Bump github.com/labstack/echo/v4 from 4.1.16 to 4.5.0
Bumps github.com/labstack/echo/v4 from 4.1.16 to 4.5.0.
Release notes
Sourced from github.com/labstack/echo/v4's releases.
v4.5.0
Important notes
A BREAKING CHANGE is introduced for JWT middleware users.
The JWT library used for the JWT middleware had to be changed from github.com/dgrijalva/jwt-go to github.com/golang-jwt/jwt due former library being unmaintained and affected by security issues. The github.com/golang-jwt/jwt project is a drop-in replacement, but supports only the latest 2 Go versions. So for JWT middleware users Go 1.15+ is required. For detailed information please read #1940
To change the library imports in all .go files in your project replace all occurrences of
dgrijalva/jwt-gowithgolang-jwt/jwt.For Linux CLI you can use:
find -type f -name "*.go" -exec sed -i "s/dgrijalva\/jwt-go/golang-jwt\/jwt/g" {} \; go mod tidyFixes
- Change JWT library to
github.com/golang-jwt/jwt#1946v4.4.0
Fixes
- Split HeaderXForwardedFor header only by comma #1878
- Fix Timeout middleware Context propagation #1910
Enhancements
- Allow for custom JSON encoding implementations #1880
- Adds JWTConfig.ParseTokenFunc to JWT middleware to allow different libraries implementing JWT parsing. #1887
- Adds RequestIDHandler function to RequestID middleware #1898
- Bind data using headers as source #1866
- Adding tests for Echo#Host #1895
v4.3.0
Important notes
- Route matching has improvements for following cases:
- Correctly match routes with parameter part as last part of route (with trailing backslash)
- Considering handlers when resolving routes and search for matching http method handler
- Echo minimal Go version is now 1.13.
Fixes
- When url ends with slash first param route is the match #1804
- Router should check if node is suitable as matching route by path+method and if not then continue search in tree #1808
- Fix timeout middleware not writing response correctly when handler panics #1864
- Fix binder not working with embedded pointer structs #1861
... (truncated)
Changelog
Sourced from github.com/labstack/echo/v4's changelog.
v4.5.0 - 2021-08-01
Important notes
A BREAKING CHANGE is introduced for JWT middleware users. The JWT library used for the JWT middleware had to be changed from github.com/dgrijalva/jwt-go to github.com/golang-jwt/jwt due former library being unmaintained and affected by security issues. The github.com/golang-jwt/jwt project is a drop-in replacement, but supports only the latest 2 Go versions. So for JWT middleware users Go 1.15+ is required. For detailed information please read #1940
To change the library imports in all .go files in your project replace all occurrences of
dgrijalva/jwt-gowithgolang-jwt/jwt.For Linux CLI you can use:
find -type f -name "*.go" -exec sed -i "s/dgrijalva\/jwt-go/golang-jwt\/jwt/g" {} \; go mod tidyFixes
- Change JWT library to
github.com/golang-jwt/jwt#1946v4.4.0 - 2021-07-12
Fixes
- Split HeaderXForwardedFor header only by comma #1878
- Fix Timeout middleware Context propagation #1910
Enhancements
- Bind data using headers as source #1866
- Adds JWTConfig.ParseTokenFunc to JWT middleware to allow different libraries implementing JWT parsing. #1887
- Adding tests for Echo#Host #1895
- Adds RequestIDHandler function to RequestID middleware #1898
- Allow for custom JSON encoding implementations #1880
v4.3.0 - 2021-05-08
Important notes
- Route matching has improvements for following cases:
- Correctly match routes with parameter part as last part of route (with trailing backslash)
- Considering handlers when resolving routes and search for matching http method handler
- Echo minimal Go version is now 1.13.
Fixes
- When url ends with slash first param route is the match #1804
... (truncated)
Commits
5b8fa69Update version and changelog for 4.5.0647af2aJWT middleware has been changed fromgithub.com/dgrijalva/jwt-goto github....58366f9Update version and changelog for 4.4.0 (#1919)02de901Fixing Timeout middleware Context propagation (#1910)5e791b0Allow for custom JSON encoding implementations (#1880)fd7a8a9Adds RequestIDHandler function to RequestID middlewaref20820cAdding tests for Echo#Host (#1895)1ac4a8fAdds JWTConfig.ParseTokenFunc to JWT middleware to allow different libraries ...fdacff0Split XFF header only by comma1c24ab8fix rateLimiteDoc- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language -
@dependabot badge mewill comment on this PR with code to add a "Dependabot enabled" badge to your readme
Additionally, you can set the following in your Dependabot dashboard:
- Update frequency (including time of day and day of week)
- Pull request limits (per update run and/or open at any time)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)