Raise Go to the latest release, update dependencies, use the standard library uuid, add a vulnerability check (closes #102)
check / check (push) Failing after 5s

Go 1.27.1 in go.mod and in the Dockerfile's test and build images.
Every module go.mod requires is at its current release; protoc-gen-go
follows protobuf to v1.36.12 and mf.pb.go is regenerated. The new
standard library uuid package replaces github.com/google/uuid; the
FromBytes call could only fail on a length validateUUID already checks,
so it and its unreachable error are gone. make vulncheck runs
govulncheck v1.8.0, installed with go install at its release commit, in
a vulncheck stage of the Dockerfile on the digest-pinned golang image;
script/check does not run it. A new test pins the bytes of a seeded
manifest written by an mfer built before this change.

Model: opus-5-5
This commit is contained in:
2026-10-06 10:14:43 +00:00
parent 2a270b40c5
commit e745e18274
15 changed files with 141 additions and 507 deletions
+33
View File
@@ -354,6 +354,39 @@ func TestGenerateCommand(t *testing.T) {
assert.True(t, exists)
}
// TestGenerateSeededManifestBytes pins the exact bytes `gen --seed` writes
// for a fixed tree, so that a Go or dependency update that changes what
// mfer writes fails here. testdata/seeded.mf was written by an mfer built
// before such an update. The tree has enough files that zstd compresses
// the manifest instead of storing it as it is.
func TestGenerateSeededManifestBytes(t *testing.T) {
t.Parallel()
fs := afero.NewMemMapFs()
start := time.Date(2025, 6, 1, 0, 0, 0, 0, time.UTC)
for i := range 200 {
path := fmt.Sprintf("/testdir/d%d/f%03d.txt", i%10, i)
mtime := start.Add(time.Duration(i) * time.Second)
require.NoError(t, fs.MkdirAll(filepath.Dir(path), 0o755))
writeTestFile(t, fs, path, fmt.Sprintf("file %d\n", i))
require.NoError(t, fs.Chtimes(path, mtime, mtime))
}
opts := testOpts([]string{
testApp, cmdGenerate, "-q", "--seed", "mfer", "-o", testOutput, testDir,
}, fs)
require.Equal(t, 0, runCLI(opts), "stderr: %s", testStderr(t, opts))
got, err := afero.ReadFile(fs, testOutput)
require.NoError(t, err)
want, err := os.ReadFile("testdata/seeded.mf")
require.NoError(t, err)
assert.Equal(t, want, got)
}
func TestGenerateAndCheckCommand(t *testing.T) {
t.Parallel()
+1 -1
View File
@@ -19,8 +19,8 @@ import (
"sync/atomic"
"testing"
"time"
"uuid"
"github.com/google/uuid"
"github.com/klauspost/compress/zstd"
"github.com/multiformats/go-multihash"
"github.com/spf13/afero"
BIN
View File
Binary file not shown.