Skip to content

Bump the go-deps group with 4 updates - #23

Merged
amirradjou merged 1 commit into
mainfrom
dependabot/go_modules/go-deps-88cfcdb459
Sep 26, 2026
Merged

amirradjou merged 1 commit into
mainfrom
dependabot/go_modules/go-deps-88cfcdb459

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 26, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-deps group with 4 updates: github.com/ipfs/boxo, github.com/ipfs/go-ipld-format, github.com/libp2p/go-libp2p and github.com/stretchr/testify.

Updates github.com/ipfs/boxo from 0.41.0 to 0.43.0

Release notes

Sourced from github.com/ipfs/boxo's releases.

v0.43.0

[!NOTE] This release was brought to you by the Shipyard team.

[!IMPORTANT] Shipyard's IPFS work ends on September 30, 2026. Until then we ship security and bug fix releases if any are absolutely needed and still possible. After that date, no one at Shipyard maintains Boxo. If you depend on Boxo, read the announcement and bring your transition questions to the community forum.

What's Changed

[!IMPORTANT] This is a bug fix release. It carries a minor version bump because the gateway no longer sends the deprecated X-Ipfs-Path header by default, replaced by Ipfs-Uri (IPIP-548). If you still need X-Ipfs-Path, set Config.DeprecatedXIpfsPath and call Headers.WithDeprecatedXIpfsPath before Headers.ApplyCors, and plan a migration to Ipfs-Uri.

Added

  • ✨ ipld/unixfs: reads of both PBNode field orders are now covered by tests, and a documented low-level opt-in (UnixFSProfile.PBNodeFieldOrder, applied via merkledag.DefaultPBNodeFieldOrder) lets writers that need streaming-friendly blocks encode the Data field before Links per IPIP-550. Off by default and selected by no named profile: UnixFS_v0_2015 and UnixFS_v1_2025 pin the canonical links-first order explicitly, so defaults and existing CIDs are unchanged. Enabling data-first changes the CID of every dag-pb node that has both fields (directories, HAMT shards, multi-chunk file roots), is process-wide (ApplyGlobals affects every merkledag.ProtoNode encoded in the process, not only UnixFS nodes), and re-encodes links-first directories in the new order the next time they are opened through the directory API and stored again (for example MFS directories on their next access). #1212
  • ✨ gateway: responses now include the Ipfs-Uri header with a canonical ipfs:// or ipns:// URI for the requested content path, and expose it via the default Access-Control-Expose-Headers. The header carries the content root in canonical form (base32 CIDv1 for /ipfs/, base36 CIDv1 for cryptographic /ipns/ names, lowercase FQDN for DNSLink) with percent-encoded path segments, so clients get a value that is safe in HTTP field context regardless of bytes in the underlying path. IPIP-548 #1209

Changed

  • 🛠 gateway: the deprecated X-Ipfs-Path response header is no longer sent by default; its value cannot represent all UnixFS file names and it is superseded by Ipfs-Uri. Action required: consumers that read X-Ipfs-Path should migrate to Ipfs-Uri; to restore the legacy header meanwhile, set Config.DeprecatedXIpfsPath and call Headers.WithDeprecatedXIpfsPath before Headers.ApplyCors so it is listed in Access-Control-Expose-Headers again. Even with the flag set, the header is omitted for content paths with bytes that cannot appear in an HTTP field value (Section 5.5 of RFC 9110), such as raw non-ASCII UnixFS file names: gateway-conformance fails a gateway that sends such values, and only Ipfs-Uri carries those paths. IPIP-548 #1209
  • gateway: conformance CI runs gateway-conformance v0.14.0, the first release with the IPIP-548 Ipfs-Uri tests. #1209
  • updated Go in go.mod to 1.26.0
  • upgrade to go-libp2p-kad-dht v0.42.2
  • upgrade to go.opentelemetry.io v1.46.0

Fixed

  • gateway: X-Ipfs-Path values no longer carry bytes that are invalid in an HTTP field value (Section 5.5 of RFC 9110). The header used to echo raw UnixFS file names, so non-ASCII paths arrived garbled or broke strict clients; when the header is enabled, it is now omitted for such paths, which only the percent-encoded Ipfs-Uri can carry. #1209
  • bootstrap: the saved backup peer list is no longer dialed when no bootstrap peers are configured. #1213

v0.42.2

[!NOTE] This release was brought to you by the Shipyard team.

[!IMPORTANT] This is the last Kubo release with new features from the Shipyard team. Our IPFS work ends on September 30, 2026. Until then we will ship security and bug fix releases if any are needed. After that date, no one at Shipyard maintains Boxo. If you depend on Boxo, read the announcement and send us your transition questions before the end of September.

What's Changed

Added

  • bitswap/network/httpnet: DefaultConnectFailureBackoff constant, the wait before Connect re-probes an endpoint after a failed probe.
  • bitswap/network/httpnet: CooldownTracker type with NewCooldownTracker, SharedCooldownTracker and the WithCooldownTracker option, for controlling where per-host backoff state lives.

Changed

... (truncated)

Changelog

Sourced from github.com/ipfs/boxo's changelog.

[v0.43.0]

[!IMPORTANT] This is a bug fix release. It carries a minor version bump because the gateway no longer sends the deprecated X-Ipfs-Path header by default, replaced by Ipfs-Uri (IPIP-548). If you still need X-Ipfs-Path, set Config.DeprecatedXIpfsPath and call Headers.WithDeprecatedXIpfsPath before Headers.ApplyCors, and plan a migration to Ipfs-Uri.

Shipyard's IPFS work ends on September 30, 2026. Until then we ship security and bug fix releases if any are absolutely needed and still possible. After that date, no one at Shipyard maintains Boxo. If you depend on Boxo, read the announcement and bring your transition questions to the community forum.

Added

  • ✨ ipld/unixfs: reads of both PBNode field orders are now covered by tests, and a documented low-level opt-in (UnixFSProfile.PBNodeFieldOrder, applied via merkledag.DefaultPBNodeFieldOrder) lets writers that need streaming-friendly blocks encode the Data field before Links per IPIP-550. Off by default and selected by no named profile: UnixFS_v0_2015 and UnixFS_v1_2025 pin the canonical links-first order explicitly, so defaults and existing CIDs are unchanged. Enabling data-first changes the CID of every dag-pb node that has both fields (directories, HAMT shards, multi-chunk file roots), is process-wide (ApplyGlobals affects every merkledag.ProtoNode encoded in the process, not only UnixFS nodes), and re-encodes links-first directories in the new order the next time they are opened through the directory API and stored again (for example MFS directories on their next access). #1212
  • ✨ gateway: responses now include the Ipfs-Uri header with a canonical ipfs:// or ipns:// URI for the requested content path, and expose it via the default Access-Control-Expose-Headers. The header carries the content root in canonical form (base32 CIDv1 for /ipfs/, base36 CIDv1 for cryptographic /ipns/ names, lowercase FQDN for DNSLink) with percent-encoded path segments, so clients get a value that is safe in HTTP field context regardless of bytes in the underlying path. IPIP-548 #1209

Changed

  • 🛠 gateway: the deprecated X-Ipfs-Path response header is no longer sent by default; its value cannot represent all UnixFS file names and it is superseded by Ipfs-Uri. Action required: consumers that read X-Ipfs-Path should migrate to Ipfs-Uri; to restore the legacy header meanwhile, set Config.DeprecatedXIpfsPath and call Headers.WithDeprecatedXIpfsPath before Headers.ApplyCors so it is listed in Access-Control-Expose-Headers again. Even with the flag set, the header is omitted for content paths with bytes that cannot appear in an HTTP field value (Section 5.5 of RFC 9110), such as raw non-ASCII UnixFS file names: gateway-conformance fails a gateway that sends such values, and only Ipfs-Uri carries those paths. IPIP-548 #1209
  • gateway: conformance CI runs gateway-conformance v0.14.0, the first release with the IPIP-548 Ipfs-Uri tests. #1209
  • updated Go in go.mod to 1.26.0
  • upgrade to go-libp2p-kad-dht v0.42.2
  • upgrade to go.opentelemetry.io v1.46.0

Fixed

  • gateway: X-Ipfs-Path values no longer carry bytes that are invalid in an HTTP field value (Section 5.5 of RFC 9110). The header used to echo raw UnixFS file names, so non-ASCII paths arrived garbled or broke strict clients; when the header is enabled, it is now omitted for such paths, which only the percent-encoded Ipfs-Uri can carry. #1209
  • bootstrap: the saved backup peer list is no longer dialed when no bootstrap peers are configured. #1213

[v0.42.2]

Added

  • bitswap/network/httpnet: DefaultConnectFailureBackoff constant, the wait before Connect re-probes an endpoint after a failed probe.
  • bitswap/network/httpnet: CooldownTracker type with NewCooldownTracker, SharedCooldownTracker and the WithCooldownTracker option, for controlling where per-host backoff state lives.

Changed

  • ✨ bitswap/network/httpnet: removed the background ping loop that probed every connected HTTP peer with GET/HEAD /ipfs/bafkqaaa every 5 seconds for the lifetime of the process (old: fixed 5s cadence per peer, results discarded; new: no periodic probes). Idle HTTP peers generate no background traffic.
  • bitswap/network/httpnet: latency to HTTP peers is measured from the Connect probe and from real retrieval responses instead of periodic pings.
  • bitswap/network/httpnet: Connect and Ping honor per-host cooldowns; after a failed endpoint probe, Connect does not re-probe the host until Retry-After (when provided) or DefaultConnectFailureBackoff elapses (old: no backoff, re-probe on every call).
  • bitswap/network/httpnet: per-host cooldowns live in a process-wide registry (SharedCooldownTracker) so backoff deadlines survive short-lived Network instances (old: per-instance state, forgotten on every restart); Network.Stop no longer stops the registry, and WithCooldownTracker gives a Network a private one.

Removed

  • bitswap/network/httpnet: HTTP 410 is no longer accepted as a successful answer to the connection probe; it was a workaround for a provider that has since shut down. 410 on real block requests still counts as a valid "content unavailable" reply.

Fixed

  • bitswap/network/httpnet: message senders created while a host was in cooldown no longer treat that cooldown as permanent; the request path resumes once the cooldown expires.
  • bitswap/network/bsnet: peers already connected when Bitswap starts are now recognised. libp2p only reports connections opened after a notifier is registered, so a peer connected during node startup stayed invisible to Bitswap for the life of that connection, and no want was ever sent to it. Nodes with another way to find content usually masked this; nodes relying on an already-connected peer could wait forever.

[v0.42.1]

... (truncated)

Commits

Updates github.com/ipfs/go-ipld-format from 0.6.3 to 0.6.4

Release notes

Sourced from github.com/ipfs/go-ipld-format's releases.

v0.6.4

What's Changed

Full Changelog: ipfs/go-ipld-format@v0.6.3...v0.6.4

Commits

Updates github.com/libp2p/go-libp2p from 0.48.0 to 0.49.0

Release notes

Sourced from github.com/libp2p/go-libp2p's releases.

v0.49.0

What's Changed

New Contributors

Full Changelog: libp2p/go-libp2p@v0.48.0...v0.49.0

Commits
  • 5c7e6ec Release v0.49.0
  • 42c3811 chore: update deps
  • 07d71d8 chore(webtransport): update webtransport-go to v0.11.1
  • bb0dc7d test(basichost): cancel in-flight refresh probes
  • a07d7ff refactor(autonatv2): unlock pickServer via defer
  • 10e3837 docs(basichost): fix stale const name in comments
  • 8745f50 fix(basichost): probe secondary addrs on the same 1h cadence as primaries
  • f23601b fix(autonatv2): don't panic in GetReachability after Close
  • 617deba test(basichost): actually spawn workers in refreshReachability cancellation test
  • 18e98a9 fix(basichost): score webrtc-direct addrs with P_WEBRTC_DIRECT
  • Additional commits viewable in compare view

Updates github.com/stretchr/testify from 1.11.1 to 1.12.1

Release notes

Sourced from github.com/stretchr/testify's releases.

v1.12.1

This is the first release which has the minimum dependencies practical in testify v1. The last remaining dependencies are github.com/stretchr/objx which itself has no dependencies, and go.yaml.in/yaml/v3. Removing objx would require v2, it cannot be vendored. Removing YAML would require vendoring the yaml library, which would do more harm than good. It's better to become aware of vulnerabilities in the official yaml package than to attempt to maintain our own.

What's Changed

New Contributors

Full Changelog: stretchr/testify@v1.12.0...v1.12.1

What's Changed

New Contributors

Full Changelog: stretchr/testify@v1.12.0...v1.12.1

v1.12.0

What's Changed

Functional Changes

Fixes

Documentation, Build & CI

... (truncated)

Commits
  • 959dbda Merge pull request #1935 from harryzcy/yaml-update
  • 9bb7176 Update go.yaml.in/yaml/v3 to v3.0.5
  • 001eb79 Merge pull request #1905 from Kentzo/patch-1
  • ad40f38 Merge pull request #1906 from stretchr/dependabot/github_actions/actions/chec...
  • 3bae017 build(deps): bump actions/checkout from 6.0.2 to 6.0.3
  • f8c01f3 mock: Mock.Return does not exist anymore
  • 12f8b56 Merge pull request #1563 from stretchr/make-AssertionFunc-types-aliases
  • a11649e assert: make *AssertionFunc type just aliases
  • dc20f41 Merge pull request #1890 from stretchr/dolmen/codegen-modernize
  • 098f8d7 _codegen: use strings.Builder
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-deps group with 4 updates: [github.com/ipfs/boxo](https://github.com/ipfs/boxo), [github.com/ipfs/go-ipld-format](https://github.com/ipfs/go-ipld-format), [github.com/libp2p/go-libp2p](https://github.com/libp2p/go-libp2p) and [github.com/stretchr/testify](https://github.com/stretchr/testify).


Updates `github.com/ipfs/boxo` from 0.41.0 to 0.43.0
- [Release notes](https://github.com/ipfs/boxo/releases)
- [Changelog](https://github.com/ipfs/boxo/blob/main/CHANGELOG.md)
- [Commits](ipfs/boxo@v0.41.0...v0.43.0)

Updates `github.com/ipfs/go-ipld-format` from 0.6.3 to 0.6.4
- [Release notes](https://github.com/ipfs/go-ipld-format/releases)
- [Commits](ipfs/go-ipld-format@v0.6.3...v0.6.4)

Updates `github.com/libp2p/go-libp2p` from 0.48.0 to 0.49.0
- [Release notes](https://github.com/libp2p/go-libp2p/releases)
- [Changelog](https://github.com/libp2p/go-libp2p/blob/master/CHANGELOG.md)
- [Commits](libp2p/go-libp2p@v0.48.0...v0.49.0)

Updates `github.com/stretchr/testify` from 1.11.1 to 1.12.1
- [Release notes](https://github.com/stretchr/testify/releases)
- [Commits](stretchr/testify@v1.11.1...v1.12.1)

---
updated-dependencies:
- dependency-name: github.com/ipfs/boxo
  dependency-version: 0.43.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/ipfs/go-ipld-format
  dependency-version: 0.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/libp2p/go-libp2p
  dependency-version: 0.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/stretchr/testify
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 26, 2026
@amirradjou
amirradjou merged commit a2c0b9c into main Sep 26, 2026
3 of 6 checks passed
@dependabot
dependabot Bot deleted the dependabot/go_modules/go-deps-88cfcdb459 branch September 26, 2026 03:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant