Skip to content

build(deps): bump google.golang.org/grpc from 1.82.0 to 1.82.1 - #1717

Merged
imjasonh merged 1 commit into
mainfrom
dependabot/go_modules/google.golang.org/grpc-1.82.1
Jul 24, 2026
Merged

build(deps): bump google.golang.org/grpc from 1.82.0 to 1.82.1#1717
imjasonh merged 1 commit into
mainfrom
dependabot/go_modules/google.golang.org/grpc-1.82.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 24, 2026

Copy link
Copy Markdown
Contributor

Bumps google.golang.org/grpc from 1.82.0 to 1.82.1.

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.82.1

Security

  • server: Stop reading from the connection when flooded by HTTP/2 frames. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT.
  • xds/rbac: Support Metadata and RequestedServerName permissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open.
  • xds/rbac: Fix panic when parsing unsupported fields in NotRule/NotId permissions.
  • xds/rbac: Support the deprecated source_ip principal identifier by treating it as equivalent to direct_remote_ip.
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note

Low Risk
Lockfile-only patch bump with no ko code changes; low risk though gRPC is used transitively for RPC-heavy tooling (e.g. registry/cosign stacks).

Overview
Bumps the indirect google.golang.org/grpc dependency from 1.82.0 to 1.82.1 in go.mod and go.sum. There are no application or source changes in this PR.

The upstream 1.82.1 release is a patch with security and hardening fixes (e.g. limiting server reads under HTTP/2 frame floods, xDS RBAC matcher and panic fixes). For ko, this is a transitive dependency update only.

Reviewed by Cursor Bugbot for commit 3d3f943. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.82.0 to 1.82.1.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.82.0...v1.82.1)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.82.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jul 24, 2026
@imjasonh
imjasonh enabled auto-merge (rebase) July 24, 2026 12:44
@imjasonh
imjasonh merged commit 4f8fa73 into main Jul 24, 2026
19 checks passed
@imjasonh
imjasonh deleted the dependabot/go_modules/google.golang.org/grpc-1.82.1 branch July 24, 2026 12:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant