Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 23, 2025

Bumps github.com/opentdf/platform/sdk from 0.7.0 to 0.10.0.

Release notes

Sourced from github.com/opentdf/platform/sdk's releases.

protocol/go: v0.10.0

0.10.0 (2025-09-16)

Features

  • policy: add protovalidate for obligation defs + vals (#2699) (af5c049)

service: v0.10.0

0.10.0 (2025-09-17)

⚠ BREAKING CHANGES

  • policy: Add manager column to provider configuration for multi-instance support (#2601)

Features

  • authz: add obligation policy decision point (#2706) (bb2a4f8)
  • core: add service negation for op mode (#2680) (029db8c)
  • core: Bump default write timeout. (#2671) (6a233c1)
  • core: Encapsulate>Encrypt (#2676) (3c5a614)
  • core: Lets key manager factory take context (#2715) (8d70993)
  • policy: add FQN of obligation definitions/values to protos (#2703) (45ded0e)
  • policy: Add manager column to provider configuration for multi-instance support (#2601) (a5fc994)
  • policy: Add obligation triggers (#2675) (22d0837)
  • policy: add protovalidate for obligation defs + vals (#2699) (af5c049)
  • policy: Allow creation and update of triggers on Obligation Values (#2691) (b1e7ba1)
  • policy: Allow for additional context to be added to obligation triggers (#2705) (7025599)
  • policy: Include Triggers in GET/LISTable reqs (#2704) (b4381d1)
  • policy: obligations + values CRUD (#2545) (c194e35)
  • use public AES protected key from lib/ocrypto (#2600) (75d7590)

Bug Fixes

  • core: remove extraneous comment (#2741) (ada8da6)
  • core: return services in the order they were registered (#2733) (1d661db)
  • deps: bump github.com/opentdf/platform/lib/ocrypto from 0.3.0 to 0.6.0 in /service (#2714) (00354b3)
  • deps: bump github.com/opentdf/platform/protocol/go from 0.7.0 to 0.9.0 in /service (#2726) (9004368)
  • deps: bump protocol/go to 0.10.0 in service (#2734) (11e6201)
  • deps: update protovalidate to v0.14.2 to use new buf validate MessageOneofRule (#2698) (1cae18e)
  • policy: Registered Resources should consider actions correctly within Decision Requests (#2681) (cf264a2)
  • sanitize db schema identifiers (#2682) (0d3dd94)

sdk: v0.10.0

0.10.0 (2025-10-21)

Features

... (truncated)

Commits
  • ebdc8bf chore(main): release sdk 0.10.0 (#2801)
  • 14191e4 feat(sdk): Call init if obligations are empty. (#2825)
  • 907f672 chore(ci): fix xtest job permissions (#2828)
  • 3cccfd2 feat(sdk): Add obligations support. (#2759)
  • 206abe3 feat(policy): List obligation triggers rpc (#2823)
  • 72fa722 chore(ci): bump github/codeql-action from 3.28.19 to 4.30.9 (#2821)
  • 23cf0f1 chore(ci): bump actions/checkout from 4.2.2 to 5.0.0 (#2774)
  • beaff21 feat(policy): namespace root certificates (#2771)
  • 205812e feat(sdk): ADR documenting SDK Obligations method coupling with decrypt (#2822)
  • cedca5b chore(ci): Correct manually entered wrong version (#2818)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Oct 23, 2025
@dependabot dependabot bot requested review from a team as code owners October 23, 2025 17:08
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Oct 23, 2025
@github-actions
Copy link
Contributor

Benchmark results, click to expand

Benchmark authorization.GetDecisions Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 165.771965ms

Benchmark authorization.v2.GetMultiResourceDecision Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 102.100939ms

Standard Benchmark Metrics Skipped or Failed

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 360.075146ms
Throughput 277.72 requests/second

TDF3 Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 38.868789448s
Average Latency 387.335663ms
Throughput 128.64 requests/second

NANOTDF Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 27.005601047s
Average Latency 269.283013ms
Throughput 185.15 requests/second

@github-actions
Copy link
Contributor

Bumps [github.com/opentdf/platform/sdk](https://github.com/opentdf/platform) from 0.7.0 to 0.10.0.
- [Release notes](https://github.com/opentdf/platform/releases)
- [Commits](sdk/v0.7.0...sdk/v0.10.0)

---
updated-dependencies:
- dependency-name: github.com/opentdf/platform/sdk
  dependency-version: 0.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/examples/github.com/opentdf/platform/sdk-0.10.0 branch from e651a6b to cd985db Compare October 30, 2025 00:23
@github-actions
Copy link
Contributor

Benchmark results, click to expand

Benchmark authorization.GetDecisions Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 186.497388ms

Benchmark authorization.v2.GetMultiResourceDecision Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 105.59477ms

Standard Benchmark Metrics Skipped or Failed

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 366.825105ms
Throughput 272.61 requests/second

TDF3 Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 40.575197255s
Average Latency 404.183509ms
Throughput 123.23 requests/second

NANOTDF Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 28.111131026s
Average Latency 280.110051ms
Throughput 177.87 requests/second

@github-actions
Copy link
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp:examples dependencies Pull requests that update a dependency file go Pull requests that update Go code size/xs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant