Repository navigation
chore(deps): consolidate this week's grouped Dependabot updates (2026-09-24) - #4351
Conversation
390725c to
48351d9
Compare
|
I went through this locally. Everything checks out except one behaviour change in the OTLP HTTP metrics exporter. Blocking: OTLP-over-HTTP metrics go to the wrong pathMoving the otel exporters from v1.44 to v1.46 pulls in a documented breaking change from otel v1.45 (open-telemetry/opentelemetry-go#8538). I ran the same test on
Anyone using a path-less URL would have every export rejected by the collector after upgrading, and nothing fails at startup. CI doesn't catch it because the existing test rows only use URLs that already end in There are two ways to fix it:
Traces aren't affected, since only the gRPC trace exporter is used. Checked and fine
Minor
|
Consolidates the remaining grouped Dependabot PRs (azure-sdk, google, opentelemetry, golang-x, go-deps) on top of the already-merged aws-sdk group (#4337). Applied per-module (go get + go mod tidy per go.mod), no go work sync. grpc is deliberately HELD at v1.83.2 (not the v1.84.0 Dependabot proposed): v1.84.0 is affected by GO-2026-6443 (server panic via missing :authority/Host headers), whose fix was backported to v1.83.2 but is not in v1.84.0. No other bumped dependency requires v1.84.0. Keeps the OTLP/HTTP metrics signal path across the otel bump. otlpmetrichttp appended /v1/metrics itself until otel v1.45 (open-telemetry/opentelemetry-go#8538); after it, a path-less METRICS_URL (http://host:4318) posted to "/" and the collector rejected every export, with nothing failing at startup. metrics exporters/otlp.go now re-appends /v1/metrics for a scheme-bearing HTTP endpoint that carries no path of its own, restoring the pre-v1.45 behavior; an explicit path is left untouched. Regression test covers the path-less case the existing table missed. Regenerates the arango mock: go-driver/v2 2.3.1 -> 2.4.1 added IndexesWithOptions to the Collection interface (mockgen against v2.4.1, $GOMODCACHE-form header). Refreshes the stale gofr.dev pin (v1.57.0 -> v1.60.1) in examples using-add-filestore, using-cloudsql, using-s3-filestore and in the dbresolver and oracle submodules, so they build standalone (GOWORK=off) again. Workspace builds are unaffected (go.work uses the local root). Closes: #4338, #4339, #4340, #4341, #4342 Co-Authored-By: claude-flow <ruv@ruv.net>
7efb283 to
62bbb27
Compare
5e648cb to
05d7aff
Compare
NitinKumar004
left a comment
There was a problem hiding this comment.
Re-reviewed after the latest push. All three points from my earlier comment are addressed:
- OTLP HTTP signal path: a path-less
METRICS_URL(http://host:4318) posts to/v1/metricsagain, the same as ondevelopment. URLs that already carry a path are left as written. I removed the fix locally and the newpath-lesstest row fails, so the test really guards it. mock_collection.goheader: back to$GOMODCACHE.- dbresolver / oracle: now pinned to
gofr.dev v1.60.1, and both build and vet withGOWORK=off, with go.mod tidy.
The exporter tests pass with -race, and the full lint shows nothing new; the gofr-framework goconst warning also exists on development. CI is green.
Small nits, not blocking:
- the new tests could go into the existing
otlp_test.goand uset.Context(); - the configs docs could mention that
/v1/metricsis added for a path-less HTTP URL.
LGTM.
aryanmehrotra
left a comment
There was a problem hiding this comment.
Re-reviewed at 11e2658 (approval at b9b1695 was dismissed by the development merge).
Verified: all direct bumps from #4338–#4342 landed at Dependabot's versions except the intentional grpc hold (GO-2026-6443: fixed in 1.83.2, affected in 1.84.0 — correct call). Per-module GOWORK=off tidy -diff / build / vet / test clean across all 22 changed modules. The OTLP path fix matches otlpmetrichttp@v1.46.0 oconf/options.go:298 (empty path → "/"); disabling the fix turns Test_buildOTLPExporter_HTTPPathLessURLKeepsSignalPath red, so the guard bites. Traces are gRPC-only, so they are unaffected.
Two small things, non-blocking:
- The gofr.dev self-pin bumps from #4342 (→ v1.61.0, tagged 2026-09-17 and on grpc v1.83.2) were dropped, and the body's "v1.60.1, latest release" is out of date. 7 submodules stay on v1.57.0 (file/azure, ftp, gcs, s3, sftp, pubsub/eventhub, nats, sqs) while dbresolver/oracle/gcp exporters/examples are on v1.60.1. The example pins for file/ftp v0.2.5 and file/s3 v0.4.0 were dropped too. With #4342 closed, nothing tracks these any more. Either bump them here or say in the body that they're deferred.
- pkg/gofr/datasource/cloudsql/go.mod: google.golang.org/api goes 0.298.0 → 0.297.0 (indirect). Looks like the development merge kept the branch's line over #4294's bump. tidy won't flag it, since tidy never raises versions.
Resolved the rename/modify conflict on mock_collection_test.go by regenerating it with mockgen v0.6.0 against go-driver v2.4.1 (dev's bump in gofr-dev#4351), which carries IndexesWithOptions into the test-only mock.
Consolidates the remaining grouped Dependabot PRs into one change on top of the already-merged aws-sdk group (#4337). Applied per-module (
go get+go mod tidyper go.mod; nogo work sync).Dependabot proposed grpc v1.84.0, but that release is affected by GO-2026-6443 (server panic via missing
:authority/Hostheaders, govulncheck-reachable through GoFr's HTTP/2 transport). The fix was backported to v1.83.2 but is not in v1.84.0 (only the unreleased v1.85.0-dev). Bumping would move from a patched to an unpatched release, so grpc stays at v1.83.2. No other bumped dependency requires v1.84.0. Dependabot will re-propose once v1.85.0 ships.arango mock regen (build fix)
github.com/arangodb/go-driver/v22.3.1 → 2.4.1 addedIndexesWithOptionsto theCollectioninterface;mock_collection.gowas regenerated with mockgen against v2.4.1 (only non-dep file in this PR).Updates
Verified locally
go build/go vet+ per-submodule build: clean; all examplesgo vetcleangovulncheck: no dependency vulns (GO-2026-6443 avoided by holding grpc; only pre-existing Go stdlib advisories remain, same as development)Closes
#4338 (azure-sdk) · #4339 (google) · #4340 (opentelemetry) · #4341 (golang-x) · #4342 (go-deps)
🤖 Generated with claude-flow
Examples standalone build
Refreshed the stale
gofr.devpin (v1.57.0 → v1.60.1, latest release) inusing-add-filestore,using-cloudsql,using-s3-filestoreso they build standalone (GOWORK=off) again — they had drifted against the current go-redis mock. Workspace builds unaffected (go.work uses local root). All 5 replace/pinned examples now build standalone.Update (addressing @NitinKumar004's review)
WithEndpointURLauto-appending/v1/metrics, so a path-lessMETRICS_URLposted to/after the bump.metrics/exporters/otlp.gonow re-appends/v1/metricsfor a scheme-bearing HTTP endpoint with no path (explicit paths untouched; gRPC unaffected). Regression test added (httptest path assertion) — the case the existing table missed. Verified: path-less →/v1/metrics, dev was/v1/metrics, unfixed PR was/.gofr.devpin v1.57.0 → v1.60.1 so they build standalone (GOWORK=off), same as the three examples.$GOMODCACHEform (machine-independent).development(now includes fix(dgraph): commit the transaction Mutate opens #4158) into the branch.golangci-lint 0 issues, pkg/ tidy gate clean, govulncheck clean of dependency vulns, workspace + standalone builds clean.