Skip to content

Simple dependency updates - #461

Open
driv3r wants to merge 5 commits into
mainfrom
chore/updates
Open

driv3r wants to merge 5 commits into
mainfrom
chore/updates

Conversation

driv3r added 5 commits October 9, 2026 13:29
Go 1.26.2 -> 1.27.2 clears the 25 reachable standard library
vulnerabilities reported by govulncheck.

Dependencies updated:
- github.com/sirupsen/logrus v1.8.1 -> v1.10.2 (fixes GO-2025-4188)
- github.com/rs/zerolog v1.35.0 -> v1.35.1
- github.com/stretchr/testify v1.8.4 -> v1.12.1
- github.com/gorilla/mux v1.6.1 -> v1.8.1
- github.com/golang/snappy 2018 pseudo-version -> v1.0.0
- github.com/DataDog/datadog-go v4.8.2 -> v4.8.3
- golang.org/x/sys, golang.org/x/text, filippo.io/edwards25519,
  go.uber.org/zap, go.uber.org/atomic, mattn/go-isatty,
  mattn/go-colorable, Microsoft/go-winio to latest

Intentionally not updated, as they sit on the row read/write, binlog
decoding or SQL generation path and need a dedicated change:
go-mysql-org/go-mysql, go-sql-driver/mysql, Masterminds/squirrel,
shopspring/decimal, and go-mysql's goccy/go-json, klauspost/compress,
google/uuid and pingcap dependencies.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant