Skip to content

Bump the "examples" group with 2 updates across multiple ecosystems - #155

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/examples-677ef3d2d7
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/examples-677ef3d2d7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the examples group with 3 updates in the /examples/caddy-plugin directory: github.com/caddyserver/caddy/v2, github.com/dunglas/httpsfv and github.com/lestrrat-go/jwx/v3.

Updates github.com/caddyserver/caddy/v2 from 2.11.4 to 2.11.7

Release notes

Sourced from github.com/caddyserver/caddy/v2's releases.

v2.11.7

This patch release fixes regressions from 2.11.6, including a crash when proxying over HTTP/2 and streams that were cut off after a minute. If you're on 2.11.6, we recommend upgrading. It also adds support for the brand new Incremental header field (RFC 10036).

Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.

Highlights

  • Fixed: crash and dropped streams caused by the new idle timeouts. 2.11.6 introduced default idle read/write timeouts, which caused some problems:

    • In 2.11.6, the request body's idle deadline could outlive the handler that set it:

      • Over HTTP/2, Caddy could panic with a nil pointer dereference when the reverse proxy was still reading a request body after the handler had returned. (#8101)
      • Over HTTP/1.1, streaming responses to requests with a body, such as SSE clients that open the stream with a POST, were cut off exactly 60 seconds after the body was read. (#8103)

      Both are fixed in #8107. Thanks @​steadytao!

    • Over HTTP/2, streaming responses that paused between writes for longer than write_idle (1 minute by default), like quiet SSE streams, were reset with a stream error. As documented, only a write that stalls should count. Thanks @​WeidiDeng! (#8118, #8119)

  • Fixed: placeholders for missing cookies are empty again. Since 2.11.6, places that keep unknown placeholders as written, like respond headers, would output {http.request.cookie.*} literally when the cookie wasn't in the request. The same happened to {http.request.tls.*} on plain HTTP requests. Both are empty again. Thanks @​steadytao! (#8019)

  • New: support for the Incremental header field (RFC 10036). It's the standard replacement for NGINX's proprietary X-Accel-Buffering header. If an upstream response has Incremental: ?1, reverse_proxy forwards it immediately, the same as flush_interval -1, and encode streams it instead of holding it back. Great for Mercure, SSE and other streaming apps.

    • If the request_buffers or response_buffers options would prevent incremental forwarding, Caddy responds with 501 Not Implemented instead of silently buffering, as the RFC requires.
    • The new proxy_status_name option adds a Proxy-Status header to those responses, explaining why the message was refused.

    Thanks @​dunglas! (#8020)

  • Faster TLS handshakes: When nothing subscribes to certificate events and debug logging is off, CertMagic no longer builds event data for every handshake. Certificate lookup per handshake is about twice as fast, with 10 allocations instead of 15. Thanks @​u5surf! (#8010)

  • Unix sockets: When a reload moves a listener (or the admin endpoint) off a Unix socket, the old socket now closes right away and its file is removed. Before, clients connecting to the old path would hang until the next garbage collection, about 2 minutes later. Thanks @​littfed! (#8061)

  • Headers handler: Multiple Set-Cookie values in a JSON config's set are now sent as separate header fields, instead of being joined with commas into one field that clients can't parse. Thanks @​Indra55! (#8080)

  • caddy fmt no longer deletes an opening brace at the very end of the input. Thanks @​n0liu! (#8047)

What's Changed

New Contributors

Full Changelog: caddyserver/caddy@v2.11.6...v2.11.7

v2.11.6

This patch release contains a large number of minor and some noticeable enhancements and bug fixes. Thank you to everyone who contributed or spent their LLM tokens responsibly to help with this release!

We have much more in the pipeline still, as AI has made contributions of all quality levels cheap and easy. We will be trying to go through them as quickly and efficiently as we can.

Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.

⚠️ Please read the breaking changes below before upgrading. Most of them come from security hardening, and most configs won't notice. If you were relying on one of the old behaviors, though, you'll want to know about it.

... (truncated)

Commits
  • 72dd0fb timeouts: fix idle writer terminate h2 response writers between writes (#8119)
  • ab7e6b6 caddyhttp: end request-body deadline ownership with handler (#8107)
  • ac63faa headers: Preserve separate Set-Cookie values (#8080)
  • 55a95ad caddyhttp: keep absent optional placeholders empty (#8019)
  • f357e2b reverseproxy: stabilise half-close test (#8049)
  • d483d78 listeners: close unix socket immediately and unlink file on reload (#8061)
  • b72bf7a caddyfile: keep an opening brace that ends the input (#8047)
  • 2f34b93 feat: implement the Incremental header field (RFC 10036) (#8020)
  • 4978c54 events: tell CertMagic which events are worth emitting (#8010)
  • ac834b5 ci: pin cosign to v2 for release signing (#8092)
  • Additional commits viewable in compare view

Updates github.com/dunglas/httpsfv from 1.1.0 to 1.1.1

Release notes

Sourced from github.com/dunglas/httpsfv's releases.

Version 1.1.1

This release fixes two panics reachable when parsing malformed structured fields (denial of service). See the security advisory: GHSA-jj78-73gf-wr5j. Upgrading is strongly recommended for all users of v1.1.0.

What's Changed

New Contributors

Full Changelog: dunglas/httpsfv@v1.1.0...v1.1.1

Commits
  • f2c11c2 fix: panics when parsing malformed display strings and dates
  • 888fe5c fix: decimal formatting issues (#14)
  • See full diff in compare view

Updates github.com/lestrrat-go/jwx/v3 from 3.1.1 to 3.3.0

Release notes

Sourced from github.com/lestrrat-go/jwx/v3's releases.

v3.3.0

Security fix for GHSA-4cf7-xm37-g63h.

Custom claim, header, and JWK field names are now JSON-escaped on output. Previously a name was written between the quotes as is, so a name containing " could close its own member and add members the application never set. For example, calling Set with the name x":0,"admin produced a signed token containing "admin":true. Every name now yields exactly one member, and names that need no escaping serialize exactly as before.

See the Changes file for guidance on screening caller-supplied names.

Fixed in v4.5.0 and v3.3.0. v2, v1, and v0 are unmaintained and will not receive a fix.

For more detailed release notes, see Changes.

What's Changed

Full Changelog: lestrrat-go/jwx@v3.2.0...v3.3.0

v3.2.0

For more detailed release notes, see Changes.

What's Changed

... (truncated)

Changelog

Sourced from github.com/lestrrat-go/jwx/v3's changelog.

Changes

v4 has many incompatibilities with v3. To see the full list of differences between v3 and v4, please read the Changes-v4.md file. Coding Agents should read MIGRATION-v4.md

UNRELEASED

  • [jws][jwk] github.com/valyala/fastjson is no longer a dependency. The header probes in jws/jwsbb and jwk/jwkbb now use encoding/json/v2 and jsontext.

    jwsbb.HeaderParse, jwsbb.HeaderParseCompact, and jwkbb.HeaderParse now reject a header whose strings contain a raw control character, invalid UTF-8, or a lone surrogate escape such as \ud800. The first HeaderGet* call returns the error, and HeaderHas reports false. jws.VerifyCompactFast, and therefore jwt.Parse, now also reject a protected header with a raw control character or invalid UTF-8 in a string, as jws.Verify does. (#2372)

  • [jwk] jwk.Set.All() and jwk.Set.Fields() now loop over a copy of the keys or fields taken when each loop starts. The set can therefore be changed inside the loop, for example with AddKey, RemoveKey, Set, or Remove, and those changes do not affect the running loop. (#2373)

  • [jwt] jwt.Parse called with exactly two jwt.WithKey options and no other options now tries both keys, so a token signed with either key verifies. Calls with three or more options already tried every key. (#2374)

  • [jwt] jwt.Equal now sorts the members of every JSON object, including nested ones, before comparing, so two tokens holding the same map-valued claim always compare equal. This is needed because v4 serializes with encoding/json/v2, which writes map keys in random order (v3's encoding/json sorted them). Raw JSON claims holding the same members in a different order also compare equal. Arrays keep their order and numbers keep their exact digits, so integers above 2^53 that differ still compare unequal. (#2375)

  • [jwe] jwe.Decrypt now tries each key provider in turn and moves on to the next one when a provider returns an error, as jws.Verify does. For example, jwe.WithKeySet with a set that has no usable key, followed by a working jwe.WithKey, decrypts with the working key. If no key works, the provider errors are included in the returned error. (#2376)

  • [jwe] JSON serialization of a JWE now always includes the ciphertext member, and jwe.Parse now accepts an empty ciphertext. A JWE that encrypts an empty plaintext with AES-GCM therefore round-trips through jwe.Encrypt(..., jwe.WithJSON()), jwe.Parse, and json.Marshal. A missing, null, or non-string ciphertext is still rejected, and the

... (truncated)

Commits
  • 0bbd1a7 release v3.3.0
  • 0fdfe98 [v3] escape JSON object member names on output (#2349)
  • bc19585 show fetch failure cause via error sink (#2344)
  • fbb3514 add example for bounded WithWaitReady wait (#2343)
  • 601b51b build(deps): bump github/codeql-action from 4.37.8 to 4.37.9 (#2332)
  • 4de1087 fix curve inference claim in classifier docs (#2330)
  • 1d28f61 [v3] add jws.WithStrictECDSA sign option (#2328)
  • a52656d Merge pull request #2326 from lestrrat-go/refactor-v3-jws-keyalg-internal
  • e6236d3 deprecate AlgorithmsForKey, move to internal
  • e931dd0 build(deps): bump github/codeql-action from 4.37.7 to 4.37.8 (#2321)
  • Additional commits viewable in compare view

Bumps the examples group with 1 update in the /examples/browser-extension directory: @types/chrome.
Bumps the examples group with 1 update in the /examples/verification-workers directory: @cloudflare/vitest-pool-workers.

Updates @types/chrome from 0.2.7 to 0.3.4

Commits

Updates @cloudflare/vitest-pool-workers from 0.22.0 to 0.23.0

Release notes

Sourced from @​cloudflare/vitest-pool-workers's releases.

@​cloudflare/config@​0.23.0

Minor Changes

  • #15928 7f57b1c Thanks @​ichernetsky-cf! - Allow "us" as a jurisdiction for Container applications

    Container placement constraints now accept constraints.jurisdiction: "us" in Wrangler and typed Cloudflare configuration. This makes the US jurisdiction available alongside "eu" and "fedramp".

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the examples group with 3 updates in the /examples/caddy-plugin directory: [github.com/caddyserver/caddy/v2](https://github.com/caddyserver/caddy), [github.com/dunglas/httpsfv](https://github.com/dunglas/httpsfv) and [github.com/lestrrat-go/jwx/v3](https://github.com/lestrrat-go/jwx).


Updates `github.com/caddyserver/caddy/v2` from 2.11.4 to 2.11.7
- [Release notes](https://github.com/caddyserver/caddy/releases)
- [Commits](caddyserver/caddy@v2.11.4...v2.11.7)

Updates `github.com/dunglas/httpsfv` from 1.1.0 to 1.1.1
- [Release notes](https://github.com/dunglas/httpsfv/releases)
- [Commits](dunglas/httpsfv@v1.1.0...v1.1.1)

Updates `github.com/lestrrat-go/jwx/v3` from 3.1.1 to 3.3.0
- [Release notes](https://github.com/lestrrat-go/jwx/releases)
- [Changelog](https://github.com/lestrrat-go/jwx/blob/develop/v4/Changes)
- [Commits](lestrrat-go/jwx@v3.1.1...v3.3.0)
build(deps-dev): bump the examples group across 2 directories with 2 updates

Bumps the examples group with 1 update in the /examples/browser-extension directory: [@types/chrome](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/chrome).
Bumps the examples group with 1 update in the /examples/verification-workers directory: [@cloudflare/vitest-pool-workers](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers).


Updates `@types/chrome` from 0.2.7 to 0.3.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/chrome)

Updates `@cloudflare/vitest-pool-workers` from 0.22.0 to 0.23.0
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/@cloudflare/config@0.23.0/packages/vitest-pool-workers)

---
updated-dependencies:
- dependency-name: github.com/caddyserver/caddy/v2
  dependency-version: 2.11.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: examples
- dependency-name: github.com/dunglas/httpsfv
  dependency-version: 1.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: examples
- dependency-name: github.com/lestrrat-go/jwx/v3
  dependency-version: 3.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: examples
- dependency-name: "@types/chrome"
  dependency-version: 0.3.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: examples
- dependency-name: "@cloudflare/vitest-pool-workers"
  dependency-version: 0.23.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: examples
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants