chore(deps): bump the dependencies group across 1 directory with 10 updates#2999
Merged
adriantam merged 1 commit intoMar 24, 2026
mainopenfga/openfga:mainfrom
dependabot/github_actions/dependencies-fd7f3b742bopenfga/openfga:dependabot/github_actions/dependencies-fd7f3b742bCopy head branch name to clipboard
Merged
chore(deps): bump the dependencies group across 1 directory with 10 updates#2999adriantam merged 1 commit intomainopenfga/openfga:mainfrom dependabot/github_actions/dependencies-fd7f3b742bopenfga/openfga:dependabot/github_actions/dependencies-fd7f3b742bCopy head branch name to clipboard
adriantam merged 1 commit into
mainopenfga/openfga:mainfrom
dependabot/github_actions/dependencies-fd7f3b742bopenfga/openfga:dependabot/github_actions/dependencies-fd7f3b742bCopy head branch name to clipboard
Conversation
…pdates Bumps the dependencies group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github/codeql-action](https://github.com/github/codeql-action) | `4.32.5` | `4.34.1` | | [actions/setup-node](https://github.com/actions/setup-node) | `6.2.0` | `6.3.0` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `5.5.2` | `5.5.3` | | [actions/cache](https://github.com/actions/cache) | `5.0.3` | `5.0.4` | | [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) | `4.0.0` | `4.1.0` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.23.0` | `0.24.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.12.0` | `4.0.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `6.19.2` | `7.0.0` | | [docker/login-action](https://github.com/docker/login-action) | `3.7.0` | `4.0.0` | | [slsa-framework/slsa-github-generator](https://github.com/slsa-framework/slsa-github-generator) | `a09dd8c05eda63cace134cb7dccd7e019f25e6f3` | `4d014fae4dbd39eb09e8d40348b73db095e6ba9a` | Updates `github/codeql-action` from 4.32.5 to 4.34.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@c793b71...3869755) Updates `actions/setup-node` from 6.2.0 to 6.3.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@6044e13...53b8394) Updates `codecov/codecov-action` from 5.5.2 to 5.5.3 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@671740a...1af5884) Updates `actions/cache` from 5.0.3 to 5.0.4 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@cdf6c1f...6682284) Updates `sigstore/cosign-installer` from 4.0.0 to 4.1.0 - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](sigstore/cosign-installer@faadad0...ba7bc0a) Updates `anchore/sbom-action` from 0.23.0 to 0.24.0 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@17ae174...e22c389) Updates `docker/setup-buildx-action` from 3.12.0 to 4.0.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@8d2750c...4d04d5d) Updates `docker/build-push-action` from 6.19.2 to 7.0.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@10e90e3...d08e5c3) Updates `docker/login-action` from 3.7.0 to 4.0.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@c94ce9f...b45d80f) Updates `slsa-framework/slsa-github-generator` from a09dd8c05eda63cace134cb7dccd7e019f25e6f3 to 4d014fae4dbd39eb09e8d40348b73db095e6ba9a - [Release notes](https://github.com/slsa-framework/slsa-github-generator/releases) - [Changelog](https://github.com/slsa-framework/slsa-github-generator/blob/main/CHANGELOG.md) - [Commits](slsa-framework/slsa-github-generator@a09dd8c...4d014fa) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.34.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: actions/setup-node dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: codecov/codecov-action dependency-version: 5.5.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: actions/cache dependency-version: 5.0.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: sigstore/cosign-installer dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: anchore/sbom-action dependency-version: 0.24.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: docker/setup-buildx-action dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: docker/build-push-action dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: docker/login-action dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: slsa-framework/slsa-github-generator dependency-version: 4d014fae4dbd39eb09e8d40348b73db095e6ba9a dependency-type: direct:production dependency-group: dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2999 +/- ##
==========================================
- Coverage 90.58% 90.54% -0.04%
==========================================
Files 188 188
Lines 20317 20317
==========================================
- Hits 18402 18393 -9
- Misses 1260 1265 +5
- Partials 655 659 +4 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
adriantam
approved these changes
Mar 24, 2026
fredrikaverpil
added a commit
to fredrikaverpil/openfga
that referenced
this pull request
Jul 12, 2026
Add support for exporting logs via OTLP, allowing integration with any OpenTelemetry-compatible backend (Grafana Loki, Datadog, GCP Cloud Logging, etc.). When log.otlp.enabled is set, logs are exported via OTLP in addition to stdout. The otelzap bridge attaches span context (trace ID, span ID) to each log record, enabling log-trace correlation in backends that support it. Configuration mirrors the trace configuration shape: the standard OTel env vars (OTEL_EXPORTER_OTLP_LOGS_ENDPOINT, OTEL_EXPORTER_OTLP_ENDPOINT) only answer where logs are sent, while the explicit OpenFGA flag (log.otlp.enabled / --log-otlp-enabled / OPENFGA_LOG_OTLP_ENABLED) answers whether to export at all — so a cluster that injects the generic endpoint variable for tracing does not silently start exporting logs on upgrade. zap's production sampling is applied outside the tee, so the keep/drop decision is made once, before fan-out: stdout and OTLP receive the same deterministically sampled stream and collector egress stays bounded during log storms. Changes: - Add otelzap bridge core backed by an OTLP log provider (internal/telemetry/logging.go) - Add WithOTELCore logger option that tees log entries to the bridge. The bridge core is capped to the configured log level, the stdout core strips the bridge-only context field via contextFilterCore, and the sampler wraps the tee (pkg/logger/logger.go) - Attach the context field in the *WithContext logging methods only when an OTEL core is configured, and use those methods in the gRPC logging interceptor so the bridge can extract span context (pkg/middleware/logging/logging.go) - Add config: log.otlp.enabled, log.otlp.endpoint, log.otlp.tls.enabled with OPENFGA_LOG_OTLP_* env vars and OTEL_EXPORTER_OTLP_* endpoint fallbacks (pkg/server/config/config.go, cmd/run/, .config-schema.json) feat: add potential v2 breaking change logs for Expand and ListUsers (openfga#3182) release: update changelog for release 1.18.1 (openfga#3188) release: Update changelog to prep for 1.18.1 release (openfga#3186) test: fix flaky TestV2CheckWithIteratorCache_HigherConsistencyBypassesCache (openfga#3061) Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com> Merge commit from fork * test reproducing ListUsers report * implement fix * additional test with 3 operands fix: match IPv4-mapped IPv6 addresses in the in_cidr condition (openfga#3181) Signed-off-by: kanywst <niwatakuma@icloud.com> fix: use deterministic proto marshaling for stored authorization models (openfga#3171) chore: create draft release and publish after provenance succeeds for immutable tags/releases (openfga#3178) docs: fix changelog entry (openfga#3177) Signed-off-by: Saad Hussain <saad.hussain@okta.com> feat: add v2Check logs for resolution breaking change (openfga#3149) feat: BatchCheck uses v2Check when ExperimentalWeightedGraphCheck is enabled (openfga#3154) Signed-off-by: Saad Hussain <saad.hussain@okta.com> chore: update changelog to add CVE identifiers for recent fixes (openfga#3176) chore: update todo comment string in migration guide (openfga#3175) release: update changelog for release `v1.18.0` (openfga#3174) Co-authored-by: adriantam <adrian.tam@okta.com> Merge commit from fork * fix(authn): require issuer and audience when OIDC authn is enabled Enforce configuration authn.oidc.audience and authn.oidc.issuer when `authn.method` is set to `oidc`. * fixed based on code review feedback * fix: adding comments + test case on empty space for audience * update based on code review feedback * Update CHANGELOG.md Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com> * update changelog * Update CHANGELOG.md --------- Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com> Merge commit from fork * fix(mysql): collate identifier columns as utf8mb4_bin * fix: add operator note to changelog * fix: move tests to shared storage * fix: separate migrations for each table * fix: add runbook for migrations * fix: set lock_wait_timeout * fix: add docker instructions * fix: add docker instructions * fix: combine the migrations back into one, fix documentation for this * fix: include details about table copy and * Update CHANGELOG.md Co-authored-by: Adrian Tam <adrian.tam@okta.com> --------- Co-authored-by: Adrian Tam <adrian.tam@okta.com> fix: use constant-time comparison for preshared key authentication (openfga#3168) chore(deps): bump the dependencies group with 2 updates (openfga#3166) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Justin Cohen <justincoh@gmail.com> chore(deps): bump the dependencies group with 2 updates (openfga#3167) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> release: update changelog for release `v1.17.1` (openfga#3165) Signed-off-by: Saad Hussain <saad.hussain@okta.com> chore: bump grpc-health-probe to v0.4.52 (openfga#3164) Co-authored-by: Saad Hussain <saad.hussain@okta.com> docs: update caching docs (openfga#3163) Signed-off-by: Saad Hussain <saad.hussain@okta.com> fix: continuation token deserializer - handle `|` in type names (openfga#3152) chore(deps): bump the dependencies group across 1 directory with 13 updates (openfga#3162) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Justin Cohen <justincoh@gmail.com> chore(deps): bump the dependencies group across 1 directory with 10 updates (openfga#3156) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Justin Cohen <justincoh@gmail.com> fix: use query start time as iterator cache entry LastModified to prevent stale-read survival (openfga#3155) chore(deps): bump grpc-ecosystem/grpc-health-probe from v0.4.50 to v0.4.51 in the dependencies group (openfga#3157) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Saad Hussain <saad.hussain@okta.com> Co-authored-by: Justin Cohen <justincoh@gmail.com> chore: Bump go toolchain to 1.26.4 (openfga#3159) fix: prevent v2Check from falling back for throttling and validation (openfga#3150) ci: make pr benchmark comparisons less fragile (openfga#3153) Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> release: update changelog for release `v1.17.0` (openfga#3151) Co-authored-by: Vic-Dev <vmichellej@gmail.com> refactor: redesign cache key generation, making it more secure and consistent (openfga#3148) feat: add configurable trace sampler with ParentBased support (openfga#3072) release: update changelog for release `v1.16.1` (openfga#3147) chore: update grpc-health-probe to latest to addres std lib CVEs (openfga#3146) fix: skip v2Check weight2 pruning if iterator is unordered (openfga#3145) Signed-off-by: Saad Hussain <saad.hussain@okta.com> chore: add concurrency-group to PR-related CI steps (openfga#3140) docs: move OIDC JWKS refresh entry from v1.15.1 to v1.16.0 (openfga#3142) fix: when v2Check is primary algorithm, fix fallback condition and emit metrics (openfga#3141) release: update changelog for release `v1.16.0` (openfga#3139) Merge commit from fork * fix: Standardize cache key generation everywhere * Revert "fix: Standardize cache key generation everywhere" This reverts commit ce60c6f9ae48a310a4dea2b824b5993520c8ba1c. * length-encoded approach * Revert "length-encoded approach" This reverts commit b94637c187c57a2d3f3904247267bbc8ad21a41a. * implement Hexer() and use in some cache keys * appendConditionsHash -> generateConditionsHash * mv Hexer -> BuildKey * BuildKey -> BuildCacheKey refactor to BuildCacheKey on each individual prefix component to remove collision risk * make v2 cacheKey functions the standard * make cache key prefixes consistent * generateConditionsHash -> generateConditionsString * delimit condition name string * remove extra empty check * relocate and reuse existing userTypeRestrictions function * replace hashing of conditions for brevity * fix tests * cleanup, add test file * remove unused slice capacity * make prefix treatments consistent * add nil-byte separator in object ids * hash user type restrictions for brevity * update comment string, use nil-byte separator for future-proofing * remove call to xxhash.new * adjustments for performance, consistency, and interface ergonomics. * make condition hash generation more efficient. * add clarifying comments for size caluculations * fix builder growth calculations to match original intentions * update outdated comment * don't hash potentially zero values * Revert "don't hash potentially zero values" This reverts commit 2ad6c5b796bc20a82c1414c5146c3c708330eefa. * add condition key separator unconditionally * patch test expectations for new key structure * export V2IteratorCachePrefix, use in tests --------- Co-authored-by: justin <justin.cohen@okta.com> Co-authored-by: Joshua Jones <joshua.jones@okta.com> fix: unintentional zeroing of slice values by setting slice to nil (openfga#3135) increase the check v2 trace information fidelity (openfga#3134) feat: add datastore ping and ping retry configurations (openfga#3113) fix: prevent v2Check strategies returning spurious false on context cancellation (openfga#3128) Signed-off-by: Saad Hussain <saad.hussain@okta.com> fix(authn/oidc): refresh JWKS on unknown kid to handle key rotation (openfga#3101) fix: v2Check falls back to v1 on errors (openfga#3126) fix: don't cache false results from cancelled-context goroutines in v2Check (openfga#3125) Signed-off-by: Saad Hussain <saad.hussain@okta.com> make union cache key unique by including the node input's label (openfga#3117) Signed-off-by: Saad Hussain <saad.hussain@okta.com> Co-authored-by: Saad Hussain <saad.hussain@okta.com> fix: shadow v2check and check use the same trace (openfga#3118) fix: bump go toolchain version to 1.26.3 (openfga#3115) chore: add more spans/attributes to v1 and v2 Check (openfga#3116) Signed-off-by: Saad Hussain <saad.hussain@okta.com> fix: add matches attribute to shadowv2Check and Check spans (openfga#3114) fix: use the same `request_id` for shadow traces in v2Check (openfga#3110) release: update changelog for release `v1.15.1` (openfga#3112) feat: reuse MySQL container across tests (openfga#3042) fix: close all channels opened thus far, before return on error (openfga#3111) chore: Add more spans/attributes to v2Check (openfga#3102) Signed-off-by: Saad Hussain <saad.hussain@okta.com> fix: ensure acquired limiter token is released on throttle context cancelation (openfga#3106) fix: cancel context before waiting on worker pool in ResolveUnionEdges (openfga#3105) fix: replace golang.org/x/exp/maps with stdlib maps to resolve govet inline errors (openfga#3104) fix: v2Check EdgeCacheKey collisions (openfga#3097) Signed-off-by: Saad Hussain <saad.hussain@okta.com> fix: expose context errors when they can be the potential cause of an underlying datastore error (openfga#3096) chore(deps): bump the dependencies group across 1 directory with 2 updates (openfga#3093) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> fix: move subproblem cache lookup from ResolveUnionEdges into ResolveUnion (openfga#3095) chore(deps): bump the dependencies group with 4 updates (openfga#3092) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> fix: error handler panic (openfga#3091) release: update changelog for release `v1.15.0` (openfga#3090) chore(deps): bump the dependencies group across 1 directory with 4 updates (openfga#3087) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> fix: v2Check correctly uses query cache even when cache controller is disabled (openfga#3086) Signed-off-by: Saad Hussain <saad.hussain@okta.com> chore(deps): bump the dependencies group across 1 directory with 7 updates (openfga#3081) Signed-off-by: dependabot[bot] <support@github.com> chore(deps): bump github.com/jackc/pgx/v5 from 5.9.1 to 5.9.2 (openfga#3085) Signed-off-by: dependabot[bot] <support@github.com> chore(deps): bump grpc-ecosystem/grpc-health-probe from v0.4.47 to v0.4.48 in the dependencies group across 1 directory (openfga#3065) Signed-off-by: dependabot[bot] <support@github.com> feat: try to use UDS internally between HTTP server and gRPC server (openfga#2937) feat: add jitter to internal cache TTLs to prevent thundering herd effects (openfga#3033) Signed-off-by: Asish Kumar <officialasishkumar@gmail.com> list objects pipeline edge pruning (openfga#3075) update toolchain go to 1.26.2 to address stdlib CVEs (openfga#3084) chore: add store ID and datastore query/item count to shadowV2Check log (openfga#3073) Signed-off-by: Saad Hussain <saad.hussain@okta.com> CI speed up (openfga#3062) Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com> Co-authored-by: Joshua Jones <joshua.jones@okta.com> Add tracing to v2 Check planner strategy selection (openfga#3077) fix: v2Check honours `check-query-cache-enabled` flag (openfga#3070) Signed-off-by: Saad Hussain <saad.hussain@okta.com> feat: reuse PostgreSQL container across tests (openfga#3018) chore: fix reporter links in changelog (openfga#3069) release: update changelog for release `v1.14.2` (openfga#3068) fix: add null byte delimiter in contextual tuple cache keys and validation in v2Check (openfga#3064) release: update changelog for release `v1.14.1` (openfga#3060) chore(deps): bump the dependencies group across 1 directory with 7 updates (openfga#3056) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Adrian Tam <adrian.tam@okta.com> fix: use a baseURL for AuthZEN configuration endpoint (openfga#3057) chore: replace docker with moby (openfga#3047) Iterator Cache V2: Storage Wrapper Pattern with Lock-Free Design (openfga#3016) Signed-off-by: Saad Hussain <saad.hussain@okta.com> Co-authored-by: Saad Hussain <saad.hussain@okta.com> Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com> test: fix flaky condition test (openfga#3058) Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> chore(deps): bump the dependencies group across 1 directory with 6 updates (openfga#3045) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp from 1.41.0 to 1.43.0 (openfga#3054) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Adrian Tam <adrian.tam@okta.com> feat: add graceful shutdown timeout configuration (openfga#2976) chore: update changelog to reflect playground off-by-default behavior (openfga#3053) chore: decouple Error() and Unwrap() (openfga#3051) perf: remove `fmt` from cache key generation (openfga#3006) perf: enhancements for list objects (openfga#3043) chore: remove stale notice file (openfga#3050) docs: update 1.14.0 for CVE fix (openfga#3046) feat: Add datastore throttling & concurrency limiting to v2Check (openfga#3035) Signed-off-by: Saad Hussain <saad.hussain@okta.com> release: update changelog for release `v1.14.0` (openfga#3040) batch check cache (openfga#3025) Merge commit from fork Also prevent enabling playground when the server requires authentication feat: add stats on tuple iterator query (openfga#3030) fix: remove unnecessary non-deterministic test (openfga#3038) remove unnecessary import (openfga#3032) perf: improve the intersection algorithm, reducing latency and memory use (openfga#3031) fix: ListObjects pipeline algorithm enhancements and fix for potential deadlock (openfga#3028) chore: Also update openfga/helm-charts in release script (openfga#3010) chore: update CICD to enforce GRPC healthprobe changes (openfga#2990) fix: SQL `TupleOperation` serialization and `pgx.ErrNoRows` error handling (openfga#3014) docs: update changelog for CVE-2026-33729 (openfga#3017) chore: output the diff after running keep-a-changelog (openfga#3015) chore(deps): bump the dependencies group across 1 directory with 11 updates (openfga#2998) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore(deps): bump the dependencies group across 1 directory with 10 updates (openfga#2999) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> release: update changelog for release `v1.13.1` (openfga#3002) Merge commit from fork * strip unicode control characters, encode context key length in cache key * add cache_key tests to ensure we escape control characters and encode context key length * run linter * docs: update changelog * Apply suggestion from @adriantam Co-authored-by: Adrian Tam <adrian.tam@okta.com> * Apply suggestion from @adriantam Co-authored-by: Adrian Tam <adrian.tam@okta.com> --------- Co-authored-by: Saad Hussain <saad.hussain@okta.com> Co-authored-by: Saad Hussain <saad.h@outlook.com> Co-authored-by: Adrian Tam <adrian.tam@okta.com> release: update changelog for release `v1.13.0` (openfga#2997) refactor: Separate caches for v1 and v2 Check (openfga#2968) Co-authored-by: Justin Cohen <justincoh@gmail.com> docs: fix typos in comments (openfga#2972) Signed-off-by: Artem Muterko <artem@sopho.tech> Co-authored-by: Adrian Tam <adrian.tam@okta.com> observability: aggregate message statistics for each list-objects sender into a single span (openfga#2993) Co-authored-by: Justin Cohen <justincoh@gmail.com> fix: capture panics in pipeline's base resolver, and return as errors. (openfga#2994) docs: fix typos in RELEASES.md and Makefile (openfga#2980) Co-authored-by: Adrian Tam <adrian.tam@okta.com> AuthZen v1.0 Implementation (openfga#2875) Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Rokibul Hasan <mdrokibulhasan@appscode.com> Signed-off-by: Vihang Mehta <vihang@gimletlabs.ai> Co-authored-by: Karl Persson <kalle.persson92@gmail.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Maria Ines Parnisari <maria.inesparnisari@okta.com> Co-authored-by: Rokibul Hasan <mdrokibulhasan18@gmail.com> Co-authored-by: José Padilla <jose.padilla@okta.com> Co-authored-by: Adrian Tam <adrian.tam@okta.com> Co-authored-by: Vihang Mehta <vihang@gimletlabs.ai> Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com> Co-authored-by: Justin Cohen <justincoh@gmail.com> release: update changelog for release `v1.12.1` (openfga#2992) chore(deps): bump google.golang.org/grpc from 1.79.1 to 1.79.3 (openfga#2988) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Adrian Tam <adrian.tam@okta.com> chore: enforce minor version upgrade rule (openfga#2978) Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> perf: tuple validation performance tweaks (openfga#2984) fix: support URI schemes in OTLP endpoint configuration (openfga#2981) refactor: remove custom pipes and replace with channels (openfga#2977) chore(docs): added caching docs (openfga#2664) Co-authored-by: Saad Hussain <saad.hussain@okta.com> release: update changelog for release `v1.12.0` (openfga#2974) chore: update toolchain go to 1.26.1 (openfga#2975) fix: update toolchain go to 1.25.8 to address stdlib CVEs (openfga#2971) fix: correct swapped format args in DecodeParameterType error message (openfga#2961) Signed-off-by: Artem Muterko <artem@sopho.tech> Co-authored-by: Adrian Tam <adrian.tam@okta.com> perf: small tweaks to tuple validation functions (openfga#2963) Co-authored-by: Vic-Dev <vmichellej@gmail.com> test: add tests for condition parameter type any with complex context structures (openfga#2959) Signed-off-by: Artem Muterko <artem@sopho.tech> test: add functional test for ReadAssertions API endpoint (openfga#2960) Signed-off-by: Artem Muterko <artem@sopho.tech> Co-authored-by: Adrian Tam <adrian.tam@okta.com> make configurable the maximum received grpc message size (openfga#2952) Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> fix: set ExperimentalPipelineListObjects in experimentals by default (openfga#2957) fix: `cache_item_count` metric overcounting (openfga#2950) Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> chore(deps): bump the dependencies group across 1 directory with 7 updates (openfga#2953) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Adrian Tam <adrian.tam@okta.com> refactor: Make shadowV2Check final log clearer (openfga#2946) Move telemetry package to internal/telemetry (openfga#2938) Signed-off-by: Oleksandr Shestopal <ar.shestopal-oshegithub@gmail.com> Co-authored-by: Adrian Tam <adrian.tam@okta.com> chore(deps): bump the dependencies group across 1 directory with 3 updates (openfga#2956) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> fix: Resolve race condition in check reducers (openfga#2947) Co-authored-by: Adrian Tam <adrian.tam@okta.com> fix: gateway grpc client tls cert rotation (openfga#2951) Signed-off-by: Shashank Goel <goelshashank13@gmail.com> fix: disable LO pipeline if ff has it set for a store (openfga#2945) chore(deps): bump the dependencies group across 1 directory with 4 updates (openfga#2949) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> fix: various random fixes (openfga#2942) refactor: check using weighted graph (openfga#2816) Co-authored-by: Yissell Garma <yissell.garma@okta.com> release: update changelog for release `v1.11.6` (openfga#2939) feat: enable pipeline algorithm by default (openfga#2921) add tests to exercise reported bug (openfga#2934) Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Co-authored-by: Adrian Tam <adrian.tam@okta.com> refine AGENTS.md to make it more concise with higher value. (openfga#2936) Co-authored-by: Justin Cohen <justincoh@gmail.com> migrate grpc dial context to NewClient (openfga#2714) Co-authored-by: Adrian Tam <adrian.tam@okta.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> chore(deps): bump filippo.io/edwards25519 from 1.1.0 to 1.1.1 (openfga#2935) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the dependencies group with 10 updates in the / directory:
4.32.54.34.16.2.06.3.05.5.25.5.35.0.35.0.44.0.04.1.00.23.00.24.03.12.04.0.06.19.27.0.03.7.04.0.0a09dd8c05eda63cace134cb7dccd7e019f25e6f34d014fae4dbd39eb09e8d40348b73db095e6ba9aUpdates
github/codeql-actionfrom 4.32.5 to 4.34.1Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
3869755Merge pull request #3763 from github/update-v4.34.1-095e0fe5020e68acUpdate changelog for v4.34.1095e0feMerge pull request #3762 from github/henrymercer/downgrade-default-bundle47b94feAdd changelog note51a1d69Downgrade default bundle to codeql-bundle-v2.24.3510cf73Merge pull request #3589 from github/mergeback/v4.34.0-to-main-c6f9311089f0c86Rebuildc3f90baUpdate changelog and version after v4.34.0c6f9311Merge pull request #3588 from github/update-v4.34.0-30c555a52eeb9b3fUpdate changelog for v4.34.0Updates
actions/setup-nodefrom 6.2.0 to 6.3.0Release notes
Sourced from actions/setup-node's releases.
Commits
53b8394Bump minimatch from 3.1.2 to 3.1.5 (#1498)54045abScope test lockfiles by package manager and update cache tests (#1495)c882bffReplace uuid with crypto.randomUUID() (#1378)774c1d6feat(node-version-file): support parsingdevEnginesfield (#1283)efcb663fix: remove hardcoded bearer (#1467)d02c89dFix npm audit issues (#1491)Updates
codecov/codecov-actionfrom 5.5.2 to 5.5.3Release notes
Sourced from codecov/codecov-action's releases.
Changelog
Sourced from codecov/codecov-action's changelog.
... (truncated)
Commits
1af5884chore(release): bump to 5.5.3 (#1922)c143300build(deps): bump actions/github-script from 7.0.1 to 8.0.0 (#1874)Updates
actions/cachefrom 5.0.3 to 5.0.4Release notes
Sourced from actions/cache's releases.
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
6682284Merge pull request #1738 from actions/prepare-v5.0.4e340396Update RELEASES8a67110Add licenses1865903Update dependencies & patch security vulnerabilities5656298Merge pull request #1722 from RyPeck/patch-14e380d1Fix cache key in examples.md for bun.lockb7e8d49Merge pull request #1701 from actions/Link-/fix-proxy-integration-tests984a21bAdd traffic sanity check stepacf2f1fFix resolution95a07c5Add wait for proxyUpdates
sigstore/cosign-installerfrom 4.0.0 to 4.1.0Release notes
Sourced from sigstore/cosign-installer's releases.
Commits
ba7bc0afix: add retry to curl downloads for transient network failures (#210)5a292e1Bump cosign to 3.0.5 (#220)351ea76Bump actions/checkout from 6.0.1 to 6.0.2 (#217)c17565ftest with go 1.26 too (#221)a6fdd19Bump actions/setup-go from 6.1.0 to 6.3.0 (#218)430b6a7docs: fix registry from gcr.io to ghcr.io (#213)4d14d7ffeat: update to v3.0.3 (#212)f148005fix: use env vars for template expansions; show curl errors (#207)c3f2d79Bump actions/checkout from 6.0.0 to 6.0.1 (#208)b9a9af4drop tests with go1.24 as it cant build (#211)Updates
anchore/sbom-actionfrom 0.23.0 to 0.24.0Release notes
Sourced from anchore/sbom-action's releases.
Commits
e22c389chore(deps): update Syft to v1.42.3 (#615)36a5fdechore: update to node 24 + deps (#614)a0a6512chore(deps): bump actions/setup-node from 6.2.0 to 6.3.0 (#608)57aae52chore(deps): update Syft to v1.42.2 (#607)c29e913chore(deps): bump fast-xml-parser and other deps (#604)Updates
docker/setup-buildx-actionfrom 3.12.0 to 4.0.0Release notes
Sourced from docker/setup-buildx-action's releases.
Commits
4d04d5dMerge pull request #485 from docker/dependabot/npm_and_yarn/docker/actions-to...cd74e05chore: update generated contenteee38ecbuild(deps): bump@docker/actions-toolkitfrom 0.77.0 to 0.79.07a83f65Merge pull request #484 from docker/dependabot/github_actions/docker/setup-qe...a5aa967Merge pull request #464 from crazy-max/rm-deprecatede73d53fbuild(deps): bump docker/setup-qemu-action from 3 to 428a438eMerge pull request #483 from crazy-max/node24034e9d3chore: update generated contentb4664d8remove deprecated inputs/outputsa8257denode 24 as default runtimeUpdates
docker/build-push-actionfrom 6.19.2 to 7.0.0Release notes
Sourced from docker/build-push-action's releases.
Commits
d08e5c3Merge pull request #1479 from docker/dependabot/npm_and_yarn/docker/actions-t...cbd2dffchore: update generated contentf76f51fchore(deps): Bump@docker/actions-toolkitfrom 0.78.0 to 0.79.07d03e66Merge pull request #1473 from crazy-max/rm-deprecated-envs98f853dchore: update generated contentcadccf6remove deprecated envs03fe877Merge pull request #1478 from docker/dependabot/github_actions/docker/setup-b...827e366chore(deps): Bump docker/setup-buildx-action from 3 to 4e25db87Merge pull request #1474 from crazy-max/rm-export-build-tool1ac2573Merge pull request #1470 from crazy-max/node24Updates
docker/login-actionfrom 3.7.0 to 4.0.0Release notes
Sourced from docker/login-action's releases.
Commits
b45d80fMerge pull request #929 from crazy-max/node24176cb9cnode 24 as default runtimecad8984Merge pull request #920 from docker/dependabot/npm_and_yarn/aws-sdk-dependenc...92cbcb2chore: update generated content5a2d6a7build(deps): bump the aws-sdk-dependencies group with 2 updates44512b6Merge pull request #928 from docker/dependabot/npm_and_yarn/docker/actions-to...28737a5chore: update generated contentdac0793build(deps): bump@docker/actions-toolkitfrom 0.76.0 to 0.77.062029f3Merge pull request #919 from docker/dependabot/npm_and_yarn/actions/core-3.0.008c8f06chore: update generated contentUpdates
slsa-framework/slsa-github-generatorfrom a09dd8c05eda63cace134cb7dccd7e019f25e6f3 to 4d014fae4dbd39eb09e8d40348b73db095e6ba9aChangelog
Sourced from slsa-framework/slsa-github-generator's changelog.
... (truncated)
Commits
4d014fachore: Update CODEOWNERS (#4469)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)Description has been truncated