An open index of dependabot pull requests across open source projects.

fix(deps): bump github.com/cloudevents/sdk-go/v2 from 2.16.0 to 2.16.1 in /api

Merged
Number: #694
Type: Pull Request
State: Merged
Author: dependabot[bot] dependabot[bot]
Association: Contributor
Comments: 2
Created: July 01, 2025 at 04:31 AM UTC
(11 months ago)
Updated: July 01, 2025 at 10:54 PM UTC
(11 months ago)
Merged: July 01, 2025 at 10:54 PM UTC
(11 months ago)
by AchoArnold
Time to Close: about 18 hours
Labels:
dependencies go
Assignees:
AchoArnold
Description:

Bumps github.com/cloudevents/sdk-go/v2 from 2.16.0 to 2.16.1.

Release notes

Sourced from github.com/cloudevents/sdk-go/v2's releases.

Release v2.16.1

CloudEvents SDK Go v2.16.1

🐛 Bug Fixes and Improvements

  • ⚡ NATS JetStream Enhancement: Made send subject optional via context by @​kmpm in cloudevents/sdk-go#1143

    • Added WithSubject function to override the default subject when sending messages
    • Added comprehensive tests and updated samples
    • Non-breaking enhancement that adds flexibility for NATS users
  • 📝 CloudEvents JSON Handling Fixes by @​alank-ps:

    • WriteJson Fix in cloudevents/sdk-go#1162: Fixed WriteJson to properly handle data as JSON when dataContentType is application/cloudevents+json or batch
    • ConsumeData Fix in cloudevents/sdk-go#1164: Fixed consumeData functions to properly recognize structured mode JSON content types
    • Improves compatibility with the CloudEvents specification
  • 🔧 CI/Test Improvements: Fix failing CI tests by @​embano1 in cloudevents/sdk-go#1156

🔄 Maintenance and Dependency Updates

  • 🛠️ Dependency Management Overhaul by @​embano1 in cloudevents/sdk-go#1145
    • Added script (hack/update-deps.sh) to update Go dependencies across all modules
    • Replaced Dependabot with custom script for better dependency management
    • Removed stale and broken OpenTelemetry samples

📦 Key Dependency Updates:

  • github.com/google/go-cmp: v0.6.0 → v0.7.0
  • golang.org/x/sync: v0.12.0 → v0.13.0
  • github.com/nats-io/nats.go: v1.37.0 → v1.41.2
  • github.com/IBM/sarama: v1.40.1 → v1.45.1
  • github.com/docker/docker: v20.10.17 → v27.1.1
  • go.opentelemetry.io/otel: v1.18.0 → v1.35.0
  • 🐹 Go version: Updated from 1.22 to 1.23.0 (toolchain 1.23.8)

🚨 Breaking Changes

None. All updates are either backward-compatible improvements, bug fixes, or internal refactors.

👥 New Contributors

📋 What's Changed

... (truncated)

Commits
  • 65b45e4 Merge pull request #1164 from alank-ps/main
  • bb544e0 fix: simplify isJSON
  • 1bf32a1 fix: extract IsJson() check to content_type
  • 8ad2c06 fix: consumeData(and ...AsBytes) should consider structued mode JSON content ...
  • 506a8fe Merge pull request #1165 from cloudevents/automated-dependency-updates
  • 5347cb0 chore: update dependencies
  • a50d97a Merge pull request #1162 from alank-ps/main
  • 753ba72 fix: WriteJson should write data as a JSON value when dataContentType=applica...
  • 0d35f37 Merge pull request #1163 from cloudevents/automated-dependency-updates
  • 4546fc7 chore: update dependencies
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Pull Request Statistics
Commits:
1
Files Changed:
2
Additions:
+9
Deletions:
-9
Package Dependencies
Ecosystem:
go
Version Change:
2.16.0 → 2.16.1
Update Type:
Patch
Path:
/api
Technical Details
ID: 2602261
UUID: 2630820951
Node ID: PR_kwDOHajk3c6czyRX
Host: GitHub
Repository: NdoleStudio/httpsms
Merge State: Unknown