build(deps): bump github.com/nats-io/nats-server/v2 from 2.12.4 to 2.12.6 in /modules/eventbus in the go_modules group across 1 directory
Closed
Number: #94
Type: Pull Request
State: Closed
Type: Pull Request
State: Closed
Author:
dependabot[bot]
Association: Unknown
Comments: 2
Association: Unknown
Comments: 2
Created:
March 24, 2026 at 08:38 PM UTC
(3 months ago)
(3 months ago)
Updated:
April 03, 2026 at 03:50 AM UTC
(2 months ago)
(2 months ago)
Closed:
April 03, 2026 at 03:50 AM UTC
(2 months ago)
(2 months ago)
Time to Close:
9 days
Labels:
dependencies go
dependencies go
Description:
Bumps the go_modules group with 1 update in the /modules/eventbus directory: github.com/nats-io/nats-server/v2.
Updates github.com/nats-io/nats-server/v2 from 2.12.4 to 2.12.6
Release notes
Sourced from github.com/nats-io/nats-server/v2's releases.
Release v2.12.6
Changelog
Refer to the 2.12 Upgrade Guide for backwards compatibility notes with 2.11.x.
Go Version
- 1.25.8
Dependencies
- golang.org/x/crypto v0.49.0 (#7953)
- github.com/nats-io/jwt/v2 v2.8.1 (#7960)
- golang.org/x/sys v0.42.0 (#7923)
- golang.org/x/time v0.15.0 (#7923)
CVEs
- Fixes CVE-2026-33216, CVE-2026-33217, CVE-2026-33215 (affecting systems using MQTT)
- Fixes CVE-2026-33246 (affects systems using leafnodes and service imports)
- Fixes CVE-2026-33218 (affects systems using leafnodes)
- Fixes CVE-2026-33219 (affects systems using WebSockets)
- Fixes CVE-2026-33223, CVE-2026-33222 (affects systems using JetStream)
- Fixes CVE-2026-33248 (affects systems using mutual TLS)
- Fixes CVE-2026-33247 (affects systems providing credentials on the command line)
- Fixes CVE-2026-33249 (affects systems where client publish permissions should be restricted)
Improved
General
- Non-WebSocket leafnode connections can now be proxied using HTTP CONNECT (#7781)
- The
$SYS.REQ.USER.INFOresponse now includes the friendly nametag of the account and/or user if known (#7973)JetStream
- The stream peer-remove command now accepts a peer ID as well as a server name (#7952)
MQTT
- Protocol compliance has been improved, including more error handling on invalid or malformed MQTT packets (#7933)
Fixed
General
... (truncated)
Commits
0e06390Release v2.12.6f593d27Cherry-picks for 2.12.6 (#61)9f904de[FIXED] Incomplete route pool on premature pongb510192[FIXED] Avoid stalling read loop on leafnode ErrMinimumVersionRequired53941c2Report the account and user name in USER.INFO request1ab002a[IMPROVED] Support HTTP proxy connection from leaf nodes also for TCP8b64082Release v2.12.6-RC.3e6ab7e9Cherry-picks for 2.12.6-RC.3 (#59)9f4d960Make the deduplication window actually work for deduplication for sourcing304e184Remove FIXME about auth callout nonce- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions
You can disable automated security fix PRs for this repo from the Security Alerts page.
Package Dependencies
Package:
github.com/nats-io/nats-server/v2
Ecosystem:
go
go
Version Change:
2.12.4 → 2.12.6
Update Type:
Patch
Patch
Path:
/modules/eventbus in the go_modules group across 1 directory
Technical Details
| ID: | 14989158 |
| UUID: | 4130516475 |
| Node ID: | PR_kwDOOMD05s7NIP-w |
| Host: | GitHub |
| Repository: | GoCodeAlone/modular |