Skip to content

fix(deps): raise transitive floors and move to go 1.26 - #6

Merged
shenzhaoyan merged 3 commits into
mainfrom
dependabot/go_modules/go_modules-d60cbccd5d
Sep 17, 2026
Merged

shenzhaoyan merged 3 commits into
mainfrom
dependabot/go_modules/go_modules-d60cbccd5d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Feb 19, 2026

Copy link
Copy Markdown
Contributor

Bumps the go_modules group with 1 update in the / directory: filippo.io/edwards25519.

Updates filippo.io/edwards25519 from 1.1.0 to 1.1.1

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the go_modules group with 1 update in the / directory: [filippo.io/edwards25519](https://github.com/FiloSottile/edwards25519).


Updates `filippo.io/edwards25519` from 1.1.0 to 1.1.1
- [Commits](FiloSottile/edwards25519@v1.1.0...v1.1.1)

---
updated-dependencies:
- dependency-name: filippo.io/edwards25519
  dependency-version: 1.1.1
  dependency-type: indirect
  dependency-group: go_modules
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Feb 19, 2026
@shenzhaoyan

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR is already up-to-date with main! If you'd still like to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

… to go 1.26

The bot's commit on this branch already satisfies the one alert
(filippo.io/edwards25519 to 1.1.1). What it does not reach is everything else
gorm.io/datatypes drags in, none of which Dependabot has opened an alert for:

  golang.org/x/crypto      0.23.0 -> 0.57.0   39 findings
  golang.org/x/text        0.20.0 -> 0.42.0   GO-2026-5970, 8 packages compiled
  golang.org/x/sys         0.35.0 -> 0.48.0   GO-2026-5024, 1 package compiled
  github.com/jackc/pgx/v5  5.5.5  -> 5.11.0   6 findings, incl. the SQL injection
                                              via dollar-quoted placeholders
  golang.org/x/sync        0.17.0 -> 0.23.0   (carried along)
  go directive             1.24.0 -> 1.26.0

All of those come from gorm.io/datatypes v1.2.7, which declares x/crypto 0.23.0,
pgx 5.5.5 and x/text 0.20.0. Moving the parent is not an option — v1.2.7 is its
latest release — so the floors are set directly and MVS takes it from there.

go.mod also gains two indirect lines it did not have, github.com/kr/pretty 0.3.0
and gopkg.in/check.v1: they are pgx 5.11.0's test dependencies, recorded by
go mod tidy. Both are clean on OSV and neither is compiled here.

The go directive is the part worth explaining, because the usual rule for a
library is to keep it as low as the dependencies force, and that would have been
1.25.0. It does not apply here: .github/workflows/go.yml sets
`go-version-file: "go.mod"`, so this line is not only a compatibility floor for
importers, it is also the toolchain CI installs. Go supports the two newest
majors and today those are 1.27 and 1.26, so a 1.25 directive means CI builds on
a toolchain that will not receive another stdlib fix. go1.25.14 happens to be
clean right now; the point is that the next advisory against it will have no
1.25.15 to move to. 1.26.0 keeps CI on a supported line, and stdlib 1.26.8 is
clean.

Raising it also removes the reason x/crypto had to stop at 0.55.0: 0.56.0 is
where x/crypto begins requiring go 1.26.0, and with the directive there it can
go to 0.57.0, taking GO-2026-6354 and GO-2026-6355 with it.

The module graph is now down to a single finding from 49 across 5 modules:
GO-2026-5932 on x/crypto 0.57.0, which has no fixed version — it is the notice
that x/crypto/openpgp is unmaintained — and which this module never compiles
anyway (`go list -deps ./...` finds no x/crypto package; it is in go.sum only
because datatypes names it). govulncheck reports nothing.

Verified against the workflow's own commands: `go build -v ./...`, `go vet`, and
`go test -short -p=1 -count=1 -failfast -timeout=10m -coverprofile -coverpkg`
all pass at 88.4% coverage, as they did before the change.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@shenzhaoyan shenzhaoyan changed the title Bump filippo.io/edwards25519 from 1.1.0 to 1.1.1 in the go_modules group across 1 directory fix(deps): raise transitive floors and move to go 1.26 Sep 17, 2026
CI went red on the previous commit:

  can't load config: the Go language version (go1.24) used to build
  golangci-lint is lower than the targeted Go version (1.26.0)

The workflow pins golangci-lint v1.64.8, which is built with go1.24.1 and
refuses any config targeting a higher Go. That is not specific to 1.26: the same
binary rejects a 1.25.0 target too, so raising the directive at all would have
broken this gate. The last green run on this branch was the bot's own commit,
where go.mod still said 1.24.0 — not, as I said earlier, a run of the 1.25.0
version of this change, which was never pushed.

The v1 line ended at v1.64.x when v2 shipped, so there is no v1 build on a newer
Go to move to. The pin goes to v2.13.2 (built with go1.27.0), and the action to
v9 — golangci-lint-action requires v8 or later to drive a v2 linter.

v2 then reports ten unchecked `Close()` calls in tests that v1 never showed.
Those are not new code and not caused by the Go bump: running v2.13.2 against
the bot's commit, with go.mod back at 1.24.0, reports exactly the same ten. v1
shipped a default exclusion list that waived errcheck on Close and friends, and
v2 dropped it. Since this repo carries no .golangci.yml and has always run on
the defaults, the defaults are followed rather than pinned back with new config:

  benchmark_test.go   2   deferred l1Cache/notFoundCache Close
  bigcache_test.go    1   inside tb.Cleanup
  entry_test.go       1   deferred
  redis_test.go       3   one direct, two deferred
  transform_test.go   3   inside t.Cleanup

Each becomes `_ = x.Close()`, with the deferred ones wrapped as
`defer func() { _ = x.Close() }()`. No test behaviour changes — the error was
discarded before and is discarded explicitly now.

Verified: golangci-lint v2.13.2 reports 0 issues, and `go build -v ./...`,
`go vet ./...` and `go test -short -p=1 -count=1 -failfast -timeout=10m` still
pass at 88.4% coverage.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@shenzhaoyan
shenzhaoyan merged commit 96e7660 into main Sep 17, 2026
1 check passed
@shenzhaoyan
shenzhaoyan deleted the dependabot/go_modules/go_modules-d60cbccd5d branch September 17, 2026 11:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant