Skip to content

build(deps): bump github.com/vektah/gqlparser/v2 from 2.5.58 to 2.5.59 in the go-dependencies group - #198

Merged
samzong merged 1 commit into
mainfrom
dependabot/go_modules/go-dependencies-037401182a
Oct 6, 2026
Merged

samzong merged 1 commit into
mainfrom
dependabot/go_modules/go-dependencies-037401182a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-dependencies group with 1 update: github.com/vektah/gqlparser/v2.

Updates github.com/vektah/gqlparser/v2 from 2.5.58 to 2.5.59

Release notes

Sourced from github.com/vektah/gqlparser/v2's releases.

v2.5.59

Changelog

  • 7bd8ce26a9a91a93381ec130c4dd0005a64312f5 Avoid iterator allocations in overlapping field validator (#481)
  • 3ccd437ff1ef32b6851a670f749d7bc2aca6b20b Benchmarks, a benchmark gate, property tests and mutation testing (#482)
  • 6ddb71072cb8e029586d5170ea73e85a0427f62c Index fragments by name in the validator walker (#472)
  • b312a14470809ce15efc7d4727eea4f080fcdebd build(deps): bump brace-expansion in /validator/imported (#480)
  • dce6e6633aa43412964d77e10faa431d593f99ad build(deps-dev): bump prettier (#473)
  • 3e25eab8a762bdf95e1a69b91540c14354dbd324 feat(validator): Add new validator.EmptyDefinitionError (#474)
  • eaee10953561f7943a8bbf46a56054aecf7c6e81 lexer: combine surrogate pair escapes in string literals (#476)
  • 1c204b4b992ebdc7724634ad4be0f52f838b15bf validator: make MaxIntrospectionDepth linear in fragment spreads (#471)
  • b99f91aec8211fe80208078b2d1991f10d1f7d57 validator: stop OverlappingFieldsCanBeMerged recursing forever on fragment cycles (revised #477) (#478)

Verifying this release

# 1. cosign signature over the checksum file (identity = the release workflow).
cosign verify-blob \
  --bundle checksums.txt.sigstore.json \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  --certificate-identity 'https://github.com/StevenACoffman/gqlparser/.github/workflows/release.yml@refs/tags/v2.5.59' \
  checksums.txt
2. source tarball + SBOM hash to the now-trusted checksums.
shasum -a 256 -c checksums.txt
3. GitHub build provenance.
gh attestation verify gqlparser_2.5.59_source.tar.gz --repo StevenACoffman/gqlparser

The SBOM is gqlparser_2.5.59_source.tar.gz.sbom.json (SPDX-2.3).


Released by GoReleaser.

Commits
  • 7bd8ce2 Avoid iterator allocations in overlapping field validator (#481)
  • 3ccd437 Benchmarks, a benchmark gate, property tests and mutation testing (#482)
  • 1c204b4 validator: make MaxIntrospectionDepth linear in fragment spreads (#471)
  • dce6e66 build(deps-dev): bump prettier (#473)
  • b312a14 build(deps): bump brace-expansion in /validator/imported (#480)
  • b99f91a validator: stop OverlappingFieldsCanBeMerged recursing forever on fragment cy...
  • 6ddb710 Index fragments by name in the validator walker (#472)
  • 3e25eab feat(validator): Add new validator.EmptyDefinitionError (#474)
  • eaee109 lexer: combine surrogate pair escapes in string literals (#476)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-dependencies group with 1 update: [github.com/vektah/gqlparser/v2](https://github.com/vektah/gqlparser).


Updates `github.com/vektah/gqlparser/v2` from 2.5.58 to 2.5.59
- [Release notes](https://github.com/vektah/gqlparser/releases)
- [Commits](vektah/gqlparser@v2.5.58...v2.5.59)

---
updated-dependencies:
- dependency-name: github.com/vektah/gqlparser/v2
  dependency-version: 2.5.59
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 5, 2026
@ghfind-review ghfind-review Bot added the review: no-score ghfind author score missing (not zero) label Oct 5, 2026
@codspeed

codspeed Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Merging this PR will degrade performance by 43.36%

⚠️ Unknown Walltime execution environment detected

Using the Walltime instrument on standard Hosted Runners will lead to inconsistent data.

For the most accurate results, we recommend using CodSpeed Macro Runners: bare-metal machines fine-tuned for performance measurement consistency.

⚠️ Different runtime environments detected

Some benchmarks with significant performance changes were compared across different runtime environments,
which may affect the accuracy of the results.

Open the report in CodSpeed to investigate

❌ 21 regressed benchmarks

Warning

Please fix the performance issues or acknowledge them on CodSpeed.

Performance Changes

Benchmark BASE HEAD Efficiency
❌ yaml 2.7 ms 5.1 ms -47.75%
❌ large 866.9 µs 1,613.9 µs -46.29%
❌ yaml-large 8 ms 14.9 ms -46.28%
❌ large 1.2 ms 2.2 ms -45.93%
❌ json 699.9 µs 1,273.1 µs -45.02%
❌ miss 1.9 ms 3.5 ms -44.9%
❌ small 77.6 µs 139.6 µs -44.41%
❌ small 65 µs 116.7 µs -44.3%
❌ hit 2 ms 3.5 ms -44.13%
❌ BenchmarkParseNormalize 4.3 ms 7.6 ms -43.73%
❌ large 907.1 µs 1,609.6 µs -43.64%
❌ BenchmarkCatalogJSON 1.6 ms 2.8 ms -43.4%
❌ table 403.3 µs 710.9 µs -43.28%
❌ BenchmarkFormatTableInferredColumns 620.9 µs 1,092.3 µs -43.16%
❌ json-small 144.8 µs 250.7 µs -42.22%
❌ BenchmarkFindCatalogCommand 4.6 µs 7.9 µs -41.78%
❌ json-large 1.8 ms 3 ms -40.99%
❌ small 82 µs 138.5 µs -40.85%
❌ small 104.5 µs 175.6 µs -40.47%
❌ large 1.3 ms 2.2 ms -40.12%
... ... ... ... ...

ℹ️ Only the first 20 benchmarks are displayed. Go to the app to view all benchmarks.

Tip

Investigate this regression by commenting @codspeedbot fix this regression on this PR, or directly use the CodSpeed MCP with your agent.


Comparing dependabot/go_modules/go-dependencies-037401182a (28b56a2) with main (37b49ba)

Open in CodSpeed

@samzong
samzong merged commit 56fb4c7 into main Oct 6, 2026
4 of 5 checks passed
@dependabot
dependabot Bot deleted the dependabot/go_modules/go-dependencies-037401182a branch October 6, 2026 15:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code review: no-score ghfind author score missing (not zero)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant