Skip to content

chore(deps): bump github.com/ipfs/boxo from 0.42.2 to 0.43.0 - #62

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/go_modules/github.com/ipfs/boxo-0.43.0
Sep 18, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/go_modules/github.com/ipfs/boxo-0.43.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/ipfs/boxo from 0.42.2 to 0.43.0.

Release notes

Sourced from github.com/ipfs/boxo's releases.

v0.43.0

[!NOTE] This release was brought to you by the Shipyard team.

[!IMPORTANT] Shipyard's IPFS work ends on September 30, 2026. Until then we ship security and bug fix releases if any are absolutely needed and still possible. After that date, no one at Shipyard maintains Boxo. If you depend on Boxo, read the announcement and bring your transition questions to the community forum.

What's Changed

[!IMPORTANT] This is a bug fix release. It carries a minor version bump because the gateway no longer sends the deprecated X-Ipfs-Path header by default, replaced by Ipfs-Uri (IPIP-548). If you still need X-Ipfs-Path, set Config.DeprecatedXIpfsPath and call Headers.WithDeprecatedXIpfsPath before Headers.ApplyCors, and plan a migration to Ipfs-Uri.

Added

  • ✨ ipld/unixfs: reads of both PBNode field orders are now covered by tests, and a documented low-level opt-in (UnixFSProfile.PBNodeFieldOrder, applied via merkledag.DefaultPBNodeFieldOrder) lets writers that need streaming-friendly blocks encode the Data field before Links per IPIP-550. Off by default and selected by no named profile: UnixFS_v0_2015 and UnixFS_v1_2025 pin the canonical links-first order explicitly, so defaults and existing CIDs are unchanged. Enabling data-first changes the CID of every dag-pb node that has both fields (directories, HAMT shards, multi-chunk file roots), is process-wide (ApplyGlobals affects every merkledag.ProtoNode encoded in the process, not only UnixFS nodes), and re-encodes links-first directories in the new order the next time they are opened through the directory API and stored again (for example MFS directories on their next access). #1212
  • ✨ gateway: responses now include the Ipfs-Uri header with a canonical ipfs:// or ipns:// URI for the requested content path, and expose it via the default Access-Control-Expose-Headers. The header carries the content root in canonical form (base32 CIDv1 for /ipfs/, base36 CIDv1 for cryptographic /ipns/ names, lowercase FQDN for DNSLink) with percent-encoded path segments, so clients get a value that is safe in HTTP field context regardless of bytes in the underlying path. IPIP-548 #1209

Changed

  • 🛠 gateway: the deprecated X-Ipfs-Path response header is no longer sent by default; its value cannot represent all UnixFS file names and it is superseded by Ipfs-Uri. Action required: consumers that read X-Ipfs-Path should migrate to Ipfs-Uri; to restore the legacy header meanwhile, set Config.DeprecatedXIpfsPath and call Headers.WithDeprecatedXIpfsPath before Headers.ApplyCors so it is listed in Access-Control-Expose-Headers again. Even with the flag set, the header is omitted for content paths with bytes that cannot appear in an HTTP field value (Section 5.5 of RFC 9110), such as raw non-ASCII UnixFS file names: gateway-conformance fails a gateway that sends such values, and only Ipfs-Uri carries those paths. IPIP-548 #1209
  • gateway: conformance CI runs gateway-conformance v0.14.0, the first release with the IPIP-548 Ipfs-Uri tests. #1209
  • updated Go in go.mod to 1.26.0
  • upgrade to go-libp2p-kad-dht v0.42.2
  • upgrade to go.opentelemetry.io v1.46.0

Fixed

  • gateway: X-Ipfs-Path values no longer carry bytes that are invalid in an HTTP field value (Section 5.5 of RFC 9110). The header used to echo raw UnixFS file names, so non-ASCII paths arrived garbled or broke strict clients; when the header is enabled, it is now omitted for such paths, which only the percent-encoded Ipfs-Uri can carry. #1209
  • bootstrap: the saved backup peer list is no longer dialed when no bootstrap peers are configured. #1213
Changelog

Sourced from github.com/ipfs/boxo's changelog.

[v0.43.0]

[!IMPORTANT] This is a bug fix release. It carries a minor version bump because the gateway no longer sends the deprecated X-Ipfs-Path header by default, replaced by Ipfs-Uri (IPIP-548). If you still need X-Ipfs-Path, set Config.DeprecatedXIpfsPath and call Headers.WithDeprecatedXIpfsPath before Headers.ApplyCors, and plan a migration to Ipfs-Uri.

Shipyard's IPFS work ends on September 30, 2026. Until then we ship security and bug fix releases if any are absolutely needed and still possible. After that date, no one at Shipyard maintains Boxo. If you depend on Boxo, read the announcement and bring your transition questions to the community forum.

Added

  • ✨ ipld/unixfs: reads of both PBNode field orders are now covered by tests, and a documented low-level opt-in (UnixFSProfile.PBNodeFieldOrder, applied via merkledag.DefaultPBNodeFieldOrder) lets writers that need streaming-friendly blocks encode the Data field before Links per IPIP-550. Off by default and selected by no named profile: UnixFS_v0_2015 and UnixFS_v1_2025 pin the canonical links-first order explicitly, so defaults and existing CIDs are unchanged. Enabling data-first changes the CID of every dag-pb node that has both fields (directories, HAMT shards, multi-chunk file roots), is process-wide (ApplyGlobals affects every merkledag.ProtoNode encoded in the process, not only UnixFS nodes), and re-encodes links-first directories in the new order the next time they are opened through the directory API and stored again (for example MFS directories on their next access). #1212
  • ✨ gateway: responses now include the Ipfs-Uri header with a canonical ipfs:// or ipns:// URI for the requested content path, and expose it via the default Access-Control-Expose-Headers. The header carries the content root in canonical form (base32 CIDv1 for /ipfs/, base36 CIDv1 for cryptographic /ipns/ names, lowercase FQDN for DNSLink) with percent-encoded path segments, so clients get a value that is safe in HTTP field context regardless of bytes in the underlying path. IPIP-548 #1209

Changed

  • 🛠 gateway: the deprecated X-Ipfs-Path response header is no longer sent by default; its value cannot represent all UnixFS file names and it is superseded by Ipfs-Uri. Action required: consumers that read X-Ipfs-Path should migrate to Ipfs-Uri; to restore the legacy header meanwhile, set Config.DeprecatedXIpfsPath and call Headers.WithDeprecatedXIpfsPath before Headers.ApplyCors so it is listed in Access-Control-Expose-Headers again. Even with the flag set, the header is omitted for content paths with bytes that cannot appear in an HTTP field value (Section 5.5 of RFC 9110), such as raw non-ASCII UnixFS file names: gateway-conformance fails a gateway that sends such values, and only Ipfs-Uri carries those paths. IPIP-548 #1209
  • gateway: conformance CI runs gateway-conformance v0.14.0, the first release with the IPIP-548 Ipfs-Uri tests. #1209
  • updated Go in go.mod to 1.26.0
  • upgrade to go-libp2p-kad-dht v0.42.2
  • upgrade to go.opentelemetry.io v1.46.0

Fixed

  • gateway: X-Ipfs-Path values no longer carry bytes that are invalid in an HTTP field value (Section 5.5 of RFC 9110). The header used to echo raw UnixFS file names, so non-ASCII paths arrived garbled or broke strict clients; when the header is enabled, it is now omitted for such paths, which only the percent-encoded Ipfs-Uri can carry. #1209
  • bootstrap: the saved backup peer list is no longer dialed when no bootstrap peers are configured. #1213
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/ipfs/boxo](https://github.com/ipfs/boxo) from 0.42.2 to 0.43.0.
- [Release notes](https://github.com/ipfs/boxo/releases)
- [Changelog](https://github.com/ipfs/boxo/blob/main/CHANGELOG.md)
- [Commits](ipfs/boxo@v0.42.2...v0.43.0)

---
updated-dependencies:
- dependency-name: github.com/ipfs/boxo
  dependency-version: 0.43.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 18, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 18, 2026
@github-actions
github-actions Bot merged commit 1c132da into main Sep 18, 2026
8 checks passed
@dependabot
dependabot Bot deleted the dependabot/go_modules/github.com/ipfs/boxo-0.43.0 branch September 18, 2026 09:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants