build(deps): bump the go_modules group across 4 directories with 3 updates
Type: Pull Request
State: Open
Association: Unknown
Comments: 6
(2 months ago)
(14 days ago)
dependencies go
Bumps the go_modules group with 1 update in the /examples/multi-engine-eventbus directory: github.com/aws/aws-sdk-go-v2/service/kinesis.
Bumps the go_modules group with 1 update in the /examples/nats-eventbus directory: github.com/aws/aws-sdk-go-v2/service/kinesis.
Bumps the go_modules group with 2 updates in the /modules/eventbus directory: github.com/aws/aws-sdk-go-v2/service/kinesis and github.com/nats-io/nats-server/v2.
Bumps the go_modules group with 1 update in the /modules/letsencrypt directory: github.com/go-jose/go-jose/v4.
Updates github.com/aws/aws-sdk-go-v2/service/kinesis from 1.38.0 to 1.43.5
Commits
f9f7a6bRelease 2025-07-19c74fb63Regenerated Clientsd09b466generate aws-eusc (#3144)45575ddRelease 2025-07-1840f9e8bRegenerated Clientsda30009Update endpoints model78fe67fUpdate API model654c62dRelease 2025-07-1747a74cdRegenerated Clientsbdd96b2Update endpoints model- Additional commits viewable in compare view
Updates github.com/aws/aws-sdk-go-v2/service/kinesis from 1.38.0 to 1.43.5
Commits
f9f7a6bRelease 2025-07-19c74fb63Regenerated Clientsd09b466generate aws-eusc (#3144)45575ddRelease 2025-07-1840f9e8bRegenerated Clientsda30009Update endpoints model78fe67fUpdate API model654c62dRelease 2025-07-1747a74cdRegenerated Clientsbdd96b2Update endpoints model- Additional commits viewable in compare view
Updates github.com/aws/aws-sdk-go-v2/service/kinesis from 1.38.0 to 1.43.5
Commits
f9f7a6bRelease 2025-07-19c74fb63Regenerated Clientsd09b466generate aws-eusc (#3144)45575ddRelease 2025-07-1840f9e8bRegenerated Clientsda30009Update endpoints model78fe67fUpdate API model654c62dRelease 2025-07-1747a74cdRegenerated Clientsbdd96b2Update endpoints model- Additional commits viewable in compare view
Updates github.com/aws/aws-sdk-go-v2/service/kinesis from 1.38.0 to 1.43.5
Commits
f9f7a6bRelease 2025-07-19c74fb63Regenerated Clientsd09b466generate aws-eusc (#3144)45575ddRelease 2025-07-1840f9e8bRegenerated Clientsda30009Update endpoints model78fe67fUpdate API model654c62dRelease 2025-07-1747a74cdRegenerated Clientsbdd96b2Update endpoints model- Additional commits viewable in compare view
Updates github.com/aws/aws-sdk-go-v2/service/kinesis from 1.38.0 to 1.43.5
Commits
f9f7a6bRelease 2025-07-19c74fb63Regenerated Clientsd09b466generate aws-eusc (#3144)45575ddRelease 2025-07-1840f9e8bRegenerated Clientsda30009Update endpoints model78fe67fUpdate API model654c62dRelease 2025-07-1747a74cdRegenerated Clientsbdd96b2Update endpoints model- Additional commits viewable in compare view
Updates github.com/aws/aws-sdk-go-v2/service/kinesis from 1.38.0 to 1.43.5
Commits
f9f7a6bRelease 2025-07-19c74fb63Regenerated Clientsd09b466generate aws-eusc (#3144)45575ddRelease 2025-07-1840f9e8bRegenerated Clientsda30009Update endpoints model78fe67fUpdate API model654c62dRelease 2025-07-1747a74cdRegenerated Clientsbdd96b2Update endpoints model- Additional commits viewable in compare view
Updates github.com/aws/aws-sdk-go-v2/service/kinesis from 1.38.0 to 1.43.5
Commits
f9f7a6bRelease 2025-07-19c74fb63Regenerated Clientsd09b466generate aws-eusc (#3144)45575ddRelease 2025-07-1840f9e8bRegenerated Clientsda30009Update endpoints model78fe67fUpdate API model654c62dRelease 2025-07-1747a74cdRegenerated Clientsbdd96b2Update endpoints model- Additional commits viewable in compare view
Updates github.com/aws/aws-sdk-go-v2/service/kinesis from 1.38.0 to 1.43.5
Commits
f9f7a6bRelease 2025-07-19c74fb63Regenerated Clientsd09b466generate aws-eusc (#3144)45575ddRelease 2025-07-1840f9e8bRegenerated Clientsda30009Update endpoints model78fe67fUpdate API model654c62dRelease 2025-07-1747a74cdRegenerated Clientsbdd96b2Update endpoints model- Additional commits viewable in compare view
Updates github.com/aws/aws-sdk-go-v2/service/kinesis from 1.38.0 to 1.43.5
Commits
f9f7a6bRelease 2025-07-19c74fb63Regenerated Clientsd09b466generate aws-eusc (#3144)45575ddRelease 2025-07-1840f9e8bRegenerated Clientsda30009Update endpoints model78fe67fUpdate API model654c62dRelease 2025-07-1747a74cdRegenerated Clientsbdd96b2Update endpoints model- Additional commits viewable in compare view
Updates github.com/nats-io/nats-server/v2 from 2.12.4 to 2.12.6
Release notes
Sourced from github.com/nats-io/nats-server/v2's releases.
Release v2.12.6
Changelog
Refer to the 2.12 Upgrade Guide for backwards compatibility notes with 2.11.x.
Go Version
- 1.25.8
Dependencies
- golang.org/x/crypto v0.49.0 (#7953)
- github.com/nats-io/jwt/v2 v2.8.1 (#7960)
- golang.org/x/sys v0.42.0 (#7923)
- golang.org/x/time v0.15.0 (#7923)
CVEs
- Fixes CVE-2026-33216, CVE-2026-33217, CVE-2026-33215 (affecting systems using MQTT)
- Fixes CVE-2026-33246 (affects systems using leafnodes and service imports)
- Fixes CVE-2026-33218 (affects systems using leafnodes)
- Fixes CVE-2026-33219 (affects systems using WebSockets)
- Fixes CVE-2026-33223, CVE-2026-33222 (affects systems using JetStream)
- Fixes CVE-2026-33248 (affects systems using mutual TLS)
- Fixes CVE-2026-33247 (affects systems providing credentials on the command line)
- Fixes CVE-2026-33249 (affects systems where client publish permissions should be restricted)
Changed
General
- There is now a 1MB size limit on JWTs (#7960)
Improved
General
- Non-WebSocket leafnode connections can now be proxied using HTTP CONNECT (#7781)
- The
$SYS.REQ.USER.INFOresponse now includes the friendly nametag of the account and/or user if known (#7973)JetStream
- The stream peer-remove command now accepts a peer ID as well as a server name (#7952)
MQTT
- Protocol compliance has been improved, including more error handling on invalid or malformed MQTT packets (#7933)
Fixed
... (truncated)
Commits
0e06390Release v2.12.6f593d27Cherry-picks for 2.12.6 (#61)9f904de[FIXED] Incomplete route pool on premature pongb510192[FIXED] Avoid stalling read loop on leafnode ErrMinimumVersionRequired53941c2Report the account and user name in USER.INFO request1ab002a[IMPROVED] Support HTTP proxy connection from leaf nodes also for TCP8b64082Release v2.12.6-RC.3e6ab7e9Cherry-picks for 2.12.6-RC.3 (#59)9f4d960Make the deduplication window actually work for deduplication for sourcing304e184Remove FIXME about auth callout nonce- Additional commits viewable in compare view
Updates github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4
Release notes
Sourced from github.com/go-jose/go-jose/v4's releases.
v4.1.4
What's Changed
Fixes Panic in JWE decryption. See https://github.com/go-jose/go-jose/security/advisories/GHSA-78h2-9frx-2jm8
Full Changelog: https://github.com/go-jose/go-jose/compare/v4.1.3...v4.1.4
Commits
0e59876Merge commit from forkddffdbcBump actions/checkout from 5 to 6 (#213)- See full diff in compare view
Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.
Package Dependencies
github.com/go-jose/go-jose/v4
go
4.1.3 → 4.1.4
Patch
github.com/nats-io/nats-server/v2
go
2.12.4 → 2.12.6
Patch
go
1.38.0 → 1.43.5
Minor
Security Advisories
Go JOSE Panics in JWE decryption
NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing
NATS JetStream has an authorization bypass through its Management API
NATS is vulnerable to pre-auth DoS through WebSockets client service
NATS has pre-auth server panic via leafnode handling
NATS allows MQTT clients to bypass ACL checks
NATS has MQTT plaintext password disclosure
NATS is vulnerable to MQTT hijacking via Client ID
NATS credentials are exposed in monitoring port via command-line argv
NATS: Message tracing can be redirected to arbitrary subject
Technical Details
| ID: | 15948183 |
| UUID: | 4221549772 |
| Node ID: | PR_kwDOOMD05s7QqpKQ |
| Host: | GitHub |
| Repository: | GoCodeAlone/modular |