Skip to content

chore(deps): bump the go-deps group with 2 updates - #11

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-deps-2374d738ff
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-deps-2374d738ff

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-deps group with 2 updates: go.mongodb.org/mongo-driver/v2 and golang.org/x/tools.

Updates go.mongodb.org/mongo-driver/v2 from 2.9.1 to 2.9.2

Release notes

Sourced from go.mongodb.org/mongo-driver/v2's releases.

MongoDB Go Driver 2.9.2

The MongoDB Go Driver Team is pleased to release version 2.9.2 of the official MongoDB Go Driver.

Release Highlights

[!WARNING] Go Driver versions v2.1.0 through v2.8.1 and v2.9.0 through v2.9.1 are affected by a security issue CVE-2026-81521 in Client.BulkWrite. The fix shipped in v2.8.2 but was not included in v2.9.0 or v2.9.1. This release restores the fix for the 2.9 line. Users on v2.9.0 or v2.9.1 are encouraged to upgrade to Go Driver v2.9.2 as soon as possible. Go Driver v1 is not affected.

[!WARNING]
Go Driver versions v1.1.0 and later and v2.0.0 through v2.9.1 are affected by a security issue CVE-2026-107325 in the bson.RawArray.Validate method. This release resolves that security issue in Go Driver v2. Users are encouraged to upgrade to Go Driver v2.9.2 as soon as possible.

This release addresses CVE-2026-81521, a security issue in calling Client.BulkWrite. A caller-controlled database name containing a period ('.') may be interpreted as a different namespace when forwarded to MongoDB. This could redirect operations to a database or collection other than the one intended by the application.

This release addresses CVE-2026-107325, a security issue in calling bson.RawArray.Validate. Calling bson.RawArray.Validate on an array whose declared length is 0 causes a runtime panic.

It also restores a fix from v2.8.1 that was likewise missing from v2.9.0 and v2.9.1: when a command's first attempt failed with a server error and the retry reported NoWritesPerformed, operations such as Database.RunCommand could return a nil error instead of the server error. They now return the original server error.

Sessions now inherit timeoutMS from the client, so operations run in a session honor the client-level timeout.

What's Changed

🐛 Fixed

Full Changelog: mongodb/mongo-go-driver@v2.9.1...v2.9.2

Commits
  • df261dc BUMP v2.9.2
  • 16b6195 GODRIVER-4088 Return the server error when the first attempt fails wi… (#2666)
  • de647b7 GODRIVER-4075 Return an error if there are invalid characters in the … (#2665)
  • 59c2e6b GODRIVER-4177 guard empty documents slice in decodeOpReply QueryFailure branc...
  • 15edca6 GODRIVER-4138 Latest server binary downloads require private S3. (#2660)
  • 74278b9 GODRIVER-4118 fix: correct Truncate boundary handling for multi-byte UTF-8 ch...
  • 13954c2 GODRIVER-4168: Authenticate the Claude review with the drivers PR bot app (#2...
  • 8f9da57 GODRIVER-4168: Run Claude review only when the claude-review label is applied...
  • 44ee9af GODRIVER-4168: Add Claude GitHub workflow (#2632)
  • a097394 GODRIVER-4136: reject BSON lengths below the 5-byte minimum before slicing (#...
  • Additional commits viewable in compare view

Updates golang.org/x/tools from 0.50.0 to 0.51.0

Commits
  • ea2f152 go.mod: update golang.org/x dependencies
  • 00443da go/analysis/passes/printf: pin testdata Go versions
  • 9ba0a15 internal/refactor/inline: check import accessibility before Go version
  • 25196fc cmd/toolstash: check -linkobj files to support early export
  • ead0503 gopls/internal/golang: unexport dragon*Question variables
  • 5693030 gopls/internal/golang: call arguments mistreated in inlineAllCalls
  • 134264d gopls/internal/golang/stubmethods: do not panic when FindByPos fails
  • 01d93d7 gopls/internal/golang: slay the dragon: update questions
  • 405de39 go/callgraph: fix benchmarks to analyze whole program
  • 231a7fa go/ssa, cmd/deadcode: release type information once functions are built
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-deps group with 2 updates: [go.mongodb.org/mongo-driver/v2](https://github.com/mongodb/mongo-go-driver) and [golang.org/x/tools](https://github.com/golang/tools).


Updates `go.mongodb.org/mongo-driver/v2` from 2.9.1 to 2.9.2
- [Release notes](https://github.com/mongodb/mongo-go-driver/releases)
- [Commits](mongodb/mongo-go-driver@v2.9.1...v2.9.2)

Updates `golang.org/x/tools` from 0.50.0 to 0.51.0
- [Release notes](https://github.com/golang/tools/releases)
- [Commits](golang/tools@v0.50.0...v0.51.0)

---
updated-dependencies:
- dependency-name: go.mongodb.org/mongo-driver/v2
  dependency-version: 2.9.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: golang.org/x/tools
  dependency-version: 0.51.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants