Install pinned goimports in script/bootstrap (closes #184)
Check / check (pull_request) Successful in 1m49s
Check / check (pull_request) Successful in 1m49s
script/fmt runs goimports, but script/bootstrap did not install it, so make fmt failed with goimports: not found on a fresh machine. bootstrap now installs goimports v0.49.0 (pinned; compatible with the repo Go 1.25, so no toolchain download) into /usr/local/bin, guarded to skip when it is already present. Node/prettier pinning is left to a separate issue; the check gate runs only gofmt, so main is unaffected. Model: opus-4-8
This commit was merged in pull request #196.
This commit is contained in:
@@ -25,6 +25,9 @@ main cannot regress.
|
||||
- 2026-09-22: Fixed the gosec G703 path-traversal finding in the deploy
|
||||
log download handler by verifying the resolved path stays within the
|
||||
deploy log directory before serving, returning 404 on escape (#177).
|
||||
- 2026-09-22: `script/bootstrap` now installs a pinned `goimports`
|
||||
(`golang.org/x/tools` v0.49.0) into `/usr/local/bin`, so `make fmt`
|
||||
succeeds on a fresh machine after `make bootstrap` (#184).
|
||||
- 2026-09-09: Fixed four deployability blockers found by QA: CSRF origin
|
||||
check over plain HTTP (`UPAAS_PLAINTEXT_HTTP`, #189), pulling the git
|
||||
image when absent (#190), the env-var editor CSRF token lookup (#191),
|
||||
|
||||
Reference in New Issue
Block a user