Skip to content

chore(deps): bump libopenapi to v0.41.5 - #4554

Merged
dgageot merged 2 commits into
mainfrom
chore/bump-libopenapi
Oct 8, 2026
Merged

dgageot merged 2 commits into
mainfrom
chore/bump-libopenapi

Conversation

@dgageot

@dgageot dgageot commented Oct 8, 2026

Copy link
Copy Markdown
Member

github.com/pb33f/libopenapi v0.41.5 ships a new YAML fork, and the previous openapi.go code decoded nodes by depending directly on the concrete yaml.Node type. Bumping straight to the new version would have caused a node type mismatch at decode time, so the upgrade needed a small refactor first.

yamlNodeToValue now decodes through a tiny nodeDecoder interface (Decode(target any) error) instead of importing either YAML library directly. Callers provide a fallback that preserves typed values and the raw string when decoding fails, and the existing nil guards are unchanged. With that in place, go.mod moves github.com/pb33f/libopenapi from v0.40.0 to v0.41.5, pulling in updated jsonpath and ordered-map transitive versions; go.yaml.in/yaml/v4 stays indirect because of go-vcr, and pb33f/go-yaml v0.1.1 is added as indirect. No other direct dependencies or replacement pins change.

Test coverage was extended with a fake decoder exercising successful types, null, and partial-output errors, plus integration cases for enum, default float, boolean, null, array, and object values; existing string and integer tests were kept as-is. task build, task test, and task lint all pass, matching CI's golangci-lint v2.13.2, and the unchanged go-licenses v1.6.0 Linux/amd64 check still passes since no license-affecting dependency changed.

Module From To Status
github.com/pb33f/libopenapi v0.40.0 v0.41.5 bumped

Introduce a small nodeDecoder interface so yamlNodeToValue no longer
depends on a concrete yaml.Node type, letting it work across old and
new YAML node implementations.

Assisted-By: docker-agent
Signed-off-by: David Gageot <david.gageot@docker.com>
Pulls in updated jsonpath and ordered-map deps.

Signed-off-by: David Gageot <david.gageot@docker.com>
Assisted-By: docker-agent
@dgageot
dgageot requested a review from a team as a code owner October 8, 2026 15:47
@aheritier aheritier added area/deps Dependency updates and version bumps kind/chore Maintenance, deps, CI, tooling (maps to chore: commit prefix) labels Oct 8, 2026
@dgageot
dgageot added this pull request to the merge queue Oct 8, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 8, 2026
@dgageot
dgageot added this pull request to the merge queue Oct 8, 2026
Merged via the queue into main with commit 8825c50 Oct 8, 2026
26 of 28 checks passed
@dgageot
dgageot deleted the chore/bump-libopenapi branch October 8, 2026 16:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/deps Dependency updates and version bumps kind/chore Maintenance, deps, CI, tooling (maps to chore: commit prefix)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants