Skip to content

chore(deps): bump the go-dependencies group with 6 updates#1025

Merged
mbevc1 merged 1 commit into
mainfrom
dependabot/go_modules/go-dependencies-680ac3a695
Jul 21, 2026
Merged

chore(deps): bump the go-dependencies group with 6 updates#1025
mbevc1 merged 1 commit into
mainfrom
dependabot/go_modules/go-dependencies-680ac3a695

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 21, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-dependencies group with 6 updates:

Package From To
github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager 0.3.2 0.3.4
github.com/aws/aws-sdk-go-v2/service/lambda 1.98.0 1.99.0
github.com/aws/aws-sdk-go-v2/service/s3 1.105.1 1.105.2
github.com/aws/smithy-go 1.27.3 1.27.4
google.golang.org/api 0.288.0 0.289.0
google.golang.org/grpc 1.82.0 1.82.1

Updates github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager from 0.3.2 to 0.3.4

Commits

Updates github.com/aws/aws-sdk-go-v2/service/lambda from 1.98.0 to 1.99.0

Commits

Updates github.com/aws/aws-sdk-go-v2/service/s3 from 1.105.1 to 1.105.2

Commits

Updates github.com/aws/smithy-go from 1.27.3 to 1.27.4

Commits

Updates google.golang.org/api from 0.288.0 to 0.289.0

Release notes

Sourced from google.golang.org/api's releases.

v0.289.0

0.289.0 (2026-07-16)

Features

Changelog

Sourced from google.golang.org/api's changelog.

0.289.0 (2026-07-16)

Features

Commits
  • 783bf4b chore(main): release 0.289.0 (#3650)
  • af8d033 feat(all): auto-regenerate discovery clients (#3659)
  • 080002a chore: constrain go version updates in renovate (#3658)
  • aa8d256 feat(all): auto-regenerate discovery clients (#3657)
  • 1fc8f45 feat(all): auto-regenerate discovery clients (#3656)
  • 7ac76e4 chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 in /internal/koko...
  • 8a47d2a chore(all): update all (#3654)
  • 69af635 feat(all): auto-regenerate discovery clients (#3655)
  • 6c876b4 feat(all): auto-regenerate discovery clients (#3653)
  • 5116a48 feat(all): auto-regenerate discovery clients (#3652)
  • Additional commits viewable in compare view

Updates google.golang.org/grpc from 1.82.0 to 1.82.1

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.82.1

Security

  • server: Stop reading from the connection when flooded by HTTP/2 frames. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT.
  • xds/rbac: Support Metadata and RequestedServerName permissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open.
  • xds/rbac: Fix panic when parsing unsupported fields in NotRule/NotId permissions.
  • xds/rbac: Support the deprecated source_ip principal identifier by treating it as equivalent to direct_remote_ip.
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-dependencies group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager](https://github.com/aws/aws-sdk-go-v2) | `0.3.2` | `0.3.4` |
| [github.com/aws/aws-sdk-go-v2/service/lambda](https://github.com/aws/aws-sdk-go-v2) | `1.98.0` | `1.99.0` |
| [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2) | `1.105.1` | `1.105.2` |
| [github.com/aws/smithy-go](https://github.com/aws/smithy-go) | `1.27.3` | `1.27.4` |
| [google.golang.org/api](https://github.com/googleapis/google-api-go-client) | `0.288.0` | `0.289.0` |
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.82.0` | `1.82.1` |


Updates `github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager` from 0.3.2 to 0.3.4
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/internal/s3shared/v0.3.2...feature/s3/transfermanager/v0.3.4)

Updates `github.com/aws/aws-sdk-go-v2/service/lambda` from 1.98.0 to 1.99.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.98.0...service/s3/v1.99.0)

Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.105.1 to 1.105.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.105.1...service/s3/v1.105.2)

Updates `github.com/aws/smithy-go` from 1.27.3 to 1.27.4
- [Release notes](https://github.com/aws/smithy-go/releases)
- [Changelog](https://github.com/aws/smithy-go/blob/main/CHANGELOG.md)
- [Commits](aws/smithy-go@v1.27.3...v1.27.4)

Updates `google.golang.org/api` from 0.288.0 to 0.289.0
- [Release notes](https://github.com/googleapis/google-api-go-client/releases)
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md)
- [Commits](googleapis/google-api-go-client@v0.288.0...v0.289.0)

Updates `google.golang.org/grpc` from 1.82.0 to 1.82.1
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.82.0...v1.82.1)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager
  dependency-version: 0.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/service/lambda
  dependency-version: 1.99.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
  dependency-version: 1.105.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/aws/smithy-go
  dependency-version: 1.27.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: google.golang.org/api
  dependency-version: 0.289.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: google.golang.org/grpc
  dependency-version: 1.82.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Jul 21, 2026
@claude

claude Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Claude finished @dependabot[bot]'s task in 1m 23s —— View job


Dependency upgrade review

  • Identify changed dependencies
  • Check changelogs/release notes for breaking changes
  • Search repo for usage of upgraded deps
  • Flag risks & suggest follow-up checks
  • Verify build/compile

All 6 grouped bumps are patch/minor versions — low risk overall. Details below.

Direct dependencies

Package Bump Usage in repo Assessment
feature/s3/transfermanager 0.3.2 → 0.3.4 internal/aws/aws.go:446,513 (DownloadObject for S3 snapshots) ⚠️ Contains a behavior fix — see note below
service/lambda 1.98.0 → 1.99.0 internal/aws/aws.go, snapshotLambda* Regenerated client; standard ListFunctions/GetFunction usage unaffected
service/s3 1.105.1 → 1.105.2 internal/aws/aws.go Regenerated client (CBOR serde wave); no API surface change for our calls
smithy-go 1.27.3 → 1.27.4 transitive AWS runtime Internal generic-client changes only
google.golang.org/api 0.288.0 → 0.289.0 internal/cloudrun/* Auto-regenerated discovery clients; non-breaking minor
google.golang.org/grpc 1.82.0 → 1.82.1 transitive (google api / otel) Security patch — worth taking

Points worth a closer look

1. transfermanager fix — Fix transfermanager GetObject ContentRange to use HTTP format (#3473)
This is the one change in this PR that alters runtime behavior for code we actually exercise. We use downloader.DownloadObject(...) in internal/aws/aws.go:513 to pull objects during S3 snapshots, and the transfer manager performs ranged/multipart GETs under the hood. The fix corrects the Content-Range handling — it's a correctness improvement, not a breaking change, but it's the change most likely to surface differences.
Suggested follow-up: a quick sanity run of an S3 snapshot against a large / multipart object to confirm downloads still complete and byte counts match.

2. grpc 1.82.1 is a security release
Adds HTTP/2 frame-flood throttling (default 100 non-DATA/HEADERS frames, tunable via GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT) plus xds/rbac fixes. gRPC is transitive here (not directly imported), so no code impact — good to merge.

Transitive bumps (informational)

golang.org/x/crypto 0.53→0.54, net 0.56→0.57, text 0.38→0.40, tools 0.45→0.47, mod 0.36→0.37, sync 0.21→0.22, enterprise-certificate-proxy 0.3.17→0.3.18, and a genproto/googleapis/rpc timestamp bump — all routine.

Note on verification

I could not run go build ./... / make lint in this environment (the commands require manual approval, so they were blocked). CI on the PR should cover compile + tests; if it's green, this is safe to merge. The only manual check I'd recommend beyond CI is the S3 multipart-download sanity run described in point 1.

@mbevc1
mbevc1 enabled auto-merge (squash) July 21, 2026 09:09
@mbevc1
mbevc1 merged commit 5d6219d into main Jul 21, 2026
13 checks passed
@mbevc1
mbevc1 deleted the dependabot/go_modules/go-dependencies-680ac3a695 branch July 21, 2026 09:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant