Skip to content

build(deps): bump github.com/pb33f/libopenapi from 0.38.7 to 0.41.3 in /codegen - #125

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/codegen/github.com/pb33f/libopenapi-0.41.3
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/codegen/github.com/pb33f/libopenapi-0.41.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/pb33f/libopenapi from 0.38.7 to 0.41.3.

Release notes

Sourced from github.com/pb33f/libopenapi's releases.

v0.41.3

This release improves handling of malformed documents, schema comparisons, reference bundling, and reproducible mock generation.

  • Parsing: Build valid sibling operations even when another operation fails, collect build errors, and avoid duplicate custom-operation builds.
  • Schema comparison: Avoid false breaking-change reports when object schemas move into equivalent or broader anyOf/oneOf structures.
  • Bundling: Correctly rewrite references inside vendor extensions, including pointers into nested schema properties.
  • Mocks: Respect configured seeds for pattern-generated strings and produce stable XML element ordering.
  • Tests: Add regression coverage for these fixes.

@​tx3stn @​matoous

v0.41.2

Update hashing performance. No fixes or features, just faster and more performant.

v0.41.1

Stop duplicating files referenced from arrays

@​mcstepp

v0.41.0

Harder, Better, Faster, Stronger

  • Rendering Stripe: 77% faster
  • Rendering DocuSign (JSON): 87% faster
  • Inline-rendering every Stripe schema: 80% faster
  • Building JSON specs: 54% to 69% faster
  • Across the whole pipeline: 58% less time, 57% less memory, 61% fewer allocations

We forked the YAML library

First thing the fork fixed: the emitter kept every single event it ever wrote, for the entire document. Rendering Stripe now allocates 76% less memory, and bundling it 71% less.

Bonus: folded block scalars (>) no longer grow a blank line when rendered. Rendered output finally matches its source.

This one breaks things. Swap go.yaml.in/yaml/v4 for github.com/pb33f/go-yaml in your imports. The package is still called yaml, so it's a find and replace. If you pass *yaml.Node values in or out of libopenapi you have to do it, because the two node types are different types. jsonpath v0.8.4, ordered-map v2.3.2 and testify v0.1.1 have all made the same move.

Two small breaks in the low-level API

  • NodeMap.Nodes is now a *low.NodeLines instead of a *sync.Map. Range, Load and Store take int line numbers, and Range visits lines in order. Most models get built and never read, so the line index only gets built when you ask for it.
  • NodeReference.Context is gone. libopenapi only ever set it on a PathItem's operations. Use pathItem.Get.Value.GetContext() instead.

Bugs, squashed

  • Global caches kept dropped documents alive, and could hand a new object a stale hash when a memory address got reused. Both fixed. A document you drop now gets reclaimed without calling ClearAllCaches. (#614, #615)
  • A BaseURL without a scheme could crash the whole process during remote lookups. Not anymore. (#578)
  • The composed bundler panicked, or left a mangled mapping behind, when a $ref pointed at a sequence or scalar (like root tags). Fixed. (#607, #608)
  • what-changed was writing map keys into shared YAML nodes. That was a data race, and it put wrong (and random) keys in reports. Fixed. (#620)
  • Swagger 2 headers now map Format, ExclusiveMinimum and UniqueItems correctly. (#630)
  • Rendering a document no longer quietly rewrites the tags on your model's enum nodes.

... (truncated)

Commits
  • 1704e72 chore: optimize composed ref lookup
  • 982b5d9 chore: increase test coverage
  • 2a91ad9 chore: address code review comment
  • 9777cd2 fix: rewrite composed refs inside extensions
  • 425ae63 fix: keep mock generation deterministic
  • 12dd58c Merge pull request #606: preserve valid operations after build errors
  • 7e05653 fix: verify operation recovery and avoid duplicate custom builds
  • 3d41584 Merge main into panic_fix and retain operation error collection
  • bcdf6bc fix(what-changed): compare object composition refactors safely (#650)
  • f7414c2 deps
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/pb33f/libopenapi](https://github.com/pb33f/libopenapi) from 0.38.7 to 0.41.3.
- [Release notes](https://github.com/pb33f/libopenapi/releases)
- [Commits](pb33f/libopenapi@v0.38.7...v0.41.3)

---
updated-dependencies:
- dependency-name: github.com/pb33f/libopenapi
  dependency-version: 0.41.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants