Skip to content

deps(go): bump github.com/jackc/pgx/v5 from 5.10.0 to 5.11.0 - #1938

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/jackc/pgx/v5-5.11.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/jackc/pgx/v5-5.11.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Bumps github.com/jackc/pgx/v5 from 5.10.0 to 5.11.0.

Release notes

Sourced from github.com/jackc/pgx/v5's releases.

v5.11.0

This release adds direct PostgreSQL type scanning through database/sql on Go 1.27, improves compatibility with libpq connection strings and PostgreSQL date/time values, and includes further decoder hardening. See Changes for connection-string and date/time behavior changes that may affect existing applications.

Features

  • stdlib: support Go 1.27's driver.RowsColumnScanner, allowing PostgreSQL types such as arrays and ranges to be scanned directly into Go values without pgtype.Map.SQLScanner. Existing database/sql scalar conversions and sql.Scanner behavior are preserved. The minimum supported Go version remains 1.25.
  • Add Rows.TypeMap to expose the type map used to decode rows, including rows created by RowsFromResultReader that have no underlying Conn. Custom implementations of Rows, including mocks, must add this method.
  • pgconn: add Config.MaxProtocolMessageBodyLen to configure the maximum incoming protocol message body size (carter-ya)
  • pgconn: add ErrReadOnlyConnection, ErrReadWriteConnection, ErrPrimaryConnection, and ErrStandbyConnection sentinel errors for target_session_attrs validation, allowing callers to use errors.Is (Adrian-Stefan Mares)
  • pgxpool: accept pool_ping_timeout in connection strings to configure Config.PingTimeout. The default is zero; zero and negative durations mean no timeout (1991santhu)

Changes

  • Name-based row-to-struct mapping now matches explicit db tags case-insensitively, with exact matches taking precedence so tags can still distinguish quoted column names that differ only by case (AlisinaDevelo)

  • pgconn: resolve the OS user account only when no user is supplied by the connection string, environment, or service file, avoiding unnecessary account lookups and crashes in some restricted container environments. Home-directory defaults for password, service, and TLS files remain available independently of the account lookup. On Unix these now use $HOME rather than the OS account's home directory (Mohamed MAACHE)

  • pgtype: date, timestamp and timestamptz text values are now parsed and written by a hand-written parser and encoder for PostgreSQL's ISO date/time format instead of time.Parse and time.Format. Go's layout language cannot express a variable-width year or the BC era, which is the root of the bugs below. The text scan path is roughly 2.5x faster for timestamp and timestamptz. Bug fixes:

    • timestamp and timestamptz no longer silently move February 29 of a BC leap year to March 1 when encoding. time.Date(-4712, 2, 29, ...) was written as 4713-03-01 BC and is now written as 4713-02-29 BC. This affected ordinary four-digit BC years, not only extended-range ones. date was never affected.
    • timestamp and timestamptz can now scan BC leap days. 4713-02-29 BC previously failed with day out of range. date could already scan them.
    • Years past 9999 can now be scanned. 10000-01-02 03:04:05 previously failed to parse, so timestamp and timestamptz values at the high end of PostgreSQL's range were unreadable over the simple protocol and in any other text-format result.
    • time.Time arguments in the simple protocol now encode BC dates correctly, using the same timestamp encoder.
    • Fractional seconds beyond microsecond precision are rounded the way the server rounds them (round half to even, carrying into the rest of the value) instead of being kept at full precision. PostgreSQL never sends more than six fractional digits, so this only affects values from other sources.

    Behavior changes:

    • date now rejects impossible dates instead of normalizing them. 2024-02-30 returned 2024-03-01 and 2024-13-01 returned 2025-01-01; both are now errors. timestamp and timestamptz already rejected them.
    • All three types now reject values outside PostgreSQL's range for that type, in the binary format as well as the text format. PostgreSQL never sends out-of-range dates, so this only affects corrupt or hand-built input; the range

... (truncated)

Changelog

Sourced from github.com/jackc/pgx/v5's changelog.

5.11.0 (September 7, 2026)

This release adds direct PostgreSQL type scanning through database/sql on Go 1.27, improves compatibility with libpq connection strings and PostgreSQL date/time values, and includes further decoder hardening. See Changes for connection-string and date/time behavior changes that may affect existing applications.

Features

  • stdlib: support Go 1.27's driver.RowsColumnScanner, allowing PostgreSQL types such as arrays and ranges to be scanned directly into Go values without pgtype.Map.SQLScanner. Existing database/sql scalar conversions and sql.Scanner behavior are preserved. The minimum supported Go version remains 1.25.
  • Add Rows.TypeMap to expose the type map used to decode rows, including rows created by RowsFromResultReader that have no underlying Conn. Custom implementations of Rows, including mocks, must add this method.
  • pgconn: add Config.MaxProtocolMessageBodyLen to configure the maximum incoming protocol message body size (carter-ya)
  • pgconn: add ErrReadOnlyConnection, ErrReadWriteConnection, ErrPrimaryConnection, and ErrStandbyConnection sentinel errors for target_session_attrs validation, allowing callers to use errors.Is (Adrian-Stefan Mares)
  • pgxpool: accept pool_ping_timeout in connection strings to configure Config.PingTimeout. The default is zero; zero and negative durations mean no timeout (1991santhu)

Changes

  • Name-based row-to-struct mapping now matches explicit db tags case-insensitively, with exact matches taking precedence so tags can still distinguish quoted column names that differ only by case (AlisinaDevelo)

  • pgconn: resolve the OS user account only when no user is supplied by the connection string, environment, or service file, avoiding unnecessary account lookups and crashes in some restricted container environments. Home-directory defaults for password, service, and TLS files remain available independently of the account lookup. On Unix these now use $HOME rather than the OS account's home directory (Mohamed MAACHE)

  • pgtype: date, timestamp and timestamptz text values are now parsed and written by a hand-written parser and encoder for PostgreSQL's ISO date/time format instead of time.Parse and time.Format. Go's layout language cannot express a variable-width year or the BC era, which is the root of the bugs below. The text scan path is roughly 2.5x faster for timestamp and timestamptz. Bug fixes:

    • timestamp and timestamptz no longer silently move February 29 of a BC leap year to March 1 when encoding. time.Date(-4712, 2, 29, ...) was written as 4713-03-01 BC and is now written as 4713-02-29 BC. This affected ordinary four-digit BC years, not only extended-range ones. date was never affected.
    • timestamp and timestamptz can now scan BC leap days. 4713-02-29 BC previously failed with day out of range. date could already scan them.
    • Years past 9999 can now be scanned. 10000-01-02 03:04:05 previously failed to parse, so timestamp and timestamptz values at the high end of PostgreSQL's range were unreadable over the simple protocol and in any other text-format result.
    • time.Time arguments in the simple protocol now encode BC dates correctly, using the same timestamp encoder.
    • Fractional seconds beyond microsecond precision are rounded the way the server rounds them (round half to even, carrying into the rest of the value) instead of being kept at full precision. PostgreSQL never sends more than six fractional digits, so this only affects values from other sources.

    Behavior changes:

    • date now rejects impossible dates instead of normalizing them. 2024-02-30 returned 2024-03-01 and 2024-13-01 returned 2025-01-01; both are now errors. timestamp and timestamptz already rejected them.
    • All three types now reject values outside PostgreSQL's range for that type, in the binary format as well as the

... (truncated)

Commits
  • 5e583fa Update changelog for v5.11.0
  • 3927116 Apply gofumpt formatting required by lint
  • eb07165 Quote filesystem paths in development connection strings
  • cf5938f Allow unsigned digit counts in binary numeric encoding
  • 3930cf5 Accept PostgreSQL POSIX timezone offsets in text timestamps
  • 93261be Prefer exact db tag matches when mapping rows to structs
  • e8d8ad1 Merge pull request #2647 from sueun-dev/fix-range-text-quoting-20260906
  • 01d2fd3 Merge pull request #2644 from eliranbz/fix-failed-prepare-deallocation
  • 9b7e3be Merge pull request #2645 from ash2k/move-channel
  • 76d78f5 Merge pull request #2643 from AshSgDe29071999/fix/hstore-pairs-estimate-clamp
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note

Medium Risk
Minor-version pgx bump with documented connection-string and date/time semantics changes affecting the PostgreSQL timeline path, though usage is stdlib-only rather than native pgx APIs.

Overview
Bumps github.com/jackc/pgx/v5 from 5.10.0 to 5.11.0 in go.mod and go.sum only; no application code changes.

The upgrade pulls in pgx 5.11 behavior around libpq-style connection resolution (e.g. deferring OS user lookup, $HOME-based defaults on Unix), stricter date/timestamp parsing, and other driver fixes. Radar uses pgx through database/sql (internal/timeline/postgres_store.go), so runtime impact depends on how timeline Postgres is configured and which timestamp/date values are read or written—not on new code in this PR.

Reviewed by Cursor Bugbot for commit 35c3c50. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps [github.com/jackc/pgx/v5](https://github.com/jackc/pgx) from 5.10.0 to 5.11.0.
- [Release notes](https://github.com/jackc/pgx/releases)
- [Changelog](https://github.com/jackc/pgx/blob/master/CHANGELOG.md)
- [Commits](jackc/pgx@v5.10.0...v5.11.0)

---
updated-dependencies:
- dependency-name: github.com/jackc/pgx/v5
  dependency-version: 5.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 30, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 30, 2026
@nadaverell

Copy link
Copy Markdown
Contributor

Superseded by #1942, which batches this update with the other soaked, reviewed Dependabot bumps from 2026-09-30 (same target version, verified together).

@nadaverell nadaverell closed this Sep 30, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/go_modules/github.com/jackc/pgx/v5-5.11.0 branch September 30, 2026 09:25
nadaverell added a commit that referenced this pull request Sep 30, 2026
One tested batch replacing this week's soaked, low-risk Dependabot PRs.
Dependency-only: no application source changes.

**Screening time:** 2026-09-30T08:40:02Z (re-checked 09:12Z, base
`0490dd87` unchanged)
**72h cutoff:** published at or before 2026-09-27T08:40:02Z. Every
resolved version below clears it.

## Included

| PR | Dependency | Old → New | Published (UTC) | Soak | Risk conclusion
|
|---|---|---|---|---|---|
| #1932 | k8s.io/{api, apiextensions-apiserver, apimachinery, apiserver,
cli-runtime, client-go, component-helpers, component-base, streaming} |
v0.37.0 → v0.37.1 | 2026-09-23 20:28–23:27 | ~6.5d | Negligible. Every
staging repo's v0.37.0...v0.37.1 compare is a single "Update
dependencies to v0.37.1 tag" commit touching only go.mod/go.sum.
`streaming` v0.37.1 is the same commit as v0.37.0. |
| #1938 | github.com/jackc/pgx/v5 | v5.10.0 → v5.11.0 | 2026-09-07 23:39
| ~22d | Low. Used only by the Postgres timeline store through `stdlib`.
See notes. |
| #1936 | github.com/klauspost/compress | v1.20.0 → v1.20.1 | 2026-09-25
08:00 | ~5d | Low–moderate. Encoder/decoder performance rewrites plus
correctness fixes; no API or default changes. Radar uses it directly
only for the HTTP gzip encoder. |
| #1934 | modernc.org/sqlite (+ modernc.org/libc) | v1.58.0 → v1.59.0
(libc v1.75.6 → v1.75.7) | sqlite 2026-09-15 07:30; libc 2026-09-01
19:33 | ~15d / ~29d | Low. The transpiled SQLite is unchanged (3.53.4).
libc uses native Go mem*/str* routines. The UDF context-pooling change
doesn't apply because Radar registers no UDFs. |
| #1937 | eslint | 10.10.0 → 10.11.0 | 2026-09-18 20:15 | ~11.5d | Low.
A few rule refinements, no breaking changes. Lint gives 0 errors / 441
warnings, the same as main. |
| #1935 | vite | 8.2.2 → 8.3.1 | 2026-09-24 12:26 | ~6d | Low. Moves
rolldown 1.2.6 → 1.2.11, whose tree-shaking and code-splitting fixes can
change bundle output, so I smoke-tested the built binary in a browser
(below). |
| #1931 | lucide-react | 1.37.0 → 1.48.0 | 2026-09-24 05:53 | ~6d | Low.
No exports were removed between the two tarballs (6137 → 6347). All 226
icon names Radar imports exist in 1.48.0. The k8s-ui peer range
`>=0.400.0` is unchanged. |

### Movement beyond the Dependabot PRs (reviewed, all soaked)
- **k8s alignment:** root `k8s.io/kubectl` and
`k8s.io/csi-translation-lib` (indirect, via `./pkg`) and all of
`pkg/go.mod`'s k8s.io requirements move to v0.37.1 as well. Without
this, #1932 would leave the graph mixing v0.37.0 and v0.37.1.
- kubectl was published 2026-09-24 01:06Z and csi-translation-lib
2026-09-24 00:45Z. Both are go.mod-only tag bumps, like the rest of the
group.
- Module-graph-only entries `k8s.io/{code-generator, kms, metrics}`
v0.37.1 were published 2026-09-23 21:22 / 21:45 / 23:18Z. None of them
appears in go.sum.
- **npm transitives:**
- `rolldown` and all 15 `@rolldown/binding-*` 1.2.6 → 1.2.11 (2026-09-24
13:54–14:30Z)
  - `@oxc-project/types` 0.147.0 → 0.151.0 (2026-09-21)
  - `picomatch` 4.0.5 → 4.0.7 (2026-08-24)
  - Nothing else in `package-lock.json` changed.
- **Newer releases deliberately not picked up:**
  - lucide-react 1.49.0 (2026-09-29) is inside the soak window.
- modernc.org/sqlite v1.60.x (2026-09-28/29) is inside the window, and
it pins libc v1.77.1. libc has an open stack-overflow crash against
v1.77.0 (cznic/libc#60).

## Held / excluded (these PRs stay open)

| PR | Update | Decision | Reason |
|---|---|---|---|
| #1933 | vitest 4.1.11 → 5.0.2 (major) | **Hold** | vitest 5 requires
Node `^22.12 \|\| ^24 \|\| >=26`, but `ci.yml` pins Node 20 for the
Frontend, k8s-ui and Settings jobs. The PR's CI only passed because npm
treats the engine mismatch as a warning (`EBADENGINE`), which Bugbot
also flagged. **Follow-up:** move CI (and CONTRIBUTING's "Node 20+") to
Node 22 first. Note that `web/` runs the hoisted vitest without
declaring it. |
| #1930 | monaco-editor 0.55.1 → 0.57.0 | **Exclude** | Needs source
changes. The deep side-effect imports in
`packages/k8s-ui/src/components/ui/monacoRuntime.ts`
(`esm/vs/editor/contrib/{find,folding,format,gotoError,hover,suggest}/...`)
no longer resolve (TS2882), which fails the Frontend, k8s-ui and
Settings jobs. |
| #1776 | modelcontextprotocol/go-sdk 1.6.1 → 1.8.0 | **Exclude** |
Changes behaviour Radar relies on.
`TestInvestigationHandlerAnnotatesRealToolCallWithoutChangingPublicContract`
fails: "private mount handshake did not mark the scope connected".
Radar's private-mount handling needs adapting first. |
| #1939 | helmfile/helmfile-action v2.2.0 → v2.4.8 | **Exclude** |
Breaks the Helm chart job. Since v2.3.0 the action installs Helm plugins
from `.tgz` release assets
([#648](helmfile/helmfile-action#648)), so
helm-unittest ends up installed twice ("two plugins claim the name
\"unittest\""). It also moved to the node24 runtime (v2.4.0). Needs a
`ci.yml` change to how `helm-plugins` is specified. |

## Radar usage and risk notes
- **pgx 5.11**
([release](https://github.com/jackc/pgx/releases/tag/v5.11.0)):
- It makes connection-string parsing match libpq exactly, which changes
some edge cases: a literal `+` in URI query values, bad percent-encoding
now errors, `#` is data, the last repeated parameter wins, bare IPv6
hosts need brackets, and backslashes in keyword/value strings now
escape.
- That touches user-supplied `RADAR_TIMELINE_POSTGRES_DSN` values with
unusual encoding, which is worth a release-note line.
- The date/time parser rewrite doesn't reach Radar data: timestamps are
stored as int64 nanoseconds.
- The new `Rows.TypeMap` interface method doesn't matter because Radar
implements no custom `pgx.Rows`.
- It also includes security hardening: startup-parameter NUL injection
is rejected, DSN passwords are redacted more thoroughly, and decoders
are hardened against panics.
- The PostgreSQL integration tests skipped locally (no server). CI runs
them with `RADAR_REQUIRE_POSTGRES_TESTS=1` against postgres:17.
- **klauspost/compress 1.20.1**
([release](https://github.com/klauspost/compress/releases/tag/v1.20.1)):
used directly only by `internal/server/compress.go`
(`kgzip.NewWriterLevel`); zstd reaches Radar only transitively (helm,
go-containerregistry, prometheus). In the smoke test, a live
`/api/resources/pods` response came back `Content-Encoding: gzip` and
decoded with system `gunzip` to 269 pods.
- **modernc sqlite/libc**
([CHANGELOG](https://gitlab.com/cznic/sqlite/-/blob/v1.59.0/CHANGELOG.md)):
used by the SQLite timeline store and `ai-runs.db`. libc is exact-pinned
to the version sqlite requires.
- **k8s 0.37.1**
([CHANGELOG-1.37](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.37.md#v1371)):
the library code is identical. The release fixes are in binaries (DRA,
kube-proxy on Windows, kubeadm).
- **vite 8.3 / rolldown**
([8.3.0](https://github.com/vitejs/vite/releases/tag/v8.3.0),
[8.3.1](https://github.com/vitejs/vite/releases/tag/v8.3.1), [rolldown
releases](https://github.com/rolldown/rolldown/releases)):
- Our `manualChunks` does its own `node_modules/` matching, so vite
8.3.0's path-segment change doesn't affect it.
- `@vitejs/plugin-react` 6.1.1 still satisfies its peer range, and
vitest 4.1.11's `vite` peer covers ^8.
- **eslint 10.11**
([release](https://github.com/eslint/eslint/releases/tag/v10.11.0)) and
**lucide-react**
([releases](https://github.com/lucide-icons/lucide/releases)): the
lucide range includes the removal of `trash` (Radar uses `Trash2`) and
glyph redraws for `Trash2` and `Building2`. That's cosmetic; tests that
assert icon class names pass.

## Verification
- **Integrity:** `go mod verify` passes in both root and `pkg`. `go.sum`
/ `pkg/go.sum` were regenerated from main with a clean `go mod tidy`.
Each changes 30 / 14 lines each way, only the modules listed above.
- **Type-check:** `make tsc` passes.
- **Lint:** `cd web && npm run lint` gives 0 errors and 441 warnings
(the same as main).
- **Frontend tests:**
  - `packages/k8s-ui` `npm test`: 209 files, 4030 passed, 1 skipped.
  - `web` `npm run test`: 151 files, 1764 passed.
- **Go tests:**
  - `cd pkg && go test ./...` passes.
- Root `go test ./...` passes except `cmd/desktop`. Its
`TestGetShellEnv` and `TestEnrichEnvPrecedenceAndDiagnostics` hit their
5s login-shell timeout while the full parallel suite was loading the
machine.
- That flake already exists on main and doesn't involve any bumped
module. Re-run on this branch with `go test ./cmd/desktop/ -count=3`,
the tests pass, and they also pass on main.
- **Build:** `make build` passes.
- **Binary smoke test** (built binary against a live GKE cluster):
- All 8 entry assets (index, rolldown-runtime, vendor, ui, monaco
JS/CSS) returned 200.
  - The Pods table rendered with lucide icons.
- The pod drawer's YAML → Edit loaded Monaco along with `monacoRuntime`,
`yamlMonacoRuntime`, the `monacoYaml.worker` and `editor.worker` chunks,
and showed the pod YAML.
- The console showed no errors. The edit was cancelled; nothing was
applied.
- **visual-test:** not run as a full `/visual-test`. The targeted
browser smoke test above covers the rendering-relevant bumps
(vite/rolldown chunking, Monaco loading, lucide icons).

Supersedes #1932, #1938, #1936, #1934, #1937, #1935, #1931

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Patch dependency upgrades with no app code changes; pgx DSN parsing
edge cases are the main operational note for unusual Postgres connection
strings.
> 
> **Overview**
> **Dependency-only batch** — no application source changes. Bumps Go
and npm lockfiles after screening several Dependabot PRs.
> 
> **Go:** Aligns all `k8s.io/*` modules to **v0.37.1** in the root
module, `./pkg`, and checksums (patch tag bumps only). Also bumps **pgx
v5.11.0** (Postgres timeline via `RADAR_TIMELINE_POSTGRES_DSN`),
**klauspost/compress v1.20.1** (HTTP gzip in
`internal/server/compress.go`), and **modernc.org/sqlite v1.59.0** with
**libc v1.75.7** (SQLite timeline / `ai-runs.db`).
> 
> **Frontend:** **vite 8.3.1** (pulls **rolldown 1.2.11** and related
`@rolldown/binding-*` / `@oxc-project/types` transitives in
`package-lock.json`), **eslint 10.11.0**, and **lucide-react 1.48.0** in
`web/` and `packages/k8s-ui`.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
7512c17. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant