Skip to content

fix(deps): update dependencies - #247

Open
tannevaled wants to merge 1 commit into
mainfrom
renovate/deps
Open

tannevaled wants to merge 1 commit into
mainfrom
renovate/deps

Conversation

@tannevaled

@tannevaled tannevaled commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence Type Update
github.com/chromedp/cdproto v0.0.0-20260922220944-a19bff23514f → v0.157.9 age confidence require minor
github.com/chromedp/chromedp v0.16.0 → v0.20.1 age confidence require minor
github.com/dop251/goja 39ec265 → a4bedf5 age confidence require digest
github.com/go-browserhttp/browserhttp v0.2.0 → v0.3.0 age confidence require minor
github.com/go-gfx/gfx v0.34.0 → v0.35.0 age confidence require minor
github.com/go-images/images v0.0.0-20260927173152-87444e36aac4 → v0.1.0 age confidence require minor
github.com/go-opentype/fonts v0.10.0 → v0.12.0 age confidence require minor
github.com/go-opentype/opentype v0.13.1-0.20260927180318-ae6327b14eac → v0.15.0 age confidence require minor
github.com/go-webengine/esbuildsandbox v0.1.0 → v0.2.0 age confidence require minor
github.com/go-widgets/painter v0.13.0 → v0.15.0 age confidence require minor
golang.org/x/image v0.46.0 → v0.47.0 age confidence require minor
golang.org/x/net v0.59.0 → v0.61.0 age confidence require minor

Release Notes

chromedp/cdproto (github.com/chromedp/cdproto)

v0.157.9

Compare Source

v0.157.8

Compare Source

v0.157.7

Compare Source

  • Chromium: 157.0.8086.1 (was 157.0.8085.3)
  • V8: 15.7.37 (was 15.7.33)
  • API changes since v0.157.6: 0 incompatible, 0 compatible

v0.157.6

Compare Source

  • Chromium: 157.0.8085.3 (was 157.0.8085.2)
  • V8: 15.7.33
  • API changes since v0.157.5: 0 incompatible, 0 compatible

v0.157.5

Compare Source

  • Chromium: 157.0.8085.2 (was 157.0.8085.1)
  • V8: 15.7.33
  • API changes since v0.157.4: 0 incompatible, 0 compatible

v0.157.4

Compare Source

  • Chromium: 157.0.8085.1
  • V8: 15.7.33
  • API changes since v0.157.3: 72 incompatible, 1 compatible

By package, as removed, changed and added names:

accessibility 0 removed 1 changed 0 added
animation 0 removed 1 changed 0 added
audits 0 removed 1 changed 0 added
browser 0 removed 2 changed 0 added
cdp 1 removed 0 changed 0 added
css 0 removed 1 changed 0 added
debugger 0 removed 2 changed 0 added
dom 0 removed 3 changed 0 added
domdebugger 0 removed 1 changed 0 added
emulation 0 removed 19 changed 0 added
har 0 removed 7 changed 0 added
headlessexperimental 0 removed 1 changed 0 added
indexeddb 0 removed 2 changed 0 added
input 0 removed 8 changed 0 added
io 0 removed 1 changed 0 added
layertree 0 removed 1 changed 0 added
network 0 removed 5 changed 1 added
overlay 0 removed 2 changed 0 added
page 0 removed 6 changed 0 added
runtime 0 removed 1 changed 0 added
storage 0 removed 1 changed 0 added
target 0 removed 2 changed 0 added
webauthn 0 removed 3 changed 0 added

v0.157.3

Compare Source

  • Chromium: 157.0.8085.1
  • V8: 15.7.33
  • API changes since v0.157.2: 2237 incompatible, 1079 compatible

By package, as removed, changed and added names:

accessibility 30 removed 17 changed 8 added
ads 4 removed 4 changed 2 added
animation 15 removed 20 changed 7 added
audits 8 removed 9 changed 3 added
autofill 7 removed 8 changed 1 added
backgroundservice 4 removed 8 changed 2 added
bluetoothemulation 20 removed 40 changed 6 added
browser 45 removed 47 changed 10 added
cachestorage 14 removed 12 changed 3 added
cast 7 removed 12 changed 2 added
cdp 4 removed 0 changed 6 added
crashreportcontext 2 removed 2 changed 1 added
css 76 removed 79 changed 35 added
debugger 69 removed 71 changed 16 added
deviceaccess 4 removed 8 changed 1 added
deviceorientation 2 removed 4 changed 0 added
digitalcredentials 4 removed 2 changed 0 added
dom 136 removed 116 changed 51 added
domdebugger 13 removed 17 changed 1 added
domsnapshot 8 removed 10 changed 1 added
domstorage 7 removed 12 changed 5 added
emulation 105 removed 98 changed 7 added
eventbreakpoints 3 removed 6 changed 0 added
extensions 13 removed 17 changed 3 added
fedcm 9 removed 16 changed 2 added
fetch 26 removed 24 changed 4 added
filesystem 2 removed 2 changed 1 added
findinpage 4 removed 8 changed 0 added
har 0 removed 2 changed 1 added
headlessexperimental 6 removed 3 changed 1 added
heapprofiler 28 removed 33 changed 9 added
indexeddb 36 removed 18 changed 4 added
input 65 removed 30 changed 1 added
inspector 2 removed 4 changed 4 added
io 7 removed 6 changed 2 added
layertree 21 removed 20 changed 8 added
log 5 removed 10 changed 1 added
media 2 removed 4 changed 5 added
memory 18 removed 23 changed 5 added
network 69 removed 96 changed 54 added
overlay 51 removed 59 changed 9 added
page 133 removed 132 changed 47 added
performance 5 removed 6 changed 2 added
performancetimeline 1 removed 2 changed 1 added
preload 2 removed 4 changed 6 added
profiler 16 removed 21 changed 7 added
pwa 14 removed 15 changed 3 added
runtime 77 removed 71 changed 19 added
security 3 removed 6 changed 1 added
serviceworker 12 removed 24 changed 3 added
smartcardemulation 14 removed 36 changed 14 added
storage 39 removed 54 changed 15 added
systeminfo 6 removed 6 changed 3 added
target 54 removed 46 changed 16 added
tethering 2 removed 4 changed 1 added
tracing 20 removed 17 changed 6 added
webaudio 4 removed 6 changed 14 added
webauthn 25 removed 46 changed 7 added
webmcp 5 removed 8 changed 5 added

v0.157.2

Compare Source

  • Chromium: 157.0.8085.1 (was 157.0.8084.3)
  • V8: 15.7.33 (was 15.7.23)
  • API changes since v0.157.1: 0 incompatible, 0 compatible

v0.157.1

Compare Source

  • Chromium: 157.0.8084.3
  • V8: 15.7.23
  • API changes since v0.157.0: 267 incompatible, 493 compatible

By package, as removed, changed and added names:

accessibility 4 removed 0 changed 0 added
animation 0 removed 1 changed 4 added
audits 29 removed 2 changed 4 added
autofill 1 removed 0 changed 0 added
backgroundservice 1 removed 0 changed 0 added
bluetoothemulation 5 removed 0 changed 0 added
browser 4 removed 3 changed 9 added
cachestorage 1 removed 0 changed 0 added
cdp 11 removed 0 changed 0 added
css 2 removed 3 changed 17 added
debugger 1 removed 13 changed 49 added
digitalcredentials 1 removed 0 changed 0 added
dom 3 removed 6 changed 10 added
domdebugger 2 removed 0 changed 0 added
emulation 5 removed 15 changed 37 added
extensions 1 removed 0 changed 0 added
fedcm 4 removed 0 changed 0 added
fetch 1 removed 2 changed 7 added
headlessexperimental 0 removed 1 changed 4 added
indexeddb 0 removed 2 changed 9 added
input 2 removed 12 changed 28 added
layertree 0 removed 1 changed 4 added
log 0 removed 4 changed 29 added
media 0 removed 1 changed 5 added
memory 1 removed 0 changed 0 added
network 27 removed 11 changed 77 added
overlay 4 removed 1 changed 3 added
page 10 removed 18 changed 44 added
performance 0 removed 2 changed 3 added
preload 6 removed 0 changed 0 added
pwa 1 removed 0 changed 0 added
runtime 0 removed 9 changed 142 added
security 4 removed 0 changed 0 added
serviceworker 3 removed 0 changed 0 added
smartcardemulation 5 removed 0 changed 0 added
storage 2 removed 0 changed 0 added
systeminfo 2 removed 0 changed 0 added
target 1 removed 0 changed 0 added
tracing 4 removed 3 changed 8 added
webaudio 5 removed 0 changed 0 added
webauthn 3 removed 0 changed 0 added
webmcp 1 removed 0 changed 0 added

chromedp/chromedp (github.com/chromedp/chromedp)

v0.20.1

Compare Source

Documentation only. The README, the package documentation and the docs have the current versions (chromedp v0.20.0, cdproto v0.157.8, remote v0.2.0), the CI matrix and the release history. The README describes termcast and the 43 programs of chromedp/examples.

v0.20.0

Compare Source

chromedp supports Go 1.25 and later. Before this release, the module needed Go 1.27 (see #​1536).

  • The JSON types come from github.com/chromedp/cdproto/cdp/jsonv2. With Go 1.27 or GOEXPERIMENT=jsonv2 they are aliases of the types of the standard encoding/json/v2 and jsontext, so the public API is the same. With Go 1.25 and 1.26 they come from github.com/go-json-experiment/json.
  • The modules chromedp, remote and test use go 1.25 and cdproto v0.157.8.
  • The CI runs Go 1.25, 1.26 and stable on Linux, stable on Windows and macOS, and the experiment and the compatibility tag.

v0.19.1

Compare Source

Documentation only. The README and the package documentation describe termcast, which draws the screen of a page in a terminal, and the 43 programs of chromedp/examples.

v0.19.0

Compare Source

This release adds new actions and options, fixes bugs, and works on Linux, Windows and macOS in CI. See docs/MIGRATION.md for every change.

New

  • Tap and TapXY send a touch tap.
  • DragAndDrop and DragAndDropXY drag and drop with the mouse and with HTML5 drag and drop.
  • Console reads the console, the uncaught exceptions and the browser log of a page as one iterator.
  • ExposeFunc calls a Go function from the page, like exposeFunction in Puppeteer.
  • PrintToPDF takes options for the paper, the margins, the scale, the page ranges, the header and the footer, the outline and a stream.
  • WithNewWindow chooses a window or a tab for a new target. NoInheritEnv starts the browser with only the given variables. WithDetachOnCancel leaves the tab open when the context ends.
  • EvalAwaitPromise waits for a promise that an expression returns.

Fixed

  • Call on a Target or a Browser returns an error when the connection to the browser is lost, and does not hang.
  • The exec allocator keeps the order of the flags.
  • WaitNotPresent works with a JSPath that gives null or an empty list.
  • Evaluate returns ErrJSNull for null when the type cannot be nil, and Text works on a text node.
  • The pipe transport, the allocator and the tests work on Windows and macOS, and the default browser lookup on Windows falls back to Microsoft Edge.

Notes

  • Use errors.Is(err, context.Canceled) and not == for the error of a call after the connection was lost.
  • The tests run on Linux, Windows and macOS in CI, and every night against the stable, beta and dev channels of headless-shell.
  • The module github.com/chromedp/chromedp/remote is unchanged and stays at remote/v0.1.0.

v0.18.0

Compare Source

v0.17.1

Compare Source

v0.17.0

Compare Source

go-browserhttp/browserhttp (github.com/go-browserhttp/browserhttp)

v0.3.0

Compare Source

v0.2.1

Compare Source

go-gfx/gfx (github.com/go-gfx/gfx)

v0.35.0: — bound the surface and the embedded raster

Compare Source

A security release. Behaviour change: svg.Rasterize now returns an error
for a surface past Options.MaxPixels, which is why it is a minor rather than
a patch. Callers wanting a larger canvas set MaxPixels.

An SVG is text, and two of the numbers in it decide allocations: the
document's own width/height, and the dimensions an embedded
<image href="data:…"> declares in its header. A surface is four bytes a pixel.

input before after
~110 bytes declaring width="40000" height="40000" 6103.5 MiB, rasterised without complaint 0.0 MiB, refused
a 246-byte SVG whose <image> claims 20000×20000 1526.1 MiB held, then drawn into a 100×100 square 0.0 MiB, skipped
a 5000×5000 document 95.4 MiB 95.4 MiB, unchanged

⛔ Nothing about the size of either input hints at the size of the output — and
drawImage skips decode failures in silence, so the gigabyte was allocated
and nothing anywhere said so.

What the fix is

Options.MaxPixels, defaulting to DefaultMaxPixels = 40 000 000 pixels
(a hundred and sixty million bytes) — the same ceiling go-pdfkit/render
already uses, so the fleet has one number for this rather than two.

  • ⛔ the embedded picture is refused from its header, via
    image.DecodeConfig, before anything is decoded: a ceiling enforced after
    the allocation it bounds is not a ceiling, it is a comment;
  • ⛔ both products are computed in int64 — two numbers a file chose,
    multiplied in int on a 32-bit build, is how a ceiling is passed by
    overflowing past it (386 is in the build matrix);
  • Scale counts towards it: the surface is the product, and only one of the
    two numbers is ours.
Also

A <line> whose two ends coincide was the module's single uncovered
statement, and the 100 % gate passed anyway because the total rounds up across
seven packages. ⛔ A gate that passes by rounding will one day pass over a real
gap. Closed.

100 % statement coverage, -race green, twelve CI checks across eight
architectures, four mutations against the ceilings all caught.

v0.34.1

Compare Source

go-opentype/fonts (github.com/go-opentype/fonts)

v0.12.0

Compare Source

v0.11.0

Compare Source

go-opentype/opentype (github.com/go-opentype/opentype)

v0.15.0

Compare Source

go-webengine/esbuildsandbox (github.com/go-webengine/esbuildsandbox)

v0.2.0

Compare Source

v0.1.1

Compare Source

go-widgets/painter (github.com/go-widgets/painter)

v0.15.0

Compare Source

v0.14.0

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@tannevaled tannevaled changed the title fix(deps): update github.com/dop251/goja digest to 0f92c90 fix(deps): update dependencies Oct 2, 2026
@tannevaled

tannevaled commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: bench/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 8 additional dependencies were updated

Details:

Package Change
github.com/ajroetker/go-highway v0.0.4 -> v0.0.12
github.com/go-gfx/gfx v0.34.0 -> v0.34.1
github.com/go-images/gif v0.1.0 -> v0.2.0
github.com/go-images/jpeg v0.2.0 -> v0.3.0
github.com/go-images/jpeg2000 v0.1.0 -> v0.13.2
github.com/go-images/png v0.1.0 -> v0.2.0
golang.org/x/sys v0.48.0 -> v0.49.0
golang.org/x/text v0.42.0 -> v0.43.0
File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 10 additional dependencies were updated

Details:

Package Change
github.com/ajroetker/go-highway v0.0.4 -> v0.0.12
github.com/andybalholm/brotli v1.2.5 -> v1.2.6
github.com/dlclark/regexp2/v2 v2.5.2 -> v2.8.1
github.com/go-images/gif v0.1.0 -> v0.2.0
github.com/go-images/jpeg v0.2.0 -> v0.3.0
github.com/go-images/jpeg2000 v0.1.0 -> v0.13.3
github.com/go-images/png v0.1.0 -> v0.2.0
golang.org/x/crypto v0.57.0 -> v0.58.0
golang.org/x/sys v0.48.0 -> v0.49.0
golang.org/x/text v0.42.0 -> v0.43.0

@tannevaled
tannevaled force-pushed the renovate/deps branch 7 times, most recently from ad0788f to 2a0eb90 Compare October 8, 2026 07:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant