversized big.Int by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2050">lestrrat-go/jwx#2050</a></li> <li>reject jwe with conflicting alg in protected vs per-recipient by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2052">lestrrat-go/jwx#2052</a></li> <li>fix AddressClaim.MarshalJSON for non-printable bytes by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2056">lestrrat-go/jwx#2056</a></li> <li>jwt: only call ParseForm when WithFormKey is supplied by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2058">lestrrat-go/jwx#2058</a></li> <li>jws: jkuProvider rejects fetched keys marked use=enc by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2060">lestrrat-go/jwx#2060</a></li> <li>jwa: unify SignatureAlgorithm/KeyEncryption/ContentEncryption into one registry by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2066">lestrrat-go/jwx#2066</a></li> <li>build(deps): bump pozil/auto-assign-issue from f245a9119ba5cc2fed4aa7b8268d576d40acddf0 to 7bf9d82c77d45976224660b873fc83e60576c5aa by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2065">lestrrat-go/jwx#2065</a></li> <li>cmd/jwx: warn on private-key-to-tty + reject keysize<=0 for oct by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2071">lestrrat-go/jwx#2071</a></li> <li>jws: refuse "b64" header in VerifyCompactFast by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2081">lestrrat-go/jwx#2081</a></li> <li>jws: VerifyCompactFast refusals match jws.VerifyError() class by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2083">lestrrat-go/jwx#2083</a></li> <li>jws: name loose keySet options in fan-out verify error by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2085">lestrrat-go/jwx#2085</a></li> <li>jws: honor RFC 7797 b64=false in Message.MarshalJSON by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2087">lestrrat-go/jwx#2087</a></li> <li>jws: reject literal-JSON "protected" in general-form JWS by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2089">lestrrat-go/jwx#2089</a></li> <li>jwt: ParseRequest: don't skip form body on chunked transfer by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2091">lestrrat-go/jwx#2091</a></li> <li>jwt: pedantic mode enforces cty=JWT nested-envelope shape by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2094">lestrrat-go/jwx#2094</a></li> <li>jwt: defensively reject missing claims in MaxDeltaIs / MinDeltaIs by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2099">lestrrat-go/jwx#2099</a></li> <li>jwt: ParseInsecure: parse loop-local payload, not original input by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2097">lestrrat-go/jwx#2097</a></li> <li>jws: Verify rejects b64=false without "b64" listed in "crit" by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2102">lestrrat-go/jwx#2102</a></li> <li>jws: Sign auto-declares "b64" in "crit" when emitting b64=false by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2104">lestrrat-go/jwx#2104</a></li> <li>jws: declare "b64" as typed bool header field by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2106">lestrrat-go/jwx#2106</a></li> <li>jws: reject general-form JWS with top-level "header" sibling of "signatures" by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2108">lestrrat-go/jwx#2108</a></li> <li>jws: typed sentinel for AlgorithmsForKey unclassifiable-key failures by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> in <a href="https://redirect.github.com/lestrrat-go/jwx/pull/2110">lestrrat-go/jwx#2110</a></li> <li>jws: VerifyMessage observes ctx cancellation between loop iterations by <a href="https://github.com/lestrrat"><code>@lestrrat</code></a> i... _Description has been truncated_ --------- Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Johan Fylling <johan.dev@fylling.se> Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Johan Fylling <johan.dev@fylling.se> Co-authored-by: Stephan Renatus <stephan.renatus@gmail.com> |
||
|
|
cb54e9c14f |
runtime: rule labels metadata processing follow-ups (#8613)
❗ We now parse rego metadata annotations by default. Rule annotations now support a `labels` field. During policy eval, labels from all successfully evaluated rules are collected and included in each decision log entry as a top-level `rule_labels` array. Each element preserves the label map from one evaluated rule. Exact duplicates are omitted. ```rego # METADATA # labels: # severity: low # team: platform allow if input.role == "admin" ``` The resulting decision log entry will contain: ```json {"rule_labels": [{"severity": "low", "team": "platform"}]} ``` --------- Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com> |
||
|
|
81987eebe4 |
fix: populate modules from bundles for coverage reporting in bundle mode (#8496)
resolve: https://github.com/open-policy-agent/opa/issues/3324 When running `opa test -c -b`, the coverage reporter received nil modules because cmd/test.go only populated the modules variable in the file-loading branch. This caused cover.Report() to skip the NotCovered walk, resulting in 100% coverage regardless of actual test coverage. Extract modules from bundles via ParsedModules() when both bundle mode and coverage are enabled, so the coverage reporter can correctly identify uncovered lines. Tested the change locally as well with the steps in the issue. Signed-off-by: Sebastian Spaink <sebastianspaink@gmail.com> |
||
|
|
40024cebd6 |
ast: not-body marshaling (#8614)
JSON- and pretty format marshaling of `ast.Not` Signed-off-by: Johan Fylling <johan.dev@fylling.se> |
||
|
|
b6c3ac1860 |
ast: Enable future.keywords.not in default capabilities (#8609)
Signed-off-by: Johan Fylling <johan.dev@fylling.se> |
||
|
|
4209e6a133 |
Support recursive JSON Schemas (#8542)
* Support recursive JSON Schemas Signed-off-by: Sebastian Spaink <sebastianspaink@gmail.com> * refactor tests to table-driven Signed-off-by: Sebastian Spaink <sebastianspaink@gmail.com> --------- Signed-off-by: Sebastian Spaink <sebastianspaink@gmail.com> |
||
|
|
edab2a5f3c |
Update opa test to stream test case results (#8517)
Signed-off-by: Sebastian Spaink <sebastianspaink@gmail.com> |
||
|
|
670d2e2556 |
ast, topdown: Add not AST node type (#8427)
Disabled by default. To enable, `not` future keyword must be present in capabilities and imported into Rego module. Implements: #8391 Signed-off-by: Johan Fylling <johan.dev@fylling.se> |
||
|
|
d0041c64d9 |
runtime+server: logger plugins (#8434)
This PR brings support for pluggable logging implementations via the logger plugin interface, which is based on Go's standard log/slog.Handler interface. This allows any slog.Handler implementation to be used as a logger plugin. Loggers can be referenced via the server.logger_plugin configuration option; and can also be used for decision logs. OPA includes a built-in file logger plugin (file_logger) that writes structured JSON logs with rotation support using lumberjack. Users can also implement and register custom logger plugins when building OPA. Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com> |
||
|
|
446f836c39 |
test: Extract runtime Info to new package (#8362)
This will allow Go SDK users to access this previously internal package. Signed-off-by: Charlie Egan <charlie_egan@apple.com> |
||
|
|
f71e693a9c |
Add line number next to test file in pretty format
Signed-off-by: Sebastian Spaink <sebastianspaink@gmail.com> |
||
|
|
0d7e509613 |
ci: bump golangci-lint (v2.9.0), fix issues
https://github.com/golangci/golangci-lint/releases/tag/v2.9.0 Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com> |
||
|
|
3c3cc9c6f6 |
Preserve original package name with special characters in optimized builds (#8296)
Signed-off-by: Sebastian Spaink <sebastianspaink@gmail.com> |
||
|
|
b29b1dad76 |
docs/website: Markdown linting and spell checking for documentation (#8292)
* Add markdownlint tooling to docs Install markdownlint-cli2 with configuration file and make targets for auto fix etc too. Signed-off-by: Charlie Egan <charlie_egan@apple.com> * Autofixable markdown issues mainly, replace tabs with spaces for consistent 2-space indentation Signed-off-by: Charlie Egan <charlie_egan@apple.com> * MD059 Signed-off-by: Charlie Egan <charlie_egan@apple.com> * Fix a number of <link> issues Signed-off-by: Charlie Egan <charlie_egan@apple.com> * MD041 Signed-off-by: Charlie Egan <charlie_egan@apple.com> * MD041 Signed-off-by: Charlie Egan <charlie_egan@apple.com> * MD046 Signed-off-by: Charlie Egan <charlie_egan@apple.com> * MD025 Signed-off-by: Charlie Egan <charlie_egan@apple.com> * MD052 Signed-off-by: Charlie Egan <charlie_egan@apple.com> * MD028 Signed-off-by: Charlie Egan <charlie_egan@apple.com> * MD001 Signed-off-by: Charlie Egan <charlie_egan@apple.com> * Add GH action check in PRs Signed-off-by: Charlie Egan <charlie_egan@apple.com> * Use 4 spaces for tabs Signed-off-by: Charlie Egan <charlie_egan@apple.com> * Use 4 spaces for tabs Signed-off-by: Charlie Egan <charlie_egan@apple.com> * docs: Add spell checking using Vale Signed-off-by: Charlie Egan <charlie_egan@apple.com> * Correct comment for space indentation rule Signed-off-by: Charlie Egan <charlie_egan@apple.com> --------- Signed-off-by: Charlie Egan <charlie_egan@apple.com> |
||
|
|
a87219e6cd |
Enable sorting JSON test results by duration (#8260)
Fixes #7444 Signed-off-by: Sebastian Spaink <sebastianspaink@gmail.com> |
||
|
|
3ede316faa |
feat: do not overwrite file on fmt without changes (#8223)
* feat: do not overwrite file on fmt without changes When no changes are detected, avoid unnecessary rewrite. It also help fmt CI tools not to see modified files like treefmt Signed-off-by: Loïc Rosso <37541460+Loic-R@users.noreply.github.com> * chore: add tests Signed-off-by: Loïc Rosso <37541460+Loic-R@users.noreply.github.com> * chore: fix tests by adding 2 sec sleep time Signed-off-by: Loïc Rosso <37541460+Loic-R@users.noreply.github.com> * chore: reduce sleep time, add permission check and better naming Co-authored-by: Charlie Egan <charlie_egan@apple.com> Signed-off-by: Loïc Rosso <37541460+Loic-R@users.noreply.github.com> --------- Signed-off-by: Loïc Rosso <37541460+Loic-R@users.noreply.github.com> Co-authored-by: Charlie Egan <charlie_egan@apple.com> |
||
|
|
6601188c64 |
runtime: Correct naming & docs for version checking (#8191)
* runtime: Correct naming of version checking code Rename telemetry functionality to version checking to accurately reflect current behavior following https://github.com/open-policy-agent/opa/pull/7756. The system only checks GitHub releases for version updates without sending any data about the OPA instance and so the privacy docs have been updated too. Signed-off-by: Charlie Egan <charlie_egan@apple.com> * Make WithTelemetryGatherers a no-op Deprecate WithTelemetryGatherers since telemetry gathering has been removed. The function now returns a no-op to maintain API compatibility without breaking existing code that might uses it. Signed-off-by: Charlie Egan <charlie_egan@apple.com> --------- Signed-off-by: Charlie Egan <charlie_egan@apple.com> |
||
|
|
8e410b830a |
String interpolation (#8109)
Adding string interpolation support to the Rego language. An interpolated string is composed of a template-string that can contain zero or more template-expressions that interpolates values into the string generated at eval-time. Requires the `template_strings` capability feature and `internal.template_string` built-in function. Implements: #4733 |
||
|
|
d82c21c9d3 |
cmd: Support --ignore in eval cmd when using bundle flag (-b) (#8062)
Signed-off-by: Sebastian Spaink <sebastianspaink@gmail.com> Co-authored-by: Ronnie-personal <76408835+Ronnie-personal@users.noreply.github.com> |
||
|
|
d3f34a3387 |
Modernize analyzer fixes (#7965)
Have done this some time in the past, but there was a few new issues this would highlight now that we're on Go 1.24. Mostly: - Use `b.Loop()` in benchmarks - Use `strings.SplitSeq` where possible - Remove `omitempty` tag for types that can't be empty Signed-off-by: Anders Eknert <anders@eknert.com> |
||
|
|
e048c1984d |
add opa test --fail-on-empty to allow making bad -r or empty folders fail (#7960)
Signed-off-by: Michael Grosser <michael@grosser.it> |
||
|
|
2cc948d872 |
TLM: Upgrade to v1 tablewriter (#7937)
- Updated test fixtures and various test fixes. Signed-off-by: Jacob Hochstetler <jacob.hochstetler@gmail.com> |
||
|
|
e1e2bfb876 |
Some small improvements to inmem storage (#7944)
Mainly making transactions cheaper to create, and read transactions much cheaper. - Add exported RootPath shorthand var - Don't return path on ParsePathEscaped failure - Allocate nothing for read transactions, other than the transaction itself - Lazy init of write update collections to avoid needless allocations - Add benchmarks **Before** ``` BenchmarkNewTransaction/Read-16 26707234 44.78 ns/op 144 B/op 3 allocs/op BenchmarkNewTransaction/Write-16 20344212 59.44 ns/op 192 B/op 4 allocs/op BenchmarkReadOne/Go_store_(roundtrip)-16 21963003 54.41 ns/op 144 B/op 3 allocs/op BenchmarkReadOne/Go_store_(no_roundtrip)-16 22217593 54.18 ns/op 144 B/op 3 allocs/op BenchmarkReadOne/AST_store_(roundtrip)-16 15626653 76.52 ns/op 160 B/op 4 allocs/op BenchmarkReadOne/AST_store_(no_roundtrip)-16 15820837 76.15 ns/op 160 B/op 4 allocs/op ``` **After** ``` BenchmarkNewTransaction/Read-16 68091271 17.37 ns/op 48 B/op 1 allocs/op BenchmarkNewTransaction/Write-16 24928028 47.68 ns/op 144 B/op 3 allocs/op BenchmarkReadOne/Go_store_(roundtrip)-16 42967630 28.10 ns/op 48 B/op 1 allocs/op BenchmarkReadOne/Go_store_(no_roundtrip)-16 43825009 27.63 ns/op 48 B/op 1 allocs/op BenchmarkReadOne/AST_store_(roundtrip)-16 24885938 48.06 ns/op 64 B/op 2 allocs/op BenchmarkReadOne/AST_store_(no_roundtrip)-16 25012396 47.96 ns/op 64 B/op 2 allocs/op ``` Signed-off-by: Anders Eknert <anders@eknert.com> |
||
|
|
7e4a0202c4 |
plugins/bundle: return callback error (#7871)
Updates the Bundle Plugins oneShot callback function signature used by Downloader, OCIDownloader, and fileLoader to return an error. This allows any issues in the callback function such as Rego parsing issues to be returned. Signed-off-by: Sebastian Spaink <sebastianspaink@gmail.com> |
||
|
|
d102e453e5 |
fix: print eval errors to stderr (#7880)
updated the presentation package print functions to accept a parameter to print to stderr. Signed-off-by: Sebastian Spaink <sebastianspaink@gmail.com> |
||
|
|
184d1b553f |
ci: port binary tests to testscript
The assertions are stricter now, e.g. we're also checking that nothing is emitted to stderr. Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com> |
||
|
|
46c9c3b5ed |
cmd/exec: Update tests to run sync when ready (#7835)
Following: open-policy-agent#7821 I think we can avoid using the async running of exec when we know the bundle server is ready to go. I saw some more issues from these tests in https://github.com/open-policy-agent/opa/actions/runs/16905415883/job/47894071103?pr=7825 and am trying to make them more reliable this way. Signed-off-by: Charlie Egan <charlieegan3@users.noreply.github.com> Co-authored-by: Charlie Egan <charlieegan3@users.noreply.github.com> |
||
|
|
9de558575a |
cli: fix 'opa exec' parameters
This also adds a new test step running all testscript txtar archives on all platforms. Our existing lo-fi binary smoke tests should move to that eventually. Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com> |
||
|
|
f77322b3fb |
build: bump Go version requirement to 1.24 (#7839)
Go 1.23 is no longer supported as per Go release policy. Changes: - Use Go v1.24.6 as the project SDK requirement - Apply lint fixes for Go 1.24 - Fix "non-constant format string in call" issues as seen in CI. Signed-off-by: Ville Vesilehto <ville@vesilehto.fi> |
||
|
|
6b8b88719d |
cmd: Exec test wait for bundle server to start (#7821)
I saw this error: https://github.com/open-policy-agent/opa/actions/runs/16743346393/job/47396197626#step:6:28 Where the bundle server for the broken bundle was not ready before the exec ran. This results in a different error message than the one in the test and so the test fails. We are trying to test what happens when there is a broken bundle, not what happens when the bundle server is unready, so I've added a wait. Signed-off-by: Charlie Egan <charlie@styra.com> |
||
|
|
47e2b74dda |
cmd/parse: Move accidental pkg var to local var. (#7813)
This commit moves an accidental package-level definition of the `opa parse` CLI subcommand to a local variable inside the `initParse` function, similar to how we do command initialization for all other OPA CLI subcommands. Before this change, it was possible to see panics from the package variable `cobra.Command` in `parse.go` having some of its flags redefined. This fix makes it possible for `make generate-cli-docs` to run without error again. Signed-off-by: Philip Conrad <philip@chariot-chaser.net> |
||
|
|
84b23ccedd |
bugfix: Add back default cmd.RootCommand definition. (#7811)
This commit fixes an issue when upgrading codebases to OPA v1.7.0. In PR #7797, we introduced the ability to provide "branding" information in OPA commands and help messages, which would allow easier customized OPA distributions in the future. However, this changeset removed the public symbol `cmd.RootCommand`, and required refactoring to use `cmd.Command`, which breaks automated upgrades, such as those done by Dependabot. This PR adds back the missing symbol, with the original/default "OPA" branding provided. This should allow existing codebases to upgrade without requiring any code changes. Signed-off-by: Philip Conrad <philip@chariot-chaser.net> |
||
|
|
ef9b6c8289 |
build: Show a warning when .manifest is ignored (#7807)
-b must be set for the user defined manifest to be used. Related to https://github.com/open-policy-agent/opa/issues/7806 Signed-off-by: Charlie Egan <charlie@styra.com> |
||
|
|
4c13c6cc9f |
perf: AST compiler optimizations (#7740)
Funnily, this started out as an attempt to look into issues reported with compiling large policy sets... before I realized that it isn't likely *this* compiler that has perf issues, but the one that "compiles" bundles as part of activation. So while these fixes likely does little to address that, there are still some rather nice improvements here, where the big ones as ususal are mostly just wins from avoiding work where it's possible. For benchmarking I've used Regal's embedded bundle, which isn't great to use over time, as it's a moving target. But since it's a pretty extensive bundle and one that covers most features of OPA, it's at least good for 1:1 comparisons when testing perf improvements. ``` // 66555594 ns/op 50239492 B/op 1083664 allocs/op - main // 62569440 ns/op 38723015 B/op 944277 allocs/op - compiler-optimizations pr ``` The B/op / alloc_space improvement is particularly nice here. What's noteworthy is how relatively little impact that has on performance in this case. That may be surprising but aligns pretty well with my previous experience of Go code where a lot of time is spend in recursive walks — that simply takes time, no matter how much you optimize. Oh well, less memory allocated for this is more memory to spend elsewhere. (I'm adding the benchmark used below to Regal in a parallel PR) Signed-off-by: Anders Eknert <anders@styra.com> |
||
|
|
94a953150a |
cmd: allow branding
This change allows users that build their own executable or "spin" of OPA to give it a name, and have it reference itself properly in help texts. It's a vanity thing, but I think some people would appreciate it, hat tip to the international association of pedants. Signed-off-by: Stephan Renatus <stephan@styra.com> Co-authored-by: kevinstyra <83973046+kevinstyra@users.noreply.github.com> |
||
|
|
52381423d3 |
test+eval: add helper to smuggle compiler through context
Signed-off-by: Stephan Renatus <stephan@styra.com> |
||
|
|
e3f6be6c22 |
cmd: use regoError to carry compiler errors into CLI machinery
Signed-off-by: Stephan Renatus <stephan@styra.com> |
||
|
|
36bae2aac6 |
cmd: use command.RunE to return errors and perform orderly shutdown of OPA
`os.Exit` immediately exits the program and doesn't run defer functions. This can be problematic as any command.OnFinalize routines and any logic after the command.Execute won't be run. Also suppress all RunE cobra error and usage messages. These would be printed twice otherwise. Signed-off-by: Stephan Renatus <stephan@styra.com> Co-authored-by: Kevin St. Pierre <kevin@styra.com> |
||
|
|
5a872a4166 |
bundle: Add support for bundle store and activation plugins. (#7771)
This commit adds support for changing out how bundle storage and activation work. To allow swapping out bundle activation, two new `bundle` package functions are provided: - `RegisterActivator`: Registers a bundle.Activator with a string ID. - `RegisterDefaultBundleActivator`: Sets the default bundle.Activator to use by ID. Behind the scenes, a few new `bundle` package variables are used to track what bundle activators are available, and which is the preferred default. This system allows registering many activators, and allows choosing the bundle activator to use at activation time. The activator to use is decided in the following order: - `(bundle.ActivateOpts).Plugin` is used when non-nil. - `bundle.bundleExtActivator` is used when an ID was set with `RegisterDefaultBundleActivator`. - The default/original bundle activator is used if no other selection was made. To support swapping out bundle storage (useful when testing new bundle designs), a new `bundle` package function is provided: - `RegisterStoreFunc`: Sets the function to use for creating bundle storage. These two features together allow swapping out most of the bundle activation flow, without requiring deep modification of the `bundle` package. Lazy bundle loading mode is also enabled across many CLI commands and other bundle loading points now when a non-default bundle activator is set. Signed-off-by: Philip Conrad <philip@chariot-chaser.net> Co-authored-by: Ashutosh Narkar <anarkar4387@gmail.com> |
||
|
|
70e5ad126b |
loader+internal: Add bundle lazy loading mode across the runtime. (#7768)
This commit comprehensively plumbs in the bundle lazy loading mode option in the compile, runtime, rego, and bundle packages. It also includes the bare minimum plumbing to allow the path watcher utilities to also toggle the option on. In nearly all places where a default is expected, the lazy loading mode is set to false (disabled) to avoid behavior changes. Signed-off-by: Philip Conrad <philip@chariot-chaser.net> |
||
|
|
6aa579de3f |
cmd: only plumb through target if it was set
allowing the default to be changed by a rego target plugin. Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com> |
||
|
|
334666355a |
opa exec: stop plugins before exit
This allows certain plugins to do their cleanup routines -- like sending decision logs to some other location when using a custom decision log setup. Signed-off-by: Stephan Renatus <stephan@styra.com> |
||
|
|
9a423eceab |
report: Fetching latest OPA release version from GH (#7756)
instead of telemetry server. Signed-off-by: Johan Fylling <johan.dev@fylling.se> |
||
|
|
817b6635a8 |
ast,format: Allowing keywords in Rego references (#7709)
Updating the parser and formatter to allow keywords in refs. Signed-off-by: Johan Fylling <johan.dev@fylling.se> |
||
|
|
3f857572a0 |
inspect: Fixing missing annotations location in opa inspect with JSON format (#7727)
Fixing: #7459 Signed-off-by: Johan Fylling <johan.dev@fylling.se> |
||
|
|
78a5ca2ab4 |
Simplify interning (#7714)
Use a single generic entrypoint for obtaining interned terms regardless of type. Signed-off-by: Anders Eknert <anders@styra.com> |
||
|
|
d2a415e25d |
opa check --bundle report virtual/base doc conflicts (#7701)
A tiny first step to have more tooling correctly report virtual and base document conflicts, as detailed in #7694. This PR fixes the `opa check` command to report conflicts of this type when the `-b`/`--bundle` flag is provided. The bundle flag is required as without that, `opa check` should only verify policies and not load data at all. While I was in the `cmd` directory, I got annoyed with how many of these commands store the same constants for their `--format` flag, so I decided to fix that too, even if it wasn't related to what I originally planned to do. I hope it's not too distracting. Signed-off-by: Anders Eknert <anders@styra.com> |
||
|
|
6f56689172 |
opa/test: run tests in parallel (#7640)
new "-p, --parallel" flag that sets how many tests can be run in parallel, which defaults to the number of CPUs Signed-off-by: sspaink <sspaink@styra.com> |
||
|
|
82b9afe7cc |
cmd/parse: expose --v0-compatible flag (#7668)
Signed-off-by: Torin Sandall <torin@styra.com> |