Skip to content

fix(deps): update dependencies - #464

Closed
tannevaled wants to merge 1 commit into
mainfrom
renovate/deps
Closed

tannevaled wants to merge 1 commit into
mainfrom
renovate/deps

Conversation

@tannevaled

@tannevaled tannevaled commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence Type Update
github.com/go-crdt/collab v0.58.0 → v0.60.0 age confidence require minor
github.com/go-crdt/crdt v0.46.0 → v0.47.0 age confidence require minor
github.com/go-gfx/gfx v0.19.0 → v0.26.0 age confidence require minor
github.com/go-images/images 23d959d → cdcee44 age confidence require digest

Release Notes

go-crdt/collab (github.com/go-crdt/collab)

v0.60.0

Compare Source

v0.59.0

Compare Source

go-crdt/crdt (github.com/go-crdt/crdt)

v0.47.0

Compare Source

go-gfx/gfx (github.com/go-gfx/gfx)

v0.26.0

Compare Source

v0.25.0

Compare Source

v0.24.0

Compare Source

svg draws <ellipse>, which was not in the element switch and so was left unpainted — silently, since an unimplemented shape is skipped rather than guessed at. It is <circle> with two radii, and both now share one oval builder.

Two comments claiming arcs were unsupported are corrected: arcToCubics has implemented them all along, and a wrong comment about a missing feature is worse than none.

v0.23.0

Compare Source

v0.22.0

Compare Source

v0.21.0

Compare Source

svg honours clip-path: a reference resolves to a coverage mask, cached per (id, transform), and clips nest by intersection. clipPathUnits="objectBoundingBox" is dropped and an unresolved reference leaves the shape whole — both documented and pinned by tests.

codec writes two containers: EncodeICO and EncodeICNS. Neither writes pixels; every representation is a standard-library PNG in a directory entry or a chunk header. ICO round-trips through sergeymakinen/go-ico, and macOS reads the Go-written .icns.

Also: golang.org/x/image v0.46.0.

v0.20.0

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@tannevaled

tannevaled commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 6 additional dependencies were updated

Details:

Package Change
github.com/andybalholm/brotli v1.2.3 -> v1.2.4
golang.org/x/image v0.45.0 -> v0.46.0
golang.org/x/sys v0.47.0 -> v0.48.0
golang.org/x/text v0.41.0 -> v0.42.0
google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa -> v0.0.0-20260706201446-f0a921348800
google.golang.org/grpc v1.83.2 -> v1.84.0

@tannevaled
tannevaled force-pushed the renovate/deps branch 2 times, most recently from 31def06 to 42f196a Compare September 12, 2026 08:27
tannevaled added a commit that referenced this pull request Sep 23, 2026
Renovate's #464 carries the same bump and is red. It bumps the root go.mod and
leaves rougelex/go.mod alone, and rougelex's own graph then needs re-tidying, so
its gate dies before it measures anything:

    go: updates to go.mod needed; to update it:
        go mod tidy

Reproduced in a clean copy of main rather than inferred: rougelex's vet passes
before any bump, and fails with exactly that line after bumping ONLY the root.
The two modules are a lockstep set.

# What it is not

  - Not the go-crdt release. With both modules bumped the rougelex gate passes on
    Go 1.26.4 and on Go 1.27.0, and so does the root's.
  - Not Go 1.27. main passes under 1.27.0 as it stands; CI runs 1.27.0 and main
    was last green on 8 September under an older one, which is what made the
    toolchain look like a suspect.

# Why the bump is worth having

crdt v0.47.0 divides every counted record header by the smallest a record can be.
Before, a claim of one record per byte reserved 96 bytes for each byte received,
and awareness was the worst of them because presence is FANNED OUT: a mebibyte cost
a server 84 MB and every participant another 84 MB. This module is where a desktop
app opens a session, so it is where that reaches a person.

collab v0.60.0 carries the link promise wake, the store contract's participants
cases, and the store framing fuzz.

Verified as CI does it, under Go 1.27.0: vet, test and the 100% gate on the root
and on rougelex, and gofmt clean.

#464 can be closed in favour of this.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
@tannevaled

Copy link
Copy Markdown
Contributor Author

Superseded by #465, which is merged.

This PR was red for a reason worth writing down: it bumps the root go.mod and leaves
rougelex/go.mod alone. rougelex's own module graph then needs re-tidying, so its gate
dies before it measures any coverage:

go: updates to go.mod needed; to update it:
	go mod tidy

Reproduced in a clean copy of main rather than inferred — rougelex's vet passes before
any bump, and fails with exactly that line after bumping only the root. #465 bumps both
and is green on the same check.

The two modules are a lockstep set for github.com/go-crdt/*: a rule matching
rougelex/go.mod alongside the root would keep them together, and the same is true of
any future dependency they share.

Neither the go-crdt release nor Go 1.27 was at fault: with both modules bumped the gate
passes on Go 1.26.4 and 1.27.0, and main passes under 1.27.0 as it stands.

@tannevaled tannevaled closed this Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant