Skip to content

chore(deps): bump the minor-and-patch group with 2 updates - #758

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/minor-and-patch-b52285b1d1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/minor-and-patch-b52285b1d1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026 •

Copy link
Copy Markdown

Bumps the minor-and-patch group with 2 updates: github.com/go-playground/locales and github.com/huandu/xstrings.

Updates github.com/go-playground/locales from 0.14.1 to 0.14.2

Release notes

Sourced from github.com/go-playground/locales's releases.

Release 0.14.2

What's Changed

New Contributors

Full Changelog: go-playground/locales@v0.14.1...v0.14.2

Commits
  • 5a63b32 docs: clarify Ordinal/CardinalPluralRule README example output (#51)
  • 90801cf fix: fix out of bounds index in W and T helper functions and add unit tests (...
  • 7e517f0 Fix 12-hour midnight formatting (0:00 am -> 12:00 am) (#53)
  • See full diff in compare view

Updates github.com/huandu/xstrings from 1.6.1 to 1.6.2

Release notes

Sourced from github.com/huandu/xstrings's releases.

Bug fixes for ToCamelCase and Translate, plus a Scrub doc clarification

This release documents everything since v1.6.0, including the two changes which were parked on the v1.6.1 tag. That tag never got a release note of its own, so its changes are listed here as well and the changelog link at the bottom compares against v1.6.0.

Both Translate bugs silently returned a wrong string instead of reporting an error, so please read the Behaviour changes section if you pass patterns which contain a literal replacement character.

Bug fixes

Translate / Delete / Count: a literal U+FFFD in a pattern

The internal marker for "no rune" was utf8.RuneError, which is the very same value as the rune U+FFFD. A literal replacement character in a from or to pattern was therefore mistaken for the end of the pattern: the rune was dropped from the pattern and every pattern rune behind it was mismapped.

  • Translate("\uFFFDa", "\uFFFDa", "xy") returned "\uFFFDx" instead of "xy".
  • Delete("\uFFFDa\uFFFDb", "\uFFFDa") returned "\uFFFD\uFFFDb" instead of "b", and Count("\uFFFDa\uFFFDb", "\uFFFDa") returned 1 instead of 3.
  • In a to pattern the documented "repeat the last rune in to" rule broke as well: Translate("abc", "abc", "x\uFFFD") returned "xxx" instead of "x\uFFFD\uFFFD".

The internal marker is noRune = -1 now, a value which decoding a string can never produce, so U+FFFD is an ordinary rune in a pattern. The historical fallback for a pattern which parses to no rune at all ("-", "---", "\\", and the same shapes behind a range such as "0-9-") is kept, and is pinned by a test now.

Translate: the last rune of a from range was dropped when to contains literals

When a from range was mapped onto the literal runes of a to pattern, the last rune of the range never got a mapping: it was left unchanged in the result, and as soon as more source runes followed, their replacement runes shifted.

  • Translate("ab", "a-b", "xy") returned "xb" instead of "xy".
  • Translate("abc", "a-c", "xyz") returned "xyc" instead of "xyz".
  • Translate("abc", "a-bc", "xyz") returned "xby" instead of "xyz", i.e. 'c' was mapped to the rune 'b' should have used.

Translator.TranslateRune was affected too: NewTranslator("a-b", "xy").TranslateRune('b') returned ('b', false) although 'b' is part of the pattern. It returns ('y', true) now.

ToCamelCase: a single uppercase rune behind a separator was lowercased

ToCamelCase lowercased the last uppercase initial of an input, so it disagreed with the lowercase spelling of the same word:

  • ToCamelCase("option_A") returned "optiona" instead of "optionA"; the same applied to "option-A" and "option A".
  • ToCamelCase("HTTP_X") returned "httpx" instead of "httpX", and ToCamelCase("é_Ö") returned "éö" instead of "éÖ".

The final lowercasing step was redundant — the loop already normalizes the uppercase runes inside each word — so it was removed. ToPascalCase is not affected, and neither is input which starts with an uppercase word: ToCamelCase("URL_Parser") is still "urlParser".

Scrub: documentation only

Scrub replaces invalid UTF-8 bytes and valid U+FFFD runes with repl, and a consecutive run of them is replaced only once. The doc comment now says so and has samples: Scrub("a\uFFFDb", "?") => "a?b". Runtime behaviour is unchanged.

Behaviour changes

  • ToCamelCase keeps a single uppercase rune behind a separator: "option_A" → "optionA" (it was "optiona"), "HTTP_X" → "httpX" (it was "httpx").
  • A pattern which contains a literal U+FFFD behaves differently now, because the rune is part of the pattern instead of being removed from it. The results listed above are the only ones which change.
  • Delete, Count and Squeeze are not affected by the range fix, and ^-reverted patterns are not affected by either of the two Translate fixes.

Tests

  • 16 new table driven cases for the range fix: ascending and descending source ranges, shorter and longer replacement patterns, runes before and after a range, several ranges in one pattern, Unicode, U+0000 as a replacement rune, and an escaped - in the to pattern.
  • Two focused tests for the replacement character fix: literal positions, range endpoints, escaped and reverted patterns, the "repeat the last rune" rule, and the shared Delete, Count and TranslateRune paths.

... (truncated)

Commits
  • 96b69c7 Merge pull request #71 from x0Lazarus/fix/range-to-literal-endpoint
  • 4cb5e7c Merge pull request #70 from x0Lazarus/fix/literal-replacement-character-patterns
  • f1befd2 Preserve the last character when translating a range to literals
  • b60089c Fix literal replacement characters in translation patterns
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch group with 2 updates: [github.com/go-playground/locales](https://github.com/go-playground/locales) and [github.com/huandu/xstrings](https://github.com/huandu/xstrings).


Updates `github.com/go-playground/locales` from 0.14.1 to 0.14.2
- [Release notes](https://github.com/go-playground/locales/releases)
- [Commits](go-playground/locales@v0.14.1...v0.14.2)

Updates `github.com/huandu/xstrings` from 1.6.1 to 1.6.2
- [Release notes](https://github.com/huandu/xstrings/releases)
- [Commits](huandu/xstrings@v1.6.1...v1.6.2)

---
updated-dependencies:
- dependency-name: github.com/go-playground/locales
  dependency-version: 0.14.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: github.com/huandu/xstrings
  dependency-version: 1.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner October 4, 2026 22:03
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 4, 2026
@kw-security

kw-security commented Oct 4, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@dependabot @github

dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 6, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/minor-and-patch-b52285b1d1 branch October 6, 2026 15:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant