Skip to content

deps(go): bump github.com/prometheus/common from 0.71.0 to 0.72.0 - #1998

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/prometheus/common-0.72.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/prometheus/common-0.72.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps github.com/prometheus/common from 0.71.0 to 0.72.0.

Release notes

Sourced from github.com/prometheus/common's releases.

v0.72.0

NOTE:

  • This release bumps go.mod to 1.26 -- mostly due to /x Go packages requiring 1.26 as well.
  • This is the first release with the experimental support of OpenMetrics 2 encoding.

What's Changed

New Contributors

Full Changelog: prometheus/common@v0.71.0...v0.72.0

Commits
  • ca4f6e1 build(deps): bump the golang-org-x group across 1 directory with 2 updates (#...
  • 3f29e55 Update supported Go versions (#1004)
  • acc069b Update common Prometheus files (#1003)
  • 04ca579 Update linting (#1002)
  • 818965d build(deps): bump github.com/prometheus/client_model (#1001)
  • eabff44 expfmt: stop a test leaving the shared parser on legacy validation (#996)
  • 8d1b388 expfmt: reject invalid UTF-8 and a trailing CR in OpenMetrics 2.0 metadata (#...
  • 4e79225 expfmt: simplify format constants and provide default negotiation slices (#992)
  • c57e58a optimize sample unmarshaling for json/v2 (#991)
  • 042f370 docs(expfmt): update OpenMetrics 2.0 supported metric types comments (#989)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note

Low Risk
Lockfile-only dependency bump with no code changes; minor risk if metric scraping/parsing relied on inputs that v0.72 now rejects.

Overview
Bumps github.com/prometheus/common from 0.71.0 to 0.72.0 in go.mod and go.sum only; no application code changes.

The new release adds experimental OpenMetrics 2 encoding support and tighter expfmt validation (e.g. invalid UTF-8 in metadata, nameless samples). Radar already pulls this library for upgrade live metric parsing (expfmt, model) and MCP Prometheus tooling, so behavior could shift only if those paths hit newly rejected formats—not because of local edits in this PR.

Reviewed by Cursor Bugbot for commit c249b6c. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps [github.com/prometheus/common](https://github.com/prometheus/common) from 0.71.0 to 0.72.0.
- [Release notes](https://github.com/prometheus/common/releases)
- [Changelog](https://github.com/prometheus/common/blob/main/CHANGELOG.md)
- [Commits](prometheus/common@v0.71.0...v0.72.0)

---
updated-dependencies:
- dependency-name: github.com/prometheus/common
  dependency-version: 0.72.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 7, 2026
@dependabot
dependabot Bot requested review from hisco and nadaverell as code owners October 7, 2026 04:44
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 7, 2026
nadaverell added a commit that referenced this pull request Oct 7, 2026
One tested batch replacing this week's soaked, low-risk Dependabot PRs.
Dependency-only: no application source changes.

**Screening time:** 2026-10-07T08:38:20Z (reconciled again at 09:00Z;
rebased onto `1f05aee9`, which picked up #2015)
**72h cutoff:** published at or before 2026-10-04T08:38:20Z. Every
resolved version below clears it. The npm lockfile was regenerated with
`npm install --package-lock-only --before=2026-10-04T08:38:20Z`, so the
resolver could not float past the cutoff.

## Included

| PR | Dependency | Old → New | Published (UTC) | Soak | Risk conclusion
|
|---|---|---|---|---|---|
| #2000 | modernc.org/sqlite (+ modernc.org/libc) | v1.59.0 → v1.60.1
(libc v1.75.7 → v1.77.1) | sqlite 2026-09-29 08:41; libc 2026-09-21
23:07 | ~8d / ~15.4d | Low–moderate. SQLite stays 3.53.4. The libc range
is substantial on Linux (see notes), so I ran the sqlite-backed stores'
tests in a Linux container. |
| #1998 | github.com/prometheus/common | v0.71.0 → v0.72.0 | 2026-09-28
08:33 | ~9d | Low. The only change on Radar's path is a stricter text
parser (see notes). Its `go 1.26` requirement matches ours. |
| #2001 | github.com/google/go-containerregistry | v0.22.0 → v0.22.1 |
2026-09-04 00:07 | ~33d | Low. SSRF-guard hardening, an authn fix that
stops empty credentials overwriting `AuthConfig.Auth`, and sha512 digest
support. Radar uses `authn`, `name`, `remote`, `v1/google` for image
inspection. |
| #2004 | react-virtuoso | 4.18.13 → 4.18.16 | 2026-09-29 16:03 | ~7.7d
| Low. 4.18.14 adds custom `ul` List wrappers. 4.18.15 fixes
`initialItemCount` clamping, which Radar doesn't use. 4.18.16 stops
TableVirtuoso leaking `skipAnimationFrameInResizeObserver` onto the DOM;
Radar doesn't pass that prop. I smoke-tested the binary in a browser
anyway. |
| #2003 | typescript-eslint (+ 10 `@typescript-eslint/*`) | 8.70.0 →
**8.71.0** | 2026-09-28 17:12 | ~8.6d | Low. Adds a new rule that's
opt-in and not enabled here, plus rule fixes. The set of 444 lint
warnings is identical before and after (0 errors). **8.71.1 (2026-10-05)
is too fresh and was deliberately not picked up.** |
| #2002 | vitest (+ @vitest/mocker, @vitest/spy) | 5.0.2 → 5.0.3 |
2026-09-30 11:30 | ~6.9d | Low. Bug fixes in repeats/retry, cache
revalidation, jsdom Blob and the pool. Both test suites pass. |
| #1999 | prettier | 3.9.8 → 3.9.9 | 2026-09-23 06:31 | ~14d |
Negligible. A Markdown `$`-as-math fix; Radar formats only `.ts/.tsx`.
`prettier --check` reports the same 1089 files before and after. |
| #2015 | source-map-js | 1.2.1 → 1.2.2 | 2026-09-30 14:08 | ~6.8d |
Low. Build/test-time only (postcss, Tailwind, jsdom via css-tree). Fixes
a DoS from malicious indexed source maps (CVE-2026-93749) and a crash
under a no-`unsafe-eval` CSP. |

### Movement beyond the Dependabot PRs (reviewed, all soaked)
- **Go:** `modernc.org/libc` v1.75.7 → v1.77.1 (2026-09-21), the version
sqlite pins.
- Three `go.sum` entries also changed, `golang.org/x/tools` v0.50.0
(2026-09-08), `modernc.org/cc/v4` v4.29.7 (2026-09-12) and
`modernc.org/ccgo/v4` v4.36.1 (2026-09-21). `go mod why` shows each one
is reached only through `go-sdk/mcp.test` or `libc.test`, never a Radar
binary.
  - `pkg/go.mod` is untouched.
- **npm:**
- `ignore` 7.0.9 → 7.0.12 (2026-10-02, ~4.8d), nested under
`@typescript-eslint/eslint-plugin`. These are gitignore-semantics fixes
plus linear-time perf work (no release notes, so I reviewed the
[compare](kaelzhang/node-ignore@7.0.9...7.0.12)).
It's lint-time only, and the lint output is identical.
- `why-is-node-running` 3.2.2 → 3.2.1, a **downgrade** that vitest 5.0.3
pins on purpose
([vitest#11403](vitest-dev/vitest#11403),
avoids `ERR_PNPM_TRUST_DOWNGRADE`). 3.2.1 was published 2024-10-29.
  - Nothing else in `package-lock.json` changed.
- **Too-fresh versions deliberately excluded by the `--before` cutoff:**
- typescript-eslint / `@typescript-eslint/*` 8.71.1 (2026-10-05 17:08Z).
- `magic-string` 1.4.3 (2026-10-05 04:52Z), which a plain refresh would
have pulled under `@vitest/mocker`. It stays at 1.4.2, inside mocker's
`^1.2.3`.

## Held / excluded (these PRs stay open)

| PR | Update | Decision | Reason |
|---|---|---|---|
| #1776 | modelcontextprotocol/go-sdk 1.6.1 → 1.8.0 | **Exclude** | I
re-tested on today's main and it still fails
`TestInvestigationHandlerAnnotatesRealToolCallWithoutChangingPublicContract`
("private mount handshake did not mark the scope connected"). Radar's
private-mount handling needs adapting first; that's a source change. |
| #1930 | monaco-editor 0.55.1 → 0.57.0 | **Exclude** | Unchanged from
last week. The deep side-effect imports in
`packages/k8s-ui/src/components/ui/monacoRuntime.ts` don't resolve under
0.57 (TS2882), and that file hasn't changed since. The PR's CI still
fails the Frontend, k8s-ui and Settings jobs. Needs a source change. |
| #1939 | helmfile/helmfile-action v2.2.0 → v2.4.8 | **Exclude** |
Unchanged from last week. Since v2.3.0 the action installs helm-unittest
twice ([#648](helmfile/helmfile-action#648)), so
the Helm chart job fails. Needs a `ci.yml` change to how `helm-plugins`
is specified. |

## Radar usage and risk notes
- **modernc sqlite 1.60 / libc 1.77.1** ([sqlite
CHANGELOG](https://gitlab.com/cznic/sqlite/-/blob/v1.60.1/CHANGELOG.md),
[libc
compare](https://gitlab.com/cznic/libc/-/compare/v1.75.7...v1.77.1)):
- Radar imports only the `database/sql` driver: the SQLite timeline
store and `ai-runs.db`. It uses no `vfs`, no `pcache`, none of the
removed `lib` constants and no `_pragma`. `StrictPragmas` is opt-in.
- The 1.60.0 change that turns a WAL `-shm` read fault into
`SQLITE_IOERR_IN_PAGE` instead of a crash is a strict improvement.
- The libc range includes musl atomics translated to Go, stdio locking
fixes, and setenv/putenv mirrored into the Go environment on musl.
That's why I ran the targeted Linux run below.
- **Last week's blocker is resolved.** libc v1.77.0's recursive `Xnanf`
stack overflow
([cznic/libc#60](https://gitlab.com/cznic/libc/-/issues/60)) caused us
to hold sqlite 1.60. v1.77.0 is now retracted, and v1.77.1 adds the fix
and a `TestNaN` regression test.
- The issue is still open upstream, so I checked directly: in v1.77.1,
Linux `Xnanf` returns `X__builtin_nanf` (`math.NaN()`), and the issue's
own reproducer prints `NaN NaN NaN` on linux/arm64 with no stack
overflow.
- **prometheus/common 0.72**
([release](https://github.com/prometheus/common/releases/tag/v0.72.0)):
- Radar uses `expfmt.NewTextParser(model.LegacyValidation)` to parse
apiserver metrics in `internal/upgrade/collectors_live.go`, and `model`
in the MCP Prometheus tool.
- The only text-parser change
([#988](prometheus/common#988)) now rejects a
nameless `{}` sample that follows metric metadata. Kubernetes apiserver
exposition never emits one.
- The rest is OpenMetrics 2.0 encoding, which is experimental and unused
here, plus format-constant docs
([#992](prometheus/common#992), backward
compatible).
- **typescript-eslint 8.71.0**
([release](https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.71.0)),
**vitest 5.0.3**
([release](https://github.com/vitest-dev/vitest/releases/tag/v5.0.3)),
**prettier 3.9.9**
([changelog](https://github.com/prettier/prettier/blob/3.9.9/CHANGELOG.md#399)),
**react-virtuoso**
([releases](https://github.com/petyosi/react-virtuoso/releases)),
**source-map-js 1.2.2**
([compare](7rulnik/source-map-js@v1.2.1...v1.2.2)),
**go-containerregistry 0.22.1**
([release](https://github.com/google/go-containerregistry/releases/tag/v0.22.1)).

## Verification
All results are on the rebased branch (base `1f05aee9`).
- **Integrity:** `npm ci` passes, and `go mod verify` passes for root
and `pkg`.
- **Type-check:** `make tsc` passes.
- **Go tests:** `make test` (root `go test ./...`, 43 packages ok) and
`cd pkg && go test ./...` both pass. The first run failed with "package
unsafe is not in std" and missing `go-build` cache files because the Go
build cache was cleaned during the run; both pass on a clean re-run.
- **Frontend tests:**
  - `packages/k8s-ui` `npm test`: 218 files, 4160 passed, 1 skipped.
  - `web` `npm run test`: 158 files, 1865 passed.
- **Lint:** `cd web && npm run lint` gives 0 errors and 444 warnings,
the same warning set as main. I compared the normalized warning lists
from a clean `npm ci` of `origin/main`.
- **Prettier:** `prettier --check` on `web/src` and
`packages/k8s-ui/src` flags 1089 files before and after, so the bump
changes no formatting.
- **Build:** `make build` passes.
- **Linux targeted test:** `go test ./internal/timeline/ ./internal/ai/`
passes in `golang:1.26` (go1.26.8, linux/arm64) against libc v1.77.1.
Those are the SQLite timeline store and the `ai-runs.db` store.
- **Binary smoke test:** I ran the built binary against a live cluster
with the Pods table at ~100 pods.
- TableVirtuoso virtualized as expected: 5182px of scroll height
rendered 29 rows, then 43 after a mid-scroll.
- Rows rendered correctly mid-list, and the console showed 0 errors and
0 warnings.
- **visual-test:** I didn't run a full `/visual-test`. The only
rendering-relevant bump is react-virtuoso, and the targeted smoke test
above covers it.

Supersedes #2000, #1998, #2001, #2004, #2003, #2002, #1999, #2015

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Dependency-only lockfile and manifest updates with no runtime code
changes; bumps are patch/minor and were screened with tests per the PR
description.
> 
> **Overview**
> This PR **batches soaked Dependabot dependency bumps** with **no
application source changes**—only `go.mod`/`go.sum`, root
`package-lock.json`, and version pins in `packages/k8s-ui/package.json`
and `web/package.json`.
> 
> **Go** updates include `modernc.org/sqlite` (v1.59.0 → v1.60.1) with
its `modernc.org/libc` transitive bump, `github.com/prometheus/common`
(v0.71.0 → v0.72.0), and `github.com/google/go-containerregistry`
(v0.22.0 → v0.22.1), plus related `go.sum` entries for sqlite/libc
toolchain deps.
> 
> **npm** updates cover `react-virtuoso` (4.18.13 → 4.18.16) in k8s-ui
and web, `typescript-eslint` / `@typescript-eslint/*` (8.70.0 → 8.71.0),
`vitest` (5.0.2 → 5.0.3) in k8s-ui, `prettier` (3.9.8 → 3.9.9), and
lockfile-only moves such as `source-map-js` 1.2.2 and vitest’s pinned
`why-is-node-running` downgrade.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
3716b5a. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
@nadaverell

Copy link
Copy Markdown
Contributor

Superseded by #2017 (merged as 2530ae4), which batched this update after the 72h soak, upstream review, and full verification.

@nadaverell nadaverell closed this Oct 7, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/go_modules/github.com/prometheus/common-0.72.0 branch October 7, 2026 09:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant