Skip to content

chore(deps): bump github.com/twmb/franz-go/pkg/kadm from 1.18.0 to 1.19.0 - #159

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/develop/github.com/twmb/franz-go/pkg/kadm-1.19.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/develop/github.com/twmb/franz-go/pkg/kadm-1.19.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 22, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/twmb/franz-go/pkg/kadm from 1.18.0 to 1.19.0.

Changelog

Sourced from github.com/twmb/franz-go/pkg/kadm's changelog.

v1.19.0. The v1.19.0 release does not work for Kafka versions pre-4.0. This release fixes that (by fixing the bug that has existed since Kafka 2.4) and adds a GH action to test against Kafka 3.8 to help prevent regressions against older brokers as this library marches forward.

  • 50aa74f1 kgo bugfix: ApiVersions replies only with key 18, not all keys

v1.19.0

This is the largest release of franz-go yet. The last patch release was Jan 20, '25. The last minor release was Oct 14, '24.

A big reason for delays the past few month+ has been from spin looping tests and investigating any issue that popped up. Another big delay is that Kafka has a full company adding features -- some questionable -- and I'm one person that spent a significant amount of time catching this library up with the latest Kafka release. Lastly, Kafka released Kafka v3.9 three weeks after my last major release, and simultaneously, a few requests came in for new features in this library that required a lot of time. I wanted a bit of a break and only resumed development more seriously in late Feb. This release is likely >100hrs of work over the last ~4mo, from understanding new features and implementing them, reviewing PRs, and debugging rare test failures.

The next Kafka release is poised to implement more large features (share groups), which unfortunately will mean even more heads down time trying to bolt in yet another feature to an already large library. I hope that Confluent chills with introducing massive client-impacting changes; they've introduced more in the past year than has been introduced from 2019-2023.

Bug fixes / changes / deprecations

  • The BasicLogger will no longer panic if only a single key (no val) is used. Thanks @​vicluq!

  • An internal coding error around managing fetch concurrency was fixed. Thanks @​iimos!

  • Some off by ones with retries were fixed (tldr: we retried one fewer times than configured)

  • AllowAutoTopicCreation and ConsumeRegex can now be used together. Previously, topics would not be created if you were producing and consuming from the same client AND if you used the ConsumeRegex option.

  • A data race in the consumer code path has been fixed. The race is hard to encounter (which is why it never came up even in my weeks of spin-looping tests with -race). See [PR #984](twmb/franz-go#984) for more details.

  • EndBeginTxnUnsafe is deprecated and unused. EndAndBeginTransaction now flushes, and you cannot produce while the function happens (the function will just be stuck flushing). As of KIP-890, the behavior that the library relied on

... (truncated)

Commits
  • 64bf328 Merge pull request #1008 from twmb/changelog-1.19
  • e607c1c changelog notes for 1.19
  • 20d3dda Merge pull request #1007 from twmb/tiny
  • 9085ebd kgo: deflake test
  • 736e01a Merge pull request #1006 from twmb/1003
  • ede740f Merge pull request #999 from rockwotj/master
  • 95d9ad2 Merge pull request #1004 from AdrielVelazquez/patch-1
  • a5ce7c5 kgo: change OnBrokerConnect to encompass the whole connect initialization flow
  • 4b1bbff Merge pull request #1005 from twmb/986
  • b2620e2 kgo: make ErrFirstReadEOF not retryable
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/twmb/franz-go/pkg/kadm](https://github.com/twmb/franz-go) from 1.18.0 to 1.19.0.
- [Changelog](https://github.com/twmb/franz-go/blob/master/CHANGELOG.md)
- [Commits](twmb/franz-go@v1.18.0...v1.19.0)

---
updated-dependencies:
- dependency-name: github.com/twmb/franz-go/pkg/kadm
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the deps Go module dependencies (usually opened by Dependabot) label Sep 22, 2026
@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 844b1561-9944-4cb9-925e-03cbd88e285e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgithub.com/​twmb/​franz-go@​v1.21.6 ⏵ v1.22.096 +4100100100100
Updatedgithub.com/​twmb/​franz-go/​pkg/​kadm@​v1.18.0 ⏵ v1.19.0100 +1100100100100
Updatedgithub.com/​twmb/​franz-go/​pkg/​kmsg@​v1.13.1 ⏵ v1.14.0100 +1100100100100

View full report

@github-actions github-actions Bot added the size/XS PR changes < 50 lines label Sep 22, 2026
@lerian-studio

Copy link
Copy Markdown
Contributor

🔒 Security Scan Results — lib-streaming

✅ PR Mergeable — no blocking findings

Stage Status Blocking?
Filesystem Scan ✅ Clean —
Docker Image Scan ➖ Skipped —
Docker Hub Health Score ➖ Skipped —
Pre-release Version Check ✅ Clean —

Trivy

Filesystem Scan

✅ No vulnerabilities or secrets found.


Pre-release Version Check

✅ No unstable version pins found.


🔍 View full scan logs

@github-actions

github-actions Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

🔍 PR Validation Summary

🚫 PR Blocked — 2 blocking failures

Check Status Blocking
Source Branch ❌ failure yes
PR Title ✅ success yes
PR Description ✅ success yes
Breaking Change Guard ✅ success yes
Blocking Checks Runtime ❌ failure yes
Commit Signatures ✅ success yes
PR Size ⏭️ skipped no
Auto Labels ⏭️ skipped no
PR Metadata ⏭️ skipped no

Fix the blocking checks above before merge.


🔍 View workflow run

@lerian-studio

Copy link
Copy Markdown
Contributor

📊 Unit Test Coverage Report: app

Metric Value
Overall Coverage 86.8% ✅ PASS
Threshold 80%

Coverage by Package

Package Coverage
github.com/LerianStudio/lib-streaming/v4/billing 97.3%
github.com/LerianStudio/lib-streaming/v4/internal/cloudevents 93.7%
github.com/LerianStudio/lib-streaming/v4/internal/config 86.8%
github.com/LerianStudio/lib-streaming/v4/internal/consumer 92.3%
github.com/LerianStudio/lib-streaming/v4/internal/contract 85.0%
github.com/LerianStudio/lib-streaming/v4/internal/dlqheader 40.0%
github.com/LerianStudio/lib-streaming/v4/internal/emitter 100.0%
github.com/LerianStudio/lib-streaming/v4/internal/kafkasec 84.9%
github.com/LerianStudio/lib-streaming/v4/internal/manifest 84.0%
github.com/LerianStudio/lib-streaming/v4/internal/producer 89.1%
github.com/LerianStudio/lib-streaming/v4/internal/transport/eventbridge 87.3%
github.com/LerianStudio/lib-streaming/v4/internal/transport/kafka 56.4%
github.com/LerianStudio/lib-streaming/v4/internal/transport/rabbitmq 93.2%
github.com/LerianStudio/lib-streaming/v4/internal/transport/sqs 84.4%
github.com/LerianStudio/lib-streaming/v4/internal/transport 96.7%
github.com/LerianStudio/lib-streaming/v4/streamingtest 90.7%
github.com/LerianStudio/lib-streaming/v4 86.2%

Generated by Go PR Analysis workflow

Base automatically changed from develop to main September 23, 2026 11:38
@github-actions

Copy link
Copy Markdown

⚠️ Invalid Source Branch

Pull requests to main can only come from:

  • develop
  • release-candidate
  • hotfix/*

Your source branch: dependabot/go_modules/develop/github.com/twmb/franz-go/pkg/kadm-1.19.0

Please change the base branch or create a PR from an allowed branch.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

deps Go module dependencies (usually opened by Dependabot) size/XS PR changes < 50 lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant