Skip to content

chore(deps): bump the go-minor-and-patch group across 1 directory with 7 updates - #155

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/server/go-minor-and-patch-68ffd58943
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/server/go-minor-and-patch-68ffd58943

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-minor-and-patch group with 7 updates in the /server directory:

Package From To
github.com/klauspost/compress 1.19.2 1.20.0
github.com/microsoft/go-mssqldb 1.9.3 1.11.0
github.com/rclone/rclone 1.75.0 1.75.1
github.com/shirou/gopsutil/v4 4.26.6 4.26.8
golang.org/x/crypto 0.55.0 0.56.0
golang.org/x/oauth2 0.36.0 0.37.0
google.golang.org/api 0.279.0 0.298.0

Updates github.com/klauspost/compress from 1.19.2 to 1.20.0

Release notes

Sourced from github.com/klauspost/compress's releases.

v1.20.0

What's Changed

New Contributors

Full Changelog: klauspost/compress@v1.19.2...v1.20.0

Commits
  • 9d8ccb1 flate: Writer with a preset dictionary emits the dictionary into the output s...
  • f93f23a build(deps): bump the github-actions group with 6 updates (#1200)
  • 42f9d96 xpress: add Microsoft XPRESS (MS-XCA) decompression (#1195)
  • 629c2ea zstd/huff0: break false partial-register dependencies in seqdec/4X decoders (...
  • ba74977 ci: test against go1.27.x, drop go1.24.x (#1198)
  • f5c1529 zstd/huff0: pin avo peephole folds, regenerate arm64 (#1199)
  • 73508b2 s2: arm64 assembly encoders, lowered from the amd64 avo program (#1187)
  • 0e43f04 xxhash: bound input of non-preemptive assembly (#1196)
  • 4005c15 s2: clamp the Go EncodeBetter skip to match the assembly (#1190)
  • dd6de45 gzhttp: limit jitter hash to jitterBuffer bytes (#1192)
  • Additional commits viewable in compare view

Updates github.com/microsoft/go-mssqldb from 1.9.3 to 1.11.0

Release notes

Sourced from github.com/microsoft/go-mssqldb's releases.

v1.11.0

1.11.0 (2026-08-23)

Features

  • add ADO.Net connection string synonyms (#374) (d72f750)

Bug Fixes

  • clarify NTLM URL encoding for URL DSNs (#378) (551d622)
  • close TCP connection on all connect() error paths (#367) (0e13fee)
  • isProc: add REVERT builtin command (#393) (31a9659)
  • prevent NTLM challenge out-of-bounds panic (DoS) (#411) (81df983)
  • prevent panic on overflowing PRELOGIN option offset and length (#415) (802d9f1)
  • prevent SQL Browser DAC response parsing panic (DoS) (#414) (bc4cbf2)
  • quote table name and ORDER columns in bulk copy (#416) (f925c53)
  • replace deprecated reflect.SliceHeader with unsafe.Slice (#366) (836048a), closes #272
  • return float64 for REAL columns in readFixedType (#381) (abddba8)
  • strip port from AKV URLs for AllowedLocations and endpoint (#369) (7fab98a)
  • types: cap initial PLP buffer allocation (#409) (f088291)

Performance Improvements

  • add comprehensive benchmark suite with CI regression detection (#376) (b935441)
  • fast path for pure ASCII decoding in CharsetToUTF8 (#431) (db51796)

v1.10.0

1.10.0 (2026-04-25)

Features

  • add devcontainer for VS Code and GitHub Codespaces (#317) (b55beeb)
  • add FailoverPartnerSPN connection string parameter (#327) (ea77c2e)
  • add NewConnectorWithProcessQueryText for mssql driver compatibility (#341) (2be611f)
  • add nullable civil types for date/time parameters (#325) (c10fa99)

Bug Fixes

  • allow named pipe protocol support for ARM64 Windows (#232) (a82c058)
  • configure release-please with PAT and correct component mapping (#349) (23bac05)
  • detect server-aborted transactions to prevent silent auto-commit (XACT_ABORT) (#370) (586ea53)
  • expose TrustServerCertificate in msdsn.Config and URL round-trip (#312) (9937cfe)
  • handle COLINFO (0xA5) and TABNAME (0xA4) TDS tokens returned by tables with triggers (#343) (7c905ad)
  • implement driver.DriverContext interface (#365) (1b610a0), closes #236
  • make readCancelConfirmation respect context cancellation (#359) (65e137f)

... (truncated)

Changelog

Sourced from github.com/microsoft/go-mssqldb's changelog.

1.11.0 (2026-08-23)

Features

  • add ADO.Net connection string synonyms (#374) (d72f750)

Bug Fixes

  • clarify NTLM URL encoding for URL DSNs (#378) (551d622)
  • close TCP connection on all connect() error paths (#367) (0e13fee)
  • isProc: add REVERT builtin command (#393) (31a9659)
  • prevent NTLM challenge out-of-bounds panic (DoS) (#411) (81df983)
  • prevent panic on overflowing PRELOGIN option offset and length (#415) (802d9f1)
  • prevent SQL Browser DAC response parsing panic (DoS) (#414) (bc4cbf2)
  • quote table name and ORDER columns in bulk copy (#416) (f925c53)
  • replace deprecated reflect.SliceHeader with unsafe.Slice (#366) (836048a), closes #272
  • return float64 for REAL columns in readFixedType (#381) (abddba8)
  • strip port from AKV URLs for AllowedLocations and endpoint (#369) (7fab98a)
  • types: cap initial PLP buffer allocation (#409) (f088291)

Performance Improvements

  • add comprehensive benchmark suite with CI regression detection (#376) (b935441)
  • fast path for pure ASCII decoding in CharsetToUTF8 (#431) (db51796)

1.10.0 (2026-04-25)

Features

  • add devcontainer for VS Code and GitHub Codespaces (#317) (b55beeb)
  • add FailoverPartnerSPN connection string parameter (#327) (ea77c2e)
  • add NewConnectorWithProcessQueryText for mssql driver compatibility (#341) (2be611f)
  • add nullable civil types for date/time parameters (#325) (c10fa99)

Bug Fixes

  • allow named pipe protocol support for ARM64 Windows (#232) (a82c058)
  • configure release-please with PAT and correct component mapping (#349) (23bac05)
  • detect server-aborted transactions to prevent silent auto-commit (XACT_ABORT) (#370) (586ea53)
  • expose TrustServerCertificate in msdsn.Config and URL round-trip (#312) (9937cfe)
  • handle COLINFO (0xA5) and TABNAME (0xA4) TDS tokens returned by tables with triggers (#343) (7c905ad)
  • implement driver.DriverContext interface (#365) (1b610a0), closes #236
  • make readCancelConfirmation respect context cancellation (#359) (65e137f)
  • replace broken AppVeyor badge with GitHub Actions badge (#334) (d3429f5)
  • return interface{} scanType for sql_variant instead of nil (#362) (296a83a), closes #186

... (truncated)

Commits
  • ecf8560 chore(main): release 1.11.0 (#380)
  • 68c1f28 test: add TDS response fuzz harness and end-to-end target (layer 1/4) (#419)
  • 46b5c6a chore(deps): bump the golang-x group across 1 directory with 2 updates (#433)
  • 5e6cedb ci: run appveyor on SQL Server 2025 and drop the duplicate job (#436)
  • ae25ae5 ci: test the supported Go releases and drop the EOL toolchain pin (#439)
  • 6f21949 chore(deps): bump github.com/stretchr/testify in the testing group (#434)
  • 8bb55ef chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#432)
  • db51796 perf: fast path for pure ASCII decoding in CharsetToUTF8 (#431)
  • f925c53 fix: quote table name and ORDER columns in bulk copy (#416)
  • bc4cbf2 fix: prevent SQL Browser DAC response parsing panic (DoS) (#414)
  • Additional commits viewable in compare view

Updates github.com/rclone/rclone from 1.75.0 to 1.75.1

Release notes

Sourced from github.com/rclone/rclone's releases.

rclone v1.75.1

This is the v1.75.1 release of rclone.

Full details of the changes can be found in the changelog.

Commits
  • 687d264 Version v1.75.1
  • 4158f63 Start v1.75.1-DEV development
  • c47832a serve: fix VFS instance leaks on server startup failures and shutdown
  • 60e9641 rc: silence deprecation lint warning in the old web gui plugin proxy
  • c841c3b build: disable staticcheck SA4023 to fix lint job timeout
  • 79fbc08 fshttp: don't send --header values to other hosts on redirect GHSA-486v-q2wf-...
  • 22859b7 http: don't leak configured headers to other hosts or over plaintext on redir...
  • 925fb4f rest: add SameHost and check HTTPS downgrades against the original request GH...
  • 96f298b archive: hide any archive entry which escapes the directory being listed GHSA...
  • 60fb55d archive: fix "directory not found" for archive paths containing "./" or "//" ...
  • Additional commits viewable in compare view

Updates github.com/shirou/gopsutil/v4 from 4.26.6 to 4.26.8

Release notes

Sourced from github.com/shirou/gopsutil/v4's releases.

v4.26.8

What's Changed

cpu

disk

net

process

Other Changes

New Contributors

Full Changelog: shirou/gopsutil@v4.26.7...v4.26.8

v4.26.7

What's Changed

cpu

net

process

other

New Contributors

Full Changelog: shirou/gopsutil@v4.26.6...v4.26.7

Commits
  • 7d254a0 Merge pull request #2127 from Ahm3dRN/windows-commandline-information
  • 4dab2b9 Merge pull request #2136 from pgimalac/aix-disk-usage-statfs
  • 1ddce22 Merge pull request #2141 from shirou/dependabot/github_actions/vmactions/free...
  • ec8a313 chore(deps): bump vmactions/freebsd-vm from 1.5.4 to 1.5.5
  • 26ae363 Merge pull request #2140 from shirou/dependabot/github_actions/vmactions/free...
  • 21afc16 chore(deps): bump vmactions/freebsd-vm from 1.5.2 to 1.5.4
  • fbf8dd1 fixed getProcessCommandLine error path to match master and refined the tests ...
  • 97835bd Windows CMDLine native fallback feedback fixes
  • 3e8ab43 fixed gofumpt
  • 4631d96 Implement NtQueryInformationProcess to get commandline Windows 8.1+
  • Additional commits viewable in compare view

Updates golang.org/x/crypto from 0.55.0 to 0.56.0

Commits
  • 86efde5 ssh: reject unexpected message types on established channels
  • a6cdac6 ssh: drop traffic on undecided channels
  • 39dc44e ssh: don't skip the source-address critical option in CheckCert
  • afebf4c x509roots/fallback/bundle: make subjectsEqual stricter on Go 1.27+
  • 89f4e9b x509roots/fallback: update bundle
  • 71488c4 ssh/knownhosts: compare only public key portions for revocation
  • 82adefa ssh: synchronize unexpected response test
  • c757c98 all: upgrade go directive to at least 1.26.0 [generated]
  • 593c81a ssh: correctly ignore pre-banner lines
  • 46efc8b acme: add crypto.SignMessage test coverage
  • Additional commits viewable in compare view

Updates golang.org/x/oauth2 from 0.36.0 to 0.37.0

Commits
  • c624b89 google: change the snake case endpoint to kebab-case
  • 09a82f6 all: upgrade go directive to at least 1.26.0 [generated]
  • See full diff in compare view

Updates google.golang.org/api from 0.279.0 to 0.298.0

Release notes

Sourced from google.golang.org/api's releases.

v0.298.0

0.298.0 (2026-09-14)

Features

v0.297.0

0.297.0 (2026-09-01)

Features

  • Move to go1.26.0 as the lowest supported go version (#3724) (7770e01)

v0.296.0

0.296.0 (2026-08-31)

Features

v0.295.0

0.295.0 (2026-08-28)

Features

v0.294.0

0.294.0 (2026-08-26)

Features

... (truncated)

Changelog

Sourced from google.golang.org/api's changelog.

0.298.0 (2026-09-14)

Features

0.297.0 (2026-09-01)

Features

  • Move to go1.26.0 as the lowest supported go version (#3724) (7770e01)

0.296.0 (2026-08-31)

Features

0.295.0 (2026-08-28)

Features

0.294.0 (2026-08-26)

Features

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…h 7 updates

Bumps the go-minor-and-patch group with 7 updates in the /server directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/klauspost/compress](https://github.com/klauspost/compress) | `1.19.2` | `1.20.0` |
| [github.com/microsoft/go-mssqldb](https://github.com/microsoft/go-mssqldb) | `1.9.3` | `1.11.0` |
| [github.com/rclone/rclone](https://github.com/rclone/rclone) | `1.75.0` | `1.75.1` |
| [github.com/shirou/gopsutil/v4](https://github.com/shirou/gopsutil) | `4.26.6` | `4.26.8` |
| [golang.org/x/crypto](https://github.com/golang/crypto) | `0.55.0` | `0.56.0` |
| [golang.org/x/oauth2](https://github.com/golang/oauth2) | `0.36.0` | `0.37.0` |
| [google.golang.org/api](https://github.com/googleapis/google-api-go-client) | `0.279.0` | `0.298.0` |



Updates `github.com/klauspost/compress` from 1.19.2 to 1.20.0
- [Release notes](https://github.com/klauspost/compress/releases)
- [Commits](klauspost/compress@v1.19.2...v1.20.0)

Updates `github.com/microsoft/go-mssqldb` from 1.9.3 to 1.11.0
- [Release notes](https://github.com/microsoft/go-mssqldb/releases)
- [Changelog](https://github.com/microsoft/go-mssqldb/blob/main/CHANGELOG.md)
- [Commits](microsoft/go-mssqldb@v1.9.3...v1.11.0)

Updates `github.com/rclone/rclone` from 1.75.0 to 1.75.1
- [Release notes](https://github.com/rclone/rclone/releases)
- [Changelog](https://github.com/rclone/rclone/blob/master/RELEASE.md)
- [Commits](rclone/rclone@v1.75.0...v1.75.1)

Updates `github.com/shirou/gopsutil/v4` from 4.26.6 to 4.26.8
- [Release notes](https://github.com/shirou/gopsutil/releases)
- [Commits](shirou/gopsutil@v4.26.6...v4.26.8)

Updates `golang.org/x/crypto` from 0.55.0 to 0.56.0
- [Commits](golang/crypto@v0.55.0...v0.56.0)

Updates `golang.org/x/oauth2` from 0.36.0 to 0.37.0
- [Commits](golang/oauth2@v0.36.0...v0.37.0)

Updates `google.golang.org/api` from 0.279.0 to 0.298.0
- [Release notes](https://github.com/googleapis/google-api-go-client/releases)
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md)
- [Commits](googleapis/google-api-go-client@v0.279.0...v0.298.0)

---
updated-dependencies:
- dependency-name: github.com/klauspost/compress
  dependency-version: 1.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: github.com/microsoft/go-mssqldb
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: github.com/rclone/rclone
  dependency-version: 1.75.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-and-patch
- dependency-name: github.com/shirou/gopsutil/v4
  dependency-version: 4.26.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/crypto
  dependency-version: 0.56.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/oauth2
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: google.golang.org/api
  dependency-version: 0.298.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 24, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants