Skip to content

Refresh dependencies and CI actions; add a pre-PR dependency scan - #145

Merged
leet-c1 merged 4 commits into
mainfrom
chore/deps-refresh
Oct 5, 2026
Merged

leet-c1 merged 4 commits into
mainfrom
chore/deps-refresh

Conversation

@leet-c1

@leet-c1 leet-c1 commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Refreshes every dependency ahead of 0.9.0, and has agents do Dependabot's job until it's enabled on this repo.

Go modules

  • All 8 direct dependencies were already at their latest release; 4 indirect ones moved (fsnotify 1.10.1, go-toml/v2 2.4.3, go.yaml.in/yaml/v3 3.0.5, check.v1).
  • gopkg.in/yaml.v3 (archived) → go.yaml.in/yaml/v3, the maintained fork viper already uses. Import swap only, in 3 files. Output is byte-identical: ~/.c1i.yaml round-trips and the OpenAPI decode were compared across both libraries.
  • go stays at 1.27.1, the latest stable.

CI

Old New
actions/checkout v4 v7
actions/setup-go v5 v7
golangci/golangci-lint-action v7 v9
guyarb/golang-test-annotations v0.6.0 v0.9.0
golangci-lint v2.13.2 v2.14.0
govulncheck v1.7.0 v1.8.0
gosec v2.28.0 v2.29.0

release.yaml@v4 is unchanged; v4 is still the latest major.

The release notes show no breaking input changes for how ci.yaml uses these actions. This PR's CI run is the real check.

Dependency scan (CLAUDE.md)

A new section tells agents to run govulncheck -show verbose for linux, darwin and windows, plus an outdated-direct-dependency query, before opening any PR. They bump anything vulnerable (called or not) or outdated, and check the pinned actions and tools.

CI's govulncheck gate fails only on called vulnerabilities. The scan loop exits non-zero if any OS run fails, including when the command is run on the left of ||.

Verification

At the new tool versions: build, vet, go test -count=1 -shuffle=on, golangci-lint (0 issues), gosec with the CI flags, govulncheck ×3 GOOS (0 vulnerabilities), go mod tidy diff, and gitleaks all clean.

Binary is 257 KB smaller. An independent code review approved the branch.

🤖 Generated with Claude Code

leet-c1 and others added 4 commits October 5, 2026 22:24
Indirect bumps: fsnotify v1.10.1, go-toml/v2 v2.4.3, go.yaml.in/yaml/v3 v3.0.5,
check.v1 (2020-11-30). Direct dependencies and the go directive (1.27.1) were
already at their latest releases.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
go.yaml.in/yaml/v3 is the maintained, API-compatible fork and was already
in the build graph through viper. This direct import swap drops
gopkg.in/yaml.v3 and gopkg.in/check.v1 from go.mod.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
actions/checkout v7, actions/setup-go v7, golangci-lint-action v9,
golang-test-annotations v0.9.0; golangci-lint v2.14.0, govulncheck v1.8.0,
gosec v2.29.0. gitleaks v8.30.1 is already latest. release.yaml is untouched.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Dependabot isn't enabled on this repo, and CI's govulncheck gate fails
only on called vulnerabilities.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@leet-c1
leet-c1 merged commit 827013c into main Oct 5, 2026
2 checks passed
@leet-c1
leet-c1 deleted the chore/deps-refresh branch October 6, 2026 14:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant