Skip to content

chore(deps): update module github.com/fxamacker/cbor/v2 to v2.9.6 - #1908

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/github.com-fxamacker-cbor-v2-2.x
Oct 7, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/github.com-fxamacker-cbor-v2-2.x

Conversation

@renovate

@renovate renovate Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/fxamacker/cbor/v2 v2.9.4 → v2.9.6 age confidence

Release Notes

fxamacker/cbor (github.com/fxamacker/cbor/v2)

v2.9.6

Compare Source

v2.9.6 fixes 12 bugs, including an important fix for apps that decode CBOR maps into Go maps, and has one behavior change. API is unchanged but more errors are detected.

Most of these bugs were identified while improving tests and reviewing code for an upcoming release.

Tests and fuzz tests were extended.

Upgrading to v2.9.6 from all prior versions is recommended.

🐞 Important Fix

Not affected:

  • Decoding data this codec encoded from the same Go map type, because this codec does not encode to CBOR null from Go values of bool, integer, float, or string kind.
  • Apps that don't decode a CBOR null or undefined map key or value into a Go map whose key or value type is of bool, integer, float, or string kind.
  • Decoding CBOR maps into structs (struct fields of map type follow the bullet above).
  • Decoding CBOR maps into map[any]any, and into any (with unchanged DefaultMapType).

For use cases outside the "not affected" list, decoding a CBOR null or undefined map key or value (including 55799(null)) into a Go map whose key or value type is of bool, integer, float, or string kind kept the previous map entry's key or value (instead of the zero value). See PR #​855 for details.

⚠️ Behavior change

Decoding CBOR null or undefined into an interface that holds a value now sets it to nil, matching encoding/json (v1 and v2). Previously, the interface kept its value (PR #​827), which was not the intended behavior.

What's Changed

Some of these bugs could only be triggered by incorrect usage in user apps, such as invalid struct tags or an unsupported DefaultByteStringType setting, etc. None of these bugs were reported by a project affected by them.

Decoding
Encoding
  • Fix encoding self-referencing types by @​fxamacker in #​833
  • Fix panic encoding marshaler of unsupported underlying types by @​fxamacker in #​834
  • Fix omitzero panic encoding struct field of unsupported underlying types implementing marshaler by @​fxamacker in #​835
  • Fix encoding TimeUnixMicro outside 1677 to 2262 by @​fxamacker in #​837
    • Encoded output also changes for some times within one second of either end of that range.
  • Reject encoding time.Time when Go formats wrong year by @​fxamacker in #​838
CI / GitHub Actions and Docs

Full Changelog: fxamacker/cbor@v2.9.4...v2.9.6

v2.9.5

Compare Source

This version was tagged from the wrong branch by mistake and is retracted.

Use v2.9.6 (https://github.com/fxamacker/cbor/releases/tag/v2.9.6) instead.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from argoyle as a code owner October 7, 2026 00:43
@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Oct 7, 2026
@renovate
renovate Bot requested a review from peter-svensson as a code owner October 7, 2026 00:43
@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Oct 7, 2026
@renovate
renovate Bot enabled auto-merge (squash) October 7, 2026 00:43
@codecov

codecov Bot commented Oct 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.83%. Comparing base (f220b59) to head (8fe8a33).
⚠️ Report is 2 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1908   +/-   ##
=======================================
  Coverage   93.83%   93.83%           
=======================================
  Files          40       40           
  Lines        1639     1639           
=======================================
  Hits         1538     1538           
  Misses        101      101           
Flag Coverage Δ
unittests 93.83% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@renovate
renovate Bot merged commit 84c3421 into main Oct 7, 2026
12 checks passed
@renovate
renovate Bot deleted the renovate/github.com-fxamacker-cbor-v2-2.x branch October 7, 2026 00:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ignore-for-release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants