Skip to content

fix(deps): update dependencies - #468

Merged
tannevaled merged 1 commit into
mainfrom
renovate/deps
Sep 27, 2026
Merged

tannevaled merged 1 commit into
mainfrom
renovate/deps

Conversation

@tannevaled

@tannevaled tannevaled commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence Type Update
github.com/go-gfx/gfx v0.19.0 → v0.34.0 age confidence require minor
github.com/go-images/images 23d959d → 8ace06e age confidence require digest
github.com/go-opentype/fonts v0.9.0 → v0.10.0 age confidence require minor
github.com/go-opentype/opentype v0.12.0 → v0.13.0 age confidence require minor
github.com/go-widgets/toolkit v0.316.0 → v0.321.0 age confidence require minor

Release Notes

go-gfx/gfx (github.com/go-gfx/gfx)

v0.34.0

Compare Source

v0.33.0

Compare Source

v0.32.0

Compare Source

v0.31.0

Compare Source

v0.30.0

Compare Source

<line> is painted.

A shape absent from gfx/svg's element switch is not rejected — it is silently not painted. <line> was in that position, and it cost a brand banner: openweft's mark draws its glyph with four <line> elements, so the generated banner carried the wordmark and an empty space where the mark belongs. Nobody published it, and 56 READMEs have shown a broken image since June.

Second time for this shape: <ellipse> was absent until v0.24.0.

The element name has to appear in two lists — the dispatch and shapePath — and both now carry a comment pointing at the other. Tests assert pixels, not parsing.

v0.29.0

Compare Source

v0.28.0

Compare Source

v0.27.0

Compare Source

v0.26.0

Compare Source

v0.25.0

Compare Source

v0.24.0

Compare Source

svg draws <ellipse>, which was not in the element switch and so was left unpainted — silently, since an unimplemented shape is skipped rather than guessed at. It is <circle> with two radii, and both now share one oval builder.

Two comments claiming arcs were unsupported are corrected: arcToCubics has implemented them all along, and a wrong comment about a missing feature is worse than none.

v0.23.0

Compare Source

v0.22.0

Compare Source

v0.21.0

Compare Source

svg honours clip-path: a reference resolves to a coverage mask, cached per (id, transform), and clips nest by intersection. clipPathUnits="objectBoundingBox" is dropped and an unresolved reference leaves the shape whole — both documented and pinned by tests.

codec writes two containers: EncodeICO and EncodeICNS. Neither writes pixels; every representation is a standard-library PNG in a directory entry or a chunk header. ICO round-trips through sergeymakinen/go-ico, and macOS reads the Go-written .icns.

Also: golang.org/x/image v0.46.0.

v0.20.0

Compare Source

go-opentype/fonts (github.com/go-opentype/fonts)

v0.10.0

Compare Source

go-opentype/opentype (github.com/go-opentype/opentype)

v0.13.0: — a ceiling that a 32-bit int walked through

Compare Source

Judge a table's extent in int64

The table-directory reader refused an out-of-range table by adding two uint32s
converted with int():

off := int(be32(rec[8:]))
length := int(be32(rec[12:]))
if off+length > len(b) {

int is 32 bits on a 32-bit build, so a length of 0xFFFFFFFF becomes −1.
off+length then comes out smaller than off, the check passes a table that
is not in the file, and the slice that follows panics — b[184:183] — in a
reader whose whole purpose is to refuse a malformed font rather than crash on one.

TestParseErrors/table_out_of_range already covered this and was already
correct. It had simply never been run on a machine where an int is 32 bits.

New: the tests run on six architectures

riscv64, loong64, ppc64le, s390x (big-endian), 386 and arm (32-bit
int) — under qemu-user-static, except 386, which runs natively because
qemu-i386 loses the guest's floating-point state across the signal Go delivers
for asynchronous preemption (5 failures in 8 identical lanes emulated, 0 in 8
native).

The CI previously cross-compiled for the 64-bit four and ran on none of them.
Every big-endian lane was green from the first run — a font file is a big-endian
container, so the readers had nothing to unlearn. Both 32-bit lanes failed, and
the fix above is what they found.

go-widgets/toolkit (github.com/go-widgets/toolkit)

v0.321.0

Compare Source

v0.320.0: — onto go-crdt v0.49.0 / collab v0.62.0

Compare Source

Both modules onto collab v0.62.0 and crdt v0.49.0 (#​467).

  • crdt v0.49.0 — v0.48.0 shipped ErrCollidingID unreachable from the only consumer that exists: one of a Composite's three entry points still dropped a text part's error, and it was the one a relay takes (go-crdt/crdt#121).
  • collab v0.62.0 — Config.OnOperationsRefused, so an operator can hear a refused batch instead of it reaching the offending session and nobody else (go-crdt/collab#183).

Nothing in these modules calls those paths; they carry the versions so the modules downstream can.

v0.319.0 is a mistag and is identical to v0.318.0. See its notes.

v0.319.0: — mistagged, identical to v0.318.0

Compare Source

Use v0.320.0 instead. This tag carries nothing new.

It was pushed while the merge it was meant to describe was still refused, so it points at the same commit as v0.318.0 (b951ef1). Its annotation claims the go-crdt v0.49.0 / collab v0.62.0 bump; it does not contain it.

It is left where it is rather than moved or deleted: the Go module proxy had already cached it, and moving a tag the proxy has served breaks anyone who fetched it. v0.320.0 (7aa8b64) is the real one.

v0.318.0

Compare Source

v0.317.0

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@tannevaled

tannevaled commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 4 additional dependencies were updated

Details:

Package Change
github.com/tannevaled/gobig2 v0.1.0 -> v0.2.0
golang.org/x/image v0.45.0 -> v0.46.0
golang.org/x/sys v0.47.0 -> v0.48.0
golang.org/x/text v0.41.0 -> v0.42.0
File name: rougelex/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 6 additional dependencies were updated

Details:

Package Change
github.com/go-gfx/gfx v0.19.0 -> v0.34.0
github.com/go-images/images v0.0.0-20260831115433-23d959d868e3 -> v0.0.0-20260926211103-8ace06e0df2f
github.com/tannevaled/gobig2 v0.1.0 -> v0.2.0
golang.org/x/image v0.45.0 -> v0.46.0
golang.org/x/sys v0.47.0 -> v0.48.0
golang.org/x/text v0.41.0 -> v0.42.0

@tannevaled
tannevaled force-pushed the renovate/deps branch 2 times, most recently from 6eb224c to a4be60a Compare September 26, 2026 09:11
@tannevaled
tannevaled merged commit a8f1052 into main Sep 27, 2026
1 check passed
@tannevaled
tannevaled deleted the renovate/deps branch September 27, 2026 17:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant