fix(deps): update module github.com/hashicorp/consul/api to v1.33.2#18
Open
renovate[bot] wants to merge 1 commit intomainfrom
Open
fix(deps): update module github.com/hashicorp/consul/api to v1.33.2#18renovate[bot] wants to merge 1 commit intomainfrom
renovate[bot] wants to merge 1 commit intomainfrom
Conversation
5ea53ba to
9f7bd44
Compare
9f7bd44 to
797213e
Compare
797213e to
e65a232
Compare
e65a232 to
adcb013
Compare
adcb013 to
6e91a9b
Compare
6e91a9b to
fef965a
Compare
fef965a to
bd65b22
Compare
bd65b22 to
437dc63
Compare
437dc63 to
59bce4b
Compare
59bce4b to
1c4fb12
Compare
1c4fb12 to
a34c73b
Compare
a34c73b to
19a8ced
Compare
19a8ced to
a710b5a
Compare
a710b5a to
c104c4a
Compare
c104c4a to
43e22bd
Compare
b96a2b8 to
f5b14cf
Compare
f5b14cf to
4aaea24
Compare
4aaea24 to
7b54f04
Compare
7b54f04 to
19dfcb5
Compare
19dfcb5 to
674d21b
Compare
674d21b to
c83d9ff
Compare
c83d9ff to
4eaff2b
Compare
4eaff2b to
744dc89
Compare
744dc89 to
d129d39
Compare
d129d39 to
938dfeb
Compare
938dfeb to
4154752
Compare
4154752 to
639f047
Compare
639f047 to
68ac323
Compare
68ac323 to
946955c
Compare
946955c to
f014144
Compare
Author
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
f014144 to
a32c8e6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.11.0→v1.33.2Release Notes
hashicorp/consul (github.com/hashicorp/consul/api)
v1.22.0Compare Source
1.22.0 (October 24, 2025)
SECURITY:
FEATURES:
IMPROVEMENTS:
consul operator utilization [-today-only] [-message] [-y]to generate a bundle with census utilization snapshot. Main flow is implemented in consul-enterprisehttp: Added a new API Handler for
/v1/operator/utilization. Core functionality to be implemented in consul-enterpriseagent: Always enabled census metrics collection with configurable option to export it to Hashicorp Reporting [GH-22843]
snapshot agentnow supports authenticating to Azure Blob Storage using Azure Managed Service Identities (MSI). [GH-11171]BUG FIXES:
consul operator utilization --helpto show only available options without extra parameters. [GH-22912]v1.21.5Compare Source
1.21.5 (September 21, 2025)
SECURITY:
mitchellh/mapstructuretogo-viper/mapstructureto v2 to address CVE-2025-52893. [GH-22581]FEATURES:
max_request_headers_kbto configure maximum header size for requests from downstream to upstream [GH-22604]max_request_headers_kbto configure maximum header size for requests from downstream to upstream in API Gateway config and proxy-defaults [GH-22679]max_request_headers_kbto configure maximum header size for requests from downstream to upstream in Mesh Gateway via service-defaults and proxy-defaults [GH-22722]max_request_headers_kbto configure maximum header size for requests from downstream to upstream in Terminating Gateway service-defaults and proxy-defaults [GH-22680]IMPROVEMENTS:
BUG FIXES:
v1.21.4Compare Source
1.21.4 (August 13, 2025)
SECURITY:
IMPROVEMENTS:
BUG FIXES:
v1.21.3Compare Source
1.21.3 (July 18, 2025)
IMPROVEMENTS:
BUG FIXES:
v1.21.2Compare Source
1.21.2 (June 17, 2025)
SECURITY:
CVE-2025-4802
CVE-2024-40896
CVE-2024-12243
CVE-2025-24528
CVE-2025-3277
CVE-2024-12133
CVE-2024-57970
CVE-2025-31115 [GH-22409]
IMPROVEMENTS:
datacenterresulting in non-generation of X.509 certificates when using external CA for agent TLS communication. [GH-22382]BUG FIXES:
v1.21.1Compare Source
1.21.1 (May 21, 2025)
FEATURES:
IMPROVEMENTS:
v1.21.0Compare Source
1.21.0 (May 06, 2025)
FEATURES:
🔗 Link to full release details
IMPROVEMENTS:
raft_prevote_disabledto allow disabling raft prevote [GH-21758]v1.20.0Compare Source
1.20.0 (October 14, 2024)
SECURITY:
CVE-2024-34155 [GH-21705]
v1.55.5 or higher. This resolves CVEsCVE-2020-8911 and
CVE-2020-8912. [GH-21684]
FEATURES:
IMPROVEMENTS:
BUG FIXES:
v1.19.2Compare Source
1.19.2 (August 26, 2024)
SECURITY:
IMPROVEMENTS:
BUG FIXES:
v1.19.1Compare Source
1.19.1 (July 11, 2024)
SECURITY:
IMPROVEMENTS:
BUG FIXES:
This affected Nomad integrations with Consul. [GH-21361]
tag.name.service.consul, were being disregarded. [GH-21361]that was always being logged on each prepared query evaluation. [GH-21381]
v1.19.0Compare Source
1.19.0 (June 12, 2024)
BREAKING CHANGES:
consulelement in the metric name have been removed. Please use the same metric without the secondconsulinstead. As an example instead ofconsul.consul.state.config_entriesuseconsul.state.config_entries[GH-20674]SECURITY:
1.27.5 and 1.28.3. This resolves CVECVE-2024-32475 (
auto_sni). [GH-21017]v0.18.7 or higher. This resolves CVECVE-2020-8559. [GH-21017]
FEATURES:
Use
v1dnsin theexperimentsagent config to disable.The legacy server will be removed in a future release of Consul.
See the Consul 1.19.x Release Notes for removed DNS features. [GH-20715]
IMPROVEMENTS:
github.com/envoyproxy/go-control-planeto 0.12.0. [GH-20973]consul-dataplanenow accepts partition, namespace, token as metadata to default those query parameters.consul-dataplanev1.5+ will send this information automatically. [GH-20899]consul snapshot decodeCLI command to output a JSON object stream of all the snapshots data. [GH-20824]telemetry.disable_per_tenancy_usage_metricsin agent configuration to disable setting tenancy labels on usage metrics. This significantly decreases CPU utilization in clusters with many admin partitions or namespaces.DEPRECATIONS:
local_storage,aws_storage,azure_blob_storage, andgoogle_storagein snapshot agent configuration files are now deprecated. Use thebackup_destinationsconfig object instead.BUG FIXES:
v1.18.2Compare Source
1.18.2 (May 14, 2024)
Enterprise LTS: Consul Enterprise 1.18 is a Long-Term Support (LTS) release.
SECURITY:
alpine:3.19. [GH-20897]vault/apito v1.12.2 to address CVE-2024-28180(removes indirect dependency on impacted
go-jose.v2) [GH-20910]CVE-2024-24787 and
CVE-2024-24788 [GH-21074]
1.26.8, 1.27.4, 1.27.5, 1.28.2 and 1.28.3. This resolves CVEsCVE-2024-27919 (
http2). [GH-20956] and CVE-2024-32475 (auto_sni). [GH-21030]v0.18.7 or higher. This resolves CVECVE-2020-8559. [GH-21034]
1.21.9. This resolves CVECVE-2023-45288 (
http2). [GH-20956]v0.24.0. This resolves CVECVE-2023-45288 (
x/net). [GH-20956]IMPROVEMENTS:
BUG FIXES:
DefaultForFailover.DNS requests against sameness groups without this field set will now error as intended.
v1.18.1Compare Source
1.18.1 (March 26, 2024)
Enterprise LTS: Consul Enterprise 1.18 is a Long-Term Support (LTS) release.
BREAKING CHANGES:
SECURITY:
google.golang.org/protobufto v1.33.0 to address CVE-2024-24786. [GH-20801]alpine3.19. This resolves CVEsCVE-2023-52425
CVE-2023-52426 [GH-20812]
1.21.8. This resolves CVEsCVE-2024-24783 (
crypto/x509).CVE-2023-45290 (
net/http).CVE-2023-45289 (
net/http,net/http/cookiejar).CVE-2024-24785 (
html/template).CVE-2024-24784 (
net/mail). [GH-20812]IMPROVEMENTS:
backup_destinationsconfig file object.BUG FIXES:
v1.18.0Compare Source
BREAKING CHANGES:
telemetry.disable_hostnamewhen determining whether to prefix gauge-type metrics with the hostname of the Consul agent. Previously, if only the default metric sink was enabled, this configuration was ignored and always treated astrue, even though its default value isfalse. [GH-20312]SECURITY:
golang.org/x/cryptoto v0.17.0 to address CVE-2023-48795. [GH-20023]FEATURES:
Use
v2dnsin theexperimentsagent config to enable.It will automatically be enabled when using the
resource-apis(Catalog v2) experiment.The new DNS implementation will be the default in Consul 1.19.
See the Consul 1.18.x Release Notes for deprecated DNS features. [GH-20643]
IMPROVEMENTS:
envoy.config.core.v3.HeaderValueOption.append. [GH-20078]envoy.config.route.v3.HeaderMatcher.safe_regex_matchandenvoy.type.matcher.v3.RegexMatcher.google_re2. [GH-20013]BUG FIXES:
v1.17.0Compare Source
1.17.0 (October 31, 2023)
BREAKING CHANGES:
DEPRECATIONS:
-admin-access-log-pathflag fromconsul connect envoycommand in favor of:-admin-access-log-config. [GH-15946]SECURITY:
golang.org/x/netto v0.17.0 to address CVE-2023-39325/ CVE-2023-44487(
x/net/http2). [GH-19225]This resolves vulnerability CVE-2023-39325
/ CVE-2023-44487(
net/http). [GH-19225]google.golang.org/grpcto 1.56.3.This resolves vulnerability CVE-2023-44487. [GH-19414]
FEATURE PREVIEW: Catalog v2
This release provides the ability to preview Consul's v2 Catalog and Resource API if enabled. The new model supports
multi-port application deployments with only a single Envoy proxy. Note that the v1 and v2 catalogs are not cross
compatible, and not all Consul features are available within this v2 feature preview. See the v2 Catalog and Resource
API documentation for more information. The v2 Catalog and
Resources API should be considered a feature preview within this release and should not be used in production
environments.
Limitations
Significant Pull Requests
FEATURES:
acl.tokens.dnsconfig field which specifies the token used implicitly during dns checks. [GH-17936]bind-varflag toconsul acl binding-rulefor templated policy variables. [GH-18719]consul acl templated-policycommands to read, list and preview templated policies. [GH-18816]IMPROVEMENTS:
CheckRegisterOptsto Agent API [GH-18943]Tokenfield toServiceRegisterOptstype in Agent API [GH-18983]-templated-policy,-templated-policy-file,-replace-templated-policy,-append-templated-policy,-replace-templated-policy-file,-append-templated-policy-fileand-varflags for creating or updating tokens/roles. [GH-18708]tls.defaults.verify_server_hostnameconfiguration option. This specifies the default value for any interfaces that support theverify_server_hostnameoption. [GH-17155]BUG FIXES:
/v1/catalog/servicesendpoint [GH-18322]performance.grpc_keepalive_timeoutandperformance.grpc_keepalive_intervalnow exist to allow for configuration on how often these dead connections will be cleaned up. [GH-19339]v1.16.0Compare Source
1.16.0 (June 26, 2023)
BREAKING CHANGES:
/v1/health/connect/and/v1/health/ingress/endpoints now immediately return 403 "Permission Denied" errors whenever a token with insufficientservice:readpermissions is provided. Prior to this change, the endpoints returned a success code with an empty result list when a token with insufficient permissions was provided. [GH-17424]Upstream overrides in service-defaults will now only apply to peer upstreams when the
peerfield is provided.Visit the 1.16.x upgrade instructions for more information. [GH-16957]
SECURITY:
alpine:3.18. [GH-17719]v1/operator/audit-hashendpoint to ACL token withoperator:readprivileges.FEATURES:
POST /v1/operator/audit-hashendpoint to calculate the hash of the data used by the audit log hash function and salt.consul operator audit hashcommand to retrieve and compare the hash of the data used by the audit log hash function and salt.consul services export- for exporting a service to a peer or partition [GH-15654]AllowEnablingPermissiveMutualTLSsetting to the mesh config entry and theMutualTLSModesetting to proxy-defaults and service-defaults. [GH-17035]property-overridebuilt-in Envoy extension that directly patches Envoy resources. [GH-17487]IMPROVEMENTS:
-filteroption toconsul config listfor filtering config entries. [GH-17183]datacenter,ap(enterprise-only), andnamespace(enterprise-only). Both short-hand and long-hand forms of these query params are now supported via the HTTP API (dc/datacenter, ap/partition, ns/namespace). [GH-17525]BUG FIXES:
in the programmed gateway having no routes. [GH-17609]
Also fixes the Consul query metadata present in the HTTP headers of the namespace read and list endpoints.
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.