build(deps): Bump the all-go group across 5 directories with 6 updates#2881
build(deps): Bump the all-go group across 5 directories with 6 updates#2881tac0turtle merged 4 commits intomainfrom
Conversation
Bumps the all-go group with 1 update in the / directory: [github.com/celestiaorg/go-header](https://github.com/celestiaorg/go-header). Bumps the all-go group with 1 update in the /execution/evm directory: [github.com/ethereum/go-ethereum](https://github.com/ethereum/go-ethereum). Bumps the all-go group with 2 updates in the /execution/grpc directory: [golang.org/x/net](https://github.com/golang/net) and [github.com/evstack/ev-node](https://github.com/evstack/ev-node). Bumps the all-go group with 2 updates in the /test/docker-e2e directory: [github.com/ethereum/go-ethereum](https://github.com/ethereum/go-ethereum) and [github.com/docker/docker](https://github.com/docker/docker). Bumps the all-go group with 2 updates in the /test/e2e directory: [github.com/ethereum/go-ethereum](https://github.com/ethereum/go-ethereum) and [github.com/celestiaorg/tastora](https://github.com/celestiaorg/tastora). Updates `github.com/celestiaorg/go-header` from 0.7.3 to 0.7.4 - [Release notes](https://github.com/celestiaorg/go-header/releases) - [Commits](celestiaorg/go-header@v0.7.3...v0.7.4) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `golang.org/x/net` from 0.46.0 to 0.47.0 - [Commits](golang/net@v0.46.0...v0.47.0) Updates `github.com/evstack/ev-node` from 1.0.0-beta.9 to 1.0.0-beta.10 - [Release notes](https://github.com/evstack/ev-node/releases) - [Changelog](https://github.com/evstack/ev-node/blob/main/CHANGELOG.md) - [Commits](v1.0.0-beta.9...v1.0.0-beta.10) Updates `golang.org/x/net` from 0.46.0 to 0.47.0 - [Commits](golang/net@v0.46.0...v0.47.0) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `github.com/docker/docker` from 28.5.1+incompatible to 28.5.2+incompatible - [Release notes](https://github.com/docker/docker/releases) - [Commits](moby/moby@v28.5.1...v28.5.2) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `github.com/celestiaorg/tastora` from 0.7.5 to 0.8.0 - [Release notes](https://github.com/celestiaorg/tastora/releases) - [Commits](celestiaorg/tastora@v0.7.5...v0.8.0) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) Updates `github.com/celestiaorg/tastora` from 0.7.5 to 0.8.0 - [Release notes](https://github.com/celestiaorg/tastora/releases) - [Commits](celestiaorg/tastora@v0.7.5...v0.8.0) Updates `github.com/ethereum/go-ethereum` from 1.16.6 to 1.16.7 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.16.6...v1.16.7) --- updated-dependencies: - dependency-name: github.com/celestiaorg/go-header dependency-version: 0.7.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: golang.org/x/net dependency-version: 0.47.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-go - dependency-name: github.com/evstack/ev-node dependency-version: 1.0.0-beta.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: golang.org/x/net dependency-version: 0.47.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/docker/docker dependency-version: 28.5.2+incompatible dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/celestiaorg/tastora dependency-version: 0.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go - dependency-name: github.com/celestiaorg/tastora dependency-version: 0.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-go - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-go ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest Buf updates on your PR. Results from workflow CI / buf-check (pull_request).
|
|
Claude finished @dependabot[bot]'s task —— View job Comprehensive Code ReviewTasks
SummaryThis Dependabot PR updates 6 Go dependencies across 5 directories. The changes include one critical security fix in go-ethereum and several important bug fixes. All changes appear safe to merge. Critical Security Finding✅ APPROVED - Critical Security Fix Includedgo-ethereum v1.16.6 → v1.16.7 contains a critical KZG cryptography vulnerability fix (CVE related to c-kzg-4844):
Dependency Updates Analysis1. github.com/celestiaorg/go-header (0.7.3 → 0.7.4)Type: Bug fixes (race condition fixes)
Assessment: ✅ Safe - These are defensive bug fixes that improve concurrency safety. 2. github.com/ethereum/go-ethereum (1.16.6 → 1.16.7)Type: Security fix + hardfork enablement
Assessment: ✅ Must merge - Contains critical security fix and required hardfork enablement. 3. golang.org/x/net (0.46.0 → 0.47.0)Type: Bug fixes and improvements
Assessment: ✅ Safe - Routine maintenance updates with bug fixes. 4. github.com/evstack/ev-node (1.0.0-beta.9 → 1.0.0-beta.10)Type: Feature additions and improvements
Breaking Changes:
Assessment: ✅ Safe - This is an internal dependency update that brings improvements to the project's own modules. 5. github.com/docker/docker (28.5.1 → 28.5.2)Type: Security fixes
Assessment: ✅ Should merge - Critical security fixes for container runtime used in tests. 6. github.com/celestiaorg/tastora (0.7.5 → 0.8.0)Type: Bug fixes and improvements
Assessment: ✅ Safe - Bug fixes and improvements to test framework. Code Changes Reviewexecution/evm/test/test_helpers.goChanges Made: - dockerClients = make(map[string]*dockerclient.Client)
+ dockerClients = make(map[string]types.TastoraDockerClient)
- func getTestScopedDockerSetup(t *testing.T) (*dockerclient.Client, string)
+ func getTestScopedDockerSetup(t *testing.T) (types.TastoraDockerClient, string)
- cli, netID := docker.DockerSetup(t)
+ cli, netID := docker.Setup(t)Assessment: ✅ Excellent
Strengths:
Module Consistency CheckAll go.mod files have been updated consistently:
Architecture & Code QualityStrengths:
No Issues Found:
Testing & CI
Security AssessmentPositive Findings:
No Security Concerns:
Performance & Resource EfficiencyExpected Impact:
DocumentationNote: The project's CLAUDE.md and CHANGELOG.md are well-maintained and document recent changes including the EVM execution client improvements from PR #2863. Recommendations1. MERGE IMMEDIATELY ✅This PR should be merged promptly due to:
2. Post-Merge ActionsAfter merging, consider:
3. Future Considerations
Final Verdict✅ APPROVED - RECOMMEND IMMEDIATE MERGE This PR contains critical security fixes and required hardfork enablement with no breaking changes to the codebase. All dependency updates are safe, well-tested, and improve the project's security posture. The single code change in Risk Level: Low |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2881 +/- ##
==========================================
- Coverage 64.81% 64.70% -0.11%
==========================================
Files 81 81
Lines 7347 7347
==========================================
- Hits 4762 4754 -8
- Misses 2043 2052 +9
+ Partials 542 541 -1
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
* main: build(deps): Bump mdast-util-to-hast from 13.2.0 to 13.2.1 in /docs in the npm_and_yarn group across 1 directory (#2900) refactor(block): centralize timeout in client (#2903) build(deps): Bump the all-go group across 2 directories with 3 updates (#2898) chore: bump default timeout (#2902) fix: revert default db (#2897) refactor: remove obsolete // +build tag (#2899) fix:da visualiser namespace (#2895) refactor: omit unnecessary reassignment (#2892) build(deps): Bump the all-go group across 5 directories with 6 updates (#2881) chore: fix inconsistent method name in retryWithBackoffOnPayloadStatus comment (#2889) fix: ensure consistent network ID usage in P2P subscriber (#2884) build(deps): Bump golangci/golangci-lint-action from 9.0.0 to 9.1.0 (#2885) build(deps): Bump actions/checkout from 5 to 6 (#2886)
Bumps the all-go group with 1 update in the / directory: github.com/celestiaorg/go-header.
Bumps the all-go group with 1 update in the /execution/evm directory: github.com/ethereum/go-ethereum.
Bumps the all-go group with 2 updates in the /execution/grpc directory: golang.org/x/net and github.com/evstack/ev-node.
Bumps the all-go group with 2 updates in the /test/docker-e2e directory: github.com/ethereum/go-ethereum and github.com/docker/docker.
Bumps the all-go group with 2 updates in the /test/e2e directory: github.com/ethereum/go-ethereum and github.com/celestiaorg/tastora.
Updates
github.com/celestiaorg/go-headerfrom 0.7.3 to 0.7.4Release notes
Sourced from github.com/celestiaorg/go-header's releases.
Commits
425f0dcfix(headertest): add locking to header test suite for concurrent use (#356)62199e0fix(store): fixes rare race condition where 2 workers attempt to close errCh ...Updates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
golang.org/x/netfrom 0.46.0 to 0.47.0Commits
9a29643go.mod: update golang.org/x dependencies07cefd8context: deprecate5ac9dacpublicsuffix: don't treat ip addresses as domain namesd1f64ccquic: use testing/synctestfff0469http2: document that RFC 7540 prioritization does not work with small payloadsf35e3a4http2: fix weight overflow in RFC 7540 write scheduler89adc90http2: fix typo referring to RFC 9218 as RFC 9128 instead8d76a2cquic: don't defer MAX_STREAMS frames indefinitely027f8b7quic: fix expected ACK Delay in client's ACK after HANDSHAKE_DONEdec9fe7dns/dnsmessage: update SVCB packing to prohibit name compressionUpdates
github.com/evstack/ev-nodefrom 1.0.0-beta.9 to 1.0.0-beta.10Changelog
Sourced from github.com/evstack/ev-node's changelog.
Commits
d7eda60refactor(syncer,cache): use compare and swap loop and add comments (#2873)9a5eba1refactor: use state da height as well (#2872)faabb32refactor: retrieve highest da height in cache (#2870)6badca1chore: change from event count to start and end height (#2871)12b9559chore: bump da (#2866)d8d1709chore: bump core (#2865)e5aa2c3chore: reduce log noise (#2864)9d4c64cfix: sync service for non zero height starts with empty store (#2834)3ad84b8build(deps): Bump golang.org/x/crypto from 0.43.0 to 0.45.0 in /execution/evm...2b45d45chore: minor improvement for docs (#2862)Updates
golang.org/x/netfrom 0.46.0 to 0.47.0Commits
9a29643go.mod: update golang.org/x dependencies07cefd8context: deprecate5ac9dacpublicsuffix: don't treat ip addresses as domain namesd1f64ccquic: use testing/synctestfff0469http2: document that RFC 7540 prioritization does not work with small payloadsf35e3a4http2: fix weight overflow in RFC 7540 write scheduler89adc90http2: fix typo referring to RFC 9218 as RFC 9128 instead8d76a2cquic: don't defer MAX_STREAMS frames indefinitely027f8b7quic: fix expected ACK Delay in client's ACK after HANDSHAKE_DONEdec9fe7dns/dnsmessage: update SVCB packing to prohibit name compressionUpdates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
github.com/docker/dockerfrom 28.5.1+incompatible to 28.5.2+incompatibleRelease notes
Sourced from github.com/docker/docker's releases.
Commits
89c5e8fMerge pull request #51396 from thaJeztah/28.x_backport_api_docs9b93878Merge pull request #51395 from thaJeztah/28.x_backport_rootless_reject6178456Merge pull request #51398 from vvoland/51397-28.x0cae4e5vendor: github.com/moby/buildkit v0.25.233cc06fMerge pull request #51394 from vvoland/51393-28.xd525277api/docs: remove BuildCache.Parent field for API v1.42 and up2fbc51bdockerd-rootless.sh: reject DOCKERD_ROOTLESS_ROOTLESSKIT_NET=hostbd98008integration-cli: Adjust nofile limits1967515Dockerfile: update runc binary to v1.3.34489660Merge pull request #51387 from thaJeztah/28.x_bump_goUpdates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
github.com/celestiaorg/tastorafrom 0.7.5 to 0.8.0Release notes
Sourced from github.com/celestiaorg/tastora's releases.
Commits
ef34bd5chore: fix jwt secret flag (#150)7defa8bchore: add labeled client and update volume cleanup (#145)97525e3chore(deps): bump github.com/consensys/gnark-crypto (#147)Updates
github.com/ethereum/go-ethereumfrom 1.16.6 to 1.16.7Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
b9f3a3dMerge branch 'master' into release/1.1607129d2version: release go-ethereum v1.16.7 stable653f8d4go.mod: update to c-kzg v2.1.5 (#33093)5b77af3version: begin v1.16.7 release cycleUpdates
github.com/celestiaorg/tastorafrom 0.7.5 to 0.8.0Release notes
Sourced from github.com/celestiaorg/tastora's releases.
Commits
ef34bd5chore: fix jwt secret flag (#150)