Skip to content

Bump the go_modules group across 1 directory with 3 updates - #121

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go_modules-377b4f7b2f
Closed

Bump the go_modules group across 1 directory with 3 updates#121
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go_modules-377b4f7b2f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 25, 2026

Copy link
Copy Markdown
Contributor

Bumps the go_modules group with 3 updates in the / directory: github.com/pion/dtls/v3, github.com/pion/stun/v3 and github.com/labstack/echo/v4.

Updates github.com/pion/dtls/v3 from 3.0.11 to 3.1.4

Release notes

Sourced from github.com/pion/dtls/v3's releases.

v3.1.4

Changelog

  • e4aad60b48a4f5619443902fb484053f53c4759b Retact v3.1.3 for breaking compatiblity with firefox
  • 0e3867b253131964ba5f527576ab739ff3cb2fac Restore Firefox compatibility
  • 12eb398551d48b762b067b412d311502030e66a5 Fix panic unmarshaling ECDHE_PSK ServerKeyExchange
  • 85fca0aac85f315fe1a35e918bbff024e5b1c987 Add MasterKeyIdentifier to use_srtp ext in flight3 (#835)
  • fd27a52a64265097a621432090926a651109b4cb Add private min and max version API (#823)
  • 620d6425fb873786357f9786982cf0e0981f34f2 Improve fuzzing for all extensions (#805)
  • 977de19f2d4f559f631c69280b2351f8478aa938 Update CI configs to v0.12.2
  • e6950f0291850b86fb704f65acf3ace88cd5b9d7 Filter non-approved FIPS curves in FIPS mode (#817)
  • 848c4bc17e147981c0b9e40bef866bb7f7c0a773 Optimize handshake memory usage
  • d0e736c2e6bcd89dada06355ef95fd0fe3957d14 DTLS 1.3 OID filter extension (#814)
  • 956d41df4ab17c1e1e387060c62242c72e8cd763 Update module golang.org/x/crypto to v0.48.0 (#809)
  • b86cb7515e56183ec0a3918d4f2738dc9b51f6ea Add missing checks and validations
  • 726522d91c73331f242ea6b5006a80e4c4244a6c Apply modernize and lint upgrades
  • d994b8bf4f571f1cf37a2f59d2c5e9b2c7a5efd7 Update CI configs to v0.12.1
  • 4fcce60395bf052abc530afd4a5ec25876e18fb4 Fix handshake hang on Finish in retransmit state
  • a25c8b860afe987ca4f17e0cc213ff686da652af Add ListenConfig option to Listener
  • 42b83fe3850722740d5258f878de148486a3ec83 Remove custom AddUint48 helper
  • 5a4e85a2fa567cc1da818d08ad2dad0d7a3346e2 DTLS 1.3 Add the Certificate Authorities extension (#807)
  • 812fc22c4f43abdf4d1da216e69e92421a64aa2c DTLS 1.3 post handshake auth extension (#806)
  • 39f310037631fb84fc47ff73447b23387eb666e3 DTLS 1.3 Add EarlyDataIndication extension (#804)
  • d1d58f212102887ef3c7e6b696d6bc218af3d7b9 Update CI configs to v0.12.0
  • 16413bad7fa0426de4c11d95f1ed2e76c0159d8b Add HKDF funcs for Key Scheduling - DTLS v1.3 (#737)
  • accee59ca63fc19171f0b807b378bb96aa49d33a Implement ChaCha20-Poly1305 Ciphersuite (#794)
  • 6b4fe8c044e03a73b6ecc8516911c7842268a430 Add RSA_PSS_RSAE back to DTLS 1.2 and fix parsing (#801)
  • 5ee9206c372458946776fe12cc7239acdd792e29 Upgrade E2E Test Docker Image (for OpenSSL 3.x) (#799)

v3.1.3

Changelog

  • 49458d604a4f3ebce1bf9587a0f3e5f3f6b4a55e Fix panic unmarshaling ECDHE_PSK ServerKeyExchange
  • e4b257d7ea9ce71c683f62a8533e06ffe1c433ee Add MasterKeyIdentifier to use_srtp ext in flight3 (#835)
  • fd27a52a64265097a621432090926a651109b4cb Add private min and max version API (#823)
  • 620d6425fb873786357f9786982cf0e0981f34f2 Improve fuzzing for all extensions (#805)
  • 977de19f2d4f559f631c69280b2351f8478aa938 Update CI configs to v0.12.2
  • e6950f0291850b86fb704f65acf3ace88cd5b9d7 Filter non-approved FIPS curves in FIPS mode (#817)
  • 848c4bc17e147981c0b9e40bef866bb7f7c0a773 Optimize handshake memory usage
  • d0e736c2e6bcd89dada06355ef95fd0fe3957d14 DTLS 1.3 OID filter extension (#814)
  • 956d41df4ab17c1e1e387060c62242c72e8cd763 Update module golang.org/x/crypto to v0.48.0 (#809)
  • b86cb7515e56183ec0a3918d4f2738dc9b51f6ea Add missing checks and validations
  • 726522d91c73331f242ea6b5006a80e4c4244a6c Apply modernize and lint upgrades
  • d994b8bf4f571f1cf37a2f59d2c5e9b2c7a5efd7 Update CI configs to v0.12.1
  • 4fcce60395bf052abc530afd4a5ec25876e18fb4 Fix handshake hang on Finish in retransmit state
  • a25c8b860afe987ca4f17e0cc213ff686da652af Add ListenConfig option to Listener
  • 42b83fe3850722740d5258f878de148486a3ec83 Remove custom AddUint48 helper
  • 5a4e85a2fa567cc1da818d08ad2dad0d7a3346e2 DTLS 1.3 Add the Certificate Authorities extension (#807)
  • 812fc22c4f43abdf4d1da216e69e92421a64aa2c DTLS 1.3 post handshake auth extension (#806)
  • 39f310037631fb84fc47ff73447b23387eb666e3 DTLS 1.3 Add EarlyDataIndication extension (#804)
  • d1d58f212102887ef3c7e6b696d6bc218af3d7b9 Update CI configs to v0.12.0
  • 16413bad7fa0426de4c11d95f1ed2e76c0159d8b Add HKDF funcs for Key Scheduling - DTLS v1.3 (#737)

... (truncated)

Commits
  • e4aad60 Retact v3.1.3 for breaking compatiblity with firefox
  • 0e3867b Restore Firefox compatibility
  • 12eb398 Fix panic unmarshaling ECDHE_PSK ServerKeyExchange
  • 85fca0a Add MasterKeyIdentifier to use_srtp ext in flight3 (#835)
  • fd27a52 Add private min and max version API (#823)
  • 620d642 Improve fuzzing for all extensions (#805)
  • 977de19 Update CI configs to v0.12.2
  • e6950f0 Filter non-approved FIPS curves in FIPS mode (#817)
  • 848c4bc Optimize handshake memory usage
  • d0e736c DTLS 1.3 OID filter extension (#814)
  • Additional commits viewable in compare view

Updates github.com/pion/stun/v3 from 3.0.2 to 3.1.5

Release notes

Sourced from github.com/pion/stun/v3's releases.

v3.1.5

Changelog

  • 02391b37388c7be80b4dafaec9b3e708d58d2aed Upgrade dtls to fix compatibility with firefox

v3.1.4

Changelog

  • 6a869cb3ce12869699dbf007fa48e1ce6760eca5 Update module github.com/pion/dtls/v3 to v3.1.3
  • 8f24ef3b428599b877f0c013fe2cc93670e5bc04 Update module github.com/pion/transport/v4 to v4.0.2

v3.1.3

Changelog

  • fa9f074a33a8059c76c960b1fbee39f308002423 Fix panic on short XOR-MAPPED-ADDRESS value
  • 01aa5b8eefd0c0934c6aebd2bd6b6fa7d3c7d715 Throw an error when parsing message type 0x000
  • c41a7f3240229f74db15968e1657c05b1ecb1037 Add opt-in strict mode and custom logger
  • bc40ca270a5fe67eabce506c1f4e154f804dbc36 Ignore attributes after message-integrity
  • 293095f9198ea72918620fb1e0177a9aaeb211db Update CI configs to v0.12.2

v3.1.2

Changelog

  • f927db87cf42b1a39cb233764eb3f9abbf9d414b Keep DTLS configs until API change
  • 20e8a63ba63129edb660b6c90fdfb22e93562dca Apply modernize, link upgrades and checks
  • 1a06979434a655d93a53ea7bdcbf85035c15f852 Update CI configs to v0.12.1
  • 97b4669b3803421b9b6aebafae6a5beb9fb76498 Update module github.com/pion/dtls/v3 to v3.1.2
  • 31c4046316a11c2125dddd7e73cb50b4c6b50d3c Update module github.com/pion/dtls/v3 to v3.0.11 [SECURITY] (#268)
  • e615214b639f76a558da9b2210eee4e9e417c338 Update CI configs to v0.12.0
  • 9279313de626b55b7b30b90af26fcd49641fd6a4 Update CI configs to v0.11.39
  • be995ed92bfcceded27a8b830f07a962dd751e7b Use constant format string
  • 76f3a9ffabac570cca57c006ae6e178b12c02caf Update CI configs to v0.11.37

v3.1.1

Changelog

  • e31e96800f14507aa5618ef704db8e0083672e0d Upgrade to pion/transport/v4

v3.1.0

Changelog

  • fbaf0f0bd7cb17d3b2db2e970ac8eb1ff21fa7cc Add STUN attributes for DTLS-in-STUN (SPED)
  • 488a5a874f08f0184264fe31a3e87881bb24fb92 Update CI configs to v0.11.36
  • b321b990c03fc614e465ab10753fc98e24bd095e Update module github.com/pion/dtls/v3 to v3.0.9
Commits
  • 02391b3 Upgrade dtls to fix compatibility with firefox
  • 6a869cb Update module github.com/pion/dtls/v3 to v3.1.3
  • 8f24ef3 Update module github.com/pion/transport/v4 to v4.0.2
  • fa9f074 Fix panic on short XOR-MAPPED-ADDRESS value
  • 01aa5b8 Throw an error when parsing message type 0x000
  • c41a7f3 Add opt-in strict mode and custom logger
  • bc40ca2 Ignore attributes after message-integrity
  • 293095f Update CI configs to v0.12.2
  • f927db8 Keep DTLS configs until API change
  • 20e8a63 Apply modernize, link upgrades and checks
  • Additional commits viewable in compare view

Updates github.com/labstack/echo/v4 from 4.13.3 to 4.15.3

Release notes

Sourced from github.com/labstack/echo/v4's releases.

v4.15.3 - Static encoded-separator route bypass fix (GHSA-vfp3-v2gw-7wfq)

Security

Fixes GHSA-vfp3-v2gw-7wfq: an encoded path separator (%2F or %5C) in a static file URL could bypass route-level middleware (e.g. authentication on a sibling route) and disclose static files. Both StaticDirectoryHandler (used by Static/StaticFS) and the Static middleware are affected. Backport of the v5 fix (#3009, released in v5.2.0). Thanks to @​a-tt-om and @​oran-gugu for reporting.

Full Changelog: labstack/echo@v4.15.2...v4.15.3

v4.15.2 - Context.Scheme() header validation

Security

Thanks to @​shblue21 for reporting this issue.

Full Changelog: labstack/echo@v4.15.1...v4.15.2

v4.15.1

What's Changed

Full Changelog: labstack/echo@v4.15.0...v4.15.1

v4.15.0

Security

WARNING: If your application relies on cross-origin or same-site (same subdomain) requests do not blindly push this version to production

The CSRF middleware now supports the Sec-Fetch-Site header as a modern, defense-in-depth approach to CSRF protection, implementing the OWASP-recommended Fetch Metadata API alongside the traditional token-based mechanism.

How it works:

Modern browsers automatically send the Sec-Fetch-Site header with all requests, indicating the relationship between the request origin and the target. The middleware uses this to make security decisions:

  • same-origin or none: Requests are allowed (exact origin match or direct user navigation)
  • same-site: Falls back to token validation (e.g., subdomain to main domain)
  • cross-site: Blocked by default with 403 error for unsafe methods (POST, PUT, DELETE, PATCH)

For browsers that don't send this header (older browsers), the middleware seamlessly falls back to traditional token-based CSRF protection.

New Configuration Options:

  • TrustedOrigins []string: Allowlist specific origins for cross-site requests (useful for OAuth callbacks, webhooks)
  • AllowSecFetchSiteFunc func(echo.Context) (bool, error): Custom logic for same-site/cross-site request validation

... (truncated)

Changelog

Sourced from github.com/labstack/echo/v4's changelog.

v4.15.3 - 2026-06-14

Security

Fixes GHSA-vfp3-v2gw-7wfq: an encoded path separator (%2F or %5C) in a static file URL could bypass route-level middleware (e.g. authentication on a sibling route) and disclose static files. Both StaticDirectoryHandler (used by Static/StaticFS) and the Static middleware are affected. Backport of the v5 fix (#3009). Thanks to @​a-tt-om and @​oran-gugu for reporting.

v4.15.2 - 2026-05-01

Security

Thanks to @​shblue21 for reporting this issue.

v4.15.1 - 2026-02-22

Enhancements

v4.15.0 - 2026-01-01

Security

NB: If your application relies on cross-origin or same-site (same subdomain) requests do not blindly push this version to production

The CSRF middleware now supports the Sec-Fetch-Site header as a modern, defense-in-depth approach to CSRF protection, implementing the OWASP-recommended Fetch Metadata API alongside the traditional token-based mechanism.

How it works:

Modern browsers automatically send the Sec-Fetch-Site header with all requests, indicating the relationship between the request origin and the target. The middleware uses this to make security decisions:

  • same-origin or none: Requests are allowed (exact origin match or direct user navigation)
  • same-site: Falls back to token validation (e.g., subdomain to main domain)
  • cross-site: Blocked by default with 403 error for unsafe methods (POST, PUT, DELETE, PATCH)

For browsers that don't send this header (older browsers), the middleware seamlessly falls back to traditional token-based CSRF protection.

New Configuration Options:

  • TrustedOrigins []string: Allowlist specific origins for cross-site requests (useful for OAuth callbacks, webhooks)

... (truncated)

Commits
  • 8800212 Changelog for v4.15.3 (#3012)
  • c3fa2a2 fix(static): reject encoded path separators that bypass route-level middlewar...
  • 25685e6 Merge pull request #2963 from aldas/v4_changelog_4_15_2
  • f9d7689 Changelog for v4.15.2
  • 37fff28 Merge pull request #2962 from aldas/v4_valid_proto
  • ca4f38a Context.Scheme should validate values taken from header
  • 2e527a7 Update CI, update deps
  • 6f3a84a Merge pull request #2905 from aldas/v4_crsf_token_fallback
  • 24fa4d0 CSRF: support older token-based CSRF protection handler that want to render t...
  • 482bb46 v4.15.0 changelog
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the go_modules group with 3 updates in the / directory: [github.com/pion/dtls/v3](https://github.com/pion/dtls), [github.com/pion/stun/v3](https://github.com/pion/stun) and [github.com/labstack/echo/v4](https://github.com/labstack/echo).


Updates `github.com/pion/dtls/v3` from 3.0.11 to 3.1.4
- [Release notes](https://github.com/pion/dtls/releases)
- [Commits](pion/dtls@v3.0.11...v3.1.4)

Updates `github.com/pion/stun/v3` from 3.0.2 to 3.1.5
- [Release notes](https://github.com/pion/stun/releases)
- [Commits](pion/stun@v3.0.2...v3.1.5)

Updates `github.com/labstack/echo/v4` from 4.13.3 to 4.15.3
- [Release notes](https://github.com/labstack/echo/releases)
- [Changelog](https://github.com/labstack/echo/blob/v4.15.3/CHANGELOG.md)
- [Commits](labstack/echo@v4.13.3...v4.15.3)

---
updated-dependencies:
- dependency-name: github.com/pion/dtls/v3
  dependency-version: 3.1.4
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: github.com/pion/stun/v3
  dependency-version: 3.1.5
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: github.com/labstack/echo/v4
  dependency-version: 4.15.3
  dependency-type: indirect
  dependency-group: go_modules
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Aug 25, 2026
@vercel

vercel Bot commented Aug 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
remote-controller-client Ready Ready Preview Aug 25, 2026 4:36pm

@PiterWeb PiterWeb closed this Aug 26, 2026
@PiterWeb
PiterWeb deleted the dependabot/go_modules/go_modules-377b4f7b2f branch August 26, 2026 09:56
@dependabot @github

dependabot Bot commented on behalf of github Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant