Skip to content

chore: bump google.golang.org/grpc from 1.83.2 to 1.84.0 in the go-minor-patch group - #446

Merged
buke merged 2 commits into
mainfrom
dependabot/go_modules/go-minor-patch-319900d126
Sep 28, 2026
Merged

buke merged 2 commits into
mainfrom
dependabot/go_modules/go-minor-patch-319900d126

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-minor-patch group with 1 update: google.golang.org/grpc.

Updates google.golang.org/grpc from 1.83.2 to 1.84.0

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.84.0

Behavior Changes

  • stats/otel: The grpc.lb.pick_first.* metrics have been removed and replaced with grpc.subchannel.* metrics. See gRFC A94 for more details. (#9215)

New Features

  • xds: Add support for contains_match in route header matchers. (#9223)

Bug Fixes

  • client: Fix a bug where a ClientConn could get permanently stuck in IDLE when an RPC was canceled during stream creation. Previously, such cancellations triggered stream cleanup twice, corrupting the channel's idleness state and causing subsequent RPCs to fail with deadline exceeded errors. (#9191)
  • client: Fix a bug where non-gRPC HTTP responses ending with an empty DATA frame failed the RPC with status code Internal instead of preserving the HTTP-mapped status code and response body. (#9217)
  • credentials: Validate metadata returned by per-RPC credentials, failing the RPC with status code Internal if invalid keys or values are found. Previously, invalid metadata from credentials was sent to the server in outgoing HTTP/2 requests. (#9202)
  • credentials/sts: Prevent potential token leakage by disallowing HTTP redirects during STS token exchange. Previously, 3xx redirects were followed automatically, replaying the request body containing authentication tokens to the redirect destination. (#9299)
  • randomsubsetting: Ignore endpoints that contain no addresses. Previously, this could cause the policy to panic while computing hashes. (#9259)
  • stats/otel: Ensure method names are populated in trace spans when metrics are disabled. Previously, running with tracing enabled and metrics disabled resulted in server trace spans lacking the RPC method name (recording only "Recv."). (#9262)
  • transport: Return io.ErrUnexpectedEOF when EOF is encountered after partial header or message body reads. Previously, partial reads could return a plain io.EOF, failing to distinguish truncated data from a clean end of stream. (#9204)
  • transport: Validate metadata supplied by balancers (in PickResult.Metadata) and resolver addresses, failing the RPC with status code Internal if invalid keys or values are found. Previously, invalid metadata from these sources was sent to the server in outgoing HTTP/2 requests. (#9203)
  • xds: Fix a rare corner case that could prevent a cluster from being removed when it is no longer in use. (#9140)
  • xds: Fix panic during route matching for routes containing header matchers with empty exact_match strings. (#9223)
  • xds: Reject routes containing header matchers with empty prefix_match or suffix_match strings. Previously, this caused a panic during route matching. (#9223)
  • xds: Fix EDS drop policies being applied at a much lower rate than configured due to an integer overflow. (#9257)
  • xds: Reject EDS resources containing drop policies with unsupported denominators. Previously, such resources caused the client to panic when calculating drop rates. (#9218)
  • xds/rbac: Reject RBAC configurations containing nested Principal or Permission rules with :scheme or grpc- prefixed header matchers. Previously, such configurations could cause DENY policies to fail open. (#9258)
  • xds/rbac: Rewrite host header matchers to :authority in nested Principal and Permission rules. Previously, this rewrite only applied to top-level rules, causing nested host matchers to never match incoming requests and DENY policies to fail open. (#9258)
  • xds/rbac: Reject CidrRanges with an unset prefix length. Previously, an omitted prefix_len field caused a panic during RBAC configuration parsing. (#9250)

Performance Improvements

  • transport: Avoid a heap allocation when flushing shared write buffers. (#9233)
  • credentials/alts: Support dynamic frame size negotiation and add the GRPC_GO_EXPERIMENTAL_ALTS_MAX_FRAME_SIZE environment variable (default 4KiB, max 512KiB) to configure the maximum ALTS record frame size. (#9268)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-minor-patch group with 1 update: [google.golang.org/grpc](https://github.com/grpc/grpc-go).


Updates `google.golang.org/grpc` from 1.83.2 to 1.84.0
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.83.2...v1.84.0)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 27, 2026
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: d6408d59-df12-4dd3-82e2-874581f7a83d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

@github-actions

Copy link
Copy Markdown

PR Code Suggestions ✨

Explore these optional code suggestions:

CategorySuggestion                                                                                                                                    Impact
Best practice
Keep go.sum in sync with bump

A go.mod version bump must be accompanied by the matching go.sum entries; the diff
shows only go.mod, so confirm go.sum is regenerated in the same commit (run go mod
tidy and commit the result), otherwise builds and CI will fail with
checksum/verification errors.

go.mod [47]

+	google.golang.org/grpc v1.84.0
 
-
Suggestion importance[1-10]: 4

__

Why: The suggestion raises a legitimate concern about go.sum consistency after bumping google.golang.org/grpc to v1.84.0, but it is a verification request rather than a code change, and the improved_code is identical to the existing_code. The PR diff only shows go.mod, so go.sum may well be updated elsewhere in the PR.

Low
Possible issue
Validate gRPC integration compatibility

Verify that packages tightly coupled to gRPC internals (OTel otelgrpc interceptors,
gRPC-Web/gateway proxies, and generated *.pb.go stubs) still compile and pass tests
against 1.84.0, since minor gRPC releases occasionally change interceptor and
resolver APIs.

go.mod [47]

+	google.golang.org/grpc v1.84.0
 
-
Suggestion importance[1-10]: 2

__

Why: The suggestion is purely speculative guidance to verify downstream gRPC-coupled packages compile against v1.84.0; it proposes no concrete code change and improved_code matches existing_code. Minor version bumps of grpc rarely break interceptors, making this low impact for the PR review.

Low

@buke
buke merged commit 9c86585 into main Sep 28, 2026
49 checks passed
@buke
buke deleted the dependabot/go_modules/go-minor-patch-319900d126 branch September 28, 2026 01:39
buke added a commit that referenced this pull request Oct 3, 2026
* chore: bump gorm.io/driver/postgres in the go-minor-patch group (#425)

Bumps the go-minor-patch group with 1 update: [gorm.io/driver/postgres](https://github.com/go-gorm/postgres).


Updates `gorm.io/driver/postgres` from 1.6.2 to 1.6.3
- [Commits](go-gorm/postgres@v1.6.2...v1.6.3)

---
updated-dependencies:
- dependency-name: gorm.io/driver/postgres
  dependency-version: 1.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Brian Wang <wangbuke@gmail.com>

* ci(pr-gate): run gate on every pull request (#431)

* ci(pr-gate): also run on PRs targeting feat/choy-ui-kit

Stacked kit PRs merge into the integration branch first; without this
base in the pull_request filter, PR Gate never starts (only main matched).

* ci(pr-gate): run on every pull request base

Drop the pull_request.branches allowlist so stacked PRs into integration
branches get the same discover-routed gate as PRs into main.

* fix(ci): harden PR-Agent /improve for large diffs (#436)

* fix(ci): harden PR-Agent /improve for large diffs

Cap max_model_tokens so /improve splits big PRs into chunks instead of one
call that finishes with empty content (finish_reason=length), and lower
reasoning_effort / suggestions-per-chunk to leave room for YAML output.

* fix(ci): drop no-op reasoning_effort for PR-Agent models

PR-Agent v0.45.0 only forwards reasoning_effort for allowlisted model ids
(e.g. gemini-2.5-flash), not gemini-3.8-flash / deepseek-v4-flash. Keep the
chunking and suggestions-per-chunk caps that actually fix empty /improve.

* chore: bump the-pr-agent/pr-agent in the github-actions group (#445)

Bumps the github-actions group with 1 update: [the-pr-agent/pr-agent](https://github.com/the-pr-agent/pr-agent).


Updates `the-pr-agent/pr-agent` from 0.45.0 to 0.46.0
- [Release notes](https://github.com/the-pr-agent/pr-agent/releases)
- [Changelog](https://github.com/The-PR-Agent/pr-agent/blob/main/CHANGELOG.md)
- [Commits](The-PR-Agent/pr-agent@v0.45.0...v0.46.0)

---
updated-dependencies:
- dependency-name: the-pr-agent/pr-agent
  dependency-version: 0.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: bump google.golang.org/grpc in the go-minor-patch group (#446)

Bumps the go-minor-patch group with 1 update: [google.golang.org/grpc](https://github.com/grpc/grpc-go).


Updates `google.golang.org/grpc` from 1.83.2 to 1.84.0
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.83.2...v1.84.0)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Brian Wang <wangbuke@gmail.com>

* feat(web): align auth and shell chrome with shadcn blocks

Keep emerald primary for CTAs only: links and Lucide inherit text color, cards use bg-card, search/sidebar drop primary outlines. Login/register compose Field/Input/Checkbox; the product header shows breadcrumbs instead of a second brand.

* fix(web): clear UA chrome and show checkbox/close icons

- Drop native button/input borders and use ring-3 focus without preflight.
- Paint checkbox checked state with utilities the engine actually emits.
- Stop table translate-y from applying to every checkbox.
- Replace text × closes with Lucide X; show the auth logo without a primary tile.

* style(web): use min-h-control and wrap-break-word utilities

- Replace min-h-[var(--choy-control-height)] with the height-control token.
- Prefer wrap-break-word over the equivalent break-words alias.

* fix(auth): stop terms links from toggling the checkbox

Links inside the associated label would bubble to the control; stop the click so Terms/Privacy do not flip agreeTerms.

* test(auth): cover AuthPanel brand navigation

Click the brand lockup with a stub router so onBrandClick is exercised.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant