Skip to content

chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.2 - #328

Merged
codacybeta merged 1 commit into
masterfrom
dependabot/go_modules/google.golang.org/grpc-1.83.1
Sep 17, 2026
Merged

codacybeta merged 1 commit into
masterfrom
dependabot/go_modules/google.golang.org/grpc-1.83.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown
Contributor

Bumps google.golang.org/grpc from 1.82.1 to 1.83.2.

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.83.2

Security

  • server: Reject requests missing both :authority and Host headers with HTTP 400 and status Internal. (grpc/grpc-go#9365)

Release 1.83.1

Security

  • xds/rbac: Fix a bug where nested Principal or Permission rules with :scheme or grpc- prefixed header matchers were not rejected, which could cause DENY rules to fail open. (#9258)
  • xds/rbac: Fix a bug where the host header matcher was not being replaced with :authority in nested Principal or Permission rules. (#9258)
  • xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as X-Role, matched no header, which could cause DENY rules to fail open. (#9332)
  • xds/rbac: Fix a bug where a :scheme or grpc- prefixed header matcher was accepted when its name was not lowercase. (#9332)
  • xds/rbac: Fix a bug where a Host header matcher was not replaced with :authority. (#9332)

Performance

  • transport: Restrict memory overhead of buffering small data frames. (#9331)

Release 1.83.0

Security

  • server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT.
  • xds/rbac: Support Metadata and RequestedServerName permissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open.
  • xds/rbac: Fix panic when parsing unsupported fields in NotRule/NotId permissions.
  • xds/rbac: Support the deprecated source_ip principal identifier by treating it as equivalent to direct_remote_ip.
  • xds: Fix panic when parsing route header matchers configured with empty exact_match, prefix_match, or suffix_match strings. (#9223)

New Features

  • xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the force-xds target URI query parameter. (#9133)
  • xds: Enable xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports. (#9145)
  • authz: Add OnPolicyUpdate callback to FileWatcherOptions to notify when an authz policy is loaded or updated. (#9142)
  • xds: Add support for the GCP Authentication HTTP Filter, which automatically fetches and attaches GCP Service Account Identity JWT tokens to outgoing RPCs.
    • This feature can be enabled by setting environment variable GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true. (#9119)
  • xds: Add support for xDS-based HTTP CONNECT proxies.
    • This feature can be enabled by setting environment variable GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true. (#9151)
  • xds: Add support for contains_match in route header matchers. (#9223)

Bug Fixes

  • credentials/alts: Fix panic when processing malformed frames by validating that the message frame length exceeds the message type field size. (#9197)
  • grpc: Fix compilation on Plan 9 targets (GOOS=plan9), broken since v1.81.0. (#9255)

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 2, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 2, 2026 08:01
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 2, 2026
codacybeta
codacybeta previously approved these changes Sep 2, 2026
@codacybeta
codacybeta enabled auto-merge (squash) September 2, 2026 08:01
@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes.

@codacy-production codacy-production Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Codacy results indicate that the changes are up to standards, and no immediate logic bugs or security flaws were found in the dependency declarations. However, a significant gap exists in the validation of this update. While the PR addresses security fixes in gRPC, it lacks evidence of automated tests to ensure these changes do not regress existing authorization policies or break compilation. Additionally, the PR scope extends beyond the title to include several indirect dependency updates (e.g., OpenTelemetry, go-spiffe) that should be explicitly documented to ensure full transparency of the changes being introduced.

About this PR

  • There are no tests or CI verification results included to confirm that these dependency bumps were validated against the project's logic, particularly regarding the security-sensitive RBAC/xDS matching logic.
  • The google.golang.org/grpc dependency is listed as an indirect dependency in go.mod. This suggests the project may rely on another library that uses gRPC. Ensure that this transitive update is sufficient or if the direct dependency itself requires an update.
  • The PR updates multiple dependencies, including OpenTelemetry GCP detectors, go-spiffe, and genproto, which are not mentioned in the PR title or description. Please update the PR metadata to accurately reflect the scope of changes.

Test suggestions

  • Verify that the application compiles successfully with the updated gRPC and indirect dependency versions.
  • Validate gRPC server/client functionality, specifically ensuring that security fixes in 1.83.1 (RBAC/xDS matching) do not introduce regressions in existing authorization policies.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify that the application compiles successfully with the updated gRPC and indirect dependency versions.
2. Validate gRPC server/client functionality, specifically ensuring that security fixes in 1.83.1 (RBAC/xDS matching) do not introduce regressions in existing authorization policies.

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.82.1 to 1.83.2.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.82.1...v1.83.2)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.83.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.2 Sep 17, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/google.golang.org/grpc-1.83.1 branch from 91aa1ca to da8341a Compare September 17, 2026 23:01
@codacybeta
codacybeta merged commit 628d9ad into master Sep 17, 2026
8 checks passed
@codacybeta
codacybeta deleted the dependabot/go_modules/google.golang.org/grpc-1.83.1 branch September 17, 2026 23:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant