Skip to content

Update module github.com/libp2p/go-libp2p to v0.50.0 - #660

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github.com-libp2p-go-libp2p-0.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github.com-libp2p-go-libp2p-0.x

Conversation

@renovate

@renovate renovate Bot commented Oct 4, 2026

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
github.com/libp2p/go-libp2p v0.36.1 → v0.50.0 age confidence

Release Notes

libp2p/go-libp2p (github.com/libp2p/go-libp2p)

v0.50.0

Compare Source

What's Changed

New Contributors

Full Changelog: libp2p/go-libp2p@v0.49.0...v0.50.0

v0.49.0

Compare Source

What's Changed

New Contributors

Full Changelog: libp2p/go-libp2p@v0.48.0...v0.49.0

v0.48.0

Compare Source

A relatively minor update. Most changes were related to internal cleanup and getting the transport interop tests running again.

🔦 Highlights

  • When listening on 0.0.0.0, BasicHost.AllAddrs returns all the interface addrs of the machine. In v0.47 we'd unwittingly introduced this change, but on discussion decided to commit to it as returning all the addresses was correct. In the absence of this behaviour, there's no way for a user to get all the addrs the libp2p host is listening on. See #​3460 for the discussion about this. #​3468
  • Fix Deterministic WebTransport Key Generation for Go 1.26 #​3320
  • Fix mocknet: make stream deadline methods noop instead of returning error

What's Changed

New Contributors

Full Changelog: libp2p/go-libp2p@v0.47.0...v0.48.0

v0.47.0

Compare Source

A relatively small release. The main changes are dependency updates and a couple of bug fixes. #​3435 changes autonatv2 reachability logic, which should be a net win for most users.

Breaking Changes

  • A WebTransport Client in this version cannot dial older (pre v0.47.0) go-libp2p WebTransport servers. The reverse works. This is partly due to a handshake change in the latest draft RFC for WebTransport. WebTransport remains experimental while the RFC is in draft, but we expect no more breaking changes.
  • AllAddrs() Actually returns all interface addresses when listening on 0.0.0.0. See #​3460 for more context. This changes an earlier intentional decision from #​911.

What's Changed

New Contributors

Full Changelog: libp2p/go-libp2p@v0.46.0...v0.47.0

v0.46.0

Compare Source

What's Changed

Full Changelog: libp2p/go-libp2p@v0.45.0...v0.46.0

v0.45.0

Compare Source

A small release that adjust some noisy logging levels and adds a method for dynamically change the slog Handler for better integration with applications that use go-log.

What's Changed

Full Changelog: libp2p/go-libp2p@v0.44.0...v0.45.0

v0.44.0

Compare Source

Highlights

Address Pipeline:
  • Observed Address Manager has been moved out of identify to its own package, github.com/libp2p/go-libp2p/p2p/host/obsaddrs
  • ⚠️ Identify Service doesn't support the DisableObservedAddrManager Option. The top level libp2p option DisableIdentifyAddressDiscovery works as it used to.

What's Changed

New Contributors

Full Changelog: libp2p/go-libp2p@v0.43.0...v0.44.0

v0.43.0

Compare Source

Highlights

This is a small release to allow users to upgrade to the latest quic-go version as the quic-go API was changed heavily in quic-go v0.53

What's Changed

Full Changelog: libp2p/go-libp2p@v0.42.0...v0.43.0

v0.42.1

Compare Source

What's Changed

New Contributors

Full Changelog: libp2p/go-libp2p@v0.41.0...v0.42.1

v0.42.0

Compare Source

⚠ Breaking Changes

Added a new method, VerifySourceAddress(net.Addr) bool, to the Resource Manager interface.
For more details see the Source Address Verification section.

For custom implementation which want to opt out of Source Address Verification and keep the existing behavior, return false from the method.

🔦 Highlights

Per Address Reachability via AutoNAT v2

libp2p hosts can now determine reachability for individual addresses using AutoNATV2. To opt in to reachability checking use the EnableAutoNATV2 libp2p option. Using this nodes can now determine their IPv4, IPv6, and browser address reachability separately. In a future release, AutoRelay will use this information and make appropriate relay reservations accordingly. https://pkg.go.dev/github.com/libp2p/go-libp2p#EnableAutoNATv2

To query addresses by their reachability, ConfirmedAddrs() (reachable, unreachable, unknown []ma.Multiaddr) that provides Reachability information per host address. https://pkg.go.dev/github.com/libp2p/go-libp2p/p2p/host/basic#BasicHost.ConfirmedAddrs
For notifications, Subscribe to the event event.EvtHostReachableAddrsChanged https://pkg.go.dev/github.com/libp2p/go-libp2p/core/event#EvtHostReachableAddrsChanged

Rate Limiting

We've introduced the package github.com/libp2p/go-libp2p/x/rate for rate limiting. The struct rate.Limiter provides Global, Network Specific, and Subnet Specific rate limiting. The Subnet specific rate limits allows for better DoS Protection by rate limiting malicious IPs. https://pkg.go.dev/github.com/libp2p/go-libp2p/x/rate

Use Limit(f func(s network.Stream)) func(s network.Stream) on Limiter to limit specific stream handlers. For example, within libp2p, the Identify Service uses this as
ids.Host.SetStreamHandler(IDPush, ids.rateLimiter.Limit(ids.handlePush)) to rate limit the number of times peers can perform identify push.

For non Stream use cases use the Allow(ip) method on the limiter.

Connection Rate Limiting

New connection requests are now rate limited per IP. By default we allow 1 connection every 5 seconds from an IP address with a burst of 16 connections per IP. The burst is high enough that this should only block malicious peers.

To configure the connection rate limits, use the WithConnRateLimiters option on the Resource Manager. https://pkg.go.dev/github.com/libp2p/go-libp2p/p2p/host/resource-manager#WithConnRateLimiters

Source Address Verification for QUIC

This release introduces Source Address Verification for QUIC, preventing DoS attacks by spoofing IP addresses. See: https://www.rfc-editor.org/rfc/rfc9000.html#section-8 for details.

We are now gating incoming QUIC connections before the handshake is started. This further improves DoS protection by not wasting CPU on handshaking QUIC connections which would have been dropped by the Resource Manager.

Other changes
  • WebRTC Direct peers can now send messages of up to 256 kB (see spec: libp2p/specs#628)
  • Refactored the addressing code within BasicHost and moved it into Address Manager. In a future release, this will be exposed to users with an improved Address API for the libp2p Host.

What's Changed

New Contributors

Full Changelog: libp2p/go-libp2p@v0.41.0...v0.42.0

v0.41.1

Compare Source

What's Changed

7059eb5 conngater: fix incorrect err return value (#​3219)
74c6860 fix(libp2phttp): bound NewStream timeout (#​3225)
ccc4849 webrtc: fix memory leak with udpmux.muxedConnection context (#​3243)
99a511f connmgr: fix transport association bug (#​3221)
eb3ff9f autonatv2: fix server dial data request policy (#​3247)
8ce45df Release v0.41.1

Full Changelog: libp2p/go-libp2p@v0.41.0...v0.41.1

v0.41.0

Compare Source

⚠︎ Breaking Changes

🔦 Highlights

Overall this is a fairly minor release focused on supporting the go-multiaddr v0.15.0.

  • Update to go-multiaddr v0.15. This is a pretty big release for go-multiaddr that should make it harder to misuse. See the v0.15.0 release notes for breaking changes: https://github.com/multiformats/go-multiaddr/releases/tag/v0.15.0
  • Uniform HTTP Peer ID Auth over native HTTP transport and HTTP over libp2p streams. See the http.Host Autthenticated HTTP example in the Go doc for an example of usage.
  • Some upnp fixes that should make upnp/nat-pmp more reliable and easier to debug. This fixes an issue with FRITZ!Box routers.

What's Changed

Full Changelog: libp2p/go-libp2p@v0.40.0...v0.41.0

v0.40.0

Compare Source

⚠ Breaking Change!

Introducing error codes mandated changing the error types returned by stream resets. All checks that depended on checking the error string or comparing equality with network.ErrReset, now need to use errors.Is(err, network.ErrReset). More details below in the error codes section.

🔦 Highlights

Error Codes

This releases introduces error codes for Stream Reset and Connection Close. This allows sending for more information to the peer about the error condition causing the abort. go-libp2p has already defined some error codes which are useful for many different use cases. You can find them in:
https://pkg.go.dev/github.com/libp2p/go-libp2p@v0.40.0/core/network#StreamErrorCode
and: https://pkg.go.dev/github.com/libp2p/go-libp2p@v0.40.0/core/network#ConnErrorCode

On streams, you can signal an error on reset by using:

str.ResetWithError(errCode)

On connections, you can signal an error on close by using:

conn.ResetWithError(errCode)

Not all transports support error codes. Most notably, WebTransport has no support for sending error codes at the moment. See the spec: libp2p/specs#623 for more details.

If you want to define custom error codes for your application protocol, you can reserve a block for your application by opening a PR in the specs repo. The above mentioned spec has details on reserving error codes for applications. Until the spec is merged, you must open a PR targeting the spec's branch.

Breaking Change!

This introduces a breaking change for users who checked stream reset errors by testing for equality with network.ErrReset as err == network.ErrReset. These tests now need to use the errors.Is(err, network.ErrReset) test. Stream Resets now return either *network.StreamError if the stream was reset by remote, or *network.ConnError if the connection was closed by remote.

What's Changed

New Contributors

Full Changelog: libp2p/go-libp2p@v0.39.0...v0.40.0

v0.39.1

Compare Source

What's Changed

New Contributors

Full Changelog: libp2p/go-libp2p@v0.38.1...v0.39.1

v0.39.0

Compare Source

🔦 Highlights

This is a small release. The main thing is updating quic-go to v0.49.0 and enabling specific environment

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate

renovate Bot commented Oct 4, 2026

Copy link
Copy Markdown
Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 17 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.22 -> 1.26.0
github.com/google/go-cmp v0.6.0 -> v0.7.0
github.com/stretchr/testify v1.9.0 -> v1.12.1
golang.org/x/exp v0.0.0-20240719175910-8a7402abbf56 -> v0.0.0-20260718201538-764159d718ef
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.3.0 -> v4.4.1
github.com/ipfs/go-cid v0.4.1 -> v0.6.2
github.com/klauspost/cpuid/v2 v2.2.9 -> v2.4.0
github.com/mr-tron/base58 v1.2.0 -> v1.3.0
github.com/multiformats/go-multiaddr v0.13.0 -> v0.16.1
github.com/multiformats/go-multibase v0.2.0 -> v0.3.0
github.com/multiformats/go-multicodec v0.9.0 -> v0.10.0
github.com/multiformats/go-multistream v0.5.0 -> v0.6.1
github.com/multiformats/go-varint v0.0.7 -> v0.1.0
go.uber.org/zap v1.27.0 -> v1.28.0
golang.org/x/crypto v0.33.0 -> v0.54.0
golang.org/x/sys v0.30.0 -> v0.47.0
google.golang.org/protobuf v1.34.2 -> v1.36.11
lukechampine.com/blake3 v1.3.0 -> v1.4.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants