build(deps): bump internal pkg pin to a pseudo-version on main - #250
Conversation
|
@coderabbitai full review |
✅ Action performedFull review finished. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (4)
📒 Files selected for processing (4)
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour. 📝 WalkthroughWalkthroughFour Go modules update their ChangesInternal pkg dependency pins
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other Merge Risk: ⚪ Minimal · up to The four modules now share a pkg revision that is on main, with matching dependency checksums. No concrete merge-blocking risk is indicated. 🚥 Pre-merge checks | ✅ 4 | ❓ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
Full details: Linked Issues checkExplanation [129] The change summary reports that all four modules now pin ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Summary
Bump the internal
pkgpin in every consumer module tov0.0.0-20261006002706-ea61b58e4b07(ea61b58, the latest pkg commit on main, an ancestor of origin/main).The issue text says providers/* still pin 43ab778; that was already partly fixed. Only ci_cd_sanity_tests still pinned the unreachable commit. The providers were on-main but stale, so they did not get later pkg fixes.
Behaviour brought in by the bump
pkg commits since the old providers/azure and providers/gcp pin (
git log b3b4cb5e3d80..ea61b58 -- pkg, 15 commits), including:providers/aws gets the 13 commits after de46f76. ci_cd_sanity_tests moves from the pre-squash commit to current main.
Verification
Per module, with GOWORK=off, GOTOOLCHAIN=go1.26.6:
go build ./...,go vet ./...,go test ./...,golangci-lint run ./...,gocyclo -over 10 -ignore "_test\.go" .,go mod tidy -diff,go mod verifyall exit 0 for aws, azure, gcp and ci_cd_sanity_tests.govulncheck ./...exits 0 in each (azure, gcp and ci_cd_sanity_tests report unreachable vulnerabilities in required modules only, same as before).go list -mshows the new pin in each module, and the module cache copy contains the #222fd20:ce::254/128entry inhttpclient. No API breaks or compile fixes were needed; the diff is go.mod/go.sum only.A pin can only reference a commit already on main, so after the next pkg change the pins lag by one commit again; this PR does not change that process.
Closes #129
Summary by CodeRabbit