Skip to content

build(deps): bump the minor-and-patch group across 1 directory with 9 updates - #38

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/minor-and-patch-0e8cc94234
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/minor-and-patch-0e8cc94234

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 23, 2026 •

Copy link
Copy Markdown

Bumps the minor-and-patch group with 9 updates in the / directory:

Package From To
github.com/a-h/templ 0.3.1001 0.3.1020
github.com/jackc/pgx/v5 5.10.0 5.11.0
github.com/redis/go-redis/v9 9.21.0 9.22.0
github.com/xraph/forge 1.9.13 1.11.1
github.com/xraph/forge/extensions/auth 1.10.0 1.11.1
github.com/xraph/go-utils 1.2.2 1.3.0
go.mongodb.org/mongo-driver/v2 2.5.0 2.9.1
go.opentelemetry.io/otel 1.44.0 1.46.0
go.opentelemetry.io/otel/trace 1.44.0 1.46.0

Updates github.com/a-h/templ from 0.3.1001 to 0.3.1020

Release notes

Sourced from github.com/a-h/templ's releases.

v0.3.1020

Changelog

  • 09d6b02 chore: bump version
  • a411f13 chore: fix linter warning in test code
  • 524cd39 feat: add -check flag, closes #1007 (#1373)
  • f3d595c feat: add Range to ExpressionAttribute nodes (#1347)
  • 82af17c feat: add Range to GoCode nodes (#1348)
  • cf98cdc feat: add Range to StringExpression nodes (#1349)
  • ff38cee feat: add ranges for attribute node values (#1383)
  • 552ed02 feat: support concurrent rendering of templ components (#1359)
  • b310a97 fix(generatecmd): check cmd.Start() error before inserting cmd in to running map (#1382)
  • 410a80e fix(lsp): delete $GOROOT hack in uri.File
  • 95a0854 fix: allow JSFuncCall on arbitrary HTML attributes (#1375)
  • e581c01 fix: attributes containing a conditional, are always multiline (#1380)
  • b2952ed fix: clear children context in Fragment.Render (#1360)
  • 8fecf2d fix: prevent corrupted output in watch mode with gzip, fixes #1365 (#1366)
  • 7adcb62 fix: show correct updates based on written Go files without watch (#1363)
  • aa493e0 fix: track Range for non-JavaScript ScriptExpression nodes (#1350)
  • d52d64e fix: use dedicated shadow host in Suspense example to ensure header is rendered (#1370)
  • 83176f9 fix: vulnerabilities in x/net (only affects templ watch mode and tests), fixes #1354
Commits
  • 09d6b02 chore: bump version
  • ff38cee feat: add ranges for attribute node values (#1383)
  • e581c01 fix: attributes containing a conditional, are always multiline (#1380)
  • b310a97 fix(generatecmd): check cmd.Start() error before inserting cmd in to `run...
  • 95a0854 fix: allow JSFuncCall on arbitrary HTML attributes (#1375)
  • 8fecf2d fix: prevent corrupted output in watch mode with gzip, fixes #1365 (#1366)
  • a411f13 chore: fix linter warning in test code
  • 524cd39 feat: add -check flag, closes #1007 (#1373)
  • d52d64e fix: use dedicated shadow host in Suspense example to ensure header is render...
  • 552ed02 feat: support concurrent rendering of templ components (#1359)
  • Additional commits viewable in compare view

Updates github.com/jackc/pgx/v5 from 5.10.0 to 5.11.0

Release notes

Sourced from github.com/jackc/pgx/v5's releases.

v5.11.0

This release adds direct PostgreSQL type scanning through database/sql on Go 1.27, improves compatibility with libpq connection strings and PostgreSQL date/time values, and includes further decoder hardening. See Changes for connection-string and date/time behavior changes that may affect existing applications.

Features

  • stdlib: support Go 1.27's driver.RowsColumnScanner, allowing PostgreSQL types such as arrays and ranges to be scanned directly into Go values without pgtype.Map.SQLScanner. Existing database/sql scalar conversions and sql.Scanner behavior are preserved. The minimum supported Go version remains 1.25.
  • Add Rows.TypeMap to expose the type map used to decode rows, including rows created by RowsFromResultReader that have no underlying Conn. Custom implementations of Rows, including mocks, must add this method.
  • pgconn: add Config.MaxProtocolMessageBodyLen to configure the maximum incoming protocol message body size (carter-ya)
  • pgconn: add ErrReadOnlyConnection, ErrReadWriteConnection, ErrPrimaryConnection, and ErrStandbyConnection sentinel errors for target_session_attrs validation, allowing callers to use errors.Is (Adrian-Stefan Mares)
  • pgxpool: accept pool_ping_timeout in connection strings to configure Config.PingTimeout. The default is zero; zero and negative durations mean no timeout (1991santhu)

Changes

  • Name-based row-to-struct mapping now matches explicit db tags case-insensitively, with exact matches taking precedence so tags can still distinguish quoted column names that differ only by case (AlisinaDevelo)

  • pgconn: resolve the OS user account only when no user is supplied by the connection string, environment, or service file, avoiding unnecessary account lookups and crashes in some restricted container environments. Home-directory defaults for password, service, and TLS files remain available independently of the account lookup. On Unix these now use $HOME rather than the OS account's home directory (Mohamed MAACHE)

  • pgtype: date, timestamp and timestamptz text values are now parsed and written by a hand-written parser and encoder for PostgreSQL's ISO date/time format instead of time.Parse and time.Format. Go's layout language cannot express a variable-width year or the BC era, which is the root of the bugs below. The text scan path is roughly 2.5x faster for timestamp and timestamptz. Bug fixes:

    • timestamp and timestamptz no longer silently move February 29 of a BC leap year to March 1 when encoding. time.Date(-4712, 2, 29, ...) was written as 4713-03-01 BC and is now written as 4713-02-29 BC. This affected ordinary four-digit BC years, not only extended-range ones. date was never affected.
    • timestamp and timestamptz can now scan BC leap days. 4713-02-29 BC previously failed with day out of range. date could already scan them.
    • Years past 9999 can now be scanned. 10000-01-02 03:04:05 previously failed to parse, so timestamp and timestamptz values at the high end of PostgreSQL's range were unreadable over the simple protocol and in any other text-format result.
    • time.Time arguments in the simple protocol now encode BC dates correctly, using the same timestamp encoder.
    • Fractional seconds beyond microsecond precision are rounded the way the server rounds them (round half to even, carrying into the rest of the value) instead of being kept at full precision. PostgreSQL never sends more than six fractional digits, so this only affects values from other sources.

    Behavior changes:

    • date now rejects impossible dates instead of normalizing them. 2024-02-30 returned 2024-03-01 and 2024-13-01 returned 2025-01-01; both are now errors. timestamp and timestamptz already rejected them.
    • All three types now reject values outside PostgreSQL's range for that type, in the binary format as well as the text format. PostgreSQL never sends out-of-range dates, so this only affects corrupt or hand-built input; the range

... (truncated)

Changelog

Sourced from github.com/jackc/pgx/v5's changelog.

5.11.0 (September 7, 2026)

This release adds direct PostgreSQL type scanning through database/sql on Go 1.27, improves compatibility with libpq connection strings and PostgreSQL date/time values, and includes further decoder hardening. See Changes for connection-string and date/time behavior changes that may affect existing applications.

Features

  • stdlib: support Go 1.27's driver.RowsColumnScanner, allowing PostgreSQL types such as arrays and ranges to be scanned directly into Go values without pgtype.Map.SQLScanner. Existing database/sql scalar conversions and sql.Scanner behavior are preserved. The minimum supported Go version remains 1.25.
  • Add Rows.TypeMap to expose the type map used to decode rows, including rows created by RowsFromResultReader that have no underlying Conn. Custom implementations of Rows, including mocks, must add this method.
  • pgconn: add Config.MaxProtocolMessageBodyLen to configure the maximum incoming protocol message body size (carter-ya)
  • pgconn: add ErrReadOnlyConnection, ErrReadWriteConnection, ErrPrimaryConnection, and ErrStandbyConnection sentinel errors for target_session_attrs validation, allowing callers to use errors.Is (Adrian-Stefan Mares)
  • pgxpool: accept pool_ping_timeout in connection strings to configure Config.PingTimeout. The default is zero; zero and negative durations mean no timeout (1991santhu)

Changes

  • Name-based row-to-struct mapping now matches explicit db tags case-insensitively, with exact matches taking precedence so tags can still distinguish quoted column names that differ only by case (AlisinaDevelo)

  • pgconn: resolve the OS user account only when no user is supplied by the connection string, environment, or service file, avoiding unnecessary account lookups and crashes in some restricted container environments. Home-directory defaults for password, service, and TLS files remain available independently of the account lookup. On Unix these now use $HOME rather than the OS account's home directory (Mohamed MAACHE)

  • pgtype: date, timestamp and timestamptz text values are now parsed and written by a hand-written parser and encoder for PostgreSQL's ISO date/time format instead of time.Parse and time.Format. Go's layout language cannot express a variable-width year or the BC era, which is the root of the bugs below. The text scan path is roughly 2.5x faster for timestamp and timestamptz. Bug fixes:

    • timestamp and timestamptz no longer silently move February 29 of a BC leap year to March 1 when encoding. time.Date(-4712, 2, 29, ...) was written as 4713-03-01 BC and is now written as 4713-02-29 BC. This affected ordinary four-digit BC years, not only extended-range ones. date was never affected.
    • timestamp and timestamptz can now scan BC leap days. 4713-02-29 BC previously failed with day out of range. date could already scan them.
    • Years past 9999 can now be scanned. 10000-01-02 03:04:05 previously failed to parse, so timestamp and timestamptz values at the high end of PostgreSQL's range were unreadable over the simple protocol and in any other text-format result.
    • time.Time arguments in the simple protocol now encode BC dates correctly, using the same timestamp encoder.
    • Fractional seconds beyond microsecond precision are rounded the way the server rounds them (round half to even, carrying into the rest of the value) instead of being kept at full precision. PostgreSQL never sends more than six fractional digits, so this only affects values from other sources.

    Behavior changes:

    • date now rejects impossible dates instead of normalizing them. 2024-02-30 returned 2024-03-01 and 2024-13-01 returned 2025-01-01; both are now errors. timestamp and timestamptz already rejected them.
    • All three types now reject values outside PostgreSQL's range for that type, in the binary format as well as the

... (truncated)

Commits
  • 5e583fa Update changelog for v5.11.0
  • 3927116 Apply gofumpt formatting required by lint
  • eb07165 Quote filesystem paths in development connection strings
  • cf5938f Allow unsigned digit counts in binary numeric encoding
  • 3930cf5 Accept PostgreSQL POSIX timezone offsets in text timestamps
  • 93261be Prefer exact db tag matches when mapping rows to structs
  • e8d8ad1 Merge pull request #2647 from sueun-dev/fix-range-text-quoting-20260906
  • 01d2fd3 Merge pull request #2644 from eliranbz/fix-failed-prepare-deallocation
  • 9b7e3be Merge pull request #2645 from ash2k/move-channel
  • 76d78f5 Merge pull request #2643 from AshSgDe29071999/fix/hstore-pairs-estimate-clamp
  • Additional commits viewable in compare view

Updates github.com/redis/go-redis/v9 from 9.21.0 to 9.22.0

Release notes

Sourced from github.com/redis/go-redis/v9's releases.

9.22.0

This is a minor release introducing two flagship (experimental) features — client-side caching and automatic pipelining — alongside support for Redis 8.10, new commands, and a large batch of stability and parser-robustness fixes. It consolidates everything shipped in 9.22.0-beta.1, so the notes below cover the full 9.21.0 → 9.22.0 upgrade.

⚠️ Two changes to be aware of when upgrading from 9.21.0:

  • Default configuration values changed (#3918): read/write timeouts, retry backoff, cluster state reload interval, and TCP keep-alive defaults are now aligned with the cross-SDK configuration proposal (see the highlight below). Explicitly configured values are unaffected.
  • WaitAOF return type corrected (#3888): WaitAOF now returns *IntSliceCmd, matching the two-integer reply of WAITAOF (previously *IntCmd, which failed to parse the reply at runtime). Code referencing the old return type needs a one-line update.

🚀 Highlights

Client-Side Caching (Experimental)

The standalone Client gains server-assisted client-side caching built on RESP3 CLIENT TRACKING. Enable it by setting ClientSideCacheConfig in Options (or supply your own cache via ClientSideCache — e.g. to share one cache across clients). Cacheable read results are served from a local in-process cache and invalidated automatically when the server reports a change, cutting round trips for read-heavy workloads.

The invalidation architecture is selected by ClientSideCacheStrategy; the default (and currently only) strategy is CSCStrategySharedTracking: one shared cache, every pool connection runs plain CLIENT TRACKING ON, and a background drainer applies buffered invalidations — portable (no BCAST) and consistent with the other Redis client libraries. Requirements and guardrails: RESP3 (Protocol: 3), standalone client, DB 0 only; commands that would change the connection identity (SELECT, AUTH, ...) are rejected while caching is enabled, and CSC is disabled when a credentials provider is set (fixed Username/Password work and are namespaced). See the README's client-side caching section and the runnable example.

Experimental: the API may change in a minor release.

(#3941) by @​ofekshenawa

Automatic Pipelining (Experimental)

AutoPipeliner is a background batcher that coalesces commands from many concurrent goroutines into Redis pipelines, multiplying throughput without any manual pipeline management. It comes in two faces, available on Client and ClusterClient (and configurable via Options.AutoPipelineOptions / UniversalOptions.AutoPipelineOptions):

  • AutoPipeline() — the blocking face: a drop-in Cmdable where each call blocks until executed, exactly like a plain client, while concurrent callers' commands batch together under the hood (measured locally over loopback: ~1M+ SET/sec vs ~100k unpipelined; indicative, not a guarantee). Per-goroutine command order is preserved.
  • AsyncAutoPipeline() — the deferred face: command calls return immediately and every typed result accessor (Val/Result/Err/...) blocks until the command has executed. Submit a window of commands, then read the results, to keep pipelines deep (~2–3M SET/sec locally; indicative).

AutoPipelineOptions controls batching: MaxBatchSize (soft target, default 200; the blocking face's preset uses 300), MaxBatchBytes (approximate payload cap so huge values flush as several bounded writes), MaxFlushDelay with optional AdaptiveDelay (delay scales down as the queue fills), and MaxConcurrentBatches (default 1 = a single ordered batch stream; raising it requires Unordered: true, so ordering is never lost by accident — Validate() rejects the combination otherwise). A usage tour and throughput comparison live in https://github.com/redis/go-redis/blob/HEAD/example/autopipeline.

Experimental: the API may change in a future release — pin your go-redis version if you adopt it.

(#3942) by @​ndyakov, with help from @​cxljs

Redis 8.10 Support

This release adds support for Redis 8.10. The README's supported-versions list now includes Redis 8.10, and CI runs the full suite against the redislabs/client-libs-test:8.10.0 image by default (#3920, #3940).

Coverage for the new commands and options that ship with Redis 8.10:

  • HIMPORT (#3919) — bulk hash import via server-side fieldsets, exposed as HImportPrepare, HImportSet, HImportDiscard, and HImportDiscardAll. Fieldsets are session state scoped to a single physical connection, which does not mix well with connection pooling — so the client keeps a versioned fieldset registry and lazily replays the PREPARE on whichever pooled connection executes a SET that needs it, at most once per connection, with no extra round trip (the PREPARE is injected into the same write as the SET).
  • LMOVEM / BLMOVEM (#3913) — move multiple elements between lists in one call.
  • SUNIONCARD / SDIFFCARD (#3897) — cardinality of set union/difference without materializing the result.
  • XREAD / XREADGROUP MAXCOUNT and MAXSIZE (#3898) — bound how much data a stream read returns.
  • TS.READ (#3896), TS.QUERYLABELS (#3926), TS.NRANGE / TS.NREVRANGE (#3870) with multiple aggregators per key (#3937), and EXCLUDEEMPTY on TS.MRANGE / TS.MREVRANGE (#3912) — new time-series query surface.
  • FT.ALIASLIST (#3925), COLLECT reducer for FT.AGGREGATE (#3886), RERANK on HNSW vector fields in FT.CREATE (#3927), and FT.HYBRID timeout warnings (#3911) — search coverage.

Cross-SDK Aligned Defaults

Default configuration values now follow the cross-SDK configuration proposal shared by all Redis client libraries (#3918):

... (truncated)

Changelog

Sourced from github.com/redis/go-redis/v9's changelog.

9.22.0 (2026-08-03)

This is a minor release introducing two flagship (experimental) features — client-side caching and automatic pipelining — alongside support for Redis 8.10, new commands, and a large batch of stability and parser-robustness fixes. It consolidates everything shipped in 9.22.0-beta.1, so the notes below cover the full 9.21.0 → 9.22.0 upgrade.

⚠️ Two changes to be aware of when upgrading from 9.21.0:

  • Default configuration values changed (#3918): read/write timeouts, retry backoff, cluster state reload interval, and TCP keep-alive defaults are now aligned with the cross-SDK configuration proposal (see the highlight below). Explicitly configured values are unaffected.
  • WaitAOF return type corrected (#3888): WaitAOF now returns *IntSliceCmd, matching the two-integer reply of WAITAOF (previously *IntCmd, which failed to parse the reply at runtime). Code referencing the old return type needs a one-line update.

🚀 Highlights

Client-Side Caching (Experimental)

The standalone Client gains server-assisted client-side caching built on RESP3 CLIENT TRACKING. Enable it by setting ClientSideCacheConfig in Options (or supply your own cache via ClientSideCache — e.g. to share one cache across clients). Cacheable read results are served from a local in-process cache and invalidated automatically when the server reports a change, cutting round trips for read-heavy workloads.

The invalidation architecture is selected by ClientSideCacheStrategy; the default (and currently only) strategy is CSCStrategySharedTracking: one shared cache, every pool connection runs plain CLIENT TRACKING ON, and a background drainer applies buffered invalidations — portable (no BCAST) and consistent with the other Redis client libraries. Requirements and guardrails: RESP3 (Protocol: 3), standalone client, DB 0 only; commands that would change the connection identity (SELECT, AUTH, ...) are rejected while caching is enabled, and CSC is disabled when a credentials provider is set (fixed Username/Password work and are namespaced). See the README's client-side caching section and the runnable example.

Experimental: the API may change in a minor release.

(#3941) by @​ofekshenawa

Automatic Pipelining (Experimental)

AutoPipeliner is a background batcher that coalesces commands from many concurrent goroutines into Redis pipelines, multiplying throughput without any manual pipeline management. It comes in two faces, available on Client and ClusterClient (and configurable via Options.AutoPipelineOptions / UniversalOptions.AutoPipelineOptions):

  • AutoPipeline() — the blocking face: a drop-in Cmdable where each call blocks until executed, exactly like a plain client, while concurrent callers' commands batch together under the hood (measured locally over loopback: ~1M+ SET/sec vs ~100k unpipelined; indicative, not a guarantee). Per-goroutine command order is preserved.
  • AsyncAutoPipeline() — the deferred face: command calls return immediately and every typed result accessor (Val/Result/Err/...) blocks until the command has executed. Submit a window of commands, then read the results, to keep pipelines deep (~2–3M SET/sec locally; indicative).

AutoPipelineOptions controls batching: MaxBatchSize (soft target, default 200; the blocking face's preset uses 300), MaxBatchBytes (approximate payload cap so huge values flush as several bounded writes), MaxFlushDelay with optional AdaptiveDelay (delay scales down as the queue fills), and MaxConcurrentBatches (default 1 = a single ordered batch stream; raising it requires Unordered: true, so ordering is never lost by accident — Validate() rejects the combination otherwise). A usage tour and throughput comparison live in https://github.com/redis/go-redis/blob/master/example/autopipeline.

Experimental: the API may change in a future release — pin your go-redis version if you adopt it.

(#3942) by @​ndyakov, with help from @​cxljs

Redis 8.10 Support

This release adds support for Redis 8.10. The README's supported-versions list now includes Redis 8.10, and CI runs the full suite against the redislabs/client-libs-test:8.10.0 image by default (#3920, #3940).

Coverage for the new commands and options that ship with Redis 8.10:

  • HIMPORT (#3919) — bulk hash import via server-side fieldsets, exposed as HImportPrepare, HImportSet, HImportDiscard, and HImportDiscardAll. Fieldsets are session state scoped to a single physical connection, which does not mix well with connection pooling — so the client keeps a versioned fieldset registry and lazily replays the PREPARE on whichever pooled connection executes a SET that needs it, at most once per connection, with no extra round trip (the PREPARE is injected into the same write as the SET).
  • LMOVEM / BLMOVEM (#3913) — move multiple elements between lists in one call.
  • SUNIONCARD / SDIFFCARD (#3897) — cardinality of set union/difference without materializing the result.
  • XREAD / XREADGROUP MAXCOUNT and MAXSIZE (#3898) — bound how much data a stream read returns.
  • TS.READ (#3896), TS.QUERYLABELS (#3926), TS.NRANGE / TS.NREVRANGE (#3870) with multiple aggregators per key (#3937), and EXCLUDEEMPTY on TS.MRANGE / TS.MREVRANGE (#3912) — new time-series query surface.
  • FT.ALIASLIST (#3925), COLLECT reducer for FT.AGGREGATE (#3886), RERANK on HNSW vector fields in FT.CREATE (#3927), and FT.HYBRID timeout warnings (#3911) — search coverage.

Cross-SDK Aligned Defaults

Default configuration values now follow the cross-SDK configuration proposal shared by all Redis client libraries (#3918):

... (truncated)

Commits
  • c7f59a2 chore(release): prepare 9.22.0 (#3947)
  • c994cfc feat(autopipeline): automatic command pipelining (#3942)
  • 228b463 chore(deps): bump actions/stale from 10 to 11 (#3944)
  • a6be850 feat(csc): add standalone client-side caching (#3941)
  • 82b0213 chore(release): prepare 9.22.0-beta.1 (#3940)
  • 8eb9583 fix(rediscmd): redact credential args in AppendCmd (#3939)
  • 90fd088 chore(ci): point 8.10 testing at custom client-libs-test image (#3938)
  • 93f961a feat(timeseries): support multiple aggregators per key in TS.NRANGE (#3937)
  • 49e0041 feat(himport): HIMPORT command with lazy per-connection prepare (#3919)
  • 3dd9675 fix(proto): peek push notification name without demanding 36 bytes (#3936)
  • Additional commits viewable in compare view

Updates github.com/xraph/forge from 1.9.13 to 1.11.1

Release notes

Sourced from github.com/xraph/forge's releases.

v1.11.1

Forge Framework v1.11.1 (2026-09-15T14:11:32Z)

Welcome to this new release of Forge Framework!

Changelog

New Features

  • 9523267bba65912c93c0da903224efd7795e435e: feat(cli): scaffold a Next.js dashboard with forge dashboard new --target=next (#103) (@​juicycleff)
  • d5c970e36bb2d0e6085d6fa284f9574e5a4ae38c: feat(client): duplex stream channels with a send path (#107) (@​juicycleff)
  • 1c23a5c6927eac031f908f06a051ee034e0bdd11: feat(client-devtools)!: make /overlay the full panel, move the lean view to /mini (#104) (@​juicycleff)
  • a84dc2dc61b64463a21eca7532f580e59a645bf1: feat(client-devtools): causal trace, network view and control rail (#101) (@​juicycleff)
  • a4c59755fa8d1c292ad5bfeb8dd918a18a617194: feat(client-devtools): close the gap to the panel design (#102) (@​juicycleff)

Bug Fixes

  • d96026ccddebc4d05f685497e7981cbf8910a9cc: fix(client-devtools): stop table columns collapsing, deprecate the lean view (#105) (@​juicycleff)
  • 4ee53c37c2f411421c1c02f1907233697ccd46e4: fix(deps): move the last three modules onto forge v1.11.0 (@​juicycleff)

Refactoring

  • 4f29ed012aaa27df396a1a9728314d74f330e507: refactor(dashboard)!: replace the server-rendered UI with React plugins (#99) (@​juicycleff)

Installation

Using Go Install

go install github.com/xraph/forge/cmd/forge@v1.11.1

Download Binary

Download the appropriate binary for your platform from the assets below.

Using Package Managers

# Homebrew (macOS/Linux)
brew install xraph/tap/forge
Scoop (Windows)
scoop bucket add xraph https://github.com/xraph/scoop-bucket
scoop install forge

What's Changed

Full changelog: xraph/forge@v1.11.0...v1.11.1

v1.11.0

Forge Framework v1.11.0 (2026-09-06T18:53:55Z)

Welcome to this new release of Forge Framework!

Changelog

New Features

  • 82e3626e898294959585663667e210b0e6114ce9: feat(dashboard): gate trace ingest on recent dashboard use (@​juicycleff)
  • d75b6e5c01a97530078a5cdb227bc8f6e3a35b4c: feat(dashboard): let the trace store gate ingest on demand (@​juicycleff)

... (truncated)

Changelog

Sourced from github.com/xraph/forge's changelog.

1.11.1 (2026-09-15)

Features

  • client: duplex stream channels with a send path (#107) (d5c970e3)
  • client-devtools: feat(client-devtools)!: make /overlay the full panel, move the lean view to /mini (#104) (1c23a5c6)
  • cli: scaffold a Next.js dashboard with forge dashboard new --target=next (#103) (9523267b)
  • client-devtools: close the gap to the panel design (#102) (a4c59755)
  • client-devtools: causal trace, network view and control rail (#101) (a84dc2dc)

Bug Fixes

  • client-devtools: stop table columns collapsing, deprecate the lean view (#105) (d96026cc)
  • deps: move the last three modules onto forge v1.11.0 (4ee53c37)

Refactoring

  • dashboard: refactor(dashboard)!: replace the server-rendered UI with React plugins (#99) (4f29ed01)

1.11.0 (2026-09-06)

Features

  • dashboard: gate trace ingest on recent dashboard use (82e3626)
  • dashboard: let the trace store gate ingest on demand (d75b6e5)
  • logger: adopt the rewritten logger with automatic format selection (0c0b5de)

Bug Fixes

  • ci: reconcile release-please with the repository's real tags (29a4655)
  • dashboard: bound caller-controlled span attribute values (167819b)
  • dashboard: bound the remaining span fields and wire the per-trace cap (2d271ee)
  • dashboard: cap the spans a single trace can retain (2c78625)
  • dashboard: drain trace notifications on one goroutine, not one per span (87ed904)
  • dashboard: handle edge cases in truncateAttr and add comprehensive tests (adef783)
  • dashboard: keep gate open for SSE viewers, tighten dashboard path match (cb87fb8)
  • dashboard: make goroutine-per-span regression test discriminate reliably (306999f)
  • dashboard: stop the trace collector retaining spans nobody is watching (351fbf1)

Documentation

  • changelog: update CHANGELOG.md for v1.10.0 (8dd10aa)

1.10.0 (2026-09-02)

... (truncated)

Commits
  • d5c970e feat(client): duplex stream channels with a send path (#107)
  • d96026c fix(client-devtools): stop table columns collapsing, deprecate the lean view ...
  • 1c23a5c feat(client-devtools)!: make /overlay the full panel, move the lean view to /...
  • 9523267 feat(cli): scaffold a Next.js dashboard with forge dashboard new --target=nex...
  • a4c5975 feat(client-devtools): close the gap to the panel design (#102)
  • a84dc2d feat(client-devtools): causal trace, network view and control rail (#101)
  • 4f29ed0 refactor(dashboard)!: replace the server-rendered UI with React plugins (#99)
  • 4ee53c3 fix(deps): move the last three modules onto forge v1.11.0
  • 5013a4a fix(deps): move to confy v1.0.3 (#77)
  • 8caa6b4 chore((main)): release 1.11.0 (#76)
  • Additional commits viewable in compare view

Updates github.com/xraph/forge/extensions/auth from 1.10.0 to 1.11.1

Release notes

Sourced from github.com/xraph/forge/extensions/auth's releases.

v1.11.1

Forge Framework v1.11.1 (2026-09-15T14:11:32Z)

Welcome to this new release of Forge Framework!

Changelog

New Features

  • 9523267bba65912c93c0da903224efd7795e435e: feat(cli): scaffold a Next.js dashboard with forge dashboard new --target=next (#103) (@​juicycleff)
  • d5c970e36bb2d0e6085d6fa284f9574e5a4ae38c: feat(client): duplex stream channels with a send path (#107) (@​juicycleff)
  • 1c23a5c6927eac031f908f06a051ee034e0bdd11: feat(client-devtools)!: make /overlay the full panel, move the lean view to /mini (#104) (@​juicycleff)
  • a84dc2dc61b64463a21eca7532f580e59a645bf1: feat(client-devtools): causal trace, network view and control rail (#101) (@​juicycleff)
  • a4c59755fa8d1c292ad5bfeb8dd918a18a617194: feat(client-devtools): close the gap to the panel design (#102) (@​juicycleff)

Bug Fixes

  • d96026ccddebc4d05f685497e7981cbf8910a9cc: fix(client-devtools): stop table columns collapsing, deprecate the lean view (#105) (@​juicycleff)
  • 4ee53c37c2f411421c1c02f1907233697ccd46e4: fix(deps): move the last three modules onto forge v1.11.0 (@​juicycleff)

Refactoring

  • 4f29ed012aaa27df396a1a9728314d74f330e507: refactor(dashboard)!: replace the server-rendered UI with React plugins (#99) (@​juicycleff)

Installation

Using Go Install

go install github.com/xraph/forge/cmd/forge@v1.11.1

Download Binary

Download the appropriate binary for your platform from the assets below.

Using Package Managers

# Homebrew (macOS/Linux)
brew install xraph/tap/forge
Scoop (Windows)
scoop bucket add xraph https://github.com/xraph/scoop-bucket
scoop install forge

What's Changed

Full changelog: xraph/forge@v1.11.0...v1.11.1

v1.11.0

Forge Framework v1.11.0 (2026-09-06T18:53:55Z)

Welcome to this new release of Forge Framework!

Changelog

New Features

  • 82e3626e898294959585663667e210b0e6114ce9: feat(dashboard): gate trace ingest on recent dashboard use (@​juicycleff)
  • d75b6e5c01a97530078a5cdb227bc8f6e3a35b4c: feat(dashboard): let the trace store gate ingest on demand (@​juicycleff)

... (truncated)

Changelog

Sourced from github.com/xraph/forge/extensions/auth's changelog.

1.11.1 (2026-09-15)

Features

  • client: duplex stream channels with a send path (#107) (d5c970e3)
  • client-devtools: feat(client-devtools)!: make /overlay the full panel, move the lean view to /mini (#104) (1c23a5c6)
  • cli: scaffold a Next.js dashboard with forge dashboard new --target=next (#103) (9523267b)
  • client-devtools: close the gap to the panel design (#102) (a4c59755)
  • client-devtools: causal trace, network view and control rail (#101) (a84dc2dc)

Bug Fixes

  • client-devtools: stop table columns collapsing, deprecate the lean view (#105) (d96026cc)
  • deps: move the last three modules onto forge v1.11.0 (4ee53c37)

Refactoring

  • dashboard: refactor(dashboard)!: replace the server-rendered UI with React plugins (#99) (4f29ed01)

1.11.0 (2026-09-06)

Features

  • dashboard: gate trace ingest on recent dashboard use (82e3626)
  • dashboard: let the trace store gate ingest on demand (d75b6e5)
  • logger: adopt the rewritten logger with automatic format selection (0c0b5de)

Bug Fixes

  • ci: reconcile release-please with the repository's real tags (29a4655)
  • dashboard: bound caller-controlled span attribute values (167819b)
  • dashboard: bound the remaining span fields and wire the per-trace cap (2d271ee)
  • dashboard: cap the spans a single trace can retain (2c78625)
  • dashboard: drain trace notifications on one goroutine, not one per span (87ed904)
  • dashboard: handle edge cases in truncateAttr and add comprehensive tests (adef783)
  • dashboard: keep gate open for SSE viewers, tighten dashboard path match (cb87fb8)
  • dashboard: make goroutine-per-span regression test discriminate reliably (306999f)
  • dashboard: stop the trace collector retaining spans nobody is watching (351fbf1)

Documentation

  • changelog: update CHANGELOG.md for v1.10.0 (8dd10aa)
Commits
  • d5c970e feat(client): duplex stream channels with a send path (#107)
  • d96026c fix(client-devtools): stop table columns collapsing, deprecate the lean view ...
  • 1c23a5c feat(client-devtools)!: make /overlay the full panel, move the lean view to /...
  • 9523267 feat(cli): scaffold a Next.js dashboard with forge dashboard new --target=nex...
  • a4c5975 feat(client-devtools): close the gap to the panel design (#102)
  • a84dc2d feat(client-devtools): causal trace, network view and control rail (#101)
  • 4f29ed0 refactor(dashboard)!: replace the server-rendered UI with React plugins (#99)
  • 4ee53c3 fix(deps): move the last three modules onto forge v1.11.0
  • 5013a4a fix(deps): move to confy v1.0.3 (#77)
  • 8caa6b4 chore((main)): release 1.11.0 (#76)
  • Additional commits viewable in compare view

Updates github.com/xraph/go-utils from 1.2.2 to 1.3.0

Release notes

Sourced from github.com/xraph/go-utils's releases.

v1.3.0

1.3.0 (2026-09-06)

Features

  • log: rewrite the logger with automatic format selection (d7271db), closes #6
Changelog

Sourced from github.com/xraph/go-utils's changelog.

1.3.0 (2026-09-06)

Features

  • log: rewrite the logger with automatic format selection (d7271db), closes #6
Commits

Updates go.mongodb.org/mongo-driver/v2 from 2.5.0 to 2.9.1

Release notes

Sourced from go.mongodb.org/mongo-driver/v2's releases.

MongoDB Go Driver 2.9.1

The MongoDB Go Driver Team is pleased to release version 2.9.1 of the official MongoDB Go Driver.

Release Highlights

[!WARNING]
Go Driver versions v1.0.0 through v1.17.9 and v2.0.0 through v2.9.0 are affected by a security issue CVE-2026-88031 in the GridFS delete methods. This release resolves that security issue in Go Driver v2. Users are encouraged to upgrade to Go Driver v2.9.1 as soon as possible. For the fix in Go Driver v1, see the v1.17.10 release.

This release addresses CVE-2026-88031, a security issue in GridFS delete methods where the file ID lookup could match more loosely than intended, potentially causing unintended file (and chunk) deletions instead of an exact match on the given file ID.

Users can manually restrict the file ID with a $eq operator before passing it to GridFSBucket methods using code like the following.

func exact...
Description has been truncated

… updates

Bumps the minor-and-patch group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/a-h/templ](https://github.com/a-h/templ) | `0.3.1001` | `0.3.1020` |
| [github.com/jackc/pgx/v5](https://github.com/jackc/pgx) | `5.10.0` | `5.11.0` |
| [github.com/redis/go-redis/v9](https://github.com/redis/go-redis) | `9.21.0` | `9.22.0` |
| [github.com/xraph/forge](https://github.com/xraph/forge) | `1.9.13` | `1.11.1` |
| [github.com/xraph/forge/extensions/auth](https://github.com/xraph/forge) | `1.10.0` | `1.11.1` |
| [github.com/xraph/go-utils](https://github.com/xraph/go-utils) | `1.2.2` | `1.3.0` |
| [go.mongodb.org/mongo-driver/v2](https://github.com/mongodb/mongo-go-driver) | `2.5.0` | `2.9.1` |
| [go.opentelemetry.io/otel](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.46.0` |
| [go.opentelemetry.io/otel/trace](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.46.0` |



Updates `github.com/a-h/templ` from 0.3.1001 to 0.3.1020
- [Release notes](https://github.com/a-h/templ/releases)
- [Commits](a-h/templ@v0.3.1001...v0.3.1020)

Updates `github.com/jackc/pgx/v5` from 5.10.0 to 5.11.0
- [Release notes](https://github.com/jackc/pgx/releases)
- [Changelog](https://github.com/jackc/pgx/blob/master/CHANGELOG.md)
- [Commits](jackc/pgx@v5.10.0...v5.11.0)

Updates `github.com/redis/go-redis/v9` from 9.21.0 to 9.22.0
- [Release notes](https://github.com/redis/go-redis/releases)
- [Changelog](https://github.com/redis/go-redis/blob/master/RELEASE-NOTES.md)
- [Commits](redis/go-redis@v9.21.0...v9.22.0)

Updates `github.com/xraph/forge` from 1.9.13 to 1.11.1
- [Release notes](https://github.com/xraph/forge/releases)
- [Changelog](https://github.com/xraph/forge/blob/main/CHANGELOG.md)
- [Commits](xraph/forge@v1.9.13...v1.11.1)

Updates `github.com/xraph/forge/extensions/auth` from 1.10.0 to 1.11.1
- [Release notes](https://github.com/xraph/forge/releases)
- [Changelog](https://github.com/xraph/forge/blob/main/CHANGELOG.md)
- [Commits](xraph/forge@v1.10.0...v1.11.1)

Updates `github.com/xraph/go-utils` from 1.2.2 to 1.3.0
- [Release notes](https://github.com/xraph/go-utils/releases)
- [Changelog](https://github.com/xraph/go-utils/blob/main/CHANGELOG.md)
- [Commits](xraph/go-utils@v1.2.2...v1.3.0)

Updates `go.mongodb.org/mongo-driver/v2` from 2.5.0 to 2.9.1
- [Release notes](https://github.com/mongodb/mongo-go-driver/releases)
- [Commits](mongodb/mongo-go-driver@v2.5.0...v2.9.1)

Updates `go.opentelemetry.io/otel` from 1.44.0 to 1.46.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.44.0...v1.46.0)

Updates `go.opentelemetry.io/otel/trace` from 1.44.0 to 1.46.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.44.0...v1.46.0)

---
updated-dependencies:
- dependency-name: github.com/a-h/templ
  dependency-version: 0.3.1020
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: github.com/jackc/pgx/v5
  dependency-version: 5.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/redis/go-redis/v9
  dependency-version: 9.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/xraph/forge
  dependency-version: 1.11.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/xraph/forge/extensions/auth
  dependency-version: 1.11.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/xraph/go-utils
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: go.mongodb.org/mongo-driver/v2
  dependency-version: 2.9.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: go.opentelemetry.io/otel
  dependency-version: 1.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: go.opentelemetry.io/otel/trace
  dependency-version: 1.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 23, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies, go. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 30, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/minor-and-patch-0e8cc94234 branch September 30, 2026 13:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants