Raise Go to the latest release, update dependencies, use the standard library uuid, add a vulnerability check (closes #102)
check / check (push) Failing after 4s
check / check (push) Failing after 4s
Go 1.27.1 in go.mod and in the Dockerfile's test and build images. Every module go.mod requires is at its current release; protoc-gen-go follows protobuf to v1.36.12 and mf.pb.go is regenerated. The standard library uuid package replaces github.com/google/uuid; FromBytes could only fail on a length validateUUID already checks, so that call and its unreachable error are gone. make vulncheck runs govulncheck v1.8.0, installed with go install at its release commit, in a vulncheck stage of the Dockerfile; script/check does not run it. The newer go directive switches on lint checks for strings.SplitSeq and t.Chdir, now used. A new test pins the bytes of a seeded manifest written by an mfer built before this change. Model: opus-5-5
This commit is contained in:
@@ -639,7 +639,7 @@ func sanitizePath(p string) (string, error) {
|
||||
func checkNoSymlinks(dest, p string) error {
|
||||
current := dest
|
||||
|
||||
for _, part := range strings.Split(p, string(filepath.Separator)) {
|
||||
for part := range strings.SplitSeq(p, string(filepath.Separator)) {
|
||||
current = filepath.Join(current, part)
|
||||
|
||||
info, err := os.Lstat(current)
|
||||
|
||||
Reference in New Issue
Block a user