Skip to content

chore(deps): bump github.com/pb33f/libopenapi from 0.39.1 to 0.41.2 - #41

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/pb33f/libopenapi-0.41.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/pb33f/libopenapi-0.41.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/pb33f/libopenapi from 0.39.1 to 0.41.2.

Release notes

Sourced from github.com/pb33f/libopenapi's releases.

v0.41.2

Update hashing performance. No fixes or features, just faster and more performant.

v0.41.1

Stop duplicating files referenced from arrays

@​mcstepp

v0.41.0

Harder, Better, Faster, Stronger

  • Rendering Stripe: 77% faster
  • Rendering DocuSign (JSON): 87% faster
  • Inline-rendering every Stripe schema: 80% faster
  • Building JSON specs: 54% to 69% faster
  • Across the whole pipeline: 58% less time, 57% less memory, 61% fewer allocations

We forked the YAML library

First thing the fork fixed: the emitter kept every single event it ever wrote, for the entire document. Rendering Stripe now allocates 76% less memory, and bundling it 71% less.

Bonus: folded block scalars (>) no longer grow a blank line when rendered. Rendered output finally matches its source.

This one breaks things. Swap go.yaml.in/yaml/v4 for github.com/pb33f/go-yaml in your imports. The package is still called yaml, so it's a find and replace. If you pass *yaml.Node values in or out of libopenapi you have to do it, because the two node types are different types. jsonpath v0.8.4, ordered-map v2.3.2 and testify v0.1.1 have all made the same move.

Two small breaks in the low-level API

  • NodeMap.Nodes is now a *low.NodeLines instead of a *sync.Map. Range, Load and Store take int line numbers, and Range visits lines in order. Most models get built and never read, so the line index only gets built when you ask for it.
  • NodeReference.Context is gone. libopenapi only ever set it on a PathItem's operations. Use pathItem.Get.Value.GetContext() instead.

Bugs, squashed

  • Global caches kept dropped documents alive, and could hand a new object a stale hash when a memory address got reused. Both fixed. A document you drop now gets reclaimed without calling ClearAllCaches. (#614, #615)
  • A BaseURL without a scheme could crash the whole process during remote lookups. Not anymore. (#578)
  • The composed bundler panicked, or left a mangled mapping behind, when a $ref pointed at a sequence or scalar (like root tags). Fixed. (#607, #608)
  • what-changed was writing map keys into shared YAML nodes. That was a data race, and it put wrong (and random) keys in reports. Fixed. (#620)
  • Swagger 2 headers now map Format, ExclusiveMinimum and UniqueItems correctly. (#630)
  • Rendering a document no longer quietly rewrites the tags on your model's enum nodes.

Big thanks to @​SAY-5 for the composed bundler fix, and to @​jhump, @​jorgembfigueira, @​sohamsengupta17, @​dnovikoff, @​zLc362 and @​andrei-samofalov for the reports. Keep them coming.

There's still more blood in this stone. Much more to come.

v0.40.1

fix: initialize operation reference so a failed sibling cannot cause a nil panic

@​SAY-5

v0.40.0

This release adds a TypeScript model generator and improves OpenAPI 3.1 enum generation for Go. Both model targets build from the same schema IR.

... (truncated)

Commits
  • f7414c2 deps
  • 89decd3 fix(datamodel/low): label hash fields so sibling values stop colliding
  • e02bcb2 fix(bundler): stop duplicating files referenced from arrays
  • 47a34d4 chore: move to github.com/pb33f/go-yaml
  • 900f64e docs: add a migration guide for the low-level API changes
  • ee50ad2 perf(datamodel/low)!: index node lines lazily, drop NodeReference.Context
  • e23d10c perf: cut render, JSON and build costs across the pipeline
  • 5ddd4e4 refactor(bundler): remove unreachable odd-length guard from walkAndRewriteRefs
  • 6cc8d15 fix: guard composed ref walker against odd-length mapping content (#607)
  • fdb8ea7 fix: stop global caches pinning released documents or returning stale hashes
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/pb33f/libopenapi](https://github.com/pb33f/libopenapi) from 0.39.1 to 0.41.2.
- [Release notes](https://github.com/pb33f/libopenapi/releases)
- [Commits](pb33f/libopenapi@v0.39.1...v0.41.2)

---
updated-dependencies:
- dependency-name: github.com/pb33f/libopenapi
  dependency-version: 0.41.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 3, 2026
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Development

Successfully merging this pull request may close these issues.

1 participant