Skip to content

fix(deps): update module github.com/go-telegram/bot to v1.27.0 - #149

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/github.com-go-telegram-bot-1.x
Sep 11, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/github.com-go-telegram-bot-1.x

Conversation

@renovate

@renovate renovate Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/go-telegram/bot v1.25.0 → v1.27.0 age confidence

Release Notes

go-telegram/bot (github.com/go-telegram/bot)

v1.27.0

Compare Source

  • Fix: a request can be retried by HTTP/2 after the server sends GOAWAY. rawRequest
    streamed the multipart body through an io.Pipe, which net/http cannot replay,
    so Request.GetBody was never set and http2.Transport failed every POST in
    flight on a draining connection with cannot retry err ... after Request.Body was written. Telegram drains connections routinely, and a bot on such a connection
    kept receiving updates while every sendMessage / editMessageText /
    answerCallbackQuery failed until the connection was dropped. The body is now
    built into a buffer up front and handed over as a *bytes.Reader, so net/http
    sets ContentLength and GetBody and the transport retries transparently. The
    trade-off is that an upload is held in memory for the duration of the request
    instead of being streamed (#​275).
  • Fix: a method without fields (getMe, logOut, close, or a params struct whose
    fields are all omitted) is sent without a body and without a multipart
    Content-Type. The pipe-based request always declared a multipart body, empty or
    not, which local telegram-bot-api --local servers reject with a bare 400, so
    bot.New against a local server failed with unexpected end of JSON input
    (#​285, #​224).
  • Fix: buildRequestForm counts custom-marshaled fields (BotCommandScope,
    InlineQueryResult) and InputMedia fields. They were written to the form but
    not counted, so a request consisting only of such a field would have been sent
    as empty.

v1.26.0

Compare Source

  • Fix: an unknown polymorphic discriminator no longer stalls long polling. Fourteen
    models (ChatMember, ReactionType, ChatBoostSource, OwnedGift, MenuButton,
    MessageOrigin, StoryAreaType, TransactionPartner, RevenueWithdrawalState,
    BackgroundType, BackgroundFill, RichBlock, RichText, PaidMedia) returned
    unsupported <Type> type from UnmarshalJSON when the type / status / source
    value was not in their switch. getUpdates decoded the whole batch with one
    json.Unmarshal, so a single update carrying a value added by a Bot API release
    failed the entire call, the offset never advanced, and the same batch was requested
    and rejected forever. The wrapper now keeps the raw value in Type (Source for
    ChatBoostSource), leaves every variant pointer nil and returns no error, so a
    consumer switching on Type reaches its default branch instead of never seeing the
    update. The webhook path gets the same tolerance through the models.
  • Fix: the nine unions with a MarshalJSON (ChatMember, ReactionType,
    ChatBoostSource, MenuButton, MessageOrigin, BackgroundType, BackgroundFill,
    RichBlock, RichText) encode an unknown discriminator as the bare
    {"type":"<Type>"} (status / source where applicable) instead of returning
    unsupported <Type> type, so an update that is logged, persisted or queued as JSON
    still encodes on the day Telegram ships a new variant. Only the discriminator
    survives: no variant was populated, so the other fields of the unknown object are
    not kept and are not written back. The remaining five unions have no custom encoder
    and are unchanged.
  • Fix: a tagged object without a discriminator ({}, or a ChatMember without
    status) is rejected by UnmarshalJSON in all fourteen unions. It is a malformed
    value rather than a variant from a future release, and MarshalJSON rejects an
    empty Type on the way back out, so accepting it would produce values that decode
    but cannot be encoded again. For RichText an empty Type is also its plain-string
    form, so {"text":"hi"} would otherwise have decoded to an empty string.
  • Fix: ReactionType.MarshalJSON handles paid. The variant has been decodable since
    Bot API 7.6 but had no marshal case, so a paid reaction read from an update could not
    be encoded back, e.g. into setMessageReaction. All three ReactionType variants now
    go through the shared marshalVariant, so a Type set without its variant pointer
    returns an error instead of panicking inside encoding/json.
  • Fix: getUpdates decodes each update on its own. An update that still fails to
    decode is reported through the errors handler with its update_id and its raw
    payload, the offset moves past it, and the rest of the batch is delivered. When the
    last update of a batch has no readable update_id (an unparsable id, a null
    element, an object without the field) the offset cannot move and the same batch comes
    back, so the poll backs off (100ms..5s, one step per request) as it does on a failed
    request, instead of re-requesting it in a tight loop. Such an element is reported
    and never delivered, and no longer resets the offset to zero.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@coderabbitai

coderabbitai Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: c8194f58-55cf-431b-806d-1cc5b9a8f854

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@deepsource-io

deepsource-io Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in a7fa8af...1f8a9c9 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Go Sep 11, 2026 5:29p.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@renovate
renovate Bot merged commit 5bb83cb into main Sep 11, 2026
15 checks passed
@renovate
renovate Bot deleted the renovate/github.com-go-telegram-bot-1.x branch September 11, 2026 22:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants