Skip to content

chore(deps): consolidate this week's grouped Dependabot updates (2026-09-24) - #4351

Merged
aryanmehrotra merged 4 commits into
developmentfrom
deps/consolidated-2026-09-24
Sep 25, 2026
Merged

aryanmehrotra merged 4 commits into
developmentfrom
deps/consolidated-2026-09-24

Conversation

@Umang01-hash

@Umang01-hash Umang01-hash commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

Consolidates the remaining grouped Dependabot PRs into one change on top of the already-merged aws-sdk group (#4337). Applied per-module (go get + go mod tidy per go.mod; no go work sync).

⚠️ grpc held at v1.83.2 (security)

Dependabot proposed grpc v1.84.0, but that release is affected by GO-2026-6443 (server panic via missing :authority/Host headers, govulncheck-reachable through GoFr's HTTP/2 transport). The fix was backported to v1.83.2 but is not in v1.84.0 (only the unreleased v1.85.0-dev). Bumping would move from a patched to an unpatched release, so grpc stays at v1.83.2. No other bumped dependency requires v1.84.0. Dependabot will re-propose once v1.85.0 ships.

arango mock regen (build fix)

github.com/arangodb/go-driver/v2 2.3.1 → 2.4.1 added IndexesWithOptions to the Collection interface; mock_collection.go was regenerated with mockgen against v2.4.1 (only non-dep file in this PR).

Updates

Package New version
cloud.google.com/go/cloudsqlconn v1.25.2
cloud.google.com/go/pubsub v1.51.1
cloud.google.com/go/storage v1.68.0
github.com/arangodb/go-driver/v2 v2.4.1
github.com/aws/aws-sdk-go-v2 v1.47.0
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.23.1
github.com/Azure/azure-sdk-for-go/sdk/storage/azblob v1.8.1
github.com/couchbase/gocb/v2 v2.12.5
github.com/dgraph-io/badger/v4 v4.9.6
github.com/go-sql-driver/mysql v1.10.1
github.com/godror/godror v0.51.5
github.com/grpc-ecosystem/go-grpc-middleware/v2 v2.3.4
github.com/jlaffaye/ftp v0.2.4
github.com/nats-io/nats-server/v2 v2.15.0
github.com/nats-io/nats.go v1.54.0
github.com/redis/go-redis/extra/redisotel/v9 v9.22.0
github.com/XSAM/otelsql v0.44.0
go.mongodb.org/mongo-driver v1.17.10
go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace v0.71.0
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp v1.46.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.46.0
go.opentelemetry.io/otel/exporters/prometheus v0.68.0
go.opentelemetry.io/otel v1.46.0
golang.org/x/crypto v0.57.0
google.golang.org/api v0.298.0
google.golang.org/genproto/googleapis/rpc v0.0.0-20260921155816-b14227669459
modernc.org/sqlite v1.59.0

Verified locally

  • pkg/ tidy gate + root tidy: clean
  • workspace go build/go vet + per-submodule build: clean; all examples go vet clean
  • govulncheck: no dependency vulns (GO-2026-6443 avoided by holding grpc; only pre-existing Go stdlib advisories remain, same as development)
  • otel exporters (metrics signal-path + traces), arangodb, grpc/service unit tests: pass

Closes

#4338 (azure-sdk) · #4339 (google) · #4340 (opentelemetry) · #4341 (golang-x) · #4342 (go-deps)

🤖 Generated with claude-flow

Examples standalone build

Refreshed the stale gofr.dev pin (v1.57.0 → v1.60.1, latest release) in using-add-filestore, using-cloudsql, using-s3-filestore so they build standalone (GOWORK=off) again — they had drifted against the current go-redis mock. Workspace builds unaffected (go.work uses local root). All 5 replace/pinned examples now build standalone.

Update (addressing @NitinKumar004's review)

  • Blocking OTLP/HTTP metrics path fix: otel v1.45 (fix(otlptracehttp,otlpmetrichttp): do not append default signal path open-telemetry/opentelemetry-go#8538) stopped WithEndpointURL auto-appending /v1/metrics, so a path-less METRICS_URL posted to / after the bump. metrics/exporters/otlp.go now re-appends /v1/metrics for a scheme-bearing HTTP endpoint with no path (explicit paths untouched; gRPC unaffected). Regression test added (httptest path assertion) — the case the existing table missed. Verified: path-less → /v1/metrics, dev was /v1/metrics, unfixed PR was /.
  • dbresolver + oracle: refreshed stale gofr.dev pin v1.57.0 → v1.60.1 so they build standalone (GOWORK=off), same as the three examples.
  • arango mock header: regenerated with the $GOMODCACHE form (machine-independent).
  • Merged current development (now includes fix(dgraph): commit the transaction Mutate opens #4158) into the branch.

golangci-lint 0 issues, pkg/ tidy gate clean, govulncheck clean of dependency vulns, workspace + standalone builds clean.

@NitinKumar004

Copy link
Copy Markdown
Contributor

I went through this locally. Everything checks out except one behaviour change in the OTLP HTTP metrics exporter.

Blocking: OTLP-over-HTTP metrics go to the wrong path

Moving the otel exporters from v1.44 to v1.46 pulls in a documented breaking change from otel v1.45 (open-telemetry/opentelemetry-go#8538). WithEndpointURL no longer appends /v1/metrics when the URL has no path. GoFr passes METRICS_URL straight into it (pkg/gofr/metrics/exporters/otlp.go:62), and the configs doc only says "full URL for HTTP".

I ran the same test on development and on this branch, with METRICS_PROTOCOL=http and METRICS_URL=http://host:4318, and recorded the request path on an httptest server:

Request path
development (otlpmetrichttp v1.44.0) /v1/metrics
this PR (otlpmetrichttp v1.46.0) /

Anyone using a path-less URL would have every export rejected by the collector after upgrading, and nothing fails at startup. CI doesn't catch it because the existing test rows only use URLs that already end in /v1/metrics.

There are two ways to fix it:

  • Keep the old behaviour: in the HTTP branch of otlpOptions, append /v1/metrics when the parsed URL has an empty path, and add a test row for a path-less URL.
  • Accept the new behaviour: document that METRICS_URL must include /v1/metrics for HTTP (configs page + release notes).

Traces aren't affected, since only the gRPC trace exporter is used.

Checked and fine

  • CI is green on all checks.
  • All 34 modules are tidy (go mod tidy -diff), and go build / go vet are clean inside the workspace.
  • Every module also builds with GOWORK=off except dbresolver and oracle. Both fail identically on development, because they still pin gofr.dev v1.57.0 (the go-redis mock drift, missing BLMoveM). You fixed the same thing for the three examples here, so these two could get the same pin refresh.
  • Holding grpc at v1.83.2 is correct. GO-2026-6443 affects v1.84.0 and is fixed only in 1.83.2 and the unreleased 1.85.0-dev.
  • govulncheck: no vulnerable dependencies. Only standard-library advisories tied to the local Go toolchain remain.
  • go-driver v2.4.1: its only breaking change is the new IndexesWithOptions method on the interface, and the regenerated mock covers it. fix(arangodb): register metrics and return not-connected errors when Connect fails #4373 also builds and passes against v2.4.1.
  • otelsql 0.44: only changes the db.client.operation.duration histogram bucket boundaries, which is an improvement.

Minor

  • The mock_collection.go header now contains a local absolute path (/Users/.../go/pkg/mod/...) instead of $GOMODCACHE as before. It would be good to regenerate it with the $GOMODCACHE form so the header stays machine-independent.

Consolidates the remaining grouped Dependabot PRs (azure-sdk, google,
opentelemetry, golang-x, go-deps) on top of the already-merged aws-sdk
group (#4337). Applied per-module (go get + go mod tidy per go.mod), no
go work sync.

grpc is deliberately HELD at v1.83.2 (not the v1.84.0 Dependabot proposed):
v1.84.0 is affected by GO-2026-6443 (server panic via missing :authority/Host
headers), whose fix was backported to v1.83.2 but is not in v1.84.0. No other
bumped dependency requires v1.84.0.

Keeps the OTLP/HTTP metrics signal path across the otel bump. otlpmetrichttp
appended /v1/metrics itself until otel v1.45 (open-telemetry/opentelemetry-go#8538);
after it, a path-less METRICS_URL (http://host:4318) posted to "/" and the
collector rejected every export, with nothing failing at startup. metrics
exporters/otlp.go now re-appends /v1/metrics for a scheme-bearing HTTP endpoint
that carries no path of its own, restoring the pre-v1.45 behavior; an explicit
path is left untouched. Regression test covers the path-less case the existing
table missed.

Regenerates the arango mock: go-driver/v2 2.3.1 -> 2.4.1 added IndexesWithOptions
to the Collection interface (mockgen against v2.4.1, $GOMODCACHE-form header).

Refreshes the stale gofr.dev pin (v1.57.0 -> v1.60.1) in examples
using-add-filestore, using-cloudsql, using-s3-filestore and in the dbresolver
and oracle submodules, so they build standalone (GOWORK=off) again. Workspace
builds are unaffected (go.work uses the local root).

Closes: #4338, #4339, #4340, #4341, #4342

Co-Authored-By: claude-flow <ruv@ruv.net>
@Umang01-hash
Umang01-hash force-pushed the deps/consolidated-2026-09-24 branch from 7efb283 to 62bbb27 Compare September 24, 2026 10:46
@Umang01-hash
Umang01-hash force-pushed the deps/consolidated-2026-09-24 branch from 5e648cb to 05d7aff Compare September 24, 2026 10:57

@NitinKumar004 NitinKumar004 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed after the latest push. All three points from my earlier comment are addressed:

  • OTLP HTTP signal path: a path-less METRICS_URL (http://host:4318) posts to /v1/metrics again, the same as on development. URLs that already carry a path are left as written. I removed the fix locally and the new path-less test row fails, so the test really guards it.
  • mock_collection.go header: back to $GOMODCACHE.
  • dbresolver / oracle: now pinned to gofr.dev v1.60.1, and both build and vet with GOWORK=off, with go.mod tidy.

The exporter tests pass with -race, and the full lint shows nothing new; the gofr-framework goconst warning also exists on development. CI is green.

Small nits, not blocking:

  • the new tests could go into the existing otlp_test.go and use t.Context();
  • the configs docs could mention that /v1/metrics is added for a path-less HTTP URL.

LGTM.

@aryanmehrotra aryanmehrotra left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed at 11e2658 (approval at b9b1695 was dismissed by the development merge).

Verified: all direct bumps from #4338–#4342 landed at Dependabot's versions except the intentional grpc hold (GO-2026-6443: fixed in 1.83.2, affected in 1.84.0 — correct call). Per-module GOWORK=off tidy -diff / build / vet / test clean across all 22 changed modules. The OTLP path fix matches otlpmetrichttp@v1.46.0 oconf/options.go:298 (empty path → "/"); disabling the fix turns Test_buildOTLPExporter_HTTPPathLessURLKeepsSignalPath red, so the guard bites. Traces are gRPC-only, so they are unaffected.

Two small things, non-blocking:

  1. The gofr.dev self-pin bumps from #4342 (→ v1.61.0, tagged 2026-09-17 and on grpc v1.83.2) were dropped, and the body's "v1.60.1, latest release" is out of date. 7 submodules stay on v1.57.0 (file/azure, ftp, gcs, s3, sftp, pubsub/eventhub, nats, sqs) while dbresolver/oracle/gcp exporters/examples are on v1.60.1. The example pins for file/ftp v0.2.5 and file/s3 v0.4.0 were dropped too. With #4342 closed, nothing tracks these any more. Either bump them here or say in the body that they're deferred.
  2. pkg/gofr/datasource/cloudsql/go.mod: google.golang.org/api goes 0.298.0 → 0.297.0 (indirect). Looks like the development merge kept the branch's line over #4294's bump. tidy won't flag it, since tidy never raises versions.

@aryanmehrotra
aryanmehrotra merged commit 8bea1f8 into development Sep 25, 2026
34 checks passed
@aryanmehrotra
aryanmehrotra deleted the deps/consolidated-2026-09-24 branch September 25, 2026 08:26
NitinKumar004 added a commit to NitinKumar004/gofr that referenced this pull request Sep 25, 2026
Resolved the rename/modify conflict on mock_collection_test.go by regenerating it with mockgen v0.6.0 against
go-driver v2.4.1 (dev's bump in gofr-dev#4351), which carries IndexesWithOptions into the test-only mock.
@aryanmehrotra aryanmehrotra mentioned this pull request Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants