Repository navigation
deps: consolidate dependabot bumps - #4370
Merged
Merged
Conversation
Holds every solana-*, agave-*, spl-* and ruint version at main's, and holds testcontainers-go (plus clickhouse-go and goose, which require it) and solana-go back.
bgm-malbeclabs
approved these changes
Sep 25, 2026
ben-dz
added a commit
that referenced
this pull request
Sep 28, 2026
Bumps testcontainers-go and its clickhouse and redpanda modules from 0.40 to 0.44, and clickhouse-go from 2.46 to 2.48. These were held back in #4370: testcontainers 0.43 moved its request types from `github.com/docker/docker` to `github.com/moby/moby/api`, and clickhouse-go 2.47+ requires testcontainers 0.43. Only the types handed to testcontainers change: `ConfigModifier`, `HostConfigModifier`, `EndpointSettingsModifier`, `Resources`, network IPAM, and wait/mapped ports, which are now plain strings. Direct Docker client calls (`dockerClient.ContainerList`, filters, inspect) stay on `github.com/docker/docker`, so go.mod now carries both. Moving those calls to `github.com/moby/moby/client` is a larger rewrite, and it can be done separately. The moby types use `netip` for IPs and subnets. The CYOA IPs for the client and ip-verifier and the network subnets are now parsed before use, and a bad value returns an error instead of being passed through as a string. goose stays at 3.27.0. 3.27.3 requires go 1.25.7, and the test and release images build on `golang:1.25.0`/`1.25.5`, which set `GOTOOLCHAIN=local` and can't fetch a newer toolchain. Rust and Solana dependencies are untouched. ## Testing Verification All six e2e shards and the three shard-e2e jobs pass in CI, and so do the container tests (`go-container-test`) and `go-test`. Locally, `go vet` is clean under every build tag in the repo (none, `qa`, `e2e`, `e2e,stress`, `container_tests`), and golangci-lint reports no issues.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Consolidates the open Dependabot PRs that can land without moving Solana.
This changes the DoubleZero Ledger program binaries. borsh 1.8.1, bytemuck, thiserror and serde are in the build tree of serviceability and record, and nothing checks those programs' checksums. The next ledger program release will ship these versions, so it should be a deliberate decision. The L1 programs under
solana/are untouched, andsolana/Cargo.lockis unchanged.No
solana-*,agave-*,spl-*or ruint version moves in any lockfile. Thesolana-*minor bumps in the rust-minor-patch group are held back because solana-compute-budget-interface 3.1 pulls solana-instruction 4.0 into the serviceability build. ruint stays at 1.16 because 1.17 and later use edition 2024, which the SBF toolchain can't parse. testcontainers-go stays at 0.40 because 0.43 moves to the moby API types and breaks e2e. clickhouse-go 2.47+ and goose 3.27.3 require it, so they stay back as well. solana-go is held with the other Solana crates.Two bumps need code changes. ureq 3 needs a small change in fork-accounts, and tint 1.2 deprecates
NewHandler, so its call sites move toNewTextHandler, which it already wraps. ureq and ureq-proto are pinned in the lockfile to avoid pulling in base64 0.23.Closes #3887
Closes #4117
Closes #4139
Closes #4210
Closes #4258
Closes #4292
Closes #4293
Closes #4359
Still open after this merges: the Solana 4.x PRs (#4134, #4135, #4136, #4137, #4140, #4141), #4263 (it fails the SBF build and would move the
solana/checksums), #4138 (base64 is pinned inCargo.toml), #4262, and whatever is left of #4250, #4290 and #4348.Testing Verification
The account compatibility check passes against devnet, testnet and mainnet. Rust lint and tests, the fixture builds and the revdist Python tests pass. The Go packages that can run without root pass. SBF builds and e2e are left to CI.