Skip to content

Update module github.com/oapi-codegen/runtime to v1.7.0 - #14

Merged
andrewheberle merged 1 commit into
mainfrom
renovate/github.com-oapi-codegen-runtime-1.x
Sep 2, 2026
Merged

andrewheberle merged 1 commit into
mainfrom
renovate/github.com-oapi-codegen-runtime-1.x

Conversation

@renovate

@renovate renovate Bot commented Jul 9, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/oapi-codegen/runtime v1.6.0 → v1.7.0 age confidence

Release Notes

oapi-codegen/runtime (github.com/oapi-codegen/runtime)

v1.7.0: : Extensions for OpenAPI 3.1 parameter binding

Compare Source

This release teaches the parameter binders about OpenAPI 3.1 multi-type unions, and fixes a long-standing panic on the request binding path. As with v1.6.0, new behavior is controlled by explicit settings rather than assumptions: binding stays exactly as it was unless the new options are used.

Notable Changes

Binding OpenAPI 3.1 multi-type union parameters

OpenAPI 3.1 allows a parameter's type to be a list, such as type: [string, integer]. Go has no type meaning "one of these", so generated code maps such parameters to any — which the binders previously rejected outright with can not bind to destination of type: interface, making these parameters unusable.

The binder options structs (BindStyledParameterOptions, BindQueryParameterOptions, BindStringToObjectOptions) gain a Types []string field carrying the union's member list. It is only consulted when the destination is an any; binding into every concrete Go type is completely unchanged. The value binds to the first member that parses, trying boolean, integer, number, then string — most restrictive first, since a string always parses. Member detection follows the JSON number grammar (RFC 8259), so values like 007 or +1 bind as strings rather than being silently reinterpreted as numbers.

The bound value's dynamic type is always one of bool, int64, float64, string, or (with format: byte) []byte, so a handler's type switch is stable regardless of what the spec's format says. Applications that want format: int32 / format: float to narrow the produced types to int32 / float32 can opt in via a new package-level setting, following the same pattern as DefaultQueryEncoder from v1.6.0:

func init() {
    runtime.NarrowUnionNumericFormats = true
}

Generator support for emitting Types is landing in oapi-codegen separately; the runtime side ships first so generated code can rely on it. Arrays of unions and deepObject-style parameters are not covered yet — see the Types field documentation for the exact scope.

Fix for a panic when binding numeric values into slice destinations

Since v1.2.0, binding a string that happens to parse as an integer into a non-[]byte slice destination panicked with reflect: call of reflect.Value.OverflowInt on slice Value, instead of returning an error. This was reachable from generated code on the request path: a nullable.Nullable[[]string] query parameter using the default form/explode serialization would panic on ?p=123 while returning a normal binding error on ?p=abc. These cases now return a clean can not bind to destination of type: slice error.

🚀 New features and improvements

🐛 Bug fixes

✍ Other changes

📦 Dependency updates

6 changes

Sponsors

We would like to thank our sponsors for their support during this release.

DevZero logo

Cybozu logo

  • No new contributors

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@socket-security

socket-security Bot commented Jul 9, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgithub.com/​oapi-codegen/​runtime@​v1.6.0 ⏵ v1.7.097100100100100

View full report

@codecov

codecov Bot commented Jul 9, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 27.89%. Comparing base (ddbb015) to head (9be59e5).

Additional details and impacted files
@@           Coverage Diff           @@
##             main      #14   +/-   ##
=======================================
  Coverage   27.89%   27.89%           
=======================================
  Files          37       37           
  Lines        1717     1717           
=======================================
  Hits          479      479           
  Misses       1238     1238           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@renovate renovate Bot changed the title Update module github.com/oapi-codegen/runtime to v1.4.2 Update module github.com/oapi-codegen/runtime to v1.6.0 Jul 17, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-oapi-codegen-runtime-1.x branch from 0786117 to bde07e6 Compare July 17, 2026 19:54
@renovate
renovate Bot force-pushed the renovate/github.com-oapi-codegen-runtime-1.x branch from bde07e6 to 791d30d Compare August 13, 2026 07:13
@renovate renovate Bot changed the title Update module github.com/oapi-codegen/runtime to v1.6.0 Update module github.com/oapi-codegen/runtime to v1.6.0 - autoclosed Aug 13, 2026
@renovate renovate Bot closed this Aug 13, 2026
@renovate
renovate Bot deleted the renovate/github.com-oapi-codegen-runtime-1.x branch August 13, 2026 08:29
@renovate renovate Bot changed the title Update module github.com/oapi-codegen/runtime to v1.6.0 - autoclosed Update module github.com/oapi-codegen/runtime to v1.7.0 Aug 16, 2026
@renovate renovate Bot reopened this Aug 16, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-oapi-codegen-runtime-1.x branch 2 times, most recently from 791d30d to d2ccf1e Compare August 16, 2026 10:14
@renovate renovate Bot changed the title Update module github.com/oapi-codegen/runtime to v1.7.0 Update module github.com/oapi-codegen/runtime to v1.7.0 - autoclosed Sep 1, 2026
@renovate renovate Bot closed this Sep 1, 2026
@renovate renovate Bot changed the title Update module github.com/oapi-codegen/runtime to v1.7.0 - autoclosed Update module github.com/oapi-codegen/runtime to v1.7.0 Sep 2, 2026
@renovate renovate Bot reopened this Sep 2, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-oapi-codegen-runtime-1.x branch 2 times, most recently from d2ccf1e to 9be59e5 Compare September 2, 2026 00:21
@andrewheberle
andrewheberle merged commit e760728 into main Sep 2, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant