Skip to content

chore(deps): update go modules (non-major) - #219

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-modules-(non-major)
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-modules-(non-major)

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
github.com/aws/aws-sdk-go-v2 v1.47.1 → v1.47.2 age confidence
github.com/aws/aws-sdk-go-v2/credentials v1.20.6 → v1.20.8 age confidence
github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.23.10 → v1.23.13 age confidence
github.com/aws/aws-sdk-go-v2/service/s3 v1.113.4 → v1.114.2 age confidence
github.com/aws/smithy-go v1.28.2 → v1.28.4 age confidence
github.com/oasdiff/oasdiff v1.32.1 → v1.33.0 age confidence
github.com/open-policy-agent/opa v1.21.0 → v1.21.1 age confidence
github.com/prometheus/client_golang v1.24.1 → v1.25.0 age confidence
github.com/redis/go-redis/v9 v9.22.0 → v9.23.0 age confidence
go.opentelemetry.io/contrib/bridges/otelslog v0.20.1 → v0.21.0 age confidence
go.opentelemetry.io/otel v1.46.0 → v1.47.0 age confidence
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.22.0 → v0.23.0 age confidence
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp v0.22.0 → v0.23.0 age confidence
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.46.0 → v1.47.0 age confidence
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.46.0 → v1.47.0 age confidence
go.opentelemetry.io/otel/sdk v1.46.0 → v1.47.0 age confidence
go.opentelemetry.io/otel/trace v1.46.0 → v1.47.0 age confidence
golang.org/x/net v0.59.0 → v0.60.0 age confidence
golang.org/x/tools v0.50.0 → v0.51.0 age confidence

Release Notes

aws/aws-sdk-go-v2 (github.com/aws/aws-sdk-go-v2)

v1.47.2

Compare Source

Module Highlights

  • github.com/aws/aws-sdk-go-v2/service/customerprofiles: v1.49.0
    • Feature: The release updates standard profile with 2 new fields that supports account-level engagement. Updated APIs include CreateProfile, UpdateProfile, MergeProfiles, SearchProfiles, BatchGetProfile, GetSegmentMembership, CreateSegmentDefinition, CreateSegmentEstimate.
  • github.com/aws/aws-sdk-go-v2/service/ec2: v1.239.0
    • Feature: Added support for the force option for the EC2 instance terminate command. This feature enables customers to recover resources associated with an instance stuck in the shutting-down state as a result of rare issues caused by a frozen operating system or an underlying hardware problem.
  • github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2: v1.47.2
    • Documentation: This release enables secondary IP addresses for Network Load Balancers.
  • github.com/aws/aws-sdk-go-v2/service/entityresolution: v1.21.0
    • Feature: Add support for creating advanced rule-based matching workflows in AWS Entity Resolution.
  • github.com/aws/aws-sdk-go-v2/service/glue: v1.121.0
    • Feature: Added support for Route node, S3 Iceberg sources/targets, catalog Iceberg sources, DynamoDB ELT connector, AutoDataQuality evaluation, enhanced PII detection with redaction, Kinesis fan-out support, and new R-series worker types.
  • github.com/aws/aws-sdk-go-v2/service/inspector2: v1.40.0
    • Feature: Extend usage to include agentless hours and add CODE_REPOSITORY to aggregation resource type
  • github.com/aws/aws-sdk-go-v2/service/iot: v1.66.0
    • Feature: This release allows AWS IoT Core users to use their own AWS KMS keys for data protection
  • github.com/aws/aws-sdk-go-v2/service/opensearch: v1.49.0
    • Feature: Granular access control support for NEO-SAML with IAMFederation for AOS data source
  • github.com/aws/aws-sdk-go-v2/service/quicksight: v1.90.0
    • Feature: Added Impala connector support
  • github.com/aws/aws-sdk-go-v2/service/s3control: v1.62.0
    • Feature: Add Tags field to CreateAccessPoint
  • github.com/aws/aws-sdk-go-v2/service/sesv2: v1.49.0
    • Feature: This release introduces support for Multi-tenant management
  • github.com/aws/aws-sdk-go-v2/service/workspacesweb: v1.29.0
    • Feature: Added ability to log session activity on a portal to an S3 bucket.
aws/smithy-go (github.com/aws/smithy-go)

v1.28.4

Compare Source

General Highlights

  • Dependency Update: Updated to the latest SDK module versions

Module Highlights

  • github.com/aws/smithy-go: v1.28.4
    • Bug Fix: Revert #​698 that fixed JoinPath with trailing slash. This has a side effect on certain S3 API paths in the downstream SDK that need more consideration.

v1.28.3

Compare Source

General Highlights

  • Dependency Update: Updated to the latest SDK module versions

Module Highlights

  • github.com/aws/smithy-go: v1.28.3
    • Bug Fix: Accept either casing of message/Message on modeled JSON error structures in schema-based deserialization, and emit the smithy.api#error trait in generated schemas
    • Bug Fix: Include the underlying error when logging failures to discard or close an HTTP response body
oasdiff/oasdiff (github.com/oasdiff/oasdiff)

v1.33.0

Compare Source

Recursive schemas: fast, deterministic, and no longer repeated per path

v1.32.0 could run for hours on a spec whose schemas reference each other in cycles, and v1.32.1 fixed that by returning to v1.31.0's cycle handling, which gave up the deterministic output v1.32.0 had introduced. This release reworks the handling so that both hold at once, on the two specs reported in #​1252 and on everything else.

Thanks @​simonbility for the report and the specs, @​philippnagel for the second spec and for testing the release candidate against it, and @​BigMichi1 for the determinism report that started this.

CLI changes

Recursive schemas

  • Specs with cyclic schemas compare in about a second, with or without --flatten-allof (#​1254, fixes #​1252). The two specs reported there are the measure: one needed --flatten-allof and ran for hours, the other has 134 schemas referencing each other in a single cycle and never finished at all. Both now complete in about a second, including the combination v1.32.1 could not do.
  • Structured output for a schema in more than one reference cycle is deterministic again (fixes #​1230). v1.32.0 fixed this, v1.32.1 had to revert it to get rid of the hang, and this release has both. Identical inputs produce identical bytes.
  • --flatten-allof keeps one copy of each schema. It used to copy a schema once for every place that referenced it: one reported spec grew from 5,195 schema objects to 3.5 million in memory. The flattened output is unchanged, and flattening it now takes milliseconds rather than seconds.
  • A change inside a recursive schema is reported once per entry into the cycle rather than once for every path through it. Every operation that reaches the change still reports it. On one reported spec a single added property produced 241,978 changelog lines before and 9,162 now.
  • A cycle edge no longer repeats one level of the diff, and a $ref-to-inline refactor inside a cycle is recognized as a refactor, the same as one outside a cycle.

Upgrading from v1.32.1

  • The circularRef field is removed from diff --format json|yaml output again, as in v1.32.0: cyclic-reference mismatches appear as ordinary field-level diffs, which say more. v1.32.1 had restored it along with v1.31.0's cycle handling.
  • Diffs of schemas that take part in more than one reference cycle change once, and then hold steady.
Go package changes
  • Breaking: diff.SchemaDiff.CircularRefDiff is removed again (#​1254), together with the ref-string circular guard, as in v1.32.0. v1.32.1 had restored both.
  • flatten/allof.MergeSpec merges a document with one state (#​1254), so a schema referenced from several places stays one object after the merge.
open-policy-agent/opa (github.com/open-policy-agent/opa)

v1.21.1

Compare Source

This release fixes a compiler regression introduced in OPA v1.21.0.

Fix some … in/every in comprehensions nested in object and set literals (#​9280)

A comprehension using some … in or every in its body, nested inside an object or set literal, was wrongly treated as ground, so the compiler skipped rewriting it. some … in then failed with rego_unsafe_var_error; every caused a compiler panic:

package example

p := {"k": [r.a | some r in input.xs]}           # rego_unsafe_var_error: var r is unsafe

q := {[1 | every x in input.xs { x > 0 }]}       # panic

Array literals weren't affected, and neither were literals that contain some other non-ground term.

authored by @​srenatus, reported by @​tun0

prometheus/client_golang (github.com/prometheus/client_golang)

v1.25.0

Compare Source

⚠️ This release raises the minimum required Go version to 1.26 and includes breaking API changes in api/prometheus/v1 (see the [CHANGE] entries below). ⚠️

1.25.0 / 2026-10-07

  • [CHANGE] Minimum required Go version is now 1.26, only the two latest Go versions (1.26 and 1.27) are supported from now on. #​2138
  • [CHANGE] api/prometheus/v1: Query, QueryRange, Series, LabelNames, and LabelValues now return Infos annotations in addition to Warnings, matching the Prometheus server's info annotations. This changes the signatures of these methods and of api.Client's Do/DoGetFallback; custom API client implementations must be updated. #​1963
  • [CHANGE] api/prometheus/v1: Rework TSDBBlocks result types to align with the Prometheus server's tsdb.BlockMeta: TSDBBlocksResult now contains Blocks []TSDBBlockMeta directly instead of mirroring the full API envelope, nested types are renamed (TSDBBlockMeta, TSDBBlockStats, TSDBBlockMetaCompaction), stat fields are uint64 with omitempty tags, and the optional compaction parents field is included. #​1928
  • [FEATURE] testutil: Add GatherAndFormat to encode a subset of metrics from a Gatherer. #​2091
  • [FEATURE] promhttp: Add HandlerOpts.AcceptedFormats to customize the formats negotiated from the incoming Accept header, enabling opt-in to experimental formats such as OpenMetrics 2.0 without changing default negotiation. #​2146
  • [ENHANCEMENT] promhttp: Negotiated metrics responses now include a Vary header. #​2142
  • [ENHANCEMENT] prometheus: Regenerate the default runtime collector metrics for Go 1.25 and Go 1.26. #​2090, #​2095
  • [ENHANCEMENT] testutil: Finalize OpenMetrics output in GatherAndFormat and CollectAndFormat (terminating # EOF). #​2125
  • [BUGFIX] api: Match complete URL path placeholders only; a :foo argument no longer substitutes inside :foobar. #​2136
  • [BUGFIX] exp/api/remote: Reset the pooled buffer before generic proto marshaling, preventing corrupted remote-write payloads. #​2139
  • [BUGFIX] testutil/promlint: Fix "mibi" unit prefix to "mebi". #​2135
What's changed

What's Changed

New Contributors

Full Changelog: prometheus/client_golang@v1.24.1...v1.25.0

redis/go-redis (github.com/redis/go-redis/v9)

v9.23.0: 9.23.0

Compare Source

This is a minor release. It contains everything from 9.23.0-beta.1, so these notes cover the full 9.22.0 → 9.23.0 upgrade.

⚠️ Changes to check when you upgrade from 9.22.0:

  • Go 1.26 is now the minimum Go version (#​4060). The go directive of the root module and of the submodules moved from 1.24 to 1.26, as part of the dependency bumps for govulncheck findings. Projects that build with Go 1.24 or 1.25 must upgrade the toolchain.
  • Each Client has a dedicated pipeline connection pool (#​4002). This includes failover clients and cluster node clients. Pipeline, TxPipeline, and autopipeline operations use this pool, so they do not compete with regular commands for main-pool connections. The pool is for burst capacity only: it dials only when necessary, an unused pool holds zero connections, and if the pool is full an operation uses the main pool. Set PipelinePoolSize: -1 to get the previous single-pool behavior.
  • AutoPipelineOptions.MaxBatchBytes has a default of 128 KiB (before, there was no limit). The default prevents a write/reply deadlock; it is not a throughput control. The buffers of the pipeline pool also have a default of 128 KiB.

⚠️ Changes to experimental APIs since 9.23.0-beta.1 (no effect if you upgrade from 9.22.0):

  • AutoPipelineOptions.FullDuplexFastSubmit is removed (#​4018). The submit channel is replaced by a queue that takes a full wave of commands in one lock, so the separate fast path is not necessary. Remove the field from your options.
  • Options.ClientSideCacheRefreshRecencyWindow is removed (#​4034). Refresh-on-invalidate now reads again every cached entry of an invalidated key and does not look at how recently the entry was read. On a write-heavy keyspace this means refresh traffic across the full resident cache. Remove the field from your options.
  • LocalCache.LRUClock() is removed (#​4034). It returned the recency token that the removed recency window used, and has no replacement. Remove calls to it.
  • ClientSideCacheInvalidationBatchWindow served stale values in beta.1 (#​4033). Under load the batcher applied only ~15% of invalidations, and the cache served invalidated values with a ~100% hit rate. 9.23.0 applies all of them. If you used this option on beta.1, upgrade.

🚀 Highlights

Full-Duplex Auto-Pipelining (Experimental)

Set AutoPipelineOptions.FullDuplex to enable the full-duplex mode of the automatic pipeliner. The default mode sends one batch per round trip. In full-duplex mode the engine holds one pipeline-pool connection, and a writer goroutine and a reader goroutine move the ordered command stream in both directions at the same time. On a high-latency link each command completes in approximately one round-trip time (RTT) on a single connection. On a 50 ms WAN profile: ~389k ops/s at 52 ms p50, against ~207k ops/s at 116 ms on the half-duplex ordered path.

The mode works on both faces of a standalone Client (AutoPipeline() and AsyncAutoPipeline()), and natively on a ClusterClient when routing goes to masters only. On a cluster, one child engine per master sends each command to the node that owns its slot, and follows MOVED / ASK redirects and retryable replies (LOADING, READONLY, ...) through the usual cluster redirect path. With replica routing (ReadOnly, RouteByLatency, or RouteRandomly), the autopipeliner uses the half-duplex shard flushers, which obey the shard picker. Config().FullDuplex reports the mode in effect.

Options:

  • FullDuplexWindow — the maximum number of commands in flight (backpressure).
  • FullDuplexIdleTimeout and FullDuplexMaxHold — when the engine returns the held connection to the pool. The pool hooks then do re-authentication and maintenance-notification handoffs.
  • MaxFlushDelay — now also used in full-duplex mode (#​4014). The writer waits only when enough commands are in flight, so low-concurrency callers keep the 1×RTT behavior. With MaxFlushDelay=250µs at 1024 callers: +22% ops/s and −26% p99. The default is 0, so this is opt-in.
  • NumShards — on a standalone Client, the number of full-duplex engines (#​4022). See below.

Pipeline() on the full-duplex connection (#​4021). Standalone Client only. Before, ap.Pipeline() used a pooled connection for each Exec. It now submits the batch to the engine as one contiguous run (FDPipelined), so replies come back in submit order, as on a dedicated connection. At 256–1024 callers with 10 commands per Exec: +49% to +52% throughput on one socket instead of ~150. Errors, retries, hooks, and metrics behave like an ordinary pipeline. A batch that cannot use the stream (a blocking command, a per-command read timeout, a diverted command, or a batch larger than the queue) falls back to the ordinary pipeline. TxPipeline stays on a pooled connection, because MULTI/EXEC needs connection affinity. On a ClusterClient, ap.Pipeline() is still the ordinary cluster pipeline. A batch that the queue cannot admit now reserves its slots and waits in a first-come line, so single commands cannot starve a long pipeline (#​4057, merged as part of #​4021) by @​vlady-kotsev.

Several engines on one client (#​4022). With FullDuplex, NumShards > 1 now means N engines on one client: one pool, one hook chain, N held connections. Commands route by a hash of their first key, so commands on the same key stay on one connection and keep their order without Unordered. Keyless commands are distributed round-robin. An FDPipelined batch stays on one engine. The pipeline pool must hold at least NumShards connections for each full-duplex autopipeliner. More engines help only under high concurrency: with 10-command pipelines, 8 engines were 30% slower than 1 at 8 callers, equal at about 128 callers, and 2.2× faster at 1024 callers.

The full-duplex path supports blocking commands, Options.Limiter (one admission per written batch), per-command and pipeline hooks, OTel metrics, retry budgets (a NoRetry command is never sent again after it is on the wire), and seamless maintenance handoffs. Limits of the stream model:

  • A hook can observe a command, but cannot stop it. A ProcessHook that returns without calling next does not cancel the command on the full-duplex path; the command is already queued on the held connection. Run policy or kill-switch hooks on a plain client or on the half-duplex autopipeliner.
  • Diverted commands are not ordered with the stream. The engine diverts blocking commands, connection-hostile commands, and managed HIMPORT commands. On the async face, wait for the result of a diverted command before you submit a command that depends on it.
  • Single commands on the full-duplex stream do not use the client-side cache. If CSC is enabled, a cacheable command on the stream does not read or write the cache.
  • Duration metrics are recorded per reply. A command that fails before it reaches the reader (lease failure, limiter denial, retry exhaustion, close) calls the error callback but records no operation-duration sample.
rdb := redis.NewClient(&redis.Options{
	Addr: "localhost:6379",
	AutoPipelineOptions: &redis.AutoPipelineOptions{
		FullDuplex: true, // stream commands on one held connection, ~1 RTT each
	},
})
defer rdb.Close()

// Deferred face: calls return immediately; result accessors block until executed.
ap, err := rdb.AsyncAutoPipeline()
if err != nil {
	panic(err)
}
cmds := make([]*redis.StatusCmd, 0, 1000)
for i := 0; i < 1000; i++ {
	cmds = append(cmds, ap.Set(ctx, fmt.Sprintf("key:%d", i), i, 0))
}
for _, cmd := range cmds {
	if err := cmd.Err(); err != nil {
		// handle error
	}
}

// Or the blocking face — a drop-in Cmdable where each call blocks like a
// plain client while concurrent callers share the full-duplex pipe:
//	ap, err := rdb.AutoPipeline()
//	val, err := ap.Get(ctx, "key").Result()

Runnable examples: example/autopipeline (all faces), example/autopipeline-fullduplex (blocking face, Pipeline() and FDPipelined), and example/autopipeline-fullduplex-async (async face, Submit, NumShards) (#​4061).

Experimental: the auto-pipelining APIs can change in a minor release.

(#​4002, #​4014, #​4018, #​4021, #​4022) by @​ndyakov

Client-Side Caching: Refresh-on-Invalidate, Miss Coalescing, Faster Reads

Two new functions for the experimental shared-tracking client-side cache. They have no effect unless CSC is enabled (#​3989) by @​ndyakov:

  • Refresh-on-invalidate (Options.ClientSideCacheRefreshOnInvalidate): when an invalidation push arrives, the client reads every cached entry of that key again in the background, so the next reader does not pay the miss. Each invalidation of a cached key costs one background read. ClientSideCacheInvalidationBatchWindow collects invalidation-driven deletes into background batches; without it, the connection reader applies each delete inline.
  • Miss coalescing (Options.ClientSideCacheCoalesceMisses): concurrent cache misses are pipelined on one tracked connection. Each miss keeps its own per-key command (no rewrite to MGET), so it is safe on a cluster. Each reply is written to the cache with the connection's tracking generation, so the server can invalidate it.

Both options need the built-in cache (ClientSideCacheConfig, or ClientSideCache set to a *LocalCache). With a custom Cache implementation they are ignored.

The cache read path is also faster (#​4034, #​4035, #​4036, #​4037) by @​ndyakov. A hit no longer writes a timestamp to the entry; a second-chance bit marks reads, and is set only under eviction pressure. The cache key is built in pooled scratch memory, the key list is built only on a miss, and nil/status/bulk-string hits are decoded without allocation. Against 9.23.0-beta.1 on a warm cache: +18% to +57% reads/s from 4 to 1024 callers, p50 from 2.6–5.4 µs to 1.0–1.5 µs, with identical hit rates and 100% of invalidations applied.

Better Distribution for Latency-Based Cluster Read Routing

RouteByLatency selects the node with the strictly minimum latency. The measurement has noise (the mean of ten pings, refreshed at most every 10 s), so all clients can select the same node from a set of nodes with almost equal latency. In one production system, GET rates across five replicas in one availability zone had a 590× spread.

The new ClusterOptions.RouteByLatencyTolerance widens the selection to every node within the tolerance of the fastest node, and distributes reads across them round-robin with the ShardPicker. A node in a different availability zone stays outside a sensible tolerance, so zone locality is kept. The default is zero (strict minimum). The option is also on FailoverOptions, for clients from NewFailoverClusterClient; the plain NewFailoverClient does not support latency routing. (#​3973) by @​jozenstar

The same work fixed a routing defect: the client recorded the nearest healthy node only when that node was also the fastest overall. A node that fails fast (for example, a refused connection) hid every healthy node, and reads went to the failing node. The client now records the healthy minimum separately. (#​3994) by @​jozenstar

EphemeralConn for Session-Scoped Work

Client.Conn() returns its connection to the parent pool on Close. If you ran AUTH or SELECT on it, later commands on the pooled client run as that ACL user and in that DB. The new Client.EphemeralConn() returns the same sticky connection, but Close removes it from the pool instead. The cost is one dial per EphemeralConn. Client.Conn() is unchanged. (#​4039) by @​saddamr3e

✨ New Features

  • Full-duplex auto-pipelining: AutoPipelineOptions.FullDuplex, with FullDuplexWindow / FullDuplexIdleTimeout / FullDuplexMaxHold, on standalone and cluster clients (#​4002) by @​ndyakov
  • Pipeline() on the full-duplex connection: ap.Pipeline() and FDPipelined submit a batch to the engine as one contiguous run, on a standalone Client (#​4021) by @​ndyakov
  • Several full-duplex engines on one client: NumShards > 1 with FullDuplex on a standalone Client, with key-hash routing (#​4022) by @​ndyakov
  • AutoPipelineOptions.MaxQueuedCommands: an opt-in hard limit on accepted, not-yet-completed autopipeline commands. At the limit a command fails immediately with ErrAutoPipelineQueueFull, so memory does not grow without limit when the server is slow. With FullDuplex, the ordered stream is bounded by FullDuplexWindow instead (a full window blocks the submitter, it does not reject), and MaxQueuedCommands limits only the commands that run outside the stream (blocking, connection-hostile, Do). The default 0 means no limit (#​4070) by @​ndyakov
  • Dedicated pipeline pool by default: PipelinePoolSize has a default of DefaultPipelinePoolSize (10) on each client. If the pool is full, an operation uses the main pool. Set -1 to disable the pool (#​4002, #​3959) by @​ndyakov
  • CSC refresh-on-invalidate and miss coalescing: Options.ClientSideCacheRefreshOnInvalidate (with ClientSideCacheInvalidationBatchWindow) and Options.ClientSideCacheCoalesceMisses (#​3989) by @​ndyakov
  • Client.EphemeralConn: a sticky connection that is removed from the pool on Close, for session-scoped AUTH / SELECT work (#​4039) by @​saddamr3e
  • RouteByLatencyTolerance: distributes reads across nodes with almost equal latency, on cluster clients and on NewFailoverClusterClient (#​3973) by @​jozenstar
  • AutoPipeliner.WaitClosed: blocks until the drain of accepted commands completes, and returns the drain result. Use it in a wrapper that must not close shared pools during a flush (#​3998) by @​ndyakov
  • redisotel-native WithRecordNilErrors: opt in to count redis.Nil replies as client errors (see the fix below) (#​4025) by @​lazerg
  • CMSInfo.CellSize: the cell-size field of CMS.INFO in Redis 8.12 (#​4010) by @​elena-kolevska

🐛 Bug Fixes

  • CSC invalidation batching: ClientSideCacheInvalidationBatchWindow applied only ~15% of invalidations under load, so the cache served stale values with a ~100% hit rate. Each batch now takes each shard lock once, and 100% of invalidations are applied (#​4033) by @​ndyakov
  • Pool waiter wake-ups: Put did not wake a worker that waited for a connection to become IDLE, so a streaming-credentials re-auth could stall until PoolTimeout and then close the connection (#​4028) by @​avitenzer. Two related waiter-queue races are fixed: a failed transition left a dead waiter queued, which later moved a connection to UNUSABLE for nobody (#​4072) by @​ndyakov
  • Command key positions: 16 typed commands (BitOp*, MIGRATE, OBJECT ENCODING/FREQ/IDLETIME/REFCOUNT, XINFO STREAM/GROUPS/CONSUMERS, LMPOP, BLMPOP, SINTERCARD, ZINTERCARD, ZMPOP, BZMPOP) routed by the wrong argument. On a Ring they went to the wrong shard; on a cluster they cost an extra MOVED round trip. A raw FCALL / FCALL_RO hashed the function name. All now route by their key (#​4048) by @​ndyakov. Raw XGROUP, ZUNION / ZINTER / ZDIFF, SDIFFCARD / SUNIONCARD, TS.NRANGE / TS.NREVRANGE, and HIMPORT SET forms are also fixed (#​4022)
  • Millisecond expirations: PExpireAt, HPExpireAt, and HPExpireAtWithArgs overflowed for dates outside the nanosecond range (for example, year 2270), so Redis deleted the key or rejected the command (#​4026) by @​jakezwang. SetArgs.ExpireAt now sends PXAT when the deadline has millisecond precision; before, EXAT dropped the milliseconds (#​4053) by @​LindseyZ1205
  • Cluster -1 timeouts: a -1 read/write timeout on ClusterOptions gave node clients the 5 s default instead of no timeout (fixes #​4049) (#​4050) by @​lazerg
  • OTel redis.Nil as error: a cache miss (redis.Nil) incremented redis.client.errors and was tagged as a server error on db.client.operation.duration. Nil replies are now classified NIL and not counted, unless WithRecordNilErrors(true) is set (fixes #​4024) (#​4025) by @​lazerg
  • Credential redaction: SENTINEL SET ... auth-pass is now redacted in command rendering (used by redisotel / rediscensus span attributes), and a MIGRATE password with the literal value auth / auth2 is redacted at the correct position (#​4011) by @​saddamr3e
  • Min/max aggregator panic: a non-numeric shard reply made AggMinAggregator / AggMaxAggregator panic instead of returning an error from Result() (#​4056) by @​Suselz
  • ParseURL skip_verify: an invalid value (for example, skip_verify=yes) was silently treated as false. ParseURL and ParseFailoverURL now return an error, like for the other boolean options (#​4064) by @​orinnz
  • uintptr arguments: uintptr and *uintptr are now encoded like the other unsigned integers; a nil *uintptr is encoded as 0 (fixes #​3100) (#​4054) by @​yamaankhan20
  • Cluster read routing

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Oct 5, 2026
@renovate

renovate Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 16 additional dependencies were updated

Details:

Package Change
github.com/klauspost/compress v1.20.0 -> v1.20.1
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.46.0 -> v1.47.0
go.opentelemetry.io/otel/metric v1.46.0 -> v1.47.0
google.golang.org/genproto/googleapis/api v0.0.0-20260819154853-08b0e4226688 -> v0.0.0-20260928230214-8a89bd6388cc
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.20 -> v1.7.21
github.com/aws/aws-sdk-go-v2/internal/configsources v1.5.4 -> v1.5.5
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.8.4 -> v2.8.5
github.com/aws/aws-sdk-go-v2/internal/v4a v1.5.4 -> v1.5.5
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.19 -> v1.13.20
github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.11.5 -> v1.11.6
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.14.4 -> v1.14.5
github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.20.4 -> v1.20.5
github.com/prometheus/common v0.70.1 -> v0.72.0
go.opentelemetry.io/otel/log v0.22.0 -> v1.47.0
go.opentelemetry.io/otel/sdk/log v0.22.0 -> v1.47.0
go.uber.org/atomic v1.11.0 -> v1.12.0

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: f86004e4-6119-402e-89b5-333abbc20c68

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/go-modules-(non-major) branch 3 times, most recently from a954a79 to fca819a Compare October 8, 2026 13:52
@renovate
renovate Bot force-pushed the renovate/go-modules-(non-major) branch from fca819a to 205e14e Compare October 8, 2026 20:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants