Raise Go to the latest release, update dependencies, use the standard library uuid, add a vulnerability check (closes #102)
check / check (push) Failing after 4s
check / check (push) Failing after 4s
Go 1.27.1 in go.mod and in the Dockerfile's test and build images. Every module go.mod requires is at its current release; protoc-gen-go follows protobuf to v1.36.12 and mf.pb.go is regenerated. The standard library uuid package replaces github.com/google/uuid; FromBytes could only fail on a length validateUUID already checks, so that call and its unreachable error are gone. make vulncheck runs govulncheck v1.8.0, installed with go install at its release commit, in a vulncheck stage of the Dockerfile; script/check does not run it. The newer go directive switches on lint checks for strings.SplitSeq and t.Chdir, now used. A new test pins the bytes of a seeded manifest written by an mfer built before this change. Model: opus-5-5
This commit is contained in:
@@ -23,7 +23,7 @@ javascript library is planned.
|
||||
|
||||
# Getting Started
|
||||
|
||||
`mfer` builds from source with a Go 1.23+ toolchain. The generated protobuf code
|
||||
`mfer` builds from source with Go 1.27.1 or later. The generated protobuf code
|
||||
is committed, so no `protoc` toolchain is required:
|
||||
|
||||
```sh
|
||||
@@ -70,7 +70,7 @@ provide:
|
||||
- `script/bootstrap` — install all dependencies, idempotently: Go and the
|
||||
modules of `go.mod`; node (the version `.nvmrc` names, through nvm when there
|
||||
is no node on `PATH`) and yarn, plus the prettier version pinned in
|
||||
`package.json`/`yarn.lock`; `gofumpt` v0.12.0 and `protoc-gen-go` v1.36.11,
|
||||
`package.json`/`yarn.lock`; `gofumpt` v0.12.0 and `protoc-gen-go` v1.36.12,
|
||||
installed into `bin/` with `go install`, each pinned to a commit; and `protoc`
|
||||
33.4, unpacked into `bin/protoc` from its release archive once the archive
|
||||
matches the sha256 the script holds for this platform. Each of those three is
|
||||
@@ -98,6 +98,11 @@ provide:
|
||||
as ordinary tests
|
||||
- `script/lint` — run `golangci-lint` in Docker: builds only the `lint` stage of
|
||||
the `Dockerfile`, whose build runs the linter, uncached so it runs every time
|
||||
- `script/vulncheck` (`make vulncheck`) — run `govulncheck` in Docker: builds
|
||||
only the `vulncheck` stage of the `Dockerfile`, uncached, which reports known
|
||||
vulnerabilities in the code `mfer` calls, from the Go vulnerability database.
|
||||
`script/check` does not run it, so an advisory published later never turns the
|
||||
gate red
|
||||
- `script/fmt` — format all code and docs (writes): `script/gofumpt --write` and
|
||||
`script/prettier --write`
|
||||
- `script/gofumpt` — run `gofumpt` over every Go file in the repository in the
|
||||
|
||||
Reference in New Issue
Block a user