An open index of dependabot pull requests across open source projects.

chore(deps): bump github.com/dreego-stack/dreego from 0.7.0 to 0.10.9

Open
Number: #18
Type: Pull Request
State: Open
Author: dependabot[bot] dependabot[bot]
Association: Unknown
Comments: 1
Created: September 30, 2026 at 07:24 PM UTC
(about 4 hours ago)
Updated: September 30, 2026 at 07:24 PM UTC
(about 4 hours ago)
Description:

Bumps github.com/dreego-stack/dreego from 0.7.0 to 0.10.9.

Changelog

Sourced from github.com/dreego-stack/dreego's changelog.

v0.10.9 - 2026-09-26

  • Feat: PROFILE "name" header directive binds a route (and a (group)/ subtree) to an App.Profile with its own session store, CSRF switch and cookie policy; without a profile the previous global session+CSRF behavior is unchanged
  • Feat: App.Profile/App.ApplyProfile let main.go define CSRF/session profiles as code objects and scope them per route pattern
  • Feat: GOIMPORT accepts any resolvable import path (stdlib, go.mod dependencies and own module paths) and supports aliases (GOIMPORT { myauth "statuna/auth" }); a missing module or base-name collision fails with a clear error instead of a static allowlist rejection
  • Feat: every generated dree.go carries a // Code generated by dreego … marker; dreego generate only overwrites or deletes marked files and refuses an unmarked dree.go instead of deleting it silently
  • Feat: each route folder generates its own Go package; the root www/routes/dree.go collects every sub-package Register, so package-level declarations no longer collide across folders
  • Feat: the dreego.Context interface exposes Set, Delete, Get, FormValue, Query and DestroySession, matching what SSRContext already implemented
  • Feat: c.Flash(key, msg), c.FlashGet(key) (reads and consumes) and c.FlashPeek(key) (reads without consuming) store flash messages in the session store
  • Feat: c.CSRFInput() renders the complete hidden csrf_token field; dreego generate warns when a g-action form has no csrf_token field; a CSRF rejection is routed through App.SetErrorHandler(403) when registered
  • Docs: new recipes for calling app code from <server> sections, machine/webhook endpoints and session/auth basics, plus a Context/SSRContext/RenderContext method table

v0.10.8 - 2026-09-21

  • Bug: c.Write appends ; charset=utf-8 only when the caller-supplied content type has no charset, so a caller-provided charset is no longer duplicated
  • Feat: SafeURL allows the webcal and caldav schemes for calendar subscriptions
  • Docs: dreego.config.json is documented in the website root (www/ by default), not the project root
  • Docs: the CLI install path github.com/dreego-stack/dreego/cmd/dreego@… is documented and the module-root pitfall explained

v0.10.7 - 2026-09-21

  • Bug: apply |raw and other expression filters in attribute, URL, script, and style contexts instead of emitting invalid Go (undefined: raw)
  • Bug: allow {#if} conditions on strings, numbers, and slices by routing them through a truthiness helper (empty string, zero, and empty collections are false), fixing the non-compiling _docs/forms.md example

v0.10.6 - 2026-09-21

  • Bug: <server> sections that mix Go declarations and statements now compile; the leading declaration block (type/func/var/const) and any top-level func are emitted at package level and the remaining statements stay inside the render function, instead of emitting the whole section at package level
  • Bug: declarations at the top of a <server> section are hoisted to package level, so route files in one directory can share types, consts, funcs, and stores
  • Bug: request-local var declarations that follow a statement stay inside the render function, so they are not turned into shared package state
  • Bug: the generated GET handler no longer overwrites a Content-Type already written by a <server type="custom"> route

v0.10.5 - 2026-09-21

  • Bug: dreego fmt is now semantics-preserving for body-level layouts; a document-level <head> nested in <body> is no longer hoisted and trailing </html>/</body> are no longer dropped
  • Bug: dreego fmt reorders only whitespace-separated root sections and preserves every token and the surrounding text
  • Bug: dreego fmt no longer rewrites string-literal contents; whitespace and | normalization stays outside "…", '…', and `…` values such as {{ "a b" }} or {#if x == "a | b"}
  • Bug: dreego fmt preserves <server>, <client>, and <style> sections byte for byte, including Go raw-string contents and alignment spacing
  • Test: round-trip property matrix over the scaffold layouts and body-level layout variants that asserts fmt never changes the lexed section structure or skeleton tags
  • Test: literal guards and an exact code-section comparison that fail against the previous whitespace collapsing
  • Test: dreego fmt --check never writes, including on a body-level layout

v0.10.4 - 2026-09-20

  • Breaking: remove the dreego init command; dreego new is the single scaffold entry point (it already creates the module, init did not)
  • Bug: dreego new now always writes the module-qualified import (the removed init could emit the broken relative import "./www")
  • Feat: the scaffolded main.go declares the listening port as a port constant, with DREEGO_PORT as the container override; the Dockerfile/docker-compose.yml read that variable instead of hardcoding 8080
  • Fix: the web-app starter no longer writes handwritten notes_store.go into the generated routes package; the notes store lives in the route's <server> section
  • Fix: dreego docs works without a go.mod (resolves first-party docs from the module cache); --list no longer exits when no go.mod exists
  • Docs: update getting-started, cli, deployment, and the template decision for the removed init, the port constant, and the web-app route store
  • Docs: add _todo/plugins/websocket-hub-broadcast.1.md for the plugin's missing hub registration and README drift

... (truncated)

Commits
  • 40a16b3 docs: apply pending release notes
  • b140351 Merge pull request #115 from dreego-stack/integration/v0109
  • 40b9d9e fix: move shared fixture types into an importable package and update the scop...
  • 3095fbb test: cover profile pattern validation, CSRF cookie path and /vN import names
  • f0bb890 fix: validate ApplyProfile patterns, scope CSRF cookie path, resolve /vN impo...
  • 37bb0c7 fix: adapt fixtures, demo and package-split tests to generated markers and pe...
  • 69c77fb docs: add release change file for v0.10.9
  • d92ab50 test: adapt route-profile and route-package tests to per-folder packages and ...
  • e465a5f Merge branch 'fix/v0109-p9-docs' into integration/v0109
  • c8d88b7 Merge branch 'fix/v0109-p6-lint' into integration/v0109
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Technical Details
ID: 16632070
UUID: 5651843529
Node ID: PR_kwDOUS5UOc8AAAABF9hZHQ
Host: GitHub
Repository: dreego-stack/plugin-auth