fix(deps): update module github.com/pion/dtls/v2 to v3 - #1726
Open
renovate[bot] wants to merge 1 commit into
Open
fix(deps): update module github.com/pion/dtls/v2 to v3#1726renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/github.com-pion-dtls-v2-3.x
branch
19 times, most recently
from
August 23, 2026 17:45
69040fc to
24fc9b6
Compare
renovate
Bot
force-pushed
the
renovate/github.com-pion-dtls-v2-3.x
branch
from
August 23, 2026 21:18
24fc9b6 to
4fd717f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v2.2.8-0.20240501061905-2c36d63320a0→v3.1.5Release Notes
pion/dtls (github.com/pion/dtls/v2)
v3.1.5Compare Source
Changelog
9c642f8Unblock reads when conn is closede2959fdRemove the obsolete Go 1.14 build tag8674b27Update actions/checkout action to v78f512dcUpdate module github.com/pion/transport/v4 to v4.0.2 (#836)1ce56abUpdate dtls-1.2 branch namebc02e81Document main-branch tagging freezev3.1.4Compare Source
Changelog
e4aad60Retact v3.1.3 for breaking compatiblity with firefox0e3867bRestore Firefox compatibility12eb398Fix panic unmarshaling ECDHE_PSK ServerKeyExchange85fca0aAdd MasterKeyIdentifier to use_srtp ext in flight3 (#835)fd27a52Add private min and max version API (#823)620d642Improve fuzzing for all extensions (#805)977de19Update CI configs to v0.12.2e6950f0Filter non-approved FIPS curves in FIPS mode (#817)848c4bcOptimize handshake memory usaged0e736cDTLS 1.3 OID filter extension (#814)956d41dUpdate module golang.org/x/crypto to v0.48.0 (#809)b86cb75Add missing checks and validations726522dApply modernize and lint upgradesd994b8bUpdate CI configs to v0.12.14fcce60Fix handshake hang on Finish in retransmit statea25c8b8Add ListenConfig option to Listener42b83feRemove custom AddUint48 helper5a4e85aDTLS 1.3 Add the Certificate Authorities extension (#807)812fc22DTLS 1.3 post handshake auth extension (#806)39f3100DTLS 1.3 Add EarlyDataIndication extension (#804)d1d58f2Update CI configs to v0.12.016413baAdd HKDF funcs for Key Scheduling - DTLS v1.3 (#737)accee59Implement ChaCha20-Poly1305 Ciphersuite (#794)6b4fe8cAdd RSA_PSS_RSAE back to DTLS 1.2 and fix parsing (#801)5ee9206Upgrade E2E Test Docker Image (for OpenSSL 3.x) (#799)v3.1.3Compare Source
Changelog
49458d6Fix panic unmarshaling ECDHE_PSK ServerKeyExchangee4b257dAdd MasterKeyIdentifier to use_srtp ext in flight3 (#835)fd27a52Add private min and max version API (#823)620d642Improve fuzzing for all extensions (#805)977de19Update CI configs to v0.12.2e6950f0Filter non-approved FIPS curves in FIPS mode (#817)848c4bcOptimize handshake memory usaged0e736cDTLS 1.3 OID filter extension (#814)956d41dUpdate module golang.org/x/crypto to v0.48.0 (#809)b86cb75Add missing checks and validations726522dApply modernize and lint upgradesd994b8bUpdate CI configs to v0.12.14fcce60Fix handshake hang on Finish in retransmit statea25c8b8Add ListenConfig option to Listener42b83feRemove custom AddUint48 helper5a4e85aDTLS 1.3 Add the Certificate Authorities extension (#807)812fc22DTLS 1.3 post handshake auth extension (#806)39f3100DTLS 1.3 Add EarlyDataIndication extension (#804)d1d58f2Update CI configs to v0.12.016413baAdd HKDF funcs for Key Scheduling - DTLS v1.3 (#737)accee59Implement ChaCha20-Poly1305 Ciphersuite (#794)6b4fe8cAdd RSA_PSS_RSAE back to DTLS 1.2 and fix parsing (#801)5ee9206Upgrade E2E Test Docker Image (for OpenSSL 3.x) (#799)v3.1.2Compare Source
Changelog
a621789Retract v3.1.01beb12fFix OpenSSL Interop for RSA SignatureHashAlgos605dc7eUpdate module golang.org/x/crypto to v0.45.0 [SECURITY] (#756)2d6d27fUpdate CI configs to v0.11.39v3.1.1Compare Source
Changelog
fa21c26Retract v3.1.0dc45e23Fix OpenSSL Interop for RSA SignatureHashAlgosv3.1.0Compare Source
Options patterns, Security fix and performance improvements.
Changelog
61762deUse sequence number for nonce in GCM ciphers (#796)46ee7c3Refactor Common AEAD Code in Ciphersuite Package (#789)10bd10aPrefer server srtp protection profiles ordering93c2677Fix rare flaky testd46d2a7Fix Bug in signature_algorithms_cert Handling (#791)acad848DTLS 1.3 signature_algorithms_cert Extension (#788)0a5b311Introduce options patterns9495befDTLS 1.3 RSA-PSS Signature Scheme Support (#778)f1c63e9Refactor error types for 1.3 extensions (#787)bed33feAdd PreSharedKey extensions for DTLS 1.3 (#773)01f7ba5Update CI configs to v0.11.375b824b0CCM Encrypt Speed + Memory Mgmt Improvements (#784)100a3aaGCM Speed + Memory Mgmt Improvements (#783)199a753Add Ciphersuite Benchmark Tests (#781)6b2fbf1Fix Race Condition in TestListenerCustomConnIDs (#782)8ea3afcFix intermittent unit test failures (#780)c6db81bUpdate README44160f0DTLS 1.3 CertificateRequest + Certificate Messages (#774)9121462Add Cookie extension for DTLS 1.3 (#770)v3.0.11Compare Source
Backport security fix for GHSA-9f3f-wv7r-qc8r (CVE-2026-26014)
This is the only release with the security fix for Go v1.21.
v3.0.10Compare Source
Changelog
713910aUpgrade to pion/transport/v4e0d3160Add the key share extension (#749)7a57e26Update CI configs to v0.11.3608d8c3eFix gosec slice bounds warnings (#764)7b9612eHandshake fragments assembly refactoring (#762)v3.0.9Compare Source
Changelog
ab5f89bImplement TLS_EMPTY_RENEGOTIATION_INFO_SCSVd5761acPrevent negative intervalsv3.0.8Compare Source
Changelog
ffd97f5Backoff handshake retransmit7ab1bc9Update actions/checkout action to v6bdb5f23Update module github.com/pion/transport/v3 to v3.1.1 (#754)1d9b6b1Update module github.com/pion/transport/v3 to v3.1.0c06c3a7Lock while writing to encryptedPacketsca7d80eUpdate CI configs to v0.11.329cfb13fImprove the record layer fuzz testsdaa0fd4Add fuzz tests for gcm9ed5950Add fuzz tests for ccm7b68bd9Add fuzz tests for packet buffer7c62411Update CI configs to v0.11.313e12f76Add more tests for prfe7cbd62Migrate elliptic curves from elliptic to ecdh6ff535fUpdate module github.com/pion/transport/v3 to v3.0.8f6b0286Add the supported_versions extension120a895Handle ECONNREFUSED timeouted044c0Update CI configs to v0.11.295611b14Apply go modernize27c3405Update actions/checkout action to v58764fbdUpdate CI configs to v0.11.26465f544Update CI configs to v0.11.256e1e3c9Update module github.com/stretchr/testify to v1.11.1495a7b5Update CI configs to v0.11.240b11eabUpdate module github.com/stretchr/testify to v1.11.0b8c2ab4Fix lint issues with golangci-lint@v20bf1902Update CI configs to v0.11.22v3.0.7Compare Source
Changelog
e3cf6bcComply with RFC5746 and RFC5246f0c0987Update module github.com/pion/logging to v0.2.463bf30cUpdate CI configs to v0.11.2034fbe21Replace interface{} with any8bf2c71Fix packet buffer read index after buffer resize806ff2fRefactor cfg.onFlightState, avoid data racef5e908fUpdate CI configs to v0.11.1958d3b7eUpdate lint rules, force testify/asserte57dc04Update social media links, move to discordv3.0.6Compare Source
What's Changed
Full Changelog: pion/dtls@v3.0.5...v3.0.6
v3.0.5Compare Source
Changelog
fbc7baeUpdate docker.io/library/golang Docker tag to v1.24 (#694)13b929bUpdate module golang.org/x/net to v0.37.0 (#697)3a0f50aUse crypto.Signer whenever possible (#681)16d6306Update module golang.org/x/net to v0.34.0 (#693)8eb9a91Upgrade golangci-lint, more linters1c0df61Update module github.com/pion/logging to v0.2.3 (#691)1e4ae60Update module golang.org/x/net to v0.33.0 [SECURITY]ceb8458Update module golang.org/x/crypto to v0.31.0 [SECURITY]4e34db5Update module golang.org/x/net to v0.31.002434c7Update module golang.org/x/crypto to v0.29.0v3.0.4Compare Source
Changelog
b3e02c4Update module golang.org/x/net to v0.30.03f61fd2Fix RSA signature verification issued796437Improve fuzzingv3.0.3Compare Source
Changelog
98a05d6Fix incorrect client retransmissionsd7f5feeUpdate module golang.org/x/net to v0.29.00be603aUpdate module golang.org/x/crypto to v0.27.00790369Update module golang.org/x/net to v0.28.0f13eec1Update module golang.org/x/crypto to v0.26.0e193dc2Update go.mod version to 1.20v3.0.2Compare Source
Changelog
1a02350Fix race between Conn.Close and Conn.Handshake032d60cUpdate CI configs to v0.11.15f6ecbc2Update docker.io/library/golang Docker tag to v1.23fd18984Fix pkg.go.dev linkv3.0.1Compare Source
Changelog
e20b162Fix multiple calls to Handshakef3e8a9eFix segfault in State::serialize method5a72b12Update module github.com/pion/transport/v3 to v3.0.7c5ab822Update module golang.org/x/net to v0.27.023674bdUpdate module golang.org/x/crypto to v0.25.07ab74fbAdd support for MKI in use_srtp7139e0eFix time units in example2ed7caaUpdate module github.com/pion/transport/v3 to v3.0.6v3.0.0Compare Source
Pion DTLS v3.0.0 is now available. Pion DTLS is a Go implementation of DTLS. It allows for secure communication over UDP. It is commonly used for VPNs, WebRTC and other real-time protocols.
This release includes 115 commits from 17 authors. This release added Connection Identifiers, concurrent handshaking when Accepting inbound connections, Censorship Circumvention and better resilience against packet loss during handshaking.
A special thank you to kevmo314 and hasheddan for all their hard work on making this release happen.
This release contains breaking changes. Please read the following carefully, the breakage can't be caught at compile time. Each change will have a linked commit. Looking at
examples/in the linked commit should show what code you need to change in your application.Breaking Changes
Before
/v2Pion DTLS would handshake on Server or Client creation. This design caused theAcceptimplementation to be blocking. A new connection couldn't be accept until the previous one had finished.This design also doesn't match the
crypto/tlsimplementation in stdlib. This mismatch would cause frustration/confusion for users.Now the handshaking only occurs when
Read,WriteorHandshakeis called. In most cases users shouldn't notice a difference.If you do want a Handshake performed without a
ReadorWritethis is the change needed.Before
After
This change was made in e4064683
New Features
Connection IDs
Connection IDs is a new feature added to the DTLS protocol itself. This change allows for clients to change IPs/Ports during a session. This allows for devices to roam (like phones) or for low power devices to shut down and reconnect without losing their DTLS session!
Connection ID generation is pluggable via the dtls.Config structure, and a random CID generator with a static size is provided for convenience. A new example has been added to demonstrate this functionality.
For those interested in digging deeper into the full set of changes, the majority of work was done in #570.
Censorship Circumvention
Software that is used to circumvent censorship like snowflake uses Pion. To block this (and other) software goverments have looked for patterns and differences in Pion DTLS and blocked it.
This new release contains hooks that allows users to randomize and circumvent these blocks. Users can modify ClientHello, ServerHello and CertificateRequest. Users can also smuggle information in a ServerHello/ClientHello RandomBytes.
You can see them all here here
Changelog
The complete log between v2.2.7 and v3.0.0:
0a8d838Prepare /v3b6fd38eUpdate module github.com/pion/transport/v3 to v3.0.5e406468Perform handshake on first read/write6178064Mark NULL and AES256CM SRTP ciphers as supportedbc3159aAdded DTLS-SRTP IDs for NULL and AES256CM ciphersd013d0cOn Read Retransmit send FSM to SENDINGec76652Retransmit last flight when in finished602dc71Make localConnectionID thread safe0a1b73aRespect disableRetransmitBackoffa6d9640Add OnConnectionAttempt to Config48d6748Implement retransmit backoff according to 4.2.4.145e16a0Update module golang.org/x/net to v0.26.0a5d1facFlight3: respect curves configuration61b3466Add ability to select cert based on ch rand byteseddca22Update module golang.org/x/crypto to v0.24.0edc7ad0Limit size of encrypted packet queuefbbdf66Update module golang.org/x/net to v0.25.0efd6737Add test for PSK and Identitycb62aacFix typo in test494c1a3Remove testify dependencyadec94aUpdate golang Docker tag to v1.228738ce1Add handshake hooking2c36d63Update module golang.org/x/net to v0.24.0d606c79Update module golang.org/x/crypto to v0.22.0f6f666eUpdate module golang.org/x/net to v0.23.0 [SECURITY]e008bc4Update CI configs to v0.11.123e667b0Update go.mod version to 1.19ae51db9Update CI configs to v0.11.78244c45Update CI configs to v0.11.40ad9cfdUpdate module github.com/pion/transport/v3 to v3.0.28a93e0eFix TestErrorsTemporary38e39e4Update module golang.org/x/net to v0.22.0a245727Update module golang.org/x/crypto to v0.21.05e95b5cUpdate module github.com/stretchr/testify to v1.9.035a00d3Fix linter errors96b8c29Fix linter errors2597464Update module golang.org/x/net to v0.20.042b6772Update module golang.org/x/crypto to v0.18.0bb54a30If not found in the cache return nil3427819Format code798b32aFix flight1parse processing exceptionba72fbaUpdate CI configs to v0.11.3520d84cUpdate CI configs to v0.11.0cfa868cRemove 'AUTHORS.txt' from README.mdb4a403cRemove 'Generate Authors' workflow9ffd96cDrop invalid record silently during handshake3e8a7d7Update module golang.org/x/crypto to v0.17.0 [SECURITY]dc751e3Update module golang.org/x/net to v0.19.03f3d833Update module golang.org/x/crypto to v0.16.0a8f7062Use atomic to avoid stale SRTP protection profile9cc3df9Respect Algorithm value in CertificateRequest7faf25fUpdate module golang.org/x/net to v0.17.0 [SECURITY]c864545Update module golang.org/x/net to v0.15.028431d9Export CipherSuiteID in connection State8401874Update module golang.org/x/crypto to v0.13.0744e27aUpdate actions/checkout action to v42b584afSpecifying underlying type of conn ID atomic.Value70caf30Use atomic.Value to maintain Go 1.13 compatibility60064c6Update module github.com/pion/transport/v3 to v3.0.1ef50d6bUpdate AUTHORS.txt7e5003aUpdate AUTHORS.txtdbc7fd9Update module github.com/pion/transport/v3 to v3.0.0a681f67Correctly identify client and server with PSK IDe85f106Update module github.com/pion/transport/v2 to v2.2.27bf18f8Update module golang.org/x/net to v0.14.0609e5beClear CIDs on potential session resumptione142ee1Serialize CIDs in state37fbc04Add CID send only client example6df50a6Add CID listener examplef5875c1Set UDP routing if CID is enablede663309Add CID routing unit tests9db84b5Add CID based datagram routinga8998afAdd UDP net.PacketListener unit tests71db42bIntroduce UDP net.PacketListener3afeb7dAdd PacketBuffer unit testseb305b1Introduce net PacketBuffer703da0cConsume net package in tests4f53ce1Introduce net packagef1d8b0aWrap Alerts when CID is negotiated3082313Convert nil CIDs to empty byte slice83b1254Fix name of cipher suite initialization function818feb8Set timeout to 10 minutes on e2e workflowd29c6f0Add basic connection ID generators2f2bc8dAdd e2e CID testsee04141Update tests to wrap net.Connf960a37Wrap net.Conn in DTLS listenerafb61f1Update DTLS Conn to use PacketConn and CIDd082911Add Conn to PacketConn utilitye5420deUpdate handshaker to handle CID extension8922879Update ciphersuites to support CIDs8ba47cbImplement AEAD additional data with CID27fd131Add local and remote CID to state9a37bfdImplement AddUint48 utility1ce6f27Add CID content type6af61b1Allow packets to specify CID wrappedb7b1e44Add support for CID related generators2005135Add support for parsing CID records9e4a4e7Add DTLS connection ID extensione9b3ce0Update pion/transport to latesta1d270fUpdate module golang.org/x/crypto to v0.12.0a6eca6cUpdate CI configs to v0.10.11eb34e7dUpdate module golang.org/x/net to v0.13.0c9eb5f2Update module golang.org/x/net to v0.12.0b033847Clean up unneccessary nested logic7307f62Fix return of nil alertErrorsb905606Add unmarshal unit tests for extensions0736d45Fix parsing supported EC point formats93704b3Add Daniel Mangum to AUTHORS.txtcabe5b8Enable Supported Signature Algorithms265bf11Enable Elliptic Curve Supported Point Formatsd7303d0Wait for OpenSSL server shutdown in e2e test159122fUpdate e2e Go image to 1.208a11cf2Remove extraneous error checks in handshaker4fc3d8fUpdate module golang.org/x/net to v0.11.04b76abfUpdate module golang.org/x/crypto to v0.10.0v2.2.12Compare Source
Changelog
48e76ccMark NULL and AES256CM SRTP ciphers as supported8cd9236Added DTLS-SRTP IDs for NULL and AES256CM ciphersv2.2.11Compare Source
Changelog
9f5ddebsimplify error type check3f0bd2aFix typing for alertErrors24571ecremove unused vars, factor out functioncfeb9caLimit size of encrypted packet queuev2.2.10Compare Source
Changelog
ebdb8bdUpdate dependenciesv2.2.9Compare Source
Changelog
d391e69Drop invalid record silently during handshakeConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.