fix(deps): raise transitive floors and move to go 1.26 - #6
Merged
Merged
Conversation
Bumps the go_modules group with 1 update in the / directory: [filippo.io/edwards25519](https://github.com/FiloSottile/edwards25519). Updates `filippo.io/edwards25519` from 1.1.0 to 1.1.1 - [Commits](FiloSottile/edwards25519@v1.1.0...v1.1.1) --- updated-dependencies: - dependency-name: filippo.io/edwards25519 dependency-version: 1.1.1 dependency-type: indirect dependency-group: go_modules ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
|
@dependabot rebase |
Contributor
Author
|
Looks like this PR is already up-to-date with main! If you'd still like to recreate it from scratch, overwriting any edits, you can request |
… to go 1.26
The bot's commit on this branch already satisfies the one alert
(filippo.io/edwards25519 to 1.1.1). What it does not reach is everything else
gorm.io/datatypes drags in, none of which Dependabot has opened an alert for:
golang.org/x/crypto 0.23.0 -> 0.57.0 39 findings
golang.org/x/text 0.20.0 -> 0.42.0 GO-2026-5970, 8 packages compiled
golang.org/x/sys 0.35.0 -> 0.48.0 GO-2026-5024, 1 package compiled
github.com/jackc/pgx/v5 5.5.5 -> 5.11.0 6 findings, incl. the SQL injection
via dollar-quoted placeholders
golang.org/x/sync 0.17.0 -> 0.23.0 (carried along)
go directive 1.24.0 -> 1.26.0
All of those come from gorm.io/datatypes v1.2.7, which declares x/crypto 0.23.0,
pgx 5.5.5 and x/text 0.20.0. Moving the parent is not an option — v1.2.7 is its
latest release — so the floors are set directly and MVS takes it from there.
go.mod also gains two indirect lines it did not have, github.com/kr/pretty 0.3.0
and gopkg.in/check.v1: they are pgx 5.11.0's test dependencies, recorded by
go mod tidy. Both are clean on OSV and neither is compiled here.
The go directive is the part worth explaining, because the usual rule for a
library is to keep it as low as the dependencies force, and that would have been
1.25.0. It does not apply here: .github/workflows/go.yml sets
`go-version-file: "go.mod"`, so this line is not only a compatibility floor for
importers, it is also the toolchain CI installs. Go supports the two newest
majors and today those are 1.27 and 1.26, so a 1.25 directive means CI builds on
a toolchain that will not receive another stdlib fix. go1.25.14 happens to be
clean right now; the point is that the next advisory against it will have no
1.25.15 to move to. 1.26.0 keeps CI on a supported line, and stdlib 1.26.8 is
clean.
Raising it also removes the reason x/crypto had to stop at 0.55.0: 0.56.0 is
where x/crypto begins requiring go 1.26.0, and with the directive there it can
go to 0.57.0, taking GO-2026-6354 and GO-2026-6355 with it.
The module graph is now down to a single finding from 49 across 5 modules:
GO-2026-5932 on x/crypto 0.57.0, which has no fixed version — it is the notice
that x/crypto/openpgp is unmaintained — and which this module never compiles
anyway (`go list -deps ./...` finds no x/crypto package; it is in go.sum only
because datatypes names it). govulncheck reports nothing.
Verified against the workflow's own commands: `go build -v ./...`, `go vet`, and
`go test -short -p=1 -count=1 -failfast -timeout=10m -coverprofile -coverpkg`
all pass at 88.4% coverage, as they did before the change.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
shenzhaoyan
approved these changes
Sep 17, 2026
CI went red on the previous commit:
can't load config: the Go language version (go1.24) used to build
golangci-lint is lower than the targeted Go version (1.26.0)
The workflow pins golangci-lint v1.64.8, which is built with go1.24.1 and
refuses any config targeting a higher Go. That is not specific to 1.26: the same
binary rejects a 1.25.0 target too, so raising the directive at all would have
broken this gate. The last green run on this branch was the bot's own commit,
where go.mod still said 1.24.0 — not, as I said earlier, a run of the 1.25.0
version of this change, which was never pushed.
The v1 line ended at v1.64.x when v2 shipped, so there is no v1 build on a newer
Go to move to. The pin goes to v2.13.2 (built with go1.27.0), and the action to
v9 — golangci-lint-action requires v8 or later to drive a v2 linter.
v2 then reports ten unchecked `Close()` calls in tests that v1 never showed.
Those are not new code and not caused by the Go bump: running v2.13.2 against
the bot's commit, with go.mod back at 1.24.0, reports exactly the same ten. v1
shipped a default exclusion list that waived errcheck on Close and friends, and
v2 dropped it. Since this repo carries no .golangci.yml and has always run on
the defaults, the defaults are followed rather than pinned back with new config:
benchmark_test.go 2 deferred l1Cache/notFoundCache Close
bigcache_test.go 1 inside tb.Cleanup
entry_test.go 1 deferred
redis_test.go 3 one direct, two deferred
transform_test.go 3 inside t.Cleanup
Each becomes `_ = x.Close()`, with the deferred ones wrapped as
`defer func() { _ = x.Close() }()`. No test behaviour changes — the error was
discarded before and is discarded explicitly now.
Verified: golangci-lint v2.13.2 reports 0 issues, and `go build -v ./...`,
`go vet ./...` and `go test -short -p=1 -count=1 -failfast -timeout=10m` still
pass at 88.4% coverage.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the go_modules group with 1 update in the / directory: filippo.io/edwards25519.
Updates
filippo.io/edwards25519from 1.1.0 to 1.1.1Commits
d1c650aextra: initialize receiver in MultiScalarMultDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.