Skip to content

Update non-major - #1

Open
1bsv-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major
Open

1bsv-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major

Conversation

@1bsv-renovate

@1bsv-renovate 1bsv-renovate Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
@types/node (source) 24.13.6 → 24.19.1 age confidence devDependencies minor
actions/setup-node v6.0.0 → v6.5.0 age confidence action minor
docker/build-push-action v7.3.0 → v7.4.0 age confidence action minor
docker/setup-buildx-action v4.3.0 → v4.4.1 age confidence action minor
github.com/bsv-blockchain/go-wallet-toolbox v0.187.1 → v0.188.1 age confidence require minor v0.189.0
github.com/libp2p/go-libp2p v0.48.1-0.20260709142922-ec408fcc60c9 → v0.50.0 age confidence replace minor
github.com/lightwebinc/bcommon v0.5.4 → v0.6.4 age confidence require minor v0.10.0 (+4)
github.com/quic-go/quic-go v0.60.0 → v0.63.0 age confidence replace minor
github.com/quic-go/webtransport-go v0.11.1 → v0.13.0 age confidence replace minor
github/codeql-action v4.37.9 → v4.38.2 age confidence action minor
mysql (source) 30a0abf → e2bde46 digest

Release Notes

actions/setup-node (actions/setup-node)

v6.5.0

Compare Source

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

v6.4.0

Compare Source

What's Changed

Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.4.0

v6.3.0

Compare Source

What's Changed

Enhancements:

When using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node.

Dependency updates:
Bug fixes:

New Contributors

Full Changelog: actions/setup-node@v6...v6.3.0

v6.2.0

Compare Source

What's Changed

Documentation
Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.2.0

v6.1.0

Compare Source

What's Changed

Enhancement:
Dependency updates:
Documentation update:

Full Changelog: actions/setup-node@v6...v6.1.0

docker/build-push-action (docker/build-push-action)

v7.4.0

Compare Source

Full Changelog: docker/build-push-action@v7.3.0...v7.4.0

docker/setup-buildx-action (docker/setup-buildx-action)

v4.4.1

Compare Source

Full Changelog: docker/setup-buildx-action@v4.4.0...v4.4.1

v4.4.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.3.0...v4.4.0

bsv-blockchain/go-wallet-toolbox (github.com/bsv-blockchain/go-wallet-toolbox)

v0.188.1

Compare Source

v0.188.0

Compare Source

Changelog

v0.187.5

Compare Source

Changelog

  • 8b71e81 fix(storage): store the resolved BEEF, not the one the payer sent (#​1052)

v0.187.4

Compare Source

Changelog

v0.187.3

Compare Source

Changelog

v0.187.2

Compare Source

Changelog

  • a904d97 chore(deps): bump go-sdk, go-chaintracks and related dependencies (#​1046)
  • 751dd3f fix(deps): drop the go-libp2p, quic-go and webtransport-go replace pins (#​983) (#​1045)
libp2p/go-libp2p (github.com/libp2p/go-libp2p)

v0.50.0

Compare Source

What's Changed

New Contributors

Full Changelog: libp2p/go-libp2p@v0.49.0...v0.50.0

lightwebinc/bcommon (github.com/lightwebinc/bcommon)

v0.6.4

Compare Source

Full Changelog: lightwebinc/bcommon@v0.6.3...v0.6.4

v0.6.3

Compare Source

Full Changelog: lightwebinc/bcommon@v0.6.2...v0.6.3

v0.6.2

Compare Source

Full Changelog: lightwebinc/bcommon@v0.6.1...v0.6.2

v0.6.1

Compare Source

Full Changelog: lightwebinc/bcommon@v0.6.0...v0.6.1

v0.6.0

Compare Source

Full Changelog: lightwebinc/bcommon@v0.5.5...v0.6.0

v0.5.5

Compare Source

Full Changelog: lightwebinc/bcommon@v0.5.4...v0.5.5

quic-go/quic-go (github.com/quic-go/quic-go)

v0.63.0

Compare Source

This release improves HTTP/3 request handling and error reporting.

Breaking Changes

  • http3: non-CONNECT server requests now leave URL.Scheme and URL.Host empty, matching net/http: #​5839
  • http3: Extended CONNECT now leaves URL.Scheme and URL.Host empty and sets RequestURI to :path: #​5841
  • http3: stream APIs now return QUIC stream and application errors as *http3.Error: #​5852

Notable Fixes

  • http3: :path must start with /; only OPTIONS allows *: #​5842
  • quicvarint: complete varints now decode successfully when returned alongside io.EOF or another reader error: #​5876

Notable Changes

  • http3.Error now supports unwrapping the underlying QUIC stream or application error: #​5873
  • http3.ClientConn now exposes LocalAddr and RemoteAddr: #​5871

Changelog

Full Changelog: quic-go/quic-go@v0.62.0...v0.63.0

v0.62.0

Compare Source

This release adds support for stream priorities based on RFC 9218:

  • SendStream and Stream now expose SetPriority, allowing applications to set the urgency and incremental scheduling behavior of stream data. Retransmissions are prioritized over new stream data and respect stream priorities: #​5770, #​5774
  • HTTP/3 servers now apply priorities from request Priority headers and PRIORITY_UPDATE frames. Priority updates are also recorded in qlog for both HTTP/3 and QUIC streams: #​5783, #​5789, #​5790, #​5795

Notable Changes

  • http3.Stream and http3.RequestStream now expose TryWriteAll, which queues a complete DATA frame without blocking or returns quic.ErrWouldBlock without queueing anything: #​5765
  • Reliable Stream Resets are now advertised using both the draft-09 and legacy draft-07 transport parameters, restoring interoperability with Safari for WebTransport: #​5782, thanks to @​0xFA11

Breaking Changes

  • quic-go now requires Go 1.26 or newer: #​5801

Notable Fixes

  • Connections now reject unread CRYPTO data as soon as TLS advances to the next encryption level, instead of waiting until the previous keys are discarded: #​5824
  • http3: servers now reject 0-RTT when their current SETTINGS are incompatible with those stored in the session ticket, preventing early requests from relying on settings the server no longer supports: #​5771
  • http3: requests containing userinfo in :authority are now rejected for HTTP and HTTPS URIs: #​5825
  • http3: request schemes are now normalized to lowercase: #​5826
  • http3: request methods are now validated as HTTP tokens; unknown methods with valid syntax remain accepted: #​5827
  • http3: Host is now used for HTTP and HTTPS requests when :authority is omitted, while conflicting Host and :authority values are rejected: #​5828
  • http3: regular CONNECT requests containing :scheme are now rejected: #​5829
  • http3: requests containing duplicate Host header fields are now rejected: #​5830
  • http3: empty pseudo-header fields are no longer treated as omitted, ensuring duplicate fields and CONNECT requirements are validated correctly: #​5833
  • http3: successful CONNECT responses are no longer transparently gzip-decoded, preserving tunnel data and the Content-Encoding header: #​5834
  • Conn.NextConnection now returns the connection context's error if the connection closes before the handshake completes: #​5764, thanks to @​floating-cat
  • Closing a validated path now retires its connection ID, without racing connection shutdown and panicking: #​5798, #​5823, thanks to @​tlstpierre
  • OpenBSD now requests a supported 2 MiB socket buffer size and correctly verifies the configured size, avoiding ineffective buffer increases and spurious warnings: #​5787, thanks to @​the-sarge

Changelog

New Contributors

Full Changelog: quic-go/quic-go@v0.61.0...v0.62.0

v0.61.0

Compare Source

This release adds new stream APIs intended for application protocols that perform their own flow-control accounting, such as WebTransport:

  • SendStream and Stream now expose TryWriteAll, which queues an entire buffer without blocking or returns ErrWouldBlock without queueing anything: #​5704
  • SendStream and Stream now expose WriteWithLimit, allowing higher-level protocols to apply an additional send limit while data is packetized: #​5753
  • ReceiveStream and Stream now expose SetReceiveFinalSizeCallback, which reports the final receive-side stream size once it is learned from a FIN or RESET_STREAM frame: #​5752

Support for the RESET_STREAM_AT extension was updated to draft-09, while retaining support for the draft-07 codepoint for backwards compatibility: #​5724

Breaking Changes

  • http3: ParseCapsule was replaced by the stateful CapsuleParser and CapsuleReader APIs. Each capsule payload must now be consumed or discarded before advancing to the next capsule: #​5729
  • The StreamID.Type and StreamID.InitiatedBy methods were removed because they exposed internal types: #​5744
  • qlog: datagram IDs were replaced by CRC32c payload checksums. The JSON field is now datagram_payload_checksum instead of datagram_id, and the corresponding exported qlog types were renamed: #​5758

Notable Fixes

  • Transport parameter parsing is around 27% faster and now reliably rejects duplicate transport parameters: #​5712
  • Session tickets containing unknown transport parameters are now rejected during restoration, preventing 0-RTT resumption when an endpoint no longer understands an extension recorded in the ticket: #​5714
  • RESET_STREAM_AT negotiation is now applied correctly to streams opened before transport parameters are received during 0-RTT: #​5715
  • RESET_STREAM_AT support is now cleared after 0-RTT rejection, preventing new streams from inheriting the rejected connection's setting: #​5716
  • Pending stream control frames from a rejected 0-RTT attempt are now discarded instead of being sent after rejection: #​5717
  • Remembered RESET_STREAM_AT support is now validated across 0-RTT resumption: #​5722
  • http3: receiving a GOAWAY now unblocks pending OpenStreamSync calls and prevents new request streams from being opened: #​5730
  • http3: invalid header values are no longer included in validation errors, avoiding accidental exposure of sensitive values when errors are logged: #​5742

Changelog

Full Changelog: quic-go/quic-go@v0.60.0...v0.61.0

quic-go/webtransport-go (github.com/quic-go/webtransport-go)

v0.13.0

Compare Source

This release updates quic-go to v0.62.0, and now requires Go 1.26 or newer.

Other Changes

  • WT_CLOSE_SESSION capsules are now queued without blocking on flow control. The complete capsule is queued or the stream is canceled: #​362

Changelog

  • ci: bump docker/login-action from 4.5.1 to 4.6.0 by @​dependabot[bot] in #​357
  • ci: bump docker/setup-buildx-action from 4.2.0 to 4.3.0 by [@&#

✂ Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • Between 12:00 PM and 11:59 PM, only on Tuesday and Friday (* 12-23 * * 2,5)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@1bsv-renovate

1bsv-renovate Bot commented Oct 4, 2026

Copy link
Copy Markdown
Author

ℹ️ Artifact update notice

File name: tools/walletd/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 15 additional dependencies were updated

Details:

Package Change
github.com/bsv-blockchain/go-sdk v1.6.0 -> v1.7.0
github.com/bsv-blockchain/aerospike-client-go/v8 v8.7.1-bsv5 -> v8.7.1-bsv6
github.com/bsv-blockchain/go-bsv-middleware v0.16.0 -> v0.16.1
github.com/bsv-blockchain/go-bt/v2 v2.7.3 -> v2.7.4
github.com/bsv-blockchain/go-chaintracks v1.3.0 -> v1.4.1
github.com/bsv-blockchain/go-teranode-p2p-client v0.3.0 -> v0.3.1
github.com/go-openapi/jsonreference v1.0.2 -> v1.0.3
github.com/grpc-ecosystem/grpc-gateway/v2 v2.30.0 -> v2.31.0
github.com/labstack/echo/v4 v4.15.4 -> v4.16.0
github.com/pierrec/lz4/v4 v4.1.30 -> v4.1.31
github.com/pion/dtls/v3 v3.1.9 -> v3.1.10
github.com/pion/webrtc/v4 v4.2.21 -> v4.2.22
github.com/prometheus/common v0.71.0 -> v0.72.0
github.com/twmb/franz-go v1.22.0 -> v1.22.1
modernc.org/sqlite v1.59.0 -> v1.60.0

@1bsv-renovate
1bsv-renovate Bot force-pushed the renovate/non-major branch from b108a7e to 7a1ce83 Compare October 4, 2026 18:42
@1bsv-renovate
1bsv-renovate Bot force-pushed the renovate/non-major branch from 7a1ce83 to 472e4fd Compare October 6, 2026 18:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant