dependabot[bot] opened a new pull request, #562:
URL: https://github.com/apache/airavata/pull/562

   Bumps [github.com/quic-go/quic-go](https://github.com/quic-go/quic-go) from 
0.48.2 to 0.49.1.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/quic-go/quic-go/releases";>github.com/quic-go/quic-go's 
releases</a>.</em></p>
   <blockquote>
   <h2>v0.49.0</h2>
   <p>In this release, we added support for HTTP client traces. We also fixed a 
large number of bugs that could lead to connection stalls, deadlocks and memory 
leaks. See the &quot;Major Fixes&quot; section for more details.</p>
   <h2>New Features</h2>
   <ul>
   <li>http3: add support for client traces 
<code>net/http/httptrace.ClientTrace</code>: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4749";>#4749</a>. 
Thanks to <a href="https://github.com/lRoccoon";><code>@​lRoccoon</code></a> for 
the contribution!</li>
   </ul>
   <h2>Major Fixes</h2>
   <ul>
   <li>fix accounting for lost RESET_STREAM frames in the stream, leading to 
potential connection stalls / deadlocks: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4804";>#4804</a>. 
Thanks to <a href="https://github.com/Wondertan";><code>@​Wondertan</code></a> 
for reporting and testing the fix!</li>
   <li>fix memory leak when the connection ID is rotated when the 
CONNECTION_CLOSE packet is sent: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4852";>#4852</a>. 
Thanks to <a href="https://github.com/MarcoPolo";><code>@​MarcoPolo</code></a> 
for debugging this issue and contributing a fix!</li>
   <li>http3: fix QUIC connection re-dialing logic: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4854";>#4854</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4875";>#4875</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4879";>#4879</a></li>
   <li>trigger sending of a new packet when a MAX_DATA frame (connection-level 
flow control update) is queued: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4844";>#4844</a></li>
   <li><code>Transport.Close</code> was reworked: calls to 
<code>Transport.Dial</code> are now canceled, and return the newly introduced 
<code>ErrTransportClosed</code>, as do calls to <code>Transport.Listen</code>: 
<a href="https://redirect.github.com/quic-go/quic-go/issues/4883";>#4883</a></li>
   </ul>
   <h2>Enhancements</h2>
   <ul>
   <li>trace dropping of packets by the <code>Transport</code> when no server 
is set: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4789";>#4789</a></li>
   <li>trace dropping of packets that the <code>Transport</code> doesn't send a 
stateless for: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4826";>#4826</a></li>
   <li>drain received packets when the connection is closed: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4773";>#4773</a></li>
   <li>add Prometheus metrics for sent and received packets: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4910";>#4910</a></li>
   <li>reduce calls to <code>time.Now</code> all over the code base: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4731";>#4731</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4885";>#4885</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4886";>#4886</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4906";>#4906</a></li>
   <li>packetize DATA_BLOCKED frames in the same QUIC packet that caused us to 
block on connection-level flow control: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4845";>#4845</a></li>
   <li>packetize STREAM_DATA_BLOCKED frames in the same QUIC packed that caused 
us to block on stream-level flow control: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4801";>#4801</a></li>
   <li>we now don't enforce that only one <code>Transport</code> listens on any 
given <code>net.PacketConn</code>: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4851";>#4851</a></li>
   </ul>
   <h2>Other Fixes</h2>
   <ul>
   <li>drain the server's connection accept queue before returning 
<code>ErrClosed</code> from <code>Accept</code>: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4846";>#4846</a>. 
Thanks to <a href="https://github.com/sukunrt";><code>@​sukunrt</code></a> for 
discovering this bug and providing very helpful reviews!</li>
   <li>preserve the error returned from <code>SendStream.Write</code> if it is 
closed after is canceled: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4882";>#4882</a></li>
   <li>fix race condition on concurrent calls to <code>Transport.Dial</code> 
and <code>Transport.Close</code>: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4904";>#4904</a></li>
   <li>qlog: fix logging of packet_in_flight on the metrics_updated event: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4895";>#4895</a></li>
   <li>fix <code>errors.Is</code> error comparisons: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4824";>#4824</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4825";>#4825</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4877";>#4877</a></li>
   <li>http3: fix race condition on concurrent calls to 
<code>http.Response.Body.Close</code>: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4798";>#4798</a>. 
Thanks to <a href="https://github.com/RPRX";><code>@​RPRX</code></a> for the 
contribution!</li>
   <li>flowcontrol: reset the connection send window on 0-RTT rejection: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4764";>#4764</a></li>
   <li>wait for connection to shut down when the Dial context is cancelled: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4872";>#4872</a></li>
   <li>http3: the <code>http.Request.Body</code> is now properly closed on all 
code paths that return a non-<code>nil</code> error: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4874";>#4874</a></li>
   <li>NEW_CONNECTION_ID frames are now rejected when zero-length connection 
IDs are used, as required by the RFC: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4878";>#4878</a></li>
   <li>the stream ID of STREAM_DATA_BLOCKED frames is now validated, as 
required by the RFC: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4836";>#4836</a></li>
   <li>fix ECN markings of packets sent in GSO batches when the marking 
changes: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4835";>#4835</a></li>
   <li>the AEAD used to calculate the Retry Integrity Tag is now created 
lazily, avoiding a panic on initialization when using Go 1.24 FIPS-only mode: 
<a href="https://redirect.github.com/quic-go/quic-go/issues/4916";>#4916</a></li>
   <li>use a 24h maximum token age as default value for 
<code>Transport.MaxTokenAge</code>: <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4763";>#4763</a></li>
   </ul>
   <h2>Behind the Scenes</h2>
   <p>In the <a 
href="https://github.com/quic-go/quic-go/releases/tag/v0.48.0";>v0.48.0</a> 
release, we started migrating our test suite away from Ginkgo (tracking issue: 
<a href="https://redirect.github.com/quic-go/quic-go/issues/3652";>#3652</a>). 
This is an absolutely massive endeavor. Before we started, the number of LOC of 
Ginkgo tests was more than 41,000.</p>
   <p>In this release, we're bringing this number down to less than 8,500 LOC: 
<a href="https://redirect.github.com/quic-go/quic-go/issues/4736";>#4736</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4746";>#4746</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4775";>#4775</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4783";>#4783</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4788";>#4788</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4790";>#4790</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4795";>#4795</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4796";>#4796</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4797";>#4797</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4799";>#4799</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4814";>#4814</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4816";>#4816<
 /a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4817";>#4817</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4823";>#4823</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4837";>#4837</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4842";>#4842</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4847";>#4847</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4848";>#4848</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4849";>#4849</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4853";>#4853</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4857";>#4857</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4860";>#4860</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4861";>#4861</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4862";>#4862</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4863";>#4
 863</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4864";>#4864</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4865";>#4865</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4869";>#4869</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4876";>#4876</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4881";>#4881</a>, <a 
href="https://redirect.github.com/quic-go/quic-go/issues/4907";>#4907</a>.</p>
   <p>There's still a lot of work ahead, but we'll hopefully be able to finish 
this item in the next couple of months.</p>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/quic-go/quic-go/commit/275c172fec2b4dae0eea5ac2052a28848b4363ea";><code>275c172</code></a>
 drop initial packets when the handshake is confirmed</li>
   <li><a 
href="https://github.com/quic-go/quic-go/commit/c385cd10f133482a24979bd4a7dadb847f9ef146";><code>c385cd1</code></a>
 handshake: lazily create the AEAD used for Retry (<a 
href="https://redirect.github.com/quic-go/quic-go/issues/4916";>#4916</a>)</li>
   <li><a 
href="https://github.com/quic-go/quic-go/commit/fb9d8e3ede64222b426dd5253c846b20e140038a";><code>fb9d8e3</code></a>
 metrics: add Prometheus metrics for sent and received packets (<a 
href="https://redirect.github.com/quic-go/quic-go/issues/4910";>#4910</a>)</li>
   <li><a 
href="https://github.com/quic-go/quic-go/commit/e12f91cfc71b5f12824c2b2257037eedc5ea16a3";><code>e12f91c</code></a>
 clean up MTU probe packet sending logic (<a 
href="https://redirect.github.com/quic-go/quic-go/issues/4914";>#4914</a>)</li>
   <li><a 
href="https://github.com/quic-go/quic-go/commit/a4c9b04c5852f87859e0e09e268adeaba7be1768";><code>a4c9b04</code></a>
 simply PTO probe packet sending logic (<a 
href="https://redirect.github.com/quic-go/quic-go/issues/4913";>#4913</a>)</li>
   <li><a 
href="https://github.com/quic-go/quic-go/commit/d41f9749d37eb5fde93dfef711a89a6663819d41";><code>d41f974</code></a>
 fix memory leak on connection ID rotation when closing connection (<a 
href="https://redirect.github.com/quic-go/quic-go/issues/4852";>#4852</a>)</li>
   <li><a 
href="https://github.com/quic-go/quic-go/commit/302308335cf346ab816b65beeb4e68855311cbce";><code>3023083</code></a>
 migrate the MTU discoverer tests away from Ginkgo (<a 
href="https://redirect.github.com/quic-go/quic-go/issues/4907";>#4907</a>)</li>
   <li><a 
href="https://github.com/quic-go/quic-go/commit/bea70c6489f534f848c84110fb410286732188d3";><code>bea70c6</code></a>
 fix flaky TestALPN integration test (<a 
href="https://redirect.github.com/quic-go/quic-go/issues/4909";>#4909</a>)</li>
   <li><a 
href="https://github.com/quic-go/quic-go/commit/eb70424fbaddd2577b787aa51e3f961451a0d49e";><code>eb70424</code></a>
 fix race condition on concurrent use of Transport.Dial and Close (<a 
href="https://redirect.github.com/quic-go/quic-go/issues/4904";>#4904</a>)</li>
   <li><a 
href="https://github.com/quic-go/quic-go/commit/5d4835e4227bec1a9060d42342cef8bfba9adcdc";><code>5d4835e</code></a>
 preserve error from SendStream during cancellation and closing (<a 
href="https://redirect.github.com/quic-go/quic-go/issues/4882";>#4882</a>)</li>
   <li>Additional commits viewable in <a 
href="https://github.com/quic-go/quic-go/compare/v0.48.2...v0.49.1";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/quic-go/quic-go&package-manager=go_modules&previous-version=0.48.2&new-version=0.49.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/airavata/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to