Raise Go to the latest release, update dependencies, use the standard library uuid, add a vulnerability check (closes #102)
check / check (push) Failing after 4s
check / check (push) Failing after 4s
Go 1.27.1 in go.mod and in the Dockerfile's test and build images. Every module go.mod requires is at its current release; protoc-gen-go follows protobuf to v1.36.12 and mf.pb.go is regenerated. The standard library uuid package replaces github.com/google/uuid; FromBytes could only fail on a length validateUUID already checks, so that call and its unreachable error are gone. make vulncheck runs govulncheck v1.8.0, installed with go install at its release commit, in a vulncheck stage of the Dockerfile; script/check does not run it. The newer go directive switches on lint checks for strings.SplitSeq and t.Chdir, now used. A new test pins the bytes of a seeded manifest written by an mfer built before this change. Model: opus-5-5
This commit is contained in:
+17
-5
@@ -11,8 +11,8 @@ RUN golangci-lint run --config .golangci.yml ./...
|
||||
|
||||
# Test phase. -race needs cgo and so a C compiler, which the Debian Go
|
||||
# image ships and the alpine one does not.
|
||||
# golang:1.23.12, 2026-03-14
|
||||
FROM golang@sha256:60deed95d3888cc5e4d9ff8a10c54e5edc008c6ae3fba6187be6fb592e19e8c0 AS test
|
||||
# golang:1.27.1, 2026-10-06
|
||||
FROM golang@sha256:1e93e00a31255c07e9a34c4207f3006e1501730c5323697cee7dfb827fdae44c AS test
|
||||
WORKDIR /src
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
@@ -21,12 +21,24 @@ RUN go test -timeout 90s -race -cover ./... || \
|
||||
{ echo "--- Rerunning with -v for details ---"; \
|
||||
go test -timeout 90s -race -v ./...; exit 1; }
|
||||
|
||||
# Build stage. Nothing is wanted from either phase above; the copies
|
||||
# Vulnerability check, built only by script/vulncheck (make vulncheck).
|
||||
# No stage depends on it, so the image build does not run it.
|
||||
# golang:1.27.1, 2026-10-06
|
||||
FROM golang@sha256:1e93e00a31255c07e9a34c4207f3006e1501730c5323697cee7dfb827fdae44c AS vulncheck
|
||||
# govulncheck v1.8.0, pinned to the commit its release tag names.
|
||||
RUN go install golang.org/x/vuln/cmd/govulncheck@709015412431dd2b5b28a53c06c70bc02d49074c
|
||||
WORKDIR /src
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
COPY . .
|
||||
RUN govulncheck ./...
|
||||
|
||||
# Build stage. Nothing is wanted from the lint or test phase; the copies
|
||||
# are what make BuildKit build them first, so this stage cannot run
|
||||
# unless lint and test passed. The Debian Go image ships git, which the
|
||||
# version step below needs.
|
||||
# golang:1.23.12, 2026-03-14
|
||||
FROM golang@sha256:60deed95d3888cc5e4d9ff8a10c54e5edc008c6ae3fba6187be6fb592e19e8c0 AS builder
|
||||
# golang:1.27.1, 2026-10-06
|
||||
FROM golang@sha256:1e93e00a31255c07e9a34c4207f3006e1501730c5323697cee7dfb827fdae44c AS builder
|
||||
COPY --from=lint /src/go.sum /dev/null
|
||||
COPY --from=test /src/go.sum /dev/null
|
||||
# A tar-stream context keeps the sender's file owners, which git refuses.
|
||||
|
||||
Reference in New Issue
Block a user