Raise Go to the latest release, update dependencies, use the standard library uuid, add a vulnerability check (closes #102)
check / check (push) Failing after 5s

Go 1.27.1 in go.mod and in the Dockerfile's test and build images.
Every module go.mod requires is at its current release; protoc-gen-go
follows protobuf to v1.36.12 and mf.pb.go is regenerated. The new
standard library uuid package replaces github.com/google/uuid; the
FromBytes call could only fail on a length validateUUID already checks,
so it and its unreachable error are gone. make vulncheck runs
govulncheck v1.8.0, installed with go install at its release commit, in
a vulncheck stage of the Dockerfile on the digest-pinned golang image;
script/check does not run it. A new test pins the bytes of a seeded
manifest written by an mfer built before this change.

Model: opus-5-5
This commit is contained in:
2026-10-06 10:14:43 +00:00
parent 2a270b40c5
commit e745e18274
15 changed files with 141 additions and 507 deletions
+1 -1
View File
@@ -15,7 +15,7 @@ ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
# in the mf.pb.go header.
PROTOC_VERSION="33.4"
PROTOC="$ROOT/bin/protoc/bin/protoc"
PROTOC_GEN_GO_VERSION="v1.36.11"
PROTOC_GEN_GO_VERSION="v1.36.12"
PROTOC_GEN_GO="$ROOT/bin/protoc-gen-go"
# sha256 <file>: print "<hash> <file>", with sha256sum, or with shasum