Skip to content

build(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.9 to 6.8.1 - #322

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/jedib0t/go-pretty/v6-6.8.1
Closed

build(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.9 to 6.8.1#322
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/jedib0t/go-pretty/v6-6.8.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 11, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/jedib0t/go-pretty/v6 from 6.7.9 to 6.8.1.

Release notes

Sourced from github.com/jedib0t/go-pretty/v6's releases.

v6.8.1

What's Changed

A hardening pass across the table, list, progress, and text packages, fixing security issues, crash/race bugs, and performance problems in the render hot paths, with benchmarks added to back the optimizations.

Security

  • table/list (HTML): escape the title, caption, and CSS class names in RenderHTML() to prevent HTML/attribute injection.
  • table (CSV): make RenderCSV() output RFC 4180 compliant, and add an opt-in Style().CSV.FieldProtection option that neutralizes spreadsheet formula-injection fields (=, +, -, @, tab, CR).
  • text: sanitize hyperlink URLs and bound the escape-sequence parser buffer so adversarial input can't grow it without limit.

Correctness

  • progress: fix a render panic on tiny tracker lengths, data races on tracker/indicator state, and a leaked time.Ticker in the terminal-size watcher.
  • table: guard auto-index rendering against empty maxColumnLengths.
  • text: prevent a panic in VAlign.Apply on negative maxLines.

Performance

  • table: compile regex filters once per render; pre-size render builders.
  • list: hoist repeated width math out of the render loops.
  • text: speed up Align.Apply and StringWidthWithoutEscSequences.
  • progress: build PacManChomp frames with a strings.Builder.

Tooling

  • Moved root-level benchmarks into their packages and wired up make bench; added benchmarks for the table/text/list/progress render hot paths and tests covering the retained-done-tracker render paths.

Full Changelog: jedib0t/go-pretty@v6.8.0...v6.8.1

v6.8.0

What's Changed

New Contributors

Full Changelog: jedib0t/go-pretty@v6.7.10...v6.8.0

v6.7.10

What's Changed

... (truncated)

Commits
  • 22c68f6 fix panics, races, and injection vectors; speed up render hot paths (#409)
  • 45fb00d text: wrap wide runes when wrapLen is odd in WrapHard (#408)
  • ad17549 progress: fix speed decay on done trackers and log overwrite; fixes #405 (#406)
  • 66563fd text: fix panic on align with unicode (#404)
  • See full diff in compare view


Note

Dependabot bump of github.com/jedib0t/go-pretty/v6 from 6.7.9 to 6.8.1, a semver-minor update that includes security hardening (HTML/CSV injection prevention), crash/race fixes, and performance improvements in the upstream library.

Written by Mendral for commit cac48ca.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Jun 11, 2026
mendral-app[bot]

This comment was marked as outdated.

Bumps [github.com/jedib0t/go-pretty/v6](https://github.com/jedib0t/go-pretty) from 6.7.9 to 6.8.1.
- [Release notes](https://github.com/jedib0t/go-pretty/releases)
- [Commits](jedib0t/go-pretty@v6.7.9...v6.8.1)

---
updated-dependencies:
- dependency-name: github.com/jedib0t/go-pretty/v6
  dependency-version: 6.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump github.com/jedib0t/go-pretty/v6 from 6.7.9 to 6.8.1 build(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.9 to 6.8.1 Jun 30, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/github.com/jedib0t/go-pretty/v6-6.8.1 branch from 84b1b29 to cac48ca Compare June 30, 2026 00:41
@mendral-app

mendral-app Bot commented Jun 30, 2026

Copy link
Copy Markdown
Contributor

🧪 Testing Guide

What this PR addresses

This is a dependency bump of github.com/jedib0t/go-pretty/v6 from v6.7.9 to v6.8.1. According to the release notes, v6.8.1 is a hardening pass across the table, list, progress, and text packages — fixing security issues, crash/race bugs, and performance problems in render hot paths.

Steps to verify

Since this is a dependency update with no application code changes, there are no reproduction steps for a specific bug. Instead, validate the following:

  1. Build succeeds: Confirm the project compiles cleanly (go build ./...).
  2. Tests pass: Run the full test suite (go test ./...) and ensure no regressions.
  3. Functionality check: If the project uses go-pretty for CLI table/list rendering, exercise those code paths (e.g., run any CLI commands that produce formatted output) and confirm output looks correct.

What to verify (expected behavior)

  • All CI checks pass (build, lint, tests).
  • No changes in CLI output formatting or table rendering behavior.
  • No new panics or race conditions in any paths that use go-pretty.

Note

Posted by PR Testing Guide · Tag @mendral-app with feedback.

@mendral-app mendral-app Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Previous bake-time concern is resolved — v6.8.1 has been available for ~19 days with no reported issues. The change is a straightforward dependency bump in go.mod/go.sum with no code modifications. The upstream release notes indicate security and correctness improvements, making this a beneficial update.

Tag @mendral-app with feedback or questions. View session

@dependabot @github

dependabot Bot commented on behalf of github Jul 2, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #338.

@dependabot dependabot Bot closed this Jul 2, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/github.com/jedib0t/go-pretty/v6-6.8.1 branch July 2, 2026 04:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants