chore(all): update deps (major) - #726
Open
renovate-bot wants to merge 1 commit into
Open
renovate-bot wants to merge 1 commit into
renovate-bot wants to merge 1 commit into
Conversation
renovate-bot
force-pushed
the
renovate/major-deps
branch
3 times, most recently
from
September 22, 2026 10:45
a29e68f to
f42b907
Compare
renovate-bot
force-pushed
the
renovate/major-deps
branch
2 times, most recently
from
September 24, 2026 23:00
0c7786d to
d7774d8
Compare
renovate-bot
force-pushed
the
renovate/major-deps
branch
from
September 30, 2026 22:28
d7774d8 to
14e230a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
8.4.1→9.2.020250512.2→20250814.2v3.37.0→v4.9.0v1.0.0→v2.140.01.3.0→2.3.41.3.0→2.3.4Release Notes
bazelbuild/bazel (bazel)
v9.2.0Compare Source
v9.1.1Compare Source
v9.1.0Compare Source
v9.0.2Compare Source
v9.0.1Compare Source
v9.0.0Compare Source
v8.8.1Compare Source
v8.8.0Compare Source
v8.7.0Compare Source
v8.6.0Compare Source
v8.5.1Compare Source
v8.5.0Compare Source
v8.4.2Compare Source
abseil/abseil-cpp (com_google_absl)
v20250814.2: Abseil LTS branch, August 2025, Patch 2Compare Source
Abseil LTS
2025081.2What's New:
absl::Mutexnow contains lower-case method names likelock()andshared_lock()to align with standard C++ mutex methods. This allowsabsl::Mutexto be used withstd::scoped_lockand friends. The old names are still present but may be removed in a future release.absl::MutexLock,absl::ReaderMutexLock, and friends now accept references toabsl::Mutex. The pointer-accepting constructors are now deprecated, and may be removed in a future release.Breaking Changes:
absl::string_view(nullptr), which is undefined behavior according to the C++ standard, now triggers anassertfailure. Note that unless you changedabsl/base/options.h,absl::string_viewis an alias forstd::string_view, so by default you will be inheriting the behavior of your standard library instead of using the Abseil implementation.sizeof(size_t).Baseline:
987c57fCherry-pick:
d38452e(Patch 1)Cherry-pick:
7313246(Patch 2)v20250814.1: Abseil LTS branch, August 2025, Patch 1Compare Source
Abseil LTS
2025081.1What's New:
absl::Mutexnow contains lower-case method names likelock()andshared_lock()to align with standard C++ mutex methods. This allowsabsl::Mutexto be used withstd::scoped_lockand friends. The old names are still present but may be removed in a future release.absl::MutexLock,absl::ReaderMutexLock, and friends now accept references toabsl::Mutex. The pointer-accepting constructors are now deprecated, and may be removed in a future release.Breaking Changes:
absl::string_view(nullptr), which is undefined behavior according to the C++ standard, now triggers anassertfailure. Note that unless you changedabsl/base/options.h,absl::string_viewis an alias forstd::string_view, so by default you will be inheriting the behavior of your standard library instead of using the Abseil implementation.sizeof(size_t).Baseline:
987c57fCherry-pick:
d38452e(Patch 1)v20250814.0: Abseil LTS branch, August 2025Compare Source
Abseil LTS
2025081.0What's New:
absl::Mutexnow contains lower-case method names likelock()andshared_lock()to align with standard C++ mutex methods. This allowsabsl::Mutexto be used withstd::scoped_lockand friends. The old names are still present but may be removed in a future release.absl::MutexLock,absl::ReaderMutexLock, and friends now accept references toabsl::Mutex. The pointer-accepting constructors are now deprecated, and may be removed in a future release.Breaking Changes:
absl::string_view(nullptr), which is undefined behavior according to the C++ standard, now triggers anassertfailure. Note that unless you changedabsl/base/options.h,absl::string_viewis an alias forstd::string_view, so by default you will be inheriting the behavior of your standard library instead of using the Abseil implementation.sizeof(size_t).Known Issues
CHECK_<OP>is failing to compile on older versions of GCC when one of the arguments is a C-style string. This is fixed byba9a180and will be included in a future patch release.Baseline:
987c57fosrg/gobgp (github.com/osrg/gobgp/v3)
v4.9.0Compare Source
Changelog
01c5c4cGoBGP 4.9.09d50d8eserver: drop stale notifications queued while a peer session was downefa0900packet/bgp: check the per-type message length in parseBodyd7c721dpacket/bgp: reject a body that does not match the declared length5e34ff5test: move the KEEPALIVE length test next to the other header testse37c5a2packet/bgp: reject KEEPALIVE messages that are not 19 octetsb2c73cftest: drop run_all_tests.sh and document how to run scenario tests8056d41docs: document the listen address of the gRPC API4bbeb79security: define what we treat as a vulnerabilitye6c6f10table: find the policy assignments in DeletePolicy itself4171aa9server: drop the policy assignment of a deleted peera111094server: store the per peer policy only for a route server clientc0214f7table: report a statement that the policy does not have36cca5dtable: check the import direction when deleting a policy698cc61table: fix preserve flag in DeletePolicyd4eb7d3config: remove the collector configuration8006da4config: log reload failures at Error again3436d72config: log the export policy assignment failure at Error5f4a6b5config: do not abort startup when zebra is not reachable94518c5fix(cmd/gobgpd): delay sdnotify readiness6e08373feat(config): return initial apply errors11a4096server: fill in the Data field of the too long message error8f72434packet/bgp: fill in the Data field of message header errorsc927e31server: type fsmStateReason's notification as *bgp.BGPNotification88ac6daserver: pass the sent NOTIFICATION to fsmStateReason in handleOpenc4e13d1server: fix wrong message wired into fsmStateReason on bad-peer-AS/invalid-msg36e6efdconfig: test peer group deletion against config updatese585c39config: fix deleting peer group and neighbor togethereb2a727packet/bgp: include the type in an unknown route distinguisher stringf9152c2packet/bgp: keep the value of an unknown route distinguisher33539eeapiutil: round-trip the SR-MPLS Binding SID label through the API8b19441tcp-ao: expose HMAC-SHA256 profiles9341943netutils: support HMAC-SHA256 for TCP-AOcb123e9spell-check: keep dictionary.txt sortedd7ae493spell-check: fix the "mututally" typo3b05300config: load TCP-AO keychains from configc32c92fconfig/oc: add TCP-AO keychain modeldae5a6cconfig/oc: reject out-of-range integers in the config file1b84a40packet/bgp: add a test for concurrent Serializee7f8d7epacket/bgp: do not cache the message length in the BGP headerb010677packet/bgp: do not store the serialized length in OPENcaccf7bpacket/bgp: do not store the serialized value in the capability3b6ff68packet/bgp: make capability Len independent of Serializea40450dserver: hold fsm.lock when reading fsm.recvOpen8c84624cmd/gobgp: document the I-PMSI route target as requiredaac7deacmd/gobgp: validate I-PMSI route target before use42abd24packet/bgp: serialize the full SID in the SRv6 Binding SID sub-TLVc0d5851packet/bgp: set the bottom-of-stack bit in the VPLS Label Base708c180packet/bgp: compare the decoded NLRI in the VPLS round-trip test45c9244packet/bgp: cover the VPLS BGP-AD NLRI at the MP_REACH level62f3d94packet/bgp: re-serialize the VPLS NLRI in the fuzz target96105cbpacket/bgp: drop the stale RFC 6074 comment in the VPLS NLRI decoder7b1d80areject VPLS NLRI with a length other than 1702bcba0ci: make the YANG check fail when pyang failsf626c40tools/pyang_plugins: declare the route-family typedef84868f8tools/pyang_plugins: drop the ineffective ip-prefix deviation9c22b63ci: add job for yang files diff97ff24econfig: fix incorrect yang generation69faffbserver: compare TCP-AO keychain messages with proto.Equalf306bbaserver: run the TCP-AO validation cases inside their subtestse68a92fserver: spell the TCP-AO keychain store field as one word2328707api, server: drop the keychain from the TCP-AO add response407debaserver: treat the TCP-AO keychain list name as a filter0e9a005server: reject out-of-range TCP-AO key IDs on keychain updateaba1929server: implement TCP-AO keychain managementa7251b9api: add TCP-AO keychain configuration API8e65579zebra: drop dead pos increments in zapi tests55eb7a8api, cli: surface the flowspec redirect-to-IP action58940aapacket/bgp: add flowspec redirect-to-IP extended communitiesad3e7c2packet/bgp: bound MUP Type 2 endpoint address length to address family5bf33cfzebra: reject a nexthop label count above the maximumb7d523bfix(server): avoid mutating Adj-RIB-In when listing accepted paths and refactorb6a519bserver: reject an unknown peer group in the dynamic neighbor APIv4.8.0Compare Source
Changelog
1049522GoBGP 4.8.04e349f6server: withdraw filtered secondary routes on soft reset out93dd9a6packet/bgp: always include the mask length in RTC NLRI strings1bccb27packet/bgp: reject Route Target Membership NLRI longer than 96 bits21ccfb9packet/bgp: make Route Target Membership NLRI codec RFC 4684-correct for all prefix lengths6934f7dtable: add rtc-prefix match for prefix-set policy conditionsbd337catable: don't infer a fixed ASN from an alternation community pattern440a3b1packet/bgp: bound the update attribute scan to its declared length5a369edbfd: discard received packets with an unbound discriminator1d16f3dtable: send IPv6 extended communities in their own attribute9c13d68packet/bgp: keep extended community decoders inside their communitya74cb86ci: run buf generate from proto so the diff check has an effect4c9c9f6apiutil: reject unparseable BGP-LS addresses instead of panicking3d78f01api: give BGP-LS link identifiers explicit presence016ac48apiutil: reject absent BGP-LS sub-messages instead of panicking6f6e630netutils: fix SA5011 nil-deref warning in bindInterface testb6c58c8packet/bgp: validate declared lengths in Prefix-SID SRv6 TLVsca4873fpacket/bgp: handle absent Multi-Topology ID in SRv6 SID NLRI173621fpacket/bgp: reject zero-length next hop for families that require one86bc653test(rtc): add scenario test for rtc policy filtering and change base check from adj-in to global ribea7e972chore(deps): bump google.golang.org/grpc from 1.79.3 to 1.82.10378ad6packet/rtr: bound RTRIPPrefix prefix and max length to address familye1bf959packet/bgp: clamp SR Policy NLRI endpoint to declared length31e136bserver: return an error from watch instead of a nil watcher88b4238fix(server): prevent watcher leaks during shutdown08ee396netutils: add TCP-AO socket helpers4e17218server: resolve unnumbered NeighborInterface before validating neighbor addressa7028f3packet/bmp: validate declared length in TLV16 value decoders3e854cepkg/server: fix Loc-RIB BMP Peer Up to match RFC 906928ba85fbfd: discard received packets with a zero Detect Multc1612bfbfd: derive detection time from remote timersd0f1080server/bmp: report Adj-RIB-In withdrawals to clear ribout on peer down69da7bfpacket/bgp: reject out-of-range prefix length in EVPNIPPrefixRoute3272a76docs: update srv6_mup.md for draft-ietf-bess-mup-safi-010845830cmd/gobgp: support MUP ST route TLVs and extended community formats7d2ace1api: add MUP ST route TLVs and MUP extended community formats71d2cc3packet/bgp: add interwork segment and address-format sub-types to MUP extended communityc2359e4packet/bgp: add optional TLVs to MUP Type 1/2 ST routesdc951acserver: rely on lazy path attributes hasha3f0566table: make lazy path attributes hash consistent with eager sites635293ctable: fix Path.Equal ignoring nexthop and NLRI payloada06cf9dpacket/bgp: clamp flowspec components to declared NLRI lengtha310174zebra: reject ZAPI header with Length below header size0d1ad1bpacket/mrt: fix attribute-length truncation in parseRibEntryeba905dadd a test that demos that the error messages related to misconfig remain the same7df6ba2Support Config Viaio.Reader5f30debpacket/bgp: fix SRv6InformationSubTLV sub-sub-TLV decode over-read0b5e3dcchore(deps): bump golang.org/x/net from 0.48.0 to 0.55.08885f0bPropagate BindToDevice to GetBgpab3b92fbgp: fix build break, gofmt and stale tests in BGP-LS String() methods5b918d2style: fix gofmt formattingb993c6dbgp: fix BGP-LS Link/Prefix NLRI key collision for IS-IS L1/L2v4.7.0Compare Source
Changelog
8b5edc2GoBGP 4.7.0441fcb6ignore Claude files4a9c2a5Use Interface/Device Bindings for BFD1ad1e03tools: add FlowSpec auto-mitigation example8c4802dci: replace fabric with shell script for building container imaged6dee83scenario_test: migrate test runner from nose to pytest09276f7server: fix Downtime updated on reconnection intermediate transitions3c0164fscenario_test: fix route server policy to use export direction40817e6gobgp: support last-as keyword in as-prepend action1cf53c9scenario_test: fix route server policy direction and test infrastructuree474954ci: enable IPv6 for route server scenario tests3acd19ftable: fix REPLACE with empty community list not propagated to API737a626table: fix case-sensitive community action type in toStatementApi2132288fix: register bfd for dynamic neighbourse5286bbscenario_test: update route_server_malformed_test to match RFC 7606 behavior8ab4f8afix: pass zone for LLA BFD peerf6cc73aserver: fix GR LocalRestarting not cleared when transitioning peer appears as OPENCONFIRM4092db3config: propagate bind-interface from peer-group transport config4a319a6packet/bgp: reject empty AS_PATH in confederation eBGP validation7325b9dAdd missing scenario tests for TCP MD55581749config: Plumb global bind-to-device from file config76ece66Support VRF for TCP MD521830f7config: remove trailing whitespace from gobgp.yangfffa3d5bgp-ls: accept prefix-length 0 in LsTLVIPReachability (default route)944decezebra: set ifindex for IPv6 link-local next-hops7204bf9packet/bgp: fix TunnelEncapSubTLVSRCandidatePathName decode over-read9f62e5bpacket/bgp: include Link Local/Remote Identifier in LsLinkDescriptor.String when both shapes are present8866bd7table: fix ext-community-set match-set-options ALL and INVERT94e64d6fix global rib peer addpathc57da62fix multipath when use bmp or monitor7743c50ci: scope GITHUB_TOKEN to minimum required permissionse25cefaRequire @fujita review for workflow changes0cc5ed4packet/bgp, apiutil: gofmt fixups in the RFC 9351 stack86958d5apiutil: end-to-end wire test for RFC 9351 FAD + multi-SID Prefix-SID + FAPMcea5414packet/bgp: render FAD sub-TLVs in LsTLVFlexAlgoDef.String for CLI outputc29c820api, apiutil: surface RFC 9351 Flex-Algorithm Definition + multi-SID Prefix-SIDe112129packet/bgp: add RFC 9351 Flex-Algorithm Definition + multi-SID Prefix-SIDb3989e1server, table: advertise the cap, negotiate it, and gate the per-session length877913eapi, apiutil: surface the BGP Extended Message capabilitye1268dbpacket/bgp: add the BGP Extended Message capability (RFC 8654)41b5bb6table: cache NLRI string in originInfo to avoid repeated allocations6f2cf37server: use sync.Map.Clear() in resetAdvertisedRoutes6331854server: avoid global propagation locks in resetAdvertisedRoutesv4.6.0Compare Source
Changelog
5151100GoBGP 4.6.084a98f8server: withdraw policy-filtered routes on soft reset out41e47a8fsm: Do not emit warnings upon receiving notification748e233server: don't treat unestablished GR peers as having sent EORc4fd8f2pkt/server: return error instead of panic on invalid SourceId in AddPathStreamd43ff16feat: add as-path-options params for peer-group api and config parser1affa9adocs(bfd): add docs for using and configuring bfd session state detectione0d6b99fix(table): preserve last action for the same path in coalesced updatesf9448f0feat: add local caps and peer-group to watchEventPeer77a5cb0fix(bfd): fix peer shutdown, remote down, and default port4ebc2d3fix(bfd): fix goroutine leak, safe public API, remove read event loop0aef2d8feat(bfd): add BFD server and peer state machine89ec8adfix(cmd): avoid nil pointer panic in CLI when NLRI cannot be decodedf0a540bfeat(table): extract communityAnyIndex and add fast match for ext-commsdf0fb4dtable: Do not emit warnings upon no-op withdrawals78d1c56fsm: Do not emit warnings upon sending notificationc246294refactor(table): drive UpdatePathAttrs from PeerInfo only.accb63bfeat(table): extend PeerInfo and add peer-group helpers for policy paths Expand PeerInfo with PeerType, route-server flags, remove-private-as, peer group name, and related neighbor/group fields so table logic can treat peer-group shared-policy paths consistently with per-peer paths.a89819erefactor(config): move IsConfederation methods from Neighbor to Global3be7559perf(table): bitmap-based fast path for standard BGP CommunitySetace3800fix(server): compare ECMP paths against best path, not predecessored9ec4ffix(cmd/gobgp): allow multiple RTs in mup route commands941f597packet/bgp: propagate errors and enforce length bounds in BGP-LS NLRI decoders5d52dd1packet/bgp: prevent nil pointer panic in TunnelEncapSubTLVSRBSID String and MarshalJSON7b3e555packet/bgp: reject malformed MPLS label stacks missing bottom-of-stack bitb6bfd5dapiutil: add tests for UnmarshalSRSegments nil Flags and round-tripb22177efix(apiutil): nil-safe Flags access in UnmarshalSRSegmentsf02ca39packet/bgp: enforce CapLen boundary in BGP OPEN capability decoders2ee365dfix: preserve unknown IPv6 Extended Communities in round-trip encodingdd70de7fix: evpn type2 handling without ip3072fe9fix: nil pointer dereference for local paths in WatchPostUpdatev4.5.0Compare Source
Changelog
5f19106GoBGP 4.5.0264380bfix bgp-ls mt-id rib collision7899bb9docs: recommend GOAMD64=v3 for maximum performance on AMD648448d2ccorrect sub-TLV length validation in BGP-LS decoders010d6a5feat(bfd): align BFD API90adc4afeat(bfd): align BFD schema with OpenConfig conventions4be569afeat: propagateBucketa50fb45feat: zebra client nexthopCache need to be accessed under lockd60caf4stopNeighbor under write lock57c66eaadd FSMHandler race testsd1cc36as.shared.mu.RWLockd6deb01feat(bfd): parse and encode Diagnostic field per RFC 5880 §4.14d989d8feat: consistent routing update35aa05afix(rtc): fix VPN path indexing — track best path (no-add-path) or all path-IDs (add-path)ae1a568feat(bfd): add RFC 5880 BFD packet codec8de689fchore(spell): add reuseaddr to spell-check dictionary SO_REUSEADDR is a standard POSIX socket option name; scspell3k doesn't recognize the combined token 'reuseaddr'.)4d098c9feat(netutils): add SetUDPTTLSockopt and SetReuseAddrSockopt helpersd12f363watcher: serialize new watcher registration9aec25fbmp: fix reconnect on write error640b3a6table: eliminate string round-trips in Select for IPv4/IPv6 UC00c7a4btable: fix shorter-prefix lookup returning only the first match for IPv4/IPv6 UCbe2b9e9apiutil: fix wrong lookup option when converting from proto enumd2d2be3table: skip paths with unconfigured family in AdjRib.Update35adaa5zebra: use netip.Addr as nexthopStateCache key153a25etest: use assert_several_times in zapi_v3 test83c341dtest: replace OSPF with static routes in zebra-nht teste26c0cctable: add unit test for new path with invalid nexthopb21a8a7test: expand unit tests for nexthopStateCache62e965afeat: (table/server) add VPN path RT index for O(1) RTC candidate lookup631de4cfix: rpki server listing panics97ca4e7test: increase NHT test timeouts for CI stabilityf20b97aserver: fix nil pointer dereference in prePolicyFilterpathb4e240etable: treat nexthop-invalid best path as no best in GetChanges075fb4cfeat: rework RTC handling with RouteTargetMembershipHandlerc86f89eCoalesce outgoing BGP UPDATE messages11d0013fix: ipv6 link local address with zone0d2f89drefactor: replace rtc handling logic to separate place. Key changes: 1. Move rtc registering logic to separate file 2. A little name and comments refactoring 3. Unit tests for rtc registering logic7cdba63server: fix goroutine leak when WatchEvent outlives Serve9695ed2Replace rtCounter (map[uint64]int) with adjRTSet (map[uint64]map[adjRTKey]struct{})55e5242ci: replace bufbuild/buf-setup-action with go installf4143feci: update GitHub Actions to Node 24 compatible versions0534445fix bmp config map issuea81d63dgobgpd: Fix printing of help message4643cbaAdd security policy for vulnerability reporting2df9ff3atomic peerinfo or lock prefixLimitWarned, llgrEndChs9b36d84server: Use State instead of Config to determine GR-enabled peers in StopBgpv4.4.0Compare Source
Changelog
12b4ebaGoBGP 4.4.07e767a8packet/bgp: use buffer length for sr-policy segment list parsing loop conditionf9f7b55packet/bgp: fix infinite loop when decoding srv6 unknown sub-TLV typesf842cdfpacket/bgp: prevent uint16 underflow in BGP-LS sub-TLV length tracking76d9110packet/mrt: fix uint16 underflow in parseRibEntry path attribute loopbc77597packet/bmp: validate ParseBody input length before reading fields51ad1adpacket/bgp: Fix AIGP PathAttribute parser to return errors215aee0fix: prevent nil dereference on BGP UPDATE validation and fix variable shadowing2814e72fix: handle keepalive write error in openconfirm state60f548enetip: use github.com/gaissmai/bart Trie52fa007build(deps): bump google.golang.org/grpc from 1.73.0 to 1.79.3ad39ab1test: fix race in TestWatchEventaf16fb5remove Locked suffix on internal APIaf29736cleanup Destinations RLock, iterate on per shard lock89b5acdadj.walkActive835fb96table manager cache maxPathCountedb48d135table destination SelectDestinationLocked44a9abctable manage don't expose internal maps0abababtable/path: fix race on attrsHash91337e9tests: add race tests for table managerb55a5dbEVPNMacNLRIs thread safe5a62b66table manager lock49e5a2atable dest shard locks4819eb3](https://redirectConfiguration
📅 Schedule: (UTC)
* * * * 1-5)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.