Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Nov 3, 2025

Bumps tailscale.com from 1.68.0 to 1.90.6.

Release notes

Sourced from tailscale.com's releases.

v1.90.6

Please refer to the changelog available at https://tailscale.com/changelog

v1.90.4

Please refer to the changelog available at https://tailscale.com/changelog

v1.90.3

Please refer to the changelog available at https://tailscale.com/changelog

v1.90.2

Please refer to the changelog available at https://tailscale.com/changelog

v1.90.1

Please refer to the changelog available at https://tailscale.com/changelog

v1.88.3

Please refer to the changelog available at https://tailscale.com/changelog

v1.88.1

Please refer to the changelog available at https://tailscale.com/changelog

v1.86.2

Please refer to the changelog available at https://tailscale.com/changelog

v1.86.0

Please refer to the changelog available at https://tailscale.com/changelog

v1.84.2

Please refer to the changelog available at https://tailscale.com/changelog

v1.84.1

Please refer to the changelog available at https://tailscale.com/changelog

v1.84.0

Please refer to the changelog available at https://tailscale.com/changelog.

v1.82.5

Please refer to the changelog available at https://tailscale.com/changelog.

v1.82.0

Please refer to the changelog available at https://tailscale.com/changelog.

v1.80.3

Please refer to the changelog available at https://tailscale.com/changelog.

v1.80.2

Please refer to the changelog available at https://tailscale.com/changelog.

v1.80.1

Please refer to the changelog available at https://tailscale.com/changelog.

... (truncated)

Commits
  • 28f6c2d VERSION.txt: this is v1.90.6
  • b6eabd4 util/eventbus: allow logging of slow subscribers (#17705)
  • 6e2f2bb ipn/ipnlocal: do not stall event processing for appc route updates (#17663)
  • faca4c0 .github/workflows: pin the google/oss-fuzz GitHub Actions
  • 6324200 VERSION.txt: this is v1.90.5
  • 300e606 cmd/k8s-operator/generate: skip tests if no network or Helm is down
  • 1a6c315 sessionrecording: fix regression in recent http2 package change
  • 68cba30 VERSION.txt: this is v1.90.4
  • 2dd72f6 Revert "logtail: avoid racing eventbus subscriptions with Shutdown (#17639)" ...
  • 53004dd wgengine/magicsock: fix js/wasm crash regression loading non-existent portmapper
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Greptile Overview

Updated On: 2025-11-03 16:37:27 UTC

Greptile Summary

This PR updates tailscale.com from v1.68.0 to v1.90.6, a significant jump of 22 minor versions that includes numerous bug fixes and improvements. The update also bumps the Go version requirement from 1.24.0 to 1.25.3.

Key Changes:

  • Major version jump for tailscale.com dependency (v1.68.0 → v1.90.6)
  • Go toolchain upgraded from 1.24.0 to 1.25.3
  • Several transitive dependencies removed as they're no longer required by Tailscale
  • Many transitive dependencies updated to newer versions
  • The codebase uses tailscale.com/tsnet for setting up Tailscale networking in services/authz/server/tailscale.go

Testing Recommendations:

  • Verify Tailscale tsnet server initialization works correctly
  • Test the Tailscale listener setup and authentication flow
  • Ensure IP validation logic for Tailscale network (100.64.0.0/10) still functions
  • Run integration tests with Tailscale authentication if available
  • Verify builds succeed with Go 1.25.3

Confidence Score: 4/5

  • This PR is reasonably safe to merge with proper testing - it's an automated dependency update with a significant version jump that requires verification
  • Score of 4 reflects that while this is an automated Dependabot update with proper checksums, it includes a major version jump (22 minor versions) for tailscale.com and a Go version upgrade. The large version gap increases the risk of breaking changes or behavioral differences. The codebase uses tsnet.Server for Tailscale networking, and this API surface should be tested. However, Tailscale generally maintains backwards compatibility well, and the checksums are properly updated.
  • Pay close attention to services/authz/server/tailscale.go behavior in runtime testing - verify Tailscale networking still functions correctly

Important Files Changed

File Analysis

Filename Score Overview
go.mod 4/5 Major dependency update from tailscale.com v1.68.0 to v1.90.6 (22 minor versions), Go version bump from 1.24.0 to 1.25.3, removed several indirect dependencies, updated many transitive dependencies
go.sum 4/5 Checksums updated for all modified dependencies including new transitive deps and removed obsolete ones, consistent with go.mod changes

Sequence Diagram

sequenceDiagram
    participant D as Dependabot
    participant GM as go.mod
    participant GS as go.sum
    participant TS as tailscale.com
    participant TD as Transitive Dependencies

    D->>GM: Update tailscale.com from v1.68.0 to v1.90.6
    D->>GM: Bump Go version from 1.24.0 to 1.25.3
    GM->>TD: Remove obsolete dependencies
    Note over GM,TD: bits-and-blooms/bitset<br/>coreos/go-iptables<br/>digitalocean/go-smbios<br/>gorilla/csrf & securecookie<br/>and others
    GM->>TD: Update transitive dependencies
    Note over GM,TD: fxamacker/cbor v2.5.0→v2.7.0<br/>gaissmai/bart v0.4.1→v0.18.0<br/>mdlayher/netlink updated<br/>and many others
    GM->>TS: Pull new API surface
    TS->>GM: Return v1.90.6 with 22 versions of changes
    D->>GS: Update all checksums
    GS->>GS: Add new dependency hashes
    GS->>GS: Remove obsolete hashes
Loading

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [tailscale.com](https://github.com/tailscale/tailscale) from 1.68.0 to 1.90.6.
- [Release notes](https://github.com/tailscale/tailscale/releases)
- [Commits](tailscale/tailscale@v1.68.0...v1.90.6)

---
updated-dependencies:
- dependency-name: tailscale.com
  dependency-version: 1.90.6
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Nov 3, 2025
Copy link

@greptile-apps greptile-apps bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

2 files reviewed, no comments

Edit Code Review Agent Settings | Greptile

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant