Skip to content

release: pin sub-modules to v0.4.0 - #79

Merged
KARTIKrocks merged 1 commit into
mainfrom
release/pin-satellites-0.4.0
Sep 25, 2026
Merged

KARTIKrocks merged 1 commit into
mainfrom
release/pin-satellites-0.4.0

Conversation

@KARTIKrocks

Copy link
Copy Markdown
Owner

Summary

Step 2 of the 0.4.0 release, following #78 and the v0.4.0 root tag. Points the eight satellite modules at the core version just published.

The satellites required v0.3.0, so anyone building gormguard, pgxguard or a parser without this repo's go.work compiled it against the 0.3 core — which predates the uniform rule config, so a .sqlguard.yml naming slow-query or a plan rule would still be rejected there. The workspace hides that completely: make test passes either way.

-	github.com/KARTIKrocks/sqlguard v0.3.0
+	github.com/KARTIKrocks/sqlguard v0.4.0

16 files: 8 × go.mod plus the go.sum updates from make tidy.

Type of change

  • Bug fix
  • New detection rule
  • New integration / parser
  • Feature / enhancement
  • Docs only
  • Refactor / chore

Checklist

  • make ci passes (fmt-check, vet, lint, vuln, test-race, lint-docs) across all modules
  • Added/updated tests (and, where practical, a failure-mode check)
  • Updated docs under website/docs/ with a version marker for anything new
  • Updated AGENTS.md / .sqlguard.example.yml if a convention or config key changed
  • Added an entry under ## [Unreleased] in CHANGELOG.md
  • No new third-party deps in analyzer / middleware / reporter
  • Findings stay redaction-safe (no raw literals leak into a Result)

No tests, docs, AGENTS.md or changelog entry: this is dependency bookkeeping that ships no behaviour, and 0.4.0's entry is already on main from #78.

Verification

GOWORK=off make test — all 14 packages pass. The only run that proves anything here: with the workspace off, each satellite resolves github.com/KARTIKrocks/sqlguard from the module proxy, so this confirms the v0.4.0 tag is fetchable and that every integration and parser compiles and passes against the real published core rather than this working tree.

That matters more this release than last, because 0.4.0 carries a breaking middleware API change — NewQueryTracker gained a severity argument. A green run here is the evidence that no satellite was calling it.

make test (with go.work) also passes, and make tidy left no further changes.

After this merges

Last step: tag each satellite at <mod>/v0.4.0 and push, per CONTRIBUTING.md. Those tags must point at this commit, since that is where each go.mod requires the matching core. Then publish the release notes, leading with the two migrations.

The eight satellites required v0.3.0, so a consumer building one without this
repo's go.work compiled it against the published 0.3 core — which predates the
uniform rule config, so a .sqlguard.yml naming slow-query or a plan rule would
still be rejected there.

Verified with GOWORK=off, the only run that resolves the satellites against
the real published tag rather than this tree: all 14 packages pass. That also
confirms none of them called middleware.NewQueryTracker, whose signature this
release changes.
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: KARTIKrocks/sqlguard/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: ea6a0b15-a896-4d27-a6e0-44a556a7daea


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@KARTIKrocks
KARTIKrocks merged commit 748d88b into main Sep 25, 2026
25 checks passed
@KARTIKrocks
KARTIKrocks deleted the release/pin-satellites-0.4.0 branch September 25, 2026 07:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant