centrifugal / centrifugo

Scalable real-time messaging server in a language-agnostic way. Self-hosted alternative to Pubnub, Pusher, Ably. Set up once and forever.
https://centrifugal.dev
Apache License 2.0
8.45k stars 598 forks source link

Bump the go-packages group with 4 updates #793

Closed dependabot[bot] closed 7 months ago

dependabot[bot] commented 8 months ago

Bumps the go-packages group with 4 updates: github.com/centrifugal/protocol, github.com/nats-io/nats.go, github.com/quic-go/quic-go and github.com/quic-go/webtransport-go.

Updates github.com/centrifugal/protocol from 0.12.0 to 0.12.1

Commits


Updates github.com/nats-io/nats.go from 1.33.1 to 1.34.0

Release notes

Sourced from github.com/nats-io/nats.go's releases.

Release v1.34.0

Changelog

Added

  • Core NATS:
    • StatusChanged method for subscription event notifications (#1570)
    • ClientTLSConfig option for setting TLS config with callbacks in Connect (#1413)

Fixed

  • Object Store:
    • Add missing Compression struct tag (#1559)
  • Legacy JetStream:
    • Fetch and FetchBatch will no longer publish a pull request if the subscription is closed or draining (#1582)
  • Service API:
    • Fixed incorrect error handling when creating a service. Thanks @​ramonberrutti for the contribution (#1585)

Improved

  • Object Store:
  • Add testing section and format CONTRIBUTING.md. Thanks @​yordis for the contribution (#1574)
  • Improved performance of respToken in muxer. Thanks for the report @​chgz (#1575)
  • Fixed typos in comments. Thanks @​paoloteti for the contribution (#1581)

Complete Changes

https://github.com/nats-io/nats.go/compare/v1.33.1...v1.34.0

Commits
  • 33316cd Release v1.34.0 (#1587)
  • 3ba8e08 [IMPROVED] Add test checking if client reconnects after jwt expires (#1586)
  • 8ba3483 Merge pull request #1585 from ramonberrutti/fix-stop-error
  • dd3a093 [FIXED] Incorrect stopErr used
  • 6dfefd9 [IMPROVED] Fetch and FetchBatch for draining and closed subscriptions (#1582)
  • 85e6223 Release v1.33.1 (#1558)
  • aefaeac [IMPROVED] Missing section in jetstream readme ToC (#1557)
  • 4bc3ea9 [IMPROVED] Fixed typos in comments (#1581)
  • 92c4a99 [ADDED] StatusChanged for core and js subscriptions (#1570)
  • 52a2d33 [IMPROVED] Bind Streams in Object Store Watchers (#1578)
  • Additional commits viewable in compare view


Updates github.com/quic-go/quic-go from 0.41.0 to 0.42.0

Release notes

Sourced from github.com/quic-go/quic-go's releases.

v0.42.0

New Features

  • added a qlog tracer for events that happen before / outside of established connection: #4305

Notable Changes

  • added a ClientHelloInfo.AddrVerified field: #4360
  • move callback controlling address verification (VerifySourceAddress) to the Transport: #4253 and #4362
  • connections that are closed before being accepted are not removed from the server's accept queue: #4245
  • http3: added a RoundTripOpt.CheckSettings callback to check the server's SETTINGS: #4355
  • http3: send the HTTP/3 settings value for Extended CONNECT (RFC 9220): #4341
  • http3: don't modify the user's quic.Config to enable QUIC datagram support: #4340

Fixes

  • mitigate a memory exhaustion attack against QUIC's connection ID mechanism: #4369
  • don't delay acknowledgments for packets during the handshake: #4279
  • fix deadlock when closing both Listener and Transport: #4332
  • fix handling of IPv4-mapped IPv6 addresses: #4309
  • fix duplicate logging of the key_discarded event for Handshake packets: #4274
  • send CONNECTION_REFUSED when refusing connections: #4250
  • http3: tighten validation logic for the :protocol pseudo header: #4261

What's Changed

... (truncated)

Commits
  • 4a99b81 close connection when an abnormally large number of frames are queued (#4369)
  • 9971fed use Transport.VerifySourceAddress to control the Retry Mechanism (#4362)
  • 497d3f5 http3: add a RoundTripOpt to check the server's SETTINGS frame (#4355)
  • ca787d6 add an AddrVerified field to the ClientHelloInfo (#4360)
  • f147639 update gomock to v0.4.0 (#4361)
  • 06b4214 remove unused ReceiveStream.CloseRemote method (#4357)
  • 5fd5d77 Merge pull request #4305 from quic-go/qlog-tracer
  • 30e01b9 use the transport tracer in integration tests
  • 55c05ac qlog: log sent packets outside of a QUIC connection
  • aff90a6 qlog: log sent Version Negotiation packets
  • Additional commits viewable in compare view


Updates github.com/quic-go/webtransport-go from 0.6.0 to 0.7.0

Release notes

Sourced from github.com/quic-go/webtransport-go's releases.

v0.7.0

Breaking Changes

Before v0.7.0, the server (incorrectly) didn't advertise support the Extended CONNECT extension. With quic-go/quic-go#4341, it now does. The client now checks for Extended CONNECT support, and aborts the handshake if the server doesn't support it. This means that v0.7.0 clients are now incompatible with pre-v0.7.0 servers.

What's Changed

New Contributors

Full Changelog: https://github.com/quic-go/webtransport-go/compare/v0.6.0...v0.7.0

Commits
  • 4080cd5 check the server's HTTP/3 SETTINGS before initiating a session (#120)
  • 748a51d update quic-go to v0.42.0 (#119)
  • 5291157 ci: uci/copy-templates (#129)
  • 2275cd7 ci: bump actions/setup-python from 4 to 5 (#128)
  • a7777b9 ci: bump nanasess/setup-chromedriver from 1 to 2 (#126)
  • 0478884 ci: bump actions/setup-go from 3 to 5 (#127)
  • 27e56e1 ci: bump actions/checkout from 3 to 4 (#125)
  • a30555b enable Dependabot for GitHub Actions (#124)
  • 73e793a ci: update ChromeDriver to v114.0.5735.90 in interop test (#123)
  • 4f3d108 set the H3 WebTransport setting on the client side (#105)
  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
dependabot[bot] commented 7 months ago

Looks like these dependencies are no longer updatable, so this is no longer needed.