Repository navigation
Refresh dependencies and CI actions; add a pre-PR dependency scan - #145
Merged
Merged
Conversation
Indirect bumps: fsnotify v1.10.1, go-toml/v2 v2.4.3, go.yaml.in/yaml/v3 v3.0.5, check.v1 (2020-11-30). Direct dependencies and the go directive (1.27.1) were already at their latest releases. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
go.yaml.in/yaml/v3 is the maintained, API-compatible fork and was already in the build graph through viper. This direct import swap drops gopkg.in/yaml.v3 and gopkg.in/check.v1 from go.mod. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
actions/checkout v7, actions/setup-go v7, golangci-lint-action v9, golang-test-annotations v0.9.0; golangci-lint v2.14.0, govulncheck v1.8.0, gosec v2.29.0. gitleaks v8.30.1 is already latest. release.yaml is untouched. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Dependabot isn't enabled on this repo, and CI's govulncheck gate fails only on called vulnerabilities. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refreshes every dependency ahead of 0.9.0, and has agents do Dependabot's job until it's enabled on this repo.
Go modules
gopkg.in/yaml.v3(archived) →go.yaml.in/yaml/v3, the maintained fork viper already uses. Import swap only, in 3 files. Output is byte-identical:~/.c1i.yamlround-trips and the OpenAPI decode were compared across both libraries.gostays at 1.27.1, the latest stable.CI
release.yaml@v4is unchanged; v4 is still the latest major.The release notes show no breaking input changes for how
ci.yamluses these actions. This PR's CI run is the real check.Dependency scan (CLAUDE.md)
A new section tells agents to run
govulncheck -show verbosefor linux, darwin and windows, plus an outdated-direct-dependency query, before opening any PR. They bump anything vulnerable (called or not) or outdated, and check the pinned actions and tools.CI's govulncheck gate fails only on called vulnerabilities. The scan loop exits non-zero if any OS run fails, including when the command is run on the left of
||.Verification
At the new tool versions: build, vet,
go test -count=1 -shuffle=on, golangci-lint (0 issues), gosec with the CI flags, govulncheck ×3 GOOS (0 vulnerabilities),go mod tidydiff, and gitleaks all clean.Binary is 257 KB smaller. An independent code review approved the branch.
🤖 Generated with Claude Code