Conversation
added 2 commits
September 27, 2026 04:37
govulncheck v1.8.0 (the version @latest resolves to) refuses to run on Go 1.24, and Go 1.24 is outside the upstream support window; the reachable stdlib fixes the security job needs ship in Go 1.26.6, the toolchain the rest of the GrayCode ecosystem already uses. - go.mod: go 1.26.6 (go mod tidy -diff is clean) - Makefile: add fmt-check, test-e2e, coverage, cross-check and vulncheck (govulncheck pinned to v1.8.0); make check now runs the gofmt gate; fuzz no longer swallows failures with || true - fmt-check escapes its command substitution: the unescaped $(gofmt -l .) was expanded by make to an empty string, so the gate could never fail - AGENTS.md, README.md, CONTRIBUTING.md: document the targets, the Go version, and the cgo requirement
- Pin every action to a full commit SHA with a version comment (same pins as rho/flux), check out without persisted credentials, and keep the workflow token read-only. - Use Go 1.26.6 with GOTOOLCHAIN=local so the job runs the toolchain it names instead of silently switching. - Split quality (tidy -diff, gofmt, build, vet, test on Linux and macOS), race, E2E, coverage and govulncheck (pinned) jobs; each runs the Makefile target a contributor runs locally. - Windows was added to the test matrix without qualification: the E2E and unit suites exec sh/python3, create symlinks and rely on cgo, and no test is gated by GOOS. Keep Windows as a compile-only check until it is qualified; README already lists it as untested. - Add .gitattributes (eol=lf) so a Windows checkout cannot turn every file into a gofmt failure.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Moves Across to the ecosystem Go toolchain (1.26.6) and makes CI deterministic and supply-chain pinned. This is the first of three PRs split out of the
chore/phase-zero-trustwork; it applies cleanly tomainon its own andchore/phase-zero-trust(#5) is stacked on these two commits.go.mod:go 1.26.6(was 1.24, outside the Go support window).go mod tidy -diffis clean.Makefile:fmt-check,test-e2e,coverage,cross-check(windows/amd64 vet + build) andvulncheck(govulncheck pinned to v1.8.0);make check= gofmt check + vet + race;fuzzno longer swallows failures with|| true.fmt-checkrecipe@test -z "$(gofmt -l .)"is expanded by make totest -z "", so the gate could never fail (make -n fmt-checkprintedtest -z ""). The recipe now escapes the substitution and lists offending files; checked with a deliberately misformatted file (exit 2).ci.yml: every action pinned to a commit SHA with a version comment (same pins as rho/flux),persist-credentials: false, read-only token,GOTOOLCHAIN=local,GOWORK=off, concurrency group. Jobs: quality (tidy -diff, gofmt, build, vet, test on ubuntu + macOS), cross-compile (Windows compile-only), race, E2E, coverage, govulncheck — each runs the Makefile target a contributor runs locally.sh/python3, create symlinks and need cgo, and no test is gated by GOOS..gitattributes(eol=lf) prevents a CRLF checkout from turning every file into a gofmt failure. README keeps Windows listed as untested.Findings addressed
govulncheck@latest→ x/vuln v1.8.0 requires go ≥ 1.26; 1.24 stdlib vulns). Now Go 1.26.6 +GOTOOLCHAIN=local+ govulncheck pinned to v1.8.0; docs updated.windows-latesttest job with concrete failure hazards. Replaced by a Windows compile-only job;.gitattributesadded.actions/checkout@v4,actions/setup-go@v5,actions/upload-artifact@v4were tag-pinned onmainand in the draft) — all CI actions SHA-pinned, credentials not persisted. The release half is in ci: release per-target archives with one checksum file and provenance #4.Not reproduced / deferred
Verification
Run on this branch (
ci/go-toolchain-gates, main's code) on darwin/arm64 with go1.26.6:GOWORK=off make checkgo test -race -count=1 ./...)GOWORK=off make test-e2eok github.com/graycodeai/across/e2e 31.8s)GOOS=linux GOARCH=amd64 GOWORK=off go build ./...GOOS=windows GOARCH=amd64 GOWORK=off go build ./...GOWORK=off make cross-checkGOWORK=off go mod tidy -diffGOWORK=off make vulncheckNo vulnerabilities found.actionlint .github/workflows/ci.yml(v1.7.12)make -n fmt-checkbefore the fixtest -z ""(no-op)The macOS and Linux CI jobs themselves have not run yet; they run on this PR.
Follow-ups
sh/python3/symlink tests by GOOS or make them portable, verify the SQLitefile:URI) before adding a Windows test job or Windows release artifacts.🤖 Generated with Claude Code