Skip to content

chore(deps): bump the go-modules group with 2 updates - #132

Merged
ralyodio merged 1 commit into
mainfrom
dependabot/go_modules/go-modules-866a958019
Sep 25, 2026
Merged

ralyodio merged 1 commit into
mainfrom
dependabot/go_modules/go-modules-866a958019

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-modules group with 2 updates: github.com/livekit/protocol and modernc.org/sqlite.

Updates github.com/livekit/protocol from 1.51.1-0.20260903060125-0cf5ba018b8e to 1.52.0

Release notes

Sourced from github.com/livekit/protocol's releases.

@​livekit/protocol@​1.52.0

Minor Changes

Patch Changes

  • Add AgentGrant.DispatchAdmin - #1744 (@​erikhortsch)

  • Add fuzz test for data track packet deserialization - #1759 (@​ladvoc)

  • Add a dotnet field to the ClientInfo to track community dotnet sdk usage - #1789 (@​MaxHeimbrock)

  • Move data track packet serialization from livekit package - #1757 (@​ladvoc)

  • Add flexfec-03 codec parameters and mime type helpers - #1805 (@​chenosaurus)

  • Replace logger.WithTap with logger.WithTee, which duplicates every log entry to a caller-supplied zaputil.Tee. The tee's core is built from the level each derived logger resolves, so the copy follows component levels rather than carrying a level of its own. - #1790 (@​paulwe)

    Replace ZapLogger.WithMinLevel with WithComponentLeveler, which attaches a zaputil.ComponentLeveler to a branch of the logger tree. A leveler owns the per-component level and write-enabler cache for one configuration source and can only widen its parent, so a caller can resolve levels per (tenant, component) without rebuilding loggers on a config change. ZapLogger.Leveler exposes the leveler a branch resolves through, for use as the parent of a derived one.

  • Change GRPC code mapping for SIP 480/486 - #1766 (@​ChelseaBradbury)

  • Add psrpc bus compression settings to PSRPCConfig - #1771 (@​paulwe)

  • sdp: harden SDPFragment.Unmarshal against out-of-range accesses - #1767 (@​boks1971)

  • agent simulation: merge accuracy_score and experience_score into a single overall_score on SimulationRun.JobMetrics and SimulationRun.RunMetrics; the old field numbers and names are reserved. - #1800 (@​u9g)

  • Add SimulationRun.CI — the provider, commit, ref, pull request, run URL, and actor of the pipeline that started a run — to SimulationRun.Create.Request and to SimulationRun, so the dashboard can link a run back to the CI job that produced it. - #1758 (@​u9g)

  • Add name field to the phone numbers. - #1781 (@​dennwc)

  • Add separate inbound and outbound statuses for phone numbers. - #1784 (@​dennwc)

  • Report SIP transfer failures with a SIPTransferError detail on the error - #1782 (@​genseric-ghiro)

  • sip: fix panic in EvaluateDispatchRule on an empty From user part - #1768 (@​hechen-eng)

Changelog

Sourced from github.com/livekit/protocol's changelog.

1.52.0

Minor Changes

  • Add new SIPAuthentication error codes. - #1798 (@​alexfish8)

  • Replace logger.WithTap with logger.WithTee, which duplicates every log entry to a caller-supplied zaputil.Tee. The tee's core is built from the level each derived logger resolves, so the copy follows component levels rather than carrying a level of its own. - #1790 (@​paulwe)

    Replace ZapLogger.WithMinLevel with WithComponentLeveler, which attaches a zaputil.ComponentLeveler to a branch of the logger tree. A leveler owns the per-component level and write-enabler cache for one configuration source and can only widen its parent, so a caller can resolve levels per (tenant, component) without rebuilding loggers on a config change. ZapLogger.Leveler exposes the leveler a branch resolves through, for use as the parent of a derived one.

Patch Changes

  • Add AgentGrant.DispatchAdmin - #1744 (@​erikhortsch)

  • Add fuzz test for data track packet deserialization - #1759 (@​ladvoc)

  • Add a dotnet field to the ClientInfo to track community dotnet sdk usage - #1789 (@​MaxHeimbrock)

  • Move data track packet serialization from livekit package - #1757 (@​ladvoc)

  • Add flexfec-03 codec parameters and mime type helpers - #1805 (@​chenosaurus)

  • Change GRPC code mapping for SIP 480/486 - #1766 (@​ChelseaBradbury)

  • Add psrpc bus compression settings to PSRPCConfig - #1771 (@​paulwe)

  • sdp: harden SDPFragment.Unmarshal against out-of-range accesses - #1767 (@​boks1971)

  • agent simulation: merge accuracy_score and experience_score into a single overall_score on SimulationRun.JobMetrics and SimulationRun.RunMetrics; the old field numbers and names are reserved. - #1800 (@​u9g)

  • Add SimulationRun.CI — the provider, commit, ref, pull request, run URL, and actor of the pipeline that started a run — to SimulationRun.Create.Request and to SimulationRun, so the dashboard can link a run back to the CI job that produced it. - #1758 (@​u9g)

  • Add name field to the phone numbers. - #1781 (@​dennwc)

  • Add separate inbound and outbound statuses for phone numbers. - #1784 (@​dennwc)

  • Report SIP transfer failures with a SIPTransferError detail on the error - #1782 (@​genseric-ghiro)

  • sip: fix panic in EvaluateDispatchRule on an empty From user part - #1768 (@​hechen-eng)

1.51.0

Minor Changes

  • egress v2: add passthrough to the encoding oneof on StartEgressRequest and ExportReplayRequest; remove the unused EgressHandler.UpdateEgress RPC and the livekit.UpdateEgressRequest message - #1716 (@​frostbyte73)

  • add RoomEndReason enum and report it on room-ended telemetry: AnalyticsEvent.room_end_reason and WebhookEvent.room_end_reason now say why a room ended (ROOM_END_API_DELETE, ROOM_END_IDLE_TIMEOUT, ROOM_END_SERVER_SHUTDOWN, ROOM_END_SUPERSEDED, ROOM_END_OPEN_FAILED), so room-end volume can be broken down by cause the way participant disconnects already are - #1748 (@​paulwe)

  • TransferSIPParticipant now returns TransferSIPParticipantResponse instead of google.protobuf.Empty, carrying the transfer id, status, a new SIPTransferReason and the SIP status when the outcome came from a SIP response. SIPTransferInfo gains the same reason. This changes the generated method signature: a transfer that reports a non-successful status without an error means the transfer did not complete. - #1730 (@​genseric-ghiro)

... (truncated)

Commits

Updates modernc.org/sqlite from 1.58.0 to 1.59.0

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

---
updated-dependencies:
- dependency-name: github.com/livekit/protocol
  dependency-version: 1.52.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules
- dependency-name: modernc.org/sqlite
  dependency-version: 1.59.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 24, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgithub.com/​livekit/​protocol@​v1.51.1-0.20260903060125-0cf5ba018b8e ⏵ v1.52.074 +1100100100100
Updatedmodernc.org/​sqlite@​v1.58.0 ⏵ v1.59.077 +110010010080

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
License policy violation: golang modernc.org/sqlite under LZMA-SDK-9.22

License: LZMA-SDK-9.22 - The applicable license policy does not permit this license (5) (LICENSE-SQLITE)

From: go.mod → golang/modernc.org/sqlite@v1.59.0

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/modernc.org/sqlite@v1.59.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@ralyodio
ralyodio merged commit 5bec301 into main Sep 25, 2026
6 checks passed
@dependabot
dependabot Bot deleted the dependabot/go_modules/go-modules-866a958019 branch September 25, 2026 02:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant