fix(deps): update module google.golang.org/grpc to v1.53.0 [security] - autoclosed #261
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.42.0
->v1.53.0
GitHub Vulnerability Alerts
CVE-2023-32731
When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HPACK table mutations to also be skipped, resulting in a desynchronization of HPACK tables between sender and receiver. If leveraged, say, between a proxy and a backend, this could lead to requests from the proxy being interpreted as containing headers from different proxy clients - leading to an information leak that can be used for privilege escalation or data exfiltration. We recommend upgrading beyond the commit contained in https://github.com/grpc/grpc/pull/32309
Release Notes
grpc/grpc-go (google.golang.org/grpc)
v1.53.0
: Release 1.53.0Compare Source
API Changes
resolver.Target.Endpoint
and replace withresolver.Target.Endpoint()
(#5852)New Features
GRPC_RING_HASH_CAP
environment variable to override the maximum ring size. (#5884)Bug Fixes
Documentation
NewOauthAccess
as deprecated (#5882)v1.52.3
: Release 1.52.3Compare Source
Bug Fixes
v1.52.1
: Release 1.52.1Compare Source
Bug Fixes
v1.52.0
: Release 1.52.0Compare Source
New Features
max_ring_size
to reduce possibility of OOMs (#5801)Behavior Changes
Dial
if an empty target is passed and no custom dialer is present; the ClientConn would otherwise be unable to connect and perform RPCs (#5732)Bug Fixes
:authority
header matches server name used in TLS handshake when the latter is overridden by the name resolver (#5748)Documentation
v1.51.0
: Release 1.51.0Compare Source
Behavior Changes
New Features
TRANSIENT_FAILURE
(#5711)Bug Fixes
v1.50.1
: Release 1.50.1Compare Source
New Features
v1.50.0
: Release 1.50.0Compare Source
Behavior Changes
client: use proper "@" semantics for connecting to abstract unix sockets. (#5678)
New Features
ValueFromIncomingContext
to more efficiently retrieve a single value (#5596)HandleConn
context (#5589)Bug Fixes
cluster_specifier_plugin
set to be NACKed when GRPC_EXPERIMENTAL_XDS_RLS_LB was off (#5670)config_source_specifier
inlrs_server
is notself
(#5613)IDLE
instead of falling back on the default channel behavior of connecting to all addresses (#5614)IDLE
(#5656)WaitForReady
on handshaker service RPCs, thereby delaying fallback when required (#5620)v1.49.0
: Release 1.49.0Compare Source
New Features
GRPC_CONFIG_OBSERVABILITY_JSON
(#5525)Behavior Changes
Bug Fixes
nil
stats handler togrpc.WithStatsHandler
orgrpc.StatsHandler
(#5543)IDLE
overTRANSIENT_FAILURE
when aggregating connectivity state (#5473)GRPC_EXPERIMENTAL_ENABLE_OUTLIER_DETECTION
is set to true (#5537)v1.48.0
: Release 1.48.0Compare Source
Bug Fixes
New Features
v1.47.0
: Release 1.47.0Compare Source
New Features
Bug Fixes
Behavior Changes
Documentation
v1.46.2
Compare Source
Bug Fixes
v1.46.1
Compare Source
v1.46.0
: Release 1.46.0Compare Source
New Features
TCP_USER_TIMEOUT
ongrpc.Server
connections usingkeepalive.ServerParameters.Time
(#5219)ClientConn
by default (#5285)API Changes
WithBalancerName()
API, deprecated over 4 years ago in #1697 (#5232)Behavior Changes
TransientFailure
inpick_first
LB policy when all addresses are removed (#5274)Bug Fixes
Dependencies
v1.45.0
: Release 1.45.0Compare Source
Bug Fixes
Performance Improvements
Behavior Changes
Canceled
orDeadlineExceeded
), instead ofUnknown
(#5156)New Features
NewServer(ServerOptions)
for creating a reflection server with advanced customizations (#5197)v1.44.0
: Release 1.44.0Compare Source
New Features
Bug Fixes
Documentation
map
s) must implement Equal (#5109)v1.43.0
: Release 1.43.0Compare Source
API Changes
WithConnectParams
DialOption
(#4915)Behavior Changes
FromContextError
(#4977)New Features
Authority
inBuildOptions
for server name to use in the authentication handshake with a remote load balancer (#4969)Bug Fixes
ClientConn
leak upon resolver initialization failure (#4900)nil
panic in rare race conditions with the pick first LB policy (#4971)Documentation
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.