dependabot[bot] opened a new pull request, #703:
URL: https://github.com/apache/airavata/pull/703

   Bumps [github.com/fatedier/frp](https://github.com/fatedier/frp) from 0.68.1 
to 0.70.1.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/fatedier/frp/releases";>github.com/fatedier/frp's 
releases</a>.</em></p>
   <blockquote>
   <h2>v0.70.1</h2>
   <h2>Fixes</h2>
   <ul>
   <li>HTTP vhost servers no longer support HTTP/1.1 <code>Upgrade: h2c</code> 
requests. Cleartext HTTP/2 prior-knowledge remains supported.</li>
   <li>Fixed control-session replacement leaks when frpc reconnects through a 
half-open TCP multiplexed connection.</li>
   <li>Fixed an SSH tunnel gateway panic when handling malformed exec 
requests.</li>
   </ul>
   <h2>v0.70.0</h2>
   <h2>Features</h2>
   <ul>
   <li>Expanded the frps dashboard API v2 migration across Clients, Proxies, 
Server Overview, Client Detail, and Proxy Detail, covering paginated 
users/clients/proxies, detail data, proxy traffic history, server system info, 
offline proxy statistics pruning, server-side pagination, search, and proxy 
type filtering.</li>
   </ul>
   <h2>Fixes</h2>
   <ul>
   <li>WebSocket and WSS tunnel payloads are now sent as binary frames, 
avoiding disconnects through RFC-compliant intermediaries that validate text 
frames as UTF-8.</li>
   <li>The <code>tls2raw</code> client plugin now writes the proxy protocol 
header to the local raw connection when proxy protocol is enabled.</li>
   <li>frpc now rejects duplicate proxy and visitor names in config files 
instead of silently overwriting earlier entries.</li>
   </ul>
   <h2>v0.69.1</h2>
   <h2>Features</h2>
   <ul>
   <li><code>transport.wireProtocol = &quot;v2&quot;</code> now also applies to 
UDP-based proxy payloads, including ordinary UDP and SUDP, so their payload 
framing is consistent with the selected wire protocol.</li>
   <li>Improved SUDP compatibility during mixed 
<code>transport.wireProtocol</code> deployments, allowing frps to bridge 
payloads between v1/default and v2 SUDP clients.</li>
   <li>XTCP work connection <code>NatHoleSid</code> messages now follow the 
selected <code>transport.wireProtocol</code>.</li>
   </ul>
   <h2>Compatibility Notes</h2>
   <ul>
   <li>When enabling <code>transport.wireProtocol = &quot;v2&quot;</code> for 
SUDP, upgrade both the proxy and visitor frpc instances first, or keep them on 
<code>v1</code> until both sides are upgraded.</li>
   </ul>
   <h2>v0.69.0</h2>
   <h2>Compatibility Policy</h2>
   <p>Starting with v0.69.0, each minor release is supported until there are 
nine newer minor releases. For example, v0.69.0 will be supported until v0.78.0 
is released. Within this window, frpc v0.69.0 is guaranteed to work with any 
frps from v0.61.0 to v0.77.0, and vice versa. Patch releases within the same 
minor are always compatible. Versions outside the support window may continue 
to work on a best-effort basis, but compatibility is no longer guaranteed.</p>
   <p>For mixed-version deployments, upgrade frps first, then upgrade frpc. 
This keeps the server side ready for newer client-side protocol behavior before 
clients start using it.</p>
   <h2>Notes</h2>
   <p>This release introduces wire protocol v2 as a transition path for future 
frpc/frps protocol changes. The existing wire protocol is difficult to extend 
without compatibility risk, and upcoming changes, including replacing 
deprecated stream encryption methods, require a versioned protocol.</p>
   <p><strong>The default value of <code>transport.wireProtocol</code> remains 
<code>v1</code> in this release.</strong> Users can keep the default for now. 
To test v2 early, upgrade both frpc and frps to versions that support it, then 
set <code>transport.wireProtocol = &quot;v2&quot;</code> in frpc. A v2-enabled 
frpc cannot connect to an older frps.</p>
   <p>When <code>transport.wireProtocol = &quot;v2&quot;</code> is enabled, the 
control channel uses negotiated AEAD encryption after the login handshake. Both 
frpc and frps must be upgraded to this release to use v2.</p>
   <p>v1 will be deprecated when v2 becomes the default in a future release. It 
will continue to be supported until v0.78.0 is released, and may be removed in 
v0.78.0 or later.</p>
   <h2>Features</h2>
   <ul>
   <li>Added <code>transport.wireProtocol</code> for frpc to select the 
internal message protocol used between frpc and frps. Supported values are 
<code>v1</code> and <code>v2</code>.</li>
   <li>Added client protocol visibility in the frps dashboard and 
<code>/api/clients</code> API. Online clients now report their negotiated 
protocol as <code>v1</code> or <code>v2</code>.</li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/fatedier/frp/commit/fa3bcca2b0c4753cd4f0e2ab189dd6a5a6a15708";><code>fa3bcca</code></a>
 Merge pull request <a 
href="https://redirect.github.com/fatedier/frp/issues/5444";>#5444</a> from 
fatedier/dev</li>
   <li><a 
href="https://github.com/fatedier/frp/commit/18eef83b69ac639cbc0cdb8f84389488825e3b5d";><code>18eef83</code></a>
 fix(client): synchronize graceful shutdown duration (<a 
href="https://redirect.github.com/fatedier/frp/issues/5442";>#5442</a>)</li>
   <li><a 
href="https://github.com/fatedier/frp/commit/466a94f5d18c3caf5a2a11d61b64e5943608c5ea";><code>466a94f</code></a>
 update quic-go dependency to v0.60.0 (<a 
href="https://redirect.github.com/fatedier/frp/issues/5443";>#5443</a>)</li>
   <li><a 
href="https://github.com/fatedier/frp/commit/898bcf73d55b254fdcd71cdcf5cac6d81a5c97d8";><code>898bcf7</code></a>
 web: restore Vite client declarations for both dashboards (<a 
href="https://redirect.github.com/fatedier/frp/issues/5415";>#5415</a>)</li>
   <li><a 
href="https://github.com/fatedier/frp/commit/0e53833a2cb9a78601d1e5f1cfc7a9ff42dd7718";><code>0e53833</code></a>
 refactor: use standard library HKDF (<a 
href="https://redirect.github.com/fatedier/frp/issues/5440";>#5440</a>)</li>
   <li><a 
href="https://github.com/fatedier/frp/commit/c23934bb67a7fb50c8ded7b5ff050399917cad12";><code>c23934b</code></a>
 web: update vulnerable transitive dependencies (<a 
href="https://redirect.github.com/fatedier/frp/issues/5441";>#5441</a>)</li>
   <li><a 
href="https://github.com/fatedier/frp/commit/23512f577e42057db4cd0060ea636dd8b2d486d3";><code>23512f5</code></a>
 fix: upgrade go-oidc to v3.18.0 (<a 
href="https://redirect.github.com/fatedier/frp/issues/5439";>#5439</a>)</li>
   <li><a 
href="https://github.com/fatedier/frp/commit/84b907a198d143be26bc5869d6046e82f32de2ea";><code>84b907a</code></a>
 deps: bump golib to v0.8.1 (<a 
href="https://redirect.github.com/fatedier/frp/issues/5437";>#5437</a>)</li>
   <li><a 
href="https://github.com/fatedier/frp/commit/f8fc3c6b1b25bb1f3e8aaf707bad65cf458572bd";><code>f8fc3c6</code></a>
 server: drop HTTP/1.1 h2c upgrade handling (<a 
href="https://redirect.github.com/fatedier/frp/issues/5436";>#5436</a>)</li>
   <li><a 
href="https://github.com/fatedier/frp/commit/7dc7be930e2452ae93fd32f2a77f8c6fcd0b652b";><code>7dc7be9</code></a>
 ssh: fix malformed exec payload panic (<a 
href="https://redirect.github.com/fatedier/frp/issues/5428";>#5428</a>)</li>
   <li>Additional commits viewable in <a 
href="https://github.com/fatedier/frp/compare/v0.68.1...v0.70.1";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/fatedier/frp&package-manager=go_modules&previous-version=0.68.1&new-version=0.70.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/airavata/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to