Repository navigation
chore(deps): update go module directive to v1.27.1 - #63
scality-renovate[bot] wants to merge 2 commits into
Conversation
|
On hold for now.
Will rebase and merge once the above is aligned. |
7fefd8e to
a4babb7
Compare
Dependency Bump EvaluationVersion change: Go 1.25.6 -> 1.26.6 (minor) Changes:
Breaking changes: None affecting this codebase. Go 1.26 introduces stricter net/url.Parse validation, Green Tea GC as default, linker section reorganization, and deprecates some crypto APIs -- but this codebase uses none of these patterns (verified: no net/url imports, no url.Parse, no crypto/ecdsa or crypto/rsa, no GODEBUG settings, no reflect.Type or reflect.Value). Security concerns: None. Go 1.26 enables post-quantum TLS key exchanges by default and includes various standard library hardening. No supply chain concerns -- this is a Go toolchain update from the official Go project. Impact on codebase:
Recommendation: REVIEW REQUIRED Notes:
-- Claude Code |
a4babb7 to
3d3c981
Compare
3d3c981 to
77de72b
Compare
77de72b to
3fddbd7
Compare
Dependency Bump EvaluationVersion change: Go 1.25.6 -> 1.27.1 (minor bump, skips 1.26 entirely) Changes:
Breaking changes:
Security concerns: None identified. No suspicious patterns in the dependency changes. Post-quantum TLS key exchanges enabled by default in Go 1.26, and multiple legacy TLS GODEBUG overrides permanently removed in 1.27 (TLS 1.0 server, RSA key exchange, 3DES), but this codebase does not use crypto/tls or net/http. Impact on codebase:
Recommendation: REVIEW REQUIRED Notes:
-- Claude Code |
The pre-merge workflow pinned Go 1.25 with GOTOOLCHAIN=local, so it could not build a module requiring go >= 1.27.1.
| env: | ||
| # renovate: datasource=golang-version depName=golang | ||
| GO_VERSION: 1.25 | ||
| GO_VERSION: 1.27 |
There was a problem hiding this comment.
golangci-lint v2.4.0 (line 13) was built with Go 1.25. It refuses to run on a module that targets a newer Go version ("the Go language version used to build golangci-lint is lower than the targeted Go version"), so the lint job will fail with go 1.27.1. Bump GOLANGCI_LINT_VERSION to a release built with Go ≥ 1.27 in this same PR.
| module github.com/scality/raidmgmt | ||
|
|
||
| go 1.25.6 | ||
| go 1.27.1 |
There was a problem hiding this comment.
This is an imported library. The go directive is the minimum Go version for every downstream module, so go 1.27.1 makes all consumers move to Go ≥ 1.27.1 (or auto-download a toolchain). Unless the code needs 1.27 features, keep the directive at the lowest version you support and bump only the CI GO_VERSION. A toolchain line can pin the build version for this repo.
Dependency Bump EvaluationVersion change: Go 1.25.6 → 1.27.1 (two minor versions) Changes (Go 1.26):
Changes (Go 1.27):
Breaking changes: encoding/json v2 is the highest-impact change for this codebase Security concerns: None identified. No crypto packages used, no TLS handling, no URL parsing. Impact on codebase:
CI status:
Recommendation: REVIEW REQUIRED Notes:
— Claude Code |
|
We have to wait for this: bumping this lib to 1.27.1 would force to bump go in the following projects:
|
This PR contains the following updates:
1.25.6→1.27.11.27.2Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.