Skip to content

fix(deps): update bump-dependencies - #55

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate.bump-dependencies
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate.bump-dependencies

Conversation

@renovate

@renovate renovate Bot commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Age Confidence
debian (source) final digest 34cd9e9 → 913f670
debian (source) stage digest 34cd9e9 → 913f670
debian_13/curl patch 8.14.1-2+deb13u4 → 8.14.1-2+deb13u5 age confidence
docker/dockerfile syntax minor 1.26 → 1.28 age confidence
github.com/davidbyttow/govips/v2 require minor v2.18.0 → v2.19.0 age confidence
github.com/go-sql-driver/mysql require patch v1.10.0 → v1.10.1 age confidence
github.com/prometheus/client_golang require minor v1.24.1 → v1.25.0 age confidence
golang (source) stage digest 484ef60 → 5cf287a
libops/.github (changelog) workflow digest 7277eac → 782ba8f
libvips patch 8.18.5 → 8.18.7 age confidence
mariadb (source) digest dd9b303 → 2bdff15

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

davidbyttow/govips (github.com/davidbyttow/govips/v2)

v2.19.0

Compare Source

Highlights

  • Streaming I/O: new LoadImageFromReader, SaveToWriter, and TranscodeStream for working with io.Reader/io.Writer instead of whole buffers (#​539). Stream loads sniff the file signature, so sub-formats like AVIF vs HEIF are still reported correctly (#​540)
  • NewImageFromMemory: build an ImageRef from a raw pixel buffer (#​528)
  • WebP TargetSize: new option on WebpExportParams, requires libvips 8.17.4+ (#​535)
  • Kill flag: SetKill exposes libvips' image evaluation kill flag, for cancelling long-running work (#​537)
  • BigTIFF image type detection (#​527)

Fixes

Several of these are memory-safety bugs that could crash a process. Upgrading is recommended.

  • Fix SIGSEGV after a failed DrawRect: the error path unref'd the caller's image, so the later Close() or GC finalizer was a double-unref. Reachable from truncated JPEGs (#​547, #​549)
  • Fix input double-unref in Join, which caused intermittent use-after-free crashes at unrelated call sites (#​531)
  • Fix SetBlob: it passed the slice header to C instead of the backing array and panicked under cgocheck on any non-empty input (#​545, #​549)
  • Fix a C string leak on every ExportMagick call (#​546, #​549)
  • Keep ImageRef arguments alive across cgo calls in two-image ops (Composite, Insert, Join, ArrayJoin, BandJoin, Mapim, Maplut, Add, Subtract, Multiply, Divide), closing a GC finalization hazard (#​543)
  • Fix background colors on 1 and 2-band greyscale images for Embed and friends (#​534, #​538)

Housekeeping

  • Add AGENTS.md with contributor and agent guidance: cgo/memory rules, testing conventions, known local quirks (#​541, #​542)
  • CI installs the libheif HEVC plugin so HEIC fixtures run (#​529)
  • Bump golang.org/x/image to 0.41.0 and golang.org/x/net to 0.55.0 (#​533, #​532)
  • Bump sharp in examples/tiff (#​536, #​548)

Thanks to @​antst, @​alon-ne, @​goodmartian, and @​joecorall for patches, and to @​svkoskin and @​OvOhao for detailed bug reports.

go-sql-driver/mysql (github.com/go-sql-driver/mysql)

v1.10.1

Compare Source

  • Fix Config.FormatDSN() dropping Addr when Net is empty.
    It now uses the default tcp network so configs with only Addr round-trip correctly. (#​1770)

  • Fix typed-nil json.RawMessage with interpolateParams=true being interpolated as an empty string.
    It is now interpolated as SQL NULL, matching server-side prepared statements. (#​1782)

  • Add MariaDB 11.8 and 12.3 to the test matrix. (#​1774)

prometheus/client_golang (github.com/prometheus/client_golang)

v1.25.0

Compare Source

⚠️ This release raises the minimum required Go version to 1.26 and includes breaking API changes in api/prometheus/v1 (see the [CHANGE] entries below). ⚠️

1.25.0 / 2026-10-07

  • [CHANGE] Minimum required Go version is now 1.26, only the two latest Go versions (1.26 and 1.27) are supported from now on. #​2138
  • [CHANGE] api/prometheus/v1: Query, QueryRange, Series, LabelNames, and LabelValues now return Infos annotations in addition to Warnings, matching the Prometheus server's info annotations. This changes the signatures of these methods and of api.Client's Do/DoGetFallback; custom API client implementations must be updated. #​1963
  • [CHANGE] api/prometheus/v1: Rework TSDBBlocks result types to align with the Prometheus server's tsdb.BlockMeta: TSDBBlocksResult now contains Blocks []TSDBBlockMeta directly instead of mirroring the full API envelope, nested types are renamed (TSDBBlockMeta, TSDBBlockStats, TSDBBlockMetaCompaction), stat fields are uint64 with omitempty tags, and the optional compaction parents field is included. #​1928
  • [FEATURE] testutil: Add GatherAndFormat to encode a subset of metrics from a Gatherer. #​2091
  • [FEATURE] promhttp: Add HandlerOpts.AcceptedFormats to customize the formats negotiated from the incoming Accept header, enabling opt-in to experimental formats such as OpenMetrics 2.0 without changing default negotiation. #​2146
  • [ENHANCEMENT] promhttp: Negotiated metrics responses now include a Vary header. #​2142
  • [ENHANCEMENT] prometheus: Regenerate the default runtime collector metrics for Go 1.25 and Go 1.26. #​2090, #​2095
  • [ENHANCEMENT] testutil: Finalize OpenMetrics output in GatherAndFormat and CollectAndFormat (terminating # EOF). #​2125
  • [BUGFIX] api: Match complete URL path placeholders only; a :foo argument no longer substitutes inside :foobar. #​2136
  • [BUGFIX] exp/api/remote: Reset the pooled buffer before generic proto marshaling, preventing corrupted remote-write payloads. #​2139
  • [BUGFIX] testutil/promlint: Fix "mibi" unit prefix to "mebi". #​2135
What's changed

What's Changed

New Contributors

Full Changelog: prometheus/client_golang@v1.24.1...v1.25.0

libvips/libvips (libvips)

v8.18.7

Compare Source

Changes since 8.18.6:

  • tiffload: copy colormaps on page load [Ada Logics]
  • buildlut: limit output lut size [Ada Logics]
  • tiffload: check for undersized jp2k tiles [Ada Logics]
  • hough_line: improve bounds check [Ada Logics]
  • pdfiumload: check for buffer too small [Ada Logics]
  • tiffload: check rgba settings between directories [Tanto Security]
  • uhdrload: calculate gain map scale factor using round-to-nearest [lovell]
  • jp2ksave: tag as UNTRUSTED [kleisauke]
  • header: only parse EXIF metadata for blob values [Shopify]
  • jp2kload: more size validation [Akokonunes]

Windows binaries here:

https://github.com/libvips/build-win64-mxe/releases/tag/v8.18.7

v8.18.6

Compare Source

Changes since 8.18.5:

  • openexrload: more validation [Hygge Halcyon]
  • heifload: tag as UNTRUSTED for libheif before 1.23.2

Windows binaries here:

https://github.com/libvips/build-win64-mxe/releases/tag/v8.18.6


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Only on Wednesday (* * * * 3)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch 8 times, most recently from fdef143 to edda8b3 Compare September 2, 2026 05:28
@renovate renovate Bot changed the title chore(deps): update bump-dependencies fix(deps): update bump-dependencies Sep 2, 2026
@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch 2 times, most recently from e607979 to 2bf6f0c Compare September 2, 2026 23:31
@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch 6 times, most recently from 80576cc to 075dae5 Compare September 16, 2026 12:12
@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch 5 times, most recently from e1ef5e6 to 8714449 Compare September 20, 2026 21:10
@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch 4 times, most recently from 31b3265 to 6ffb077 Compare October 2, 2026 18:16
@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch 3 times, most recently from 420b42e to 0dfe5ca Compare October 6, 2026 06:00
@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch 6 times, most recently from 6bb6a4e to 913059c Compare October 8, 2026 18:02
@renovate

renovate Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 7 additional dependencies were updated

Details:

Package Change
github.com/prometheus/client_model v0.6.2 -> v0.6.3
github.com/prometheus/common v0.70.1 -> v0.72.0
github.com/prometheus/procfs v0.21.1 -> v0.22.0
golang.org/x/net v0.57.0 -> v0.59.0
golang.org/x/sys v0.47.0 -> v0.48.0
golang.org/x/text v0.41.0 -> v0.42.0
google.golang.org/protobuf v1.36.11 -> v1.36.12

@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch from 913059c to 10e8898 Compare October 8, 2026 21:25

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants