Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

chore(deps): bump google.golang.org/grpc from 1.64.1 to 1.79.3 in /proto#250

Open
dependabot[bot] wants to merge 1 commit into
main from
dependabot/go_modules/proto/google.golang.org/grpc-1.79.3
Open

chore(deps): bump google.golang.org/grpc from 1.64.1 to 1.79.3 in /proto #250
dependabot[bot] wants to merge 1 commit into
main from
dependabot/go_modules/proto/google.golang.org/grpc-1.79.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 19, 2026
edited
Loading

Copy link
Copy Markdown
Contributor

Bumps google.golang.org/grpc from 1.64.1 to 1.79.3.

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.79.3

Security

  • server: fix an authorization bypass where malformed :path headers (missing the leading slash) could bypass path-based restricted "deny" rules in interceptors like grpc/authz. Any request with a non-canonical path is now immediately rejected with an Unimplemented error. (#8981)

Release 1.79.2

Bug Fixes

  • stats: Prevent redundant error logging in health/ORCA producers by skipping stats/tracing processing when no stats handler is configured. (grpc/grpc-go#8874)

Release 1.79.1

Bug Fixes

Release 1.79.0

API Changes

  • mem: Add experimental API SetDefaultBufferPool to change the default buffer pool. (#8806)
  • experimental/stats: Update MetricsRecorder to require embedding the new UnimplementedMetricsRecorder (a no-op struct) in all implementations for forward compatibility. (#8780)

Behavior Changes

  • balancer/weightedtarget: Remove handling of Addresses and only handle Endpoints in resolver updates. (#8841)

New Features

  • experimental/stats: Add support for asynchronous gauge metrics through the new AsyncMetricReporter and RegisterAsyncReporter APIs. (#8780)
  • pickfirst: Add support for weighted random shuffling of endpoints, as described in gRFC A113.
    • This is enabled by default, and can be turned off using the environment variable GRPC_EXPERIMENTAL_PF_WEIGHTED_SHUFFLING. (#8864)
  • xds: Implement :authority rewriting, as specified in gRFC A81. (#8779)
  • balancer/randomsubsetting: Implement the random_subsetting LB policy, as specified in gRFC A68. (#8650)

Bug Fixes

  • credentials/tls: Fix a bug where the port was not stripped from the authority override before validation. (#8726)
  • xds/priority: Fix a bug causing delayed failover to lower-priority clusters when a higher-priority cluster is stuck in CONNECTING state. (#8813)
  • health: Fix a bug where health checks failed for clients using legacy compression options (WithDecompressor or RPCDecompressor). (#8765)
  • transport: Fix an issue where the HTTP/2 server could skip header size checks when terminating a stream early. (#8769)
  • server: Propagate status detail headers, if available, when terminating a stream during request header processing. (#8754)

Performance Improvements

  • credentials/alts: Optimize read buffer alignment to reduce copies. (#8791)
  • mem: Optimize pooling and creation of buffer objects. (#8784)
  • transport: Reduce slice re-allocations by reserving slice capacity. (#8797)

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Mar 19, 2026
@dependabot dependabot Bot requested a review from a team as a code owner March 19, 2026 00:27
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot March 19, 2026 00:27

socket-security Bot commented Mar 19, 2026
edited
Loading

Copy link
Copy Markdown

senojj commented May 8, 2026

Copy link
Copy Markdown

@dependabot rebase

dependabot[bot] reacted with thumbs up emoji

Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.64.1 to 1.79.3.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.64.1...v1.79.3)
---
updated-dependencies:
- dependency-name: google.golang.org/grpc
 dependency-version: 1.79.3
 dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Copilot AI review requested due to automatic review settings May 8, 2026 13:12
@dependabot dependabot Bot force-pushed the dependabot/go_modules/proto/google.golang.org/grpc-1.79.3 branch from e5f4d7b to 411ab8e Compare May 8, 2026 13:12
@dependabot dependabot Bot review requested due to automatic review settings May 8, 2026 13:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

No reviews

Assignees

No one assigned

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

1 participant

AltStyle によって変換されたページ (->オリジナル) /