Skip to content

Bump github.com/oapi-codegen/runtime from 1.6.0 to 1.7.0 in /go - #95

Merged
jeremy merged 3 commits into
mainfrom
dependabot/go_modules/go/github.com/oapi-codegen/runtime-1.7.0
Sep 10, 2026
Merged

Bump github.com/oapi-codegen/runtime from 1.6.0 to 1.7.0 in /go#95
jeremy merged 3 commits into
mainfrom
dependabot/go_modules/go/github.com/oapi-codegen/runtime-1.7.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 20, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/oapi-codegen/runtime from 1.6.0 to 1.7.0.

Release notes

Sourced from github.com/oapi-codegen/runtime's releases.

v1.7.0: Extensions for OpenAPI 3.1 parameter binding

This release teaches the parameter binders about OpenAPI 3.1 multi-type unions, and fixes a long-standing panic on the request binding path. As with v1.6.0, new behavior is controlled by explicit settings rather than assumptions: binding stays exactly as it was unless the new options are used.

Notable Changes

Binding OpenAPI 3.1 multi-type union parameters

OpenAPI 3.1 allows a parameter's type to be a list, such as type: [string, integer]. Go has no type meaning "one of these", so generated code maps such parameters to any — which the binders previously rejected outright with can not bind to destination of type: interface, making these parameters unusable.

The binder options structs (BindStyledParameterOptions, BindQueryParameterOptions, BindStringToObjectOptions) gain a Types []string field carrying the union's member list. It is only consulted when the destination is an any; binding into every concrete Go type is completely unchanged. The value binds to the first member that parses, trying boolean, integer, number, then string — most restrictive first, since a string always parses. Member detection follows the JSON number grammar (RFC 8259), so values like 007 or +1 bind as strings rather than being silently reinterpreted as numbers.

The bound value's dynamic type is always one of bool, int64, float64, string, or (with format: byte) []byte, so a handler's type switch is stable regardless of what the spec's format says. Applications that want format: int32 / format: float to narrow the produced types to int32 / float32 can opt in via a new package-level setting, following the same pattern as DefaultQueryEncoder from v1.6.0:

func init() {
    runtime.NarrowUnionNumericFormats = true
}

Generator support for emitting Types is landing in oapi-codegen separately; the runtime side ships first so generated code can rely on it. Arrays of unions and deepObject-style parameters are not covered yet — see the Types field documentation for the exact scope.

Fix for a panic when binding numeric values into slice destinations

Since v1.2.0, binding a string that happens to parse as an integer into a non-[]byte slice destination panicked with reflect: call of reflect.Value.OverflowInt on slice Value, instead of returning an error. This was reachable from generated code on the request path: a nullable.Nullable[[]string] query parameter using the default form/explode serialization would panic on ?p=123 while returning a normal binding error on ?p=abc. These cases now return a clean can not bind to destination of type: slice error.

🚀 New features and improvements

🐛 Bug fixes

✍ Other changes

📦 Dependency updates

... (truncated)

Commits
  • 25e2d35 Fix panic binding numeric values into non-byte slice destinations (#156)
  • f2e468c Bind OpenAPI 3.1 multi-type union parameters into any destinations (#154)
  • 611503e chore(deps): update github/codeql-action action to v4.37.7 (#152)
  • d8c6443 chore(deps): update release-drafter/release-drafter action to v7.7.0 (#151)
  • 0caa035 chore(deps): update github/codeql-action action to v4.37.5 (#150)
  • 95ed734 fix(deps): update module github.com/labstack/echo/v5 to v5.3.1 (#149)
  • 2f68f55 chore: use go mod tidy instead of tidied (#148)
  • 03f0d06 chore(deps): update release-drafter/release-drafter action to v7.6.0 (#147)
  • 99e61d7 chore(deps): update github/codeql-action action to v4.37.2 (#146)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by cubic

Bumps github.com/oapi-codegen/runtime from 1.6.0 to 1.7.0 to add optional OpenAPI 3.1 union parameter binding and fix a request-binding panic. Previously, union params mapped to any were rejected and some numeric-to-slice bindings could panic; now binding remains unchanged by default, union support is opt-in via binder options, and those cases return a clean error instead of panicking.

  • No migration required; existing behavior stays the same unless union binding options or runtime.NarrowUnionNumericFormats are enabled.
  • Tests that expected a panic on numeric-to-slice binding should now expect an error.
  • If we plan to use union parameters, also upgrade the generator to emit Types and wire the new options.
  • Drops unused golang.org/x/net dependency from go.mod and the conformance runner's go.mod.

Written for commit 4e2172f. Summary will update on new commits.

Review in cubic

Bumps [github.com/oapi-codegen/runtime](https://github.com/oapi-codegen/runtime) from 1.6.0 to 1.7.0.
- [Release notes](https://github.com/oapi-codegen/runtime/releases)
- [Commits](oapi-codegen/runtime@v1.6.0...v1.7.0)

---
updated-dependencies:
- dependency-name: github.com/oapi-codegen/runtime
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 20, 2026
Copilot AI balanced review requested due to automatic review settings August 20, 2026 21:53
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 20, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the generated Go client’s OpenAPI runtime dependency from v1.6.0 to v1.7.0.

Changes:

  • Bumps github.com/oapi-codegen/runtime.
  • Refreshes module checksums and removes an unused direct dependency.

Tip

If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or run gh pr ready --undo.
Click "Ready for review" or run gh pr ready to reengage.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
go/go.mod Updates the runtime dependency and module requirements.
go/go.sum Records v1.7.0 checksums.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

* origin/main: (45 commits)
  Rust SDK (#145)
  Read a Set Aside group with its postings (#142)
  Generated client reads revalidate through the response cache (#140)
  Generated client retries and refresh resends fire Hooks.OnRetry (#139)
  Form requests retry once after a 401 refresh instead of recursing (#138)
  Generated client honors WithMaxRetries and retries once after a 401 refresh (#137)
  Ask for JSON on the deletes HEY already answers in JSON (#136)
  Send a reply as the sender the prefill resolved (#135)
  Bump github/codeql-action/upload-sarif (#96)
  Let a reply carry its subject (#134)
  Bump version to 0.28.1 (#132)
  Fix all-day calendar event updates sending invalid clock times (#131)
  Bump version to 0.28.0 (#130)
  Model the Imbox's Previously Seen postings: GetImboxSeen (#129)
  Model the contact thread list: page cursor and postings on GetContact (#127)
  Model a bundle's unseen postings: GetBundleUnseenPostings (#126)
  Expose calendar recording pagination (#125)
  Model scheduled bubble-up: SchedulePostingsBubbleUp (#124)
  Model the identity calendar preferences: UpdateFirstWeekDay and UpdateTimeFormat (#123)
  Bump the SDK to 0.22.0 (#122)
  ...
@jeremy

jeremy commented Sep 9, 2026

Copy link
Copy Markdown
Member

The red Conformance Tests check was not a runtime behaviour change. The Go conformance runner at conformance/runner/go has its own go.mod with the SDK pulled in through a replace, and it still listed oapi-codegen/runtime v1.6.0 as an indirect dependency, so go run . refused with go: updates to go.mod needed. Dependabot only tidies the module it bumps.

Pushed a go mod tidy for the runner on top of the bump. Checked the 1.7.0 changes against what the generated client uses: 1.7.0 adds opt-in OpenAPI 3.1 union binding and fixes a panic on the server-side request-binding path; client.gen.go only calls runtime.StyleParamWithLocation, which is untouched. The full make check (Go, Rust, both conformance runners) passes locally on this branch merged with main.

@jeremy

jeremy commented Sep 9, 2026

Copy link
Copy Markdown
Member

Two further reds on the tidy push, both from the branch being 45 commits behind main rather than from the bump: CodeQL's Analyze (rust) checks out the PR head, which predates the Rust SDK (#145) and has no rust/ tree, so it found nothing to analyse; and API Compatibility diffs the PR head against main, so main's newer EntriesService.CreateReply signature read as a break in this direction. Merged main into the branch so CI sees the current tree.

@jeremy
jeremy merged commit 4e0a9c6 into main Sep 10, 2026
21 checks passed
@jeremy
jeremy deleted the dependabot/go_modules/go/github.com/oapi-codegen/runtime-1.7.0 branch September 10, 2026 03:57
@jeremy jeremy mentioned this pull request Sep 10, 2026
3 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants