Skip to content

fix(deps): update module github.com/azure/azure-sdk-for-go/sdk/storage/azblob to v1.8.2 (main) - #7

Open
sc-renovate[bot] wants to merge 1 commit into
mainfrom
deps-update/main-azure-sdk-for-go-monorepo
Open

sc-renovate[bot] wants to merge 1 commit into
mainfrom
deps-update/main-azure-sdk-for-go-monorepo

Conversation

@sc-renovate

@sc-renovate sc-renovate Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Confidence
github.com/Azure/azure-sdk-for-go/sdk/storage/azblob v1.8.0 → v1.8.2 age confidence

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

Azure/azure-sdk-for-go (github.com/Azure/azure-sdk-for-go/sdk/storage/azblob)

v1.8.2

1.8.2 (2026-10-01)

Bugs Fixed
  • Fixed blob.Client.GetSASURL() generating a SAS that omitted the pinned blob version from the signed string-to-sign when called on a client returned by WithVersionID. The resulting SAS was byte-for-byte identical to an ordinary base-blob (sr=b) SAS and, once corrected to include sr=bv, would still fail to authenticate because the version identifier was never included in the signed payload. Both the resource-type binding and the signed version identifier are now correctly propagated for SignWithSharedKey and SignWithUserDelegation.
  • Fixed GetSASURL() on blob.Client, container.Client, and service.Client (and the specialized blob clients blockblob.Client, appendblob.Client, pageblob.Client which delegate to blob.Client) appending a duplicated ? to the resulting URL when called on a client whose URL already contained a query string (e.g. a client returned by WithSnapshot or WithVersionID, or a custom endpoint with pre-existing query parameters), which produced a malformed SAS URL.
Other Changes
  • Updated azcore version to 1.23.2

v1.8.1

1.8.1 (2026-09-09)

Known Issues
  • The default x-ms-version was updated to 2026-12-06, which is not yet supported by all Azure Storage stamps. Affected storage accounts may return 400 InvalidHeaderValue errors. The rollout is expected to complete across all public regions by early October 2026. In the meantime, either pin to v1.8.0 or inject a per-retry pipeline policy that sets x-ms-version to 2026-10-06.
Breaking Changes
  • DownloadBuffer and DownloadFile now use ETag locking to ensure consistency across parallel chunk requests when the blob size is not specified upfront (i.e., Range.Count is zero). If a blob is modified during a multi-chunk download, subsequent requests will fail with ConditionNotMet instead of silently returning data from mixed blob versions.
Bugs Fixed
  • Fixed CRLF injection vulnerability in Blob Batch subrequest serialization. Header values containing CR or LF characters are now rejected before serialization, preventing header injection in batch requests.
  • Fixed WASM compilation by using heap-allocated buffers on JS targets.
  • Fixed Structured Message CRC64 download validation being skipped when the final payload byte exactly fills the caller's read buffer; the trailing segment footer and message trailer CRC64 are now drained and validated in the same Read.
  • Fixed transient net.Error/io.ErrUnexpectedEOF failures during a Structured Message download not being retried: the decoder now preserves the error chain with %w and the retry reader classifies retryable errors with errors.Is/errors.As.
  • Structured Message download now rejects a response missing the negotiated CRC64 flag instead of silently skipping validation.
  • Fixed the Structured Message encoder emitting a valid, complete message when the source returned a non-EOF error exactly on a segment boundary; such errors are now propagated.
  • Structured Message decoding now rejects a payload that declares fewer segments and appends unvalidated trailing bytes (SMDecode requires the parsed message to consume the entire input, and the streaming decoder validates the consumed byte count against the declared message length).
  • Fixed the Structured Message encoder returning io.EOF when the source ends before the declared content length; a premature EOF is now surfaced as io.ErrUnexpectedEOF so callers do not accept a truncated message.
  • Fixed Structured Message decoder discarding errors (including net.Error and io.EOF) when the returned bytes exactly complete a segment; such errors are now propagated so RetryReader can retry transient failures at segment boundaries.
  • Premature EOF during Structured Message framing reads (header, segment footer, or message trailer) now wraps io.ErrUnexpectedEOF so RetryReader classifies truncated framing as retryable.
Other Changes
  • Optimized DownloadBuffer and DownloadFile to use an initial GET request instead of a HEAD (GetProperties) call for blob size discovery. For small blobs (<=4MB), the entire content is returned in a single request, reducing download latency by ~50%.
  • Updated azcore to v1.23.1.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@sc-renovate

sc-renovate Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 3 additional dependencies were updated

Details:

Package Change
github.com/pierrec/lz4/v4 v4.1.27 -> v4.1.28
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.23.1 -> v1.23.2
github.com/klauspost/cpuid/v2 v2.2.11 -> v2.4.0

@sc-renovate
sc-renovate Bot force-pushed the deps-update/main-azure-sdk-for-go-monorepo branch from 389ecd2 to f8c44b7 Compare October 1, 2026 20:16
@sc-renovate sc-renovate Bot changed the title fix(deps): update module github.com/azure/azure-sdk-for-go/sdk/storage/azblob to v1.8.1 (main) fix(deps): update module github.com/azure/azure-sdk-for-go/sdk/storage/azblob to v1.8.2 (main) Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants