Repository navigation
Update module github.com/libp2p/go-libp2p to v0.50.0 - #660
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
requested review from
GalRogozinski and
MatheusFranco99
as code owners
October 4, 2026 08:22
Author
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.36.1→v0.50.0Release Notes
libp2p/go-libp2p (github.com/libp2p/go-libp2p)
v0.50.0Compare Source
What's Changed
New Contributors
Full Changelog: libp2p/go-libp2p@v0.49.0...v0.50.0
v0.49.0Compare Source
What's Changed
New Contributors
Full Changelog: libp2p/go-libp2p@v0.48.0...v0.49.0
v0.48.0Compare Source
A relatively minor update. Most changes were related to internal cleanup and getting the transport interop tests running again.
🔦 Highlights
0.0.0.0,BasicHost.AllAddrsreturns all the interface addrs of the machine. In v0.47 we'd unwittingly introduced this change, but on discussion decided to commit to it as returning all the addresses was correct. In the absence of this behaviour, there's no way for a user to get all the addrs the libp2p host is listening on. See #3460 for the discussion about this. #3468What's Changed
New Contributors
Full Changelog: libp2p/go-libp2p@v0.47.0...v0.48.0
v0.47.0Compare Source
A relatively small release. The main changes are dependency updates and a couple of bug fixes. #3435 changes autonatv2 reachability logic, which should be a net win for most users.
Breaking Changes
AllAddrs()Actually returns all interface addresses when listening on0.0.0.0. See #3460 for more context. This changes an earlier intentional decision from #911.What's Changed
stream.Close()blocks indefinitely on unresponsive peers by @lidel in #3448New Contributors
Full Changelog: libp2p/go-libp2p@v0.46.0...v0.47.0
v0.46.0Compare Source
What's Changed
Full Changelog: libp2p/go-libp2p@v0.45.0...v0.46.0
v0.45.0Compare Source
A small release that adjust some noisy logging levels and adds a method for dynamically change the slog Handler for better integration with applications that use go-log.
What's Changed
Full Changelog: libp2p/go-libp2p@v0.44.0...v0.45.0
v0.44.0Compare Source
Highlights
Address Pipeline:
github.com/libp2p/go-libp2p/p2p/host/obsaddrsDisableObservedAddrManagerOption. The top level libp2p optionDisableIdentifyAddressDiscoveryworks as it used to.What's Changed
New Contributors
Full Changelog: libp2p/go-libp2p@v0.43.0...v0.44.0
v0.43.0Compare Source
Highlights
This is a small release to allow users to upgrade to the latest quic-go version as the quic-go API was changed heavily in quic-go v0.53
What's Changed
Full Changelog: libp2p/go-libp2p@v0.42.0...v0.43.0
v0.42.1Compare Source
What's Changed
stream.goby @Prabhat1308 in #3237modernc.org/sqlitedirectly by @levisyin in #3227purgeStore()by @vipocenka in #3273New Contributors
Full Changelog: libp2p/go-libp2p@v0.41.0...v0.42.1
v0.42.0Compare Source
⚠ Breaking Changes
Added a new method,
VerifySourceAddress(net.Addr) bool, to the Resource Manager interface.For more details see the Source Address Verification section.
For custom implementation which want to opt out of Source Address Verification and keep the existing behavior, return
falsefrom the method.🔦 Highlights
Per Address Reachability via AutoNAT v2
libp2p hosts can now determine reachability for individual addresses using AutoNATV2. To opt in to reachability checking use the
EnableAutoNATV2libp2p option. Using this nodes can now determine their IPv4, IPv6, and browser address reachability separately. In a future release, AutoRelay will use this information and make appropriate relay reservations accordingly. https://pkg.go.dev/github.com/libp2p/go-libp2p#EnableAutoNATv2To query addresses by their reachability,
ConfirmedAddrs() (reachable, unreachable, unknown []ma.Multiaddr)that provides Reachability information per host address. https://pkg.go.dev/github.com/libp2p/go-libp2p/p2p/host/basic#BasicHost.ConfirmedAddrsFor notifications, Subscribe to the event
event.EvtHostReachableAddrsChangedhttps://pkg.go.dev/github.com/libp2p/go-libp2p/core/event#EvtHostReachableAddrsChangedRate Limiting
We've introduced the package
github.com/libp2p/go-libp2p/x/ratefor rate limiting. The structrate.Limiterprovides Global, Network Specific, and Subnet Specific rate limiting. The Subnet specific rate limits allows for better DoS Protection by rate limiting malicious IPs. https://pkg.go.dev/github.com/libp2p/go-libp2p/x/rateUse
Limit(f func(s network.Stream)) func(s network.Stream)onLimiterto limit specific stream handlers. For example, within libp2p, the Identify Service uses this asids.Host.SetStreamHandler(IDPush, ids.rateLimiter.Limit(ids.handlePush))to rate limit the number of times peers can perform identify push.For non Stream use cases use the
Allow(ip)method on the limiter.Connection Rate Limiting
New connection requests are now rate limited per IP. By default we allow 1 connection every 5 seconds from an IP address with a burst of 16 connections per IP. The burst is high enough that this should only block malicious peers.
To configure the connection rate limits, use the
WithConnRateLimitersoption on the Resource Manager. https://pkg.go.dev/github.com/libp2p/go-libp2p/p2p/host/resource-manager#WithConnRateLimitersSource Address Verification for QUIC
This release introduces Source Address Verification for QUIC, preventing DoS attacks by spoofing IP addresses. See: https://www.rfc-editor.org/rfc/rfc9000.html#section-8 for details.
We are now gating incoming QUIC connections before the handshake is started. This further improves DoS protection by not wasting CPU on handshaking QUIC connections which would have been dropped by the Resource Manager.
Other changes
What's Changed
stream.goby @Prabhat1308 in #3237modernc.org/sqlitedirectly by @levisyin in #3227purgeStore()by @vipocenka in #3273New Contributors
Full Changelog: libp2p/go-libp2p@v0.41.0...v0.42.0
v0.41.1Compare Source
What's Changed
7059eb5conngater: fix incorrect err return value (#3219)74c6860fix(libp2phttp): bound NewStream timeout (#3225)ccc4849webrtc: fix memory leak with udpmux.muxedConnection context (#3243)99a511fconnmgr: fix transport association bug (#3221)eb3ff9fautonatv2: fix server dial data request policy (#3247)8ce45dfRelease v0.41.1Full Changelog: libp2p/go-libp2p@v0.41.0...v0.41.1
v0.41.0Compare Source
⚠︎ Breaking Changes
🔦 Highlights
Overall this is a fairly minor release focused on supporting the go-multiaddr v0.15.0.
What's Changed
Full Changelog: libp2p/go-libp2p@v0.40.0...v0.41.0
v0.40.0Compare Source
⚠ Breaking Change!
Introducing error codes mandated changing the error types returned by stream resets. All checks that depended on checking the error string or comparing equality with
network.ErrReset, now need to useerrors.Is(err, network.ErrReset). More details below in the error codes section.🔦 Highlights
Error Codes
This releases introduces error codes for Stream Reset and Connection Close. This allows sending for more information to the peer about the error condition causing the abort. go-libp2p has already defined some error codes which are useful for many different use cases. You can find them in:
https://pkg.go.dev/github.com/libp2p/go-libp2p@v0.40.0/core/network#StreamErrorCode
and: https://pkg.go.dev/github.com/libp2p/go-libp2p@v0.40.0/core/network#ConnErrorCode
On streams, you can signal an error on reset by using:
On connections, you can signal an error on close by using:
Not all transports support error codes. Most notably, WebTransport has no support for sending error codes at the moment. See the spec: libp2p/specs#623 for more details.
If you want to define custom error codes for your application protocol, you can reserve a block for your application by opening a PR in the specs repo. The above mentioned spec has details on reserving error codes for applications. Until the spec is merged, you must open a PR targeting the spec's branch.
Breaking Change!
This introduces a breaking change for users who checked stream reset errors by testing for equality with
network.ErrResetaserr == network.ErrReset. These tests now need to use theerrors.Is(err, network.ErrReset)test. Stream Resets now return either*network.StreamErrorif the stream was reset by remote, or*network.ConnErrorif the connection was closed by remote.What's Changed
New Contributors
Full Changelog: libp2p/go-libp2p@v0.39.0...v0.40.0
v0.39.1Compare Source
What's Changed
extAddrby @wlynxg in #3140New Contributors
Full Changelog: libp2p/go-libp2p@v0.38.1...v0.39.1
v0.39.0Compare Source
🔦 Highlights
This is a small release. The main thing is updating quic-go to v0.49.0 and enabling specific environment
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.