Skip to content

release: pin sub-modules to v0.3.0 - #76

Merged
KARTIKrocks merged 1 commit into
mainfrom
release/pin-satellites-0.3.0
Sep 25, 2026
Merged

KARTIKrocks merged 1 commit into
mainfrom
release/pin-satellites-0.3.0

Conversation

@KARTIKrocks

Copy link
Copy Markdown
Owner

Summary

Step 2 of the 0.3.0 release, following #75 and the v0.3.0 root tag. Points the eight satellite modules at the core version that was just published.

This matters more than it looks. The satellites required v0.2.0, so anyone building gormguard, pgxguard or a parser without this repo's go.work compiled it against the published 0.2 core — the one that still leaks literal values into Result.Query and Result.Fingerprint. The workspace hides that completely: make test passes either way.

-	github.com/KARTIKrocks/sqlguard v0.2.0
+	github.com/KARTIKrocks/sqlguard v0.3.0

16 files: 8 × go.mod plus the go.sum updates from make tidy.

Type of change

  • Bug fix
  • New detection rule
  • New integration / parser
  • Feature / enhancement
  • Docs only
  • Refactor / chore

Checklist

  • make ci passes (fmt-check, vet, lint, vuln, test-race, lint-docs) across all modules
  • Added/updated tests (and, where practical, a failure-mode check)
  • Updated docs under website/docs/ with a version marker for anything new
  • Updated AGENTS.md / .sqlguard.example.yml if a convention or config key changed
  • Added an entry under ## [Unreleased] in CHANGELOG.md
  • No new third-party deps in analyzer / middleware / reporter
  • Findings stay redaction-safe (no raw literals leak into a Result)

No tests, docs, AGENTS.md or changelog entry: this is dependency bookkeeping that ships no behaviour, and 0.3.0's entry is already on main from #75.

Verification

GOWORK=off make test — all 14 packages pass. That is the run that matters and the only one that proves anything here: with the workspace off, each satellite resolves github.com/KARTIKrocks/sqlguard from the module proxy, so this confirms the v0.3.0 tag is fetchable and that every integration and parser compiles and passes against the real published core, not against this working tree.

make test (with go.work) also passes, and make tidy left no further changes.

After this merges

Last step of the release: tag each satellite at <mod>/v0.3.0 and push, per CONTRIBUTING.md. Those tags have to point at this commit, since that is where each go.mod requires the matching core.

The eight satellites required v0.2.0, so a consumer building one without this
repo's go.work compiled it against the published 0.2 core — which still has
the redaction leak 0.3.0 fixes.

Verified with GOWORK=off, which is the only run that resolves the satellites
against the real published tag rather than this tree: all 14 packages pass.
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: KARTIKrocks/sqlguard/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: b79cff53-e05c-4905-96eb-9f3a696885b5


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@KARTIKrocks
KARTIKrocks merged commit 729d2dc into main Sep 25, 2026
25 checks passed
@KARTIKrocks
KARTIKrocks deleted the release/pin-satellites-0.3.0 branch September 25, 2026 04:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant