Skip to content

fix/pin poetry python 3.11 9.5 - #7878

Closed
olegsu wants to merge 70 commits into
mainfrom
fix/pin-poetry-python-3.11-9.5
Closed

olegsu wants to merge 70 commits into
mainfrom
fix/pin-poetry-python-3.11-9.5

Conversation

@olegsu

@olegsu olegsu commented Aug 11, 2026

Copy link
Copy Markdown
Collaborator

mergify Bot and others added 30 commits July 27, 2026 09:58
…pping bug by renaming it to entity.Details (#7474)

### Summary of your changes

For: #incident-3395-failing-quality-gate-for-entity-store-synthetics
Incident Slack: https://elastic.slack.com/archives/C0BJQCSBT47

Publishing asset details as `entity.attributes` breaks Entity Store
extraction. This, along with related integrations PR, fixes the issue by
using `entity.Details` instead. Integrations PR contains an ingest
pipeline that ensures even old Cloudbeat versions that publish
`entity.attributes` get remapped to `Details`. This allows extraction to
work as intended.

### Related Issues

Towards https://github.com/elastic/security-team/issues/18408
<hr>This is an automatic backport of pull request #7473 done by
[Mergify](https://mergify.com).

Co-authored-by: Kuba Soboń <wtty.fool@gmail.com>
…fetchers for InfoSec (#7482)

### Summary of your changes

> [!NOTE]
> **Stacked on #7473.** This PR is based on
`asset-inventory/fix-entity-attributes`, which renames the
`entity.attributes` (flattened) bag to `entity.Details` to fix the
Entity Store generic-extraction bug. All new fields below are therefore
emitted under **`entity.Details.*`** (not `entity.attributes.*`). Please
review/merge #7473 first; this PR's diff shows only the InfoSec fetcher
changes on top of it.

| Resource | Field | Change |
| -------------------- | --------------------------------- |
------------------------------------------------------------------------------------------------------------------------
|
| **EC2** | `entity.Details.Role` | Added `LookupTag(tags, "role")` in
`buildDetails` |
| **RDS** | `entity.Details.DBInstanceStatus` | Added `Status` field to
wrapper struct; mapped from `DBInstanceStatus` in provider; emitted in
fetcher |
| **ELB v2** (ALB/NLB) | `entity.Details.IPAddresses` |
`GetIPAddresses()` now also collects `PrivateIPv4Address` and
`IPv6Address` per AZ address (previously only `IpAddress`) |
| **ELB v1** (Classic) | `entity.Details.State` | `GetState()` returns
`"active"` (hardcoded as classic API exposes no state field) |
| **ELB v1** (Classic) | `entity.Details.IPAddresses` | DNS-resolves the
ELB `DNSName` at fetch time via injectable `hostResolver`; soft-fails to
empty on error |

### Related Issues

Closes https://github.com/elastic/security-team/issues/18294

### Checklist
- [x] I have added tests that prove my fix is effective or that my
feature works
<hr>This is an automatic backport of pull request #7277 done by
[Mergify](https://mergify.com).

Co-authored-by: Kuba Soboń <wtty.fool@gmail.com>
Bump cloudbeat version to `9.5.1`

Co-authored-by: Cloud Security Machine <cloudsecmachine@users.noreply.github.com>
## Summary

Bumps `github.com/aquasecurity/trivy` from `v0.71.0` to `v0.71.1` on the
`9.5` branch.
…SkipToken, not ResultTruncated (#7688)

## Summary

Most Azure subscriptions in CSPM scans were showing only
subscription-level findings, with zero resource-level findings (storage
accounts, VMs, key vaults, etc.). Root cause: cloudbeat's Azure Resource
Graph (ARG) pagination loop stopped after the first page of results on
every real-world query, silently dropping resources per scan cycle.

## Root cause

In
`internal/resources/providers/azurelib/inventory/resource_graph_provider.go`,
`runPaginatedQuery` broke out of its pagination loop whenever
`response.ResultTruncated == false`. That flag does not mean "no more
pages" — per Microsoft's Resource Graph pagination contract, `SkipToken`
presence/absence is the only reliable continuation signal. In practice,
ordinary paginated ARG responses report `ResultTruncated: false` even
when a valid `SkipToken` for the next page is present, so the loop
always exited after page 1.

## Fix

Pagination now continues based solely on whether `SkipToken` is empty,
matching Microsoft's reference pagination pattern, instead of trusting
`ResultTruncated`.

## Regression test

Added a test in
`internal/resources/providers/azurelib/inventory/resource_graph_provider_test.go`
that mocks a 3-page ARG response sequence where every page reports
`ResultTruncated: false` but carries a `SkipToken` until the final page.
It fails against the pre-fix code (only page 1's asset is returned) and
passes with the fix.<hr>This is an automatic backport of pull request
#7424 done by [Mergify](https://mergify.com).

Co-authored-by: Evgeniy Belyi <jeniawhite92@gmail.com>
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| oras.land/oras-go/v2 | `v2.6.1` → `v2.6.2` |
![age](https://developer.mend.io/api/mc/badges/age/go/oras.land%2foras-go%2fv2/v2.6.2?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/oras.land%2foras-go%2fv2/v2.6.1/v2.6.2?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/checkout](https://redirect.github.com/actions/checkout)
([changelog](https://redirect.github.com/actions/checkout/compare/34e114876b0b11c390a56381ad16ebd13914f8d5..11d5960a326750d5838078e36cf38b85af677262))
| action | digest | `34e1148` → `11d5960` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| debian | final | digest | `35b8ff7` → `34cd9e9` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…9.5) (#7751)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[github.com/bitnami/go-version](https://redirect.github.com/bitnami/go-version)
| indirect | digest | `4eabdf0` → `2aa268a` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…7752)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [github.com/dop251/goja](https://redirect.github.com/dop251/goja) |
indirect | digest | `b07b744` → `493f220` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…7754)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [github.com/google/pprof](https://redirect.github.com/google/pprof) |
indirect | digest | `7023385` → `ef3492d` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…0 (9.5) (#7758)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[github.com/power-devops/perfstat](https://redirect.github.com/power-devops/perfstat)
| indirect | digest | `82ca368` → `8845660` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…8ba (9.5) (#7755)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[github.com/ianlancetaylor/demangle](https://redirect.github.com/ianlancetaylor/demangle)
| indirect | digest | `1ff4bf4` → `83e58ba` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…7761)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| python | final | digest | `5b3879b` → `a7fb1e6` |
| python | stage | digest | `5b3879b` → `a7fb1e6` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…5) (#7756)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[github.com/lufia/plan9stats](https://redirect.github.com/lufia/plan9stats)
| indirect | digest | `477a660` → `341c2f0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/containerd/containerd/v2](https://redirect.github.com/containerd/containerd)
| `v2.3.2` → `v2.3.3` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fcontainerd%2fcontainerd%2fv2/v2.3.3?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fcontainerd%2fcontainerd%2fv2/v2.3.2/v2.3.3?slim=true)
|
|
[github.com/containerd/ttrpc](https://redirect.github.com/containerd/ttrpc)
| `v1.2.8` → `v1.2.9` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fcontainerd%2fttrpc/v1.2.9?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fcontainerd%2fttrpc/v1.2.8/v1.2.9?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>containerd/containerd
(github.com/containerd/containerd/v2)</summary>

###
[`v2.3.3`](https://redirect.github.com/containerd/containerd/releases/tag/v2.3.3):
containerd 2.3.3

[Compare
Source](https://redirect.github.com/containerd/containerd/compare/v2.3.2...v2.3.3)

Welcome to the v2.3.3 release of containerd!

The third patch release for containerd 2.3 contains various fixes and
updates.

##### Highlights

- Set SystemTemp environment variable on Windows so temp directory
overrides work for SYSTEM services
([#&#8203;13694](https://redirect.github.com/containerd/containerd/pull/13694))

##### Container Runtime Interface (CRI)

- Fix nil pointer dereference in NRI GetIPs during pod sandbox teardown
or container exit
([#&#8203;13697](https://redirect.github.com/containerd/containerd/pull/13697))
- Reject CreateContainer calls when the target sandbox is not running
([#&#8203;13668](https://redirect.github.com/containerd/containerd/pull/13668))
- Ensure sandbox shutdown on RunPodSandbox hook failures to avoid mount
leaks
([#&#8203;13645](https://redirect.github.com/containerd/containerd/pull/13645))

##### Image Distribution

- Surface OCI error bodies in registry 403 responses by falling back to
GET requests
([#&#8203;13738](https://redirect.github.com/containerd/containerd/pull/13738))

##### Snapshotters

- Align default 4K mkfs block size for EROFS across all platforms
([#&#8203;13632](https://redirect.github.com/containerd/containerd/pull/13632))

Please try out the release binaries and report any issues at
<https://github.com/containerd/containerd/issues>.

##### Contributors

- Maksym Pavlenko
- Samuel Karp
- Chris Henzie
- Phil Estes
- Sebastiaan van Stijn
- Akihiro Suda
- Austin Vazquez
- Chris Crone
- Derek McGowan
- Maksim An
- crawfordxx
- cshung
- lauralorenz

##### Changes

<details><summary>14 commits</summary>
<p>

- Prepare release notes for v2.3.3
([#&#8203;13750](https://redirect.github.com/containerd/containerd/pull/13750))
-
[`7f6cee02a`](https://redirect.github.com/containerd/containerd/commit/7f6cee02ad5afc5f3244ec36937d8eed61f7057d)
Prepare release notes for v2.3.3
- CI: migrate Vagrant to Lima
([#&#8203;13744](https://redirect.github.com/containerd/containerd/pull/13744))
-
[`7316210ce`](https://redirect.github.com/containerd/containerd/commit/7316210ce6bd95e8afd2856e256b5d9855385d01)
CI: migrate Vagrant to Lima
- remotes: surface OCI error body in registry 4xx responses
([#&#8203;13738](https://redirect.github.com/containerd/containerd/pull/13738))
-
[`457fba3a3`](https://redirect.github.com/containerd/containerd/commit/457fba3a380dab10ef7e9334352352f72caf8423)
remotes: surface OCI error body on HEAD 403 via GET fallback
- Update go to 1.26.5
([#&#8203;13732](https://redirect.github.com/containerd/containerd/pull/13732))
-
[`dc2df934e`](https://redirect.github.com/containerd/containerd/commit/dc2df934efebc78523d6821c2520f538ff65986d)
Update go to 1.26.5
- ci: pin fog-json to resolve gem conflict
([#&#8203;13711](https://redirect.github.com/containerd/containerd/pull/13711))
-
[`5be0495df`](https://redirect.github.com/containerd/containerd/commit/5be0495dff529910a85b6ca1b2a1a35ea220da59)
ci: pin fog-json to resolve gem conflict
- Fix nil pointer dereference in NRI GetIPs
([#&#8203;13697](https://redirect.github.com/containerd/containerd/pull/13697))
-
[`36c713971`](https://redirect.github.com/containerd/containerd/commit/36c7139715fee7ff2f87f78a8b3d6fea4e2e7b35)
Fix nil pointer dereference in NRI GetIPs
- Set SystemTemp env var to config temp on Windows
([#&#8203;13694](https://redirect.github.com/containerd/containerd/pull/13694))
-
[`26dce170d`](https://redirect.github.com/containerd/containerd/commit/26dce170df24e227aeb5ccd1cec1e5c91b307595)
Set SystemTemp env var to config temp on Windows
- update runhcs to v0.15.0-rc.3
([#&#8203;13693](https://redirect.github.com/containerd/containerd/pull/13693))
-
[`9bc2c2349`](https://redirect.github.com/containerd/containerd/commit/9bc2c23496073c3b48b083f6bede9e82d879a7d4)
update runhcs to v0.15.0-rc.3
- Update to current setup-go version
([#&#8203;13686](https://redirect.github.com/containerd/containerd/pull/13686))
-
[`3e97edeb7`](https://redirect.github.com/containerd/containerd/commit/3e97edeb7d3dfcee903c37ab531b1fdfe0a49ae4)
Update to current setup-go version
- cri: reject CreateContainer when sandbox is not running
([#&#8203;13668](https://redirect.github.com/containerd/containerd/pull/13668))
-
[`8856b0f9c`](https://redirect.github.com/containerd/containerd/commit/8856b0f9c3ae50efe6f2a84ab7337953faeb129f)
cri: reject CreateContainer when sandbox is not running
- update runhcs to v0.15.0-rc.2
([#&#8203;13666](https://redirect.github.com/containerd/containerd/pull/13666))
-
[`ae796cec5`](https://redirect.github.com/containerd/containerd/commit/ae796cec596341f3db4ea324199b83670aaa8162)
update runhcs to v0.15.0-rc.2
- test: fix flaky image timestamp check on coarse clocks
([#&#8203;13643](https://redirect.github.com/containerd/containerd/pull/13643))
-
[`168d56783`](https://redirect.github.com/containerd/containerd/commit/168d56783608354301e6f6dfb3ceb9af342c7dde)
test: fix flaky image timestamp check on coarse clocks
- Add defer in event of mid-function failures in RunPodSandbox to avoid
mount leaks
([#&#8203;13645](https://redirect.github.com/containerd/containerd/pull/13645))
-
[`d1db61db8`](https://redirect.github.com/containerd/containerd/commit/d1db61db8d6b59cdb27e5e1843911ad12e25a5e7)
Add deferred call to ShutdownSandbox to avoid leaks
- erofs: align default mkfs block size across platforms
([#&#8203;13632](https://redirect.github.com/containerd/containerd/pull/13632))
-
[`01b0f03f6`](https://redirect.github.com/containerd/containerd/commit/01b0f03f676c19bf5beca591524f274b61537694)
erofs: align default mkfs block size across platforms

</p>
</details>

##### Dependency Changes

This release has no dependency changes

Previous release can be found at
[v2.3.2](https://redirect.github.com/containerd/containerd/releases/tag/v2.3.2)

##### Which file should I download?

- `containerd-<VERSION>-<OS>-<ARCH>.tar.gz`: ✅Recommended. Dynamically
linked with glibc 2.35 (Ubuntu 22.04).
- `containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz`: Statically linked.
Expected to be used on Linux distributions that do not use glibc >=
2.35. Not position-independent.

In addition to containerd, typically you will have to install
[runc](https://redirect.github.com/opencontainers/runc/releases)
and [CNI
plugins](https://redirect.github.com/containernetworking/plugins/releases)
from their official sites too.

See also the [Getting
Started](https://redirect.github.com/containerd/containerd/blob/main/docs/getting-started.md)
documentation.

</details>

<details>
<summary>containerd/ttrpc (github.com/containerd/ttrpc)</summary>

###
[`v1.2.9`](https://redirect.github.com/containerd/ttrpc/releases/tag/v1.2.9)

[Compare
Source](https://redirect.github.com/containerd/ttrpc/compare/v1.2.8...v1.2.9)

#### What's Changed

- Migrate from protobuild to buf by
[@&#8203;kzys](https://redirect.github.com/kzys) in
[#&#8203;226](https://redirect.github.com/containerd/ttrpc/pull/226)
- build(deps): bump actions/setup-go from 6.3.0 to 6.4.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;228](https://redirect.github.com/containerd/ttrpc/pull/228)
- Fix proto generation by
[@&#8203;dmcgowan](https://redirect.github.com/dmcgowan) in
[#&#8203;232](https://redirect.github.com/containerd/ttrpc/pull/232)
- Set buf version from file and match dev version by
[@&#8203;dmcgowan](https://redirect.github.com/dmcgowan) in
[#&#8203;233](https://redirect.github.com/containerd/ttrpc/pull/233)
- server: cancel per-stream context when handler returns by
[@&#8203;eginez](https://redirect.github.com/eginez) in
[#&#8203;231](https://redirect.github.com/containerd/ttrpc/pull/231)
- Fix deadlock when stream is not consumed by
[@&#8203;dmcgowan](https://redirect.github.com/dmcgowan) in
[#&#8203;229](https://redirect.github.com/containerd/ttrpc/pull/229)
- Remove gogo vanity command and gogo dependency by
[@&#8203;liggitt](https://redirect.github.com/liggitt) in
[#&#8203;239](https://redirect.github.com/containerd/ttrpc/pull/239)
- build(deps): bump actions/checkout from 6.0.2 to 6.0.3 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;240](https://redirect.github.com/containerd/ttrpc/pull/240)
- build(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;238](https://redirect.github.com/containerd/ttrpc/pull/238)
- build(deps): bump google.golang.org/grpc from 1.69.2 to 1.81.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;237](https://redirect.github.com/containerd/ttrpc/pull/237)
- build(deps): bump golang.org/x/sys from 0.42.0 to 0.46.0 in the
golang-x group across 1 directory by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;215](https://redirect.github.com/containerd/ttrpc/pull/215)

#### New Contributors

- [@&#8203;eginez](https://redirect.github.com/eginez) made their first
contribution in
[#&#8203;231](https://redirect.github.com/containerd/ttrpc/pull/231)

**Full Changelog**:
<containerd/ttrpc@v1.2.8...v1.2.9>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| golang | final | digest | `efaccb5` → `2005724` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[k8s.io/kube-openapi](https://redirect.github.com/kubernetes/kube-openapi)
| indirect | digest | `cdb1db5` → `d427ff9` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
….5) (#7768)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/ebitengine/purego](https://redirect.github.com/ebitengine/purego)
| `v0.10.1` → `v0.10.2` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2febitengine%2fpurego/v0.10.2?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2febitengine%2fpurego/v0.10.1/v0.10.2?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>ebitengine/purego (github.com/ebitengine/purego)</summary>

###
[`v0.10.2`](https://redirect.github.com/ebitengine/purego/releases/tag/v0.10.2)

[Compare
Source](https://redirect.github.com/ebitengine/purego/compare/v0.10.1...v0.10.2)

- Fixed an issue with FreeBSD 15 or later
([#&#8203;480](https://redirect.github.com/ebitengine/purego/issues/480))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
….5) (#7770)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/go-git/go-billy/v5](https://redirect.github.com/go-git/go-billy)
| `v5.9.0` → `v5.9.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fgo-git%2fgo-billy%2fv5/v5.9.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fgo-git%2fgo-billy%2fv5/v5.9.0/v5.9.1?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>go-git/go-billy (github.com/go-git/go-billy/v5)</summary>

###
[`v5.9.1`](https://redirect.github.com/go-git/go-billy/releases/tag/v5.9.1)

[Compare
Source](https://redirect.github.com/go-git/go-billy/compare/v5.9.0...v5.9.1)

#### What's Changed

- build: Update module golang.org/x/net to v0.55.0 \[SECURITY]
(releases/v5.x) by
[@&#8203;go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#&#8203;216](https://redirect.github.com/go-git/go-billy/pull/216)
- build: Update module golang.org/x/text to v0.39.0 \[SECURITY]
(releases/v5.x) by
[@&#8203;go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#&#8203;230](https://redirect.github.com/go-git/go-billy/pull/230)
- build: Update module golang.org/x/net to v0.56.0 \[SECURITY]
(releases/v5.x) by
[@&#8203;go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#&#8203;229](https://redirect.github.com/go-git/go-billy/pull/229)

**Full Changelog**:
<go-git/go-billy@v5.9.0...v5.9.1>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…5) (#7771)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/go-git/go-git/v5](https://redirect.github.com/go-git/go-git)
| `v5.19.1` → `v5.19.2` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fgo-git%2fgo-git%2fv5/v5.19.2?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fgo-git%2fgo-git%2fv5/v5.19.1/v5.19.2?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>go-git/go-git (github.com/go-git/go-git/v5)</summary>

###
[`v5.19.2`](https://redirect.github.com/go-git/go-git/releases/tag/v5.19.2)

[Compare
Source](https://redirect.github.com/go-git/go-git/compare/v5.19.1...v5.19.2)

#### What's Changed

- build: Update module golang.org/x/crypto to v0.52.0 \[SECURITY]
(releases/v5.x) by
[@&#8203;go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#&#8203;2150](https://redirect.github.com/go-git/go-git/pull/2150)
- build: Update module github.com/go-git/go-git/v5 to v5.19.1
\[SECURITY] (releases/v5.x) by
[@&#8203;go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#&#8203;2141](https://redirect.github.com/go-git/go-git/pull/2141)
- build: Update module golang.org/x/net to v0.55.0 \[SECURITY]
(releases/v5.x) by
[@&#8203;go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#&#8203;2152](https://redirect.github.com/go-git/go-git/pull/2152)
- git: Worktree: Add stores index entires with backslashes on Windows by
[@&#8203;joshblum](https://redirect.github.com/joshblum) in
[#&#8203;2262](https://redirect.github.com/go-git/go-git/pull/2262)
- storage: dotgit, reject path traversal in reference names by
[@&#8203;pjbgf](https://redirect.github.com/pjbgf) in
[#&#8203;2254](https://redirect.github.com/go-git/go-git/pull/2254)
- build: Update module golang.org/x/net to v0.56.0 \[SECURITY]
(releases/v5.x) by
[@&#8203;go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#&#8203;2267](https://redirect.github.com/go-git/go-git/pull/2267)
- build: Update module golang.org/x/text to v0.39.0 \[SECURITY]
(releases/v5.x) by
[@&#8203;go-git-renovate](https://redirect.github.com/go-git-renovate)\[bot]
in [#&#8203;2268](https://redirect.github.com/go-git/go-git/pull/2268)
- \[v5] git: worktree, make the filesystem wrapper a symlink-safe
boundary by [@&#8203;pjbgf](https://redirect.github.com/pjbgf) in
[#&#8203;2277](https://redirect.github.com/go-git/go-git/pull/2277)

**Full Changelog**:
<go-git/go-git@v5.19.1...v5.19.2>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…te-proxy to v0.3.20 (9.5) (#7774)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/googleapis/enterprise-certificate-proxy](https://redirect.github.com/googleapis/enterprise-certificate-proxy)
| `v0.3.18` → `v0.3.20` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fgoogleapis%2fenterprise-certificate-proxy/v0.3.20?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fgoogleapis%2fenterprise-certificate-proxy/v0.3.18/v0.3.20?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>googleapis/enterprise-certificate-proxy
(github.com/googleapis/enterprise-certificate-proxy)</summary>

###
[`v0.3.20`](https://redirect.github.com/googleapis/enterprise-certificate-proxy/releases/tag/v0.3.20)

[Compare
Source](https://redirect.github.com/googleapis/enterprise-certificate-proxy/compare/v0.3.19...v0.3.20)

#### What's Changed

- chore(deps): update actions/upload-artifact action to v7 by
[@&#8203;renovate-bot](https://redirect.github.com/renovate-bot) in
[#&#8203;156](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/156)
- chore(deps): update actions/checkout action to v7 by
[@&#8203;renovate-bot](https://redirect.github.com/renovate-bot) in
[#&#8203;201](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/201)
- build(deps): bump golang.org/x/crypto from 0.47.0 to 0.52.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;205](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/205)
- chore(deps): update actions/setup-go action to v7 by
[@&#8203;renovate-bot](https://redirect.github.com/renovate-bot) in
[#&#8203;207](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/207)
- Update CODEOWNERS by
[@&#8203;andyrzhao](https://redirect.github.com/andyrzhao) in
[#&#8203;218](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/218)
- feat: Transition from localized logging to a robust, standardized
logging utility across the entire ECP repository. by
[@&#8203;agrawalradhika-cell](https://redirect.github.com/agrawalradhika-cell)
in
[#&#8203;217](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/217)
- chore: Bump version from v0.3.19 to v0.3.20 by
[@&#8203;agrawalradhika-cell](https://redirect.github.com/agrawalradhika-cell)
in
[#&#8203;221](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/221)

**Full Changelog**:
<googleapis/enterprise-certificate-proxy@v0.3.19...v0.3.20>

###
[`v0.3.19`](https://redirect.github.com/googleapis/enterprise-certificate-proxy/releases/tag/v0.3.19)

[Compare
Source](https://redirect.github.com/googleapis/enterprise-certificate-proxy/compare/v0.3.18...v0.3.19)

#### What's Changed

- fix: use legacy OpenSSL algorithms for keychain import by
[@&#8203;nolanleastin](https://redirect.github.com/nolanleastin) in
[#&#8203;210](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/210)
- chore: Update version.txt to 0.3.18 by
[@&#8203;nolanleastin](https://redirect.github.com/nolanleastin) in
[#&#8203;204](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/204)
- fix: mTLS routing for hosts starting with 'mtls.' by
[@&#8203;nolanleastin](https://redirect.github.com/nolanleastin) in
[#&#8203;209](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/209)
- chore: update go.mod toolchain to 1.26.5 by
[@&#8203;nolanleastin](https://redirect.github.com/nolanleastin) in
[#&#8203;212](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/212)
- fix: serialize PKCS11 operations to resolve thread exhaustion by
[@&#8203;nolanleastin](https://redirect.github.com/nolanleastin) in
[#&#8203;211](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/211)
- chore: update version.txt to v0.3.19 by
[@&#8203;nolanleastin](https://redirect.github.com/nolanleastin) in
[#&#8203;214](https://redirect.github.com/googleapis/enterprise-certificate-proxy/pull/214)

**Full Changelog**:
<googleapis/enterprise-certificate-proxy@v0.3.17...v0.3.19>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…(9.5) (#7769)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/go-asn1-ber/asn1-ber](https://redirect.github.com/go-asn1-ber/asn1-ber)
| `v1.5.8-0.20260416181348-e7dc79048676` → `v1.5.8` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fgo-asn1-ber%2fasn1-ber/v1.5.8?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fgo-asn1-ber%2fasn1-ber/v1.5.8-0.20260416181348-e7dc79048676/v1.5.8?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>go-asn1-ber/asn1-ber
(github.com/go-asn1-ber/asn1-ber)</summary>

###
[`v1.5.8`](https://redirect.github.com/go-asn1-ber/asn1-ber/releases/tag/v1.5.8)

[Compare
Source](https://redirect.github.com/go-asn1-ber/asn1-ber/compare/v1.5.7...v1.5.8)

#### What's Changed

- Correct Implementation for Relative OIDs by
[@&#8203;s00500](https://redirect.github.com/s00500) in
[#&#8203;45](https://redirect.github.com/go-asn1-ber/asn1-ber/pull/45)
- add test for result of tests/tc10.ber by
[@&#8203;vetinari](https://redirect.github.com/vetinari) in
[#&#8203;46](https://redirect.github.com/go-asn1-ber/asn1-ber/pull/46)
- set ldap boolean length to 1 byte by
[@&#8203;borislavfra](https://redirect.github.com/borislavfra) in
[#&#8203;47](https://redirect.github.com/go-asn1-ber/asn1-ber/pull/47)
- fix: guard against stack overflow on deeply-nested BER packets
([#&#8203;49](https://redirect.github.com/go-asn1-ber/asn1-ber/issues/49))
by [@&#8203;cpuschma](https://redirect.github.com/cpuschma) in
[#&#8203;50](https://redirect.github.com/go-asn1-ber/asn1-ber/pull/50)
- fix: enforce `MaxPacketLengthBytes` for constructed packets by
[@&#8203;cpuschma](https://redirect.github.com/cpuschma) in
[#&#8203;53](https://redirect.github.com/go-asn1-ber/asn1-ber/pull/53)
- fix: reject long-form definite lengths that wrap negative by
[@&#8203;cpuschma](https://redirect.github.com/cpuschma) in
[#&#8203;54](https://redirect.github.com/go-asn1-ber/asn1-ber/pull/54)

#### New Contributors

- [@&#8203;borislavfra](https://redirect.github.com/borislavfra) made
their first contribution in
[#&#8203;47](https://redirect.github.com/go-asn1-ber/asn1-ber/pull/47)

**Full Changelog**:
<go-asn1-ber/asn1-ber@v1.5.7...v1.5.8>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[k8s.io/apiextensions-apiserver](https://redirect.github.com/kubernetes/apiextensions-apiserver)
| `v0.36.2` → `v0.36.3` |
![age](https://developer.mend.io/api/mc/badges/age/go/k8s.io%2fapiextensions-apiserver/v0.36.3?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/k8s.io%2fapiextensions-apiserver/v0.36.2/v0.36.3?slim=true)
|
| [k8s.io/apiserver](https://redirect.github.com/kubernetes/apiserver) |
`v0.36.2` → `v0.36.3` |
![age](https://developer.mend.io/api/mc/badges/age/go/k8s.io%2fapiserver/v0.36.3?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/k8s.io%2fapiserver/v0.36.2/v0.36.3?slim=true)
|
|
[k8s.io/cli-runtime](https://redirect.github.com/kubernetes/cli-runtime)
| `v0.36.2` → `v0.36.3` |
![age](https://developer.mend.io/api/mc/badges/age/go/k8s.io%2fcli-runtime/v0.36.3?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/k8s.io%2fcli-runtime/v0.36.2/v0.36.3?slim=true)
|
|
[k8s.io/component-base](https://redirect.github.com/kubernetes/component-base)
| `v0.36.2` → `v0.36.3` |
![age](https://developer.mend.io/api/mc/badges/age/go/k8s.io%2fcomponent-base/v0.36.3?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/k8s.io%2fcomponent-base/v0.36.2/v0.36.3?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>kubernetes/apiextensions-apiserver
(k8s.io/apiextensions-apiserver)</summary>

###
[`v0.36.3`](https://redirect.github.com/kubernetes/apiextensions-apiserver/compare/v0.36.2...v0.36.3)

[Compare
Source](https://redirect.github.com/kubernetes/apiextensions-apiserver/compare/v0.36.2...v0.36.3)

</details>

<details>
<summary>kubernetes/apiserver (k8s.io/apiserver)</summary>

###
[`v0.36.3`](https://redirect.github.com/kubernetes/apiserver/compare/v0.36.2...v0.36.3)

[Compare
Source](https://redirect.github.com/kubernetes/apiserver/compare/v0.36.2...v0.36.3)

</details>

<details>
<summary>kubernetes/cli-runtime (k8s.io/cli-runtime)</summary>

###
[`v0.36.3`](https://redirect.github.com/kubernetes/cli-runtime/compare/v0.36.2...v0.36.3)

[Compare
Source](https://redirect.github.com/kubernetes/cli-runtime/compare/v0.36.2...v0.36.3)

</details>

<details>
<summary>kubernetes/component-base (k8s.io/component-base)</summary>

###
[`v0.36.3`](https://redirect.github.com/kubernetes/component-base/compare/v0.36.2...v0.36.3)

[Compare
Source](https://redirect.github.com/kubernetes/component-base/compare/v0.36.2...v0.36.3)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
….5) (#7766)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/bitfield/gotestdox](https://redirect.github.com/bitfield/gotestdox)
| `v0.2.2` → `v0.2.3` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fbitfield%2fgotestdox/v0.2.3?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fbitfield%2fgotestdox/v0.2.2/v0.2.3?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>bitfield/gotestdox (github.com/bitfield/gotestdox)</summary>

###
[`v0.2.3`](https://redirect.github.com/bitfield/gotestdox/compare/v0.2.2...v0.2.3)

[Compare
Source](https://redirect.github.com/bitfield/gotestdox/compare/v0.2.2...v0.2.3)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
#7767)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/cloudflare/circl](https://redirect.github.com/cloudflare/circl)
| `v1.6.4` → `v1.6.5` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fcloudflare%2fcircl/v1.6.5?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fcloudflare%2fcircl/v1.6.4/v1.6.5?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>cloudflare/circl (github.com/cloudflare/circl)</summary>

###
[`v1.6.5`](https://redirect.github.com/cloudflare/circl/releases/tag/v1.6.5):
CIRCL v1.6.5

[Compare
Source](https://redirect.github.com/cloudflare/circl/compare/v1.6.4...v1.6.5)

#### What's Changed

- ascon: don't output plaintext if authentication fails by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;631](https://redirect.github.com/cloudflare/circl/pull/631)
- Dilithium: don't accept signatures with trailing data by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;632](https://redirect.github.com/cloudflare/circl/pull/632)
- Fix HPKE/KEM exact-length key unmarshaling by
[@&#8203;drmikecrypto](https://redirect.github.com/drmikecrypto) in
[#&#8203;627](https://redirect.github.com/cloudflare/circl/pull/627)
- Bump x/crypto and golangci-lint by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;637](https://redirect.github.com/cloudflare/circl/pull/637)
- ecc/bls12381: reject trailing data in G1/G2 SetBytes by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;636](https://redirect.github.com/cloudflare/circl/pull/636)
- eddilithium: fail verification if signature is wrong length by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;633](https://redirect.github.com/cloudflare/circl/pull/633)
- tss/rsa: fix length check to prevent runtime out-of-bounds panic by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;640](https://redirect.github.com/cloudflare/circl/pull/640)
- dleq: verify: return false instead of panic()ing on nil parameters by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;641](https://redirect.github.com/cloudflare/circl/pull/641)
- ed448: document verification behaviour by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;642](https://redirect.github.com/cloudflare/circl/pull/642)
- ed448: reject non-canonical point encodings by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;635](https://redirect.github.com/cloudflare/circl/pull/635)
- slhdsa: ensure full reads when rand source is provided by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;634](https://redirect.github.com/cloudflare/circl/pull/634)
- ed{25519,448}: don't accept trailing data for keys by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;643](https://redirect.github.com/cloudflare/circl/pull/643)
- frodo: pack: fix accidental zero buffer assumption by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;645](https://redirect.github.com/cloudflare/circl/pull/645)
- secretsharing: check that share ID is not zero. by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;644](https://redirect.github.com/cloudflare/circl/pull/644)
- kyber: document pk isn't checked like ML-KEM by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;648](https://redirect.github.com/cloudflare/circl/pull/648)
- zk/dleq: Don't accept trailing data on proof by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;649](https://redirect.github.com/cloudflare/circl/pull/649)
- slhdsa: don't panic if prehash-hash is out of range by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;647](https://redirect.github.com/cloudflare/circl/pull/647)
- goldilocks: don't panic when unmarshalling invalid point by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;646](https://redirect.github.com/cloudflare/circl/pull/646)
- hpke: don't panic when unmarshalling opener/sealer from empty buffer
by [@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;656](https://redirect.github.com/cloudflare/circl/pull/656)
- ot/simot: don't panic on mismatched ciphertext lengths by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;655](https://redirect.github.com/cloudflare/circl/pull/655)
- fourq: document point decoding is lenient by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;654](https://redirect.github.com/cloudflare/circl/pull/654)
- oprf: add note on multiple Point encodings by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;653](https://redirect.github.com/cloudflare/circl/pull/653)
- tss/rsa: don't panic when combining empty list of shares by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;652](https://redirect.github.com/cloudflare/circl/pull/652)
- ecc/p384: document that package is not fully constant time by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;651](https://redirect.github.com/cloudflare/circl/pull/651)
- ristretto: reject non-canonical scalars by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;650](https://redirect.github.com/cloudflare/circl/pull/650)
- Add more explicit constant time warnings by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;638](https://redirect.github.com/cloudflare/circl/pull/638)
- mlsbset: make Encode() constant time by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;639](https://redirect.github.com/cloudflare/circl/pull/639)
- mlsbset: fix stray index in Encode comment by
[@&#8203;lukevalenta](https://redirect.github.com/lukevalenta) in
[#&#8203;658](https://redirect.github.com/cloudflare/circl/pull/658)
- removeLen32Prefixed: check for possible data overflow by
[@&#8203;mdosch](https://redirect.github.com/mdosch) in
[#&#8203;629](https://redirect.github.com/cloudflare/circl/pull/629)
- expander: panic if requested output length overflows DST. by
[@&#8203;cjpatton](https://redirect.github.com/cjpatton) in
[#&#8203;664](https://redirect.github.com/cloudflare/circl/pull/664)
- zk/dleq: add base point `a` to challenge derivation. by
[@&#8203;cjpatton](https://redirect.github.com/cjpatton) in
[#&#8203;663](https://redirect.github.com/cloudflare/circl/pull/663)
- dh/sidh: document Import() side-effect for kem/sike. by
[@&#8203;cjpatton](https://redirect.github.com/cjpatton) in
[#&#8203;662](https://redirect.github.com/cloudflare/circl/pull/662)
- ecc/fourq: improve constant-timeness of fpSgn, fqSqrt. by
[@&#8203;cjpatton](https://redirect.github.com/cjpatton) in
[#&#8203;666](https://redirect.github.com/cloudflare/circl/pull/666)
- blinsign/blindrsa/partiallyblindrsa: reject malformed moduli. by
[@&#8203;cjpatton](https://redirect.github.com/cjpatton) in
[#&#8203;665](https://redirect.github.com/cloudflare/circl/pull/665)
- blindsign/blindrsa: align PSSZERO behavior with RFC 9474. by
[@&#8203;cjpatton](https://redirect.github.com/cjpatton) in
[#&#8203;660](https://redirect.github.com/cloudflare/circl/pull/660)
- ecc/fourq: fix fqSqr arithmetic error on amd64 by
[@&#8203;cjpatton](https://redirect.github.com/cjpatton) in
[#&#8203;659](https://redirect.github.com/cloudflare/circl/pull/659)
- README: warn that not all packages are constant time by
[@&#8203;frangelbarrera](https://redirect.github.com/frangelbarrera) in
[#&#8203;668](https://redirect.github.com/cloudflare/circl/pull/668)
- internal/test: unify ACVP test vector parsing by
[@&#8203;ihopenre-eng](https://redirect.github.com/ihopenre-eng) in
[#&#8203;667](https://redirect.github.com/cloudflare/circl/pull/667)
- blindrsa: fix interface documentation by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;672](https://redirect.github.com/cloudflare/circl/pull/672)
- ecc/fourq: fix legacy (non-BMI2) GF(p^2) multiplication on amd64 by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;669](https://redirect.github.com/cloudflare/circl/pull/669)
- p384: document assumed reductions by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;670](https://redirect.github.com/cloudflare/circl/pull/670)
-
[`ed25519`](https://redirect.github.com/cloudflare/circl/commit/ed25519):
document another divergence with crypto/ed25519 by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;671](https://redirect.github.com/cloudflare/circl/pull/671)
- prio3/histogram: don't panic on measurement equal to the bucket count
by [@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;673](https://redirect.github.com/cloudflare/circl/pull/673)
- zk/qndleq: document Qn membership precondition by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;675](https://redirect.github.com/cloudflare/circl/pull/675)
- vdaf/prio3: require all prep shares by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;676](https://redirect.github.com/cloudflare/circl/pull/676)
- vdaf/prio3: document prep sequencing requirement by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;677](https://redirect.github.com/cloudflare/circl/pull/677)
- zk/dl: reject identity proof inputs by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;678](https://redirect.github.com/cloudflare/circl/pull/678)
- tss/rsa: document trusted modulus requirement by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;680](https://redirect.github.com/cloudflare/circl/pull/680)
- dh/csidh: harden key imports by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;689](https://redirect.github.com/cloudflare/circl/pull/689)
- zk/dleq: validate batch shape by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;684](https://redirect.github.com/cloudflare/circl/pull/684)
- ot/simot: make sender sessions one-shot by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;679](https://redirect.github.com/cloudflare/circl/pull/679)
- vdaf/prio3/sum: reject unsafe measurement bounds by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;682](https://redirect.github.com/cloudflare/circl/pull/682)
- tss/rsa: validate sign share protocol parameters by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;674](https://redirect.github.com/cloudflare/circl/pull/674)
- vdaf/prio3/sum: reject aggregate field overflow by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;681](https://redirect.github.com/cloudflare/circl/pull/681)
- vdaf/prio3: validate preparation inputs by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;683](https://redirect.github.com/cloudflare/circl/pull/683)
- oprf: reject invalid deterministic blinds by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;688](https://redirect.github.com/cloudflare/circl/pull/688)
- vdaf/prio3: reject degenerate parameters by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;685](https://redirect.github.com/cloudflare/circl/pull/685)
- oprf: validate finalize state by
[@&#8203;bwesterb](https://redirect.github.com/bwesterb) in
[#&#8203;687](https://redirect.github.com/cloudflare/circl/pull/687)

#### New Contributors

- [@&#8203;drmikecrypto](https://redirect.github.com/drmikecrypto) made
their first contribution in
[#&#8203;627](https://redirect.github.com/cloudflare/circl/pull/627)
- [@&#8203;lukevalenta](https://redirect.github.com/lukevalenta) made
their first contribution in
[#&#8203;658](https://redirect.github.com/cloudflare/circl/pull/658)
- [@&#8203;mdosch](https://redirect.github.com/mdosch) made their first
contribution in
[#&#8203;629](https://redirect.github.com/cloudflare/circl/pull/629)
- [@&#8203;frangelbarrera](https://redirect.github.com/frangelbarrera)
made their first contribution in
[#&#8203;668](https://redirect.github.com/cloudflare/circl/pull/668)
- [@&#8203;ihopenre-eng](https://redirect.github.com/ihopenre-eng) made
their first contribution in
[#&#8203;667](https://redirect.github.com/cloudflare/circl/pull/667)

**Full Changelog**:
<cloudflare/circl@v1.6.4...v1.6.5>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…9.5) (#7776)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/klauspost/compress](https://redirect.github.com/klauspost/compress)
| `v1.19.0` → `v1.19.2` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fklauspost%2fcompress/v1.19.2?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fklauspost%2fcompress/v1.19.0/v1.19.2?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>klauspost/compress (github.com/klauspost/compress)</summary>

###
[`v1.19.2`](https://redirect.github.com/klauspost/compress/releases/tag/v1.19.2)

[Compare
Source](https://redirect.github.com/klauspost/compress/compare/v1.19.1...v1.19.2)

#### What's Changed

- huff0: add arm64 assembly for Decompress4X/1X via avo lowering by
[@&#8203;lizthegrey](https://redirect.github.com/lizthegrey) in
[#&#8203;1172](https://redirect.github.com/klauspost/compress/pull/1172)
- zstd: Re-enable unsafe decodeSync memory copies
([#&#8203;1168](https://redirect.github.com/klauspost/compress/issues/1168))
by [@&#8203;lizthegrey](https://redirect.github.com/lizthegrey) in
[#&#8203;1171](https://redirect.github.com/klauspost/compress/pull/1171)
- zstd: fix arm64 asm frame offsets placing locals on the saved LR slot
by [@&#8203;lizthegrey](https://redirect.github.com/lizthegrey) in
[#&#8203;1176](https://redirect.github.com/klauspost/compress/pull/1176)
- zstd: avoid racing MaxDecodedSize write on shared dict litEnc by
[@&#8203;zanarellidev](https://redirect.github.com/zanarellidev) in
[#&#8203;1182](https://redirect.github.com/klauspost/compress/pull/1182)
- zstd: keep BuildDict recent-offsets positive and loadable by
[@&#8203;zanarellidev](https://redirect.github.com/zanarellidev) in
[#&#8203;1184](https://redirect.github.com/klauspost/compress/pull/1184)
- zstd: handle zero-literal BuildDict corpus by
[@&#8203;cyphercodes](https://redirect.github.com/cyphercodes) in
[#&#8203;1178](https://redirect.github.com/klauspost/compress/pull/1178)
- zstd: don't clear the registered dictionary when decoding past the
window by [@&#8203;sueun-dev](https://redirect.github.com/sueun-dev) in
[#&#8203;1177](https://redirect.github.com/klauspost/compress/pull/1177)

#### New Contributors

- [@&#8203;zanarellidev](https://redirect.github.com/zanarellidev) made
their first contribution in
[#&#8203;1183](https://redirect.github.com/klauspost/compress/pull/1183)
- [@&#8203;cyphercodes](https://redirect.github.com/cyphercodes) made
their first contribution in
[#&#8203;1178](https://redirect.github.com/klauspost/compress/pull/1178)
- [@&#8203;sueun-dev](https://redirect.github.com/sueun-dev) made their
first contribution in
[#&#8203;1177](https://redirect.github.com/klauspost/compress/pull/1177)

**Full Changelog**:
<klauspost/compress@v1.19.1...v1.19.2>

###
[`v1.19.1`](https://redirect.github.com/klauspost/compress/releases/tag/v1.19.1)

[Compare
Source](https://redirect.github.com/klauspost/compress/compare/v1.19.0...v1.19.1)

#### What's Changed

- zstd: Validate SnappyConverter literal copies by
[@&#8203;klauspost](https://redirect.github.com/klauspost) in
[#&#8203;1170](https://redirect.github.com/klauspost/compress/pull/1170)
- flate: use `Peek` instead of `ReadByte` for the `bufio.Reader` decode
path by [@&#8203;joechenrh](https://redirect.github.com/joechenrh) in
[#&#8203;1169](https://redirect.github.com/klauspost/compress/pull/1169)
- zstd: bump avo pin, regenerate arm64 asm by
[@&#8203;lizthegrey](https://redirect.github.com/lizthegrey) in
[#&#8203;1167](https://redirect.github.com/klauspost/compress/pull/1167)

#### New Contributors

- [@&#8203;joechenrh](https://redirect.github.com/joechenrh) made their
first contribution in
[#&#8203;1169](https://redirect.github.com/klauspost/compress/pull/1169)

**Full Changelog**:
<klauspost/compress@v1.19.0...v1.19.1>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
#7779)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/mattn/go-isatty](https://redirect.github.com/mattn/go-isatty)
| `v0.0.22` → `v0.0.24` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fmattn%2fgo-isatty/v0.0.24?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fmattn%2fgo-isatty/v0.0.22/v0.0.24?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>mattn/go-isatty (github.com/mattn/go-isatty)</summary>

###
[`v0.0.24`](https://redirect.github.com/mattn/go-isatty/compare/v0.0.23...v0.0.24)

[Compare
Source](https://redirect.github.com/mattn/go-isatty/compare/v0.0.23...v0.0.24)

###
[`v0.0.23`](https://redirect.github.com/mattn/go-isatty/compare/v0.0.22...v0.0.23)

[Compare
Source](https://redirect.github.com/mattn/go-isatty/compare/v0.0.22...v0.0.23)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…o v1.0.1 (9.5) (#7777)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/knadh/koanf/providers/confmap](https://redirect.github.com/knadh/koanf)
| `v1.0.0` → `v1.0.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fknadh%2fkoanf%2fproviders%2fconfmap/v1.0.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fknadh%2fkoanf%2fproviders%2fconfmap/v1.0.0/v1.0.1?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…7782)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/oklog/ulid/v2](https://redirect.github.com/oklog/ulid) |
`v2.1.1` → `v2.1.2` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2foklog%2fulid%2fv2/v2.1.2?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2foklog%2fulid%2fv2/v2.1.1/v2.1.2?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>oklog/ulid (github.com/oklog/ulid/v2)</summary>

###
[`v2.1.2`](https://redirect.github.com/oklog/ulid/releases/tag/v2.1.2)

[Compare
Source](https://redirect.github.com/oklog/ulid/compare/v2.1.1...v2.1.2)

#### What's Changed

- fix: Scan accepts text-encoded ULIDs in \[]byte by
[@&#8203;sonnemusk](https://redirect.github.com/sonnemusk) in
[#&#8203;134](https://redirect.github.com/oklog/ulid/pull/134)

#### New Contributors

- [@&#8203;sonnemusk](https://redirect.github.com/sonnemusk) made their
first contribution in
[#&#8203;134](https://redirect.github.com/oklog/ulid/pull/134)

**Full Changelog**:
<oklog/ulid@v2.1.1...v2.1.2>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
elastic-renovate-prod Bot and others added 28 commits August 11, 2026 02:00
…7778)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/knadh/koanf/v2](https://redirect.github.com/knadh/koanf) |
`v2.3.5` → `v2.3.6` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fknadh%2fkoanf%2fv2/v2.3.6?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fknadh%2fkoanf%2fv2/v2.3.5/v2.3.6?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>knadh/koanf (github.com/knadh/koanf/v2)</summary>

###
[`v2.3.6`](https://redirect.github.com/knadh/koanf/releases/tag/v2.3.6)

[Compare
Source](https://redirect.github.com/knadh/koanf/compare/v2.3.5...v2.3.6)

#### What's Changed

- fix: error on scalar/map type mismatch in MergeStrict regardless of
order by [@&#8203;upuddu](https://redirect.github.com/upuddu) in
[#&#8203;424](https://redirect.github.com/knadh/koanf/pull/424)
- Bump google.golang.org/grpc from 1.56.3 to 1.82.1 in /examples by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;430](https://redirect.github.com/knadh/koanf/pull/430)
- Bump golang.org/x/crypto from 0.45.0 to 0.52.0 in /providers/kiln by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;427](https://redirect.github.com/knadh/koanf/pull/427)
- deps: upgrade go-toml to v2.4.3 by
[@&#8203;GreyXor](https://redirect.github.com/GreyXor) in
[#&#8203;419](https://redirect.github.com/knadh/koanf/pull/419)
- skip disabled secret on azure kv read by
[@&#8203;genlp](https://redirect.github.com/genlp) in
[#&#8203;437](https://redirect.github.com/knadh/koanf/pull/437)

#### New Contributors

- [@&#8203;upuddu](https://redirect.github.com/upuddu) made their first
contribution in
[#&#8203;424](https://redirect.github.com/knadh/koanf/pull/424)
- [@&#8203;genlp](https://redirect.github.com/genlp) made their first
contribution in
[#&#8203;437](https://redirect.github.com/knadh/koanf/pull/437)

**Full Changelog**:
<knadh/koanf@v2.3.5...v2.3.6>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/go-logr/logr](https://redirect.github.com/go-logr/logr) |
`v1.4.3` → `v1.4.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fgo-logr%2flogr/v1.4.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fgo-logr%2flogr/v1.4.3/v1.4.4?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>go-logr/logr (github.com/go-logr/logr)</summary>

###
[`v1.4.4`](https://redirect.github.com/go-logr/logr/releases/tag/v1.4.4)

[Compare
Source](https://redirect.github.com/go-logr/logr/compare/v1.4.3...v1.4.4)

#### What's Changed

- drop +build tags by [@&#8203;pohly](https://redirect.github.com/pohly)
in [#&#8203;401](https://redirect.github.com/go-logr/logr/pull/401)
- CI: avoid floating dependencies, fix issues by
[@&#8203;pohly](https://redirect.github.com/pohly) in
[#&#8203;432](https://redirect.github.com/go-logr/logr/pull/432)
- Bump to Go 1.26 by
[@&#8203;thockin](https://redirect.github.com/thockin) in
[#&#8203;445](https://redirect.github.com/go-logr/logr/pull/445)
- funcr: bound slog.Group nesting depth to prevent stack overflow by
[@&#8203;martinholovsky](https://redirect.github.com/martinholovsky) in
[#&#8203;447](https://redirect.github.com/go-logr/logr/pull/447)
- funcr: Handle and test recursive values by
[@&#8203;thockin](https://redirect.github.com/thockin) in
[#&#8203;446](https://redirect.github.com/go-logr/logr/pull/446)

#### New Contributors

- [@&#8203;martinholovsky](https://redirect.github.com/martinholovsky)
made their first contribution in
[#&#8203;447](https://redirect.github.com/go-logr/logr/pull/447)

**Full Changelog**:
<go-logr/logr@v1.4.3...v1.4.4>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [golang.org/x/crypto](https://pkg.go.dev/golang.org/x/crypto) |
[`v0.53.0` →
`v0.54.0`](https://cs.opensource.google/go/x/crypto/+/refs/tags/v0.53.0...refs/tags/v0.54.0)
|
![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fcrypto/v0.54.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fcrypto/v0.53.0/v0.54.0?slim=true)
|
| [golang.org/x/mod](https://pkg.go.dev/golang.org/x/mod) | [`v0.37.0` →
`v0.38.0`](https://cs.opensource.google/go/x/mod/+/refs/tags/v0.37.0...refs/tags/v0.38.0)
|
![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fmod/v0.38.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fmod/v0.37.0/v0.38.0?slim=true)
|
| [golang.org/x/net](https://pkg.go.dev/golang.org/x/net) | [`v0.56.0` →
`v0.57.0`](https://cs.opensource.google/go/x/net/+/refs/tags/v0.56.0...refs/tags/v0.57.0)
|
![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fnet/v0.57.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fnet/v0.56.0/v0.57.0?slim=true)
|
| [golang.org/x/text](https://pkg.go.dev/golang.org/x/text) | [`v0.39.0`
→
`v0.40.0`](https://cs.opensource.google/go/x/text/+/refs/tags/v0.39.0...refs/tags/v0.40.0)
|
![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2ftext/v0.40.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2ftext/v0.39.0/v0.40.0?slim=true)
|
| [golang.org/x/tools](https://pkg.go.dev/golang.org/x/tools) |
[`v0.47.0` →
`v0.48.0`](https://cs.opensource.google/go/x/tools/+/refs/tags/v0.47.0...refs/tags/v0.48.0)
|
![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2ftools/v0.48.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2ftools/v0.47.0/v0.48.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…n-library-for-go to v1.8.0 (9.5) (#7802)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/AzureAD/microsoft-authentication-library-for-go](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go)
| `v1.7.2` → `v1.8.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fAzureAD%2fmicrosoft-authentication-library-for-go/v1.8.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fAzureAD%2fmicrosoft-authentication-library-for-go/v1.7.2/v1.8.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>AzureAD/microsoft-authentication-library-for-go
(github.com/AzureAD/microsoft-authentication-library-for-go)</summary>

###
[`v1.8.0`](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go/releases/tag/v1.8.0)

[Compare
Source](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go/compare/v1.7.2...v1.8.0)

#### What's Changed

- Recover from panics in `json.Unmarshal` to prevent token-cache crashes
(fixes
[#&#8203;579](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go/issues/579))
by [@&#8203;4gust](https://redirect.github.com/4gust) in
[#&#8203;614](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go/pull/614)
- fix(base.go): empty partition key causing external cache miss by
[@&#8203;MatteoCalabro-TomTom](https://redirect.github.com/MatteoCalabro-TomTom)
in
[#&#8203;615](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go/pull/615)
- Add User Federated Identity Credential (`user_fic`) grant type support
by [@&#8203;Avery-Dunn](https://redirect.github.com/Avery-Dunn) in
[#&#8203;619](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go/pull/619)

#### New Contributors

-
[@&#8203;MatteoCalabro-TomTom](https://redirect.github.com/MatteoCalabro-TomTom)
made their first contribution in
[#&#8203;615](https://redirect.github.com/AzureAD/microsoft-authentication-library-for-go/pull/615)

**Full Changelog**:
<AzureAD/microsoft-authentication-library-for-go@v1.7.2...1.8.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
….5) (#7804)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/coreos/go-oidc/v3](https://redirect.github.com/coreos/go-oidc)
| `v3.19.0` → `v3.20.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fcoreos%2fgo-oidc%2fv3/v3.20.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fcoreos%2fgo-oidc%2fv3/v3.19.0/v3.20.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>coreos/go-oidc (github.com/coreos/go-oidc/v3)</summary>

###
[`v3.20.0`](https://redirect.github.com/coreos/go-oidc/releases/tag/v3.20.0)

[Compare
Source](https://redirect.github.com/coreos/go-oidc/compare/v3.19.0...v3.20.0)

#### What's Changed

- oidc: modernize with new Go APIs by
[@&#8203;ericchiang](https://redirect.github.com/ericchiang) in
[#&#8203;487](https://redirect.github.com/coreos/go-oidc/pull/487)
- oidc: improve documentation for APIs by
[@&#8203;ericchiang](https://redirect.github.com/ericchiang) in
[#&#8203;488](https://redirect.github.com/coreos/go-oidc/pull/488)
- SECURITY.md: add a security policy and point to project-level
reporting by
[@&#8203;ericchiang](https://redirect.github.com/ericchiang) in
[#&#8203;489](https://redirect.github.com/coreos/go-oidc/pull/489)
- oidc: ignore JWKs with unknown signing algorithms rather than failing
by [@&#8203;ericchiang](https://redirect.github.com/ericchiang) in
[#&#8203;491](https://redirect.github.com/coreos/go-oidc/pull/491)
- readme: update README and docs by
[@&#8203;ericchiang](https://redirect.github.com/ericchiang) in
[#&#8203;492](https://redirect.github.com/coreos/go-oidc/pull/492)
- oidc: add API for determining when issuer URLs mismatch by
[@&#8203;ericchiang](https://redirect.github.com/ericchiang) in
[#&#8203;493](https://redirect.github.com/coreos/go-oidc/pull/493)
- oidc: add constants for "email" and "profile" scopes by
[@&#8203;ericchiang](https://redirect.github.com/ericchiang) in
[#&#8203;494](https://redirect.github.com/coreos/go-oidc/pull/494)

**Full Changelog**:
<coreos/go-oidc@v3.19.0...v3.20.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…7803)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/cheggaaa/pb/v3](https://redirect.github.com/cheggaaa/pb) |
`v3.1.7` → `v3.2.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fcheggaaa%2fpb%2fv3/v3.2.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fcheggaaa%2fpb%2fv3/v3.1.7/v3.2.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>cheggaaa/pb (github.com/cheggaaa/pb/v3)</summary>

###
[`v3.2.0`](https://redirect.github.com/cheggaaa/pb/compare/v3.1.7...v3.2.0)

[Compare
Source](https://redirect.github.com/cheggaaa/pb/compare/v3.1.7...v3.2.0)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…ry-operations-go/detectors/gcp to v1.35.0 (9.5) (#7808)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go)
| `v1.33.0` → `v1.35.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fGoogleCloudPlatform%2fopentelemetry-operations-go%2fdetectors%2fgcp/v1.35.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fGoogleCloudPlatform%2fopentelemetry-operations-go%2fdetectors%2fgcp/v1.33.0/v1.35.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…7806)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/gofrs/uuid/v5](https://redirect.github.com/gofrs/uuid) |
`v5.4.0` → `v5.5.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fgofrs%2fuuid%2fv5/v5.5.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fgofrs%2fuuid%2fv5/v5.4.0/v5.5.1?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>gofrs/uuid (github.com/gofrs/uuid/v5)</summary>

###
[`v5.5.1`](https://redirect.github.com/gofrs/uuid/releases/tag/v5.5.1)

[Compare
Source](https://redirect.github.com/gofrs/uuid/compare/v5.5.0...v5.5.1)

#### What's Changed

- Fix integer overflow on 32bit architectures by
[@&#8203;gibmat](https://redirect.github.com/gibmat) in
[#&#8203;257](https://redirect.github.com/gofrs/uuid/pull/257)
- Update README.md to remove go report card by
[@&#8203;cameracker](https://redirect.github.com/cameracker) in
[#&#8203;255](https://redirect.github.com/gofrs/uuid/pull/255)
- build(deps): bump the all group with 7 updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;256](https://redirect.github.com/gofrs/uuid/pull/256)

#### New Contributors

- [@&#8203;gibmat](https://redirect.github.com/gibmat) made their first
contribution in
[#&#8203;257](https://redirect.github.com/gofrs/uuid/pull/257)

**Full Changelog**:
<gofrs/uuid@v5.5.0...v5.5.1>

###
[`v5.5.0`](https://redirect.github.com/gofrs/uuid/releases/tag/v5.5.0)

[Compare
Source](https://redirect.github.com/gofrs/uuid/compare/v5.4.0...v5.5.0)

#### What's Changed

- fix: prevent UUIDv7 counter wrap after 4096 ids by
[@&#8203;mistermoe](https://redirect.github.com/mistermoe) in
[#&#8203;253](https://redirect.github.com/gofrs/uuid/pull/253)
- perf: Improve error handling performance by removing expensive
formatting by [@&#8203;AmritM18](https://redirect.github.com/AmritM18)
in [#&#8203;247](https://redirect.github.com/gofrs/uuid/pull/247)
- Feature/uuidv8 by
[@&#8203;cameracker](https://redirect.github.com/cameracker) in
[#&#8203;241](https://redirect.github.com/gofrs/uuid/pull/241)

#### New Contributors

- [@&#8203;AmritM18](https://redirect.github.com/AmritM18) made their
first contribution in
[#&#8203;247](https://redirect.github.com/gofrs/uuid/pull/247)
- [@&#8203;mistermoe](https://redirect.github.com/mistermoe) made their
first contribution in
[#&#8203;253](https://redirect.github.com/gofrs/uuid/pull/253)

**Full Changelog**:
<gofrs/uuid@v5.4.0...v5.5.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…804.0 (9.5) (#7813)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/letsencrypt/boulder](https://redirect.github.com/letsencrypt/boulder)
| `v0.20260630.0` → `v0.20260804.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fletsencrypt%2fboulder/v0.20260804.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fletsencrypt%2fboulder/v0.20260630.0/v0.20260804.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>letsencrypt/boulder (github.com/letsencrypt/boulder)</summary>

###
[`v0.20260804.0`](https://redirect.github.com/letsencrypt/boulder/releases/tag/v0.20260804.0)

[Compare
Source](https://redirect.github.com/letsencrypt/boulder/compare/v0.20260729.0...v0.20260804.0)

#### What's Changed

- privatekey: Return a deterministic crypto.Signer from verifyMLDSA by
[@&#8203;beautifulentropy](https://redirect.github.com/beautifulentropy)
in
[#&#8203;8926](https://redirect.github.com/letsencrypt/boulder/pull/8926)
- cert-checker: configure issuers for CP/CPS lints by
[@&#8203;aarongable](https://redirect.github.com/aarongable) in
[#&#8203;8927](https://redirect.github.com/letsencrypt/boulder/pull/8927)
- unsigned: implement RFC 9925 by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8901](https://redirect.github.com/letsencrypt/boulder/pull/8901)
- trees/cosignature: Address remaining comments from
[#&#8203;8904](https://redirect.github.com/letsencrypt/boulder/issues/8904)
by
[@&#8203;beautifulentropy](https://redirect.github.com/beautifulentropy)
in
[#&#8203;8928](https://redirect.github.com/letsencrypt/boulder/pull/8928)
- build(deps): bump github/codeql-action/analyze from 4.36.2 to 4.37.3
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;8929](https://redirect.github.com/letsencrypt/boulder/pull/8929)
- observer: ccadb: check reported CRL shards for completeness by
[@&#8203;inahga](https://redirect.github.com/inahga) in
[#&#8203;8890](https://redirect.github.com/letsencrypt/boulder/pull/8890)
- Remove sa.FQDNSetExists dead code by
[@&#8203;ezekiel](https://redirect.github.com/ezekiel) in
[#&#8203;8888](https://redirect.github.com/letsencrypt/boulder/pull/8888)

**Full Changelog**:
<letsencrypt/boulder@v0.20260729.0...v0.20260804.0>

###
[`v0.20260729.0`](https://redirect.github.com/letsencrypt/boulder/releases/tag/v0.20260729.0)

[Compare
Source](https://redirect.github.com/letsencrypt/boulder/compare/v0.20260728.0...v0.20260729.0)

#### What's Changed

- Update grpc to v1.82.1 by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8910](https://redirect.github.com/letsencrypt/boulder/pull/8910)
- Update CODEOWNERS by
[@&#8203;aarongable](https://redirect.github.com/aarongable) in
[#&#8203;8921](https://redirect.github.com/letsencrypt/boulder/pull/8921)
- mtca: write to tiles by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8900](https://redirect.github.com/letsencrypt/boulder/pull/8900)
- Move GenerateSKID into Core for sharing across ca, ceremony, and lints
by [@&#8203;aarongable](https://redirect.github.com/aarongable) in
[#&#8203;8922](https://redirect.github.com/letsencrypt/boulder/pull/8922)
- Remove the ability to issue id-kp-clientAuth certificates by
[@&#8203;aarongable](https://redirect.github.com/aarongable) in
[#&#8203;8925](https://redirect.github.com/letsencrypt/boulder/pull/8925)
- proof: implement MTCProof by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8907](https://redirect.github.com/letsencrypt/boulder/pull/8907)
- trees/cosignature: Sign and verify MTC checkpoint cosignatures by
[@&#8203;beautifulentropy](https://redirect.github.com/beautifulentropy)
in
[#&#8203;8904](https://redirect.github.com/letsencrypt/boulder/pull/8904)
- entry: add MTCLogEntry.ToTBSCertificate() by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8908](https://redirect.github.com/letsencrypt/boulder/pull/8908)
- Create scaffolding for configuring lints with issuers by
[@&#8203;aarongable](https://redirect.github.com/aarongable) in
[#&#8203;8923](https://redirect.github.com/letsencrypt/boulder/pull/8923)

**Full Changelog**:
<letsencrypt/boulder@v0.20260728.0...v0.20260729.0>

###
[`v0.20260728.0`](https://redirect.github.com/letsencrypt/boulder/releases/tag/v0.20260728.0)

[Compare
Source](https://redirect.github.com/letsencrypt/boulder/compare/v0.20260720.0...v0.20260728.0)

#### What's Changed

- observer: ccadb: use less RAM by
[@&#8203;inahga](https://redirect.github.com/inahga) in
[#&#8203;8892](https://redirect.github.com/letsencrypt/boulder/pull/8892)
- Remove GetRevocationStatus dead code by
[@&#8203;aarongable](https://redirect.github.com/aarongable) in
[#&#8203;8884](https://redirect.github.com/letsencrypt/boulder/pull/8884)
- bad-key-revoker: also revoke accounts with blocked keys by
[@&#8203;aarongable](https://redirect.github.com/aarongable) in
[#&#8203;8837](https://redirect.github.com/letsencrypt/boulder/pull/8837)
- Update golang.org/x/text to v0.39.0 by
[@&#8203;aarongable](https://redirect.github.com/aarongable) in
[#&#8203;8897](https://redirect.github.com/letsencrypt/boulder/pull/8897)
- Rename Authz IdInt fields to plain Id. by
[@&#8203;ezekiel](https://redirect.github.com/ezekiel) in
[#&#8203;8893](https://redirect.github.com/letsencrypt/boulder/pull/8893)
- ra/sa: Prevent parallel validation attempts by
[@&#8203;aarongable](https://redirect.github.com/aarongable) in
[#&#8203;8838](https://redirect.github.com/letsencrypt/boulder/pull/8838)
- Ceremony: generate serials with a prefix to guarantee length by
[@&#8203;aarongable](https://redirect.github.com/aarongable) in
[#&#8203;8899](https://redirect.github.com/letsencrypt/boulder/pull/8899)
- mtca: add profile and run Prepare by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8886](https://redirect.github.com/letsencrypt/boulder/pull/8886)
- tiles: add Frontier to read/write tiles by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8896](https://redirect.github.com/letsencrypt/boulder/pull/8896)
- Update otel to v1.44.0 by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8906](https://redirect.github.com/letsencrypt/boulder/pull/8906)

**Full Changelog**:
<letsencrypt/boulder@v0.20260720.0...v0.20260728.0>

###
[`v0.20260720.0`](https://redirect.github.com/letsencrypt/boulder/releases/tag/v0.20260720.0)

[Compare
Source](https://redirect.github.com/letsencrypt/boulder/compare/v0.20260713.0...v0.20260720.0)

#### What's Changed

- trees/checkpoint: Add checkpoint.Checkpoint by
[@&#8203;beautifulentropy](https://redirect.github.com/beautifulentropy)
in
[#&#8203;8830](https://redirect.github.com/letsencrypt/boulder/pull/8830)
- sa: use tx object in AddPrecertificate by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8865](https://redirect.github.com/letsencrypt/boulder/pull/8865)
- observer: Fix possible panic in TLSProbe check by
[@&#8203;beautifulentropy](https://redirect.github.com/beautifulentropy)
in
[#&#8203;8836](https://redirect.github.com/letsencrypt/boulder/pull/8836)
- trees/subtree: Generate and verify MTC subtree consistency proofs by
[@&#8203;beautifulentropy](https://redirect.github.com/beautifulentropy)
in
[#&#8203;8808](https://redirect.github.com/letsencrypt/boulder/pull/8808)
- minio: self-initialize container by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8880](https://redirect.github.com/letsencrypt/boulder/pull/8880)
- Remove all string ID fields for Authzs. by
[@&#8203;ezekiel](https://redirect.github.com/ezekiel) in
[#&#8203;8828](https://redirect.github.com/letsencrypt/boulder/pull/8828)
- crl-storer: factor out S3 config and initialization by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8873](https://redirect.github.com/letsencrypt/boulder/pull/8873)
- test: run unittests under gotip when appropriate by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8883](https://redirect.github.com/letsencrypt/boulder/pull/8883)
- linter: pass through RawSubject by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8869](https://redirect.github.com/letsencrypt/boulder/pull/8869)
- mtca: add sequencing by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8826](https://redirect.github.com/letsencrypt/boulder/pull/8826)
- issuance: add ProfileConfig.MTC by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8868](https://redirect.github.com/letsencrypt/boulder/pull/8868)
- Update publicsuffix-go by
[@&#8203;rellem](https://redirect.github.com/rellem) in
[#&#8203;8882](https://redirect.github.com/letsencrypt/boulder/pull/8882)
- entry: add MTCLogEntry, TBSCertificateLogEntry by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8867](https://redirect.github.com/letsencrypt/boulder/pull/8867)
- mtca: add S3 connection by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8885](https://redirect.github.com/letsencrypt/boulder/pull/8885)

#### New Contributors

- [@&#8203;rellem](https://redirect.github.com/rellem) made their first
contribution in
[#&#8203;8882](https://redirect.github.com/letsencrypt/boulder/pull/8882)

**Full Changelog**:
<letsencrypt/boulder@v0.20260713.0...v0.20260720.0>

###
[`v0.20260713.0`](https://redirect.github.com/letsencrypt/boulder/releases/tag/v0.20260713.0)

[Compare
Source](https://redirect.github.com/letsencrypt/boulder/compare/v0.20260707.0...v0.20260713.0)

#### What's Changed

- test.sh: Anchor the grep pattern used to exclude one package. by
[@&#8203;ezekiel](https://redirect.github.com/ezekiel) in
[#&#8203;8863](https://redirect.github.com/letsencrypt/boulder/pull/8863)
- Don't exit on failure if cert-checker finds bad certs by
[@&#8203;lenaunderwood22](https://redirect.github.com/lenaunderwood22)
in
[#&#8203;8866](https://redirect.github.com/letsencrypt/boulder/pull/8866)
- Use DialerRetries from config file in redis RingOptions. by
[@&#8203;ezekiel](https://redirect.github.com/ezekiel) in
[#&#8203;8864](https://redirect.github.com/letsencrypt/boulder/pull/8864)
- bdns: error when CAA query response is truncated by
[@&#8203;Preston12321](https://redirect.github.com/Preston12321) in
[#&#8203;8839](https://redirect.github.com/letsencrypt/boulder/pull/8839)
- Add conversation resolution requirement to CONTRIBUTING.md. by
[@&#8203;ezekiel](https://redirect.github.com/ezekiel) in
[#&#8203;8860](https://redirect.github.com/letsencrypt/boulder/pull/8860)
- Observer: add jitter to each monitor to prevent stampedes by
[@&#8203;aarongable](https://redirect.github.com/aarongable) in
[#&#8203;8872](https://redirect.github.com/letsencrypt/boulder/pull/8872)

**Full Changelog**:
<letsencrypt/boulder@v0.20260707.0...v0.20260713.0>

###
[`v0.20260707.0`](https://redirect.github.com/letsencrypt/boulder/releases/tag/v0.20260707.0)

[Compare
Source](https://redirect.github.com/letsencrypt/boulder/compare/v0.20260630.0...v0.20260707.0)

#### What's Changed

- trees/cosigned: Add cosigned.Message by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8819](https://redirect.github.com/letsencrypt/boulder/pull/8819)
- admin: close files after reading by
[@&#8203;aarongable](https://redirect.github.com/aarongable) in
[#&#8203;8835](https://redirect.github.com/letsencrypt/boulder/pull/8835)
- linter: check that CRL issuers match issuer subjects byte-for-byte by
[@&#8203;Preston12321](https://redirect.github.com/Preston12321) in
[#&#8203;8827](https://redirect.github.com/letsencrypt/boulder/pull/8827)
- cert-checker: Allow scraping pprof data by
[@&#8203;beautifulentropy](https://redirect.github.com/beautifulentropy)
in
[#&#8203;8833](https://redirect.github.com/letsencrypt/boulder/pull/8833)
- Revert "Replace log package with fully slog-based system" by
[@&#8203;aarongable](https://redirect.github.com/aarongable) in
[#&#8203;8853](https://redirect.github.com/letsencrypt/boulder/pull/8853)
- build(deps): bump actions/setup-go from 6.4.0 to 6.5.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;8831](https://redirect.github.com/letsencrypt/boulder/pull/8831)
- Pivot WFE around the string(authzID) to int64(authzID) type change. by
[@&#8203;ezekiel](https://redirect.github.com/ezekiel) in
[#&#8203;8856](https://redirect.github.com/letsencrypt/boulder/pull/8856)
- ca: add per-profile MaxCertificateSize by
[@&#8203;jsha](https://redirect.github.com/jsha) in
[#&#8203;8806](https://redirect.github.com/letsencrypt/boulder/pull/8806)

**Full Changelog**:
<letsencrypt/boulder@v0.20260630.0...v0.20260707.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…ry-operations-go/internal/resourcemapping to v0.59.0 (9.5) (#7810)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go)
| `v0.57.0` → `v0.59.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fGoogleCloudPlatform%2fopentelemetry-operations-go%2finternal%2fresourcemapping/v0.59.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fGoogleCloudPlatform%2fopentelemetry-operations-go%2finternal%2fresourcemapping/v0.57.0/v0.59.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>GoogleCloudPlatform/opentelemetry-operations-go
(github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping)</summary>

###
[`v0.59.0`](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/releases/tag/v0.59.0)

[Compare
Source](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/compare/v0.58.0...v0.59.0)

#### What's Changed

- Adds support for resolving OpenTelemetry authentication extensions by
[@&#8203;Angelawork](https://redirect.github.com/Angelawork) in
[#&#8203;1181](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1181)
- update golang.org/x/crypto by
[@&#8203;braydonk](https://redirect.github.com/braydonk) in
[#&#8203;1182](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1182)
- Update module google.golang.org/grpc to v1.82.1 \[SECURITY] by
[@&#8203;renovate-bot](https://redirect.github.com/renovate-bot) in
[#&#8203;1184](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1184)
- Prepare release 0.59.0/1.35.0 by
[@&#8203;braydonk](https://redirect.github.com/braydonk) in
[#&#8203;1183](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1183)

#### New Contributors

- [@&#8203;Angelawork](https://redirect.github.com/Angelawork) made
their first contribution in
[#&#8203;1181](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1181)

**Full Changelog**:
<GoogleCloudPlatform/opentelemetry-operations-go@v0.58.0...v0.59.0>

###
[`v0.58.0`](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/releases/tag/v0.58.0):
v1.34.0/v0.58.0

[Compare
Source](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/compare/v0.57.0...v0.58.0)

#### What's Changed

- googlemanagedprometheus: Add `destination_project_quota` by
[@&#8203;braydonk](https://redirect.github.com/braydonk) in
[#&#8203;1175](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1175)
- Prepare release v1.34.0/v0.58.0 by
[@&#8203;braydonk](https://redirect.github.com/braydonk) in
[#&#8203;1178](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1178)

**Full Changelog**:
<GoogleCloudPlatform/opentelemetry-operations-go@v0.57.0...v0.58.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
….5) (#7812)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/lestrrat-go/jwx/v3](https://redirect.github.com/lestrrat-go/jwx)
| `v3.1.1` → `v3.2.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2flestrrat-go%2fjwx%2fv3/v3.2.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2flestrrat-go%2fjwx%2fv3/v3.1.1/v3.2.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>lestrrat-go/jwx (github.com/lestrrat-go/jwx/v3)</summary>

###
[`v3.2.0`](https://redirect.github.com/lestrrat-go/jwx/releases/tag/v3.2.0)

[Compare
Source](https://redirect.github.com/lestrrat-go/jwx/compare/v3.1.1...v3.2.0)

For more detailed release notes, see
[Changes](https://redirect.github.com/lestrrat-go/jwx/blob/v3.2.0/Changes).

#### What's Changed

- build(deps): bump github.com/lestrrat-go/dsig from 1.2.1 to 1.3.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2043](https://redirect.github.com/lestrrat-go/jwx/pull/2043)
- build(deps): bump golang.org/x/crypto from 0.50.0 to 0.51.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2159](https://redirect.github.com/lestrrat-go/jwx/pull/2159)
- build(deps): bump actions/stale from 10.2.0 to 10.3.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2174](https://redirect.github.com/lestrrat-go/jwx/pull/2174)
- build(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2179](https://redirect.github.com/lestrrat-go/jwx/pull/2179)
- build(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2180](https://redirect.github.com/lestrrat-go/jwx/pull/2180)
- build(deps): bump actions/checkout from 6.0.2 to 6.0.3 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2184](https://redirect.github.com/lestrrat-go/jwx/pull/2184)
- bump httprc to v3.0.6 by
[@&#8203;lestrrat](https://redirect.github.com/lestrrat) in
[#&#8203;2189](https://redirect.github.com/lestrrat-go/jwx/pull/2189)
- autodoc updates by
[@&#8203;github-actions](https://redirect.github.com/github-actions)\[bot]
in [#&#8203;2190](https://redirect.github.com/lestrrat-go/jwx/pull/2190)
- build(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2192](https://redirect.github.com/lestrrat-go/jwx/pull/2192)
- build(deps): bump actions/checkout from 6.0.3 to 7.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2226](https://redirect.github.com/lestrrat-go/jwx/pull/2226)
- build(deps): bump actions/cache from 5.0.5 to 6.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2231](https://redirect.github.com/lestrrat-go/jwx/pull/2231)
- build(deps): bump actions/setup-go from 6.4.0 to 6.5.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2230](https://redirect.github.com/lestrrat-go/jwx/pull/2230)
- build(deps): bump actions/cache from 6.0.0 to 6.1.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2238](https://redirect.github.com/lestrrat-go/jwx/pull/2238)
- build(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2242](https://redirect.github.com/lestrrat-go/jwx/pull/2242)
- fix misspellings in code comments by
[@&#8203;lestrrat](https://redirect.github.com/lestrrat) in
[#&#8203;2249](https://redirect.github.com/lestrrat-go/jwx/pull/2249)
- build(deps): bump actions/stale from 10.3.0 to 10.4.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2254](https://redirect.github.com/lestrrat-go/jwx/pull/2254)
- build(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2250](https://redirect.github.com/lestrrat-go/jwx/pull/2250)
- build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2258](https://redirect.github.com/lestrrat-go/jwx/pull/2258)
- build(deps): bump actions/checkout from 7.0.0 to 7.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2261](https://redirect.github.com/lestrrat-go/jwx/pull/2261)
- bump x/crypto to v0.54.0 in codegen modules by
[@&#8203;lestrrat](https://redirect.github.com/lestrrat) in
[#&#8203;2266](https://redirect.github.com/lestrrat-go/jwx/pull/2266)
- \[v3] retain unparseable JWK set keys, opt-in by
[@&#8203;lestrrat](https://redirect.github.com/lestrrat) in
[#&#8203;2265](https://redirect.github.com/lestrrat-go/jwx/pull/2265)
- \[v3] fix per-call reject-dup-kid override by
[@&#8203;lestrrat](https://redirect.github.com/lestrrat) in
[#&#8203;2270](https://redirect.github.com/lestrrat-go/jwx/pull/2270)
- \[v3] test jwe rejects UnsupportedKey placeholder by
[@&#8203;lestrrat](https://redirect.github.com/lestrrat) in
[#&#8203;2272](https://redirect.github.com/lestrrat-go/jwx/pull/2272)
- \[v3] doc: recommend retain mode for third-party JWK sets as PQC rolls
out by [@&#8203;lestrrat](https://redirect.github.com/lestrrat) in
[#&#8203;2274](https://redirect.github.com/lestrrat-go/jwx/pull/2274)
- fix jwe JSON AAD serialization by
[@&#8203;lestrrat](https://redirect.github.com/lestrrat) in
[#&#8203;2276](https://redirect.github.com/lestrrat-go/jwx/pull/2276)
- add JWE authenticated data option by
[@&#8203;lestrrat](https://redirect.github.com/lestrrat) in
[#&#8203;2278](https://redirect.github.com/lestrrat-go/jwx/pull/2278)

**Full Changelog**:
<lestrrat-go/jwx@v3.1.1...v3.2.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…11 (9.5) (#7814)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/magiconair/properties](https://redirect.github.com/magiconair/properties)
| `v1.8.10` → `v1.18.11` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fmagiconair%2fproperties/v1.18.11?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fmagiconair%2fproperties/v1.8.10/v1.18.11?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>magiconair/properties
(github.com/magiconair/properties)</summary>

###
[`v1.18.11`](https://redirect.github.com/magiconair/properties/releases/tag/v1.18.11)

[Compare
Source](https://redirect.github.com/magiconair/properties/compare/v1.8.10...v1.18.11)

#### What's Changed

- test with go1.25 and go1.26 by
[@&#8203;magiconair](https://redirect.github.com/magiconair) in
[#&#8203;88](https://redirect.github.com/magiconair/properties/pull/88)
- fix: strip UTF-8 BOM when loading properties by
[@&#8203;sonnemusk](https://redirect.github.com/sonnemusk) in
[#&#8203;87](https://redirect.github.com/magiconair/properties/pull/87)

#### New Contributors

- [@&#8203;sonnemusk](https://redirect.github.com/sonnemusk) made their
first contribution in
[#&#8203;87](https://redirect.github.com/magiconair/properties/pull/87)

**Full Changelog**:
<magiconair/properties@v1.8.10...v1.18.11>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
….5) (#7818)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/redis/go-redis/v9](https://redirect.github.com/redis/go-redis)
| `v9.21.0` → `v9.22.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fredis%2fgo-redis%2fv9/v9.22.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fredis%2fgo-redis%2fv9/v9.21.0/v9.22.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>redis/go-redis (github.com/redis/go-redis/v9)</summary>

###
[`v9.22.0`](https://redirect.github.com/redis/go-redis/releases/tag/v9.22.0):
9.22.0

[Compare
Source](https://redirect.github.com/redis/go-redis/compare/v9.21.0...v9.22.0)

This is a minor release introducing two flagship (experimental) features
— **client-side caching** and **automatic pipelining** — alongside
support for Redis 8.10, new commands, and a large batch of stability and
parser-robustness fixes. It consolidates everything shipped in
9.22.0-beta.1, so the notes below cover the full 9.21.0 → 9.22.0
upgrade.

⚠️ Two changes to be aware of when upgrading from 9.21.0:

- **Default configuration values changed**
([#&#8203;3918](https://redirect.github.com/redis/go-redis/pull/3918)):
read/write timeouts, retry backoff, cluster state reload interval, and
TCP keep-alive defaults are now aligned with the cross-SDK configuration
proposal (see the highlight below). Explicitly configured values are
unaffected.
- **`WaitAOF` return type corrected**
([#&#8203;3888](https://redirect.github.com/redis/go-redis/pull/3888)):
`WaitAOF` now returns `*IntSliceCmd`, matching the two-integer reply of
`WAITAOF` (previously `*IntCmd`, which failed to parse the reply at
runtime). Code referencing the old return type needs a one-line update.

#### 🚀 Highlights

##### Client-Side Caching (Experimental)

The standalone `Client` gains server-assisted client-side caching built
on RESP3 `CLIENT TRACKING`. Enable it by setting `ClientSideCacheConfig`
in `Options` (or supply your own cache via `ClientSideCache` — e.g. to
share one cache across clients). Cacheable read results are served from
a local in-process cache and invalidated automatically when the server
reports a change, cutting round trips for read-heavy workloads.

The invalidation architecture is selected by `ClientSideCacheStrategy`;
the default (and currently only) strategy is
`CSCStrategySharedTracking`: one shared cache, every pool connection
runs plain `CLIENT TRACKING ON`, and a background drainer applies
buffered invalidations — portable (no BCAST) and consistent with the
other Redis client libraries. Requirements and guardrails: RESP3
(`Protocol: 3`), standalone client, DB 0 only; commands that would
change the connection identity (`SELECT`, `AUTH`, ...) are rejected
while caching is enabled, and CSC is disabled when a credentials
provider is set (fixed `Username`/`Password` work and are namespaced).
See the README's [client-side caching
section](README.md#client-side-caching) and the runnable
[example](example/client-side-caching).

**Experimental:** the API may change in a minor release.

([#&#8203;3941](https://redirect.github.com/redis/go-redis/pull/3941))
by [@&#8203;ofekshenawa](https://redirect.github.com/ofekshenawa)

##### Automatic Pipelining (Experimental)

`AutoPipeliner` is a background batcher that coalesces commands from
many concurrent goroutines into Redis pipelines, multiplying throughput
without any manual pipeline management. It comes in two faces, available
on `Client` and `ClusterClient` (and configurable via
`Options.AutoPipelineOptions` / `UniversalOptions.AutoPipelineOptions`):

- **`AutoPipeline()`** — the blocking face: a drop-in `Cmdable` where
each call blocks until executed, exactly like a plain client, while
concurrent callers' commands batch together under the hood (measured
locally over loopback: \~1M+ SET/sec vs \~100k unpipelined; indicative,
not a guarantee). Per-goroutine command order is preserved.
- **`AsyncAutoPipeline()`** — the deferred face: command calls return
immediately and every typed result accessor (`Val`/`Result`/`Err`/...)
blocks until the command has executed. Submit a window of commands, then
read the results, to keep pipelines deep (\~2–3M SET/sec locally;
indicative).

`AutoPipelineOptions` controls batching: `MaxBatchSize` (soft target,
default 200; the blocking face's preset uses 300), `MaxBatchBytes`
(approximate payload cap so huge values flush as several bounded
writes), `MaxFlushDelay` with optional `AdaptiveDelay` (delay scales
down as the queue fills), and `MaxConcurrentBatches` (default 1 = a
single ordered batch stream; raising it requires `Unordered: true`, so
ordering is never lost by accident — `Validate()` rejects the
combination otherwise). A usage tour and throughput comparison live in
[`example/autopipeline`](example/autopipeline).

**Experimental:** the API may change in a future release — pin your
go-redis version if you adopt it.

([#&#8203;3942](https://redirect.github.com/redis/go-redis/pull/3942))
by [@&#8203;ndyakov](https://redirect.github.com/ndyakov), with help
from [@&#8203;cxljs](https://redirect.github.com/cxljs)

##### Redis 8.10 Support

This release adds support for **Redis 8.10**. The README's
supported-versions list now includes Redis 8.10, and CI runs the full
suite against the `redislabs/client-libs-test:8.10.0` image by default
([#&#8203;3920](https://redirect.github.com/redis/go-redis/pull/3920),
[#&#8203;3940](https://redirect.github.com/redis/go-redis/pull/3940)).

Coverage for the new commands and options that ship with Redis 8.10:

- **`HIMPORT`**
([#&#8203;3919](https://redirect.github.com/redis/go-redis/pull/3919)) —
bulk hash import via server-side fieldsets, exposed as `HImportPrepare`,
`HImportSet`, `HImportDiscard`, and `HImportDiscardAll`. Fieldsets are
session state scoped to a single physical connection, which does not mix
well with connection pooling — so the client keeps a versioned fieldset
registry and lazily replays the `PREPARE` on whichever pooled connection
executes a `SET` that needs it, at most once per connection, with no
extra round trip (the `PREPARE` is injected into the same write as the
`SET`).
- **`LMOVEM` / `BLMOVEM`**
([#&#8203;3913](https://redirect.github.com/redis/go-redis/pull/3913)) —
move multiple elements between lists in one call.
- **`SUNIONCARD` / `SDIFFCARD`**
([#&#8203;3897](https://redirect.github.com/redis/go-redis/pull/3897)) —
cardinality of set union/difference without materializing the result.
- **`XREAD` / `XREADGROUP` `MAXCOUNT` and `MAXSIZE`**
([#&#8203;3898](https://redirect.github.com/redis/go-redis/pull/3898)) —
bound how much data a stream read returns.
- **`TS.READ`**
([#&#8203;3896](https://redirect.github.com/redis/go-redis/pull/3896)),
**`TS.QUERYLABELS`**
([#&#8203;3926](https://redirect.github.com/redis/go-redis/pull/3926)),
**`TS.NRANGE` / `TS.NREVRANGE`**
([#&#8203;3870](https://redirect.github.com/redis/go-redis/pull/3870))
with multiple aggregators per key
([#&#8203;3937](https://redirect.github.com/redis/go-redis/pull/3937)),
and **`EXCLUDEEMPTY`** on `TS.MRANGE` / `TS.MREVRANGE`
([#&#8203;3912](https://redirect.github.com/redis/go-redis/pull/3912)) —
new time-series query surface.
- **`FT.ALIASLIST`**
([#&#8203;3925](https://redirect.github.com/redis/go-redis/pull/3925)),
**`COLLECT` reducer for `FT.AGGREGATE`**
([#&#8203;3886](https://redirect.github.com/redis/go-redis/pull/3886)),
**`RERANK` on HNSW vector fields in `FT.CREATE`**
([#&#8203;3927](https://redirect.github.com/redis/go-redis/pull/3927)),
and **`FT.HYBRID` timeout warnings**
([#&#8203;3911](https://redirect.github.com/redis/go-redis/pull/3911)) —
search coverage.

##### Cross-SDK Aligned Defaults

Default configuration values now follow the cross-SDK configuration
proposal shared by all Redis client libraries
([#&#8203;3918](https://redirect.github.com/redis/go-redis/pull/3918)):

| Setting | Old default | New default |
| ------------------------------ | ----------- |
--------------------------------------------------------- |
| `ReadTimeout` / `WriteTimeout` | 3s | 5s |
| Retry backoff (min/max) | 8ms / 512ms | 10ms / 1s |
| Cluster state reload interval | 10s | 60s |
| TCP keep-alive | 5min period | 30s idle / 5s interval / 3 probes
(`net.KeepAliveConfig`) |

Applications that set these values explicitly are unaffected;
applications relying on the old defaults inherit the new ones.

##### Data-Race and Parser Hardening Sweep

A systematic audit fixed data races across the client — hooks
(`AddHook`,
[#&#8203;3868](https://redirect.github.com/redis/go-redis/pull/3868)),
`Ring.SetAddrs`
([#&#8203;3862](https://redirect.github.com/redis/go-redis/pull/3862)),
cluster node slices
([#&#8203;3861](https://redirect.github.com/redis/go-redis/pull/3861)),
pub/sub reconnect
([#&#8203;3906](https://redirect.github.com/redis/go-redis/pull/3906)),
maintenance notifications
([#&#8203;3894](https://redirect.github.com/redis/go-redis/pull/3894),
[#&#8203;3872](https://redirect.github.com/redis/go-redis/pull/3872)),
pool handoff
([#&#8203;3876](https://redirect.github.com/redis/go-redis/pull/3876)),
and `redisotel`
([#&#8203;3881](https://redirect.github.com/redis/go-redis/pull/3881)) —
and hardened the RESP parsers against malformed or unexpected replies:
over-reads on nil replies
([#&#8203;3874](https://redirect.github.com/redis/go-redis/pull/3874)),
integer overflow when skipping map/attribute bodies
([#&#8203;3877](https://redirect.github.com/redis/go-redis/pull/3877)),
unhashable RESP3 map keys
([#&#8203;3873](https://redirect.github.com/redis/go-redis/pull/3873)),
odd-length flat replies
([#&#8203;3900](https://redirect.github.com/redis/go-redis/pull/3900)),
mismatched declared array lengths
([#&#8203;3907](https://redirect.github.com/redis/go-redis/pull/3907)),
unexpected extra reply frames
([#&#8203;3884](https://redirect.github.com/redis/go-redis/pull/3884)),
and nil elements in numeric/bool slice replies
([#&#8203;3922](https://redirect.github.com/redis/go-redis/pull/3922)).

##### PubSub `Receive` Hang Fix

`PeekPushNotificationName` blocked until 36 bytes were buffered, so a
short subscribe confirmation (channel name of six or fewer characters)
on an otherwise idle connection hung `PubSub.Receive` forever — a
regression introduced in 9.20.1 by
[#&#8203;3842](https://redirect.github.com/redis/go-redis/pull/3842).
The peek now parses whatever is already buffered and only waits for one
more byte when the frame prefix is valid but incomplete. Fixes
[#&#8203;3935](https://redirect.github.com/redis/go-redis/issues/3935).

([#&#8203;3936](https://redirect.github.com/redis/go-redis/pull/3936))
by [@&#8203;ndyakov](https://redirect.github.com/ndyakov)

##### Correct Cluster Transaction Retries

The cluster transaction pipeline treated a `MULTI`...`EXEC` block as
independently retryable commands, which could scatter a transaction
across nodes or send malformed transactions on retry. Redirects
(`MOVED`/`ASK`/`TRYAGAIN`) and aborts are now handled at the
whole-transaction level, matching Redis transaction semantics: the
transaction is re-routed and retried as a unit, never partially
([#&#8203;3909](https://redirect.github.com/redis/go-redis/pull/3909))
by [@&#8203;cxljs](https://redirect.github.com/cxljs).

##### Credential Redaction in Command Tracing

`rediscmd.AppendCmd` — used by `redisotel` and `rediscensus` to render
commands into span attributes — now redacts credential arguments as
`<redacted>`: `AUTH`, `HELLO ... AUTH`, `CONFIG SET` of `requirepass` /
`masterauth` / TLS key passphrases, `ACL SETUSER` password rules, and
`MIGRATE ... AUTH`/`AUTH2`. The client sends `HELLO ... AUTH` on every
handshake and `AUTH` on every streaming-credentials rotation through the
regular hook chain, so tracing hooks previously captured credentials
even when the application never issued an auth command itself
([#&#8203;3939](https://redirect.github.com/redis/go-redis/pull/3939))
by [@&#8203;saddamr3e](https://redirect.github.com/saddamr3e).

#### ✨ New Features

- **Client-side caching**: server-assisted caching for the standalone
client via `ClientSideCacheConfig` / `ClientSideCache`, with the
`CSCStrategySharedTracking` invalidation strategy
([#&#8203;3941](https://redirect.github.com/redis/go-redis/pull/3941))
by [@&#8203;ofekshenawa](https://redirect.github.com/ofekshenawa)
- **Automatic pipelining**: `AutoPipeline()` (blocking) and
`AsyncAutoPipeline()` (deferred results) on `Client` and
`ClusterClient`, configured via `AutoPipelineOptions`
([#&#8203;3942](https://redirect.github.com/redis/go-redis/pull/3942))
by [@&#8203;ndyakov](https://redirect.github.com/ndyakov), with help
from [@&#8203;cxljs](https://redirect.github.com/cxljs)
- **`HIMPORT` command family**: `HImportPrepare` / `HImportSet` /
`HImportDiscard` / `HImportDiscardAll` with lazy per-connection fieldset
prepare replay
([#&#8203;3919](https://redirect.github.com/redis/go-redis/pull/3919))
by [@&#8203;ndyakov](https://redirect.github.com/ndyakov)
- **`LMOVEM` / `BLMOVEM`**: move multiple list elements in one call,
with `COUNT` (up to N) or `EXACTLY` (all-or-nothing) semantics via
`LMoveMArgs`
([#&#8203;3913](https://redirect.github.com/redis/go-redis/pull/3913))
by [@&#8203;ofekshenawa](https://redirect.github.com/ofekshenawa)
- **`SUnionCard` / `SDiffCard`**: cardinality of set union/difference
([#&#8203;3897](https://redirect.github.com/redis/go-redis/pull/3897))
by [@&#8203;ofekshenawa](https://redirect.github.com/ofekshenawa)
- **`XRead` / `XReadGroup` `MAXCOUNT` / `MAXSIZE`**: bound stream read
responses by entry count or payload size
([#&#8203;3898](https://redirect.github.com/redis/go-redis/pull/3898))
by [@&#8203;ofekshenawa](https://redirect.github.com/ofekshenawa)
- **`TS.READ`**: read samples from a series starting at a given
timestamp, with `TSReadEarliest` (`-`), `TSReadLatest` (`+`), and
`TSReadNew` (`$`) sentinels
([#&#8203;3896](https://redirect.github.com/redis/go-redis/pull/3896))
by [@&#8203;ofekshenawa](https://redirect.github.com/ofekshenawa)
- **`TS.QUERYLABELS`**: query label names/values across time series
([#&#8203;3926](https://redirect.github.com/redis/go-redis/pull/3926))
by [@&#8203;ndyakov](https://redirect.github.com/ndyakov)
- **`TS.NRANGE` / `TS.NREVRANGE`**: range queries across multiple series
([#&#8203;3870](https://redirect.github.com/redis/go-redis/pull/3870))
by [@&#8203;ofekshenawa](https://redirect.github.com/ofekshenawa), with
multiple aggregators per key
([#&#8203;3937](https://redirect.github.com/redis/go-redis/pull/3937))
by [@&#8203;ndyakov](https://redirect.github.com/ndyakov)
- **`TS.MRANGE` / `TS.MREVRANGE` `EXCLUDEEMPTY`**: skip series with no
samples in the result
([#&#8203;3912](https://redirect.github.com/redis/go-redis/pull/3912))
by [@&#8203;ofekshenawa](https://redirect.github.com/ofekshenawa)
- **`FT.ALIASLIST`**: list all index aliases
([#&#8203;3925](https://redirect.github.com/redis/go-redis/pull/3925))
by [@&#8203;ndyakov](https://redirect.github.com/ndyakov)
- **`FT.AGGREGATE` `COLLECT` reducer**: collect grouped values into an
array
([#&#8203;3886](https://redirect.github.com/redis/go-redis/pull/3886))
by [@&#8203;ndyakov](https://redirect.github.com/ndyakov)
- **`FT.CREATE` `RERANK`**: `RERANK` parameter on HNSW vector field
definitions
([#&#8203;3927](https://redirect.github.com/redis/go-redis/pull/3927))
by [@&#8203;ofekshenawa](https://redirect.github.com/ofekshenawa)
- **`FT.HYBRID` timeout warnings**: timeout warnings are now populated
in hybrid search results
([#&#8203;3911](https://redirect.github.com/redis/go-redis/pull/3911))
by [@&#8203;ofekshenawa](https://redirect.github.com/ofekshenawa)
- **`FT.HYBRID` KNN `SHARD_K_RATIO`** (Redis 8.8+): per-shard K ratio
for KNN clauses
([#&#8203;3841](https://redirect.github.com/redis/go-redis/pull/3841))
by [@&#8203;ndyakov](https://redirect.github.com/ndyakov)

#### 🐛 Bug Fixes

- **PubSub `Receive` hang**: peek push-notification names without
demanding 36 buffered bytes, fixing a hang on short subscribe
confirmations (fixes
[#&#8203;3935](https://redirect.github.com/redis/go-redis/issues/3935),
regression from 9.20.1)
([#&#8203;3936](https://redirect.github.com/redis/go-redis/pull/3936))
by [@&#8203;ndyakov](https://redirect.github.com/ndyakov)
- **Cluster transactions**: re-route the whole tx pipeline on
redirect/abort instead of per-command
([#&#8203;3909](https://redirect.github.com/redis/go-redis/pull/3909))
by [@&#8203;cxljs](https://redirect.github.com/cxljs)
- **Credential leak in traces**: `rediscmd.AppendCmd` redacts credential
arguments (`AUTH`, `HELLO ... AUTH`, `CONFIG SET` secret params, `ACL
SETUSER` password rules, `MIGRATE AUTH`/`AUTH2`), so `redisotel` /
`rediscensus` span attributes no longer contain passwords
([#&#8203;3939](https://redirect.github.com/redis/go-redis/pull/3939))
by [@&#8203;saddamr3e](https://redirect.github.com/saddamr3e)
- **`WaitAOF` return type**: returns `*IntSliceCmd` matching the
two-integer `WAITAOF` reply
([#&#8203;3888](https://redirect.github.com/redis/go-redis/pull/3888))
by [@&#8203;CipherN9](https://redirect.github.com/CipherN9)
- **`Ring.Publish` routing**: publish to the shard that owns the topic
instead of a round-robined one
([#&#8203;3893](https://redirect.github.com/redis/go-redis/pull/3893))
by [@&#8203;dkindel](https://redirect.github.com/dkindel)
- **Pool `OnRemove` hooks**: fire `OnRemove` on `putConn` eviction paths
so removal hooks see every evicted connection
([#&#8203;3932](https://redirect.github.com/redis/go-redis/pull/3932))
by [@&#8203;cxljs](https://redirect.github.com/cxljs)
- **`UniversalClient` `InfoMap`**: added `InfoMap` to the `Cmdable`
interface
([#&#8203;3904](https://redirect.github.com/redis/go-redis/pull/3904))
by
[@&#8203;nazarli-shabnam](https://redirect.github.com/nazarli-shabnam)
- **`SlowLogGet` context**: pass the caller's context instead of a
background one
([#&#8203;3915](https://redirect.github.com/redis/go-redis/pull/3915))
by [@&#8203;sonnemusk](https://redirect.github.com/sonnemusk)
- **`ModuleLoadex` nil config**: return an error instead of panicking on
nil config
([#&#8203;3916](https://redirect.github.com/redis/go-redis/pull/3916))
by [@&#8203;sonnemusk](https://redirect.github.com/sonnemusk)
- **`ParseURL` IPv6 hosts**: keep single brackets for IPv6 hosts without
a port
([#&#8203;3882](https://redirect.github.com/redis/go-redis/pull/3882))
by [@&#8203;sueun-dev](https://redirect.github.com/sueun-dev)
- **`ParseURL` durations**: treat unit durations `<= 0` as disabled
([#&#8203;3866](https://redirect.github.com/redis/go-redis/pull/3866))
by [@&#8203;sueun-dev](https://redirect.github.com/sueun-dev)
- **Nil `*uint8` encoding**: encode nil `*uint8` as `"0"` like other
numeric pointers
([#&#8203;3869](https://redirect.github.com/redis/go-redis/pull/3869))
by [@&#8203;sueun-dev](https://redirect.github.com/sueun-dev)
- **`JSONSliceCmd` read errors**: return the read error from `readReply`
instead of swallowing it
([#&#8203;3903](https://redirect.github.com/redis/go-redis/pull/3903))
by [@&#8203;saddamr3e](https://redirect.github.com/saddamr3e)
- **RESP parser hardening**: reconcile declared entry-array lengths
([#&#8203;3907](https://redirect.github.com/redis/go-redis/pull/3907)),
handle nil elements in int/uint/bool slice parsers
([#&#8203;3922](https://redirect.github.com/redis/go-redis/pull/3922)),
drain unexpected reply frames
([#&#8203;3884](https://redirect.github.com/redis/go-redis/pull/3884)),
reject odd-length flat replies in Z/KeyValue parsers
([#&#8203;3900](https://redirect.github.com/redis/go-redis/pull/3900)),
avoid int overflow when skipping map/attr bodies
([#&#8203;3877](https://redirect.github.com/redis/go-redis/pull/3877)),
don't over-read nil replies in `Reader.Discard`
([#&#8203;3874](https://redirect.github.com/redis/go-redis/pull/3874))
by [@&#8203;saddamr3e](https://redirect.github.com/saddamr3e); reject
unhashable keys in RESP3 map parsing
([#&#8203;3873](https://redirect.github.com/redis/go-redis/pull/3873))
by [@&#8203;iabdullah215](https://redirect.github.com/iabdullah215)
- **Data races**: hook state during `AddHook`
([#&#8203;3868](https://redirect.github.com/redis/go-redis/pull/3868)),
`onNewNode` during `Ring.SetAddrs`
([#&#8203;3862](https://redirect.github.com/redis/go-redis/pull/3862)),
shared masters/slaves slices in cluster
([#&#8203;3861](https://redirect.github.com/redis/go-redis/pull/3861)),
shared `opt.Addr` during pub/sub reconnect
([#&#8203;3906](https://redirect.github.com/redis/go-redis/pull/3906)),
`clusterStateReloadCallback` in maintnotifications
([#&#8203;3894](https://redirect.github.com/redis/go-redis/pull/3894)),
conn reader in `isHealthyConn` during handoff
([#&#8203;3876](https://redirect.github.com/redis/go-redis/pull/3876))
by [@&#8203;saddamr3e](https://redirect.github.com/saddamr3e); handoff
race window in maintnotifications
([#&#8203;3872](https://redirect.github.com/redis/go-redis/pull/3872))
by [@&#8203;ndyakov](https://redirect.github.com/ndyakov)
- **`redisotel`**: use `ObservableCounter` for cumulative pool stats
([#&#8203;3914](https://redirect.github.com/redis/go-redis/pull/3914))
by [@&#8203;Solaris-star](https://redirect.github.com/Solaris-star);
avoid a data race on shared attributes during `MinIdleConns` warmup
([#&#8203;3881](https://redirect.github.com/redis/go-redis/pull/3881))
by [@&#8203;ndyakov](https://redirect.github.com/ndyakov)

#### 🧰 Maintenance

- **Cross-SDK default alignment**: new defaults for timeouts, retry
backoff, cluster state reload, and TCP keep-alive
([#&#8203;3918](https://redirect.github.com/redis/go-redis/pull/3918))
by [@&#8203;ndyakov](https://redirect.github.com/ndyakov)
- **CI on Redis 8.10**: 8.10 made the default test version
([#&#8203;3920](https://redirect.github.com/redis/go-redis/pull/3920))
with version gating by major.minor
([#&#8203;3908](https://redirect.github.com/redis/go-redis/pull/3908))
by [@&#8203;ofekshenawa](https://redirect.github.com/ofekshenawa); the
test stack now runs the GA `redislabs/client-libs-test:8.10.0` image and
8.8 was dropped from the CI matrix
([#&#8203;3940](https://redirect.github.com/redis/go-redis/pull/3940))
- **Type-safe atomics**: use typed `sync/atomic` value types
([#&#8203;3860](https://redirect.github.com/redis/go-redis/pull/3860))
and remove the dead `assertUnstableCommand` RESP3 path
([#&#8203;3928](https://redirect.github.com/redis/go-redis/pull/3928))
by [@&#8203;cxljs](https://redirect.github.com/cxljs)
- **Docs**: clarify that `ExpireTime` / `PExpireTime` return Unix
timestamps
([#&#8203;3917](https://redirect.github.com/redis/go-redis/pull/3917))
by [@&#8203;sonnemusk](https://redirect.github.com/sonnemusk); remove a
duplicate example step
([#&#8203;3875](https://redirect.github.com/redis/go-redis/pull/3875))
by
[@&#8203;andy-stark-redis](https://redirect.github.com/andy-stark-redis)

#### 👥 Contributors

We'd like to thank all the contributors who worked on this release!


[@&#8203;andy-stark-redis](https://redirect.github.com/andy-stark-redis),
[@&#8203;CipherN9](https://redirect.github.com/CipherN9),
[@&#8203;cxljs](https://redirect.github.com/cxljs),
[@&#8203;dkindel](https://redirect.github.com/dkindel),
[@&#8203;iabdullah215](https://redirect.github.com/iabdullah215),
[@&#8203;nazarli-shabnam](https://redirect.github.com/nazarli-shabnam),
[@&#8203;ndyakov](https://redirect.github.com/ndyakov),
[@&#8203;ofekshenawa](https://redirect.github.com/ofekshenawa),
[@&#8203;saddamr3e](https://redirect.github.com/saddamr3e),
[@&#8203;Solaris-star](https://redirect.github.com/Solaris-star),
[@&#8203;sonnemusk](https://redirect.github.com/sonnemusk),
[@&#8203;sueun-dev](https://redirect.github.com/sueun-dev)

***

**Full Changelog**:
<redis/go-redis@v9.21.0...v9.22.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [modernc.org/memory](https://gitlab.com/cznic/memory) | `v1.11.0` →
`v1.12.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/modernc.org%2fmemory/v1.12.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/modernc.org%2fmemory/v1.11.0/v1.12.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>cznic/memory (modernc.org/memory)</summary>

###
[`v1.12.0`](https://gitlab.com/cznic/memory/compare/v1.11.0...v1.12.0)

[Compare
Source](https://gitlab.com/cznic/memory/compare/v1.11.0...v1.12.0)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
….0 (9.5) (#7815)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/nikolalohinski/gonja/v2](https://redirect.github.com/nikolalohinski/gonja)
| `v2.8.0` → `v2.9.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fnikolalohinski%2fgonja%2fv2/v2.9.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fnikolalohinski%2fgonja%2fv2/v2.8.0/v2.9.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>nikolalohinski/gonja
(github.com/nikolalohinski/gonja/v2)</summary>

###
[`v2.9.0`](https://redirect.github.com/nikolalohinski/gonja/compare/v2.8.0...v2.9.0)

[Compare
Source](https://redirect.github.com/nikolalohinski/gonja/compare/v2.8.0...v2.9.0)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [modernc.org/libc](https://gitlab.com/cznic/libc) | `v1.74.0` →
`v1.75.3` |
![age](https://developer.mend.io/api/mc/badges/age/go/modernc.org%2flibc/v1.75.3?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/modernc.org%2flibc/v1.74.0/v1.75.3?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>cznic/libc (modernc.org/libc)</summary>

### [`v1.75.3`](https://gitlab.com/cznic/libc/compare/v1.75.2...v1.75.3)

[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.75.2...v1.75.3)

### [`v1.75.2`](https://gitlab.com/cznic/libc/compare/v1.75.1...v1.75.2)

[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.75.1...v1.75.2)

### [`v1.75.1`](https://gitlab.com/cznic/libc/compare/v1.75.0...v1.75.1)

[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.75.0...v1.75.1)

### [`v1.75.0`](https://gitlab.com/cznic/libc/compare/v1.74.4...v1.75.0)

[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.74.4...v1.75.0)

### [`v1.74.4`](https://gitlab.com/cznic/libc/compare/v1.74.3...v1.74.4)

[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.74.3...v1.74.4)

### [`v1.74.3`](https://gitlab.com/cznic/libc/compare/v1.74.2...v1.74.3)

[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.74.2...v1.74.3)

### [`v1.74.2`](https://gitlab.com/cznic/libc/compare/v1.74.1...v1.74.2)

[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.74.1...v1.74.2)

### [`v1.74.1`](https://gitlab.com/cznic/libc/compare/v1.74.0...v1.74.1)

[Compare
Source](https://gitlab.com/cznic/libc/compare/v1.74.0...v1.74.1)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| golang | final | digest | `2005724` → `7caba52` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
#7773)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/go-ldap/ldap/v3](https://redirect.github.com/go-ldap/ldap)
| `v3.4.13` → `v3.4.14` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fgo-ldap%2fldap%2fv3/v3.4.14?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fgo-ldap%2fldap%2fv3/v3.4.13/v3.4.14?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>go-ldap/ldap (github.com/go-ldap/ldap/v3)</summary>

###
[`v3.4.14`](https://redirect.github.com/go-ldap/ldap/releases/tag/v3.4.14)

[Compare
Source](https://redirect.github.com/go-ldap/ldap/compare/v3.4.13...v3.4.14)

I want to thank everyone who contributed in the recents months. Compared
to last year, the number of activities and PRs (including open ones) has
increased dramatically. I would like to thank everyone who contributed
to the project.

**Personal note:** Please keep in mind that this project is not funded
or supported by a large company or similar organization. We work on the
library in our free time after work. I appreciate your support, but
please keep this in mind (including with other open-source projects).

#### What's Changed

- make stop-local-server fails with Docker due to unsupported -t option
by [@&#8203;t2y](https://redirect.github.com/t2y) in
[#&#8203;584](https://redirect.github.com/go-ldap/ldap/pull/584)
- Fix panic on malformed LDAP responses by
[@&#8203;Bahtya](https://redirect.github.com/Bahtya) in
[#&#8203;586](https://redirect.github.com/go-ldap/ldap/pull/586)
- chore(deps): bump github.com/Azure/go-ntlmssp from 0.1.0 to 0.1.1 in
/v3 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;587](https://redirect.github.com/go-ldap/ldap/pull/587)
- Reject unescaped special characters in DN values per RFC 4514 by
[@&#8203;t2y](https://redirect.github.com/t2y) in
[#&#8203;588](https://redirect.github.com/go-ldap/ldap/pull/588)
- v3/control: replace unchecked type asserts in DecodeControl with
comma-ok by
[@&#8203;c-tonneslan](https://redirect.github.com/c-tonneslan) in
[#&#8203;589](https://redirect.github.com/go-ldap/ldap/pull/589)
- fix(conn): parse ldapi:// URLs per RFC 4516 by
[@&#8203;c-tonneslan](https://redirect.github.com/c-tonneslan) in
[#&#8203;590](https://redirect.github.com/go-ldap/ldap/pull/590)
- fix: decode Server Side Sorting controlValue as BER-encoded OCTET
STRING per RFC 2891 by
[@&#8203;ahanwhite](https://redirect.github.com/ahanwhite) in
[#&#8203;593](https://redirect.github.com/go-ldap/ldap/pull/593)
- fix: generate digest-md5 cnonce with crypto/rand by
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#&#8203;594](https://redirect.github.com/go-ldap/ldap/pull/594)
- fix: escape quoted-string metacharacters in digest-md5 response by
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#&#8203;595](https://redirect.github.com/go-ldap/ldap/pull/595)
- fix: escape attribute and matching rule in DecompileFilter by
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#&#8203;596](https://redirect.github.com/go-ldap/ldap/pull/596)
- fix: set Result code when decoding ServerSideSortingResult control by
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#&#8203;597](https://redirect.github.com/go-ldap/ldap/pull/597)
- fix: reject trailing bytes in hex-encoded DN attribute value by
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#&#8203;598](https://redirect.github.com/go-ldap/ldap/pull/598)
- fix: synchronize writes to Conn.err with GetLastError by
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#&#8203;601](https://redirect.github.com/go-ldap/ldap/pull/601)
- unescape quoted-pair sequences in digest-md5 challenge parser by
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#&#8203;600](https://redirect.github.com/go-ldap/ldap/pull/600)
- fix: avoid uint16 overflow in gssapi UnmarshalWrapToken offset by
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#&#8203;602](https://redirect.github.com/go-ldap/ldap/pull/602)
- fix(conn): finish Unbind message context to prevent Close deadlock by
[@&#8203;efd6](https://redirect.github.com/efd6) in
[#&#8203;599](https://redirect.github.com/go-ldap/ldap/pull/599)
- fix: compare multi-valued RDN attributes as a multiset by
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#&#8203;604](https://redirect.github.com/go-ldap/ldap/pull/604)
- fix: respect backslash parity for escaped trailing space in DN value
by
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#&#8203;603](https://redirect.github.com/go-ldap/ldap/pull/603)
- fix: skip empty referral sequence in getReferral by
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#&#8203;610](https://redirect.github.com/go-ldap/ldap/pull/610)
- fix: guard malformed paging control in DecodeControl by
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#&#8203;611](https://redirect.github.com/go-ldap/ldap/pull/611)
- handle linear whitespace in digest-md5 challenge parser by
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#&#8203;607](https://redirect.github.com/go-ldap/ldap/pull/607)
- chore: crypto update by
[@&#8203;CameronJHall](https://redirect.github.com/CameronJHall) in
[#&#8203;613](https://redirect.github.com/go-ldap/ldap/pull/613)
- fix: guard malformed responseValue in PasswordModify by
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#&#8203;614](https://redirect.github.com/go-ldap/ldap/pull/614)
- decode extended responseName by context class by
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
in [#&#8203;605](https://redirect.github.com/go-ldap/ldap/pull/605)
- fix: prevent SearchAsync goroutine leak when context is cancelled
during send by [@&#8203;t2y](https://redirect.github.com/t2y) in
[#&#8203;615](https://redirect.github.com/go-ldap/ldap/pull/615)
- fix: guard nil responseValue when parsing WhoAmI result by
[@&#8203;johnweldon](https://redirect.github.com/johnweldon) in
[#&#8203;617](https://redirect.github.com/go-ldap/ldap/pull/617)
- fix: guard constructed-form attributeType in server-side sort decode
by [@&#8203;johnweldon](https://redirect.github.com/johnweldon) in
[#&#8203;618](https://redirect.github.com/go-ldap/ldap/pull/618)
- chore: Update dependencies by
[@&#8203;cpuschma](https://redirect.github.com/cpuschma) in
[#&#8203;620](https://redirect.github.com/go-ldap/ldap/pull/620)

#### New Contributors

- [@&#8203;Bahtya](https://redirect.github.com/Bahtya) made their first
contribution in
[#&#8203;586](https://redirect.github.com/go-ldap/ldap/pull/586)
- [@&#8203;c-tonneslan](https://redirect.github.com/c-tonneslan) made
their first contribution in
[#&#8203;589](https://redirect.github.com/go-ldap/ldap/pull/589)
- [@&#8203;ahanwhite](https://redirect.github.com/ahanwhite) made their
first contribution in
[#&#8203;593](https://redirect.github.com/go-ldap/ldap/pull/593)
-
[@&#8203;netliomax25-code](https://redirect.github.com/netliomax25-code)
made their first contribution in
[#&#8203;594](https://redirect.github.com/go-ldap/ldap/pull/594)
- [@&#8203;efd6](https://redirect.github.com/efd6) made their first
contribution in
[#&#8203;599](https://redirect.github.com/go-ldap/ldap/pull/599)
- [@&#8203;CameronJHall](https://redirect.github.com/CameronJHall) made
their first contribution in
[#&#8203;613](https://redirect.github.com/go-ldap/ldap/pull/613)

**Full Changelog**:
<go-ldap/ldap@v3.4.13...v3.4.14>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/docker/cli](https://redirect.github.com/docker/cli) |
`v29.6.2+incompatible` → `v29.7.2+incompatible` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fdocker%2fcli/v29.7.2+incompatible?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fdocker%2fcli/v29.6.2+incompatible/v29.7.2+incompatible?slim=true)
|
|
[github.com/docker/go-connections](https://redirect.github.com/docker/go-connections)
| `v0.7.0` → `v0.8.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fdocker%2fgo-connections/v0.8.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fdocker%2fgo-connections/v0.7.0/v0.8.1?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>docker/cli (github.com/docker/cli)</summary>

###
[`v29.7.2+incompatible`](https://redirect.github.com/docker/cli/compare/v29.7.1...v29.7.2)

[Compare
Source](https://redirect.github.com/docker/cli/compare/v29.7.1...v29.7.2)

###
[`v29.7.1+incompatible`](https://redirect.github.com/docker/cli/compare/v29.7.0...v29.7.1)

[Compare
Source](https://redirect.github.com/docker/cli/compare/v29.7.0...v29.7.1)

###
[`v29.7.0+incompatible`](https://redirect.github.com/docker/cli/compare/v29.6.2...v29.7.0)

[Compare
Source](https://redirect.github.com/docker/cli/compare/v29.6.2...v29.7.0)

</details>

<details>
<summary>docker/go-connections
(github.com/docker/go-connections)</summary>

###
[`v0.8.1`](https://redirect.github.com/docker/go-connections/compare/v0.8.0...v0.8.1)

[Compare
Source](https://redirect.github.com/docker/go-connections/compare/v0.8.0...v0.8.1)

###
[`v0.8.0`](https://redirect.github.com/docker/go-connections/compare/v0.7.0...v0.8.0)

[Compare
Source](https://redirect.github.com/docker/go-connections/compare/v0.7.0...v0.8.0)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…7805)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/gocsaf/csaf/v3](https://redirect.github.com/gocsaf/csaf) |
`v3.5.1` → `v3.6.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fgocsaf%2fcsaf%2fv3/v3.6.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fgocsaf%2fcsaf%2fv3/v3.5.1/v3.6.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>gocsaf/csaf (github.com/gocsaf/csaf/v3)</summary>

###
[`v3.6.0`](https://redirect.github.com/gocsaf/csaf/releases/tag/v3.6.0)

[Compare
Source](https://redirect.github.com/gocsaf/csaf/compare/v3.5.1...v3.6.0)

This release was focused on extending the functionality while
maintaining
backwards compatibility. This is why we only changed the minor version.

If you observe anything that has broken the API, please open an issue.

Most of these changes were made to support the [CSAF online
checker](https://redirect.github.com/csaf-tools/provider-online-check).
Issues found during the development of the online checker were also
fixed.

##### Highlights

- Uploader: add option to call external signing tool:
[#&#8203;738](https://redirect.github.com/gocsaf/csaf/pull/738)
- Optimization of memory usage:
- Checker close http connections:
[#&#8203;737](https://redirect.github.com/gocsaf/csaf/pull/737)
- Prevent large buffers used in dowloading:
[#&#8203;745](https://redirect.github.com/gocsaf/csaf/pull/745)
- (Experimental) streaming loading ROLIE feeds:
[#&#8203;746](https://redirect.github.com/gocsaf/csaf/pull/746)
- Allow cancellation of API calls which use http connections internally:
[#&#8203;740](https://redirect.github.com/gocsaf/csaf/pull/740)
- New flags for more granular control:
- Add pre\_flight option to csaf\_checker that logs pmdURL on successful
PMD check:
[#&#8203;729](https://redirect.github.com/gocsaf/csaf/pull/729)
- Add client\_timeout flag in csaf\_checker, csaf\_downloader and
csaf\_aggregator:
[#&#8203;730](https://redirect.github.com/gocsaf/csaf/pull/730)
- Checker: Implement a requirement evaluation trail to make more
transparent why domains have passed or failed:
[#&#8203;741](https://redirect.github.com/gocsaf/csaf/pull/741)
- More information logged:
- Log the used PMD found by the loader:
[#&#8203;725](https://redirect.github.com/gocsaf/csaf/pull/725)
- Add log for redundant PMDs in security.txt:
[#&#8203;742](https://redirect.github.com/gocsaf/csaf/pull/742)
- Adjust ROLIE Info messages to be more understandable:
[#&#8203;732](https://redirect.github.com/gocsaf/csaf/pull/732)

##### Other Changes

- Drop null entries when loading a ROLIE feed by
[@&#8203;arpitjain099](https://redirect.github.com/arpitjain099) in
[#&#8203;744](https://redirect.github.com/gocsaf/csaf/pull/744)
- Stop checking if there is no valid PMD:
[#&#8203;731](https://redirect.github.com/gocsaf/csaf/pull/731)
- Add UTF8 validation for files in checker, downloader and validator:
[#&#8203;736](https://redirect.github.com/gocsaf/csaf/pull/736)

##### New Contributors

- [@&#8203;arpitjain099](https://redirect.github.com/arpitjain099) made
a first contribution in
[#&#8203;744](https://redirect.github.com/gocsaf/csaf/pull/744)
  Thank you!

**Full Changelog**:
<gocsaf/csaf@v3.5.1...v3.6>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…24.1 (9.5) (#7816)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/prometheus/client_golang](https://redirect.github.com/prometheus/client_golang)
| `v1.23.2` → `v1.24.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fprometheus%2fclient_golang/v1.24.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fprometheus%2fclient_golang/v1.23.2/v1.24.1?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>prometheus/client_golang
(github.com/prometheus/client_golang)</summary>

###
[`v1.24.1`](https://redirect.github.com/prometheus/client_golang/releases/tag/v1.24.1):
/ 2026-07-23

[Compare
Source](https://redirect.github.com/prometheus/client_golang/compare/v1.24.0...v1.24.1)

Small bugfix release for promhttp.

#### What's Changed

\[BUGFIX] promhttp: Fix panic on requests with nil URL.
[#&#8203;2065](https://redirect.github.com/prometheus/client_golang/issues/2065)

**Full Changelog**:
<prometheus/client_golang@v1.24.0...v1.24.1>

###
[`v1.24.0`](https://redirect.github.com/prometheus/client_golang/releases/tag/v1.24.0):
- 2026-07-20

[Compare
Source](https://redirect.github.com/prometheus/client_golang/compare/v1.23.2...v1.24.0)

##### Changes

- \[CHANGE] Minimum required Go version is now 1.25, only the two latest
Go versions (1.25 and 1.26) are supported from now on.
[#&#8203;1862](https://redirect.github.com/prometheus/client_golang/issues/1862)
- \[CHANGE] prometheus: Name validation now always uses the UTF-8 scheme
instead of the deprecated `model.NameValidationScheme` global. Default
behavior is unchanged; code that set `NameValidationScheme =
LegacyValidation` no longer gets legacy enforcement at metric, label,
and push-grouping construction.
[#&#8203;2051](https://redirect.github.com/prometheus/client_golang/issues/2051)
- \[CHANGE] api/prometheus/v1: Support matchers (`matches[]` parameter)
in `Rules` method (`Rules(ctx context.Context, matches []string)
(RulesResult, error)`).
[#&#8203;1843](https://redirect.github.com/prometheus/client_golang/issues/1843)
- \[CHANGE] api/prometheus/v1: Refactor `LabelNames` method to return
`model.LabelNames` instead of `[]string` for consistency across the API.
[#&#8203;1850](https://redirect.github.com/prometheus/client_golang/issues/1850)
- \[CHANGE] exp/api/remote: Simplify `Store` interface, rename `Handler`
to `WriteHandler`, and encapsulate write response handling.
[#&#8203;1855](https://redirect.github.com/prometheus/client_golang/issues/1855)
- \[FEATURE] prometheus: Add new Go 1.26 runtime metrics
(`/sched/goroutines-created:goroutines`,
`/sched/goroutines/not-in-go:goroutines`,
`/sched/goroutines/runnable:goroutines`,
`/sched/goroutines/running:goroutines`,
`/sched/goroutines/waiting:goroutines`, `/sched/threads/total:threads`).
[#&#8203;1942](https://redirect.github.com/prometheus/client_golang/issues/1942)
- \[FEATURE] prometheus: Add `WithUnit(unit string)` option and explicit
OpenMetrics unit support in `CounterOpts`, `GaugeOpts`, `SummaryOpts`,
and `HistogramOpts`.
[#&#8203;1392](https://redirect.github.com/prometheus/client_golang/issues/1392)
- \[FEATURE] prometheus: Expose descriptor construction error through
public `Err()` method on `Desc`.
[#&#8203;1902](https://redirect.github.com/prometheus/client_golang/issues/1902)
- \[FEATURE] promhttp: Add opt-in `HandlerOpts.CoalesceGather` to
deduplicate concurrent `Gather` calls so overlapping scrapes share one
collection cycle, preventing goroutine pile-up when the scrape rate
outpaces collection time.
[#&#8203;1969](https://redirect.github.com/prometheus/client_golang/issues/1969)
- \[FEATURE] promhttp: HTTP handlers created by `promhttp` package now
support metrics filtering by providing one or more `name[]` query
parameters. The default behavior when none are provided remains the
same, returning all metrics.
[#&#8203;1925](https://redirect.github.com/prometheus/client_golang/issues/1925)
- \[FEATURE] api/prometheus/v1: Add query formatting endpoint support
(`/format_query`) and `FormatQuery(ctx context.Context, query string)
(string, error)` method.
[#&#8203;1846](https://redirect.github.com/prometheus/client_golang/issues/1846),
[#&#8203;1856](https://redirect.github.com/prometheus/client_golang/issues/1856)
- \[FEATURE] api/prometheus/v1: Add support for `/status/tsdb/blocks`
endpoint via `TSDBBlocks(ctx context.Context) ([]TSDBBlock, error)`
method.
[#&#8203;1896](https://redirect.github.com/prometheus/client_golang/issues/1896)
- \[FEATURE] exp/api/remote: Export `BackoffConfig` to allow
customization when using `WithAPIBackoff`.
[#&#8203;1895](https://redirect.github.com/prometheus/client_golang/issues/1895)
- \[FEATURE] exp/api/remote: Add `RetryCallBack` to allow custom logging
or handling on retry attempts in the remote write client.
[#&#8203;1888](https://redirect.github.com/prometheus/client_golang/issues/1888),
[#&#8203;1890](https://redirect.github.com/prometheus/client_golang/issues/1890)
- \[ENHANCEMENT] prometheus/collectors/version: Allow specifying custom
labels when registering the version collector.
[#&#8203;1860](https://redirect.github.com/prometheus/client_golang/issues/1860)
- \[ENHANCEMENT] api: Use cloned `http.DefaultTransport` when
constructing default HTTP clients to prevent accidental mutations of
shared global transport state.
[#&#8203;1885](https://redirect.github.com/prometheus/client_golang/issues/1885)
- \[BUGFIX] prometheus: Recover from collector panics during `Gather()`
and return an error instead of crashing the process.
[#&#8203;1961](https://redirect.github.com/prometheus/client_golang/issues/1961)
- \[BUGFIX] prometheus: Fix `cpu-seconds` unit suffix handling for
metric `go_cpu_classes_gc_mark_assist_cpu_seconds`.
[#&#8203;1991](https://redirect.github.com/prometheus/client_golang/issues/1991)
- \[BUGFIX] promhttp: `InstrumentHandlerDuration` and
`InstrumentHandlerCounter` no longer panic when given an
observer/counter that does not implement
`ExemplarObserver`/`ExemplarAdder` (e.g. a `SummaryVec`). The exemplar
is dropped and the value is recorded via the plain `Observe`/`Add` path,
matching the safe-cast already used by
`Timer.ObserveDurationWithExemplar`.
[#&#8203;2005](https://redirect.github.com/prometheus/client_golang/issues/2005)
- \[BUGFIX] api/prometheus/v1: Fall back to `GET` requests when `POST`
requests return `403 Forbidden` or method not allowed.
[#&#8203;2030](https://redirect.github.com/prometheus/client_golang/issues/2030)
- \[BUGFIX] api: Respect context cancellation inside `httpClient.Do`.
[#&#8203;1971](https://redirect.github.com/prometheus/client_golang/issues/1971)
- \[BUGFIX] exp/api/remote: Fix compression buffer pooling where
compressed buffers were released prematurely, causing corrupted
remote-write payloads.
[#&#8203;1889](https://redirect.github.com/prometheus/client_golang/issues/1889)
- \[BUGFIX] exp/api/remote: Reject malformed snappy payloads declaring
huge decoded sizes. Enforce a 32MB decoded-size limit to prevent OOM
from oversized remote-write requests.
[#&#8203;1917](https://redirect.github.com/prometheus/client_golang/issues/1917)
- \[BUGFIX] exp/api/remote: Ensure remote write v2 headers cannot be
returned on v1 requests.
[#&#8203;1927](https://redirect.github.com/prometheus/client_golang/issues/1927)

<details>
<summary> All commits </summary>

- build(deps): bump github.com/prometheus/procfs from 0.16.1 to 0.17.0
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1839](https://redirect.github.com/prometheus/client_golang/pull/1839)
- build(deps): bump golang.org/x/sys from 0.33.0 to 0.34.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1838](https://redirect.github.com/prometheus/client_golang/pull/1838)
- prometheus/collectors: use godoc link for runtime/metrics supported
metrics by [@&#8203;xieyuschen](https://redirect.github.com/xieyuschen)
in
[#&#8203;1844](https://redirect.github.com/prometheus/client_golang/pull/1844)
- Fix doc typo by [@&#8203;torrca](https://redirect.github.com/torrca)
in
[#&#8203;1849](https://redirect.github.com/prometheus/client_golang/pull/1849)
- Merge release-1.23 into main by
[@&#8203;vesari](https://redirect.github.com/vesari) in
[#&#8203;1851](https://redirect.github.com/prometheus/client_golang/pull/1851)
- build(deps): bump github/codeql-action from 3.29.2 to 3.29.5 in the
github-actions group by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1852](https://redirect.github.com/prometheus/client_golang/pull/1852)
- Refactor LabelNames to return model.LabelNames type for consistency by
[@&#8203;yshngg](https://redirect.github.com/yshngg) in
[#&#8203;1850](https://redirect.github.com/prometheus/client_golang/pull/1850)
- remote: simplified Store interface; renamed Handler to WriteHandler by
[@&#8203;bwplotka](https://redirect.github.com/bwplotka) in
[#&#8203;1855](https://redirect.github.com/prometheus/client_golang/pull/1855)
- feat(api/prometheus): add format\_query endpoint for query formatting
by [@&#8203;yshngg](https://redirect.github.com/yshngg) in
[#&#8203;1846](https://redirect.github.com/prometheus/client_golang/pull/1846)
- feat(api): add FormatQuery method to Prometheus v1 API by
[@&#8203;yshngg](https://redirect.github.com/yshngg) in
[#&#8203;1856](https://redirect.github.com/prometheus/client_golang/pull/1856)
- Support matchers in rules API by
[@&#8203;jotak](https://redirect.github.com/jotak) in
[#&#8203;1843](https://redirect.github.com/prometheus/client_golang/pull/1843)
- Use prometheus/common.expfmt.NewTextParser by
[@&#8203;aknuds1](https://redirect.github.com/aknuds1) in
[#&#8203;1859](https://redirect.github.com/prometheus/client_golang/pull/1859)
- Merge release-1.23 into main by
[@&#8203;aknuds1](https://redirect.github.com/aknuds1) in
[#&#8203;1861](https://redirect.github.com/prometheus/client_golang/pull/1861)
- chore: Drop support for \<go1.22 by
[@&#8203;mrueg](https://redirect.github.com/mrueg) in
[#&#8203;1862](https://redirect.github.com/prometheus/client_golang/pull/1862)
- collectors/version: Allow custom additional labels by
[@&#8203;mrueg](https://redirect.github.com/mrueg) in
[#&#8203;1860](https://redirect.github.com/prometheus/client_golang/pull/1860)
- build(deps): bump github.com/prometheus/common from 0.65.0 to 0.66.0
by [@&#8203;ywwg](https://redirect.github.com/ywwg) in
[#&#8203;1865](https://redirect.github.com/prometheus/client_golang/pull/1865)
- Sync release-1.23 into main by
[@&#8203;aknuds1](https://redirect.github.com/aknuds1) in
[#&#8203;1868](https://redirect.github.com/prometheus/client_golang/pull/1868)
- Sync main with release-1.23 by
[@&#8203;aknuds1](https://redirect.github.com/aknuds1) in
[#&#8203;1871](https://redirect.github.com/prometheus/client_golang/pull/1871)
- chore: clean up golangci-lint configuration by
[@&#8203;mmorel-35](https://redirect.github.com/mmorel-35) in
[#&#8203;1802](https://redirect.github.com/prometheus/client_golang/pull/1802)
- build(deps): bump google.golang.org/protobuf from 1.36.8 to 1.36.9 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1880](https://redirect.github.com/prometheus/client_golang/pull/1880)
- build(deps): bump google.golang.org/protobuf from 1.36.6 to 1.36.9 in
/exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1882](https://redirect.github.com/prometheus/client_golang/pull/1882)
- build(deps): bump github.com/prometheus/common from 0.65.0 to 0.66.1
in /exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1883](https://redirect.github.com/prometheus/client_golang/pull/1883)
- build(deps): bump the github-actions group with 4 updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1881](https://redirect.github.com/prometheus/client_golang/pull/1881)
- Fix typo in remote api err msg by
[@&#8203;SungJin1212](https://redirect.github.com/SungJin1212) in
[#&#8203;1878](https://redirect.github.com/prometheus/client_golang/pull/1878)
- chore: Update metrics for new Go version by
[@&#8203;github-actions](https://redirect.github.com/github-actions)\[bot]
in
[#&#8203;1864](https://redirect.github.com/prometheus/client_golang/pull/1864)
- Add RetryCallBack to remote\_api.go by
[@&#8203;pipiland2612](https://redirect.github.com/pipiland2612) in
[#&#8203;1888](https://redirect.github.com/prometheus/client_golang/pull/1888)
- bug(remote\_write): Fix compression buffer pooling by
[@&#8203;fpetkovski](https://redirect.github.com/fpetkovski) in
[#&#8203;1889](https://redirect.github.com/prometheus/client_golang/pull/1889)
- Change RetryCallBack initialized by
[@&#8203;pipiland2612](https://redirect.github.com/pipiland2612) in
[#&#8203;1890](https://redirect.github.com/prometheus/client_golang/pull/1890)
- Fix CI bug by
[@&#8203;pipiland2612](https://redirect.github.com/pipiland2612) in
[#&#8203;1892](https://redirect.github.com/prometheus/client_golang/pull/1892)
- Use cloned http.DefaultTransport. issue-1857 by
[@&#8203;karthikkondapally](https://redirect.github.com/karthikkondapally)
in
[#&#8203;1885](https://redirect.github.com/prometheus/client_golang/pull/1885)
- Public backoff config to allow usage of WithAPIBackoff by
[@&#8203;pipiland2612](https://redirect.github.com/pipiland2612) in
[#&#8203;1895](https://redirect.github.com/prometheus/client_golang/pull/1895)
- Clarify exp library stability by
[@&#8203;pipiland2612](https://redirect.github.com/pipiland2612) in
[#&#8203;1894](https://redirect.github.com/prometheus/client_golang/pull/1894)
- feat: add support for `/status/tsdb/blocks` endpoint by
[@&#8203;tjhop](https://redirect.github.com/tjhop) in
[#&#8203;1896](https://redirect.github.com/prometheus/client_golang/pull/1896)
- minor refactor of replaceInvalidRune() in bridge.go by
[@&#8203;karthikkondapally](https://redirect.github.com/karthikkondapally)
in
[#&#8203;1897](https://redirect.github.com/prometheus/client_golang/pull/1897)
- build(deps): bump github.com/prometheus/procfs from 0.17.0 to 0.19.2
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1903](https://redirect.github.com/prometheus/client_golang/pull/1903)
- build(deps): bump github.com/klauspost/compress from 1.18.0 to 1.18.1
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1906](https://redirect.github.com/prometheus/client_golang/pull/1906)
- build(deps): bump golang.org/x/sys from 0.35.0 to 0.37.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1904](https://redirect.github.com/prometheus/client_golang/pull/1904)
- build(deps): bump github.com/prometheus/common from 0.66.1 to 0.67.2
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1907](https://redirect.github.com/prometheus/client_golang/pull/1907)
- build(deps): bump github.com/klauspost/compress from 1.18.0 to 1.18.1
in /exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1911](https://redirect.github.com/prometheus/client_golang/pull/1911)
- build(deps): bump google.golang.org/protobuf from 1.36.9 to 1.36.10 in
/exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1909](https://redirect.github.com/prometheus/client_golang/pull/1909)
- build(deps): bump github.com/prometheus/common from 0.66.1 to 0.67.2
in /exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1910](https://redirect.github.com/prometheus/client_golang/pull/1910)
- build(deps): bump the github-actions group with 2 updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1908](https://redirect.github.com/prometheus/client_golang/pull/1908)
- chore(ci): Add CRLF detection and fix targets to prevent CRLF
contamination by
[@&#8203;kakkoyun](https://redirect.github.com/kakkoyun) in
[#&#8203;1898](https://redirect.github.com/prometheus/client_golang/pull/1898)
- chore(ci): Use stable names for CI steps by
[@&#8203;kakkoyun](https://redirect.github.com/kakkoyun) in
[#&#8203;1914](https://redirect.github.com/prometheus/client_golang/pull/1914)
- build(deps): bump github.com/klauspost/compress from 1.18.1 to 1.18.2
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1920](https://redirect.github.com/prometheus/client_golang/pull/1920)
- build(deps): bump github.com/prometheus/common from 0.67.2 to 0.67.4
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1921](https://redirect.github.com/prometheus/client_golang/pull/1921)
- build(deps): bump golang.org/x/sys from 0.37.0 to 0.38.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1922](https://redirect.github.com/prometheus/client_golang/pull/1922)
- build(deps): bump github.com/prometheus/common from 0.67.2 to 0.67.4
in /exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1923](https://redirect.github.com/prometheus/client_golang/pull/1923)
- build(deps): bump github.com/klauspost/compress from 1.18.1 to 1.18.2
in /exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1924](https://redirect.github.com/prometheus/client_golang/pull/1924)
- build(deps): bump the github-actions group with 4 updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1919](https://redirect.github.com/prometheus/client_golang/pull/1919)
- feat: expose Desc error through public Err() method by
[@&#8203;duricanikolic](https://redirect.github.com/duricanikolic) in
[#&#8203;1902](https://redirect.github.com/prometheus/client_golang/pull/1902)
- Allow `/metrics` handler output filtering via `name[]` query param by
[@&#8203;colega](https://redirect.github.com/colega) in
[#&#8203;1925](https://redirect.github.com/prometheus/client_golang/pull/1925)
- Prevent OOM from malformed snappy payloads by validating decoded
length by [@&#8203;makasim](https://redirect.github.com/makasim) in
[#&#8203;1917](https://redirect.github.com/prometheus/client_golang/pull/1917)
- Ensure remote write v2 headers cannot be returned on v1 requests by
[@&#8203;kgeckhart](https://redirect.github.com/kgeckhart) in
[#&#8203;1927](https://redirect.github.com/prometheus/client_golang/pull/1927)
- build(deps): bump google.golang.org/protobuf from 1.36.10 to 1.36.11
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1932](https://redirect.github.com/prometheus/client_golang/pull/1932)
- build(deps): bump golang.org/x/sys from 0.38.0 to 0.39.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1933](https://redirect.github.com/prometheus/client_golang/pull/1933)
- build(deps): bump google.golang.org/protobuf from 1.36.10 to 1.36.11
in /exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1935](https://redirect.github.com/prometheus/client_golang/pull/1935)
- build(deps): bump the github-actions group with 5 updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1934](https://redirect.github.com/prometheus/client_golang/pull/1934)
- promhttp/zstd: add unit tests for zstd writer registration by
[@&#8203;90ashish](https://redirect.github.com/90ashish) in
[#&#8203;1929](https://redirect.github.com/prometheus/client_golang/pull/1929)
- feat(collector): add Go 1.26 new runtime metrics by
[@&#8203;kakkoyun](https://redirect.github.com/kakkoyun) in
[#&#8203;1942](https://redirect.github.com/prometheus/client_golang/pull/1942)
- build(deps): bump github.com/prometheus/common from 0.67.4 to 0.67.5
in /exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1948](https://redirect.github.com/prometheus/client_golang/pull/1948)
- build(deps): bump the github-actions group with 4 updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1946](https://redirect.github.com/prometheus/client_golang/pull/1946)
- build(deps): bump github.com/klauspost/compress from 1.18.2 to 1.18.3
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1944](https://redirect.github.com/prometheus/client_golang/pull/1944)
- build(deps): bump golang.org/x/sys from 0.39.0 to 0.40.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1945](https://redirect.github.com/prometheus/client_golang/pull/1945)
- build(deps): bump github.com/klauspost/compress from 1.18.2 to 1.18.3
in /exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1947](https://redirect.github.com/prometheus/client_golang/pull/1947)
- chore(test): bump 1.25, tests with synctest and check not panic by
[@&#8203;manute](https://redirect.github.com/manute) in
[#&#8203;1950](https://redirect.github.com/prometheus/client_golang/pull/1950)
- build(deps): bump github.com/prometheus/procfs from 0.19.2 to 0.20.1
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1954](https://redirect.github.com/prometheus/client_golang/pull/1954)
- build(deps): bump golang.org/x/sys from 0.40.0 to 0.41.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1957](https://redirect.github.com/prometheus/client_golang/pull/1957)
- build(deps): bump github.com/klauspost/compress from 1.18.3 to 1.18.4
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1955](https://redirect.github.com/prometheus/client_golang/pull/1955)
- build(deps): bump go.opentelemetry.io/otel/sdk from 1.34.0 to 1.40.0
in /tutorials/whatsup by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1959](https://redirect.github.com/prometheus/client_golang/pull/1959)
- build(deps): bump github.com/prometheus/common from 0.67.4 to 0.67.5
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1956](https://redirect.github.com/prometheus/client_golang/pull/1956)
- build(deps): bump the github-actions group with 2 updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1958](https://redirect.github.com/prometheus/client_golang/pull/1958)
- chore(collectors/go): generate the tests after new metric by
[@&#8203;kakkoyun](https://redirect.github.com/kakkoyun) in
[#&#8203;1962](https://redirect.github.com/prometheus/client_golang/pull/1962)
- Remove Arthur from the list of maintainers by
[@&#8203;ArthurSens](https://redirect.github.com/ArthurSens) in
[#&#8203;1964](https://redirect.github.com/prometheus/client_golang/pull/1964)
- build(deps): bump google.golang.org/grpc from 1.69.4 to 1.79.3 in
/tutorials/whatsup by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1965](https://redirect.github.com/prometheus/client_golang/pull/1965)
- fix: recover from collector panic and return error in Gather by
[@&#8203;Saflaski](https://redirect.github.com/Saflaski) in
[#&#8203;1961](https://redirect.github.com/prometheus/client_golang/pull/1961)
- prometheus: clarify MetricVec delete semantics in godoc by
[@&#8203;Retr0-XD](https://redirect.github.com/Retr0-XD) in
[#&#8203;1967](https://redirect.github.com/prometheus/client_golang/pull/1967)
- build(deps): bump golang.org/x/sys from 0.41.0 to 0.42.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1973](https://redirect.github.com/prometheus/client_golang/pull/1973)
- build(deps): bump github.com/klauspost/compress from 1.18.4 to 1.18.5
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1974](https://redirect.github.com/prometheus/client_golang/pull/1974)
- build(deps): bump github.com/klauspost/compress from 1.18.4 to 1.18.5
in /exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1976](https://redirect.github.com/prometheus/client_golang/pull/1976)
- Optionally add OM unit by
[@&#8203;vesari](https://redirect.github.com/vesari) in
[#&#8203;1392](https://redirect.github.com/prometheus/client_golang/pull/1392)
- fix: respect context cancellation in httpClient.Do by
[@&#8203;pedrampdd](https://redirect.github.com/pedrampdd) in
[#&#8203;1971](https://redirect.github.com/prometheus/client_golang/pull/1971)
- build(deps): bump go.opentelemetry.io/otel/sdk from 1.40.0 to 1.43.0
in /tutorials/whatsup by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1978](https://redirect.github.com/prometheus/client_golang/pull/1978)
- Synchronize common files from prometheus/prometheus by
[@&#8203;prombot](https://redirect.github.com/prombot) in
[#&#8203;1977](https://redirect.github.com/prometheus/client_golang/pull/1977)
- Synchronize common files from prometheus/prometheus by
[@&#8203;prombot](https://redirect.github.com/prombot) in
[#&#8203;1980](https://redirect.github.com/prometheus/client_golang/pull/1980)
- examples: add native histogram usage example by
[@&#8203;thegdsks](https://redirect.github.com/thegdsks) in
[#&#8203;1981](https://redirect.github.com/prometheus/client_golang/pull/1981)
- chore(ci): add macOS, Windows and arm64 test runners by
[@&#8203;kakkoyun](https://redirect.github.com/kakkoyun) in
[#&#8203;1968](https://redirect.github.com/prometheus/client_golang/pull/1968)
- prometheus: honor PidFn on windows and darwin by
[@&#8203;Retr0-XD](https://redirect.github.com/Retr0-XD) in
[#&#8203;1966](https://redirect.github.com/prometheus/client_golang/pull/1966)
- Synchronize common files from prometheus/prometheus by
[@&#8203;prombot](https://redirect.github.com/prombot) in
[#&#8203;1984](https://redirect.github.com/prometheus/client_golang/pull/1984)
- Synchronize common files from prometheus/prometheus by
[@&#8203;prombot](https://redirect.github.com/prombot) in
[#&#8203;1985](https://redirect.github.com/prometheus/client_golang/pull/1985)
- promhttp: implement WithXFromContext in terms of WithXFromRequest by
[@&#8203;tie](https://redirect.github.com/tie) in
[#&#8203;1863](https://redirect.github.com/prometheus/client_golang/pull/1863)
- Synchronize common files from prometheus/prometheus by
[@&#8203;prombot](https://redirect.github.com/prombot) in
[#&#8203;1988](https://redirect.github.com/prometheus/client_golang/pull/1988)
- Fix bug unit cpu-seconds not a suffix of metric
go\_cpu\_classes\_gc\_mark\_assist\_cpu\_seconds by
[@&#8203;vesari](https://redirect.github.com/vesari) in
[#&#8203;1991](https://redirect.github.com/prometheus/client_golang/pull/1991)
- build(deps): bump golang.org/x/sys from 0.42.0 to 0.43.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1993](https://redirect.github.com/prometheus/client_golang/pull/1993)
- build(deps): bump github.com/klauspost/compress from 1.18.5 to 1.18.6
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1992](https://redirect.github.com/prometheus/client_golang/pull/1992)
- build(deps): bump github.com/klauspost/compress from 1.18.5 to 1.18.6
in /exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1995](https://redirect.github.com/prometheus/client_golang/pull/1995)
- exp/api/remote: limit request body size in SnappyDecodeMiddleware by
[@&#8203;roidelapluie](https://redirect.github.com/roidelapluie) in
[#&#8203;1996](https://redirect.github.com/prometheus/client_golang/pull/1996)
- Synchronize common files from prometheus/prometheus by
[@&#8203;prombot](https://redirect.github.com/prombot) in
[#&#8203;2001](https://redirect.github.com/prometheus/client_golang/pull/2001)
- build(deps): bump the github-actions group across 1 directory with 4
updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1994](https://redirect.github.com/prometheus/client_golang/pull/1994)
- ci(update-go-versions): declare permissions for the monthly chore PR
by [@&#8203;arpitjain099](https://redirect.github.com/arpitjain099) in
[#&#8203;2003](https://redirect.github.com/prometheus/client_golang/pull/2003)
- docs: fix godoc indentation and typos in timer.go and wrap.go by
[@&#8203;immanuwell](https://redirect.github.com/immanuwell) in
[#&#8203;2009](https://redirect.github.com/prometheus/client_golang/pull/2009)
- ci: harden actions/checkout with persist-credentials: false by
[@&#8203;roidelapluie](https://redirect.github.com/roidelapluie) in
[#&#8203;2011](https://redirect.github.com/prometheus/client_golang/pull/2011)
- fix(registry): prevent file descriptor leak in WriteToTextfile by
[@&#8203;ProjectMutilation](https://redirect.github.com/ProjectMutilation)
in
[#&#8203;2010](https://redirect.github.com/prometheus/client_golang/pull/2010)
- Synchronize common files from prometheus/prometheus by
[@&#8203;prombot](https://redirect.github.com/prombot) in
[#&#8203;2008](https://redirect.github.com/prometheus/client_golang/pull/2008)
- promhttp: add regression test for concurrent map writes
([#&#8203;1274](https://redirect.github.com/prometheus/client_golang/issues/1274))
by [@&#8203;pedrampdd](https://redirect.github.com/pedrampdd) in
[#&#8203;2000](https://redirect.github.com/prometheus/client_golang/pull/2000)
- build(deps): bump github.com/prometheus/common from
0.67.6-0.20260224092343-e4c38a0aea47 to 0.68.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2015](https://redirect.github.com/prometheus/client_golang/pull/2015)
- build(deps): bump the github-actions group with 2 updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2016](https://redirect.github.com/prometheus/client_golang/pull/2016)
- build(deps): bump golang.org/x/sys from 0.43.0 to 0.45.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2014](https://redirect.github.com/prometheus/client_golang/pull/2014)
- build(deps): bump github.com/prometheus/common from 0.67.5 to 0.68.0
in /exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2017](https://redirect.github.com/prometheus/client_golang/pull/2017)
- promhttp: fix grammar in exemplar option doc comments by
[@&#8203;s3onghyun](https://redirect.github.com/s3onghyun) in
[#&#8203;2023](https://redirect.github.com/prometheus/client_golang/pull/2023)
- fix: use keyed fields in SamplePair struct literals in api\_test.go by
[@&#8203;immanuwell](https://redirect.github.com/immanuwell) in
[#&#8203;2012](https://redirect.github.com/prometheus/client_golang/pull/2012)
- refactor: replace interface{} with any (Go 1.18+) by
[@&#8203;MD-Mushfiqur123](https://redirect.github.com/MD-Mushfiqur123)
in
[#&#8203;2021](https://redirect.github.com/prometheus/client_golang/pull/2021)
- Synchronize common files from prometheus/prometheus by
[@&#8203;prombot](https://redirect.github.com/prombot) in
[#&#8203;2013](https://redirect.github.com/prometheus/client_golang/pull/2013)
- build(deps): bump github.com/prometheus/common from 0.68.0 to 0.69.0
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2025](https://redirect.github.com/prometheus/client_golang/pull/2025)
- build(deps): bump github.com/prometheus/common from 0.68.0 to 0.69.0
in /exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2027](https://redirect.github.com/prometheus/client_golang/pull/2027)
- build(deps): bump golang.org/x/sys from 0.45.0 to 0.46.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2026](https://redirect.github.com/prometheus/client_golang/pull/2026)
- Synchronize common files from prometheus/prometheus by
[@&#8203;prombot](https://redirect.github.com/prombot) in
[#&#8203;2028](https://redirect.github.com/prometheus/client_golang/pull/2028)
- build(deps): bump github.com/prometheus/procfs from 0.20.1 to 0.21.0
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2033](https://redirect.github.com/prometheus/client_golang/pull/2033)
- build(deps): bump github.com/klauspost/compress from 1.18.6 to 1.18.7
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2036](https://redirect.github.com/prometheus/client_golang/pull/2036)
- build(deps): bump github.com/prometheus/procfs from 0.21.0 to 0.21.1
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2035](https://redirect.github.com/prometheus/client_golang/pull/2035)
- build(deps): bump github.com/klauspost/compress from 1.18.6 to 1.18.7
in /exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2038](https://redirect.github.com/prometheus/client_golang/pull/2038)
- Synchronize common files from prometheus/prometheus by
[@&#8203;prombot](https://redirect.github.com/prombot) in
[#&#8203;2041](https://redirect.github.com/prometheus/client_golang/pull/2041)
- fix(api): fall back to GET on forbidden POSTs by
[@&#8203;immanuwell](https://redirect.github.com/immanuwell) in
[#&#8203;2030](https://redirect.github.com/prometheus/client_golang/pull/2030)
- build(deps): bump golang.org/x/net from 0.48.0 to 0.55.0 in
/tutorials/whatsup by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2042](https://redirect.github.com/prometheus/client_golang/pull/2042)
- build(deps): bump the github-actions group across 1 directory with 5
updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2043](https://redirect.github.com/prometheus/client_golang/pull/2043)
- chores: remove example Dockerfile and container\_description.yaml by
[@&#8203;bwplotka](https://redirect.github.com/bwplotka) in
[#&#8203;2044](https://redirect.github.com/prometheus/client_golang/pull/2044)
- Update dependabot config by
[@&#8203;SuperQ](https://redirect.github.com/SuperQ) in
[#&#8203;2046](https://redirect.github.com/prometheus/client_golang/pull/2046)
- build(deps): bump github.com/klauspost/compress from 1.18.7 to 1.19.0
in /exp by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2048](https://redirect.github.com/prometheus/client_golang/pull/2048)
- build(deps): bump github.com/klauspost/compress from 1.18.7 to 1.19.0
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2047](https://redirect.github.com/prometheus/client_golang/pull/2047)
- promhttp: don't panic when instrumenting with non-exemplar observers
by [@&#8203;spor3006](https://redirect.github.com/spor3006) in
[#&#8203;2005](https://redirect.github.com/prometheus/client_golang/pull/2005)
- Replace deprecated model.NameValidationScheme with explicit
UTF8Validation by
[@&#8203;kakkoyun](https://redirect.github.com/kakkoyun) in
[#&#8203;2051](https://redirect.github.com/prometheus/client_golang/pull/2051)
- test: fix two flaky tests (darwin start\_time regex, memstats
HeapReleased drift) by
[@&#8203;kakkoyun](https://redirect.github.com/kakkoyun) in
[#&#8203;2050](https://redirect.github.com/prometheus/client_golang/pull/2050)
- fix: correct typos in comments and test error messages by
[@&#8203;maxtaran2010](https://redirect.github.com/maxtaran2010) in
[#&#8203;2049](https://redirect.github.com/prometheus/client_golang/pull/2049)
- examples: improve simple main.go example by
[@&#8203;dhanudhanushree](https://redirect.github.com/dhanudhanushree)
in
[#&#8203;1999](https://redirect.github.com/prometheus/client_golang/pull/1999)
- Synchronize common files from prometheus/prometheus by
[@&#8203;prombot](https://redirect.github.com/prombot) in
[#&#8203;2055](https://redirect.github.com/prometheus/client_golang/pull/2055)
- feat(promhttp): add CoalesceGather option to deduplicate concurrent
Gather calls by [@&#8203;kakkoyun](https://redirect.github.com/kakkoyun)
in
[#&#8203;1969](https://redirect.github.com/prometheus/client_golang/pull/1969)
- build(deps): update all Go dependencies in all go.mod files by
[@&#8203;bwplotka](https://redirect.github.com/bwplotka) in
[#&#8203;2059](https://redirect.github.com/prometheus/client_golang/pull/2059)
- Cut v1.24.0-rc.0 by
[@&#8203;bwplotka](https://redirect.github.com/bwplotka) in
[#&#8203;2058](https://redirect.github.com/prometheus/client_golang/pull/2058)

</details>

#### New Contributors
* @&#8203;xieyuschen made their first
contributi[https://github.com/prometheus/client_golang/pull/1844](https://redirect.github.com/prometheus/client_golang/pull/1844)l/1844
* @&#8203;torrca made their first
contributi[https://github.com/prometheus/client_golang/pull/1849](https://redirect.github.com/prometheus/client_golang/pull/1849)l/1849
* @&#8203;yshngg made their first
contributi[https://github.com/prometheus/client_golang/pull/1850](https://redirect.github.com/prometheus/client_golang/pull/1850)l/1850
* @&#8203;jotak made their first
contributi[https://github.com/prometheus/client_golang/pull/1843](https://redirect.github.com/prometheus/client_golang/pull/1843)l/1843
* @&#8203;SungJin1212 made their first
contributi[https://github.com/prometheus/client_golang/pull/1878](https://redirect.github.com/prometheus/client_golang/pull/1878)l/1878
* @&#8203;github-actions[bot] made their first
contributi[https://github.com/prometheus/client_golang/pull/1864](https://redirect.github.com/prometheus/client_golang/pull/1864)l/1864
* @&#8203;pipiland2612 made their first
contributi[https://github.com/prometheus/client_golang/pull/1888](https://redirect.github.com/prometheus/client_golang/pull/1888)l/1888
* @&#8203;fpetkovski made their first
contributi[https://github.com/prometheus/client_golang/pull/1889](https://redirect.github.com/prometheus/client_golang/pull/1889)l/1889
* @&#8203;karthikkondapally made their first
contributi[https://github.com/prometheus/client_golang/pull/1885](https://redirect.github.com/prometheus/client_golang/pull/1885)l/1885
* @&#8203;tjhop made their first
contributi[https://github.com/prometheus/client_golang/pull/1896](https://redirect.github.com/prometheus/client_golang/pull/1896)l/1896
* @&#8203;duricanikolic made their first
contributi[https://github.com/prometheus/client_golang/pull/1902](https://redirect.github.com/prometheus/client_golang/pull/1902)l/1902
* @&#8203;makasim made their first
contributi[https://github.com/prometheus/client_golang/pull/1917](https://redirect.github.com/prometheus/client_golang/pull/1917)l/1917
* @&#8203;kgeckhart made their first
contributi[https://github.com/prometheus/client_golang/pull/1927](https://redirect.github.com/prometheus/client_golang/pull/1927)l/1927
* @&#8203;90ashish made their first
contributi[https://github.com/prometheus/client_golang/pull/1929](https://redirect.github.com/prometheus/client_golang/pull/1929)l/1929
* @&#8203;manute made their first
contributi[https://github.com/prometheus/client_golang/pull/1950](https://redirect.github.com/prometheus/client_golang/pull/1950)l/1950
* @&#8203;Saflaski made their first
contributi[https://github.com/prometheus/client_golang/pull/1961](https://redirect.github.com/prometheus/client_golang/pull/1961)l/1961
* @&#8203;Retr0-XD made their first
contributi[https://github.com/prometheus/client_golang/pull/1967](https://redirect.github.com/prometheus/client_golang/pull/1967)l/1967
* @&#8203;pedrampdd made their first
contributi[https://github.com/prometheus/client_golang/pull/1971](https://redirect.github.com/prometheus/client_golang/pull/1971)l/1971
* @&#8203;thegdsks made their first
contributi[https://github.com/prometheus/client_golang/pull/1981](https://redirect.github.com/prometheus/client_golang/pull/1981)l/1981
* @&#8203;tie made their first
contributi[https://github.com/prometheus/client_golang/pull/1863](https://redirect.github.com/prometheus/client_golang/pull/1863)l/1863
* @&#8203;arpitjain099 made their first
contributi[https://github.com/prometheus/client_golang/pull/2003](https://redirect.github.com/prometheus/client_golang/pull/2003)l/2003
* @&#8203;immanuwell made their first
contributi[https://github.com/prometheus/client_golang/pull/2009](https://redirect.github.com/prometheus/client_golang/pull/2009)l/2009
* @&#8203;ProjectMutilation made their first
contributi[https://github.com/prometheus/client_golang/pull/2010](https://redirect.github.com/prometheus/client_golang/pull/2010)l/2010
* @&#8203;s3onghyun made their first
contributi[https://github.com/prometheus/client_golang/pull/2023](https://redirect.github.com/prometheus/client_golang/pull/2023)l/2023
* @&#8203;MD-Mushfiqur123 made their first
contributi[https://github.com/prometheus/client_golang/pull/2021](https://redirect.github.com/prometheus/client_golang/pull/2021)l/2021
* @&#8203;spor3006 made their first
contributi[https://github.com/prometheus/client_golang/pull/2005](https://redirect.github.com/prometheus/client_golang/pull/2005)l/2005
* @&#8203;maxtaran2010 made their first
contributi[https://github.com/prometheus/client_golang/pull/2049](https://redirect.github.com/prometheus/client_golang/pull/2049)l/2049
* @&#8203;dhanudhanushree made their first
contributi[https://github.com/prometheus/client_golang/pull/1999](https://redirect.github.com/prometheus/client_golang/pull/1999)l/1999

**Full Changelog**:
<prometheus/client_golang@v1.23.2...v1.24.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…ry-operations-go/exporter/metric to v0.59.0 (9.5) (#7809)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go)
| `v0.57.0` → `v0.59.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fGoogleCloudPlatform%2fopentelemetry-operations-go%2fexporter%2fmetric/v0.59.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fGoogleCloudPlatform%2fopentelemetry-operations-go%2fexporter%2fmetric/v0.57.0/v0.59.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>GoogleCloudPlatform/opentelemetry-operations-go
(github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric)</summary>

###
[`v0.59.0`](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/releases/tag/v0.59.0)

[Compare
Source](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/compare/v0.58.0...v0.59.0)

#### What's Changed

- Adds support for resolving OpenTelemetry authentication extensions by
[@&#8203;Angelawork](https://redirect.github.com/Angelawork) in
[#&#8203;1181](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1181)
- update golang.org/x/crypto by
[@&#8203;braydonk](https://redirect.github.com/braydonk) in
[#&#8203;1182](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1182)
- Update module google.golang.org/grpc to v1.82.1 \[SECURITY] by
[@&#8203;renovate-bot](https://redirect.github.com/renovate-bot) in
[#&#8203;1184](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1184)
- Prepare release 0.59.0/1.35.0 by
[@&#8203;braydonk](https://redirect.github.com/braydonk) in
[#&#8203;1183](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1183)

#### New Contributors

- [@&#8203;Angelawork](https://redirect.github.com/Angelawork) made
their first contribution in
[#&#8203;1181](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1181)

**Full Changelog**:
<GoogleCloudPlatform/opentelemetry-operations-go@v0.58.0...v0.59.0>

###
[`v0.58.0`](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/releases/tag/v0.58.0):
v1.34.0/v0.58.0

[Compare
Source](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/compare/v0.57.0...v0.58.0)

#### What's Changed

- googlemanagedprometheus: Add `destination_project_quota` by
[@&#8203;braydonk](https://redirect.github.com/braydonk) in
[#&#8203;1175](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1175)
- Prepare release v1.34.0/v0.58.0 by
[@&#8203;braydonk](https://redirect.github.com/braydonk) in
[#&#8203;1178](https://redirect.github.com/GoogleCloudPlatform/opentelemetry-operations-go/pull/1178)

**Full Changelog**:
<GoogleCloudPlatform/opentelemetry-operations-go@v0.57.0...v0.58.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [golang.org/x/mod](https://pkg.go.dev/golang.org/x/mod) | [`v0.38.0` →
`v0.39.0`](https://cs.opensource.google/go/x/mod/+/refs/tags/v0.38.0...refs/tags/v0.39.0)
|
![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fmod/v0.39.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fmod/v0.38.0/v0.39.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
….5) (#7817)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/prometheus/common](https://redirect.github.com/prometheus/common)
| `v0.69.0` → `v0.70.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fprometheus%2fcommon/v0.70.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fprometheus%2fcommon/v0.69.0/v0.70.1?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>prometheus/common (github.com/prometheus/common)</summary>

###
[`v0.70.1`](https://redirect.github.com/prometheus/common/releases/tag/v0.70.1)

[Compare
Source](https://redirect.github.com/prometheus/common/compare/v0.70.0...v0.70.1)

#### What's Changed

- Update CHANGELOG for v0.70.0 by
[@&#8203;roidelapluie](https://redirect.github.com/roidelapluie) in
[#&#8203;945](https://redirect.github.com/prometheus/common/pull/945)
- config: clarify sensitive redirect headers match net/http by
[@&#8203;roidelapluie](https://redirect.github.com/roidelapluie) in
[#&#8203;924](https://redirect.github.com/prometheus/common/pull/924)
- Synchronize common files from prometheus/prometheus by
[@&#8203;prombot](https://redirect.github.com/prombot) in
[#&#8203;946](https://redirect.github.com/prometheus/common/pull/946)
- build(deps): bump actions/checkout from 7.0.0 to 7.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;950](https://redirect.github.com/prometheus/common/pull/950)
- build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;949](https://redirect.github.com/prometheus/common/pull/949)
- build(deps): bump the codeql group with 4 updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;948](https://redirect.github.com/prometheus/common/pull/948)
- build(deps): bump golang.org/x/net from 0.56.0 to 0.57.0 in the
golang-org-x group across 1 directory by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;947](https://redirect.github.com/prometheus/common/pull/947)

**Full Changelog**:
<prometheus/common@v0.70.0...v0.70.1>

###
[`v0.70.0`](https://redirect.github.com/prometheus/common/blob/HEAD/CHANGELOG.md#v0700--2026-07-10)

[Compare
Source](https://redirect.github.com/prometheus/common/compare/v0.69.0...v0.70.0)

##### Enhancements

- route: add support for the QUERY HTTP method.
[#&#8203;932](https://redirect.github.com/prometheus/common/issues/932)

##### Bugfixes

- config: fix `TLSVersion.String()` printing a pointer address instead
of the numeric version for unknown TLS versions.
[#&#8203;929](https://redirect.github.com/prometheus/common/issues/929)

##### Internal

- expfmt: add `BenchmarkConvertMetricFamily` comparing the Prometheus
text and OpenMetrics 1.0 encoders.
[#&#8203;943](https://redirect.github.com/prometheus/common/issues/943)
- Update Go dependencies.
[#&#8203;933](https://redirect.github.com/prometheus/common/issues/933)
[#&#8203;934](https://redirect.github.com/prometheus/common/issues/934)
- Synchronize common files from prometheus/prometheus.
[#&#8203;923](https://redirect.github.com/prometheus/common/issues/923)
[#&#8203;927](https://redirect.github.com/prometheus/common/issues/927)
[#&#8203;930](https://redirect.github.com/prometheus/common/issues/930)
[#&#8203;937](https://redirect.github.com/prometheus/common/issues/937)
- Update GitHub Actions.
[#&#8203;938](https://redirect.github.com/prometheus/common/issues/938)
[#&#8203;939](https://redirect.github.com/prometheus/common/issues/939)
[#&#8203;940](https://redirect.github.com/prometheus/common/issues/940)
[#&#8203;941](https://redirect.github.com/prometheus/common/issues/941)
[#&#8203;942](https://redirect.github.com/prometheus/common/issues/942)

**Full Changelog**:
<prometheus/common@v0.69.0...v0.70.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/aws/aws-sdk-go-v2](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.42.1` → `v1.43.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2/v1.43.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2/v1.42.1/v1.43.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.7.13` → `v1.7.16` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2faws%2fprotocol%2feventstream/v1.7.16?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2faws%2fprotocol%2feventstream/v1.7.13/v1.7.16?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/config](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.32.25` → `v1.32.35` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fconfig/v1.32.35?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fconfig/v1.32.25/v1.32.35?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/credentials](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.19.24` → `v1.19.34` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fcredentials/v1.19.34?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fcredentials/v1.19.24/v1.19.34?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.18.29` → `v1.18.35` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2ffeature%2fec2%2fimds/v1.18.35?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2ffeature%2fec2%2fimds/v1.18.29/v1.18.35?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/internal/configsources](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.4.30` → `v1.4.35` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2finternal%2fconfigsources/v1.4.35?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2finternal%2fconfigsources/v1.4.30/v1.4.35?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/internal/endpoints/v2](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v2.7.30` → `v2.7.35` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2finternal%2fendpoints%2fv2/v2.7.35?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2finternal%2fendpoints%2fv2/v2.7.30/v2.7.35?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/internal/v4a](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.4.30` → `v1.4.36` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2finternal%2fv4a/v1.4.36?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2finternal%2fv4a/v1.4.30/v1.4.36?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/accessanalyzer](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.49.5` → `v1.51.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2faccessanalyzer/v1.51.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2faccessanalyzer/v1.49.5/v1.51.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/autoscaling](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.67.4` → `v1.71.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fautoscaling/v1.71.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fautoscaling/v1.67.4/v1.71.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/cloudformation](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.72.1` → `v1.76.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fcloudformation/v1.76.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fcloudformation/v1.72.1/v1.76.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/cloudtrail](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.56.4` → `v1.58.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fcloudtrail/v1.58.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fcloudtrail/v1.56.4/v1.58.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/cloudwatch](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.59.0` → `v1.66.3` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fcloudwatch/v1.66.3?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fcloudwatch/v1.59.0/v1.66.3?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.78.0` → `v1.82.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fcloudwatchlogs/v1.82.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fcloudwatchlogs/v1.78.0/v1.82.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/configservice](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.64.1` → `v1.68.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fconfigservice/v1.68.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fconfigservice/v1.64.1/v1.68.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/dynamodb](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.59.0` → `v1.63.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fdynamodb/v1.63.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fdynamodb/v1.59.0/v1.63.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/ebs](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.34.7` → `v1.36.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2febs/v1.36.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2febs/v1.34.7/v1.36.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/ec2](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.308.0` → `v1.321.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fec2/v1.321.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fec2/v1.308.0/v1.321.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/ecr](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.58.4` → `v1.60.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fecr/v1.60.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fecr/v1.58.4/v1.60.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/eks](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.88.1` → `v1.90.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2feks/v1.90.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2feks/v1.88.1/v1.90.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/elasticloadbalancing](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.34.6` → `v1.36.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2felasticloadbalancing/v1.36.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2felasticloadbalancing/v1.34.6/v1.36.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.55.4` → `v1.58.5` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2felasticloadbalancingv2/v1.58.5?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2felasticloadbalancingv2/v1.55.4/v1.58.5?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/iam](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.54.5` → `v1.58.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fiam/v1.58.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fiam/v1.54.5/v1.58.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.13.12` → `v1.13.15` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2finternal%2faccept-encoding/v1.13.15?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2finternal%2faccept-encoding/v1.13.12/v1.13.15?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/internal/checksum](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.9.22` → `v1.9.28` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2finternal%2fchecksum/v1.9.28?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2finternal%2fchecksum/v1.9.22/v1.9.28?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.12.6` → `v1.12.12` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2finternal%2fendpoint-discovery/v1.12.12?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2finternal%2fendpoint-discovery/v1.12.6/v1.12.12?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/internal/presigned-url](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.13.29` → `v1.13.35` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2finternal%2fpresigned-url/v1.13.35?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2finternal%2fpresigned-url/v1.13.29/v1.13.35?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/internal/s3shared](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.19.29` → `v1.19.36` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2finternal%2fs3shared/v1.19.36?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2finternal%2fs3shared/v1.19.29/v1.19.36?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/kms](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.53.4` → `v1.55.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fkms/v1.55.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fkms/v1.53.4/v1.55.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/lambda](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.93.0` → `v1.101.2` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2flambda/v1.101.2?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2flambda/v1.93.0/v1.101.2?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/organizations](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.51.10` → `v1.53.5` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2forganizations/v1.53.5?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2forganizations/v1.51.10/v1.53.5?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/rds](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.119.3` → `v1.124.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2frds/v1.124.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2frds/v1.119.3/v1.124.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/route53](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.62.5` → `v1.65.6` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2froute53/v1.65.6?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2froute53/v1.62.5/v1.65.6?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/s3](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.104.0` → `v1.107.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fs3/v1.107.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fs3/v1.104.0/v1.107.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/s3control](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.71.5` → `v1.73.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fs3control/v1.73.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fs3control/v1.71.5/v1.73.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/securityhub](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.71.7` → `v1.76.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsecurityhub/v1.76.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsecurityhub/v1.71.7/v1.76.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/signin](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.2.0` → `v1.5.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsignin/v1.5.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsignin/v1.2.0/v1.5.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/sns](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.40.1` → `v1.42.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsns/v1.42.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsns/v1.40.1/v1.42.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/sqs](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.44.0` → `v1.46.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsqs/v1.46.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsqs/v1.44.0/v1.46.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/sso](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.31.3` → `v1.33.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsso/v1.33.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsso/v1.31.3/v1.33.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/ssooidc](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.36.6` → `v1.38.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fssooidc/v1.38.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fssooidc/v1.36.6/v1.38.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/sts](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.43.3` → `v1.45.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsts/v1.45.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsts/v1.43.3/v1.45.4?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/Azure/azure-sdk-for-go/sdk/azcore](https://redirect.github.com/Azure/azure-sdk-for-go)
| `v1.21.1` → `v1.22.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fAzure%2fazure-sdk-for-go%2fsdk%2fazcore/v1.22.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fAzure%2fazure-sdk-for-go%2fsdk%2fazcore/v1.21.1/v1.22.0?slim=true)
|
|
[github.com/Azure/azure-sdk-for-go/sdk/azidentity](https://redirect.github.com/Azure/azure-sdk-for-go)
| `v1.13.1` → `v1.14.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fAzure%2fazure-sdk-for-go%2fsdk%2fazidentity/v1.14.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fAzure%2fazure-sdk-for-go%2fsdk%2fazidentity/v1.13.1/v1.14.0?slim=true)
|
|
[github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/monitor/armmonitor](https://redirect.github.com/Azure/azure-sdk-for-go)
| `v0.11.0` → `v0.13.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fAzure%2fazure-sdk-for-go%2fsdk%2fresourcemanager%2fmonitor%2farmmonitor/v0.13.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fAzure%2fazure-sdk-for-go%2fsdk%2fresourcemanager%2fmonitor%2farmmonitor/v0.11.0/v0.13.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
…v1.101.0 (9.5) (#7829)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/microsoftgraph/msgraph-sdk-go](https://redirect.github.com/microsoftgraph/msgraph-sdk-go)
| `v1.99.0` → `v1.101.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fmicrosoftgraph%2fmsgraph-sdk-go/v1.101.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fmicrosoftgraph%2fmsgraph-sdk-go/v1.99.0/v1.101.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>microsoftgraph/msgraph-sdk-go
(github.com/microsoftgraph/msgraph-sdk-go)</summary>

###
[`v1.101.0`](https://redirect.github.com/microsoftgraph/msgraph-sdk-go/releases/tag/v1.101.0)

[Compare
Source](https://redirect.github.com/microsoftgraph/msgraph-sdk-go/compare/v1.100.0...v1.101.0)

##### Features

- **generation:** update request builders and models
([388f40e](https://redirect.github.com/microsoftgraph/msgraph-sdk-go/commit/388f40ebf697f4185a0e7837815257069b44a0de))

###
[`v1.100.0`](https://redirect.github.com/microsoftgraph/msgraph-sdk-go/releases/tag/v1.100.0)

[Compare
Source](https://redirect.github.com/microsoftgraph/msgraph-sdk-go/compare/v1.99.0...v1.100.0)

##### Features

- **generation:** update request builders and models
([c8f08e8](https://redirect.github.com/microsoftgraph/msgraph-sdk-go/commit/c8f08e8aa9e3b2c0058a974015712ea924ec4a06))
- **generation:** update request builders and models
([44f234d](https://redirect.github.com/microsoftgraph/msgraph-sdk-go/commit/44f234dc4000e9ef9c03f176e9fcb7f7ce60c521))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6IjkuNSIsImxhYmVscyI6WyJUZWFtOlNlY3VyaXR5LUNsb3VkIFNlcnZpY2VzIiwiYmFja3BvcnQtc2tpcCIsImRlcGVuZGVuY2llcyIsInJlbm92YXRlIiwicmVub3ZhdGUtYXV0by1hcHByb3ZlIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
Hermit's pre-commit package bumped its runtime dependency from
python3@3.9 to python3@3.14 (cashapp/hermit-packages#773), so hooks
launched through pre-commit now see python3.14 first on PATH. Poetry 2.x
resolves the interpreter from PATH, and since security-policies declares
requires-python = ">=3.11", python3.14 satisfies it: the
"poetry run -C security-policies" hooks created a fresh, empty 3.14
virtualenv instead of reusing the 3.11 one built during setup, failing
with "ModuleNotFoundError: No module named 'git'".

Pinning the env with "poetry env use python3.11" records the selection in
envs.toml so every later "poetry run" reuses the env that actually has
the dependencies installed.

Same fix already applied on 9.4 in #4759.
@olegsu olegsu closed this Aug 11, 2026
@olegsu
olegsu deleted the fix/pin-poetry-python-3.11-9.5 branch August 12, 2026 03:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant