Skip to content

Release v1.19.4 - #859

Merged
tphoney merged 11 commits into
mainfrom
copybara/v1.19.4
Sep 29, 2026
Merged

tphoney merged 11 commits into
mainfrom
copybara/v1.19.4

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Copybara Sync - Release v1.19.4

This PR was automatically created by Copybara, syncing changes from the overmindtech/workspace monorepo.

Original author: Elliot Waddington (getinnocuous@users.noreply.github.com)

What happens when this PR is merged?

  1. The tag-on-merge workflow will automatically create the v1.19.4 tag on main
  2. This tag will trigger the release workflow, which will:
    • Run tests
    • Build and publish release binaries via GoReleaser
    • Upload packages to Cloudsmith

Review Checklist

  • Changes look correct and match the expected monorepo sync
  • Tests pass (see CI checks below)

tphoney and others added 11 commits September 29, 2026 09:52
…702)

<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
Plan ID: UNTIL-1088

Fixes [ENG-6540](https://linear.app/overmind/issue/ENG-6540). Anyone who
can explore GCP in Overmind could previously read VM bootstrap secrets
(startup scripts, SSH keys, and similar metadata values) off Compute
instances, instance templates, and machine images.

## What changed

Drop `metadata.items` from SDP attributes at serialize time using the
existing nested-path exclusion helper. Protobuf objects stay intact so
instance-template and created-by graph links still work.

- **Compute instances** — also exclude `metadata.items`
- **Machine images** — exclude `instance_properties.metadata.items` and
`source_instance_properties.metadata.items`
- **Instance templates** — exclude `properties.metadata.items` for that
type only in the shared dynamic serializer

Out of scope: a general secret-redaction framework, AWS/Azure, regional
instance templates, cache flush.

## Tests

- Instance Get with `startup-script`, `ssh-keys`, and
`instance-template`: secrets absent from attributes; template/created-by
links still present; metadata fingerprint remains
- Machine image Get with startup scripts on both instance-properties and
source-instance-properties metadata: both values absent
- Instance template Get with `properties.metadata.items` startup-script:
value absent; existing link-rule static tests still green

```
go test -race -timeout 10m ./sources/gcp/manual ./sources/gcp/dynamic ./sources/gcp/dynamic/adapters
ok
```

Do not paste live startup-script or SSH-key values into review comments.
Use fixture VMs after deploy; source cache TTL is one hour.
<!-- CURSOR_AGENT_PR_BODY_END -->

Linear Issue:
[ENG-6540](https://linear.app/overmind/issue/ENG-6540/high-gcp-compute-instance-adapter-leaks-metadatastartup-script-secrets)

<div><a
href="https://cursor.com/agents/bc-95c75c60-6099-4b6e-b959-cb5400f6d447?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-95c75c60-6099-4b6e-b959-cb5400f6d447&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
GitOrigin-RevId: 7bcffdf23f5d774c3da7a3d2fb955b802a2461fd
## Summary
- Close Dependabot
[#252](https://github.com/overmindtech/workspace/security/dependabot/252)
by pinning `devalue` to 5.9.2 (CVE-2026-81176, quadratic DoS in
`devalue.parse`).
- Close Dependabot
[#251](https://github.com/overmindtech/workspace/security/dependabot/251)
by bumping
`go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc` from
v1.40.0 to v1.46.0 (CVE-2026-81870, exporter endpoint leak in verbose
OTel logs).
- `devalue@5.9.2` is excluded from the 72-hour soak so this security
patch can install immediately.

ENG-6553

https://linear.app/overmind/issue/ENG-6553/patch-dependabot-devalue-cve-2026-81176-and-otel-otlptracegrpc-cve

## Test plan
- [ ] Confirm `pnpm-lock.yaml` resolves `devalue@5.9.2` and no `5.8.2`
remains
- [ ] Confirm `go.mod` / `go.sum` list `otlptracegrpc v1.46.0`
- [ ] After merge, Dependabot alerts #252 and #251 auto-close

Co-authored-by: Cursor <cursoragent@cursor.com>
GitOrigin-RevId: 1f762c57b007b53b92c2d943e3850d0bacd24d53
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/aws/aws-sdk-go-v2/config](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.33.4` → `v1.33.5` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fconfig/v1.33.5?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fconfig/v1.33.4/v1.33.5?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/credentials](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.20.4` → `v1.20.5` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fcredentials/v1.20.5?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fcredentials/v1.20.4/v1.20.5?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/directconnect](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.50.0` → `v1.51.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fdirectconnect/v1.51.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fdirectconnect/v1.50.0/v1.51.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/dynamodb](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.68.0` → `v1.69.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fdynamodb/v1.69.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fdynamodb/v1.68.0/v1.69.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/ec2](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.332.0` → `v1.335.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fec2/v1.335.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fec2/v1.332.0/v1.335.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/ecs](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.97.0` → `v1.99.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fecs/v1.99.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fecs/v1.97.0/v1.99.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/kms](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.60.0` → `v1.61.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fkms/v1.61.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fkms/v1.60.0/v1.61.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/s3](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.113.0` → `v1.113.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fs3/v1.113.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fs3/v1.113.0/v1.113.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/sesv2](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.73.0` → `v1.74.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsesv2/v1.74.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsesv2/v1.73.0/v1.74.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/sns](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.47.0` → `v1.47.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsns/v1.47.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsns/v1.47.0/v1.47.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/sts](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.50.0` → `v1.51.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsts/v1.51.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsts/v1.50.0/v1.51.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/6708) for more information.

---

### Release Notes

<details>
<summary>aws/aws-sdk-go-v2
(github.com/aws/aws-sdk-go-v2/service/directconnect)</summary>

###
[`v1.51.0`](https://redirect.github.com/aws/aws-sdk-go-v2/blob/HEAD/CHANGELOG.md#Release-2026-09-15)

#### General Highlights

- **Dependency Update**: Updated to the latest SDK module versions

#### Module Highlights

- `github.com/aws/aws-sdk-go-v2/service/accessanalyzer`:
[v1.57.0](service/accessanalyzer/CHANGELOG.md#v1570-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/appconfig`:
[v1.54.0](service/appconfig/CHANGELOG.md#v1540-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/appconfigdata`:
[v1.32.0](service/appconfigdata/CHANGELOG.md#v1320-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/applicationautoscaling`:
[v1.51.0](service/applicationautoscaling/CHANGELOG.md#v1510-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/applicationinsights`:
[v1.44.0](service/applicationinsights/CHANGELOG.md#v1440-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/appsync`:
[v1.62.0](service/appsync/CHANGELOG.md#v1620-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/auditmanager`:
[v1.55.0](service/auditmanager/CHANGELOG.md#v1550-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/autoscalingplans`:
[v1.39.0](service/autoscalingplans/CHANGELOG.md#v1390-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/b2bi`:
[v1.0.0-preview.130](service/b2bi/CHANGELOG.md#v100-preview130-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/backupgateway`:
[v1.36.0](service/backupgateway/CHANGELOG.md#v1360-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/batch`:
[v1.77.0](service/batch/CHANGELOG.md#v1770-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/bcmdashboards`:
[v1.11.0](service/bcmdashboards/CHANGELOG.md#v1110-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/bcmdataexports`:
[v1.25.0](service/bcmdataexports/CHANGELOG.md#v1250-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/bcmpricingcalculator`:
[v1.21.0](service/bcmpricingcalculator/CHANGELOG.md#v1210-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/bcmrecommendedactions`:
[v1.12.0](service/bcmrecommendedactions/CHANGELOG.md#v1120-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/bedrock`:
[v1.73.0](service/bedrock/CHANGELOG.md#v1730-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/bedrockagent`:
[v1.66.0](service/bedrockagent/CHANGELOG.md#v1660-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/bedrockagentcorecontrol`:
[v1.67.0](service/bedrockagentcorecontrol/CHANGELOG.md#v1670-2026-09-15)
- **Feature**: Amazon Bedrock AgentCore Runtime now supports specifying
the platform version of an agent runtime through the new platformVersion
field on CreateAgentRuntime, UpdateAgentRuntime, and GetAgentRuntime.
- `github.com/aws/aws-sdk-go-v2/service/bedrockdataautomationruntime`:
[v1.19.0](service/bedrockdataautomationruntime/CHANGELOG.md#v1190-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/bedrockruntime`:
[v1.63.0](service/bedrockruntime/CHANGELOG.md#v1630-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/billing`:
[v1.20.0](service/billing/CHANGELOG.md#v1200-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/budgets`:
[v1.52.0](service/budgets/CHANGELOG.md#v1520-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/cloudhsm`:
[v1.38.0](service/cloudhsm/CHANGELOG.md#v1380-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs`:
[v1.88.0](service/cloudwatchlogs/CHANGELOG.md#v1880-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/codeconnections`:
[v1.19.0](service/codeconnections/CHANGELOG.md#v1190-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/costandusagereportservice`:
[v1.43.0](service/costandusagereportservice/CHANGELOG.md#v1430-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/costexplorer`:
[v1.73.0](service/costexplorer/CHANGELOG.md#v1730-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/directconnect`:
[v1.51.0](service/directconnect/CHANGELOG.md#v1510-2026-09-15)
- **Feature**: AWS Direct Connect is introducing flat-rate pricing, a
simplified billing model that gives you a fixed monthly price for
dedicated connectivity with no per-gigabyte data transfer out charges
within the selected pricing tier.
- `github.com/aws/aws-sdk-go-v2/service/dynamodb`:
[v1.69.0](service/dynamodb/CHANGELOG.md#v1690-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/ecr`:
[v1.66.0](service/ecr/CHANGELOG.md#v1660-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/ecs`:
[v1.99.0](service/ecs/CHANGELOG.md#v1990-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/elasticsearchservice`:
[v1.51.0](service/elasticsearchservice/CHANGELOG.md#v1510-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/firehose`:
[v1.52.0](service/firehose/CHANGELOG.md#v1520-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/fis`:
[v1.46.0](service/fis/CHANGELOG.md#v1460-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/imagebuilder`:
[v1.65.0](service/imagebuilder/CHANGELOG.md#v1650-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/inspector2`:
[v1.60.0](service/inspector2/CHANGELOG.md#v1600-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/kafka`:
[v1.65.0](service/kafka/CHANGELOG.md#v1650-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/kinesis`:
[v1.55.0](service/kinesis/CHANGELOG.md#v1550-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/kms`:
[v1.61.0](service/kms/CHANGELOG.md#v1610-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/mediaconnect`:
[v1.60.0](service/mediaconnect/CHANGELOG.md#v1600-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/mediaconvert`:
[v1.105.0](service/mediaconvert/CHANGELOG.md#v11050-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/medialive`:
[v1.111.0](service/medialive/CHANGELOG.md#v11110-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/mediatailor`:
[v1.71.0](service/mediatailor/CHANGELOG.md#v1710-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/mq`:
[v1.45.0](service/mq/CHANGELOG.md#v1450-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/personalizeevents`:
[v1.40.0](service/personalizeevents/CHANGELOG.md#v1400-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/personalizeruntime`:
[v1.42.0](service/personalizeruntime/CHANGELOG.md#v1420-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/ram`:
[v1.45.0](service/ram/CHANGELOG.md#v1450-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/resiliencehub`:
[v1.44.0](service/resiliencehub/CHANGELOG.md#v1440-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/resiliencehubv2`:
[v1.11.0](service/resiliencehubv2/CHANGELOG.md#v1110-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/secretsmanager`:
[v1.50.0](service/secretsmanager/CHANGELOG.md#v1500-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/securityhub`:
[v1.82.0](service/securityhub/CHANGELOG.md#v1820-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/sfn`:
[v1.51.0](service/sfn/CHANGELOG.md#v1510-2026-09-15)
  - **Feature**: Enable schema-based (de)serialization for this service.
- `github.com/aws/aws-sdk-go-v2/service/transfer`:
[v1.83.0](service/transfer/CHANGELOG.md#v1830-2026-09-15)
- **Feature**: AWS Transfer Family now preserves the original source IP
address using Proxy Protocol v2 when you place a Network Load Balancer
in front of your server for SFTP connections.
- `github.com/aws/aws-sdk-go-v2/service/workspaces`:
[v1.81.0](service/workspaces/CHANGELOG.md#v1810-2026-09-15)
- **Feature**: Added support for 4 new graphics-optimized compute types
- Graphics.g7 (2xlarge, 4xlarge, 8xlarge, 12xlarge).

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/London)

- Branch creation
  - "after 6pm on thursday,before 10am on friday"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend Renovate
CLI](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC45OS4wIiwidXBkYXRlZEluVmVyIjoiNDQuMTA0LjEiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyIsImdvbGFuZyJdfQ==-->

Co-authored-by: overmind-renovate[bot] <329497464+overmind-renovate[bot]@users.noreply.github.com>
GitOrigin-RevId: 501ca978cdee00caa9df51594cf1b2f920b17888
…tes (#6734)

<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
## Summary

- Cloud Run services, revisions, and worker pools, plus Cloud Functions,
no longer publish plaintext environment-variable values in SDP item
attributes.
- Variable names and Secret Manager references stay on the item so
engineers can still see which secrets are wired, and existing secret
links are unchanged.
- Shared attribute conversion now walks arrays and can blank map values,
which is what makes paths like `template.containers.env.value` actually
drop every env value.

## Linear Ticket

Fixes:
[ENG-6591](https://linear.app/overmind/issue/ENG-6591/redact-gcp-workload-environment-variables-from-sdp-attributes)
— Redact GCP workload environment variables from SDP attributes

- **Purpose**: Close a high-severity finding by stripping plaintext GCP
workload environment values from SDP attributes, using the same
attribute-stripping approach already used for instance-template
metadata.

## Changes

**Shared attribute conversion (`sources/shared/util.go`)**
- `ToAttributesWithExclude` keeps its signature and now delegates to
`ToAttributesRedacting`.
- Dotted exclusion paths descend maps and every element of arrays, so a
leaf such as `value` is deleted on every env entry of every container.
- `ToAttributesRedacting` also blanks named maps: keys stay, each value
becomes `""` (including non-string values). A missing path is a no-op.

**GCP dynamic serializer (`sources/gcp/dynamic/shared.go`)**
- `externalToSDP` calls `ToAttributesRedacting` on the attribute copy.
`linkItem` still walks the original API payload.
- Per-type paths:
- `gcp-run-service`: exclude `template.containers.env.value`; blank
`buildConfig.environmentVariables`
  - `gcp-run-revision`: exclude `containers.env.value`
  - `gcp-run-worker-pool`: exclude `template.containers.env.value`
- `gcp-cloud-functions-function`: blank
`serviceConfig.environmentVariables` and
`buildConfig.environmentVariables`
- `secretEnvironmentVariables` and `valueSource` are not redacted.
Instance-template `properties.metadata.items` exclusion stays alongside
`labels`.

**Tests**
- Shared unit tests cover array leaf deletion, map-value blanking, and a
non-array exclude plus a missing blank path.
- Cloud Run service, revision, and Cloud Functions Get tests assert
sentinel plaintext values are absent, names remain, secret refs remain,
and (for services) the existing Secret Manager static link still
matches.
- New worker-pool Get test asserts the plaintext env value is absent and
the name remains.

Reviewers should focus on the walker in `ToAttributesRedacting` (array
descent and map blanking) and the per-type path lists in
`externalToSDP`.

## Until Plan

Plan ID: UNTIL-1102

- **Plan**: Redact GCP workload environment variables from SDP
attributes
- **Approved by**: none yet

> Deviation analysis and reviewer assignment are handled automatically
by the
> pre-approved PR review automation (see docs/PREAPPROVED_CHANGES.md).

<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a
href="https://cursor.com/agents/bc-d4a667c9-2f4d-4bc1-9c8b-336c0ac08a74?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-d4a667c9-2f4d-4bc1-9c8b-336c0ac08a74&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: carabasdaniel <carabasdaniel@users.noreply.github.com>
GitOrigin-RevId: 7e7ebefe7e534a1583d7cc8d5fd335117a7e866a
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/aws/aws-sdk-go-v2](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.47.0` → `v1.47.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2/v1.47.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2/v1.47.0/v1.47.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/config](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.33.5` → `v1.33.6` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fconfig/v1.33.6?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fconfig/v1.33.5/v1.33.6?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/credentials](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.20.5` → `v1.20.6` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fcredentials/v1.20.6?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fcredentials/v1.20.5/v1.20.6?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.20.0` → `v1.20.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2ffeature%2fec2%2fimds/v1.20.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2ffeature%2fec2%2fimds/v1.20.0/v1.20.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/apigateway](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.47.0` → `v1.50.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fapigateway/v1.50.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fapigateway/v1.47.0/v1.50.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/autoscaling](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.78.0` → `v1.78.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fautoscaling/v1.78.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fautoscaling/v1.78.0/v1.78.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/cloudfront](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.73.0` → `v1.73.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fcloudfront/v1.73.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fcloudfront/v1.73.0/v1.73.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/cloudwatch](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.72.0` → `v1.73.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fcloudwatch/v1.73.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fcloudwatch/v1.72.0/v1.73.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/directconnect](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.51.0` → `v1.53.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fdirectconnect/v1.53.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fdirectconnect/v1.51.0/v1.53.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/dynamodb](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.69.0` → `v1.69.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fdynamodb/v1.69.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fdynamodb/v1.69.0/v1.69.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/ec2](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.335.0` → `v1.336.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fec2/v1.336.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fec2/v1.335.0/v1.336.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/ecs](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.99.0` → `v1.99.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fecs/v1.99.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fecs/v1.99.0/v1.99.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/efs](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.49.0` → `v1.49.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fefs/v1.49.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fefs/v1.49.0/v1.49.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/eks](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.99.0` → `v1.101.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2feks/v1.101.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2feks/v1.99.0/v1.101.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/elasticloadbalancing](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.41.0` → `v1.41.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2felasticloadbalancing/v1.41.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2felasticloadbalancing/v1.41.0/v1.41.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.63.0` → `v1.63.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2felasticloadbalancingv2/v1.63.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2felasticloadbalancingv2/v1.63.0/v1.63.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/iam](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.64.0` → `v1.64.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fiam/v1.64.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fiam/v1.64.0/v1.64.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/kms](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.61.0` → `v1.61.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fkms/v1.61.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fkms/v1.61.0/v1.61.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/lambda](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.108.0` → `v1.110.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2flambda/v1.110.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2flambda/v1.108.0/v1.110.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/networkfirewall](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.72.0` → `v1.74.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fnetworkfirewall/v1.74.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fnetworkfirewall/v1.72.0/v1.74.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/networkmanager](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.50.0` → `v1.50.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fnetworkmanager/v1.50.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fnetworkmanager/v1.50.0/v1.50.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/rds](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.129.0` → `v1.129.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2frds/v1.129.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2frds/v1.129.0/v1.129.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/route53](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.70.0` → `v1.70.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2froute53/v1.70.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2froute53/v1.70.0/v1.70.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/s3](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.113.1` → `v1.113.4` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fs3/v1.113.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fs3/v1.113.1/v1.113.4?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/sesv2](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.74.0` → `v1.76.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsesv2/v1.76.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsesv2/v1.74.0/v1.76.0?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/sns](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.47.1` → `v1.47.2` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsns/v1.47.2?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsns/v1.47.1/v1.47.2?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/sqs](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.52.0` → `v1.52.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsqs/v1.52.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsqs/v1.52.0/v1.52.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/ssm](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.78.0` → `v1.78.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fssm/v1.78.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fssm/v1.78.0/v1.78.1?slim=true)
|
|
[github.com/aws/aws-sdk-go-v2/service/sts](https://redirect.github.com/aws/aws-sdk-go-v2)
| `v1.51.0` → `v1.51.1` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsts/v1.51.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2faws%2faws-sdk-go-v2%2fservice%2fsts/v1.51.0/v1.51.1?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/6708) for more information.

---

### Release Notes

<details>
<summary>aws/aws-sdk-go-v2 (github.com/aws/aws-sdk-go-v2)</summary>

###
[`v1.47.1`](https://redirect.github.com/aws/aws-sdk-go-v2/blob/HEAD/CHANGELOG.md#Release-2026-09-17)

#### Module Highlights

- `github.com/aws/aws-sdk-go-v2/service/bedrockagentcore`:
[v1.49.0](service/bedrockagentcore/CHANGELOG.md#v1490-2026-09-17)
- **Feature**: Batch evaluation now supports evaluating specific traces
within a session. Each session can specify up to 100 trace IDs to
evaluate.
- `github.com/aws/aws-sdk-go-v2/service/connect`:
[v1.200.0](service/connect/CHANGELOG.md#v12000-2026-09-17)
- **Feature**: Made the replicaAlias attribute optional in the
ReplicateInstance API to support Global routing for Amazon Connect
Global Resiliency (ACGR) instances. This change maintains backward
compatibility. When onboarding to ACGR without Global routing, you must
specify a custom replicaAlias in your API call
- `github.com/aws/aws-sdk-go-v2/service/ec2`:
[v1.334.0](service/ec2/CHANGELOG.md#v13340-2026-09-17)
  - **Feature**: Adding support for "Tunnel" VPC Endpoint
- `github.com/aws/aws-sdk-go-v2/service/guardduty`:
[v1.93.0](service/guardduty/CHANGELOG.md#v1930-2026-09-17)
- **Feature**: This change surfaces AI Protection resources on existing
public IAM attack sequences. Customers will now see which model was
accessed and whether a guardrail intervened as part of the
credential-compromise sequence.
- `github.com/aws/aws-sdk-go-v2/service/iotwireless`:
[v1.65.0](service/iotwireless/CHANGELOG.md#v1650-2026-09-17)
- **Feature**: Adds Multi-frame GNSS support to the AWS IoT Core Device
Location GetPositionEstimate API. The new GnssMultiFrame measurement
type improves location accuracy by combining multiple GNSS signal
captures (2, 4, 8, 16, or 32) from the same device to estimate its
position.
- `github.com/aws/aws-sdk-go-v2/service/notifications`:
[v1.17.0](service/notifications/CHANGELOG.md#v1170-2026-09-17)
- **Feature**: Added support for attachments on managed notification
events. Added support to access and subscribe sensitive managed
notification events.
- `github.com/aws/aws-sdk-go-v2/service/sesv2`:
[v1.74.0](service/sesv2/CHANGELOG.md#v1740-2026-09-17)
- **Feature**: Added support to query the tenant name for
BatchGetMetricData and CreateExportJob APIs to filter metrics and
messages at the tenant level.
- `github.com/aws/aws-sdk-go-v2/service/sns`:
[v1.47.1](service/sns/CHANGELOG.md#v1471-2026-09-17)
  - **Documentation**: SNS API reference documentation update
- `github.com/aws/aws-sdk-go-v2/service/socialmessaging`:
[v1.21.0](service/socialmessaging/CHANGELOG.md#v1210-2026-09-17)
  - **Feature**: Add support for WhatsApp Calling APIs.
- `github.com/aws/aws-sdk-go-v2/service/vpclattice`:
[v1.33.0](service/vpclattice/CHANGELOG.md#v1330-2026-09-17)
  - **Feature**: Adding support for CIDR Resource Configuration

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/London)

- Branch creation
  - "after 6pm on thursday,before 10am on friday"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend Renovate
CLI](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTUuMiIsInVwZGF0ZWRJblZlciI6IjQ0LjExNS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJnb2xhbmciXX0=-->

Co-authored-by: overmind-renovate[bot] <329497464+overmind-renovate[bot]@users.noreply.github.com>
GitOrigin-RevId: c6ab17e7e782bf80edad04fa13c71b9049395e19
<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
## Summary
- pin both Go modules, build images, and setup documentation to Go
1.27.1
- move Azure Network SDK imports from `armnetwork/v11` to
`armnetwork/v12`
- move Until GitHub API call sites from `go-github/v91` to
`go-github/v92`, retaining v88 only for `ghinstallation` v2.19.0 token
options
- move Until GitLab API call sites from `client-go/v2` to `client-go/v3`
- regenerate Azure network client mocks; no upgraded-version workaround
became dead
- refresh the documented monorepo Go target in `docs/MEMORY.md`

Plan ID: UNTIL-1101

## Test plan
- [x] `go test -race ./sources/azure/manual`
- [x] `go test -race ./services/until-backend/loops -run
'Test(TransportForAccount|ToolBundleInstallationForAccount)'`
- [x] `go test -race ./services/until-backend/integrations/github -run
'TestResolveGitHubReviewer'`
- [x] `go test -race ./services/until-backend/integrations/gitlab -run
'Test(ClientFactory_ClientForInstall|StatusSyncWorker)'`
- [x] `go test -run '^$' ./sources/azure/integration-tests`
- [x] `golangci-lint run` for all modified Go packages
- [x] `git diff --check`

## Until Loop waiver
The user said: “skip plan review”.

Plan Review and the Plan check were skipped for this implementation.

## Notes
- The devcontainer toolchain-copy stage remains necessary: Microsoft’s
mutable `dev-1.27-bookworm` currently contains Go 1.27.1, but no
patch-pinned 1.27.1 tag exists. Switching to the mutable tag also failed
the repository’s Snyk security and license checks.
- The existing `replace` directives for the Anthropic SDK, otelpgx,
go-git, avro, `golang.org/x/image`, and thrift remain because they
address unrelated upstream issues.
- `sigs.k8s.io/structured-merge-diff/v6` remains unchanged because its
generated Kubernetes usage is outside this scope.
<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a
href="https://cursor.com/agents/bc-78a96097-0f12-4e12-b0e8-38b2df4190c1?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-78a96097-0f12-4e12-b0e8-38b2df4190c1&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
GitOrigin-RevId: 831cc794048ae8b9577eb892b4af58b82869db8c
…attributes (#6739)

<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
## Summary

- Kubernetes Pods and controllers no longer publish plaintext container
environment-variable values in SDP item attributes.
- Variable names and `valueFrom` Secret/ConfigMap references stay on the
item so engineers can still see which secrets are wired, and existing
secret links are unchanged.
- Shared workload redaction runs for every serialized k8s item, covering
Pod, Deployment, ReplicaSet, StatefulSet, DaemonSet, Job, CronJob, and
ReplicationController.

## Linear Ticket

Fixes:
[ENG-6592](https://linear.app/overmind/issue/ENG-6592/redact-kubernetes-workload-environment-variables-from-sdp-attributes)
— Redact Kubernetes workload environment variables from SDP attributes

- **Purpose**: Close a high-severity finding by stripping plaintext
Kubernetes workload environment values from SDP attributes, matching the
GCP approach in ENG-6591.

## Changes

**Shared workload redaction (`k8s-source/adapters/workload_redact.go`)**
- `redactWorkloadEnvValues` type-switches on workload objects and clears
`EnvVar.Value` on containers, init containers, and ephemeral containers.
- Empty values are omitted from JSON (`omitempty`), so the `value` key
is absent from attributes.
- Unknown types (including Secrets) are a no-op; Secret data redaction
is unchanged.

**Generic serializer (`k8s-source/adapters/generic_source.go`)**
- `resourceToItem` calls workload env redaction after any
adapter-specific `Redact` hook and before `ToAttributesViaJson`.
- `LinkedItemQueryExtractor` still sees `valueFrom` references, so
Secret/ConfigMap links are preserved.

**Tests**
- Table-driven tests for every workload type assert sentinel plaintext
values are absent and names/secret refs remain.
- CronJob `resourceToItem` test covers the nested `jobTemplate` path
through the real serializer.
- Pod Get test asserts attributes omit the sentinel while
AutoQueryExtract still finds a non-env URL.

Reviewers should focus on the type switch coverage (especially CronJob
nesting and nil ReplicationController templates) and that Secret
redaction is independent.
<!-- CURSOR_AGENT_PR_BODY_END -->

Linear Issue:
[ENG-6592](https://linear.app/overmind/issue/ENG-6592/redact-kubernetes-workload-environment-variables-from-sdp-attributes)

<div><a
href="https://cursor.com/agents/bc-859baaa1-1926-4b3e-b5ac-e90370800da7?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-859baaa1-1926-4b3e-b5ac-e90370800da7&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
GitOrigin-RevId: eb35527ee9a04e5fba5db6b3ed6e470cf4474024
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/sql/armsql/v2](https://redirect.github.com/Azure/azure-sdk-for-go)
| `v2.0.0-beta.8` → `v2.0.0-beta.9` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fAzure%2fazure-sdk-for-go%2fsdk%2fresourcemanager%2fsql%2farmsql%2fv2/v2.0.0-beta.9?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fAzure%2fazure-sdk-for-go%2fsdk%2fresourcemanager%2fsql%2farmsql%2fv2/v2.0.0-beta.8/v2.0.0-beta.9?slim=true)
|
|
[github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/storage/armstorage/v4](https://redirect.github.com/Azure/azure-sdk-for-go)
| `v4.1.0` → `v4.2.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fAzure%2fazure-sdk-for-go%2fsdk%2fresourcemanager%2fstorage%2farmstorage%2fv4/v4.2.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fAzure%2fazure-sdk-for-go%2fsdk%2fresourcemanager%2fstorage%2farmstorage%2fv4/v4.1.0/v4.2.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/6708) for more information.

---

### Configuration

📅 **Schedule**: (in timezone Europe/London)

- Branch creation
  - "after 6pm on thursday,before 10am on friday"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend Renovate
CLI](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTUuMiIsInVwZGF0ZWRJblZlciI6IjQ0LjExNS40IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJnb2xhbmciXX0=-->

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Dependency bumps with a localized health-mapping fix for one Azure SQL
resource type; storage is version-only in this diff.
>
> **Overview**
> Bumps Azure SDK dependencies **`armsql/v2`** (beta.8 → beta.9) and
**`armstorage/v4`** (4.1.0 → 4.2.0); only the SQL bump required code
changes.
>
> **SQL server private endpoint connection** health now uses typed
`armsql.PrivateEndpointProvisioningState` values instead of lowercased
strings. Mapping aligns with the newer API contract: `Succeeded` →
healthy, `Created`/`InProgress` → pending, `Failed`/`Canceled` → error.
Legacy states removed in preview API versions (`Ready`, `Approving`,
`Dropping`, `Rejecting`) no longer map to OK/pending/error and report
**unknown** health instead.
>
> Tests add a **`HealthMapping`** table-driven case (including the
removed `Ready` string) and default fixtures use `Succeeded` rather than
`Ready`.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
c0b6ad34781a983aba8a8dfd54781374b7dd8e6d. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

---------

Co-authored-by: overmind-renovate[bot] <329497464+overmind-renovate[bot]@users.noreply.github.com>
Co-authored-by: carabasdaniel <daniel.carabas@overmind.tech>
Co-authored-by: Cursor <cursoragent@cursor.com>
GitOrigin-RevId: 6a79d68f9a8ca4e74bcb8b6c982ebb03a1acc20f
## Summary
- The weekly leaderboard excludes Linear issues labeled
`until-plan-sync`, matching the renamed label.
- Cited docs, READMEs, and tests drop the old product name, except kept
filenames, real ticket ids, the telemetry detector, pinned benchmark
paths, and assertions of strings production still matches.
- The exception list no longer records README needles or a Linear label
that this edit removed.

Plan ID: UNTIL-1112

missing-cited-backend-test-cleanups: cited tests left unchanged still
contain only strings the plan keeps (production matchers, pinned
brent-demo and .brent/workflows paths, the legacy display-name heal, the
Slack manifest host, and the oauth HMAC) or they contain no old-name
token.

## Test plan
- [x] `bash scripts/until-rename/check-exceptions.sh` exits 0
- [x] `go test` for `go/tracing` and the MCP OAuth cases in `go/auth`
- [x] `go test` for the until-backend unit tests that changed (identity
greps, upload/SPA/logo/SLO/security.txt, timeline actor classification,
system prompt, retired paths, oauth HMAC)
- [ ] Integration tests that only rename fixtures still need a database
run in CI

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Changes are overwhelmingly documentation and test/fixture renames;
production routing and OAuth behavior are only touched via test
expectations, not new runtime logic.
>
> **Overview**
> Continues the Until rename by scrubbing **cited** docs, runbooks, and
test copy that still said “Brent,” while tightening what the rename
exception list tracks.
>
> **Engineering leaderboard** now excludes Linear audit-trail issues
labeled **`until-plan-sync`** (roster key and `weekly.mjs` logic renamed
from `brent-plan-sync`).
>
> **Documentation** uses neutral wording (previous product name, retired
telemetry prefix, manifest hosts) in Copybara isolation, observability
cutover, 1Password inventory, `until-backend` README, and integration
READMEs; **`permanent-exceptions.md`** drops many README “needle” lines
and the Linear `brent-plan-sync` exception row that this pass no longer
needs.
>
> **Tests and fixtures** swap old branding for Until-oriented names
(`custom_pr_review`, `until-app[bot]`, `UNTIL-13`, prod
`until.overmind.tech`, etc.) and rename “retired Brent path” cases to
**generic retired routes** (`/retired/…`) without changing the asserted
behavior (404/unmounted legacy URLs, legacy cookies rejected).
>
> **Shared Go tests**: MCP OAuth metadata tests no longer require
**`/brent/`** in a forbidden-path list; the telemetry naming guard
**shrinks its allowlist** so fewer non-telemetry `brent.*` literals are
grandfathered.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
2b7da5aa6ed15dc7d71b17dbf8f4f83a7d46beca. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
GitOrigin-RevId: 79dabbef6fb1d7e700debc3d761bb3f8c202a04a
## Summary

- Teach `go/sdp-go/llm` to call OpenAI with an optional per-account key
and fall back to the platform key when that key is rejected, out of
quota, missing the model, or still failing after retries. A 400 or a
cancelled call is returned as-is.
- Chat resolves the key once per conversation and stays on the platform
key after a fallback, so response chaining does not cross organisations.
Embeddings resolve on every call.
- No service passes a resolver yet. Callers behave as they do today
until a later change stores the key.

## Linear Ticket

Fixes:
[ENG-6617](https://linear.app/overmind/issue/ENG-6617/openai-key-support-for-overmind)
— OpenAI key support for overmind

- **Purpose**: Let a customer bill Overmind OpenAI usage to their own
key, starting with the shared llm package.

## Changes

- Add an OpenAI error classifier, an account-key resolver, and a
fallback loop in the Responses provider. Account clients skip SDK
retries on quota errors. Spans record the key source, the fallback
reason, and the account name.
- Move embeddings off `sashabaranov/go-openai` onto the official client,
with the same classify, fallback, and report rule per call.
- Cover chat and embedding fallback with `httptest`. Package docs name
`NewOpenAIResponsesProvider` and say `RetryableError` comes from
TypedProvider and Anthropic only.

## Until Plan

Plan ID: UNTIL-1111

- **Plan**: Account OpenAI keys with platform fallback in the llm
package
- **Approved by**: Thomas Honey

> Deviation analysis and reviewer assignment are handled automatically
by the
> pre-approved PR review automation (see docs/PREAPPROVED_CHANGES.md).

Made with [Cursor](https://cursor.com)

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
GitOrigin-RevId: b9dc3275747d6498268e50aa07cb8e1d4305c696
@tphoney
tphoney merged commit 7cb5015 into main Sep 29, 2026
@tphoney
tphoney deleted the copybara/v1.19.4 branch September 29, 2026 10:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants