From ff817f6cf81d7ae27e64279c7d844d5889400046 Mon Sep 17 00:00:00 2001 From: Julien Neuhart Date: Thu, 17 Sep 2026 15:33:55 +0200 Subject: [PATCH] chore(deps)!: migrate from regexp2 v1 to regexp2 v2 --- go.mod | 2 +- go.sum | 4 +-- pkg/gotenberg/allowlist_test.go | 6 ++--- pkg/gotenberg/flags.go | 6 ++--- pkg/gotenberg/flags_test.go | 2 +- pkg/gotenberg/outbound.go | 2 +- pkg/gotenberg/outbound_test.go | 26 +++++++++---------- pkg/gotenberg/pattern.go | 2 +- pkg/gotenberg/pattern_test.go | 4 +-- pkg/modules/api/api.go | 2 +- pkg/modules/api/context_test.go | 4 +-- pkg/modules/chromium/browser.go | 2 +- pkg/modules/chromium/chromium.go | 2 +- pkg/modules/chromium/events.go | 2 +- pkg/modules/chromium/pinning_proxy.go | 2 +- pkg/modules/chromium/pinning_proxy_test.go | 2 +- .../chromium/pinning_proxy_upstream_test.go | 2 +- pkg/modules/chromium/routes.go | 2 +- pkg/modules/chromium/scopebudget_test.go | 2 +- pkg/modules/libreoffice/api/proxy.go | 2 +- pkg/modules/libreoffice/api/proxy_test.go | 4 +-- pkg/modules/webhook/webhook.go | 2 +- 22 files changed, 42 insertions(+), 42 deletions(-) diff --git a/go.mod b/go.mod index 874f4b5e..490abd8a 100644 --- a/go.mod +++ b/go.mod @@ -8,7 +8,7 @@ require ( github.com/chromedp/chromedp v0.14.2 // pinned: v0.15.x breaks the headless print-mode paint pipeline (rAF / ResizeObserver / IntersectionObserver stop firing, blank charts). See https://github.com/gotenberg/gotenberg/issues/1535. github.com/coreos/go-oidc/v3 v3.21.0 github.com/cucumber/godog v0.16.0 - github.com/dlclark/regexp2 v1.12.0 + github.com/dlclark/regexp2/v2 v2.8.0 github.com/gomarkdown/markdown v0.0.0-20260824154242-13c5cf49db8d github.com/google/uuid v1.6.0 github.com/hashicorp/go-retryablehttp v0.7.8 diff --git a/go.sum b/go.sum index ae94f7ea..d974763b 100644 --- a/go.sum +++ b/go.sum @@ -58,8 +58,8 @@ github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSs github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= github.com/distribution/reference v0.6.0 h1:0IXCQ5g4/QMHHkarYzh5l+u8T3t73zM5QvfrDyIgxBk= github.com/distribution/reference v0.6.0/go.mod h1:BbU0aIcezP1/5jX/8MP0YiH4SdvB5Y4f/wlDRiLyi3E= -github.com/dlclark/regexp2 v1.12.0 h1:0j4c5qQmnC6XOWNjP3PIXURXN2gWx76rd3KvgdPkCz8= -github.com/dlclark/regexp2 v1.12.0/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8= +github.com/dlclark/regexp2/v2 v2.8.0 h1:CekDhPLGfm+GAJmPVFIG+5dqMIQPkyHJll7BbdneDfw= +github.com/dlclark/regexp2/v2 v2.8.0/go.mod h1:avUrQvPaLz2DrFNHJF0taWAFFX2C1GMSSoeiqFjcBmU= github.com/docker/go-connections v0.8.1 h1:JibmG5hULs5qXSr/cp/w3Pw5fZuStt4MOHMUExb29/M= github.com/docker/go-connections v0.8.1/go.mod h1:no1qkHdjq7kLMGUXYAduOhYPSJxxvgWBh7ogVvptn3Q= github.com/docker/go-units v0.5.0 h1:69rxXcBk27SvSaaxTtLh/8llcHD8vYHT7WSdRZ/jvr4= diff --git a/pkg/gotenberg/allowlist_test.go b/pkg/gotenberg/allowlist_test.go index 7b188740..6a37a7bb 100644 --- a/pkg/gotenberg/allowlist_test.go +++ b/pkg/gotenberg/allowlist_test.go @@ -3,7 +3,7 @@ package gotenberg import ( "testing" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" ) func TestAuditAllowList(t *testing.T) { @@ -93,7 +93,7 @@ func TestAuditAllowList_FlaggedPatternsAreActuallyExploitable(t *testing.T) { t.Fatalf("pattern %q was not flagged", tc.pattern) } - ok, err := regexp2.MustCompile(tc.pattern, 0).MatchString(tc.attack) + ok, err := regexp2.MustCompile(tc.pattern, regexp2.None).MatchString(tc.attack) if err != nil { t.Fatalf("match %q: %v", tc.attack, err) } @@ -129,7 +129,7 @@ func TestAuditAllowList_SafePatternsRejectTheAttacks(t *testing.T) { t.Fatalf("safe pattern %q was flagged as %q", pattern, findings[0].Risk) } - re := regexp2.MustCompile(pattern, 0) + re := regexp2.MustCompile(pattern, regexp2.None) for _, attack := range attacks { ok, err := re.MatchString(attack) if err != nil { diff --git a/pkg/gotenberg/flags.go b/pkg/gotenberg/flags.go index 96e7d100..12a61b8e 100644 --- a/pkg/gotenberg/flags.go +++ b/pkg/gotenberg/flags.go @@ -7,7 +7,7 @@ import ( "strings" "time" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" "github.com/labstack/gommon/bytes" flag "github.com/spf13/pflag" @@ -239,7 +239,7 @@ func (f *ParsedFlags) MustRegexp(name string) *regexp2.Regexp { panic(err) } - re := regexp2.MustCompile(val, 0) + re := regexp2.MustCompile(val, regexp2.None) re.MatchTimeout = PatternMatchTimeout return re @@ -276,7 +276,7 @@ func (f *ParsedFlags) MustRegexpSlice(name string) []*regexp2.Regexp { continue } - re := regexp2.MustCompile(val, 0) + re := regexp2.MustCompile(val, regexp2.None) re.MatchTimeout = PatternMatchTimeout regexps = append(regexps, re) diff --git a/pkg/gotenberg/flags_test.go b/pkg/gotenberg/flags_test.go index b140a1c1..df3044b1 100644 --- a/pkg/gotenberg/flags_test.go +++ b/pkg/gotenberg/flags_test.go @@ -7,7 +7,7 @@ import ( "testing" "time" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" flag "github.com/spf13/pflag" ) diff --git a/pkg/gotenberg/outbound.go b/pkg/gotenberg/outbound.go index 8ff409ad..187c58e7 100644 --- a/pkg/gotenberg/outbound.go +++ b/pkg/gotenberg/outbound.go @@ -15,7 +15,7 @@ import ( "strings" "time" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" "github.com/hashicorp/go-retryablehttp" "golang.org/x/net/http/httpproxy" ) diff --git a/pkg/gotenberg/outbound_test.go b/pkg/gotenberg/outbound_test.go index 5b79d292..c99b8f7a 100644 --- a/pkg/gotenberg/outbound_test.go +++ b/pkg/gotenberg/outbound_test.go @@ -9,7 +9,7 @@ import ( "testing" "time" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" ) func TestIsPublicIP(t *testing.T) { @@ -164,10 +164,10 @@ func mustAddrs(t *testing.T, ss ...string) []netip.Addr { func TestFilterOutboundURL(t *testing.T) { defaultDeny := []*regexp2.Regexp{ - regexp2.MustCompile(`^https?://(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.|169\.254\.|0\.0\.0\.0|127\.|localhost|\[::1\]|\[fd)`, 0), + regexp2.MustCompile(`^https?://(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.|169\.254\.|0\.0\.0\.0|127\.|localhost|\[::1\]|\[fd)`, regexp2.None), } chromiumDeny := []*regexp2.Regexp{ - regexp2.MustCompile(`^file:(?!//\/tmp/).*`, 0), + regexp2.MustCompile(`^file:(?!//\/tmp/).*`, regexp2.None), } for _, tc := range []struct { @@ -246,7 +246,7 @@ func TestFilterOutboundURL(t *testing.T) { { scenario: "allow-list match bypasses IP check", rawURL: "http://internal.service/api", - allow: []*regexp2.Regexp{regexp2.MustCompile(`^http://internal\.service`, 0)}, + allow: []*regexp2.Regexp{regexp2.MustCompile(`^http://internal\.service`, regexp2.None)}, deny: defaultDeny, opts: []DecideOption{WithDenyPrivateIPs(true)}, expectErr: false, @@ -254,15 +254,15 @@ func TestFilterOutboundURL(t *testing.T) { { scenario: "deny-list still wins over allow-list match", rawURL: "http://internal.service/api", - allow: []*regexp2.Regexp{regexp2.MustCompile(`^http://internal`, 0)}, - deny: []*regexp2.Regexp{regexp2.MustCompile(`/api$`, 0)}, + allow: []*regexp2.Regexp{regexp2.MustCompile(`^http://internal`, regexp2.None)}, + deny: []*regexp2.Regexp{regexp2.MustCompile(`/api$`, regexp2.None)}, expectErr: true, expectIs: ErrFiltered, }, { scenario: "allow-list non-empty and no match rejects", rawURL: "https://other.example/", - allow: []*regexp2.Regexp{regexp2.MustCompile(`^https://allowed\.example`, 0)}, + allow: []*regexp2.Regexp{regexp2.MustCompile(`^https://allowed\.example`, regexp2.None)}, expectErr: true, expectIs: ErrFiltered, }, @@ -539,7 +539,7 @@ func TestDecideOutbound_DenyLists_WinOverDenyPrivateIPs(t *testing.T) { // The regex deny-list fires before any resolution; verifies that // operator-supplied deny patterns remain effective regardless of // IP-class options. - deny := []*regexp2.Regexp{regexp2.MustCompile(`^http://evil\.`, 0)} + deny := []*regexp2.Regexp{regexp2.MustCompile(`^http://evil\.`, regexp2.None)} _, err := DecideOutbound( context.Background(), @@ -605,7 +605,7 @@ func TestDecideOutbound_UserinfoDoesNotEvadeDenyList(t *testing.T) { context.Background(), rawURL, nil, - []*regexp2.Regexp{regexp2.MustCompile(privateIPsDenyList, 0)}, + []*regexp2.Regexp{regexp2.MustCompile(privateIPsDenyList, regexp2.None)}, time.Now().Add(5*time.Second), ) if !errors.Is(err, ErrFiltered) { @@ -617,7 +617,7 @@ func TestDecideOutbound_UserinfoDoesNotEvadeDenyList(t *testing.T) { func TestDecideOutbound_UserinfoDoesNotSatisfyAllowList(t *testing.T) { // A host-terminated allow-list, the shape the documentation recommends. - allowList := []*regexp2.Regexp{regexp2.MustCompile(`^https://trusted\.example\.com(:[0-9]+)?(/|$)`, 0)} + allowList := []*regexp2.Regexp{regexp2.MustCompile(`^https://trusted\.example\.com(:[0-9]+)?(/|$)`, regexp2.None)} for _, rawURL := range []string{ "https://trusted.example.com@169.254.169.254/latest/meta-data/", @@ -656,7 +656,7 @@ func TestDecideOutbound_UserinfoKeptOutOfErrorMessages(t *testing.T) { context.Background(), "http://alice:hunter2@127.0.0.1:9999/", nil, - []*regexp2.Regexp{regexp2.MustCompile(privateIPsDenyList, 0)}, + []*regexp2.Regexp{regexp2.MustCompile(privateIPsDenyList, regexp2.None)}, time.Now().Add(5*time.Second), ) if err == nil { @@ -680,7 +680,7 @@ func TestDecideOutbound_LegitimateCredentialsStillReachTheHost(t *testing.T) { decision, err := DecideOutbound( context.Background(), "https://alice:hunter2@example.com/report.pdf", - []*regexp2.Regexp{regexp2.MustCompile(`^https://example\.com(:[0-9]+)?(/|$)`, 0)}, + []*regexp2.Regexp{regexp2.MustCompile(`^https://example\.com(:[0-9]+)?(/|$)`, regexp2.None)}, nil, time.Now().Add(5*time.Second), WithDenyPrivateIPs(true), @@ -774,7 +774,7 @@ func TestDecideOutboundBoundsCatastrophicPatterns(t *testing.T) { // caller's whole budget, so a 30s API_TIMEOUT bought a 30s CPU burn. // The trailing "!" makes the match fail only after the nested quantifier // has explored every way to split the run of "a"s. - pattern := regexp2.MustCompile(`^https://example\.com/(a+)+$`, 0) + pattern := regexp2.MustCompile(`^https://example\.com/(a+)+$`, regexp2.None) pattern.MatchTimeout = PatternMatchTimeout rawURL := "https://example.com/" + strings.Repeat("a", 40) + "!" diff --git a/pkg/gotenberg/pattern.go b/pkg/gotenberg/pattern.go index a54de874..75f38150 100644 --- a/pkg/gotenberg/pattern.go +++ b/pkg/gotenberg/pattern.go @@ -1,7 +1,7 @@ package gotenberg import ( - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" ) // patternMatchAttempts caps how many times [MatchPattern] runs one pattern diff --git a/pkg/gotenberg/pattern_test.go b/pkg/gotenberg/pattern_test.go index f7b61f1e..2e237e22 100644 --- a/pkg/gotenberg/pattern_test.go +++ b/pkg/gotenberg/pattern_test.go @@ -5,14 +5,14 @@ import ( "testing" "time" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" ) // mustPattern compiles a pattern the way the production lists are built. func mustPattern(t *testing.T, expr string) *regexp2.Regexp { t.Helper() - re := regexp2.MustCompile(expr, 0) + re := regexp2.MustCompile(expr, regexp2.None) re.MatchTimeout = PatternMatchTimeout return re diff --git a/pkg/modules/api/api.go b/pkg/modules/api/api.go index 1b50283d..82ed365f 100644 --- a/pkg/modules/api/api.go +++ b/pkg/modules/api/api.go @@ -12,7 +12,7 @@ import ( "time" "github.com/alexliesenfeld/health" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" "github.com/labstack/echo/v5" flag "github.com/spf13/pflag" "golang.org/x/sync/errgroup" diff --git a/pkg/modules/api/context_test.go b/pkg/modules/api/context_test.go index e1e361b2..bce60b55 100644 --- a/pkg/modules/api/context_test.go +++ b/pkg/modules/api/context_test.go @@ -19,7 +19,7 @@ import ( "testing" "time" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" "github.com/labstack/echo/v5" "github.com/gotenberg/gotenberg/v8/pkg/gotenberg" @@ -875,7 +875,7 @@ func TestNewContext_DownloadFromRedirectVerdictStaysGeneric(t *testing.T) { fs := gotenberg.NewFileSystem(new(gotenberg.OsMkdirAll)) // The first hop is allowed, the redirect target is denied by the deny-list. - denyList := []*regexp2.Regexp{regexp2.MustCompile("^"+regexp.QuoteMeta(private.URL), 0)} + denyList := []*regexp2.Regexp{regexp2.MustCompile("^"+regexp.QuoteMeta(private.URL), regexp2.None)} _, cancel, err := newContext(echoCtx, logger, fs, 10*time.Second, 0, downloadFromConfig{ denyList: denyList, diff --git a/pkg/modules/chromium/browser.go b/pkg/modules/chromium/browser.go index ca54fb76..8dbfbbd9 100644 --- a/pkg/modules/chromium/browser.go +++ b/pkg/modules/chromium/browser.go @@ -17,7 +17,7 @@ import ( "github.com/chromedp/cdproto/page" "github.com/chromedp/cdproto/runtime" "github.com/chromedp/chromedp" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" "github.com/shirou/gopsutil/v4/process" "github.com/gotenberg/gotenberg/v8/pkg/gotenberg" diff --git a/pkg/modules/chromium/chromium.go b/pkg/modules/chromium/chromium.go index d384c05d..0c5b8829 100644 --- a/pkg/modules/chromium/chromium.go +++ b/pkg/modules/chromium/chromium.go @@ -14,7 +14,7 @@ import ( "github.com/alexliesenfeld/health" "github.com/chromedp/cdproto/network" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" flag "github.com/spf13/pflag" "go.opentelemetry.io/otel/attribute" "go.opentelemetry.io/otel/codes" diff --git a/pkg/modules/chromium/events.go b/pkg/modules/chromium/events.go index 1deb7722..984babc1 100644 --- a/pkg/modules/chromium/events.go +++ b/pkg/modules/chromium/events.go @@ -19,7 +19,7 @@ import ( "github.com/chromedp/cdproto/page" "github.com/chromedp/cdproto/runtime" "github.com/chromedp/chromedp" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" "golang.org/x/sync/errgroup" "github.com/gotenberg/gotenberg/v8/pkg/gotenberg" diff --git a/pkg/modules/chromium/pinning_proxy.go b/pkg/modules/chromium/pinning_proxy.go index 0f4a3cd1..4fcf2798 100644 --- a/pkg/modules/chromium/pinning_proxy.go +++ b/pkg/modules/chromium/pinning_proxy.go @@ -14,7 +14,7 @@ import ( "sync/atomic" "time" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" "golang.org/x/net/http/httpproxy" "github.com/gotenberg/gotenberg/v8/pkg/gotenberg" diff --git a/pkg/modules/chromium/pinning_proxy_test.go b/pkg/modules/chromium/pinning_proxy_test.go index 7ebb17f7..089e6232 100644 --- a/pkg/modules/chromium/pinning_proxy_test.go +++ b/pkg/modules/chromium/pinning_proxy_test.go @@ -18,7 +18,7 @@ import ( "testing" "time" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" "github.com/gotenberg/gotenberg/v8/pkg/gotenberg" ) diff --git a/pkg/modules/chromium/pinning_proxy_upstream_test.go b/pkg/modules/chromium/pinning_proxy_upstream_test.go index 0da6f6e4..858476e0 100644 --- a/pkg/modules/chromium/pinning_proxy_upstream_test.go +++ b/pkg/modules/chromium/pinning_proxy_upstream_test.go @@ -14,7 +14,7 @@ import ( "testing" "time" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" "github.com/gotenberg/gotenberg/v8/pkg/gotenberg" ) diff --git a/pkg/modules/chromium/routes.go b/pkg/modules/chromium/routes.go index e960dd38..d1bf08e6 100644 --- a/pkg/modules/chromium/routes.go +++ b/pkg/modules/chromium/routes.go @@ -14,7 +14,7 @@ import ( "strings" "time" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" "github.com/gomarkdown/markdown" "github.com/labstack/echo/v5" "github.com/microcosm-cc/bluemonday" diff --git a/pkg/modules/chromium/scopebudget_test.go b/pkg/modules/chromium/scopebudget_test.go index 774dfb14..c4d6a2ad 100644 --- a/pkg/modules/chromium/scopebudget_test.go +++ b/pkg/modules/chromium/scopebudget_test.go @@ -6,7 +6,7 @@ import ( "testing" "time" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" "github.com/gotenberg/gotenberg/v8/pkg/gotenberg" ) diff --git a/pkg/modules/libreoffice/api/proxy.go b/pkg/modules/libreoffice/api/proxy.go index 467583f7..728ea802 100644 --- a/pkg/modules/libreoffice/api/proxy.go +++ b/pkg/modules/libreoffice/api/proxy.go @@ -14,7 +14,7 @@ import ( "sync" "time" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" "golang.org/x/net/http/httpproxy" "github.com/gotenberg/gotenberg/v8/pkg/gotenberg" diff --git a/pkg/modules/libreoffice/api/proxy_test.go b/pkg/modules/libreoffice/api/proxy_test.go index 6dc1015a..c8692dee 100644 --- a/pkg/modules/libreoffice/api/proxy_test.go +++ b/pkg/modules/libreoffice/api/proxy_test.go @@ -17,14 +17,14 @@ import ( "testing" "time" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" ) func compileRegexes(t *testing.T, patterns ...string) []*regexp2.Regexp { t.Helper() out := make([]*regexp2.Regexp, 0, len(patterns)) for _, p := range patterns { - r, err := regexp2.Compile(p, 0) + r, err := regexp2.Compile(p, regexp2.None) if err != nil { t.Fatalf("compile %q: %v", p, err) } diff --git a/pkg/modules/webhook/webhook.go b/pkg/modules/webhook/webhook.go index 5b2613cf..4b87e1e5 100644 --- a/pkg/modules/webhook/webhook.go +++ b/pkg/modules/webhook/webhook.go @@ -5,7 +5,7 @@ import ( "sync/atomic" "time" - "github.com/dlclark/regexp2" + "github.com/dlclark/regexp2/v2" flag "github.com/spf13/pflag" "github.com/gotenberg/gotenberg/v8/pkg/gotenberg"