Skip to content

build(deps): bump the root dependencies and point the examples at v1.11.8 - #330

Merged
Jaro-c merged 1 commit into
developfrom
build/deps-2026-09-07
Sep 7, 2026
Merged

Jaro-c merged 1 commit into
developfrom
build/deps-2026-09-07

Conversation

@Jaro-c

@Jaro-c Jaro-c commented Sep 7, 2026

Copy link
Copy Markdown
Member

Supersedes #281, #282, #283 and #284. Closing those four in favour of this one.

They had been open since 2026-08-17, and two of them would have landed a repository that was already behind on the day it merged: #281 proposes golang.org/x/crypto v0.55.0 when v0.56.0 is out, and #284 pins the nine examples to authcore v1.11.7 when v1.11.8 shipped this morning. Re-landing the same four bumps at the versions that are actually current costs one branch and avoids merging a correction that needs correcting.

What moves

Root, still five direct dependencies:

Module From To
golang.org/x/crypto v0.54.0 v0.56.0
golang.org/x/net v0.57.0 v0.58.0
golang.org/x/text v0.40.0 v0.41.0

Examples: authcore v1.11.6 to v1.11.8 in all nine, and gofiber/fiber/v3 v3.4.0 to v3.5.0 in the fiber example, which carries fasthttp, klauspost/compress and mattn/go-isatty with it. gin was already on v1.12.0, the current release.

What I measured

Check Result
govulncheck ./... exit 0, No vulnerabilities found
go test -race ./... 9/9 packages pass
Nine examples, go build && go vet 9/9 pass, one package each
go directive, all 11 module files untouched at 1.26.6

One latent entry remains, in a module I require but do not call: the standing GO-2026-5932 advisory that x/crypto/openpgp is unmaintained and unsafe by design, Fixed in: N/A, applying to every version of the module since 0. Nothing here imports openpgp.

Three files this deliberately does not add

go mod tidy under GOWORK=off wrote a go.sum into the apikey, basic and username examples, which have never carried one. Those three depend on nothing but authcore, and the workspace resolves it from the checkout, so there is no hash to record. I deleted them and confirmed all three still build and vet. Committing them would add three files that every future bump has to keep in step, which is the coupling the workspace removed.

Release

This changes a dependency floor, which the releases standard counts as something a consumer receives, so it wants a tag rather than sitting on develop. It is not urgent the way #328 was: govulncheck was already clean at v1.11.8, so nothing here closes an open advisory.

…11.8

Supersedes #281, #282, #283 and #284, which had gone stale sitting open
since 2026-08-17.

Two of them would have landed a repository that was already behind on
the day it merged. #281 proposed `golang.org/x/crypto` v0.55.0 and
v0.56.0 is out; #284 pinned the nine examples to `authcore` v1.11.7 and
v1.11.8 shipped this morning. Re-landing the same four bumps at the
versions that are actually current costs one branch and avoids merging a
correction that needs correcting.

Root, five direct dependencies as before:

- `golang.org/x/crypto` v0.54.0 to v0.56.0
- `golang.org/x/net` v0.57.0 to v0.58.0
- `golang.org/x/text` v0.40.0 to v0.41.0

Examples: `authcore` v1.11.6 to v1.11.8 in all nine, and
`gofiber/fiber/v3` v3.4.0 to v3.5.0 in the fiber example, which carries
`fasthttp`, `klauspost/compress` and `mattn/go-isatty` with it. `gin`
was already on v1.12.0, the current release.

### What I measured

| Check | Result |
|---|---|
| `govulncheck ./...` | exit 0, **No vulnerabilities found** |
| `go test -race ./...` | 9/9 packages pass |
| Nine examples, `go build && go vet` | 9/9 pass, one package each |
| `go` directive, all 11 module files | untouched at 1.26.6 |

One latent entry remains, in a module I require but do not call: the
standing `GO-2026-5932` advisory that `x/crypto/openpgp` is unmaintained
and unsafe by design, `Fixed in: N/A`, applying to every version of the
module since 0. Nothing here imports `openpgp`.

### Three files this deliberately does not add

`go mod tidy` under `GOWORK=off` wrote a `go.sum` into the apikey, basic
and username examples, which have never carried one. Those three depend
on nothing but `authcore`, and the workspace resolves it from the
checkout, so there is no hash to record. I deleted them and confirmed
all three still build and vet. Committing them would have added three
files that every future bump has to keep in step, which is the coupling
the workspace removed.

Signed-off-by: Jaro-c <75870284+Jaro-c@users.noreply.github.com>
@Jaro-c Jaro-c added type:deps Dependency update prio:P3 Low priority status:review In review effort:XS Extra small area:examples Subsystem: examples labels Sep 7, 2026
@Jaro-c
Jaro-c merged commit 3a67c24 into develop Sep 7, 2026
15 of 16 checks passed
@Jaro-c
Jaro-c deleted the build/deps-2026-09-07 branch September 7, 2026 05:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:examples Subsystem: examples effort:XS Extra small prio:P3 Low priority status:review In review type:deps Dependency update

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant