Skip to content

deps(deps): Bump github.com/slack-go/slack from 0.29.0 to 0.30.1 - #169

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/slack-go/slack-0.30.1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/slack-go/slack-0.30.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/slack-go/slack from 0.29.0 to 0.30.1.

Release notes

Sourced from github.com/slack-go/slack's releases.

v0.30.1

[!IMPORTANT] This is a security release. Upgrade if your app passes file URLs from messages or events to GetFile. Full details are in CHANGELOG.md.

Security

GetFile, GetFileContext and UploadToURL now send the token only to https URLs on slack.com, slack-gov.com and their subdomains, and to the host set with OptionAPIURL. Any other URL returns an error before a request is made.

The url_private of a remote or external file (File.IsExternal) points outside Slack, so GetFile(file.URLPrivate) sent the token to that host. See GHSA-3q3v-34v2-g88f.

A test that points GetFile at an httptest server must also pass that server to OptionAPIURL:

api := slack.New("xoxb-test", slack.OptionAPIURL(ts.URL+"/"))
err := api.GetFile(ts.URL+"/files-pri/T1-F1/a.txt", &buf)

Thanks to @​Lordseriouspig (what a handle... 😂) for the report.

Full Changelog: slack-go/slack@v0.30.0...v0.30.1

v0.30.0

[!WARNING] This release has breaking changes. It needs Go 1.26 or later, DeleteFileComment takes its arguments in a new order, and four methods have new variadic signatures that break interfaces and mocks. Read Breaking changes before you upgrade. Full details are in CHANGELOG.md.

Breaking changes

DeleteFileComment takes (fileID, commentID)

DeleteFileComment now uses the same argument order as DeleteFileCommentContext (#1611). Swap the arguments of every call:

// Before
err := api.DeleteFileComment(commentID, fileID)
// After
err := api.DeleteFileComment(fileID, commentID)

The compiler cannot catch this because both arguments are strings. A call that still passes a comment ID (Fc…) will return an error in order to try to catch it. YMMV so please raise an issue if you encounter issues

Variadic options on CreateManifest and GetUserInfo

CreateManifest, CreateManifestContext, GetUserInfo and GetUserInfoContext now take variadic options. An interface or mock that declares the old signature needs the new parameter:

// Before
type slackAPI interface {
      GetUserInfo(user string) (*slack.User, error)
      CreateManifest(manifest *slack.Manifest, token string) (*slack.ManifestResponse, error)
}
</tr></table> 

... (truncated)

Changelog

Sourced from github.com/slack-go/slack's changelog.

[0.30.1] - 2026-10-04

Security

  • GetFile, GetFileContext and UploadToURL now send the token only to https URLs on slack.com, slack-gov.com and their subdomains, and to the host set with OptionAPIURL. Any other URL returns an error before a request is made. The url_private of a remote or external file (File.IsExternal) points outside Slack, so GetFile(file.URLPrivate) sent the token to that host (GHSA-3q3v-34v2-g88f). A test that points GetFile at an httptest server must also pass that server to OptionAPIURL.

[0.30.0] - 2026-10-04

Added

  • slackevents: Add the Agent messaging events app_context_changed (AppContextChangedEvent), agent_session_stopped (AgentSessionStoppedEvent) and agent_session_title_changed (AgentSessionTitleChangedEvent). The shared AppContext object is also exposed as AppHomeOpenedEvent.Context and MessageEvent.AppContext, which Slack populates once the app subscribes to app_context_changed. An AppContextEntity carries a string Value for channel, canvas and list entities and a Message for message_context entities, whose value is an object.
  • slackevents: EventsAPICallbackEvent now unmarshals authorizations, so the installations an event was delivered for can be read without a second request.
  • Add SetAgentSessionStatus and RenameAgentSession (plus Context variants) for the agents.sessions.setStatus and agents.sessions.rename methods, with AgentSessionStatus* constants for the accepted statuses.
  • CreateManifest now returns the new app's AppId, Credentials and OAuthAuthorizeUrl from apps.manifest.create. Slack sends the credentials only in this response (#1587).
  • Add Features.AgentView and Features.AssistantView for the features.agent_view and features.assistant_view app manifest settings, so a typed export and update keeps them (#1588, #1589).
  • Add Features.UnfurlDomains, Features.RichPreviews, Features.Search, OAuthConfig.PKCEEnabled, OAuthConfig.TokenManagementEnabled, Settings.IsMCPEnabled, Settings.TokenRotationEnabled, Settings.IncomingWebhooks, Settings.FunctionRuntime, Settings.SIWSLinks, EventSubscriptions.MetadataSubscriptions and OutgoingDomains for the matching app manifest keys, so a typed export and update keeps them. Features.Search covers the two callback IDs, not slackbot_metadata (#1588).
  • Add Attachment.HideColor (hide_color), which removes the color bar from a file unfurl sent with chat.unfurl (#1590).
  • Block Kit: Add TaskCardBlock.HideTitle (hide_title) and WithHideTitle, which hide the

... (truncated)

Commits
  • a015532 chore: bump to v0.30.1
  • 3e2e96d security: send the token only to Slack hosts in GetFile and UploadToURL
  • 39e1829 chore: bump to v0.30.0
  • a76e4ab refactor(users): take a scoped GetUserInfoOption on GetUserInfo (#1613)
  • 81b481f feat(manifests): add raw manifest methods and a team_id option for create (#1...
  • 0dbdd91 feat(users): make include_locale configurable (#1603)
  • e1f05bb GetFile: error on HTML download responses (#1582)
  • 4bce1c2 fix(usergroups): support documented response variants (#1605)
  • 3e17228 feat(manifests): add more fields to manifests_test (#1612)
  • 92e8b00 fix(files)!: take DeleteFileComment arguments as (fileID, commentID) (#1611)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/slack-go/slack](https://github.com/slack-go/slack) from 0.29.0 to 0.30.1.
- [Release notes](https://github.com/slack-go/slack/releases)
- [Changelog](https://github.com/slack-go/slack/blob/master/CHANGELOG.md)
- [Commits](slack-go/slack@v0.29.0...v0.30.1)

---
updated-dependencies:
- dependency-name: github.com/slack-go/slack
  dependency-version: 0.30.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, go. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions
github-actions Bot enabled auto-merge October 7, 2026 22:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants